Legal Compliance
Personal Data Protection Act (PDPA)
Our commitment to protecting your personal data in accordance with Singapore's Personal Data Protection Act.
Effective Date: January 1, 2024
PDPA Compliance Statement
One X Group Pte. Ltd. is committed to complying with Singapore's Personal Data Protection Act (PDPA) and protecting the personal data of our customers, employees, and business partners.
What is the PDPA?
The Personal Data Protection Act (PDPA) is Singapore's data protection law that governs the collection, use, disclosure, and care of personal data. It recognizes both the right of individuals to protect their personal data and the need of organizations to collect, use or disclose personal data for legitimate and reasonable purposes.
Our PDPA Obligations
Consent Obligation
We obtain your consent before collecting, using, or disclosing your personal data, except where permitted by law. We ensure that consent is:
- Informed - we clearly explain the purposes for collection, use, or disclosure
- Voluntary - given freely without coercion
- Specific - related to specific purposes
Purpose Limitation Obligation
We collect, use, and disclose personal data only for purposes that:
- A reasonable person would consider appropriate in the circumstances
- Have been notified to the individual
- The individual has consented to
Notification Obligation
We inform individuals about the purposes for which we collect, use, or disclose their personal data before or at the time of collection.
Access and Correction Obligation
We provide individuals with access to their personal data and allow them to correct any errors or omissions.
Accuracy Obligation
We make reasonable efforts to ensure that personal data is accurate and complete.
Protection Obligation
We implement appropriate security arrangements to protect personal data in our possession or under our control.
Retention Limitation Obligation
We cease to retain personal data when it is no longer necessary for business or legal purposes.
Transfer Limitation Obligation
We ensure adequate protection when transferring personal data outside Singapore.
Data Protection Officer (DPO)
We have appointed a Data Protection Officer to oversee our PDPA compliance:
Data Protection Officer
One X Group Pte. Ltd.
71 Robinson Road
Singapore 068895
Email: dpo@onexgroup.co
Your Rights Under PDPA
As an individual, you have the following rights under the PDPA:
Right to Access
You can request access to your personal data that we hold and information about how we have been using it.
Right to Correction
You can request correction of any errors or omissions in your personal data.
Right to Withdraw Consent
You can withdraw your consent for the collection, use, or disclosure of your personal data, subject to legal or contractual restrictions.
Right to Data Portability
You can request to receive your personal data in a commonly used and machine-readable format.
Making a PDPA Request
To exercise your rights under the PDPA, please contact our Data Protection Officer:
- Submit your request in writing to dpo@onexgroup.co
- Provide sufficient information to verify your identity
- Specify the type of request (access, correction, withdrawal of consent, etc.)
- Provide specific details about the personal data involved
Response Timeline
- Access Requests: We will respond within 30 days
- Correction Requests: We will respond within 30 days
- Data Breach Notifications: We will notify affected individuals without undue delay
- Complaints: We will acknowledge within 5 business days and investigate within 30 days
Data Breach Response
In the event of a data breach that is likely to result in significant harm, we will:
- Notify the Personal Data Protection Commission (PDPC) as soon as practicable
- Notify affected individuals without undue delay
- Take immediate steps to contain the breach
- Investigate the cause and implement remedial measures
Complaints
If you have concerns about how we handle your personal data, you can:
- Contact our Data Protection Officer at dpo@onexgroup.co
- File a complaint with the Personal Data Protection Commission (PDPC) at www.pdpc.gov.sg
Updates to PDPA Compliance
We regularly review and update our PDPA compliance measures to ensure continued protection of personal data and adherence to regulatory requirements.
This PDPA compliance statement should be read in conjunction with our Privacy Policy.