Data Protection Policy
Section 1: Introduction – About this Data Protection Policy
1.1 The purpose of this Data Protection Policy is to inform you of how Intellectual Property Office of Singapore (“IPOS”) and its subsidiary(ies), including IPOS International Pte Ltd (“II”) (collectively referred to herein as the “IPOS Group”, “us”, “we” or “our”) manage Personal Data (as defined in Section 2.1 below) that is within our possession or control. Please take a moment to read this Data Protection Policy so that you know and understand the purposes for which we collect, use and disclose your Personal Data.
1.2 By submitting your information to us or signing up for any products and services offered by us, you agree and consent to the collection, use, disclosure and other processing of your Personal Data by and among the IPOS Group and, where applicable, our respective representatives and agents. You further agree and consent to the disclosure of such Personal Data to any of the IPOS Group’s entities’ authorised service providers and relevant third parties in the manner set forth in this Data Protection Policy.
1.3 This Data Protection Policy supplements but does not supersede nor replace any other consent you may have previously provided to any of the IPOS Group’s entities in respect of your Personal Data, and your consent herein is additional to any rights which the IPOS Group may have at law to collect, use or disclose your Personal Data.
1.4 The IPOS Group may from time to time update this Data Protection Policy to ensure that this Data Protection Policy is consistent with our future developments, industry trends, and/or any changes in legal or regulatory requirements and, where reasonably possible, we will communicate any significant changes to you in such form as we deem appropriate, including by publishing the modified or revised Data Protection Policy on our website(s). Where required by applicable law, we may also post a notice, or reach you via other forms of communication (e.g. sending you an SMS message or email) according to such contact particulars that we may have of you in our records from time to time. Subject to your rights at law, you agree to be bound by the prevailing terms of this Data Protection Policy as updated from time to time on our website(s), application(s), and digital services. Please check back regularly for updated information on the handling of your Personal Data.
Section 2: Personal Data
2.1 For the purposes of this Data Protection Policy, “Personal Data”, in line with the definition set forth in Singapore’s Personal Data Protection Act 2012 (“Act”), refers to any data, whether true or not, about an individual who can be identified (a) from that data; or (b) from that data and other information to which we have or are likely to have access.
2.2 We may process different kinds of Personal Data, including but not limited to:
2.2.1 Identity data includes first name, last name, NRIC, passport, Advocates and Solicitors of the Singapore Bar number or other identification number, job title, name of your organisation;
2.2.2 Contact data includes telephone number(s), mailing address and email address;
2.2.3 Details of the events you want to attend or have attended;
2.2.4 Images of you participating in events;
2.2.5 Images on our CCTV systems; and
2.2.6 Any other information relating to any individuals which you have provided in any forms you may have submitted to us, or via other forms of interaction with you.
2.3 Where we need to collect Personal Data by law, or under the terms of a contract we have with you, and you do not provide such data when requested, we may be unable to perform the contract we have or provide certain services to you. In such cases, we may have to cancel a service you have with us, but we will notify you if this is the case at the time.
Section 3: Collection of Personal Data
3.1 Generally, we collect Personal Data in the following ways:
3.1.1 when you submit an application form or registration form, or other forms relating to any of our products and services;
3.1.2 when you enter into any agreement or provide other documentation or information in respect of your interactions with us, or when you use our services;
3.1.3 when you interact with our customer service officers, for example, via telephone calls, letters, face-to-face meetings, social media platforms and emails;
3.1.4 when you use our electronic services, or interact with us via any of our website(s) or use services on any of our website(s);
3.1.5 when you request that we contact you or request that you be included in an email or other mailing list;
3.1.6 when you respond to our promotions, initiatives or to any request for additional Personal Data;
3.1.7 when your images are captured by us via CCTV cameras while you are within our premises, or via photographs or videos taken by us or our representatives when you attend events at our premises;
3.1.8 when you are contacted by, and respond to, our marketing representatives and customer service officers;
3.1.9 when we receive references from business partners and third parties, for example, where you have been referred by them;
3.1.10 when you fill up surveys administered by our third-party surveying service providers;
3.1.11 when we seek information from third parties about you in connection with the products and services you have applied for; and/or
3.1.12 when you submit your Personal Data to us for any other reason.
3.2 In addition, we may also collect Personal Data from third parties, including third party event partners who, in turn, collect Personal Data from you. Event partners organise and facilitate programmes, courses and events, or otherwise offer products and services that are complimentary to those offered by any of the IPOS Group’s entities. For the avoidance of doubt, the collection, use, disclosure and processing of your Personal Data by each such event partner will be subject to that event partner’s privacy policy.
