Author: Lawyer Zhang Jingxinyue, PRC-qualified Lawyer | Singapore Registered Foreign Lawyer
Note: Against the backdrop of globalization and the rapid development of e-commerce and cross-border trade, large amounts of personal information are collected and used by third parties for various reasons. Countries around the world attach great importance to data security and have comprehensively strengthened data protection by promulgating policies and regulations, reinforcing regulatory enforcement, and improving their technical capabilities for security governance.
As Asia’s commercial center, Singapore has attracted many telecommunications and Internet service providers to deploy servers and data centers there because of its favorable geographic location and well-developed infrastructure. This has made Singapore a hub for network traffic in Asia and one of the key exchange points for the global Internet. At the same time, Singapore has a well-developed data law framework, and its level of data protection ranks among the highest in the world.
For Chinese businesses entering the Singapore market, particular attention must be paid to complying with Singapore’s data requirements in order to avoid regulatory violations. This article introduces Singapore’s data protection framework, cases involving penalties for violations, and recommendations for data risk management, providing a reference for businesses planning their Singapore data-compliance arrangements before expanding overseas and for maintaining compliance in daily operations.
01 Overview of Singapore’s Data Protection Legal Framework
Singapore has a 12-year legislative history in the field of personal data protection. Its data protection framework is primarily based on the 2012 Personal Data Protection Act (the “PDPA”), a comprehensive statute governing the collection, use and disclosure of personal data. The Act came into effect in stages beginning in January 2013. It gives individuals the right to have their personal data protected and sets out detailed requirements for institutions and businesses when collecting, using or disclosing personal information, ensuring that individuals’ personal data is not misused and that legal protection is available when their rights are infringed.
To better implement the Personal Data Protection Act, Singapore has also adopted regulations and guidelines on personal data protection in specific sectors, such as telecommunications, real estate, education, healthcare and social services. These subsidiary laws guide businesses in protecting personal data and are continuously revised and improved in response to changing circumstances.
The 2014 Personal Data Protection Regulations are the principal subsidiary legislation under the PDPA and focus on access to and correction of personal data and the transfer of personal data. Since 2018, Singapore has seen several notable developments in personal data protection legislation. These include an important case issued on January 14, 2019, the Consultation Guidelines on the Personal Data Protection Act for National Identity Numbers and Other Types of National Identification Numbers issued on August 31, 2018, and the consultation draft of the Personal Data Protection (Amendment) Bill issued on May 14, 2020, all of which reflect new legislative trends.
1. Regulations
- Personal Data Protection (Composition of Offences) Regulations 2013;
- Personal Data Protection (Do Not Call Registry) Regulations 2013;
- Personal Data Protection (Enforcement) Regulations 2014;
- Personal Data Protection Regulations 2014.
The four regulations above came into effect together on July 2, 2014.
- Personal Data Protection (Appeal) Regulations, which came into effect on January 23, 2015.
2. Guidelines
The Personal Data Protection Commission of Singapore issues consultation guidelines under section 49(1) of the Personal Data Protection Act. These guidelines explain how the Commission interprets the provisions of the Act.
There are seven principal consultation guidelines:
- Consultation Guidelines on Key Concepts in the Personal Data Protection Act, revised on October 9, 2019;
- Consultation Guidelines on Selected Topics under the Personal Data Protection Act, revised on October 9, 2019;
- Consultation Guidelines on the Do Not Call Registry, revised on July 27, 2017;
- Consultation Guidelines on Consent for Marketing Purposes, issued on May 8, 2015;
- Consultation Guidelines on the Enforcement of Data Protection Provisions, issued on April 21, 2016;
- Consultation Guidelines on the Application of the PDPA to Election Activities, issued on August 8, 2017;
- Consultation Guidelines on the Personal Data Protection Act for National Identity Numbers and Other Types of National Identification Numbers, issued on August 31, 2018.
The Personal Data Protection Commission also recognizes that different sectors may face sector-specific issues. It has therefore developed sector-specific consultation guidelines to address such issues. These guidelines were developed based on inquiries and feedback received by the PDPC from members of relevant industries and in close cooperation with the relevant sector regulators. They mainly include the following seven items:
- Consultation Guidelines for the Telecommunications Sector, issued on May 16, 2014;
- Consultation Guidelines for the Real Estate Agency Sector, issued on May 16, 2014;
- Consultation Guidelines for the Education Sector, revised on August 31, 2018;
- Consultation Guidelines for the Healthcare Sector, revised on March 28, 2017;
- Consultation Guidelines for the Social Service Sector, revised on August 31, 2018;
- Consultation Guidelines on Taxi Records in Transport Services, revised on May 22, 2018;
- Consultation Guidelines on Corporate Governance, issued on March 11, 2019.
