Categories: PDPA

by Koh Teng Teng

Share

PDPAJanuary 5th, 2026

Share

A resident emails the managing agent asking for CCTV footage of the car park from last Tuesday because their car was scratched. The managing agent forwards it to the security company. Security says the council should decide. Three weeks pass. The footage is overwritten by the system’s automated cycle.

That sequence is a strict breach of the Personal Data Protection Act (PDPA), and it is the Management Corporation Strata Title (MCST) that answers for it.

📌 Key Takeaways: MCSTs & PDPA Compliance

  • Ultimate Accountability: The MCST is legally responsible for data breaches and access requests, not the security guard or managing agent.
  • Halt the Overwrite: You must immediately suspend automated CCTV overwriting the moment a valid access request is received.
  • Masking is Expected: Blanket refusals because “other people are in the video” are not permitted. Masking/blurring third parties is required.
  • Mandatory DPO: Every MCST must formally appoint a Data Protection Officer (DPO).

Why Is the MCST Accountable Instead of the Managing Agent?

Managing agents and security vendors handle personal data on the ground, but the MCST remains responsible for how that data is managed. The PDPC’s enforcement decisions (such as the May 2025 Case No. DP-2405-C2318) make this boundary incredibly clear: when something goes wrong, the MCST—not the contractor—is held accountable and fined.

Under the Personal Data Protection Act 2012, an organisation remains fully responsible for personal data in the possession or under the control of a “data intermediary” acting on its behalf. As we’ve seen in broader regulatory enforcement trends across Singapore, outsourcing the operational work does not outsource the legal obligation.

What Does the PDPA Require When Someone Requests CCTV Footage?

Residents, visitors, and third parties can legally ask for access to personal data about themselves—most commonly CCTV footage following a localized incident. These requests cannot be ignored, delayed indefinitely, or rejected outright simply because other people appear in the background of the footage.

The PDPA requires an organisation to respond to an access request as soon as reasonably possible. Where the MCST cannot fulfill the request within 30 days, it must inform the requestor in writing—within that initial 30-day window—stating the exact time by which it will respond.

The PDPC expects MCSTs to:

  • Acknowledge and assess the request properly upon receipt.
  • Consider practical steps such as masking/blurring other individuals in the frame.
  • Respond within the statutory 30-day timeframe.
  • Keep clear, time-stamped records of how the decision was made.

How Should an MCST Process a CCTV Access Request?

To avoid regulatory penalties, MCSTs and managing agents should adopt this strict operational sequence:

✅ Step-by-Step Action Plan

  1. Log It Immediately: Date, requestor, what is sought, incident date/time, and location. The 30-day clock starts when the request is received by anyone acting for the MCST (e.g., the security guard), not when it finally reaches the council.
  2. Suspend the Overwrite: This is the step most often missed. CCTV systems typically overwrite on a 14- or 30-day fixed cycle. If the footage is gone by the time the council meets, the MCST has failed to respond to a valid request and failed to preserve data.
  3. Verify Identity: Confirm they are requesting their own personal data. A request for footage of someone else entirely is not an access request—it is a different legal question.
  4. Assess Withholding Rules: The PDPA sets out circumstances where an organization must not provide access (e.g., revealing personal data about another individual). However, third parties appearing in footage is a reason to consider redaction, not automatic refusal.
  5. Consider Masking: Blurring or pixelating other individuals is what the PDPC expects you to consider. If your system or vendor cannot do it, that is a procurement gap you need to fix.
  6. Decide and Document: Record who decided, on what basis, and with reference to which PDPA provision. The assessment record is as important as the outcome.
  7. Respond in Writing: Fulfill the request within 30 days, or issue a written notification of an extended date.

Struggling with PDPA Compliance for Your MCST?

Don’t let mishandled CCTV requests lead to PDPC fines. Partner with Alder to appoint an outsourced Data Protection Officer (DPO) and streamline your council’s compliance.

Explore Outsourced DPO Services

Where Do MCSTs Typically Go Wrong?

During PDPC investigations, several recurring failures consistently emerge across condominiums and commercial estates:

  • No Owner for the Request: The request circulates between the managing agent, security team, and council with nobody accountable for the 30-day clock.
  • Footage Overwritten Before a Decision: The single most common failure, and entirely preventable with an immediate preservation protocol.
  • Blanket Refusal: Denying access simply because “others are in frame” is not a legally permissible default position.
  • Generic Managing Agent Policies: A template that describes some other development’s arrangements will not hold up. Policies must reflect how this MCST actually operates.
  • No DPO (or a DPO in name only): Appointing an estate manager who does not know they hold the legal title of DPO is a very common regulatory finding.