3.3 The servers used for the hosting of our website(s), application(s) and/or digital services utilise cookies. When you use our website(s), application(s) or digital services, we may collect and store information relating to your device or usage, such as IP address, browser type and operating system, where such collection is necessary for functionality, security, analytics or system administration purposes. Such information may constitute Personal Data in certain circumstances and is processed in accordance with this Data Protection Policy and applicable law. Please refer to Section 9 (Use of Cookies) below for more details on our use of cookies.
3.4 If you provide us with any Personal Data relating to a third party (e.g. information of your spouse, children, parents, and/or employees), by submitting such information to us, you represent and warrant to us that you have obtained the consent of the third party to provide us with their Personal Data for the respective purposes.
3.5 In particular, if you provide us with any Personal Data relating to a minor who is less than 13 years of age, by submitting such information to us, you confirm that you are legally able to consent on their behalf to provide us with their Personal Data for the respective purposes.
3.6 You should ensure that all Personal Data submitted to us is complete, accurate, true and correct. Failure on your part to do so may result in our inability to provide you with the products and services you have requested.
Section 4: Purposes for the Collection, Use and Disclosure of Your Personal Data
4.1 Generally, the IPOS Group collects, uses and discloses your Personal Data for the following purposes:
4.1.1 providing customer service and support, including to respond to your queries, feedback, complaints and requests;
4.1.2 to create, maintain your profile in our system database for internal records and reference, including for the verification of your identity;
4.1.3 to manage and administer the IPOS Group’s business operations and ensure compliance with internal policies and procedures;
4.1.4 to facilitate business asset transactions (which may extend to any mergers, acquisitions or asset sales) involving any of the IPOS Group’s entities;
4.1.5 to match any Personal Data held which relates to you for any of the purposes listed herein;
4.1.6 to request feedback or participation in surveys, as well as to conduct market research and/or analysis for statistical, profiling or other purposes for us to review, develop and improve the quality of our products and services;
4.1.7 to prevent, detect and investigate matters, including potential or existing criminal offences, existing or potential disputes, billing or fraud;
4.1.8 to analyse and manage commercial risks;
4.1.9 for facilities management services and managing the safety and security of our premises (including but not limited to carrying out CCTV surveillance and conducting security clearances);
4.1.10 to monitor or record phone calls and customer-facing interactions for quality assurance, employee training and performance evaluation and identity verification purposes;
4.1.11 in connection with any claims, actions or proceedings (including but not limited to drafting and reviewing documents, transaction documentation, obtaining legal advice, and facilitating dispute resolution), and/or protecting and enforcing our contractual and legal rights and obligations;
4.1.12 to meet or comply with any rules, laws, regulations, codes of practice or guidelines issued by any legal or regulatory bodies which are applicable on an entity of the IPOS Group (including but not limited to responding to regulatory complaints, disclosing to regulatory bodies and conducting audit checks, due diligence and investigations);
4.1.13 health and safety management, including safe management measures, social distancing, disease control and prevention, quarantine arrangements, contact tracing and other response measures; and/or
4.1.14 any other purpose reasonably related to the aforesaid.
4.1.15 If you are an existing or prospective participant (including an invited speaker or lecturer) of our courses, events and programmes:
4.1.15.1 providing, administering and conducting information sessions, courses, events and programmes (including facilitating registration, recording attendance, processing payment for courses, conducting tests and examinations, event budgeting and contacting you for administrative purposes);
4.1.15.2 facilitating your applications to other educational institutions which you may apply to;
4.1.15.3 administering debt recovery and debt management;
4.1.15.4 facilitating your use of our online portals;
4.1.15.5 maintaining an alumni network and organising alumni activities such as information sessions and talks;
4.1.15.6 registering you on member lists (including the Community of Practice on IP Management);
4.1.15.7 administering continuing professional development points;
4.1.15.8 taking photograph(s) and/or video(s) of you for (i) internal dissemination within the IPOS Group and (ii) generating publicity materials for our courses, events and programmes;
4.1.15.9 publicity, marketing and providing networking opportunities to other registered participants of the same course for which you have registered; and/or
4.1.15.10 any other purpose reasonably related to the aforesaid.
4.1.16 If you are required to take examinations and tests administered by an IPOS Group entity:
4.1.16.1 administering the relevant examinations and tests;
4.1.16.2 notifying you of test details and updates;
4.1.16.3 facilitating your use of online test portals; and/or
4.1.16.4 any other purpose reasonably related to the aforesaid.
4.1.17 If you have submitted any applications to an IPOS Group entity:
4.1.17.1 conducting research and surveys on behalf of the IPOS Group; and/or
4.1.17.2 any other purpose reasonably related to the aforesaid.