The Personal Data Protection Commission provides opinions and recommendations on industry guidelines formulated by industry associations under the Personal Data Protection Act. The industry guidelines issued to date include the following two items:
- LIA Code of Practice for Life Insurance Companies under the Singapore Personal Data Protection Act, issued on April 1, 2015;
- LIA Code of Conduct for Financial Adviser Representatives under the Personal Data Protection Act, issued on April 1, 2015.
In addition, the Personal Data Protection Commission has published a series of other guidelines for reference:
- Notification Guidelines, revised on September 26, 2019;
- Guidelines on Personal Data Protection in Electronic Media, revised on January 20, 2017;
- Practical Guidelines on the Transmission of Payment Card Magnetic Stripes through Card Readers, issued on April 21, 2016;
- Guidelines on Handling Access Requests, issued on June 9, 2016;
- Guidelines on Data Protection Clauses for Agreements Relating to the Processing of Personal Data, issued on July 20, 2016;
- Guidelines on Building Websites for Small and Medium-Sized Enterprises, revised on July 10, 2018;
- Guidelines on the Processing of Personal Data on Physical Media, revised on January 20, 2017;
- Guidelines on Preventing Accidental Disclosure when Processing and Sending Personal Data, issued on January 20, 2017;
- Guidelines on Developing a Data Protection Management Programme, issued on July 15, 2019;
- Guidelines on Data Protection Impact Assessments, issued on November 1, 2017;
- Guidelines on Basic Data Anonymization Techniques, issued on January 25, 2018;
- Guidelines on Institutional Printing Processes, issued on May 3, 2018;
- Technical Guidelines on NRIC and Other National Identification Numbers under the PDPA Consultation Guidelines, revised on August 26, 2019;
- Guide to Managing Data Breaches 2.0, issued on May 22, 2019;
- Guidelines on Active Enforcement, issued on May 22, 2019;
- Guidelines on Data Protection by Design for Information and Communications Technology Systems, issued on May 31, 2019;
- Guidelines on Accountability under the Personal Data Protection Act, issued on July 15, 2019.
02 Regulatory Authority for Data Protection: the Personal Data Protection Commission (PDPC)
To better administer and enforce the PDPA, the Singapore Government established the Personal Data Protection Commission (PDPC) on January 2, 2013. The PDPC is responsible for administering and enforcing matters relating to the Personal Data Protection Act, building a trusted environment between businesses and users, contributing to the development of Singapore’s economy, and representing the Singapore Government in international data protection matters.
The PDPC is also responsible for overseeing the development and operation of the Do Not Call (DNC) Registry. It prohibits organizations from sending marketing messages to Singapore telephone numbers registered on the DNC Registry, ensuring that individuals receive only the telephone marketing messages they want and helping businesses improve customer relationships by increasing consumer confidence and trust.
03 Main Content and Application of Singapore’s PDPA
1. Comparison between Singapore’s PDPA and the EU GDPR
The EU General Data Protection Regulation (GDPR) came into effect on May 25, 2018. The GDPR attaches great importance to personal data protection and regulation and establishes a series of protective thresholds and mechanisms. It has been described by practitioners and academics as the strictest personal data protection legislation in history. A brief comparison between the PDPA and the GDPR is set out below:
2. Scope of Application of the PDPA
The core issue under the PDPA is how “personal data” is defined. The Act defines it as data relating to a living or deceased individual, regardless of whether the data is true. If the data, either by itself or together with other information obtained or likely to be obtained by an organization, can identify an individual, it falls within the definition.
For the entities covered, the PDPA uses the term “organization,” which includes individuals, sole proprietorships, partnerships, companies and other forms of organization that collect, use or disclose personal data within or outside Singapore. However, the following entities and activities are not subject to the regulations:
- Individuals acting in a personal or domestic capacity;
- Employees acting in the course of their employment by an organization;
- Government agencies.
