SlideShare uma empresa Scribd logo
1 de 25
Baixar para ler offline
Personal Data Protection Act 2010:
Employee Data Privacy
Labour Law Conference
9 – 10 April 2015
Adlin Abdul Majid
Content
• Introduction
• Issues & Implications
• Conclusion
2
Introduction
Written / Oral
3
PERSONAL DATA PROTECTION ACT 2010
Application
• Applies to any person who processes or has control over or authorises
processing of personal data in respect of commercial transactions
• Applies if:
• PERSON ESTABLISHED IN MALAYSIA: Personal data is processed,
whether or not in context of that establishment, by that person or
any other person employed or engaged by that establishment
• PERSON NOT ESTABLISHED IN MALAYSIA: Uses equipment in
Malaysia to process personal data (otherwise than for purpose of
transit in Malaysia)
NOT
applicable
• Federal & State Governments
• Personal data processed outside Malaysia, unless intended to be further
processed in Malaysia
Complaints-based system
Application to employment relationships
4
• Any transaction of a commercial nature, whether contractual
or not
• Includes matters relating to:
• Supply or exchange of goods or services;
• Agency;
• Investments;
• Financing;
• Banking; &
• Insurance
• Does not include a credit reporting business
commercial transactions
Draft Guidelines on
Management of Employee Data
7 Principles of data protection
Written / Oral
5
Data Subject
General Principle
Data Processor/
3rd Party
Data User
Security Principle
Retention Principle
Integrity Principle
Notice &
Choice Principle
Disclosure
Principle
Access Principle
Employee
Employer
Service
providers
Content
• Introduction
• Issues & Implications
• Conclusion
6
Issues & Implications
7
Notice
Access
Retention
Consent
Issues & Implications
8
Notice
Access
Retention
Consent
What do you need consent for?
Written / Oral
9
Consent?
Non-sensitive
personal data
Disclosure of
personal data
to third parties
Transfer of
personal data
overseas
Sensitive
personal data
(explicit
consent)
Exemptions to consent
10
No Exemption Example
(a) For the performance of a contract to which
the data subject is a party
Existing bank customers
(b) For the taking of steps at the request of the
data subject with a view to entering into a
contract
Before the sale & purchase of a car, the
information requested by the salesman
in order to execute the contract
(c) For compliance with any legal obligation to
which the data user is the subject, other
than an obligation imposed by a contract
When an organisation is under a duty
pursuant to eg. tax laws, to provide
information of its employees to
authorities
(d) In order to protect the vital interests of the
data subject
In a situation where a person is
unconscious & needs medical
treatment to save his life
(e) For the administration of justice For the enforcement of a court order
(f) For the exercise of any functions conferred
on any person by or under any law
If an organisation is tasked to perform
a service by a law
Written / Oral
11
Explicit consent given by data subject
Processing is necessary
Personal data has been made public
Sensitive personal data may only be processed if…
Example of explicit consent
12
Consent: What does it entail?
Written / Oral
13
PDPA Regulations
DRAFT GUIDELINES ON
CONSENT
• Key test: Ability to
demonstrate that
consent exists /
given
• Data subject must
be fully aware of &
understand consent
• Consent
understood to have
been given when
individuals DO NOT
OBJECT or
volunteer personal
data after purposes
clearly explained
Issues & Implications
14
Notice
Access
Retention
Consent
Notice & choice
Written / Oral
15
• Data user shall provide a WRITTEN NOTICE to the data subject. To
include:
• That personal data of the data subject is being processed by or
on behalf of the data user
• Description of the personal data
• Purpose it is collected & further processed
• Class of 3rd parties to whom data user discloses / may disclose
the personal data
• Whether it is obligatory for the data subject to provide the
personal data
• Must be given as soon as practicable
• In national language & English
• Must be able to keep a record of service of notice
Issues & Implications
16
Notice
Access
Retention
Consent
17
Channels of serving notices to employees
Notice to
employees
Emails
Employment
forms
Employment
contracts
Salary slips
Right to access personal data
18
Right to
access
Full
disclosure
Partial
disclosure
Refuse to
disclose
Must respond within 21 days
When can you refuse to disclose / partially disclose?
Written / Oral
19
No sufficient
information on
identity of requestor
/ data subject
No sufficient
information to locate
personal data
Burden or expense of
providing access
Would disclose
information of
another individual
Another data user
controls personal
data
Violation of court
order
Would disclose
confidential
commercial
information
Access is regulated
by another law
Issues & Implications
20
Notice
Access
Retention
Consent
21
s10 PDPA
Employment
Draft
Guidelines
*Must destroy personal data
once purpose of processing has
lapsed
*Be aware of obligations
imposed by law, such as s61 of
Employment Act 1955
*Fresh consent needed for
future uses
*Should minimise cost by
deleting / anonymise when no
longer necessary
Retention of employee records
Retention of former employees’ data
22
HK
Guidance
Necessary for legal
/ contractual /
statutory obligation
Directly related to
managing the
relationship
between employer
& former employee
Need to defend
organisation in civil or
criminal suit
Consented to by
former
employee
Needed for job
references /
reapplication
Content
• Introduction
• Issues & Implications
• Conclusion
23
Conclusion
24
PRE-EMPLOYMENT
• Receipt of CVs
BEGINNING OF EMPLOYMENT
• Requests for personal data: Non-sensitive personal
data / sensitive personal data
DURING EMPLOYMENT
• Further requests for personal data
• Security / Access / Integrity / Disclosure
END OF EMPLOYMENT
• Retention
Thank you
(aam@lh-ag.com)