4.1.18 If you submit an application to us as a candidate for an employment or representative position:
4.1.18.1 processing your application including pre-recruitment checks, such as in relation to your credit standing and qualifications;
4.1.18.2 providing or obtaining employee references;
4.1.18.3 for background screening/vetting or health check-ups;
4.1.18.4 facilitating and conducting interviews;
4.1.18.5 assessing your suitability for the position applied for;
4.1.18.6 entering into an employment relationship with you or appointing you to any office;
4.1.18.7 communicating with you as required by II to comply with its policies and processes, including for business continuity purposes;
4.1.18.8 processing staff referrals; and/or
4.1.18.9 any other purposes relating to or reasonably necessary for any of the aforesaid.
4.2 Furthermore, where permitted under the Act and/or where you have provided your consent to an IPOS Group entity separately, the IPOS Group may also collect, use, process and disclose your Personal Data for the following additional purposes:
4.2.1 providing or marketing services, products and benefits to you, including but not limited to special events and promotions from the IPOS Group;
4.2.2 matching Personal Data with other data collected for other purposes and from other sources (including third parties) in connection with the provision, marketing or offering of products and services by the IPOS Group;
4.2.3 administering and organising contests, lucky draws, promotional events, competitions and marketing campaigns, and personalising your experience at IPOS or II’s touchpoints;
4.2.4 conducting market research, analytics and surveys to enable the IPOS Group to understand and determine customer preferences and demographics for us to offer you products and services as well as special offers and marketing programmes which may be relevant to your preferences and profile; and/or
4.2.5 any other purpose reasonably related to the aforesaid.
4.3 If you have provided your Singapore telephone number(s) and have indicated that you consent to receiving marketing or promotional information via your Singapore telephone number(s), then from time to time, the IPOS Group may continue to contact you using such Singapore telephone number(s) (including via voice calls, text, fax, or other means) with information about our products and services, unless you have withdrawn your consent.
4.4 In relation to certain products and services, or in your interactions with any of the IPOS Group entities, we may also have specifically notified you of other purposes for which we collect, use or disclose your Personal Data. If so, we will collect, use and disclose your Personal Data for these additional purposes as well, unless we have specifically notified you otherwise.
Section 5: Third Parties to Whom Personal Data May Be Disclosed
5.1 The IPOS Group will take reasonable steps to protect your Personal Data against unauthorised disclosure. Subject to the provisions of any applicable law, your Personal Data may be disclosed by the IPOS Group, for the purposes listed above (where applicable), to the following third parties, whether they are located overseas or in Singapore:
5.1.1 companies providing services relating to medical screening, insurance, marketing and consultancy to any of the IPOS Group entities;
5.1.2 agents, contractors or third-party service providers who provide operational services to an IPOS Group entity, such as courier services, telecommunications, information technology, payment, printing, billing, payroll, processing, technical services, training, market research, call centre, security, employee recognition or other services;
5.1.3 agents, contractors or third-party service providers (including but not limited to external tutors and lecturers) who provide services in connection with the courses, programmes and events organised, conducted and administered by an IPOS Group entity;
5.1.4 our partners or collaborators in our courses, events and programmes (including but not limited to the National University of Singapore);
5.1.5 any business partner, investor, assignee or transferee (actual or prospective) to facilitate business asset transactions (which may extend to any merger, acquisition or asset sale) involving an IPOS Group entity;
5.1.6 external banks, credit card companies and their respective service providers;
5.1.7 our professional advisers such as consultants, auditors and lawyers;
5.1.8 relevant government ministries, regulators, statutory boards or authorities or law enforcement agencies to comply with any laws, rules, guidelines and regulations or schemes imposed by any governmental authority;
5.1.9 other existing or prospective participants (including invited speakers or lecturers) of our courses, events and programmes; and
5.1.10 any other party whom you authorise us to disclose your Personal Data to.
Section 6: Deemed Consent
6.1 In addition to the matters set forth above, subject to and in accordance with applicable law, you shall be deemed to have consented to us collecting, using, disclosing and sharing amongst themselves your Personal Data, and disclosing such Personal Data to our authorised service providers and relevant third parties:
6.1.1 where in response to a request for your Personal Data in connection with identified purposes, you voluntarily provide such Personal Data to us for such purpose(s) and it is reasonable that you would voluntarily provide such Personal Data; or
6.1.2 where the collection, use or disclosure of your Personal Data is reasonably necessary for the conclusion and/or performance of a contract between you and us or any other organisation entered into at your request, which may include recipients of your Personal Data not indicated in this Data Protection Policy.
Section 7: Other Bases for Handling or Processing Your Personal Data
7.1 In addition to and without limiting the consents you have provided to our collection, use and disclosure of your Personal Data for the purposes set out elsewhere in this Data Protection Policy, where permitted by applicable law, we may also, in accordance with the requirements thereof, also collect, use and/or disclose your Personal Data as further detailed below without consent, where we meet the requirements of applicable law:
7.1.1 for our legitimate interests or the legitimate interests of any other person, including but not limited to the purposes expressly set forth in this Data Protection Policy; and
7.1.2 for improving our existing or developing new products, services, methods, processes or business, learning and understanding the preferences and personalising the experiences and recommendations of you or another individual, based on your Personal Data records with us (regardless of whether you are an existing or prospective customer).