The PDPA also applies to all personal data stored in electronic or non-electronic form, except for the following data:
- Personal data contained in records that have existed for at least 100 years;
- Personal data relating to a deceased individual who has been dead for more than 10 years;
- Business contact information, such as an individual’s name, position, business telephone number, address and email address.
Overall, the PDPA applies to individuals and business entities that collect, use or disclose personal data inside or outside Singapore, but does not regulate private conduct by individuals or families, employees acting in the performance of their duties, or government conduct. The law takes a relatively broad approach to personal data, focusing on an abstract identifiability test rather than specifically listing which types of data constitute personal data. Its protection extends to data concerning living individuals and qualifying deceased individuals, but excludes business contact information.
3. Consent
Under Singapore’s PDPA, the legality of processing personal data is primarily based on the consent of the data subject. Under section 14 of the PDPA, unless a specific statutory exemption or deemed-consent provision applies, an organization must, in principle, provide notice and obtain the individual’s express consent when collecting, using or disclosing personal data. After giving consent, the individual retains the right to withdraw it at any time by notifying the organization.
Importantly, the PDPA permits an organization, subject to specific conditions, to collect, use and disclose personal data directly for business improvement purposes without obtaining consent. This differs from China’s Personal Information Protection Law, which permits consent exemptions only in circumstances such as the processing of publicly available personal information or matters involving the public interest, while express consent is required when personal information is processed for business-improvement purposes.
Although the PDPA is relatively permissive regarding the use of personal data for business purposes, processing activities that are not for business improvement cannot be exempted from the consent requirement merely to prevent abuse of this provision. For example, the PDPA expressly provides that express consent must be obtained when personal data is used for direct marketing or the sending of marketing messages. In such circumstances, an organization cannot rely on a consent exemption. These provisions are intended to ensure that personal data processing is conducted on a reasonable and transparent basis and that the rights and interests of data subjects are protected.
4. PDPA Data Processing Principles
The PDPA sets out nine principles that all organizations must observe when processing personal data.
- Consent obligation: When collecting, using or disclosing personal information, an organization must first obtain the individual’s authorized consent and must allow the individual to withdraw consent after receiving reasonable notice. Once consent is withdrawn, the organization must stop collecting, using and/or disclosing the individual’s personal data.
- Purpose limitation obligation: An organization may collect, use or disclose personal data only for purposes to which the individual has consented, and may use the data only within the reasonable scope of the products or services provided by the organization.
- Notification obligation: Before collecting, using or disclosing personal data, an organization must explain to the individual the reasons for collecting the data and the purpose and scope of its use.
- Access and correction obligation: Upon receiving a request from an individual, an organization should provide information about how the individual’s personal data has been used and disclosed. If the individual asks for an error or omission in the personal data to be corrected, the organization must accept the request as soon as possible.
- Accuracy obligation: An organization must ensure that personal data is complete and accurate.
- Protection obligation: An organization must adopt necessary security measures to protect personal data and prevent unauthorized access, collection, use, disclosure, copying, alteration, disposal or similar threats and risks.
- Retention limitation obligation: An organization may retain personal data only for purposes required by law or business needs. If retaining the data is no longer necessary to achieve a business purpose or the purpose for which it was collected, the organization must stop retaining it or remove its association with the particular individual.
- Transfer limitation obligation: If an organization needs to transfer personal data overseas, such as by storing data in the cloud, it must ensure that the recipient country can provide a level of data protection comparable to that under the PDPA. This comparability standard may be achieved in the following ways:
- The organization enters into a data-processing agreement with the recipient, requiring the recipient to provide a level of personal data protection comparable to that required by the PDPA;
- The organization demonstrates that the applicable law of the country or region to which the personal data will be transferred provides a corresponding level of data protection;
- The organization obtains the data subject’s consent to the transfer, with that consent satisfying the applicable conditions.
- Openness obligation: An organization must adopt appropriate measures and policies to ensure that its conduct complies with the obligations under the PDPA and must make information about its policies and practices publicly available. In practice, an organization should appoint at least one data protection officer to ensure its compliance with the PDPA and provide the officer’s contact details so that individuals wishing to understand the organization’s data protection policies can contact the officer.
5. The PDPA in Employment Relationships
- Does an enterprise need to obtain a job applicant’s consent to collect and use the applicant’s personal data?
