Personal Data Protection Policy

1. Introduction 

The College of Allied Educators Singapore (CAE) is committed to protecting personal data in accordance with the Personal Data Protection Act 2012 (PDPA). This policy sets out CAE’s internal standards and procedures for managing personal data to ensure lawful, fair, and transparent processing. All CAE employees, contractors, and agents are expected to adhere to these standards. 

2. Scope 

This policy applies to all personal data collected, used, and stored by CAE, whether through electronic or manual means. It covers all individuals associated with CAE, including students, staff, and other stakeholders. 

3. Principles for Personal Data Protection 

CAE is committed to processing personal data in a manner that adheres to the following principles: 

  1. Lawfulness, Fairness, and Transparency: Personal data is collected and processed lawfully, fairly, and transparently. Individuals are informed of the purposes for which their data is collected and how it will be used. 
  1. Purpose Limitation: Data is collected for specific, explicit, and legitimate purposes. It will not be further processed in a manner incompatible with those purposes. 
  1. Data Minimization: Personal data collected is adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed. 
  1. Accuracy: CAE ensures that personal data is accurate and kept up to date. Inaccurate data will be rectified or erased without delay. 
  1. Storage Limitation: Personal data is retained only for as long as necessary for the purposes for which it was collected, or as required by applicable laws. 
  1. Integrity and Confidentiality: Personal data is processed securely, protected against unauthorized or unlawful processing, accidental loss, destruction, or damage. 
  1. Accountability: CAE is responsible for complying with these principles and will maintain documentation to demonstrate compliance. 

4. Data Collection and Use 

  1. Personal data is collected through various channels, including application forms, online submissions, email, and other direct communications. 
  1. Data collected may include contact information, identification details, academic records, and any other relevant information needed to provide educational services, process applications, or meet regulatory requirements. 
  1. CAE ensures that individuals are informed of the purposes for which their data is collected and that they provide consent where necessary. 

5. Consent Management 

  1. Obtaining Consent: CAE obtains consent from individuals before collecting, using, or disclosing personal data, unless an exception under the PDPA applies. 
  1. Withdrawal of Consent: Individuals may withdraw their consent at any time by notifying CAE in writing. CAE will inform the individual of the consequences of the withdrawal, which may include the inability to continue providing certain services. 
  1. Opt-Out Mechanisms: All marketing communications will include a clear and straightforward way for individuals to opt out of future communications. 

6. Data Security Measures 

CAE employs the following measures to ensure the security and confidentiality of personal data: 

  1. Access Controls: Access to personal data is restricted to authorized personnel who need it to perform their duties. 
  1. Data Encryption: Sensitive data is encrypted during transmission and storage to protect against unauthorized access. 
  1. Regular Audits and Risk Assessments: Periodic reviews and assessments are conducted to identify potential data protection risks and to ensure the effectiveness of security measures. 
  1. Incident Management: In the event of a data breach, CAE will take prompt steps to contain the breach, assess its impact, notify affected individuals where necessary, and take remedial actions to prevent future incidents. 

7. Data Retention Policy 

  1. Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. 
  1. Data that is no longer needed is securely destroyed or anonymized. 

8. Data Accuracy and Updates 

  1. CAE takes steps to ensure that the personal data it holds is accurate and up to date. 
  1. Individuals are encouraged to notify CAE of any changes to their personal data to maintain data accuracy. 

9. Disclosure of Personal Data 

  1. Personal data will not be disclosed to third parties without the individual’s consent, except as required by law or to authorized service providers for the purpose of fulfilling CAE’s operational needs. 
  1. All third parties handling personal data on behalf of CAE are required to comply with the standards set out in this policy. 

10. Staff Training and Awareness 

  1. Regular training is provided to CAE staff to ensure they understand the requirements of the PDPA and the importance of data protection. 
  1. Staff members are required to adhere to this policy and to report any suspected data breaches to the Data Protection Officer immediately. 

11. Data Protection Officer 

The Data Protection Officer (DPO) is responsible for overseeing compliance with this policy, advising on data protection matters, and handling any data protection queries or complaints. 

Contact Information for Data Protection Officer 

Shahdan Sulaiman
Email: shahdan@icae.edu.sg 
Phone: 6533-0031 

12. Policy Review 

This policy is reviewed once every two years or when there are changes in the applicable data protection laws or CAE’s data processing practices. 

Version 1.0