PDPA
What is PDPA?
Personal Data Protection Act, data protection legislation enacted by various countries (such as Singapore and Thailand) to regulate the collection and use of personal data.
Terms that appear alongside pdpa
Each of these is named in at least one of the same controls as pdpa. The number is how many controls name both.
- gdpr 37 shared controls
- consent 36 shared controls
- data protection 34 shared controls
- data subject 21 shared controls
- compliance 16 shared controls
- breach notification 14 shared controls
- lawful basis 11 shared controls
- accountability 10 shared controls
Frameworks that govern pdpa
What the standards actually require on pdpa
Requirements naming pdpa across 6 standards, quoted from the control text.
Personal data collected prior to PDPA enforcement may continue to be processed for original purposes provided data subjects are notified of opt-out rights.
Section 25 · Historical and Pre-PDPA Data →Training + awareness + coordination operationalise UU PDP within Indonesia and across the regional + global regulatory landscape. Training and Awareness: mandatory cyber + privacy awareness training for all staff + role-specific training for IT + security + ex...
IDPdp-Training-Awareness-Coord-ASEAN-SingaporePDPA-APEC-CBPR-GDPR-Art70to76-MoCom-Transition · Indonesia PDP Training + Awareness + Indonesian Representative + Lembaga PDP Transition + Coordination ASEAN/Singapore PDPA/APEC CBPR/GDPR/India DPDP/Cross-Sectoral OJK/BI/BSSN →Provide and operate channels for data subjects to exercise statutory rights under Sections 30-43. Right of access (Section 30) within 21 days extendable + prescribed fee not exceeding RM10.
MY-PDPA-Data-Subject-Rights-Access-Correction-Portability-Withdraw-Consent-Prevent-Marketing-Sections-30-43 · Malaysia PDPA Subject Rights + Access + Correction + Portability + Withdraw Consent + Prevent Marketing + Sections 30 to 43 →Cooperate with Personal Data Protection Agency inspections, requests for information, and corrective orders within statutory timelines.
AM-DPA-17 · PDPA Inspections and Cooperation →Implement Incident Management + Business Continuity + Cloud Service Customer Data Protection per MTCS SS 584. Incident Management (ISO 27001 Annex A.16 + ISO 27035) - incident response plan + 24x7 SOC + Computer Security Incident Response Team (CSIRT) + incide...
MTCS-Incident-Business-Continuity-CSC-Data-Protection-72-Hour-Notification-BCP-DR-PDPA · MTCS Incident + Business Continuity + CSC Data Protection + 72-Hour Notification + BCP + DR + PDPA →Global CBPR Forum coordination with adjacent privacy regimes. EU GDPR + GDPR ADEQUACY: no formal EU adequacy decision recognizing CBPR + ongoing European Commission dialogue; some EU companies use CBPR as supplementary measure + accountability evidence;
CBPR-Coord-GDPR-UK-Japan-Korea-Singapore-Philippines-StateLaws · Global CBPR Forum: Coordination with GDPR + UK GDPR + Japan APPI + Korea PIPA + Singapore PDPA + Philippines DPA + US State Laws →Questions people ask about pdpa
What is PDPA?
Why is PDPA important for compliance?
Which compliance frameworks address PDPA?
Where can I learn more about PDPA?
See how PDPA applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.