- When an individual voluntarily provides personal data to an enterprise in the form of a job application, the individual is regarded as having consented to the enterprise collecting, using and disclosing the data to evaluate the application.
- Once the applicant is hired, it is reasonable for the enterprise to continue using the personal data provided in the application form to manage its relationship with that individual.
- If the enterprise wishes to use the personal data for purposes outside the circumstances above, or if no applicable exception under the PDPA applies, it must notify the employee and obtain consent for that use.
- Can an enterprise retain the personal data of job applicants who were not hired?
- The data may be retained only for the period required for a lawful purpose.
- An enterprise should also note that a job applicant has the right to access and request correction of personal data about the applicant held by the enterprise.
- Upon request, the enterprise must also inform the individual how the individual’s personal information was used during the preceding year.
- If the individual was ultimately not hired and the personal information consists of evaluative comments retained solely for evaluation purposes, the enterprise is not required to provide that information to the individual. In that case, the enterprise does not need to notify the individual of the evaluative opinions generated during the hiring decision.
- Can an enterprise use information on a business card for recruitment? Section 4(5) of the PDPA provides that business contact information supplied for commercial purposes, including an individual’s name, position, business telephone or fax number, business address, business email address and other similar information, is outside the scope of the organization’s protection obligations.
- How does the PDPA apply to employees’ employment records?
- Employees should be informed of the purpose for collecting their information and the circumstances in which their personal data needs to be used or disclosed, and consent should be obtained before the data is collected, used or disclosed.
- In many circumstances, an employer must obtain consent at the beginning of the relationship, when appointing a new employee, to collect, use and disclose the employee’s personal information. If more personal data is needed at different stages of the employment relationship, the employee’s consent should be obtained again. An employee may withdraw consent in accordance with the PDPA.
- If information is collected, used or disclosed for evaluative purposes, including determining whether an individual is suitable for employment, promotion or continued employment, or reviewing qualifications, the individual’s consent is not required. Examples include obtaining a reference from a former employer to determine suitability or obtaining performance records or other relevant information to assess an employee’s performance.
- Legal scope of collecting, using and disclosing personal data for the purpose of managing or terminating an employment relationship
- Although an employee does not need to give consent, the employer must notify the employee of the purpose for collecting, using or disclosing personal information. The PDPA does not prescribe the form or method of notification.
- To avoid doubt, an enterprise should provide employees with a general notice of the purposes for collecting, using and disclosing data, such as performance evaluation, and should provide a corresponding notice before collecting an employee’s personal information each time.
- Personal information used for the purpose of managing or terminating an employment relationship includes:
- Using an employee’s bank-account information to pay salary;
- Monitoring how an employee uses computer-network resources and the company’s internal network during working hours;
- Managing employee-benefit plans, such as training or education allowances.
- An enterprise may continue to retain a former employee’s personal data as long as there is a valid or lawful purpose. However, personal data should not be retained where no clear purpose has been defined. Retaining data for an uncertain purpose and an uncertain period correspondingly increases the risk of violating the PDPA.
- What “responsibility” does a company bear if an employee fails to comply with the PDPA?
- An enterprise is responsible for any violation caused by an employee during the employment period. In particular, any act undertaken by an employee in the course of employment, whether or not it was approved by the employer in advance, is the responsibility of the enterprise.
- The PDPA’s definition of “employee” includes volunteers, and its definition of “employment” includes work performed in an unpaid volunteer relationship.
6. Legal Consequences of Violating the PDPA
An organization that violates its data protection obligations under the PDPA may face the following penalties:
- An order to stop the unlawful collection, use or disclosure of personal data;
- An order to delete unlawfully collected personal data and/or;
- An order to provide the affected individual with access to and correction of personal data;
- Following subsequent amendments to the PDPA, a fine of up to 10% of the organization’s annual turnover or SGD 1 million, whichever is higher.
In addition, an individual may lodge a complaint with the relevant department of the PDPC to seek effective judicial relief, obtain an injunction, or recover compensation from the organization for losses caused by its conduct.
04 Scope of Application of the Consultation Guidelines on the Personal Data Protection Act for National Identity Numbers and Other Types of National Identification Numbers
On August 31, 2018, the PDPC issued the Consultation Guidelines on the Personal Data Protection Act for National Identity Numbers and Other Types of National Identification Numbers (the “Identity Number Guidelines”), which formally took effect on September 1, 2019. The Identity Number Guidelines specifically regulate the collection, use and disclosure of Singapore national identity cards and identity numbers.
