Key Definitions
Jump to
Key Definitions Start Comparison
Personal data

Last review date: January 2025

"Personal data" is defined under the PDPA as "any information relating to a person, which enables the identification of such person, whether directly or indirectly, but not including the information of a deceased person in particular."

Sensitive/special personal data (including personal data subject to additional protections/ restrictions/breach notification obligations)

Last review date: January 2025

Sensitive data includes:

         personal data revealing racial or ethnic origin
         personal data revealing political opinions
         personal data revealing religious or philosophical belief
         personal data revealing trade / professional union or association membership
         genetic data
         biometric data for the purpose of uniquely identifying a natural person or biometric templates
         data concerning health/medical information
         data concerning a natural person's sex life or sexual orientation
         personal data regarding an individual's criminal record
         other

  • Any data which affects the data subject in a manner to be determined by the Personal Data Protection Committee
  • Disability
Controller vs Processor

Last review date: January 2025

Do the privacy laws distinguish between controllers/owners and processors/agents? Whereby:

  • the controller/owner is a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data
  • the processor/agent is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller

Yes.