MDDI's Response to PQ on Prohibitions on Misuse of Identity Data Collected by Social Media Age Assurance Providers for Advertising, Profiling and Third-Party Transfers
6 October 2026
Parliament Sitting on 6 October 2026
Question for Written Answer
32. Mr Gabriel Lam asked the Minister for Digital Development and Information whether providers conducting age assurance for social-media services will be prohibited from (i) retaining identity information beyond what is necessary for verification (ii) using such information for advertising or profiling and (iii) transferring such information to third parties for unrelated purposes.
Answer
We expect the designated social media services to implement age assurance methods in accordance with their obligations under the Personal Data Protection Act 2012 (PDPA) and relevant guidelines issued by the Personal Data Protection Commission.
Organisations that collect personal data for age assurance must stop retaining the data when it is no longer needed for age assurance and retention is no longer necessary for legal or business purposes. Any further use or disclosure for other purposes, such as advertising or profiling, or to third parties for unrelated purposes, must comply with the PDPA requirements on consent and notification.
