For instance, organisations should ensure that computer networks are secure, and
personal data encrypted.
129 They should consider, as part of good governance:
accountability; standards, policies and procedures; risk management; and classification and tracking of personal data.
130 They should also educate employees on
potential threats to, and protection measures for, personal data.
131
There are also guidelines on preventing accidental disclosure of personal data,
including: automating the processing of documents containing personal data and
checking these systems regularly; ensuring additional checks following the
processing, printing and sorting of documents to ensure that the destination information is correct and matches that of the intended recipient; and establishing a policy
for sending compiled sets of personal data of different individuals (e.g. through
spreadsheets).
132 The use of passwords for documents containing personal data, as
well as regular staff training on proper data protection procedures, is also
encouraged.
133
These guidelines reflect the approach taken in several cases decided by the
Commission. For instance, in The Institution of Engineers Singapore
134 (“IES”),
there was a breach of personal data of IES members stored on the organisation’s
website. While a number of measures had been taken to secure the site, including use
of a firewall and anti-virus software, up-to-date software, and limited administrative
access, the Commission found the following flaws: no encrypted storage of member
passwords; no security audit on the website; no penetrating testing; and no specific
arrangements with the website vendors to put in place security measures to safeguard
personal data stored on the website.
135 In addition, there were common vulnerabilities with the website (including cross-site scripting); these could have been easily
detected through the performance of a vulnerability scan, which was also an industry
best practice.
136
Based on case law, factors that the Commission has taken into account regarding
reasonable protection of personal data conveyed and stored through electronic
means include
137
: failure to audit systems, carry out penetration tests and test
website vulnerabilities
138 ; use of outdated software and/or failure to recognise
129 PDPC Guide to Securing Personal Data in Electronic Medium paras 9.1, 10.3.
130 PDPC Guide to Securing Personal Data in Electronic Medium para 4.1.
131 PDPC Guide to Securing Personal Data in Electronic Medium paras 5.1–5.2.
132 PDPC (2017) Guide to Preventing Accidental Disclosure when Processing and Sending Personal
Data pp. 3–4.
133 Guide to Preventing Accidental Disclosure p. 5.
134 [2016] SGPDPC 02.
135 [2016] SGPDPC 02 at [29]-[30], [33].
136 [2016] SGPDPC 02 at [31]-[32].
137 See Woon CY (2016) Personal Data Protection Act – Obligation to Protect and Secure Data, and
What to Do in Case of Breach. https://dentons.rodyk.com/en/insights/alerts/2016/november/8/per
sonal-data-protection-act-obligations-to-protect-and-secure-data-and-what-to-do-in-case-ofbreach. Accessed 30 August 2019.
138 See K Box Entertainment Group Pte. Ltd. [2016] SGPDPC 01.
322
E.-I. Ong
Précédent

- 324/540

Suivant