# 個人データ削除権及び救済メカニズム

- 日付: 2024-04-03
- 関係者: Chua Kheng Wee Louis · Josephine Teo
- 出典: https://sprs.parl.gov.sg/search/#/sprs3topic?reportid=written-answer-16262
- sgai: https://sgai.md/ja/debates/written-answer-16262/
- ライセンス：sgai が作成した内容（要約・翻訳・分析）は CC BY 4.0（出典明記と sgai.md へのリンクが条件）。逐語的な原文（議会記録・演説・字幕・政策原文）は原権利者に帰属し、参照目的でのみ掲載。条項：https://github.com/meltflake/sgai/blob/main/DATA-LICENSE.md

## なぜ重要か

個人データ保護法には法定削除権条項がなく、執行は完全に個人データ保護委員会の自由裁量に依存しており、AI時代のデータ主体の権利保護に潜在的なリスクを埋め込んでいます。

## 要約

議員は、個人データ保護法において個人データ削除権および関連する救済メカニズムが含まれているかどうかについて質問している。政府は、法律は組織がデータがもはや必要でなくなった時点で、同意の有無を問わず、保有を中止するか適切に処理しなければならないと規定しており、個人データ保護委員会はデータの破棄または使用中止を指示する権限を有していると指摘している。コア争点は、明確な「削除権」条項およびその実施保障が存在するかどうかにある。

## 要点

- No explicit right to erasure clause
- Strict limits on data retention
- Regulator has enforcement power

## 全文

27号 蔡庆伟氏は通信・情報大臣に対し、「削除権」条項の欠如を踏まえ、『2012年個人データ保護法』は(i)その個人データの収集、使用または開示に同意していない個人について、請求時に組織にその個人データの削除を要求することができるかどうか、および(ii)組織が削除しなかった場合、当該個人が採用できる救済措置は何かについて規定しているかを質問した。

ジョセフィン・テオ氏は答えました。個人データ保護法（PDPA）は、個人データが収集時の目的またはその他の合法的な商業もしくは法律目的のために使用されなくなった場合、組織は当該個人データの保有を停止し、または適切な方法で処分することを要求しています。

同意の有無を問わず、組織はこの要件を遵守する必要があります。PDPA下の保有期間は、個人データがさらに使用されないことを保証するのに十分です。組織がこれらの要件を遵守しない場合、個人データ保護委員会（PDPC）は、当該組織に関連する個人データを破棄するか、または個人データの収集、使用もしくは開示を停止するよう指示する権限を有しています。

## Hansard (original, English)

© Parliament of Singapore — reproduced for reference only.

27 Mr Chua Kheng Wee Louis asked the Minister for Communications and Information given the absence of a 'right to erasure' clause, whether the Personal Data Protection Act 2012 provides for (i) individuals who have not given consent for the collection, use, or disclosure of their personal data and requiring an organisation to delete their personal data upon request and (ii) the recourse for such individuals if the organisation does not do so.

Mrs Josephine Teo : The Personal Data Protection Act (PDPA) requires an organisation to cease retention of personal data or dispose of it in a proper manner when it is no longer needed for the purposes it was collected for, or other legitimate business or legal purpose.

This requirement applies regardless of whether consent had or had not been given for the organisation's collection, use or disclosure of personal data. Retention limits under the PDPA sufficiently safeguard the further use of an individual's personal data. If the organisation does not adhere to these requirements, the Personal Data Protection Commission (PDPC) has the power to direct the organisation to destroy, or stop collecting, using or disclosing, the personal data concerned.
