Employment |

Collection of Personal Data by Employer: Does It Infringe the PDPA?


Under Singapore’s Personal Data Protection Act, employers generally do not need an employee’s consent to collect, use or disclose personal data, provided it is for purposes related to managing the employment relationship.

That said, this is not a blanket exemption. Employers who go beyond what is reasonably needed for employment purposes, or who mishandle sensitive identifiers like NRIC numbers, can still fall foul of the Act. This guide sets out exactly where the line sits, and what HR teams and employees should each know.

Collection of Personal Data by Employer

The starting point under the PDPA is that an organisation must obtain an individual’s consent before collecting, using or disclosing their personal data. In the employment context, however, the Act carves out specific situations where an employer can process employee data without going through consent each time.

This guide covers:

  • The general consent rule and when it applies to employers
  • The two main exceptions employers rely on: evaluative purpose and managing or terminating the employment relationship
  • What employers must still do even when consent is not required
  • Special rules for NRIC numbers and other national identifiers
  • Employee monitoring, and what counts as reasonable
  • What happens if an employer mishandles or leaks personal data

Under the Personal Data Protection Act 2012, an organisation must not collect, use or disclose an individual’s personal data unless the individual has given consent, or an exception under the Act applies. Personal data covers any information that can identify someone, whether on its own or combined with other information the organisation holds, which includes a job applicant’s or employee’s name, contact details, NRIC number, and photographs.

Consent does not always need to be given explicitly. If a job applicant voluntarily submits their resume and personal details to apply for a role, they are generally treated as having deemed consent for the company to collect and use that data to assess the application. If they are subsequently hired, it is reasonable for the employer to continue using that same information to manage the new employment relationship.

Also Read: Wrongful Dismissal in Singapore Law: Employee and Employer Guide

Two exceptions do most of the work for employers in practice, and they are easy to confuse with each other.

infographic article about collection of personal data by employers
when employers can collect data without consent

Evaluative purpose exception

This exception covers collecting, using or disclosing personal data to determine someone’s suitability, eligibility, or qualifications for employment, promotion, or continued employment. It typically applies to things like:

  • Obtaining a reference from a candidate’s previous employer
  • Collecting performance records to decide on a promotion or bonus
  • Assessing qualifications or conduct during a probation period

Managing or terminating the employment relationship exception

This exception covers collection that is reasonable for administering an existing employment relationship, rather than evaluating the person. Common examples include:

  • Using an employee’s bank account details to pay salaries
  • Monitoring how an employee uses company computer network resources
  • Posting an employee’s photograph on the internal staff directory
  • Managing staff benefit schemes, such as training subsidies or insurance

If an employer wants to use personal data for a purpose that falls outside both exceptions, for example, using an employee’s personal social media activity outside work, it generally needs to go back to obtaining proper consent.

Relying on an exception does not remove every obligation. Employers must still inform employees, on or before collecting the data, of the purpose for which it is being collected, used, or disclosed for managing or terminating the employment relationship.

In practice, this is usually done through the employment contract, an employee handbook, or a dedicated data protection policy, rather than a separate consent form for each purpose.

Collecting NRIC and Other National Identification Numbers

NRIC numbers get separate, stricter treatment. The PDPC’s advisory guidelines on NRIC and other national identification numbers generally prohibit organisations from collecting, using, disclosing, or physically retaining NRICs and copies of NRICs, unless the collection is required by law or another PDPA exception applies, or the employer needs to verify the individual’s identity to a high degree of accuracy, with consent obtained after notice.

For employers, onboarding a new hire is typically one of the situations where NRIC collection is legally required, since it is needed to maintain statutory employment records under the Employment Act. Outside of that, employers should avoid defaulting to NRIC as a general-purpose identifier and should stop holding a former employee’s NRIC once it is no longer needed for legal or business purposes.

Not every piece of employee data sits in the same category, and employers who assume everything is covered by the employment exceptions tend to run into trouble. The table below sets out how common categories are typically treated.

Data or ActivityTypical TreatmentBasis
Job application details, voluntarily submittedExempt from separate consentDeemed consent, evaluative purpose
Bank details for payrollExempt from separate consentManaging employment relationship
Performance records for promotion decisionsExempt from separate consentEvaluative purpose
Photo on internal staff directoryExempt, but must be notifiedManaging employment relationship
NRIC numberGenerally requires a legal basis, not a blanket exemptionNRIC Advisory Guidelines
Monitoring of personal social media outside workRequires consentNo employment exception applies

Employee Monitoring and What Counts as Reasonable

Monitoring how employees use company issued devices and network resources falls within the managing the employment relationship exception, but that does not make it unlimited. The PDPC expects monitoring to be proportionate to a legitimate business purpose, disclosed to employees in advance through a policy or contract clause, and used only for the purpose that was communicated.

