singapore american school



Similar documents
Data Protection Consent Clause and Policy Background

DATA PROTECTION POLICY

Clause 1. Definitions and Interpretation

BRITISH COUNCIL DATA PROTECTION CODE FOR PARTNERS AND SUPPLIERS

Policy and Procedure Title: Maintaining Secure Learner Records Policy No: CCTP1001 Version: 1.0

Last updated: 30 May Credit Suisse Privacy Policy

ANGUS COUNCIL SUPPLEMENTARY CONDITIONS OF CONTRACT. SC 01 - Contract Performance Guarantee Insurance

Protection. Code of Practice. of Personal Data RPC001147_EN_D_19

Credit Reporting Privacy Policy of Baybrick Pty Ltd

APPENDIX I: STANDARD FORM BUSINESS ASSOCIATE CONTRACT AND DATA USE AGREEMENT (2012 Version)

ATMD Bird & Bird. Singapore Personal Data Protection Policy

Firm Registration Form

Summary of Data Protection Requirements When transferring Data Outside the UK End Users

How To Protect Your Data In European Law

Terms and Conditions for Online Services of BOC Credit Card (International) Limited

BOC Credit Card (International) Limited - Terms and Conditions for Online Services

Processor Binding Corporate Rules (BCRs), for intra-group transfers of personal data to non EEA countries

UGANDA REVENUE AUTHORITY TERMS AND CONDITIONS FOR WEB PORTAL USE

5. PRIVACY MFC shall take all reasonable steps to protect the personal information of Users. See our privacy policy below for more information.

PRESIDENT S DECISION No. 40. of 27 August Regarding Data Protection at the European University Institute. (EUI Data Protection Policy)

DATA PROTECTION POLICY

Data Protection. Processing and Transfer of Personal Data in Kvaerner. Binding Corporate Rules Public Document

AlixPartners, LLP. General Data Protection Statement

SAMPLE RETURN POLICY

Protection. Code of Practice. of Personal Data RPC001147_EN_WB_L_1

Recommendations for companies planning to use Cloud computing services

WEBSITE & SOCIAL MEDIA PRIVACY POLICY

Personal Data Act (1998:204);

1.3 By requesting us to register or manage a domain names or names on your behalf, you agree to:

Terms and Conditions of Website Hosting

Terms of Use & Privacy Policy

Data Protection Act a more detailed guide

Privacy Policy and Terms of Use

Policy and Procedure for approving, monitoring and reviewing personal data processing agreements

Software Support and Maintenance Terms

OBJECTS AND REASONS. (a) the regulation of the collection, keeping, processing, use or dissemination of personal data;

Guidelines on Data Protection. Draft. Version 3.1. Published by

DATA PROTECTION POLICY. Examples of personal data which TWM may require from clients include the following and for the reasons ascribed to each;

Corporate ICT & Data Management. Data Protection Policy

NBB INTERNET BANKING TERMS AND CONDITIONS

Article 29 Working Party Issues Opinion on Cloud Computing

Data protection issues on an EU outsourcing

Data Protection Policy

This Amendment consists of two parts. This is part 1 of 2 and must be accompanied by and signed with part 2 of 2 (Annex 1) to be valid.

Terms and Conditions For Online-Payments

Cloud Hosting Terms and Conditions

Appendix 11 - Swiss Data Protection Act

Data Protection in Ireland

APPENDIX I: STANDARD FORM BUSINESS ASSOCIATE CONTRACT AND DATA USE AGREEMENT

AASA Online Privacy Policy CRP.020

DATA PROTECTION POLICY

PRIVACY POLICY. Privacy Statement

GENERAL ELECTRIC COMPANY EMPLOYMENT DATA PROTECTION STANDARDS

Privacy Policy Draft

ELECTRONIC TRADING FACILITIES SUPPLEMENTAL TERMS AND CONDITIONS OF TRADING

MONMOUTHSHIRE COUNTY COUNCIL DATA PROTECTION POLICY

Data Protection Policy.

any Service that involves gambling, betting, adult, sex or over 18 services or information;

BUSINESS ASSOCIATE AGREEMENT

GENOA, a QoL HEALTHCARE COMPANY GENOA ONLINE SYSTEM TERMS OF USE

DIFC LAW NO. 1 OF 2007

Covered California. Terms and Conditions of Use

General Terms and Conditions for the Purchase and Maintenance of Hardware

07/2013. Specific Terms and Conditions Mobile Device Management

Corporate Policy. Data Protection for Data of Customers & Partners.