Why Doesn’t Delegating to a Managing Agent Remove Liability?

Even where a managing agent or security contractor operates the physical CCTV system and directly receives access requests, the MCST remains the Data Controller. Just as modern businesses must strictly govern third-party tech vendors (as seen in the recent PDPC Generative AI and data guidelines), an MCST must:

  • Appoint a Data Protection Officer (DPO) and make their business contact information publicly available.
  • Maintain clear, MCST-specific data protection policies and procedures.
  • Ensure contractors know exactly what to do when a request arrives, and by when.

The Contractual Gap: If your managing agent agreement does not specify retention periods, preservation protocols, masking capabilities, and escalation timelines, you are relying purely on goodwill rather than legal protection.

What Other CCTV Obligations Must MCSTs Follow Beyond Access Requests?

Access requests are just one obligation. An MCST operating CCTV should also have settled:

  • Notification: Clear signage informing individuals that recording takes place and for what specific purpose (e.g., security).
  • Purpose Limitation: Footage collected for security should not be casually repurposed (e.g., monitoring staff break times).
  • Retention: A defined period (e.g., 30 days) applied consistently, with footage disposed of when no longer needed.
  • Access Control: Strict, logged limits on who can physically or digitally view the footage.

Frequently Asked Questions (FAQ)

How long does an MCST have to respond to a CCTV access request?

As soon as reasonably possible. If the MCST cannot respond within 30 days, it must formally notify the requestor in writing within those 30 days stating exactly when it will fulfill the request.

Can an MCST refuse a request because other residents appear in the footage?

Not as a blanket position. The MCST is expected to consider whether masking or redaction (blurring faces) makes disclosure practicable, and must document its assessment either way.

Can a resident request footage of another person?

No. An access request under the PDPA strictly covers the requestor’s own personal data. A request for footage of someone else is not an access request and should be assessed entirely differently.

Who should be the MCST’s DPO?

The PDPA requires an appointed individual, but it does not require the role to be internal. Many MCSTs successfully appoint an external, outsourced DPO. The appointment must be real—the person must be contactable, informed, and possess the authority to act.

What if the footage has already been overwritten?

The MCST must still respond to the requestor. It should explain the position and be prepared to account to the PDPC regarding its retention practices and whether reasonable preservation steps were taken once the request was received.

How Can Alder Support Your MCST Council?

Good data protection is not about doing more. It is about knowing what to do when it matters. Alder’s outsourced compliance and DPO services are designed to make PDPA compliance highly practical for MCSTs:

  • Acting as the MCST’s officially appointed Data Protection Officer.
  • Putting clear, easy-to-follow SOPs in place for access requests and data breaches.
  • Drafting formal responses and assessments so the council is not left guessing.
  • Reviewing managing agent and security vendor contracts for dangerous data protection gaps.
  • Supporting the MCST if a resident complaint or PDPC regulatory query arises.

Protect Your MCST from Regulatory Fines

Need help drafting a bespoke data protection policy or reviewing your CCTV handling procedures? Contact Alder’s PDPA compliance specialists today.

Contact Alder Compliance

Disclaimer: This article is for general informational purposes only and does not constitute formal legal advice. For guidance tailored to your MCST’s specific arrangements, consult Alder Compliance.

About the Author: Koh Teng Teng

Teng Teng is the Compliance Director at Alder. She holds a Bachelor of Arts from the National University of Singapore and is an Associate of The Chartered Governance Institute (CGI) and the Chartered Secretaries Institute of Singapore (CSIS). With over 7 years of experience in compliance and regulatory advisory, she leads Alder’s outsourced compliance service delivery, helping clients strengthen governance and meet Singapore regulatory requirements.

Related Posts

  • Alder Corporate Services can help your Singapore business comply with PDPA regulations. Our outsourced DPO services ensure proper NRIC authentication procedures before 2027 enforcement.

  • Most MCSTs assume data protection issues only arise when there is a complaint. In reality, many breaches happen quietly. Weak passwords, unsecured systems, or unclear responsibilities between managing agents and vendors. By the time something goes wrong, it is often too late.