Section 8: Third Party Websites
Our website(s) may contain links to other websites operated by third parties, such as our business partners. We are not responsible for the privacy practices of websites operated by third parties that are linked to our website(s). We encourage you to learn about the privacy policies of such third-party websites. Once you have left our website, you should check the applicable terms, conditions and policies of the third-party website to determine how they will handle any information they collect from you.
Section 9: Use of Cookies
9.1 Our website(s) and application(s) make use of cookies. A cookie is a small piece of information that is placed on your computer when you visit certain websites. The cookies placed by the servers hosting our website(s) and application(s) are readable only by us, and cookies cannot access, read or modify any other data on an electronic device. All web-browsers offer the option to refuse any cookie, and if you refuse our cookie, no information will be gathered from you.
9.2 Should you wish to disable the cookies associated with these browsers, you may do so by changing the setting on your browser. Unless you have adjusted your browser settings to block cookies, our system will issue cookies as soon as you visit our site or click on a link in a targeted email that we have sent you, even if you have previously deleted our cookies.
9.3 If you do not agree to our use of cookies and other technologies as set out in this Data Protection Policy, you should delete or disable the cookies associated with our website(s) and platforms by changing the settings on your browser accordingly. However, you may not be able to enter certain part(s) of our website(s) or application(s) and may impact your user experience while on our website(s) or application(s).
Section 10: Data Security
10.1 The IPOS Group will take reasonable efforts to protect Personal Data in our possession or our control by making reasonable security arrangements to prevent unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks. However, we cannot guarantee the security of any Personal Data we may have collected from or about you, or that no harm will arise from the use of our website(s), application(s), and digital services (for example viruses, bugs, trojan horses, spyware or adware). You should be aware of the risks associated with using website(s), application(s), and digital services.
10.2 While we strive to protect your Personal Data, we cannot ensure the security of the information you transmit to us via the Internet, when you browse our website(s), or use our application(s) and/or digital services. We urge you to take every precaution to protect your Personal Data when you are on the Internet, when you browse our website(s), or use our application(s) and/or digital services. We recommend that you change your passwords often, use a combination of letters and numbers, and ensure that you use a secure browser.
10.3 If applicable, you undertake to keep your username and password secure and confidential and shall not disclose or permit it to be disclosed to any unauthorised person. If you know or suspect that someone else knows your username and password or believe the confidentiality of your username and password has been lost, stolen or compromised in any way or that actual or possible unauthorised transactions have taken place, please inform us as soon as reasonably practicable. We are not liable for any damages resulting from any security breaches, on unauthorised and/or fraudulent use of your username and password.
Section 11: International Transfers
11.1 While we are based in Singapore, our external third parties may be based outside of Singapore. As such, the processing of your Personal Data may take place outside of Singapore.
11.2 Whenever we transfer your Personal Data to third parties who are located outside of Singapore, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
11.2.1 We will only transfer your Personal Data to countries that have been deemed to provide an adequate level of protection for Personal Data; or
11.2.2 Where we use certain service providers, we use specific contracts which give Personal Data the same standard of protection that is required in accordance with data protection obligations applicable to us.
11.3 Please contact us if you want further information on the specific mechanism used by us when transferring your Personal Data out of Singapore.
Section 12: Data Retention
We will only retain your Personal Data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, accounting, or reporting requirements.
Section 13: Contacting Us – Feedback, Withdrawal of Consent, Access and Correction of your Personal Data
13.1 If you:
13.1.1 have any questions or feedback relating to your Personal Data or our Data Protection Policy;
13.1.2 would like to withdraw your consent to any use of your Personal Data as set out in this Data Protection Policy; or
13.1.3 would like more information on or access and make corrections to your Personal Data records,
you may contact IPOS at ipos_enquiry@ipos.gov.sg or by calling (65) 6339 8616, or you may contact II at dpo@iposinternational.com.
13.2 You may withdraw your consent given for any or all purposes set out in this Data Protection Policy by contacting us in writing. If you withdraw your consent to any or all use of your Personal Data, depending on the nature of your request, the IPOS Group may not be in a position to administer any contractual relationship in place, which in turn may also result in the termination of any agreements with any of the IPOS Group entities, and you may be in breach of your contractual obligations or undertakings under such agreement(s). The IPOS Group’s legal rights and remedies in such event are expressly reserved.
Section 14: Governing Law
This Data Protection Policy, your browsing of our website(s), and use of our application(s) and/or digital services shall be governed in all respects by the laws of Singapore.