Mais conteúdo relacionado

Mais procurados

Confidentiality in the Workplace
Confidentiality in the WorkplaceConfidentiality in the Workplace
Confidentiality in the Workplace
salvarez63
 

Mais procurados (20)

Data Privacy: What you need to know about privacy, from compliance to ethics
Data Privacy: What you need to know about privacy, from compliance to ethicsData Privacy: What you need to know about privacy, from compliance to ethics
Data Privacy: What you need to know about privacy, from compliance to ethics
 
18 Tips for Data Classification - Data Sheet by Secure Islands
18 Tips for Data Classification - Data Sheet by Secure Islands18 Tips for Data Classification - Data Sheet by Secure Islands
18 Tips for Data Classification - Data Sheet by Secure Islands
 
Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and Privacy
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
Data protection
Data protectionData protection
Data protection
 
Privacy and Data Security
Privacy and Data SecurityPrivacy and Data Security
Privacy and Data Security
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
 
Privacy & Data Protection
Privacy & Data ProtectionPrivacy & Data Protection
Privacy & Data Protection
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
Data Protection Presentation
Data Protection PresentationData Protection Presentation
Data Protection Presentation
 
What about GDPR?
What about GDPR?What about GDPR?
What about GDPR?
 
Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
 
Personal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochurePersonal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochure
 
EU's General Data Protection Regulation (GDPR)
EU's General Data Protection Regulation (GDPR)EU's General Data Protection Regulation (GDPR)
EU's General Data Protection Regulation (GDPR)
 
Confidentiality in the Workplace
Confidentiality in the WorkplaceConfidentiality in the Workplace
Confidentiality in the Workplace
 
DPDP Act 2023.pdf
DPDP Act 2023.pdfDPDP Act 2023.pdf
DPDP Act 2023.pdf
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
Legal obligations and responsibilities of data processors and controllers und...
Legal obligations and responsibilities of data processors and controllers und...Legal obligations and responsibilities of data processors and controllers und...
Legal obligations and responsibilities of data processors and controllers und...
 

Destaque

Data Protection Act
Data Protection ActData Protection Act
Data Protection Act
Yizi
 
Presentation ICT2
Presentation ICT2Presentation ICT2
Presentation ICT2
safa
 
Cybercrime Court Decisions from Latin America - Legal and Policy Developments...
Cybercrime Court Decisions from Latin America - Legal and Policy Developments...Cybercrime Court Decisions from Latin America - Legal and Policy Developments...
Cybercrime Court Decisions from Latin America - Legal and Policy Developments...
Cédric Laurant
 
Legal Framework of Internet Banking
Legal Framework of Internet BankingLegal Framework of Internet Banking
Legal Framework of Internet Banking
Mahyuddin Khalid
 
Highlights of the Singapore Personal Data Protection Act 2012
Highlights of the Singapore Personal Data Protection Act 2012Highlights of the Singapore Personal Data Protection Act 2012
Highlights of the Singapore Personal Data Protection Act 2012
Fuji Xerox Singapore
 
