Download Training Directory (2021) Download Now

Apr 2020

2 Days Advanced Personal Data Protection Act in Singapore (LIVE Stream)

Course Information

Start Date27 Apr 2020, Monday
End Date28 Apr 2020, Tuesday
Time09:00 am - 05:00 pm
VenueOnline Live Streaming (Zoom)
Fee$1200 (Excluding GST), Inclusive of e-certificate, e-materials and $50 Grab Voucher
Contact6720 3333 (Ms Chye Fen) training.aventis@gmail.com
Register Now
Get Group Quote
LIVE Stream


The Singapore Personal Data Protection Act (“PDPA”) came into force over two phases, the provisions relating to the Do Not Call regime came into force at the beginning of 2014 and the remaining provisions of the PDPA came into force in the middle of 2014. Since then, many organizations are still grappling with the implementation of their compliance program to meet their obligations under the PDPA. Now, three years on, it is a good time for your organization to get updated on the latest regulation and compliance requirement within the framework of the advisory guidelines issued by the Personal Data Protection Commission.

Course Objectives

A 2 Day Workshop to help your organization developed an Effective System to ensure Full compliance with the PDPA latest PDPA Requirement

The objective of this 2-day advanced course is to provide a step by step guide on how you can develop an effective and easy to maintain system within your organization to ensure that your organizational be in Full compliance of the latest Requirement

Exemptions to PDPA? What You Must Know

While there are certain exemptions to these obligations, it is clear that the organizations have a heavy responsibility particularly in light of the fact that criminal and civil consequences may be the result of one or more breaches of the PDPA.

Due to the serious potential consequences for breaches of the PDPA, in this 2-day Advanced PDPA workshop, we will be covering a detailed understanding of the critical provisions of the PDPA.It is hoped, thereby, that attendees will be able to ensure that their organizations are PDPA-compliant in all respects. Reference will be made to cases involving breaches and alleged breaches of the PDPA.

Who Should Attend?

This course is targeted at all officers and managers of any organization that handle personal data particularly the Data Protection Officer. This includes those in the Human Resources, Legal, Sales, Marketing, Finance, Compliance and Audit teams.

Additionally, it is targeted at the executives of such organizations such as the Chief Executive Officer, President, Managing Director, Chief Financial Officer, Chief Information Officer and Directors who should also have a good knowledge of the PDPA. This is so they can supervise the employees who handle personal data as there are criminal and civil sanctions for the breach of the PDPA.


“An intelligent and knowledgeable facilitator! He gave very helpful case study and it was well-explained. I have learned quite a lot of new knowledge from him!” – Ong Bee Chong, Ministry of Education

“The trainer explained in simple layman terms even though he is a lawyer. He is very patient in explaining and we have learned a lot” – Florence Ho, Lions Home For Elders

Trainer: Mirza Khaleel Namazie, Advocate & Solicitor (Singapore)

Khaleel was admitted as an Advocate & Solicitor of the Supreme Court of Singapore in 1994. He is also a member of the Law Society of England & Wales. He read for a Bachelor’s Degree in Law at the National University of Singapore and for a Master’s Degree in Computer and Communications Law at Queen Mary & Westfield College, University of London, the component subjects which were Information Technology Law, Intellectual Property Law, Telecommunications Law, Electronic Banking Law and Internet Law.

Apart from his experience in advising local and international clients in private practice on a variety of commercial, corporate and litigation matters, Khaleel worked in the Asia Pacific Legal Department of Hewlett-Packard Singapore Pte Ltd as a Commercial Contracts Manager with special responsibility for the Asia Emerging Countries of Pakistan, Bangladesh and Vietnam and with Singapore Telecommunications Limited as Senior Legal Counsel as part of the SingTel Global Offices team. During that time, he was also responsible for negotiating the legal aspects of a number of high value telecommunications and IT agreements with a significant number of Fortune 500 companies.

Course Outline

An Updated View of the latest PDPA Requirement

  1. The data protection provisions
  2. The Do Not Call registry provisions

Scope of significant terms under the PDPA such as but not limited to ‘personal data’, ‘individuals’, ‘organizations’, ‘data intermediaries’, ‘processing’, ‘collection’, ‘use and disclosure’, ‘reasonable’ and exclusions thereto.

The scope of the 9 Obligations under the data protection provisions of the PDPA and exceptions thereto

  1. The Consent Obligation
  2. The Purpose Limitation Obligation
  3. The Notification Obligation
  4. The Access and Correction Obligation
  5. The Accuracy Obligation
  6. The Protection Obligation
  7. The Retention Limitation Obligation
  8. The Transfer Limitation Obligation
  9. The Openness Obligation

Data Protection Officer – Dos and Don’t

  1. Your personal and organizational responsibilities
  2. Appointment and Role
  3. Responsibility to ensure compliance with the PDPA
  4. Understanding the criminal and civil sanctions for breaches of the PDPA
  5. Case Studies involving breaches and alleged breaches of the PDPA


  1. What this means
  2. When this is appropriate to be implemented

Applicability of the PDPA to different situations

  1. Employment
  2. Photography, recordings and CCTV
  3. Online matters
  4. Personal identification documentation such as NRIC

Developed an Effective System in place to ensure compliance with the PDPA

  1. Awareness of the PDPA among management and employees
  2. Internalizing the importance of the PDPA among all members of the organization
  3. Training and updating all members of the organization on the PDPA and updates thereto by conducting A Personal Data Audit
  4. What to do if the organization is not PDPA-compliant

The Do Not Call (DNC) Registry

  1. Establishment of the Registry
  2. The registers that are maintained by the Registry
  3. Obligations of organizations relating to the sending of marketing messages
  4. Exceptions to the above obligations

*Including a brief review of the scope of the European Union General Data Protection Regulation.