, Singapore
108 views

Data protection penalties in Singapore hits over a million dollars so far in 2019

By Alain Esseiva

Singapore has seen a 47% increase in the number of data investigations since 2017 handing out over one and a half million dollars in fines, affecting companies from almost every industry

A recent notification from the Personal Data Protection Commission (PDPC) of Singapore outlined a number of penalties incurred by six Singaporean companies for breaching the Personal Data Protection Act.

Financial penalties ranged from $5,000 to $1m and were caused by a number of infractions including not having a Data Protection Officer to the unauthorised disclosure of clients’ personal data.

Since 2017, the PDPC has stepped up its investigations of companies thought to be in breach of the PDPA from 19 in 2017 to 28 in 2019 (and the number may still grow within the next months). Whilst some investigations resulted in no breach being found, the majority (52%) resulted in fines totalling $1,526,500, with the remainder resulting in warnings or further direction.

Interestingly, these investigations affected 76 companies and organisations ranging from small firms to major public/private institutions. Industries include services and F&B to transport and insurance. Additionally, the severity of the fines have increased with the first six months of 2019 seeing an average of $73,882 per fine handed out, compared to $9,300 in 2017.

One company did not have an appointed DPO and had no practices in place to comply with the PDPA. Another did not have adequate online firewall security and so suffered a ransomware attack, and another firm’s employee disclosed customer details without authorisation.

Some of the companies could have claimed they were simply unlucky – for example, the firm who suffered the ransomware attached was undergoing a full IT migration and its IT team was waiting for the IT infrastructure to be refreshed before configuring the appropriate firewall settings. Yet all it took was one incident for the PDPC to be alerted, resulting in the exposure of their lack of PDPA compliance and significant fines.

Data breaches can happen to any company no matter what type and infractions can come from a variety of sources, from employees disclosing data to cyber-attacks.

It is imperative that firms in Singapore take data protection seriously. Amongst other requirements, Singapore-based companies should appoint at least one person as a DPO, ensure consent has been granted by individuals before collecting, using or disclosing their data and allow individuals to withdraw that consent and retain data only when needed and destroy it if no longer required. 

Join Singapore Business Review community
Join Singapore Business Review community
A NOTE FROM SINGAPORE BUSINESS REVIEW

Reaching the people who run Asia's businesses is harder than it used to be.

Inboxes are crowded. Attention is short. The executives you most want to reach — the founders, CFOs, and operators who actually move budgets — are the hardest to find through the usual channels. If you're building a company, a category, or a reputation, you already know this.

We've spent twenty years building the room they read. Singapore Business Review is where senior decision makers in Singapore and across Southeast Asia come for business coverage they can't get elsewhere — in print, online, and in person at the summits and roundtables we host across seven markets.

If you have something these readers should know about — a point of view worth publishing, a product worth their attention, an event worth their time — we'd like to hear what you're trying to do.

No rate cards until we understand the brief. It's a better use of everyone's time.

Top News

SBR 5 Lorem Ipsum News 2 [8 May]
Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book. It has survived not only five centuries, but also the leap into electronic typesetting, remaining essentially unchanged. It was popularised in the 1960s with the release of Letraset sheets containing Lorem Ipsum passages, and more recently with desktop publishing software like Aldus PageMaker including versions of Lorem Ipsum.
SBR 4 Lorem Ipsum [8 May Top Stories]
Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book. It has survived not only five centuries, but also the leap into electronic typesetting, remaining essentially unchanged. It was popularised in the 1960s with the release of Letraset sheets containing Lorem Ipsum passages, and more recently with desktop publishing software like Aldus PageMaker including versions of Lorem Ipsum.
Vibrant Group wins suit against Blackgold Australia
The group shall be paid damages and fees by Blackgold Australia’s ex-CEO and ex-chairman.
Lorem Ipsum text in year 2025
Contrary to popular belief, Lorem Ipsum is not simply random text. It has roots in a piece of classical Latin literature from 45 BC, making it over 2000 years old.

Exclusives

Exclusive three SBR 12 Lorem Ipsum [8 May]
Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book. It has survived not only five centuries, but also the leap into electronic typesetting, remaining essentially unchanged. It was popularised in the 1960s with the release of Letraset sheets containing Lorem Ipsum passages, and more recently with desktop publishing software like Aldus PageMaker including versions of Lorem Ipsum.
SBR 3 Lorem Ipsum [ Exclusive 2]
Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book. It has survived not only five centuries, but also the leap into electronic typesetting, remaining essentially unchanged. It was popularised in the 1960s with the release of Letraset sheets containing Lorem Ipsum passages, and more recently with desktop publishing software like Aldus PageMaker including versions of Lorem Ipsum.
SBR 2 Lorem Ipsum [8 May]
Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book. It has survived not only five centuries, but also the leap into electronic typesetting, remaining essentially unchanged. It was popularised in the 1960s with the release of Letraset sheets containing Lorem Ipsum passages, and more recently with desktop publishing software like Aldus PageMaker including versions of Lorem Ipsum.

Event News

Video [Event News]
Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley