Privacy Notice For Employees Template for Singapore

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Privacy Notice For Employees?

The Privacy Notice For Employees is a crucial compliance document required under Singapore's Personal Data Protection Act (PDPA). It serves as a comprehensive guide for employees regarding their personal data rights and the organization's data processing activities. This document becomes necessary when organizations collect, use, or disclose employee personal data, which includes but is not limited to employment records, performance evaluations, and contact information. The notice must align with PDPA requirements and should be regularly updated to reflect any changes in data handling practices or regulatory requirements.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Singapore

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Privacy Notice For Employees

A Privacy Notice For Employees is a legally required document under Singapore's Personal Data Protection Act 2012 (PDPA) that establishes transparency between employers and employees regarding personal data handling. This notice serves as your primary communication tool to inform employees about their data protection rights and your organization's data processing activities, ensuring compliance with Singapore's comprehensive data protection framework.

When do you need this document?

You need a Privacy Notice For Employees whenever your organization collects, uses, or discloses employee personal data in Singapore. This requirement applies from the moment you begin the recruitment process and continues throughout the employment relationship. The notice is mandatory when processing employment applications, maintaining personnel files, conducting performance evaluations, managing payroll and benefits, implementing workplace monitoring systems, or handling employee health records. You must also provide updated notices when introducing new data processing activities, implementing workplace technology that collects personal data, or when regulatory requirements change. The PDPA requires this notice to be provided before or at the time of data collection, making it essential during onboarding processes.

Key legal considerations

Your Privacy Notice For Employees must include specific elements to ensure PDPA compliance. The notice should clearly identify the types of personal data collected, from basic contact information to sensitive data like health records or performance metrics. You must specify the purposes for which data is collected, used, and disclosed, ensuring these purposes are reasonable and directly related to your employment relationship. The notice should explain your data protection measures, retention policies, and employees' rights including access, correction, and withdrawal of consent where applicable. You must also disclose any third parties who may receive employee data, such as payroll providers, insurance companies, or regulatory bodies. Consider including information about data transfers outside Singapore and the safeguards in place. The notice should be written in clear, understandable language and made easily accessible to all employees.

Legal requirements in Singapore

Under Singapore's PDPA 2012 and the updated PDPA Regulations 2021, organizations must comply with specific notification requirements when processing employee personal data. The Personal Data Protection Commission (PDPC) Guidelines emphasize that employee data requires special consideration due to the inherent power imbalance in employment relationships. Your notice must align with the consent, purpose limitation, and notification obligations under the PDPA, while recognizing that some employee data processing may rely on legitimate interests rather than explicit consent. The Employment Act (Chapter 91) also governs how employment records must be maintained and disclosed. You must ensure your privacy notice addresses mandatory data breach notification requirements and incorporates PDPC's guidance on employee data handling. Regular updates to the notice are required when data processing practices change, new technologies are implemented, or when PDPC issues new guidelines affecting employee data protection.

GOVERNING LAW

Applicable law

This Privacy Notice For Employees is drafted to comply with Singapore law. Key legislation includes:

PDPA 2012: Primary legislation governing personal data protection in Singapore - Personal Data Protection Act 2012, which provides the baseline standards for personal data protection

PDPA Regulations 2021: Updated regulations that complement the PDPA, providing specific requirements for data protection and breach notification

Employment Act: Chapter 91 of Singapore laws, containing provisions relating to employment relationships and employee records management

PDPC Key Concepts Guidelines: Advisory Guidelines from PDPC explaining key concepts in the PDPA and their practical application

PDPC Selected Topics Guidelines: Specific guidelines for selected topics under PDPA including handling of employee data

Guide to Notification: PDPC guidance on notification requirements for data collection and use

Data Breach Management Guide: PDPC guidelines on managing and reporting data breaches

Data Protection Management Programme Guide: Framework for developing and implementing a comprehensive data protection program

Workplace Safety and Health Act: Requirements related to collection and protection of workplace safety and health-related personal data

Employment of Foreign Manpower Act: Additional requirements for handling personal data of foreign employees

Cross Border Data Transfer Requirements: Rules governing the transfer of personal data outside of Singapore

APEC CBPR System: APEC Cross-Border Privacy Rules System for consistent data protection across APEC economies

Tripartite Guidelines: Guidelines on Fair Employment Practices affecting employee data handling

MOM Data Retention Requirements: Ministry of Manpower's requirements for retention of employee data and records

Cybersecurity Act: Requirements for protection of critical information infrastructure and cybersecurity standards

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it