Under the Identity Number Guidelines, organizations generally must not collect, use or disclose national identity numbers or copies of identity documents. The rules concerning national identity numbers also apply to birth-certificate numbers, foreigner identification numbers and work-pass numbers, which are collectively referred to as “other types of national identification numbers” in the Identity Number Guidelines, as well as passport numbers. Where there is a genuine need to collect a passport number, the organization should limit collection to a partial passport number and ensure an appropriate level of security to protect the passport number collected, unless otherwise permitted by law. Examples are set out below.
Situations in which a Singapore identity number is needed:
✓ When a new employee joins an enterprise
✓ When registering at a hotel
✓ When seeking medical treatment at a clinic or hospital
✓ When applying for a mobile-phone plan
✓ When enrolling in a private education institution
Situations in which a Singapore identity number is not needed:
x When redeeming free parking
x When joining any retail membership club
x When registering for a service or submitting service feedback
x When purchasing movie tickets online
x When participating in a prize draw
05 Penalty Cases
Violations of Singapore’s PDPA may result in substantial fines. The maximum fine is SGD 1 million, approximately RMB 5.35 million, or 10% of an organization’s annual turnover in Singapore, whichever is higher. Individuals who suffer loss or damage because of a breach of the data protection obligations under the PDPA have a private right of action and may bring civil proceedings against the organization. Since the PDPA came into effect, the PDPC has penalized a number of organizations for failing to protect personal data or infringing personal data rights.
According to publicly available information released on August 6, 2019, the PDPC fined five organizations for failing to comply with the Personal Data Protection Act:
- CDP disclosed the personal data of CDP account holders without authorization and was fined USD 24,000;
- Toppan Security Printing disclosed the personal data of CDP account holders without authorization and was fined USD 18,000;
- Horizon Fast Ferry was fined USD 54,000 for failing to formulate and implement a data protection policy and failing to implement reasonable security measures to protect its customers’ personal data;
- Genki Sushi was fined USD 16,000 after a ransomware attack caused by its failure to implement reasonable security measures to protect its employees’ personal data;
- Championtutor was fined USD 5,000 for failing to appoint a data protection officer and failing to formulate compliance policies.
The most serious and influential personal-data breach case was the 2019 SingHealth group incident. Between June 27 and July 4, 2018, the case-record database system of Singapore Health Services Pte. Ltd. (“SingHealth”) was attacked. Hackers unlawfully accessed and copied the personal data of nearly 1.5 million patients and the prescription records of nearly 1.6 million outpatient patients, resulting in a large-scale data breach and making it the most serious personal-information breach in Singapore’s history. The PDPC commenced an investigation after receiving complaints from affected individuals. After considering the evidence, the parties’ representations and mitigating circumstances, including the effective remedial measures taken by the companies after the incident, the PDPC issued fines of SGD 250,000, approximately RMB 1.25 million, against SingHealth and SGD 750,000, approximately RMB 3.75 million, against Integrated Health Information Systems Pte. Ltd. The PDPC held that, although SingHealth as a healthcare institution could outsource some functions to a service provider, it could not transfer its statutory obligations under the PDPA to another party. The two companies ultimately voluntarily admitted the data breach, accepted the PDPC’s findings, agreed to assume responsibility in accordance with the PDPC’s directions, and considered the penalties reasonable and appropriate.
On January 14, 2022, Nature Society Singapore, a non-governmental organization, was fined SGD 14,000, approximately RMB 66,000, by the PDPC for violating Singapore’s Personal Data Protection Act. The PDPC brought multiple allegations against Nature Society Singapore: its website database had failed to take reasonable measures to protect personal data; it had failed to appoint a data protection officer; and it lacked written policies and operating procedures for complying with the PDPA.
On November 10, 2023, the PDPC fined Ascentis Pte Ltd SGD 10,000, approximately RMB 53,539, because the company had not adopted sufficient security measures to protect the personal data in its possession or control. The fine arose from a data breach in 2022. On September 13, 2022, the PDPC received a notification from Singapore’s computer emergency response team stating that the e-commerce platform of Starbucks Singapore had leaked the personal data of 332,774 users and that the data was being traded online. After investigating, the PDPC found that Ascentis, as the platform developer, had breached the “protection obligation” under section 24 of the PDPA.
