ThreatLabZ
Storie di successo dei clienti
Carriere
Partner
Supporto
Contattaci
1-408-533-0288
Zscaler Cloud Portal | Admin
Zscaler Cloud Portal | Admin
Zscaler Cloud Portal | Admin
Zscaler Cloud Portal | Admin
Zscaler Cloud Portal | Admin
admin.zscloud.net
Zscaler Private Access Cloud Portal One | Admin
Portale di Zscaler Private Access Cloud | Amministratore
Home
Scopri il prodottoRichiedi una dimostrazione
Proteggi la forza lavoro

Offri agli utenti un accesso fluido, sicuro e affidabile alle applicazioni e ai dati..

Proteggi il cloud

Sviluppa ed esegui app cloud sicure, abilita la connettività zero trust al cloud e proteggi i carichi di lavoro dal data center al cloud.

Proteggi gli ambienti IoT e OT

Fornisci una connettività zero trust ai dispositivi IoT e OT e un accesso remoto sicuro ai sistemi OT.

Proteggi il B2B

Fornisci ai tuoi partner una connettività zero trust site-to-site e un accesso affidabile alle app B2B.

Zscaler Platform
Perché scegliere Zscaler?
Leadership nell settore dell'AI
SASE di Zscaler
Zscaler SSE
Riconoscimenti degli analisti
Automazione Zero Trust
Storie dei clienti
Ecosistema di partner
Riduci il tuo impatto ambientale

Resoconto di settore

Zscaler: una leader nel Magic Quadrant™ di Gartner® 2025 per il Security Service Edge (SSE)

nvaigation-gartner-report-2025
SASE Zero Trust
Accesso sicuro a Internet (ZIA)
Accesso privato sicuro (ZPA)
Esperienza digitale (ZDX)
Firewall zero trust
Cloud Sandbox
Zero Trust Browser
Zero Trust Branch
SD-WAN zero trust
Segmentazione IoT/OT
Accesso remoto con privilegi
Zscaler Cellular
Sicurezza dell'AI
Gestione delle risorse IA
AI Access Security
AI Red Teaming
Limitazioni dell'AI
Zero Trust Cloud
Secure Ingress and Egress Traffic
Secure East-West Traffic
Microsegmentazione
Zero Trust Gateway
Sicurezza dei dati
DLP per web e e-mail
DLP dell'endpoint
Sicurezza dei dispositivi personali (BYOD)
Multi-Mode CASB
Sicurezza SaaS unificata
DSPM
Microsoft Copilot Data Protection
Operazioni di sicurezza
Risk360
Tecnologia di deception
Asset Exposure Management
Gestione unificata delle vulnerabilità
Ricerca gestita delle minacce
Managed Detection & Response
Data Fabric for Security
CASI D'USO
Zero trust + AI
Business Insights
Sostituire la VPN
Protezione dalle minacce informatiche
Blocca i ransomware
Alternativa alla VDI
Proteggere i dati
Ottimizza le esperienze digitali
Distribuisci i dispositivi personali in modo sicuro
Riduci il rischio informatico
Security Operations
Continuous Threat Exposure Management
Accelerare fusioni, acquisizioni e cessioni
Soluzioni per l'industria e il mercato
Assistenza sanitaria
Servizi finanziari e bancari
Settore manifatturiero
Istruzione
Retail
Governo australiano
Governo cinese
Settore pubblico degli Stati Uniti
Governo federale degli Stati Uniti
Amministrazione statale e locale degli Stati Uniti
APJ Mid-Market / Commercial
Partner
Esplora i nostri partner
Diventa un partner
Portale partner
PARTNER TECNOLOGICI
Scopri i partner per la tecnologia
Microsoft
CrowdStrike
AWS
Okta
Rubrik
SAP
Zero trust + AI
Business Insights
Sostituire la VPN
Protezione dalle minacce informatiche
Blocca i ransomware
Alternativa alla VDI
Proteggere i dati
Ottimizza le esperienze digitali
Distribuisci i dispositivi personali in modo sicuro
Riduci il rischio informatico
Security Operations
Continuous Threat Exposure Management
Accelerare fusioni, acquisizioni e cessioni
Assistenza sanitaria
Servizi finanziari e bancari
Settore manifatturiero
Istruzione
Retail
Governo australiano
Governo cinese
Settore pubblico degli Stati Uniti
Governo federale degli Stati Uniti
Amministrazione statale e locale degli Stati Uniti
APJ Mid-Market / Commercial
Esplora i nostri partner
Diventa un partner
Portale partner
Scopri i partner per la tecnologia
Microsoft
CrowdStrike
AWS
Okta
Rubrik
SAP
Centro risorse
Libreria delle risorse
Blog
Storie di successo dei clienti
Webinar
Zpedia
Eventi e formazione
Prossimi eventi
Zenith Live
Zscaler Academy
Ricerca e servizi di sicurezza
Analisi di ThreatLabz
Aggiornamenti degli avvisi di sicurezza
Strumenti
Anteprima della sicurezza
Security and Risk Assessment
Divulga una vulnerabilità
Executive Insights App
Calcolatore del ROI della protezione dai ransomware
Community e assistenza
Customer Success Center
Zenith Community
Portale di assistenza Zscaler
Libreria delle risorse
Blog
Storie di successo dei clienti
Webinar
Zpedia
Prossimi eventi
Zenith Live
Zscaler Academy
Analisi di ThreatLabz
Aggiornamenti degli avvisi di sicurezza
Anteprima della sicurezza
Security and Risk Assessment
Divulga una vulnerabilità
Executive Insights App
Calcolatore del ROI della protezione dai ransomware
Customer Success Center
Zenith Community
Portale di assistenza Zscaler
Informazioni su Zscaler

