, Singapore
108 views

Data protection penalties in Singapore hits over a million dollars so far in 2019

By Alain Esseiva

Singapore has seen a 47% increase in the number of data investigations since 2017 handing out over one and a half million dollars in fines, affecting companies from almost every industry

A recent notification from the Personal Data Protection Commission (PDPC) of Singapore outlined a number of penalties incurred by six Singaporean companies for breaching the Personal Data Protection Act.

Financial penalties ranged from $5,000 to $1m and were caused by a number of infractions including not having a Data Protection Officer to the unauthorised disclosure of clients’ personal data.

Since 2017, the PDPC has stepped up its investigations of companies thought to be in breach of the PDPA from 19 in 2017 to 28 in 2019 (and the number may still grow within the next months). Whilst some investigations resulted in no breach being found, the majority (52%) resulted in fines totalling $1,526,500, with the remainder resulting in warnings or further direction.

Interestingly, these investigations affected 76 companies and organisations ranging from small firms to major public/private institutions. Industries include services and F&B to transport and insurance. Additionally, the severity of the fines have increased with the first six months of 2019 seeing an average of $73,882 per fine handed out, compared to $9,300 in 2017.

One company did not have an appointed DPO and had no practices in place to comply with the PDPA. Another did not have adequate online firewall security and so suffered a ransomware attack, and another firm’s employee disclosed customer details without authorisation.

Some of the companies could have claimed they were simply unlucky – for example, the firm who suffered the ransomware attached was undergoing a full IT migration and its IT team was waiting for the IT infrastructure to be refreshed before configuring the appropriate firewall settings. Yet all it took was one incident for the PDPC to be alerted, resulting in the exposure of their lack of PDPA compliance and significant fines.

Data breaches can happen to any company no matter what type and infractions can come from a variety of sources, from employees disclosing data to cyber-attacks.

It is imperative that firms in Singapore take data protection seriously. Amongst other requirements, Singapore-based companies should appoint at least one person as a DPO, ensure consent has been granted by individuals before collecting, using or disclosing their data and allow individuals to withdraw that consent and retain data only when needed and destroy it if no longer required. 

Join Singapore Business Review community
Join Singapore Business Review community
A NOTE FROM SINGAPORE BUSINESS REVIEW

You're the reader we write for. You're also the person our partners want to reach.

If that sentence describes you — a founder, a C-suite, someone whose attention companies pay good money for — then you already understand why SBR works. We've spent twenty years earning the trust of readers exactly like you. Which is exactly what makes this an interesting place for your company to show up, too.

The ways it can show up are broader than most people assume — thought leadership articles, sponsored content, industry summits across Southeast Asia, regional awards programmes, podcasts, and media placements in print and digital. The right fit depends on what you're trying to do, which is why we'd rather start with a conversation than send a rate card.

If your company has something this audience should know about, we'd like to hear what you're working on.

No rate cards until we understand the brief. It's a better use of everyone's time.

Top News

30 One-Sentence Stories From People Who Have Built Better Habits
None of these stories are mine. They were sent to me by readers of Atomic Habits. My hope is that these examples will illustrate how real people are putting the book into practice. They will show you what people are actually doing to build good habits and break bad ones. And hopefully, they will spark some ideas for how you can do the same.
SBR 5 Lorem Ipsum News 2 [8 May]
Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book. It has survived not only five centuries, but also the leap into electronic typesetting, remaining essentially unchanged. It was popularised in the 1960s with the release of Letraset sheets containing Lorem Ipsum passages, and more recently with desktop publishing software like Aldus PageMaker including versions of Lorem Ipsum.
SBR 4 Lorem Ipsum [8 May Top Stories]
Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book. It has survived not only five centuries, but also the leap into electronic typesetting, remaining essentially unchanged. It was popularised in the 1960s with the release of Letraset sheets containing Lorem Ipsum passages, and more recently with desktop publishing software like Aldus PageMaker including versions of Lorem Ipsum.

Exclusives

How Experts Figure What to Focus On
eliminate the distractions. Commit to one thing and become great at that thing.”
Exclusive three SBR 12 Lorem Ipsum [8 May]
Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book. It has survived not only five centuries, but also the leap into electronic typesetting, remaining essentially unchanged. It was popularised in the 1960s with the release of Letraset sheets containing Lorem Ipsum passages, and more recently with desktop publishing software like Aldus PageMaker including versions of Lorem Ipsum.
SBR 3 Lorem Ipsum [ Exclusive 2]
Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book. It has survived not only five centuries, but also the leap into electronic typesetting, remaining essentially unchanged. It was popularised in the 1960s with the release of Letraset sheets containing Lorem Ipsum passages, and more recently with desktop publishing software like Aldus PageMaker including versions of Lorem Ipsum.

Event News

Video [Event News]
Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley