Protection of personal data in Singapore and Brazil—A general comparison

by Renato Leite Monteiro1

Data protection is current a trend topic on world politics, in both the media and society in general. The issue is far from new, but since Edward Snowden2 released information about a secret worldwide surveillance program performed by the United States of America National Security Agency on electronic communications over the Internet, news pops up almost every day revealing that not only common US and foreign citizens3, but also head-of-states4, have had their communications monitored.

These revelations by Mr Snowden exposed a surveillance program that included tapping the Brazilian President. Such an act led the head-of-state to address the situation in her opening speech at the United Nations General Assembly of 20135, highlighting that “tampering in such a manner in the affairs of other countries is a breach of international law and an affront to the principles that must guide relations among them”. It also led to cancelling an official visit to the United States, under the reasoning that “interception practices of communication and citizens’ data, companies and members of the Brazilian government are a grave fact, a threat to national sovereignty and individual rights, and incompatible with the democratic cooperation between friendly nations"6.

In a time when the amount of electronic data produced everyday surpasses the amount of regular data produced by the entire human civilization since its dawn7, several countries have yet to regulate how data which flows through its infrastructure should be processed and treated. Europe has been legislating about it for more than thirty years8. The United States has only sectorial laws9, regarding, e.g., health records or tax data. Although Brazil has statutory provisions in its constitution guaranteeing the right to privacy10, it still does not have a comprehensive protection to personal data. Rather, it only has a brief overview of the issue in its consumer code and also in specific regulations, such as medical records.11 Singapore has recently introduced the Personal Data Protection Act [PDPA] 12, which encompasses certain particularities when compared to similar provisions from other regions of the world.

As opposed to Brazil and the European signatory countries, Singapore does not provide to its citizens a statutory right to privacy, instead relying more on the tort remedy of breach of confidence to enforce such a claim.13 Confirming the theory that “privacy” and “data protection” are two different concepts14, the word “privacy” is absent from Singapore’s Data Protection Act.15 The Act focuses on information management; and the economic, commercial and competitive advantages of having clear rules on how the industry based in Singapore ought to process personal data.16  A culmination of years of discussion and comments17, Singapore’s act comprises a concept of personal data18, but does not differentiate it from sensitive data.19 Its main advantages are the rules on collection, use and disclosure of personal data, setting forth the need of actual or deemed consent from the individual to perform those acts.20 Consent can be withdraw at any moment21 and deemed consent is limited to situations when the individual voluntarily provides the personal data or there are reasons to believe that such data would be provided.22 Also, the individual must be informed as to the purpose his information is being collected23, and its use must be limited to such purpose.24 But there are exceptions to the need of consent, such as emergencies, legal services and newsworthiness.25 It created a Data Protection Authority (“DPA”)26, responsible for the enforcement of the act. In case of a violation, the authority can fix said offenders with penalties up to $1 million, amongst other measures.27

It is important to note that the PDPA left out major provisions present not only on the Brazilian Bill on the Protection of Personal Data, but in several other legislations. The PDPA does not provide, when dealing with trans-border transfers, the need for the foreign country to apply the same level of protection to personal data as Singapore. Rather, it only requires the same standard of protection.28 Also, it has not implemented a data breach notification system, setting pace on the opposite direction of countries with a very liberal approach to data protection.29 Another interesting provision that confirms that the approach of the act is to enhance Singapore’s economy, and not primarily protect the privacy of its citizens, is that data processed by government institutions do not need to follow the PDPA’s requirements30. Data breach obligations have been one of the most effective measures mandated by data protection legislations31, since data processors, data controllers and intermediaries are required to notify not only the DPAs, but also the individuals whose personal data have been breached. Up to this date publicizing data breaches has not been a regular practice of private organizations and governments, that fear liability and – more important – bad publicity that can lead to direct repercussions on businesses.32

As for Brazil, the country has been openly discussing Internet regulation33. Recently, a law was approved (“cybercrime bill”) amending its criminal code to include certain acts performed through electronic means and over the Internet34. Concurrently, a civil legislative framework is under debate.35  This bill will encompass questions such as Internet Service Providers’ (“ISP”) liability for third-party content, network neutrality and set time limits to ISPs’ storage of Internet users’ connection data. But this framework does not directly addresses the issue of protection of personal data. For this a different bill has been introduced.36 Due to the recent set of events involving privacy and data breaches of Brazilian citizens, both provisions that were on hold have been urgently brought into force.37

The Brazilian Bill38 on the Protection of Personal Data is based on the European Directives on Data Protection39 and on the Canadian Data Protection Act [PIPEDA].40 It guarantees a list of citizens’ basic rights regarding their personal data: the right to (i) access one’s data; (ii) correct inaccurate or wrong data; (iii) delete them; (iv) object to their processing; (v) not be subject to purely automated decisions; and (iv) be compensated for the misuse of one’s personal data.41

Similar to the European provisions, and different from the Singapore’s PDPA42, the bill sets forth that personal data can only be transferred to countries that guarantee the same level of protection.43 The DPA, the institution created to overview the enforcement of the act, will pronounce the acknowledgement of the same level of protection.44 It mandates a data breach notification regime;45 differentiates between personal data and sensitive data;46 and furthermore, it expands its application not only to private organizations, but also to governmental institutions of all levels.47 The bill even determines strict liability to data processors in case of data breaches.48

Therefore, both legislative provisions, Singaporean and Brazilian, aim on setting clear rules to the processing of personal data over electronic infrastructures in their territory. This is a clear reaction to digital era in which the world is currently inserted. But the laws are founded on different perspectives. Singapore’s PDPA is based on economic goals. Brazil’s bill is based on the country’s long lasting history of statutory recognition of the right to privacy.49 Which is more important depends on the different approaches given by interpreters. But it is important to bear in mind the current state of international politics due to the recent data breaches scandals.50 Nonetheless, both countries may end up achieving the same objective, which is to protect the personal data of its citizens.

[1] New York University LL.M. Candidate in Global Business Law, National University of Singapore LL.M. Candidate in Intellectual Property and Technology Law, Singapore Law Review Editor.