Report of hrm department waqar
Report of hrm department waqarReport of hrm department waqar
Report of hrm department waqar
WAQAR AHMED
 

Destaque (20)

Outsourcing and transfer of personal data - Titta Penttilä - TeliaSonera
Outsourcing and transfer of personal data - Titta Penttilä - TeliaSoneraOutsourcing and transfer of personal data - Titta Penttilä - TeliaSonera
Outsourcing and transfer of personal data - Titta Penttilä - TeliaSonera
 
Complying with Singapore Personal Data Protection Act - A Practical Guide
Complying with Singapore Personal Data Protection Act - A Practical GuideComplying with Singapore Personal Data Protection Act - A Practical Guide
Complying with Singapore Personal Data Protection Act - A Practical Guide
 
Personal data Protection Act Singapore How-to Perform Assessment
Personal data Protection Act Singapore How-to Perform AssessmentPersonal data Protection Act Singapore How-to Perform Assessment
Personal data Protection Act Singapore How-to Perform Assessment
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection Act
 
New Media Internet Expression and European Data Protection
New Media Internet Expression and European Data ProtectionNew Media Internet Expression and European Data Protection
New Media Internet Expression and European Data Protection
 
The principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - ukThe principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - uk
 
The Data Protection Act What You Need To Know
The Data Protection Act   What You Need To KnowThe Data Protection Act   What You Need To Know
The Data Protection Act What You Need To Know
 
What All Organisations Need to Know About Data Protection and Cloud Computing...
What All Organisations Need to Know About Data Protection and Cloud Computing...What All Organisations Need to Know About Data Protection and Cloud Computing...
What All Organisations Need to Know About Data Protection and Cloud Computing...
 
Presentation ICT2
Presentation ICT2Presentation ICT2
Presentation ICT2
 
Webinar: Compliance and Data Protection in the Big Data Age: MongoDB Security...
Webinar: Compliance and Data Protection in the Big Data Age: MongoDB Security...Webinar: Compliance and Data Protection in the Big Data Age: MongoDB Security...
Webinar: Compliance and Data Protection in the Big Data Age: MongoDB Security...
 
Cyberlaw
CyberlawCyberlaw
Cyberlaw
 
Sexual Harassment & Gender Discrimination by Janice Anne Leo
Sexual Harassment & Gender Discrimination by Janice Anne LeoSexual Harassment & Gender Discrimination by Janice Anne Leo
Sexual Harassment & Gender Discrimination by Janice Anne Leo
 
Chapter 1
Chapter 1Chapter 1
Chapter 1
 
Cybercrime Court Decisions from Latin America - Legal and Policy Developments...
Cybercrime Court Decisions from Latin America - Legal and Policy Developments...Cybercrime Court Decisions from Latin America - Legal and Policy Developments...
Cybercrime Court Decisions from Latin America - Legal and Policy Developments...
 
Data Protection & Privacy in Malaysian Total Hospital Information System
Data Protection & Privacy in Malaysian Total Hospital Information SystemData Protection & Privacy in Malaysian Total Hospital Information System
Data Protection & Privacy in Malaysian Total Hospital Information System
 
Ethics and information security 2
Ethics and information security 2Ethics and information security 2
Ethics and information security 2
 
Legal Framework of Internet Banking
Legal Framework of Internet BankingLegal Framework of Internet Banking
Legal Framework of Internet Banking
 
Hacking and Hacktivism
Hacking and HacktivismHacking and Hacktivism
Hacking and Hacktivism
 
Highlights of the Singapore Personal Data Protection Act 2012
Highlights of the Singapore Personal Data Protection Act 2012Highlights of the Singapore Personal Data Protection Act 2012
Highlights of the Singapore Personal Data Protection Act 2012
 
Report of hrm department waqar
Report of hrm department waqarReport of hrm department waqar
Report of hrm department waqar
 

Semelhante a Personal Data Protection Act - Employee Data Privacy

GDPR - 5 Months On!
GDPR - 5 Months On!GDPR - 5 Months On!
Data Protection Act presentation
Data Protection Act presentationData Protection Act presentation
Data Protection Act presentation
Ian Clive Oultram
 

Semelhante a Personal Data Protection Act - Employee Data Privacy (20)

Reddico GDPR Presentation
Reddico GDPR PresentationReddico GDPR Presentation
Reddico GDPR Presentation
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
 
Building Consumer Trust through Individual Rights / DSAR Management
Building Consumer Trust through Individual Rights / DSAR ManagementBuilding Consumer Trust through Individual Rights / DSAR Management
Building Consumer Trust through Individual Rights / DSAR Management
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
GDPR - 5 Months On!
GDPR - 5 Months On!GDPR - 5 Months On!
GDPR - 5 Months On!
 