On November 10, 2023, the PDPC fined Tokyo Century Leasing (Singapore) Pte. Ltd. SGD 82,000, approximately RMB 439,025, because the company had failed to comply with the protection obligation under section 24 of the PDPA and had not taken appropriate security measures to protect the personal data in its possession or control.
06 What Aspects of Data Compliance Should Singapore Businesses Self-Assess?
- Is personal data stored in an internal system or in the cloud through a third-party provider?
- Does the data storage arrangement satisfy the following prerequisites:
- Whether the current IT infrastructure supports it;
- Whether sufficient security and cybersecurity measures are in place to prevent data from being damaged.
- If data is stored through a third-party cloud service, what security measures are in place? Examples include annual independent penetration testing, ISO 27001 information security management system certification and other relevant certifications.
- In the event of a power outage, are there appropriate backup measures for retrieving and restoring “lost” data, including backup measures provided by a third-party cloud service?
- When personal data is transferred, is it encrypted for security purposes, and does the arrangement comply with the relevant PDPA and/or GDPR policies?
- Other internal measures:
- Conducting a risk assessment to determine whether information-security arrangements are appropriate;
- Using a web application firewall;
- Using anti-virus software with automatic updates;
- Regularly applying security updates to operating systems and software;
- Regularly reviewing user access.
Businesses must note that they are required to comply with the following rules under the “2012 Personal Information Protection Regulations”: personal information data collected before the PDPA came into effect on July 2, 2014, namely originally collected personal data, may continue to be used unless the individual has withdrawn consent. If personal information data was obtained after July 2, 2014, the business must notify the individual and obtain confirmed consent to the collection, use and disclosure before using the data.
07 Recommendations for Data Risk Management by Chinese Businesses
Singapore has well-developed infrastructure and an attractive investment environment, making it highly appealing to Chinese businesses. However, Singapore has a rigorous legal system. Chinese businesses are advised to pay particular attention to avoiding the risk of penalties arising from improper operations or violations.
1. Strengthen Awareness of Protecting the Rights of Citizens in the Host Country
In the digital economy, social issues such as prejudice and discrimination, data privacy and control over data occur frequently. In the Singapore market, the rights awareness of members of Singaporean society has been rising in recent years. At the same time, the Singapore Government has strengthened regulation of new technologies. For example, in November 2018, the Monetary Authority of Singapore (MAS) issued its principles to strengthen regulation of fairness, ethics, accountability and transparency in the use of AI in the financial sector, known as FEAT. Accordingly, Chinese investors in relevant fields may face not only legal sanctions but also a loss of market trust and an unfavorable operating position if their transactions, integration activities or daily operations involve sensitive social issues such as data breaches.
2. Strengthen Compliance Management
Businesses should fully understand the importance of customer personal data security and respect and protect customers’ privacy rights. From a comprehensive perspective, enterprises should strengthen their ability to protect personal information and privacy and embed data protection requirements into the establishment of their corporate systems. In addition, striking a balance between authorization to obtain personal information and user experience should be an indispensable consideration when designing products or services. For businesses operating in multiple jurisdictions, ensuring that their activities in each jurisdiction comply with local privacy-protection laws requires continuous monitoring of updates to relevant laws and regulations, translating new regulatory requirements into internal corporate rules, and optimizing internal processes so that all corporate activities comply with Singapore’s PDPA.
Finally, Singapore deserves its reputation as “one of the safest countries in the world.” This is reflected not only in personal safety but also in the protection of personal information. To protect personal data as fully as possible, the Singapore Government continues to improve its laws and strengthen the rigor of its regulations.
- Click “View Original” at the end of the article to use the Personal Data Protection Self-Assessment Checklist and understand how well personal data is being protected.
- For more information about the Personal Information Protection Law, visit the official website: http://www.pdpc.gov.sg/personal-data-protection-act/overview
- For further consultation on cross-border data transfers and data compliance in Singapore and Southeast Asian countries, please contact the professional consulting team of Zhongxin Legal News.
—
This article is provided for information purposes only and does not constitute formal legal advice.
This article is general information and not legal advice. Specific matters require assessment by appropriately qualified professionals.