0% found this document useful (0 votes)
2 views2 pages

Data Protection Management

The document outlines the Technical Skills and Competencies (TSC) for Data Protection Management within the Governance and Compliance category. It details the proficiency levels required to develop and implement a Data Protection Management Programme in compliance with the Personal Data Protection Act 2012. Key areas include knowledge of personal data, abilities to manage data protection processes, and the responsibilities of data protection roles within an organization.

Uploaded by

Apisit Saetang
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views2 pages

Data Protection Management

The document outlines the Technical Skills and Competencies (TSC) for Data Protection Management within the Governance and Compliance category. It details the proficiency levels required to develop and implement a Data Protection Management Programme in compliance with the Personal Data Protection Act 2012. Key areas include knowledge of personal data, abilities to manage data protection processes, and the responsibilities of data protection roles within an organization.

Uploaded by

Apisit Saetang
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

SKILLS FRAMEWORK FOR INFOCOMM TECHNOLOGY

TECHNICAL SKILLS & COMPETENCIES (TSC) REFERENCE DOCUMENT

TSC Category Governance and Compliance

TSC Title Data Protection Management

TSC Description Develop and implement a Data Protection Management Programme to comply with the Personal Data Protection Act 2012

Level 1 Level 2 Level 3 Level 4 Level 5 Level 6


TSC Proficiency
Description ICT-CGP-3020-1.1 ICT-CGP-4020-1.1 ICT-CGP-5020-1.1
Collect, use or disclose Develop the organisation’s Formulate the organisation’s
personal data in accordance Data Protection data protection strategy and
with the organisation’s Data Management Programme ensure effectiveness of Data
Protection Management (DPMP) in accordance with Protection Management
Programme (DPMP) legal requirements Programme (DPMP)
Knowledge • Definition of personal • Components of a DPMP • Data Protection by
data • Data lifecycle Design (DPbD)
• Organisation’s • Personal Data Protection approach
processes, procedures Act 2012 (PDPA) • Data Protection Impact
and guidelines of DPMP • DPMP and its Assessment (DPIA)
• Personal Data Protection relationship to the data • Best practices in data
Act 2012 (PDPA) lifecycle protection
• PDPA and the data • Dynamic and iterative • Principles in data
lifecycle consent approaches to protection policy
• Obligations under the comply with the consent • Personal Data Protection
PDPA requirement under Act 2012 (PDPA)
• Accountability under the PDPA
PDPA • Circumstances that may
• Best practices in allow for exemptions
operationalising PDPA from all or any of the
PDPA provisions
• Methods to document
personal data flows
• PDPA Assessment Tool
for Organisations
(PATO)
Abilities • Obtain consent to • Document the flows of • Review the
collect, use or disclose personal data within the organisation’s DPMP to
individuals’ personal organisation determine gaps and
data • Create content registry areas for improvement
• Allow individuals to to record consent • Formulate the
withdraw consent provided by individuals organisation’s regional
• Collect, use or disclose to the organisation DPMP
personal data only for • Conduct a DPIA to
identify, assess and

©SkillsFuture Singapore and Infocomm Media Development Authority


Effective Date: January 2020, Version 1.1 Page 1 of 2
SKILLS FRAMEWORK FOR INFOCOMM TECHNOLOGY
TECHNICAL SKILLS & COMPETENCIES (TSC) REFERENCE DOCUMENT

the purpose for which • Identify key gaps and address personal data
consent was obtained areas for improvement in protection risks based on
• Notify individuals of the data protection the organisation’s
purposes for the • Develop processes to functions, needs and
collection, use or handle data breach processes
disclosure of their incidents • Assess if the handling of
personal data • Publish information on personal data complies
• Correct errors or the organisation’s data with the PDPA or data
omissions in individuals’ protection policies, protection best practices
personal data upon practices and compliant- • Introduce technical or
request handling process organisational measures
• Ensure accuracy and • Determine the to safeguard against
completeness in the circumstances under data protection risks to
collection of personal which organisations individuals
data must seek fresh consent • Designate regional data
• Cease retention or for the use of personal protection roles and
anonymise personal data responsibilities within the
data when it is no longer • Designate data organisation
necessary for business protection roles and
or legal purposes responsibilities within the
organisation
• Adopt innovative
processes and methods
to comply with PDPA
requirements
• Submit reports of data
protection measures to
senior management
For Data Protection-related programmes, please refer “Guide to Develop Training Courses for Data Protection Officer (DPO)”, Personal Data Protection Commission (PDPC),
Range of Application
[Link] [March 2020]

©SkillsFuture Singapore and Infocomm Media Development Authority


Effective Date: January 2020, Version 1.1 Page 2 of 2

You might also like