The Personal Data Protection Commission (“PDPC“) has issued the Advisory Guidelines on the PDPA for Children’s Personal Data in the Digital Environment (“Children’s Guidelines“), which aim to provide guidance and best practices to the industry on:
(a) How valid consent may be obtained from children (defined as individuals who are below 18 years of age);
(b) According higher protection standards to children’s personal data as sensitive data; and
(c) How children’s data/profiles may be used.
The Children’s Guidelines apply to organisations whose online products or services are likely to be accessed by children, such as social media services, technology-aided learning, online games, and smart toys or devices.
The Guidelines provide clarification on the following data protection obligations under the Personal Data Protection Act 2012 (“PDPA“) in the context of children’s personal data:
(a) Notification. Organisations should consider the nature of their content and adopt age-appropriate language and media.
(b) Consent. A child between 13 and 17 years of age may give valid consent, when the policies on the collection, use and disclosure of personal data are readily understandable by them. However, there may be instances where an organisation will consider a higher age of consent more appropriate in its business context. Where the child is below 13 years of age, the organisation must obtain consent from the parent or guardian.
(c) Reasonable purposes. The PDPC will adopt a principles-based approach to consider what is reasonable when collecting, using, or disclosing a child’s personal data.
(d) Protection of children’s personal data. The personal data of children is generally considered to be sensitive personal data and must be accorded a higher standard of protection under the PDPA.
(e) Notification of breach. The organisation should proactively inform the child’s parent or guardian of the data breach, or if the organisation does not have his/her contact details, it should ensure that the data breach notification to the child is in a language that is readily understandable by the child.
(f) Accountability. To meet the Accountability Obligation, organisations are advised to conduct Data Protection Impact Assessments to help them develop and implement appropriate policies and practices.
Click on the following link for more information:
- Advisory Guidelines on the PDPA for Children’s Personal Data in the Digital Environment (available on the PDPC website at www.pdpc.gov.sg)