When personal data is provided to us, we have a professional and legal responsibility to protect it.
Accuracy Obligation
Make a reasonable effort to ensure that the personal data collected is accurate and complete, especially if it is likely to be used to make a decision that affects the individual or to be disclosed to another organisation.
Protection Obligation
Reasonable security arrangements have to be made to protect the personal data in your organisation’s possession to prevent unauthorised access, collection, use, disclosure or similar risks.

Retention Limitation Obligation
Cease retention of personal data or dispose of it in a proper manner when it is no longer needed for any business or legal purpose.
Transfer Limitation Obligation
Transfer personal data to another country only according to the requirements prescribed under the regulations, to ensure that the standard of protection is comparable to the protection under the PDPA, unless exempted by the PDPC.