Scopri come tutto è iniziato e le previsioni per il futuro

Partner

Incontra i nostri partner ed esplora gli integratori di sistema e le alleanze tecnologiche

Notizie e annunci

Non perdere gli aggiornamenti sulle ultime novità

Team di leadership

Incontra il nostro team di gestione

Integrazioni con i partner

Esplora le integrazioni con i nostri partner per la tecnologia

Rapporti con gli investitori

Scopri le ultime notizie, le informazioni sulle azioni e i report trimestrali

Carriere

Unisciti alla nostra missione

Conformità

Scopri di più sui nostri rigorosi standard

Centro stampa

Trova tutto ciò di cui hai bisogno per parlare di Zscaler

Culture

Our values, leadership principles, and ways of working

Zenith Ventures

Scopri di più sui nostri rigorosi standard

Environmental, Social and Governance

Scopri il nostro approccio ESG

Home
Scopri il prodottoRichiedi una dimostrazione

Zscaler and Singapore’s Personal Data Protection Act

Contents

  1. Introduction
  2. What Is Personal Data Under the PDPA?
  3. How Does Zscaler Comply with the PDPA?
  4. Helpful Links Regarding the PDPA

Introduction

Singapore’s comprehensive personal data protection law, the Personal Data Protection Act (“PDPA”), was enacted in 2012. The PDPA was amended in November 2020, with some of the amendments becoming effective as of February 1, 2021 and other amendments expected to go into effect early next year.

The PDPA regulates the collection, use and disclosure of personal data by individuals and private organizations. It does not apply to the public sector, which is subject to separate data protections laws and regulations.

With limited exceptions, the PDPA requires that an organization obtain the consent of an individual in order to process that individual’s personal data. Consent can be either express or deemed. Express consent is only valid if the individual has been provided with adequate notice of the purposes of data collection, use and disclosure. Deemed consent includes a situation where an individual (i) voluntarily provides personal data to an organization for a notified purpose and (ii) it is reasonable that the individual would voluntarily provide the personal data. In addition, consent may be deemed when an individual provides personal data to an organization with a view to entering into a contract with that organization where reasonably necessary for the conclusion of the contract.

The 2020 amendments to the PDPA expanded the concept of “deemed consent.” In addition, the amendments added two new bases for the processing of personal data: (i) legitimate interests (similar to the concept under the GDPR) and (ii) business improvement purposes.

With respect to transfers of personal data outside of Singapore, the PDPA requires that organizations provide a standard of protection that is comparable to the protection under the PDPA. An organization’s obligations under the PDPA apply regardless of whether the organization has a physical presence in Singapore.

The Personal Data Protection Commission of Singapore is responsible for overseeing and enforcing the PDPA. Among the Commission’s enforcement powers are:

• Stopping the collection, use or disclosure of personal data in contravention of the PDPA;

• Destroying personal data collected in contravention of the PDPA;

• Providing or refusing access to or correction of personal data; and/or

• Requiring payment of financial penalties.

The 2020 amendments to the PDPA increased the potential financial penalties for violations of the PDPA to 10% of annual gross turnover in Singapore or S$1 million, whichever is higher. These penalties are expected to go into effect in early 2022.

What Is Personal Data Under the PDPA?

Personal data is defined simply (but broadly) under the PDPA as any data about an individual who can be identified (i) from that data or (ii) from that data and other information to which the organization has or is likely to have access.

The PDPA does not apply to business contact information. The exclusion of business contact information encompasses an individual’s name, position name or title, business telephone number, business address, business electronic mail address or business fax number, and any other similar information about the individual that is provided for business and not solely for personal purposes.

There is no definition of sensitive information under the PDPA. However, guidance published by the Personal Data Protection Commission provides that certain types of information, such as national identity numbers, passport numbers and work permit numbers, should not be collected unless certain narrow exceptions apply. In addition, the Commission’s guidance indicates that organizations should take into account the sensitivity of personal data in determining the appropriate levels of security (e.g., encryption is recommended for personal data that would have a higher adverse impact if subject to unauthorized access).