The supplier shall have appropriate policies and procedures in place to ensure compliance with

SAFEGUARDING CHILDREN AND CHILD PROTECTION POLICY

TERM OF THE AGREEMENT

Trading Terms 1. Payment 2. Orders 3. Freight/Postage (GST Applicable) 4. Pricing Policy (GST Applicable) 5. Invoice Format

STOCK FOOTAGE LICENSE AGREEMENT. License Agreement Number:

Data Protection Policy

Data Protection Policy June 2014

MYACCLAIM PRIVACY POLICY

Terms and Conditions For Online-Payments

Internet Banking Agreement and Disclosure

BUSINESS ASSOCIATE AGREEMENT

Terms and Conditions of Use and Sale as at 1 st January 2009

BUSINESS ASSOCIATE AGREEMENT ( BAA )

Data Compliance. And. Your Obligations

USER AGREEMENT FOR: ELECTRONIC DEALINGS THROUGH THE CUSTOMS CONNECT FACILITY

Without prejudice to the generality of the foregoing paragraph, The Gallery Tattoo Studio does not warrant that:

HIPAA BUSINESS ASSOCIATE AGREEMENT

Binding Corporate Rules ( BCR ) Summary of Third Party Rights

ROEHAMPTON UNIVERSITY DATA PROTECTION POLICY

Business Online Bill Pay Terms and Conditions

Transcription:

Background The Singapore Personal Data Protection Act - 2012 (PDPA) establishes a data protection law that comprises various rules governing the collection, use, disclosure, and care of personal data. It recognizes both the rights of individuals to protect their personal data, including rights of access and correction, and the needs of organizations to collect, use, or disclose personal data for legitimate and reasonable purposes. The PDPA takes into account the following concepts: Consent Organizations may collect, use, or disclose personal data only with the individual s knowledge and consent (with some exceptions); Purpose Organizations may collect, use, or disclose personal data in an appropriate manner for the circumstances, and only if they have informed the individual of purposes for the collection, use, or disclosure; and Reasonableness Organizations may collect, use, or disclose personal data only for purposes that would be considered appropriate to a reasonable person in the given circumstances. Consent For the purposes of school students under the age of 13, it is reasonable and accepted that parental consent is sufficient. In addition to parents, we will also obtain explicit permission from staff in order to use their data as an employer. Parental Consent Clause The school will collect and use personal data about you and your child in accordance with the Singapore Personal Data Protection Act (2012.) You consent to us using such personal data as set out in the school s Data Protection Policy which is available on the school s website and may be amended from time to time and where otherwise reasonably necessary for the school to provide appropriate services. Staff Consent Clause The school will collect and use personal data about you in accordance with the Singapore Personal Data Protection Act (2012.) You consent to us using such personal data as set out in the school s Data Protection Policy which is available on the school s website and may be amended from time to time and where otherwise reasonably necessary for the school to provide you employment. Staff who have children enrolled at the school must provide permission twice, once for themselves as an employee and once as a parent. Implied Consent Where a person has made a free decision to opt in to a process or situation where the collection or use of personal data can be reasonably expected, then implied permission can be assumed. This includes: Staff Online Applications (when applications are submitted) Student Online Applications (the admissions process prior to acceptance) Alumni Website Sign-up Events Campus - CCTV

Data Protection Policy The school collects and uses personal data about staff, students, and families in accordance with the Singapore Personal Data Protection Act - 2012 (PDPA) and other relevant laws and requirements on private education institutions in Singapore. Data Collected and Purpose The school holds personal data on its students, including: contact details, assessment/examination results, attendance information, behaviour, and characteristics such as ethnic group, special educational needs, any relevant medical information, photographs, and/or video footage. The data is used in order to support the education of the students, to monitor and report on their progress, to provide appropriate personal and social care, and to assess the performance of the school as a whole, together with any other uses normally associated with this provision in an independent school environment. The school may make use of limited personal data (such as contact details) relating to students, their parents, or guardians for fundraising, marketing, or promotional purposes and to maintain relationships with students of the school. Data is shared as necessary with third party companies to provide extended services; examples include transport, medical, catering, travel services, and online services such as email. In particular, the school may: a. Make available information to any internal organization or society set up for the purpose of maintaining contact with students or for administration, fundraising, marketing, or promotional purposes relating to the school, e.g. alumni. The school will remain as the data controller and this policy will govern data usage. b. Make use of photographs, videos, and/or sound recordings of students in school publications, the school website, school social media channels, and other official school communication channels. Photographs, videos, and/or sound recordings of students will not be used in publicity campaigns placed with external media outlets without the express permission of the relevant family. d. Make personal data, including sensitive personal data, available to staff for planning activities and trips, both in and outside of Singapore. e. Retain and use personal data after a student has graduated to provide references, educational history, and alumni services consistent with an independent school environment. Data Security The school undertakes to: a. Implement appropriate security measures to protect personal data against accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure, or access, in particular when the processing of data involves the transmission or storage on or within a network. b. That it shall notify data subjects about any accidental or unauthorised access of their data that may lead to damage or harm. Data Retention & Removal The school undertakes that it shall only keep the data collected as long as is necessary to provide the services outlined above.