Covert monitoring, or reusing monitoring data collected for security purposes to build a performance case against an employee without having disclosed that intention, sits in much riskier territory.

What Happens If an Employer Mishandles Employee Data

Employers that fail to protect the personal data they are entitled to hold can still be in breach of the PDPA. Under Section 26B, an organisation must notify the PDPC of a data breach that is assessed as notifiable, meaning it is likely to cause significant harm to affected individuals, or it involves 500 or more individuals regardless of harm. Notification must be made as soon as practicable, and in any event no later than three calendar days after the organisation completes its assessment.

Failing to notify a notifiable breach is a separate contravention from the breach itself, and the PDPC treats it as an aggravating factor. Financial penalties can reach up to S$1 million or 10% of the organisation’s annual turnover in Singapore, whichever is higher.

Also Read: Employment Disputes Singapore: Types, Process & How to Handle

Speak With an Employment Lawyer About Your PDPA Obligations

Getting the collection of personal data wrong, whether by over-collecting NRIC numbers, skipping the notification requirement, or mishandling a data breach, can expose a company to PDPC penalties well beyond what most HR teams expect.

The line between what is genuinely exempt and what still needs consent is not always obvious, especially once monitoring tools, third-party HR platforms, or cross-border data transfers enter the picture.

Ramesh Bharani Nagaratnam and the employment law team at RBN Chambers regularly advise companies on PDPA compliance in the workplace, from drafting compliant data protection clauses to responding to a live data breach. Contact us today if you need help reviewing how your company collects and handles employee data.

Frequently Asked Questions

Can my employer collect my NRIC number?

Only in specific situations, such as when you are onboarded as a new hire and the employer needs it for statutory employment records. Employers cannot collect or retain NRIC numbers as a general practice without a legal basis or applicable exception.

Do I need to consent to my employer using my photo on the staff directory?

Not separately. This typically falls under the exception for managing an employment relationship, though your employer should still inform you that this is one of the purposes for which your data is used.

Can my employer monitor my use of the company network without my consent?

Generally yes, provided the monitoring is reasonable, proportionate, and disclosed to you in advance, usually through your employment contract or an internal policy.

What happens if my employer’s data breach exposes my personal data?

If the breach is likely to cause significant harm, or affects 500 or more individuals, the employer must notify the PDPC within three calendar days of assessing it as notifiable, and generally must notify you as well.

Does an employer need my consent to check references from a previous employer?

No. This is typically covered under the evaluative purpose exception, which allows employers to assess a candidate’s or employee’s suitability for a role without needing separate consent for each check.

Employment disputes arise when the rights of employees are breached or contractual terms are not followed by either party. To avoid such disputes, it is essential to understand the laws governing employment in Singapore. The Employment Act is a good place to start.

Our lawyers were in a lift in the CBD the other day, precariously positioned in between 2 seemingly disgruntled ladies, when one of them suddenly blurted, “Wa lau! HR find out my new handphone number leh! I going to PDPA them ah!

Our lawyers considered playing good Samaritans and voicing their views, but good sense prevailed and we refrained from offering advice without monies into account.

We presume this is something of interest to many employees, so we shed some light on whether your employer can collect, use or disclose your personal data

In the Singapore Personal Data Protection Act 2012 (“the PDPA”), personal data is information about someone who can be identified from that information, such as their name, NRIC number, residential address, telephone number. The thrust of the PDPA is any request for personal data must be reasonable given the circumstances. Further, the PDPA has considerable impact, given that it applies to organisations (except public agencies) formed or having a place of business in Singapore or elsewhere.

After 2 July 2014, an organisation must not collect, use or disclose personal data without an individual’s consent. In obtaining consent, the organisation must inform the individual of the purpose of the use or disclosure of the personal data. If one voluntarily provides their personal data, it would be considered that consent has been given.

However, consent is not required in certain circumstances. For example, in an employment context, an employer does not need an employee’s consent to collect, use or disclose personal data provided it is for the purposes of the employment. In this circumstance, the personal data may be attained from the other sources apart from the individual himself / herself.

For further insight into the PDPA, please contact our lawyers.

Delivering Solutions not just Answers to your legal disputes

We provide solutions to all our clients regardless of the scale or complexity of the cases. Let us know how we can help.

Contact Us
Disclaimer:
Any information of a legal nature in this blog is given in good faith and has been derived from resources believed to be reliable and accurate. The author of the information contained herein this blog does not give any warranty or accept any responsibility arising in any way, including by reason of negligence for any errors or omissions herein. Readers should seek independent legal advice.