Privacy Policy
Singapore Commercial Credit Bureau Pte. Ltd. (“SCCB”, “we”, “us”) is committed to complying with the Personal Data Protection Act 2012 (the “PDPA”) and the guidelines issued by the Personal Data Protection Commission (the “PDPC”).
This Policy explains how we may collect, use, disclose and otherwise handle personal data in the course of our business. Our business includes credit and business information reports and scores covering businesses and individuals; searches of public registers, including litigation, bankruptcy and property records; beneficial ownership and know-your-customer solutions; a payment bureau recording payment conduct contributed by members; credit monitoring; data and analytics services; training and seminar services; and debt recovery services carried out for our customers.
Much of the personal data we hold is obtained from a source other than the individual concerned, such as a public register, a customer or a data contributor. This Policy is the means by which we notify individuals of the purposes for which their personal data may be collected, used and disclosed, whether or not we obtained it from them directly.
Business contact information
Some of the information we handle about individuals is business contact information, such as a person’s name, position, business telephone number, business address and business email address, provided otherwise than solely for personal purposes. The data protection obligations under the PDPA do not apply to business contact information. Other provisions of the PDPA, including those relating to the Do Not Call Registry, may still apply.
Where it is unclear whether information about an individual is business contact information, we treat it as personal data and handle it in accordance with this Policy.
Personal data we collect
We may collect personal data for purposes that a reasonable person would consider appropriate in the circumstances. Personal data may be obtained directly from an individual; from publicly available sources and public registers; from our customers, subscribers and data contributors, including information they provide about payment conduct and outstanding debts; and from other parties whom we reasonably believe are authorised to disclose it.
The types of personal data collected vary with the service, and may include:
- identifying and contact details, and identifiers such as national identification numbers, where required by law or where necessary to accurately establish or verify identity to a high degree of fidelity;
- business role, directorship, shareholding and beneficial ownership information;
- credit, payment, financial and account related information;
- information obtained from public registers, including records of insolvency, litigation, judgments and regulatory or licensing action, where relevant to our services;
- information about debts, defaults, payment conduct and their resolution, including debts referred to us for recovery and information contributed by our subscribers;
- correspondence and records of our dealings with you; and
- registration and attendance information for our training and seminars.
Purposes
Personal data may be collected, used and disclosed for purposes including:
- assessing commercial credit risk, financial standing and business reliability;
- compiling, maintaining and providing credit and business information reports, scores, credit profiles and related insights, relating to businesses and to individuals;
- carrying out searches of public registers, including litigation, bankruptcy and property records, and providing the results;
- providing beneficial ownership and know-your-customer solutions to customers, including to help them meet their own legal obligations;
- operating a payment bureau that records payment conduct information contributed by members (i.e., our customers/subscribers);
- providing credit monitoring services, including alerting subscribers to changes affecting an entity they monitor;
- developing, maintaining, validating and improving our databases, analytical tools, models and services;
- providing debt recovery services on behalf of our customers;
- recording information about a debt, default or payment conduct, including information arising from debt recovery activity carried out for a customer, in the credit profile of the person concerned, where we are permitted to do so;
- providing training and seminar services;
- managing customer relationships, contracts, communications and service delivery;
- marketing our products, services and events, where you have consented or where we are otherwise permitted to do so;
- responding to enquiries, requests, disputes and complaints; and
- meeting legal, regulatory, licensing, audit and governance requirements.
We may also use personal data for other purposes notified to the individual at or before the time of collection, or as otherwise permitted or required by law.
Our basis for handling personal data
Depending on the circumstances, we may rely on consent given by the individual, whether directly or through a data contributor; on deemed consent; and on the exceptions available under the PDPA, including those relating to publicly available data, the recovery of a debt, legal proceedings and investigations, evaluative purposes and business asset transactions.
Where we rely on the legitimate interests exception under the PDPA, the legitimate interests concerned are the provision and maintenance of reliable credit and business information, relating to businesses and to individuals, so that credit risk can be assessed; the prevention, detection and investigation of fraud, misrepresentation and default; the lawful recovery of debts owed to our customers; and the protection of the security and integrity of our systems and information. We take reasonable steps to identify and address any adverse effect on individuals arising from that reliance.