Data Decoded: Understanding India's Draft Data Protection Bill
Data Decoded: Understanding India's Draft Data Protection BillData Decoded: Understanding India's Draft Data Protection Bill
Data Decoded: Understanding India's Draft Data Protection Bill
 
How to Turn GDPR into a Competitive Advantage
How to Turn GDPR into a Competitive AdvantageHow to Turn GDPR into a Competitive Advantage
How to Turn GDPR into a Competitive Advantage
 
Bahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdfBahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdf
 
The General Data Protection Regulation (GDPR) in Ireland-What You Should Know
The General Data Protection Regulation (GDPR) in Ireland-What You Should KnowThe General Data Protection Regulation (GDPR) in Ireland-What You Should Know
The General Data Protection Regulation (GDPR) in Ireland-What You Should Know
 
GDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc MichaelsGDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc Michaels
 
Gdpr powerpoint 15.01.18
Gdpr powerpoint 15.01.18Gdpr powerpoint 15.01.18
Gdpr powerpoint 15.01.18
 
The Protection of Personal Information Act: A Presentation
The Protection of Personal Information Act: A PresentationThe Protection of Personal Information Act: A Presentation
The Protection of Personal Information Act: A Presentation
 
An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
WB-2022-01-25-India Data Protection Bill
WB-2022-01-25-India Data Protection BillWB-2022-01-25-India Data Protection Bill
WB-2022-01-25-India Data Protection Bill
 
Data Protection Act presentation
Data Protection Act presentationData Protection Act presentation
Data Protection Act presentation
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection Regulation
 

Mais de legalPadmin

Mais de legalPadmin (12)

Collective bargaining in a difficult economy by siva kumar
Collective bargaining in a difficult economy by siva kumarCollective bargaining in a difficult economy by siva kumar
Collective bargaining in a difficult economy by siva kumar
 
Change Of Ownership In Business: Its Impact On The Contract of Employment
Change Of Ownership In Business: Its Impact On The Contract of EmploymentChange Of Ownership In Business: Its Impact On The Contract of Employment
Change Of Ownership In Business: Its Impact On The Contract of Employment
 
Fit & Proper Punishment Pre Panzana: Conflicting Views at High Court, Court o...
Fit & Proper Punishment Pre Panzana: Conflicting Views at High Court, Court o...Fit & Proper Punishment Pre Panzana: Conflicting Views at High Court, Court o...
Fit & Proper Punishment Pre Panzana: Conflicting Views at High Court, Court o...
 
Redundancy, Retrenchment and Separation
Redundancy, Retrenchment and SeparationRedundancy, Retrenchment and Separation
Redundancy, Retrenchment and Separation
 
Managing Dismissal Cases - Trial preparation
Managing Dismissal Cases - Trial preparationManaging Dismissal Cases - Trial preparation
Managing Dismissal Cases - Trial preparation
 
Managing Dismissal Cases - Pretrial preparation
Managing Dismissal Cases - Pretrial preparationManaging Dismissal Cases - Pretrial preparation
Managing Dismissal Cases - Pretrial preparation
 
Managing Dismissal Cases to Avoid Repercussions
Managing Dismissal Cases to Avoid RepercussionsManaging Dismissal Cases to Avoid Repercussions
Managing Dismissal Cases to Avoid Repercussions
 
Challenges Encountered with Indonesia’s Rules and Requirements for Terminatio...
Challenges Encountered with Indonesia’s Rules and Requirements for Terminatio...Challenges Encountered with Indonesia’s Rules and Requirements for Terminatio...
Challenges Encountered with Indonesia’s Rules and Requirements for Terminatio...
 
