Insurance Association Singapore (“LIA”)
121 and The Association of Banks in
Singapore (“ABS”).
122
3 Personal Data Processed by Electronic Means
3.1 Services Provided at a Distance
PDPA As stated previously, the PDPA covers all personal data, whether in electronic or other form.
123 The PDPA states that an organisation “shall protect personal
data in its possession or . . . control by making reasonable security arrangements to
prevent unauthorised access, collection, use, disclosure, copying, modification,
disposal or similar risks”.
124 The Commission’s guidelines reiterate the need to
adopt arrangements which are reasonable under the circumstances.
125
For instance, an organisation should ensure that its security arrangements “fit the
nature of the personal data held . . . and the possible harm that might result from a
security breach”; “identify reliable and well-trained personnel”; “implement robust
policies and procedures for ensuring appropriate levels of security for personal data
of varying levels of sensitivity”; and “be prepared and able to respond to information
security breaches promptly and effectively”.
126 Thus in My Digital Lock Pte Ltd,
127
the Commission stated that “[r]easonable . . . security arrangements when transferring personal data” requires a process where “the personal data is reasonably
protected from unauthorised access or interference, until the personal data reaches
its intended destination or recipient where other security arrangements on storage
would apply”.
Guidelines have also been issued in this regard, concerning: the security and
protection of personal data stored in electronic medium; good practices for
protecting electronic personal data; and enhanced practices that may be adopted.
128
121 Life Insurance Association Singapore (2015) MU61/15—LIA Code of Practice for Life Insurers
on the Singapore Personal Data Protection Act (No. 26 of 2012). https://www.lia.org.sg/media/
1229/mu-6115-code-of-practice-on-pdpa.pdf. Accessed 30 August 2019. Life Insurance Association Singapore (2015) MU 62/15—LIA Code Of Conduct For Tied Agents Of Life Insurers On The
Singapore Personal Data Protection Act (No. 26 of 2012). https://www.lia.org.sg/media/1230/mu6215-code-of-conduct-on-pdpa.pdf. Accessed 30 August 2019.
122 The Association of Banks in Singapore (2015) Code of Banking Practices – The Personal Data
Protection Act (“PDPA”). https://abs.org.sg/docs/library/abs-code-banking-practices-pdpa.pdf.
Accessed 30 August 2019.
123 PDPC Advisory Guidelines on Key Concepts paras 5.2, 5.30.
124 PDPA s 24.
125 PDPC Advisory Guidelines on Key Concepts para 17.2.
126 PDPC Advisory Guidelines on Key Concepts para 17.3.
127 [2016] SGPDPC 20 at [25].
128 PDPC Guide to Securing Personal Data in Electronic Medium para 2.3.
Singapore Report: Data Protection in the Internet
321
121 and The Association of Banks in
Singapore (“ABS”).
122
3 Personal Data Processed by Electronic Means
3.1 Services Provided at a Distance
PDPA As stated previously, the PDPA covers all personal data, whether in electronic or other form.
123 The PDPA states that an organisation “shall protect personal
data in its possession or . . . control by making reasonable security arrangements to
prevent unauthorised access, collection, use, disclosure, copying, modification,
disposal or similar risks”.
124 The Commission’s guidelines reiterate the need to
adopt arrangements which are reasonable under the circumstances.
125
For instance, an organisation should ensure that its security arrangements “fit the
nature of the personal data held . . . and the possible harm that might result from a
security breach”; “identify reliable and well-trained personnel”; “implement robust
policies and procedures for ensuring appropriate levels of security for personal data
of varying levels of sensitivity”; and “be prepared and able to respond to information
security breaches promptly and effectively”.
126 Thus in My Digital Lock Pte Ltd,
127
the Commission stated that “[r]easonable . . . security arrangements when transferring personal data” requires a process where “the personal data is reasonably
protected from unauthorised access or interference, until the personal data reaches
its intended destination or recipient where other security arrangements on storage
would apply”.
Guidelines have also been issued in this regard, concerning: the security and
protection of personal data stored in electronic medium; good practices for
protecting electronic personal data; and enhanced practices that may be adopted.
128
121 Life Insurance Association Singapore (2015) MU61/15—LIA Code of Practice for Life Insurers
on the Singapore Personal Data Protection Act (No. 26 of 2012). https://www.lia.org.sg/media/
1229/mu-6115-code-of-practice-on-pdpa.pdf. Accessed 30 August 2019. Life Insurance Association Singapore (2015) MU 62/15—LIA Code Of Conduct For Tied Agents Of Life Insurers On The
Singapore Personal Data Protection Act (No. 26 of 2012). https://www.lia.org.sg/media/1230/mu6215-code-of-conduct-on-pdpa.pdf. Accessed 30 August 2019.
122 The Association of Banks in Singapore (2015) Code of Banking Practices – The Personal Data
Protection Act (“PDPA”). https://abs.org.sg/docs/library/abs-code-banking-practices-pdpa.pdf.
Accessed 30 August 2019.
123 PDPC Advisory Guidelines on Key Concepts paras 5.2, 5.30.
124 PDPA s 24.
125 PDPC Advisory Guidelines on Key Concepts para 17.2.
126 PDPC Advisory Guidelines on Key Concepts para 17.3.
127 [2016] SGPDPC 20 at [25].
128 PDPC Guide to Securing Personal Data in Electronic Medium para 2.3.
Singapore Report: Data Protection in the Internet
321