How Does Zscaler Comply with the PDPA?

Although the PDPA has limited applicability to a “data intermediary” (defined as an organization that processes personal data on behalf of another organization), Zscaler is committed to assisting its customers in complying with the PDPA as well as satisfying Zscaler’s own obligations under the PDPA, including by taking the following actions:

1. Accountability. Zscaler has appointed individuals who are responsible for Zscaler’s compliance with the PDPA. These responsibilities include: (i) ensuring that Zscaler’s policies and processes are compliant with the PDPA; (ii) fostering a data protection culture among employees; (iii) managing personal data protection-related queries and complaints from the public; (iv) alerting Zscaler management to any risks that might arise with regard to personal data; and (v) being the point of contact for the Personal Data Protection Commission on any data protection matters.

2. Purpose Limitation. Zscaler only collects, uses, and discloses customer personal data for the purpose of providing Zscaler’s services and as otherwise permitted under the PDPA.

3. Notifications. Zscaler provides notifications of the purposes for which it collects, uses and discloses personal data and only collects, uses, and discloses personal data for such purposes.

4. Access and Correction. Zscaler facilitates its customers’ ability to access and/or correct the personal data in its possession or under its control.

5. Accuracy. Zscaler makes reasonable efforts to ensure that the personal data it collects is accurate and complete.

6. Security. Zscaler protects the personal data in its possession or under its control by making reasonable security efforts to prevent (i) unauthorized access, collection, use, disclosure, copying, modification or disposal, or similar risks; and (ii) the loss of any storage medium or device on which personal data is stored.

7. Retention Limitation. Zscaler ceases to retain personal data when (i) the purpose for which the personal data was collected is no longer being served by retention of the personal data; and (ii) retention is no longer necessary for legal or business purposes.

8. Transfer Limitation. When Zscaler transfers personal data outside Singapore, it ensures a standard of protection comparable to the protection under the PDPA.

9. Data Breach Notification. If Zscaler has reason to believe that a data breach has occurred in relation to personal data that Zscaler is processing on behalf of and for the purposes of its customers, Zscaler will, without undue delay, notify its affected customers of the occurrence of the data breach.

10. Data Portability. When the relevant amendment to the PDPA becomes effective, Zscaler will assist its customers in complying with data porting requests.

Helpful Links Regarding the PDPA

Singapore Personal Data Protection Commission: https://www.pdpc.gov.sg/

Text of the PDPA: https://sso.agc.gov.sg/Act/PDPA2012

Regulations under the PDPA: https://sso.agc.gov.sg/SL-Supp/S63-2021/Published/20210129?DocDate=20210129

Advisory Guidelines on Enforcement of the PDPA: https://www.pdpc.gov.sg/-/media/Files/PDPC/PDF-Files/Advisory-Guidelines/Advisory-Guidelines-on-Enforcement-of-DP-Provisions-1-Feb-2021.pdf?la=en

Piattaforma Zero Trust
AI Security
Sicurezza dei dati
SecOps
Prodotti e soluzioni
Scopri il prodotto
Settori
Partner
Carbonio
Informazioni su Zscaler
FAQ su Zscaler
Leadership
Carriere
Investitore
Stampa
Responsabilità
Contatti
Prezzi
Red Canary
Community
Analysts
News
Zenith Live
Eventi
Executive Insights App
Attività di ricerca di Threatlabz
Libreria delle risorse
Blog
Webinar
Zpedia
Cyber Academy
Storie di successo dei clienti
Customer Success Center
Contatta l'assistenza
Portale di Assistenza
Avvisi di sicurezza
Divulga una vulnerabilità
Analisi dei rischi per la sicurezza
Conformità
Portale partner
Home

Zscaler è universalmente riconosciuta come leader nel settore dello zero trust. Sfruttando il security cloud più grande del pianeta, Zscaler anticipa le esigenze delle aziende, nonché protegge e semplifica il business delle realtà più affermate del mondo. 

Visita la nostra pagina Facebook(opens in a new tab)Trovaci su LinkedIn(opens in a new tab)Seguici su X(opens in a new tab)Iscriviti al nostro canale Youtube(opens in a new tab)Seguici su Instagram(opens in a new tab)
Mappa del sitoPrivacyLegaleSicurezzaPreferenze sui cookie
© 2026 Zscaler, Inc.

Tutti i diritti riservati. Zscaler™ e gli altri marchi commerciali presenti su zscaler.it/legal/trademarks sono (I) marchi commerciali o marchi di servizio registrati o (II) marchi commerciali o marchi di servizio di Zscaler, Inc. negli Stati Uniti e/o in altri Paesi. Tutti gli altri marchi commerciali sono di proprietà dei rispettivi titolari.