Access and Correction Obligation
Upon request, organisations have to provide individuals with access to their personal data as well as information about how the data was used or disclosed within a year before the request.
Organisations are also required to correct any error or omission in an individual’s personal data as soon as practicable and send the corrected data to other organisations to which the personal data was disclosed (or to selected organisations that the individual has consented to), within a year before the correction is made.

Data Breach Notification Obligation
In the event of a data breach, organisations must take steps to assess if it is notifiable. If the data breach likely results in significant harm to individuals, and/or are of significant scale, organisations are required to notify the PDPC and the affected individuals as soon as practicable.