Where we provide debt recovery services on behalf of a customer, we may act as a data intermediary for that customer in respect of personal data processed solely for the purpose of recovering that debt. In those cases the customer remains the organisation responsible for that personal data, and a request relating to it may need to be directed to them. We will help you identify the right party where we can.
Where, with the customer’s authority and where we are permitted to do so, information about a debt, default or payment conduct is recorded in the credit profile of the person concerned, that is a separate use of personal data for our own purposes. In relation to that use we act as an organisation in our own right and rely on the bases set out above.
Where a customer, subscriber or data contributor provides personal data to us, we require them to have obtained any consent necessary, or to be otherwise permitted, to disclose it to us for the purposes described in this Policy.
Disclosure
We may disclose personal data in the ordinary course of business, including to:
- customers with a legitimate purpose in connection with accessing credit or business information, subject to contractual restrictions on their use of that information;
- the party that engaged us, where we provide debt recovery services;
- service providers, professional advisers, auditors and companies within our group that support our operations, subject to appropriate confidentiality and data protection arrangements; and
- regulators, public authorities and courts where required or permitted by law.
Accuracy, protection and retention
We take reasonable steps to ensure that personal data used in our services is accurate and complete to the extent necessary for its intended purpose, and we make reasonable security arrangements to protect personal data in our possession or under our control against unauthorised access, use, disclosure, alteration, loss or similar risks. If you believe information we hold about you is inaccurate or incomplete, you may ask us to correct it under Section 10. Where we correct personal data, we will take the steps required by the PDPA in relation to organisations to which that personal data was previously disclosed.
We retain personal data for as long as it is reasonably necessary for the purposes for which it was collected, or as required or permitted for legal, regulatory, contractual, audit or evidential purposes. Credit and business information may necessarily be retained over a period of years so that it remains meaningful for credit risk assessment. Where personal data is no longer required, we take reasonable steps to dispose of it securely or to remove the means by which it can be associated with an individual.
Employees and job applicants
Personal data about our employees, contractors and job applicants is collected and used for employment, recruitment and related administrative purposes, and is handled in accordance with our internal policies and any notice given to them.
Our premises and website
Closed circuit television is in operation at our premises for security and safety purposes. Our website may use cookies and similar technologies, including for analytics, to help the site function and to understand how it is used. You can usually control cookies through your browser settings, although some parts of the site may not work as intended if cookies are disabled.
Overseas transfers
Where personal data is transferred outside Singapore, we take reasonable steps to ensure that the recipient is bound to provide a standard of protection comparable to that required under the PDPA, through contractual or other means permitted by the PDPA.
Your Choices
Access and correction
You may request access to personal data we hold about you, and information about how it has been used or disclosed, and you may request correction of an error or omission. We may need to verify your identity, exceptions under the PDPA may apply, and a reasonable fee may be charged for an access request, in which case we will tell you before proceeding. We will respond within the time allowed by the PDPA, and if more time is needed we will tell you.
If your request concerns information recorded in a credit profile, please tell us which entry you are asking about and why you believe it is wrong or incomplete, and provide any supporting document you have. This helps us check the entry with its source.
Withdrawing consent
Where we rely on your consent, you may withdraw it at any time on giving reasonable notice, by contacting us using the details below. We will tell you the likely consequences. Withdrawal does not affect anything done before it takes effect, and does not prevent us from continuing to handle personal data where we are required or permitted to do so by law.
Marketing
You may ask us at any time to stop sending you marketing communications, and we will give effect to your request as required by law. This does not affect communications relating to a service you already hold.
Data incidents
Where a data breach is notifiable under the PDPA, we will notify the PDPC and, where required, affected individuals, in accordance with the PDPA.
Contacting us, and complaints
We have appointed a Data Protection Officer who is responsible for overseeing our compliance with the PDPA and for dealing with data protection queries, requests and complaints. Please direct any query, request or complaint to:
| Data Protection Officer | The Data Protection Officer |
| dpo@sccb.com.sg | |
| Address |
Singapore Commercial Credit Bureau Pte. Ltd.
6 Shenton Way, #17-10, OUE Downtown 2, Singapore
068809
|
We will look into your complaint and respond to you. If you are not satisfied with our response, you may refer the matter to the Personal Data Protection Commission at www.pdpc.gov.sg.
Changes to this Policy
We may revise this Policy from time to time. Where a revision materially affects how we handle personal data, we will take reasonable steps to bring it to the attention of those affected.