Redundancy, Retrenchment and Separation
Redundancy, Retrenchment and SeparationRedundancy, Retrenchment and Separation
Redundancy, Retrenchment and Separation
 
Managing Dismissal to Avoid Repercussion
Managing Dismissal to Avoid RepercussionManaging Dismissal to Avoid Repercussion
Managing Dismissal to Avoid Repercussion
 
Sexual Harassment & Gender Discrimination in the Workplace)
Sexual Harassment & Gender Discrimination in the Workplace)Sexual Harassment & Gender Discrimination in the Workplace)
Sexual Harassment & Gender Discrimination in the Workplace)
 
Employment Laws Addressing Needs of Employers
Employment Laws Addressing Needs of EmployersEmployment Laws Addressing Needs of Employers
Employment Laws Addressing Needs of Employers
 

Último

一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
e9733fc35af6
 
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
Airst S
 
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
ShashankKumar441258
 
Contract law. Indemnity
Contract law.                     IndemnityContract law.                     Indemnity
Contract law. Indemnity
mahikaanand16
 
一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理
Airst S
 

Último (20)

Smarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation Strategy
Smarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation StrategySmarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation Strategy
Smarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation Strategy
 
ARTICLE 370 PDF about the indian constitution.
ARTICLE 370 PDF about the  indian constitution.ARTICLE 370 PDF about the  indian constitution.
ARTICLE 370 PDF about the indian constitution.
 
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
 
589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf
 
Hely-Hutchinson v. Brayhead Ltd .pdf
Hely-Hutchinson v. Brayhead Ltd         .pdfHely-Hutchinson v. Brayhead Ltd         .pdf
Hely-Hutchinson v. Brayhead Ltd .pdf
 
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
 
Cyber Laws : National and International Perspective.
Cyber Laws : National and International Perspective.Cyber Laws : National and International Perspective.
Cyber Laws : National and International Perspective.
 
CAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction FailsCAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction Fails
 
3 Formation of Company.www.seribangash.com.ppt
3 Formation of Company.www.seribangash.com.ppt3 Formation of Company.www.seribangash.com.ppt
3 Formation of Company.www.seribangash.com.ppt
 
Clarifying Land Donation Issues Memo for
Clarifying Land Donation Issues Memo forClarifying Land Donation Issues Memo for
Clarifying Land Donation Issues Memo for
 
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
 
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
 
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURYA SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
 
Contract law. Indemnity
Contract law.                     IndemnityContract law.                     Indemnity
Contract law. Indemnity
 
Navigating the Legal and Ethical Landscape of Blockchain Investigation.pdf
Navigating the Legal and Ethical Landscape of Blockchain Investigation.pdfNavigating the Legal and Ethical Landscape of Blockchain Investigation.pdf
Navigating the Legal and Ethical Landscape of Blockchain Investigation.pdf
 
The Active Management Value Ratio: The New Science of Benchmarking Investment...
The Active Management Value Ratio: The New Science of Benchmarking Investment...The Active Management Value Ratio: The New Science of Benchmarking Investment...
The Active Management Value Ratio: The New Science of Benchmarking Investment...
 
一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理
 
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
 
Corporate Sustainability Due Diligence Directive (CSDDD or the EU Supply Chai...
Corporate Sustainability Due Diligence Directive (CSDDD or the EU Supply Chai...Corporate Sustainability Due Diligence Directive (CSDDD or the EU Supply Chai...
Corporate Sustainability Due Diligence Directive (CSDDD or the EU Supply Chai...
 
Navigating Employment Law - Term Project.pptx
Navigating Employment Law - Term Project.pptxNavigating Employment Law - Term Project.pptx
Navigating Employment Law - Term Project.pptx
 

