The story in full
What happened, and the only explanation that fits all of it
A motorcyclist suffers a traumatic brain injury in a road accident. He has no memory of what
happened to him. He asks the two condominiums flanking the road for the CCTV footage that
captured the event, not only to support an insurance claim, but to understand what happened to him at all.
Both refuse. The footage is overwritten. The regulator accepts the condominiums’ explanations
and finds no breach. Every legal challenge receives the same one-line response. The oversight body
mirrors the same pattern. Across 374 published enforcement cases (compiled June 2026), the Access Obligation has
produced zero breach findings. This is not a sequence of unrelated failures. It has one explanation.
1. What the Complainant needed
On 13 April 2024, the Complainant was injured when a taxi cut into his lane on Cairnhill Road.
The impact caused a traumatic brain injury, a subarachnoid haemorrhage (bleeding around the brain). The Complainant
lost all memory of the accident and the period surrounding it. The taxi driver was subsequently
charged under the Road Traffic Act for careless driving.
The Complainant needed the CCTV footage from the two condominiums flanking the road for two
distinct reasons: first, to understand what had happened to him, the footage was the only record
of an event he has no memory of; second, to support an insurance claim against
the driver. Security staff at both condominiums had already identified the relevant footage within
minutes of the accident. It existed, it was findable, and it showed the taxi cutting into the lane.
Source: PDPC Decision, MCST 4599 (2025 SGPDPC 3) ↗ · NUH discharge records (subarachnoid haemorrhage, April 2024), in the Complainant’s possession
2. What both condominiums did
Both condominiums refused on grounds that do not appear in s.21(3) or the Fifth Schedule of the PDPA, the only provisions that authorise a lawful refusal of an access request.
The Scotts Tower (MCST 4599) cited “privacy” as a blanket reason; when challenged,
claimed no footage existed. PDPC’s own finding later confirmed footage existed until 30 April, 13 days after that verbal denial.
Suites@Cairnhill (MCST 3615) provided its DPO, who told the Complainant in writing:
“Only by police direct/order the MCST to disclose the footage that MCST is obliged to do so.”
When the Complainant cited the correct PDPA Advisory Guidelines in reply, the DPO responded:
“It seems to me you are having difficulty understanding our position”, and refused further communication.
Neither organisation was acting recklessly. They were acting in a regulatory environment
where the Access Obligation has never produced a breach finding, and in this case, it did not.
Source: PDPA 2012, s.21(3) and Fifth Schedule, Singapore Statutes Online ↗ · PDPC Advisory Guidelines for Management Corporations, 17 May 2022, §3.7
3. What PDPC did
PDPC did not test the condominiums’ stated refusal grounds against s.21(3) or the Fifth Schedule.
Instead, it substituted its own reasoning in each case: “not personal data” for MCST 3615
(the MCST had not said this); “footage overwritten before formal refusal” for MCST 4599
(ignoring the verbal refusal and the false “no footage” claim that preceded the overwrite).
To reach the MCST 3615 finding, PDPC applied a “clarity” standard, face or licence plate
must be visible, that does not appear in the PDPA. The statute defines personal data by identifiability,
not image quality.
When the Complainant challenged these findings across nine legal questions spanning six PDPA sections,
PDPC’s response to every question was identical: “The Guidelines are not determinative;
the PDPA takes precedence.” PDPC did not name which guideline, which PDPA clause, or how they
conflict. The decisions were withheld until the Complainant escalated to the Prime Minister’s
Office, government ministers, and the President’s Office. PDPC then declared the matter closed.
Source: Decision, MCST 4599 ↗ · Summary, MCST 3615 ↗ · PDPA 2012, s.2(1) ↗
4. What the enforcement register shows
These cases were not outliers. Across 374 published enforcement actions in PDPC’s public register (compiled June 2026),
the Access Obligation (s.21) has produced zero breach findings. Not one. The dominant pattern of
enforcement is protection of data (s.24) and consent violations (s.13), obligations that run
against organisations mishandling data they hold. The access obligation, the right of a citizen
to retrieve their own data from an organisation, is the least enforced provision in the entire register.
The clarity test PDPC invented in MCST 3615, applied consistently, explains this. If face or licence
plate must be visible for CCTV footage to qualify as personal data, the majority of real-world CCTV
footage falls outside access protection entirely. Any organisation can deny an access request simply
by asserting the footage is too unclear to identify anyone. PDPC has given no tools to challenge
that assertion.
Of these 374 decisions, only two have involved a complainant demanding access to their own CCTV data and being refused, and both were the Complainant’s. The case-by-case enumeration is in the narrative section of this site.
Source: enforcement-index.html, this site, generated from the public PDPC register
5. The explanation that fits
Ordinary regulatory failure is uneven. It makes mistakes in different directions, produces inconsistent
outcomes, and responds differently to different challenges. What is documented here is coherent:
every decision, at every level, in the same direction. PDPC substituted invented reasoning for the
MCSTs’ actual stated grounds. IMDA, the oversight body, replicated the same pattern of delay
and non-engagement. The IAU found “no wrongdoing” without addressing the material facts.
Nine legal questions received one identical non-answer. Zero breach findings across 374 cases.
This site does not assert that a policy of non-enforcement was explicitly decided or that any individual
acted in bad faith. What the documented record shows is that the evidence is consistent with a de facto
policy of non-enforcement of the Access Obligation for CCTV footage, and inconsistent with ordinary
regulatory error. The clarity test is the legal mechanism. The zero breach history is the outcome.
The non-engagement is what follows when a regulator cannot defend its position on the merits.
It is one thing not to actively enforce a statutory right. That is a policy choice Parliament can
examine. It is another to redefine the statutory definition of personal data to defeat a request,
to accept refusal grounds that appear nowhere in the statute, to declare one’s own published
guidelines wrong without saying why, and then to cease communication. That is not non-enforcement.
It is the active dismissal of a legitimate complaint through reasoning that departs from the
law the regulator is sworn to apply.
The Complainant has asked PDPC to correct this record nine times. The nine questions and
PDPC’s responses are in the narrative section of this site.