Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherBrowse by ChannelAbout the NetworkJoin the NetworkProductsSub-MenuProducts OverviewBlog ProBlog PlusBlog PremierMicrositeSyndication PortalsAboutContactSubscribeSupport
Book a Demo
Search
Close

Singapore Ramps Up Data Protection Enforcement – Five Useful Takeaways

By Charmian Aw on May 24, 2024
Email this postTweet this postLike this postShare this post on LinkedIn

In May 2024 alone, Singapore’s data protection regulator, the Personal Data Protection Commission (Commission) has issued three enforcement decisions that imposed a total of SG$102,000 (approximately US$76,000) in regulatory fines for infringements of Singapore’s Personal Data Protection Act (Act).

The Commission also accepted undertakings from six other organisations, each of whom was found to be lacking in its compliance with the Act. By way of background, the Commission is empowered to, in lieu of carrying out a full investigation, accept an undertaking from an organisation that has potentially contravened the Act. Such undertaking must seek to implement remediation plans, and address systemic shortcomings, to ensure compliance on a continual basis.

The recent decisions in May shed light on a number of important issues and offer useful takeaways for a business to note when considering its compliance with the Act.

We outline five such key takeaways.

  • There is no “one size fits all” approach to meeting the security obligation.
  • In all the above cases, the organisations were found to be “wanting” or “lacklustre” in their cybersecurity and data protection practices.
  • The Commission went to great lengths to assess where the standards in each of these instances fell short. It also referenced its various published guides and previous decisions that offered an array of examples of good practices when protecting personal data; including vendor management, encryption, password protocols, pre-launch testing, vulnerability scans, regular security reviews and ongoing monitoring.
  • Ultimately, however, it is the organisation that holds responsibility (and retains discretion) to determine how best to operationalise compliance, since any design and implementation of security would need to reflect the nature of the business and types of services offered, as well as the volume and sensitivity of data handled. In other words, the obligation to protect personal data by making “reasonable security arrangements” is contextual.
  • Minors’ and national identification details are considered to be more sensitive.
  • While not explicitly prescribed in the Act, the enforcement decisions allude to greater weight being given to breaches that involve more sensitive personal data, namely, minors’ data, as well as national identification details including passport numbers.
  • A repeated infringement is an aggravating factor.
  • The fact that one of the organisations had previously contravened the Act was a relevant consideration in a higher penalty being meted out by the Commission.
  • An organisation’s cooperativeness, and owning up to its responsibilities, are mitigating factors.
  • In general, organisations that were found to be cooperative throughout the Commission’s inquiry and investigation process, or which voluntarily undertook to improve on their compliance in specific and measurable ways, faced less severe regulatory sanctions.
  • The Act imposes an obligation on organisations to protect all personal data in their possession or control – not just of data subjects located within Singapore.
  • The Commission also clarified that its jurisdiction to enforce contraventions of the Act is not fettered by other proceedings undertaken by privacy authorities abroad.

Should you require any advice or assistance, feel free to reach out to your usual firm contact.

Disclaimer: The views and opinions expressed here are of the author(s) alone and do not necessarily reflect the opinion or position of Squire Patton Boggs or its clients. While every effort has been made to ensure that the information contained in this article is accurate, neither its author(s) nor Squire Patton Boggs accept responsibility for any errors or omissions. The content of this article is for general information only and is not intended to constitute or be relied upon as legal advice.

Photo of Charmian Aw Charmian Aw
Read more about Charmian AwEmail
  • Posted in:
    Privacy & Data Security
  • Blog:
    Privacy World
  • Organization:
    Squire Patton Boggs
  • Article: View Original Source

LexBlog, Inc. logo
Facebook LinkedIn Twitter RSS
Real Lawyers
99 Park Row
  • About LexBlog
  • Careers
  • Press
  • Contact LexBlog
  • Privacy Policy
  • Editorial Policy
  • Disclaimer
  • Terms of Service
  • RSS Terms of Service
  • Products
  • Blog Pro
  • Blog Plus
  • Blog Premier
  • Microsite
  • Syndication Portals
  • LexBlog Community
  • 1-800-913-0988
  • Submit a Request
  • Support Center
  • System Status
  • __

New to the Network

  • Crunched Credit
  • Nothing but Substance
  • Franchising & Distribution Law Blog
  • Business Risk Management Blog
  • Employee Benefits & Executive Compensation Blog
Copyright © 2024, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo