書面答弁 · 2024-04-03 · 議会 14
個人データ削除権及び救済メカニズム
議員は、個人データ保護法において個人データ削除権および関連する救済メカニズムが含まれているかどうかについて質問している。政府は、法律は組織がデータがもはや必要でなくなった時点で、同意の有無を問わず、保有を中止するか適切に処理しなければならないと規定しており、個人データ保護委員会はデータの破棄または使用中止を指示する権限を有していると指摘している。コア争点は、明確な「削除権」条項およびその実施保障が存在するかどうかにある。
重要なポイント
- • No explicit right to erasure clause
- • Strict limits on data retention
- • Regulator has enforcement power
現行の法律規定および規制メカニズムを支持します
明確な削除権の保証が欠けていることに異議を唱えます
データの保持と破棄の規制を強化します
“The Personal Data Protection Commission (PDPC) has the power to direct the organisation to destroy, or stop collecting, using or disclosing, the personal data concerned.”
参加者 (2)
全文翻訳(日本語)
Hansard 原文 · 2026-05-02
27号 蔡庆伟氏は通信・情報大臣に対し、「削除権」条項の欠如を踏まえ、『2012年個人データ保護法』は(i)その個人データの収集、使用または開示に同意していない個人について、請求時に組織にその個人データの削除を要求することができるかどうか、および(ii)組織が削除しなかった場合、当該個人が採用できる救済措置は何かについて規定しているかを質問した。
ジョセフィン・テオ氏は答えました。個人データ保護法(PDPA)は、個人データが収集時の目的またはその他の合法的な商業もしくは法律目的のために使用されなくなった場合、組織は当該個人データの保有を停止し、または適切な方法で処分することを要求しています。
同意の有無を問わず、組織はこの要件を遵守する必要があります。PDPA下の保有期間は、個人データがさらに使用されないことを保証するのに十分です。組織がこれらの要件を遵守しない場合、個人データ保護委員会(PDPC)は、当該組織に関連する個人データを破棄するか、または個人データの収集、使用もしくは開示を停止するよう指示する権限を有しています。
英語原文
SPRS Hansard 原本記録 · 取得日:2026-05-02
27 Mr Chua Kheng Wee Louis asked the Minister for Communications and Information given the absence of a 'right to erasure' clause, whether the Personal Data Protection Act 2012 provides for (i) individuals who have not given consent for the collection, use, or disclosure of their personal data and requiring an organisation to delete their personal data upon request and (ii) the recourse for such individuals if the organisation does not do so.
Mrs Josephine Teo : The Personal Data Protection Act (PDPA) requires an organisation to cease retention of personal data or dispose of it in a proper manner when it is no longer needed for the purposes it was collected for, or other legitimate business or legal purpose.
This requirement applies regardless of whether consent had or had not been given for the organisation's collection, use or disclosure of personal data. Retention limits under the PDPA sufficiently safeguard the further use of an individual's personal data. If the organisation does not adhere to these requirements, the Personal Data Protection Commission (PDPC) has the power to direct the organisation to destroy, or stop collecting, using or disclosing, the personal data concerned.