Data Compliance and Regulations (PDPA, GDPR)

Context: FIT1043_MOC · the legal side of governance · enforces confidentiality · the “legal objective” that conflicts with business value

Quick Revision

  • 🎯 Objective: meet the laws protecting personal data âž” ethics (moral handling) enforced via compliance with regulations.
  • 📦 Core Components: PCI (payment cards) | PDPA (9 obligations) | GDPR (stricter EU law).
  • ⚡ Key Constraint: GDPR is stricter than PDPA — 72-hour breach notification and penalties up to 4% of global turnover / €20M.

📝 How It Works

1. Ethics & Compliance

  • Ethics âž” the moral handling of data.
  • Compliance âž” the process of ensuring you meet regulations (which exist to protect confidentiality).
  • PCI (Payment Card Industry) âž” reduces credit-card fraud, e.g. card data stored only encrypted; handlers must comply; audited annually.

2. PDPA — Nine Obligations

  • Consent âž” needed before personal data is collected/used/disclosed.
  • Purpose limitation âž” inform of purpose; don’t use data beyond it.
  • Notification âž” notify individuals of the purpose before consent.
  • Access & correction âž” individuals may access and correct their data.
  • Accuracy âž” reasonable effort to keep data accurate/complete.
  • Protection âž” reasonable security against unauthorised access/use/disclosure/modification/disposal.
  • Retention limitation âž” keep data only for a period, then delete permanently.
  • Transfer limitation âž” no cross-border transfer unless the recipient country has comparable protection.
  • Do Not Call Registry âž” registered numbers may not receive unsolicited marketing.

3. PDPA vs GDPR

  • GDPR âž” EU regulation (approved 2016, effect 25 May 2018); stricter consent rules.
  • Breach notification âž” notify authorities/affected parties within 72 hours of awareness.
  • Penalties âž” up to 4% of annual global turnover or €20 million (whichever is greater).

4. Australia (OAIC)

  • Privacy Act 1988 âž” Australia’s core privacy law; the OAIC (Office of the Australian Information Commissioner) issues guidance on the “reasonable steps” entities must take to secure personal information.
  • Notifiable Data Breaches (NDB) Act 2017 âž” requires eligible data breaches to be notified to the OAIC and affected individuals — Australia’s counterpart to GDPR’s breach-notification duty.
  • (Applied session lab: 30_Projects/FIT1043_Labs/Week11-NoSQL-Privacy.pdf.)

⚖️ Core Decision Matrix

AspectPDPAGDPR (EU)
Consentrequiredstricter/explicit
Breach notice—within 72 hours
Penalty—up to 4% global turnover / €20M
Scopenational (e.g. Malaysia/SG)EU-wide, extraterritorial

When It Flips: compliance is where the legal objective collides with the business objective — regulations (PDPA/GDPR) constrain how freely a business can collect/use/transfer data to extract value, which governance must balance.

đź§  Active Recall