Compliance FAQ's

What communications that were used to inform data subjects about the collection, use, and disclosure of their personal information?

The Data Subject is notified about the use and disclosure of their personal information at the time of collection.
Additionally, the user can reference out privacy policy on our website https://datadirect.com.sg/privacy-policy-data-direct/. The privacy policy informs the Data Subject how their data was collected, its use and disclosure.

Do you maintain a record of the notifications or communications sent to data subjects regarding their personal information? How are these records organized and accessible?

We record the notification provided to the data subject regarding their personal information collection, use and disclosure as described in above.
This record of notification and acceptance of the notification is recorded with the data subject personal details as a record in our database.

What is the legal basis Data Direct relies on to collect the data from your consumer? What is the legal basis you rely on to share such personal information?

The legal basis Data Direct relies on to collect the personal data from the Data Subject is opt-in consent.

How was consent obtained from data subjects, and through which channels (e.g., online froms, checkboxes, in-person signatures, etc.)?

Consent is obtained from Data Subjects through an online web page where they are presented with a sure journey where they are provided with information and respond using tick boxes that are NOT pre ticked.

Was the consent obtained explicitly (e.g., through a specific action or statement) or implicitly (e.g., implied by the data subject's behavior or continued use of a service?

Consent is obtained explicitly from Data Subject through an online web page where they are presented with a user journey where they are provided with information and respond using tick boxes that are NOT pre ticked.

Was the purpose of data processing clearly stated at the time of botaining consent, and how was it communicated to the data subject?

The Purpose for collecting, use and disclosure of the Data Subject personal data is clearly stated on the online web page where they are presented with a user journey where they are provided with information and respond using tick boxes that are NOT pre ticked.

Did the consent cover the inclusion of the data subject's information in your database for sharing with third parties, or was it a bulk-consent (e.g., general acceptance of T&Cs or privacy policy, or one consent for serval purposes?

Consent is obtained explicitly from Data Subjects through an online web page where they are presented with a user journey where they are provided with information and respond using tick boxes that are NOT pre ticked. Consent is obtained therefore from each Data Subject.

Is there a record of the consent obtained, including the date, method, and content of the consent? How is this information stored and managed within your organization?

Consent to each explicitly resented notification provided to the data subject regarding their personal information collection, use and disclosure is record in our database with the associated Data Subjects collected data. Not only do we collect the consent status but also the notification datails provided, date and source.

Is there a mechanism for data subjects to withdraw their consent, and how are such requests handled?

With consent Opt-Out we provide the sure with a contact point on our web page and privacy policy so that Data Subjects can make.
We manage the following polices and processes in respect of this area in line with GDPR and any in country compliance requirements.

  1. Data Subject Rights Policy - This policy outlines how we ensure compliance with ADPR rights, including the right to object (Article 21) and the right to withdraw consent Article.
  2. Consent Management Policy - since GDPR requires explicit, informed, and freely given consent, we have a structured approach to obtaining, recording, and revoking consent. We ensure the right to withdraw consent at any time is as easy as giving it.
  3. Opt-Out Mechanism Policy - this ensures compliance with direct marketing rules (Article 21(2)), where users must be able to opt out of marketing communications.
  4. Data Processing and Retention Policy - if an opt-out is requested, this policy ensures the organization stops processing the user's data and deletes or anonymizes it where required.
Key GDPR Articles Related to Opt-Outs we comply with:
  • Article 7(3) - Right to withdraw consent
  • Article 21(1) - Right to object to data processing
  • Article 21(2) - Right to object to direct marketing
  • Article 17 - Right to erasure (Right to be Forgotten)

If consent is withdrawn, how is the data subject's information handled thereafter, and what steps are taken to cease processing their data?

With consent Opt-Out Future Data Handling how we handle the Data Subjects data depends on the request type by the Data Subject.
Should the Data Subject seek partial opt-out the nature of the partial opt-out is recorded and the Data Subjects record is processed accordingly only withing the remaining consent. Should they seek full opt-out the status is records against the client record and no further processing is allowed.
Should they seek Right to Erasure (Article 17 GDPR) then the Data Subjects record including backups is deleted.

Have there been any instances where data subjects have raised concerns or complaints about the consent process? If so, how were these addressed?

Consumer Complaint Process, we maintain a complete Data Subject Enquiry and complaint process. This covers:

  1. Level 1 Submitting a complaint to our Data Controller with Internal Review and Response
  2. Level 2 Escalation to the Supervisory Authority and Investigation by the Supervisory Authority
  3. Level 3 Judicial Remedies
Our processes and policies cover:
"Complaint Mechanism" (Article 77 GDPR) - Right to lodge a complaint with a Supervisory Authority.
"Right to Judicial Remedy" (Article 78 GDPR) - Right to seek legal recourse if a complaint is mishandled.
"Alternative Dispute Resolution (ADR)" - Some organizations provide informal resolution mechanisms.
We record approximately 1 Level 1 enquiry per month with no Level 2 or above progression. All enquiries and process status are record in our control register.

What methods are in place to verify the accuracy of personal information at the time of collection.

We collect Personal Information directly from the Data Subject. This is done so under conditions whereby it is advantageous for the Data Subject to provide their personal data to us correctly. As such we believe that we start from a position of strength in collecting accurate UpToDate data.

At the collection point we perform a number of data qualification steps.

Input QA
QA Name: we establish the quality of the name provided Data Subject
QA address: we establish the quality of the address provided Data Subject
QA Mobile: we establish the quality of the mobile provided Data Subject
QA Email: we establish the quality of the address provided Data Subject
Repeat QA - Repeated records (Data Subjects enters details over multiple campaigns) are cross validated.

Please explain the methods used to aid in the verification and updating of personal information.

We implement several verification processes:

Campaign Targets - existing records are utilized for client campaigns in direct marketing and failed records are removed
Liveness services - liveness services such a HLR, email bounce, left address, call center dial flags and mail services are run periodically to confirm data.
Data Subject Requests - the Data Subject has a right to update their details with we provide for in this section.

How do we ensure the accuracy of the personal data shared?

WE ensure the accuracy of the personal data shared by following the processes and policies below:
Point of collection data Quality assurance.
Ongoing verification and maintenance services (liveness).
Data refresh cycle and internal cross validation.