NESST Personal Data Policy
1. This policy informs you how NESST manages your Personal Data under the Personal Data Protection Act 2012 (Cap. 26) (“PDPA”). Under PDPA, Personal Data is information about an individual who can be identified from that data; or from that data and other information to which the organisation has or is likely to have access. The Act recognises the rights of individuals to protect their personal data and the needs of organisations to collect, process, use or disclose personal data for business and legal purposes.
2. Details of the purposes of processing of your Personal Data by NESST are set out in this policy. NESST abides by the PDPA that safeguards the protection of Personal Data of individuals. The term “Personal Data” refers to information that is connected to you as an identifiable individual, defined under the PDPA to mean data, whether true or not, about an individual who can be identified from that data, or from that data and other information to which an organization has or is likely to have access (“Personal Data”). Personal Data includes, amongst others, (a) full name, (b) NRIC Number or FIN (Foreign Identification Number), (c) passport number, (d) personal mobile telephone number, (e) facial image of an individual (e.g. in a photograph or video recording), (f) voice of an individual (e.g. in a voice recording), (g) fingerprint, (h) iris image, (i) DNA profile, etc.
3. This Privacy Policy applies to the products, services, certification and website(s) provided, mobile application(s) provided and/or the business conducted, by us, and explains how we handle Personal Data and comply with the requirements of the PDPA.
4. The contents of this Privacy Policy may change over time so please check back frequently. Any changes to this Privacy Policy will be posted on and can be viewed at https://www.nesst.sg/privacy/
5. This Privacy Policy is subject to Singapore law.
6. NESST does not exercise control over the third party websites displayed as search results or links from within its services or within its Website. These third party websites may place their own cookies or other files on your computer, collect data or solicit personal information from you, for which NESST is not responsible or liable. Accordingly, NESST does not make any representations concerning the privacy practices or policies of such third parties or terms of use of such third party websites, nor does NESST guarantee the accuracy, integrity, or quality of the information, data, text, software, sound, photographs, graphics, videos, messages or other materials available on such third party websites. The link to such third party websites on our Website does not imply any endorsement by NESST of such third party websites, the third party websites’ providers, or the information on the third party websites. If you decide to visit a third party website linked to our Website, you do this entirely at your own risk. You should read the privacy policies of such third party websites.
7. If you opt to submit or send us any application, report, dispute, claim, information, email or any other form of correspondence, you will be deemed to have provided explicit personal consent or, where applicable, obtained third party consent, to provide information including Personal Data to NESST for our reasonable collection, processing, use and disclosure. You also provide personal or representative consent to this information disclosure by any or both of us to the following parties and to subsequent disclosure among same parties of any and all information including, without limitation, Personal Data that may have been possessed or collected in connection with your application, report, dispute, claim, information, email or any other form of correspondence
Collection and Processing of Your Personal Data
8. NESST collects and processes your Personal Data through the following means:
- when you contact, or are contacted by, and respond and interact with us or service providers via telephone, website, chatbot, e-mail, letters, physical or virtual meetings, social media platforms (such as Facebook and LinkedIn), mobile applications and others. All inbound and outbound telephone calls are recorded;
- when you provide your organisation’s information for enquiry
- when you respond with or submit Personal Data on reports, disputes, claims, cases including referred cases or others; when you respond to join our campaigns, promotions, events, surveys, polls, focus group discussions, competitions, contests, lucky draws or other activities organised or conducted by us;
- when you have CCTV, video and audio recordings or photographs taken by us, our partners or representatives during your physical or virtual interviews, meetings or events organised or hosted by us;
- when you apply to join us as an employee, secondee, trainee, intern, client or others;
- when you submit financial information such as bank, credit card and other payment details;
- when you submit your Personal Data for any other reason.
11. NESST uses your Personal Data for the following purposes:
- respond to requests or for the purposes for which it was provided to us as stated at the time of the collection or processing (or as is obvious from the context of collection or processing);
- register employer or individual representatives for NESST’s programmes;
- management of workplace programmes and grant funding administration;
provide physical or virtual employer training events;
provide you updates through our mailing broadcast on our news, events, initiatives, or other activities; - conduct market research and analysis including business, customer satisfaction or other research, surveys, polls and focus group discussions to develop or enhance our programmes, services, websites and applications;
- monitor or record telephone calls and customer-facing interactions for identification verification, quality assurance and audit, record keeping and administration purposes;
- manage the safety and security of our services (including but not limited to protection of our website, application and service platforms; preventing, monitoring or investigating their misuse or security) and premises (CCTV surveillance; security clearances and others);
- conducting investigations relating to disputes, billing or fraud and managing our governance risks;
- for recruitment, appointment, onboarding and training for employees, secondees, trainees, interns and others;
- for management, financial and regulatory reporting, risk management and compliance, external and internal audit, record keeping and administration purposes;
- protecting our rights and interests and those of our users and customers, enforcing legal obligations owed to us or responding to complaints, litigation or investigations to protect ourselves from legal liability;
- sharing data in connection with our business structure, transactions or activities;
- for NESST’s third party contractors as stipulated in your contract or agreement with NESST;
- for compliance with laws, regulations, guidelines, directions and other similar requirements.
12. NESST may disclose Personal Data for the following reasons:
- to relevant authorities and other government regulatory bodies (including the State Courts) upon their official requests;
- to any other party to whom you authorise us to disclose your Personal Data;
- to an employee, secondee, trainee, intern, independent contractor or data intermediary providing services to support NESST, whom are under a duty of confidentiality to NESST;
- to third parties who perform services such as financial, risk management and compliance, external and internal audit, IT services, data analytics, marketing, customer or other research, surveys, polls and focus group discussions on behalf of NESST;
- to the extent necessary to comply with laws, regulations, guidelines, directions and other similar requirements.
- have any enquiries on NESST’s Personal Data Policy;
- need more information or access to the data which you have provided to us in the past. We will require you to provide certain information to process your request; may charge you a fee to process your request or may decline a request for access (under applicable laws).