PDPA Policy & Practices
PDPA Policy & Practices
ASSYAKIRIN MOSQUE MANAGEMENT BOARD
PERSONAL DATA PROTECTION POLICY
- The Assyakirin Mosque Management Board (“Assyakirin Mosque”) takes our responsibilities under the Personal Data Protection Act 2012 (PDPA) seriously. We also recognise the importance of the personal data our stakeholders have entrusted to us and believe that it is our responsibility to properly manage, protect and process these personal data. Assyakirin Mosque is therefore committed to comply with the Personal Data Protection Act (the “PDPA”).
2. This document contains the Policy and Practices (“P&Ps”) adopted by Assyakirin Mosque in the collection, use, disclosure and update of personal data that is in its possession or will come into its possession.
B. Data Protection Officer
- Assyakirin Mosque is to appoint a Data Protection Officer (“DPO”) who will be responsible for ensuring mosque’s compliance and implementation of PDPA.
C. Collection of Personal Data
- Assyakirin Mosque is to only collect personal data that are reasonably necessary to fulfil the purposes for which the personal data are collected. See Annex A list the information that we collect from you, where we collect these information and how we use and disclose your personal information.
- Personal data collected before 2 July 2014 (the “Appointed Day”)
a. Assyakirin Mosque is not required to obtain consent for the collection of personal data before the Appointed Day.
b. If an individual does not want Assyakirin Mosque to retain his or her personal data collected before the Appointed Day, the individual must give reasonable notice to Assyakirin Mosque to withdraw his or her consent to Assyakirin Mosque’s retention of that personal data.
6. Personal data collected after the Appointed Day
a. After the Appointed Day, Assyakirin Mosque is to obtain the consent of an individual before collecting personal data about that individual. This includes the collection of additional personal data about an individual whom Assyakirin Mosque has collected personal data before the Appointed Day.
D. Use of Personal Data
- Assyakirin Mosque may use personal data collected before the Appointed Day for the purposes for which the personal data was collected, whether such use occurs before or after the Appointed Day.
- Assyakirin Mosque is to obtain consent to use personal data that has been collected after the Appointed Day.
- Where an individual withdraws his or her consent of this Policy, Assyakirin Mosque must cease to use that individual’s personal data within a reasonable time, whether that personal data was collected before or after the Appointed Day.
E. Disclosure of Personal Data
- Assyakirin Mosque may disclose personal data collected for the purposes for which that personal data was collected
- Assyakirin Mosque is to obtain consent to disclose personal data that has been collected after the Appointed Day.
- Where an individual withdraws his or her consent, Assyakirin Mosque must cease to disclose that individual’s personal data.
F. Consent of Individuals Below 18 Years Old
- In respect for individuals who have not attained the age of 18 years, Assyakirin Mosque is to obtain the consent of a parent or guardian of the individual before collecting, using or disclosing personal data about that individual.
G. Protecting and Storing of Personal Data
- Assyakirin Mosque is to protect personal data in its possession or control by making reasonable arrangements to prevent unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks related to personal data in its possession or control.
- Assyakirin Mosque may implement protection measures, as follows:
a. physical measures such as locked filing cabinets and restriction of access to offices;
b. restriction of personnel access to personal data, for example, security clearance and limiting of access to a “need-to-know” basis; and
c. technological measures such as the password protection and encryption of information stored in an electronic medium. There should be IT policy of changing passwords twice a year.
- Where necessary, more sensitive personal data are to be under a higher standard of protection.
- Assyakirin Mosque is to ensure that all employees and volunteers are aware of the importance of protecting the confidentiality of personal data.
- Assyakirin Mosque is to ensure that care is taken when personal data are to be disposed of or destroyed to prevent unauthorised parties from gaining access to that personal data.
H. Retention of Personal Data
- Assyakirin Mosque is to ensure that any personal data that are no longer serving the purpose(s) for which they are collected, or that are no longer necessary to be retained for any legal or business purpose, are removed or made anonymous.
I. Withdrawal of Consent and Making a Complaint
- An individual may withdraw his or her consent to the collection, use or disclosure of his or her personal data by giving reasonable notice to Assyakirin Mosque to do so.
- An individual who wishes to make a request, or to lodge a complaint to Assyakirin Mosque pertaining to any failure to comply with the provisions of the PDPA, may lodge the request / complaint to the DPO using the mosque office account at DPO@assyakirin.mosque.org.sg or submitting a letter of request / complaint to the DPO of Assyakirin Mosque.
- The DPO is to investigate the complaint within a reasonable time and contact the complainant within a reasonable time, in order to address any concerns relating to compliance with the PDPA.
J. Availability and Review of P&P
- The document shall be made available upon request. This document may be found at Assyakirin Mosque’s website www.assyakirin.sg or at Assyakirin Mosque Office located at 550 Yung An Road, Singapore 618617.
- The Assyakirin Mosque Management Board will, from time to time, monitor, review and amend this document in its absolute discretion where it deems necessary or appropriate in accordance with the PDPA.
Updated April 2015
- What is Personal Data
Personal Data is any information about you that you have provided to us including but not limited to the following:
□ Identity Card / Birth Certificate / Passport Details
□ Contact details (including telephone number and email address)
□ Residential address
□ Date of birth
□ Marital Status
□ Education Background
□ Name of school currently attending (students only)
□ Parent’s name and particulars (for those below age of 18)
□ Photographs, audio / video recordings
□ Feedback and response to survey / evaluation form
- Where we collect your personal information
2.1 Mosque Membership Database
In order for us to keep a record and update our membership database, we may from time to time contact you to update your personal information. This information is also used to communicate with you, respond to your enquiries or feedback, provide you with information and/or updates on the Mosque.
2.2 Mosque Events, Seminars, Training and Camps / Talks
Assyakirin Mosque holds events such as Camps, Seminars, and religious talks on a regular basis. Participants will be asked to register for the event and information such as national registration identity card (NRIC) number, foreign identification number (FIN), passport number, name, postal address, email address and telephone number, marital status, profession, age may be collected only for use by the event organisers to follow up with you and update you promptly as well as to inform you of future events that may interest you.
2.3 Information collected on website
We may collect information such as your name, email address, telephone number when you fill up our online “Contact Us” form, so that we could respond to your enquiries promptly.
2.4 Photographs and audio / video recordings
Through your participation and involvement in our Mosque events, your photographs and audio / video recordings may be collected.
- How we use and disclose your personal information
Once you have given us your personal information, you are not anonymous to us. We may use your personal information to contact you for our Mosque events, courses, seminars, workshops from time to time. This may include mail, email and text messages. We are committed to send you only text messages or emails that pertain to courses, seminars, workshops and events which you have signed up with us.
Photographs and audio / video recordings during our Mosque events may be used for our publicity and promotion purposes such as printed newsletter, brochures, flyers, posters, banners, calendars, electronic publications, websites and social media platforms.
We may also disclose your personal information to third party agencies such as insurance companies and travel agencies for travel insurance and hotel bookings where applicable. Access to your personal information will only be provided to them for the purpose of performing our services. We will require them to ensure that the personal information disclosed to them is kept confidential and secured.
If you do not wish to receive information or updates from the Mosque, you may opt out anytime by calling our office at 62681846 or email us at DPO@assyakirin.mosque.org.sg to inform us to be unsubscribed from our mailing list / database.