Personal Data Protection Act - Employee Data Privacy

  • 1. Personal Data Protection Act 2010: Employee Data Privacy Labour Law Conference 9 – 10 April 2015 Adlin Abdul Majid
  • 2. Content • Introduction • Issues & Implications • Conclusion 2
  • 3. Introduction Written / Oral 3 PERSONAL DATA PROTECTION ACT 2010 Application • Applies to any person who processes or has control over or authorises processing of personal data in respect of commercial transactions • Applies if: • PERSON ESTABLISHED IN MALAYSIA: Personal data is processed, whether or not in context of that establishment, by that person or any other person employed or engaged by that establishment • PERSON NOT ESTABLISHED IN MALAYSIA: Uses equipment in Malaysia to process personal data (otherwise than for purpose of transit in Malaysia) NOT applicable • Federal & State Governments • Personal data processed outside Malaysia, unless intended to be further processed in Malaysia Complaints-based system
  • 4. Application to employment relationships 4 • Any transaction of a commercial nature, whether contractual or not • Includes matters relating to: • Supply or exchange of goods or services; • Agency; • Investments; • Financing; • Banking; & • Insurance • Does not include a credit reporting business commercial transactions Draft Guidelines on Management of Employee Data
  • 5. 7 Principles of data protection Written / Oral 5 Data Subject General Principle Data Processor/ 3rd Party Data User Security Principle Retention Principle Integrity Principle Notice & Choice Principle Disclosure Principle Access Principle Employee Employer Service providers
  • 6. Content • Introduction • Issues & Implications • Conclusion 6
  • 9. What do you need consent for? Written / Oral 9 Consent? Non-sensitive personal data Disclosure of personal data to third parties Transfer of personal data overseas Sensitive personal data (explicit consent)
  • 10. Exemptions to consent 10 No Exemption Example (a) For the performance of a contract to which the data subject is a party Existing bank customers (b) For the taking of steps at the request of the data subject with a view to entering into a contract Before the sale & purchase of a car, the information requested by the salesman in order to execute the contract (c) For compliance with any legal obligation to which the data user is the subject, other than an obligation imposed by a contract When an organisation is under a duty pursuant to eg. tax laws, to provide information of its employees to authorities (d) In order to protect the vital interests of the data subject In a situation where a person is unconscious & needs medical treatment to save his life (e) For the administration of justice For the enforcement of a court order (f) For the exercise of any functions conferred on any person by or under any law If an organisation is tasked to perform a service by a law
  • 11. Written / Oral 11 Explicit consent given by data subject Processing is necessary Personal data has been made public Sensitive personal data may only be processed if…
  • 12. Example of explicit consent 12
  • 13. Consent: What does it entail? Written / Oral 13 PDPA Regulations DRAFT GUIDELINES ON CONSENT • Key test: Ability to demonstrate that consent exists / given • Data subject must be fully aware of & understand consent • Consent understood to have been given when individuals DO NOT OBJECT or volunteer personal data after purposes clearly explained
  • 15. Notice & choice Written / Oral 15 • Data user shall provide a WRITTEN NOTICE to the data subject. To include: • That personal data of the data subject is being processed by or on behalf of the data user • Description of the personal data • Purpose it is collected & further processed • Class of 3rd parties to whom data user discloses / may disclose the personal data • Whether it is obligatory for the data subject to provide the personal data • Must be given as soon as practicable • In national language & English • Must be able to keep a record of service of notice
  • 17. 17 Channels of serving notices to employees Notice to employees Emails Employment forms Employment contracts Salary slips
  • 18. Right to access personal data 18 Right to access Full disclosure Partial disclosure Refuse to disclose Must respond within 21 days
  • 19. When can you refuse to disclose / partially disclose? Written / Oral 19 No sufficient information on identity of requestor / data subject No sufficient information to locate personal data Burden or expense of providing access Would disclose information of another individual Another data user controls personal data Violation of court order Would disclose confidential commercial information Access is regulated by another law
  • 21. 21 s10 PDPA Employment Draft Guidelines *Must destroy personal data once purpose of processing has lapsed *Be aware of obligations imposed by law, such as s61 of Employment Act 1955 *Fresh consent needed for future uses *Should minimise cost by deleting / anonymise when no longer necessary Retention of employee records
  • 22. Retention of former employees’ data 22 HK Guidance Necessary for legal / contractual / statutory obligation Directly related to managing the relationship between employer & former employee Need to defend organisation in civil or criminal suit Consented to by former employee Needed for job references / reapplication
  • 23. Content • Introduction • Issues & Implications • Conclusion 23
  • 24. Conclusion 24 PRE-EMPLOYMENT • Receipt of CVs BEGINNING OF EMPLOYMENT • Requests for personal data: Non-sensitive personal data / sensitive personal data DURING EMPLOYMENT • Further requests for personal data • Security / Access / Integrity / Disclosure END OF EMPLOYMENT • Retention