Right of Access and Correction Families have a right to see the data held about them (subject to the exemptions listed below) and to request for data to be corrected if it is incorrect. Families can access the majority of personal data held about them via the school s online Information Management System. To request data or for data to be changed that you do not have edit rights to, please contact data@sas.edu.sg. The school will consider the request and respond within three working days. The response may be to decline the request with reasons or to provide a time scale in which the data will be supplied. Exemptions to Right of Access The PDPA does not provide the right of access to any and all information held by an organization. Therefore the school retains the right to refuse access to: Opinion data kept for evaluative purposes Examination papers or the results of examinations Confidential references written to support a student s application to other educational institutions or courses Data or material that provides personal data about other individuals in contravention of this policy or the PDPA Sharing Data with Third Parties The school shares personal data with a variety of third parties for the purposes of the third party providing a relevant service to the institution. Examples of these services include transport, catering, travel services, accommodation, and medical. The school will only share data for the purposes of eliciting a necessary service from these third party organizations and not for commercial gain. Where the school signs explicit contracts with these organizations it will include clauses from Appendix A - Contracts with Third Parties to ensure that the organization is using the data purely for the intended purpose of providing the required service and that it is taking appropriate precautions to safeguard the data. In some instances, for example for online services provided by companies outside of Singapore, explicit signed contracts do not exist. In these instances the school will ensure that the terms and conditions of the service include clauses that: The school remains the owner of the data. The service provider is not entitled to use any data held on its service for any purpose other than to provide the required service. The service provider is taking reasonable precautions to ensure the security of the data. Once the school terminates its agreement with the service provider, that any and all data held will be deleted and not used for any other purpose.

Appendix A - Contracts with Third Parties When signing contracts with any third party organizations that the school will share personal data with the contract should include the following clauses or entries to the same effect. The school collects and uses personal data about staff, students, and families in accordance with the Singapore Data Protection Act (2012) and other relevant laws and requirements on private education institutions in Singapore. As a result of the provision of your obligations under this agreement, you may have access to personal data about the school s employees, students, parents, and/or other contacts. You must (and must ensure that your employees, agents, sub-contractors, and representatives will) keep all such data secure and protected against improper disclosure or use as detailed in this agreement. Definitions: a. Personal data shall refer to data, whether true or not, about an individual who can be identified from that data; or from that data and other information to which the organization has or is likely to have access and all other data deemed protected under the Personal Data Protection Act 2012 b. PDPA shall mean the personal Data Protection Act (2012) c. The school shall mean the entity who transfers the data to be used d. The company shall mean the processor who agrees to accept the school s personal data intended for processing and use in accordance with this agreement 1.Data Use a. That any personal data shared by the school or collected by the company as a result of providing the services covered in this agreement will be used solely for the purposes of providing the service detailed in this agreement b. That no personal data collected or shared will be used to offer or solicit further services from the individuals concerned c. To process the personal data only on behalf of the school and in compliance with its instructions d. That the processing, including the transfer itself, of the personal data has been and will continue to be carried out in accordance with the relevant provisions of the applicable data protection law and do not violate the relevant laws of the Republic of Singapore in which the school resides e. That it shall promptly notify the school about any request for disclosure received directly from any authority or individual. 2. Data Security a. To implement appropriate security measures to protect personal data against accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure, or access, in particular when the processing of data involves the transmission or storage on or within a network b. That it shall promptly notify the school about any accidental or unauthorised access of the data, or any loss of the data whether leading to unauthorised access or not.

3. Data Retention - Obligations After the Termination of Contract or Services a. That on the termination of the contract or services that required data processing services, that the company shall at the request of the school transfer all the data transferred and copies thereof to the data exporter or shall destroy all the personal data and certify that he has done so, unless legislation imposed on the data importer prevents him from returning or destroying all or part of the data transferred. In that case the company warrants that he will guarantee the confidentiality of the personal data and will not actively process the personal data transferred anymore. Once the legal requirement for retention has passed the company warrants that it will destroy all data retained. 4. Data Correctness and Right of Correction a. To provide the school on request all the personal details of individuals that have been collected as the result of this agreement and to amend or delete such data on request within the lifetime of the agreement. 5. Liability a. The parties agree that if one party is held liable for a violation of the clauses committed by the other party in contravention of the PDPA, the latter will, to the extent he is liable, indemnify the first party from any cost, charge, damages, expenses, or losses it has incurred.