vulnerabilities associated with software or hardware
139 ; failure to address common
website vulnerabilities such as SQL injection vulnerabilities
140 and cross-site
scripting
141 ; use of the auto-fill function
142 ; failure to remove unused user accounts
or pages, or limit access to website administration
143 ; failure to use encryption
and/or strong passwords (or any passwords at all)
144 ; and failure to exercise reasonable control of information on the organisation’s website.
145
Other factors (which seem equally applicable to non-electronic data breaches)
include: whether personal data was in fact disclosed and, if so, the number of
individuals whose personal data was disclosed
146 and the sensitivity of the data
involved
147
; and failure to implement adequate data protection procedures and
policies (including appointing a data protection officer).
148 Finally, the Commission
also considers whether: prompt remedial action was taken
149
; the affected parties
were notified of the breach
150 ; and if the organisation was cooperative and forthcoming during the Commission’s investigations.
151
In this regard, Singapore suffered its largest cyberattack in July 2018: hackers
stole the personal particulars of 1.5 million patients, and the outpatient prescription
records of nearly 160,000 patients, from Singapore Health Services Pte Ltd’s patient
139 See K Box Entertainment Group Pte. Ltd. [2016] SGPDPC 01; Institution of Engineers [2016]
SGPDPC 02.
140 See Metro Pte Ltd [2016] SGPDPC 07.
141 See Institution of Engineers [2016] SGPDPC 02.
142 See Full House Communications Pte Ltd [2016] SGPDPC 08.
143 See K Box Entertainment Group Pte. Ltd. [2016] SGPDPC 01; Fei Fah Medical Manufacturing
Pte. Ltd. [2016] SGPDPC 03; Social Metric Pte Ltd [2017] SGPDPC 17.
144 See K Box Entertainment Group Pte. Ltd. [2016] SGPDPC 01; Institution of Engineers [2016]
SGPDPC 02; My Digital Lock Pte Ltd [2016] SGPDPC 20; Fu Kwee Kitchen Catering Services
[2016] SGPDPC 14; Smiling Orchid [2016] SGPDPC 19; The Cellar Door Pte Ltd [2016]
SGPDPC 22.
145 Watami Food Service Singapore Pte Ltd [2018] SGPDPC [12].
146 See K Box Entertainment Group Pte. Ltd. [2016] SGPDPC 01; Institution of Engineers [2016]
SGPDPC 02; Aviva Ltd [2016] SGPDPC 15; Comfort Transportation Pte Ltd [2016] SGPDPC 17.
147 See Aviva Ltd [2016] SGPDPC 15; Central Depository (Pte) Limited [2016] SGPDPC 11;
Challenger Technologies Limited [2016] SGPDPC 06.
148 See, e.g., K Box Entertainment Group Pte. Ltd. [2016] SGPDPC 01; Fu Kwee Kitchen Catering
Services [2016] SGPDPC 14; National University of Singapore [2017] SGPDPC 05; Tiger Airways
Singapore Pte Ltd [2017] SGPDPC 06; M Stars Movers & Logistics Specialist Pte Ltd [2017]
SGPDPC 15.
149 See Central Depository (Pte) Limited [2016] SGPDPC 11; Challenger Technologies Limited
[2016] SGPDPC 06; Spear Security Force Pte. Ltd. [2016] SGPDPC 12; ABR Holdings Limited
[2016] SGPDPC 16.
150 See Institution of Engineers [2016] SGPDPC 02.
151 See Institution of Engineers [2016] SGPDPC 02; Fei Fah Medical Manufacturing Pte. Ltd.
[2016] SGPDPC 03; Yes Tuition Agency [2016] SGPDPC 05; Singapore Computer Society [2016]
SGPDPC 09; Central Depository (Pte) Limited [2016] SGPDPC 11; Singapore Management
University Alumni Association [2018] SGPDPC 6.
Singapore Report: Data Protection in the Internet
323
139 ; failure to address common
website vulnerabilities such as SQL injection vulnerabilities
140 and cross-site
scripting
141 ; use of the auto-fill function
142 ; failure to remove unused user accounts
or pages, or limit access to website administration
143 ; failure to use encryption
and/or strong passwords (or any passwords at all)
144 ; and failure to exercise reasonable control of information on the organisation’s website.
145
Other factors (which seem equally applicable to non-electronic data breaches)
include: whether personal data was in fact disclosed and, if so, the number of
individuals whose personal data was disclosed
146 and the sensitivity of the data
involved
147
; and failure to implement adequate data protection procedures and
policies (including appointing a data protection officer).
148 Finally, the Commission
also considers whether: prompt remedial action was taken
149
; the affected parties
were notified of the breach
150 ; and if the organisation was cooperative and forthcoming during the Commission’s investigations.
151
In this regard, Singapore suffered its largest cyberattack in July 2018: hackers
stole the personal particulars of 1.5 million patients, and the outpatient prescription
records of nearly 160,000 patients, from Singapore Health Services Pte Ltd’s patient
139 See K Box Entertainment Group Pte. Ltd. [2016] SGPDPC 01; Institution of Engineers [2016]
SGPDPC 02.
140 See Metro Pte Ltd [2016] SGPDPC 07.
141 See Institution of Engineers [2016] SGPDPC 02.
142 See Full House Communications Pte Ltd [2016] SGPDPC 08.
143 See K Box Entertainment Group Pte. Ltd. [2016] SGPDPC 01; Fei Fah Medical Manufacturing
Pte. Ltd. [2016] SGPDPC 03; Social Metric Pte Ltd [2017] SGPDPC 17.
144 See K Box Entertainment Group Pte. Ltd. [2016] SGPDPC 01; Institution of Engineers [2016]
SGPDPC 02; My Digital Lock Pte Ltd [2016] SGPDPC 20; Fu Kwee Kitchen Catering Services
[2016] SGPDPC 14; Smiling Orchid [2016] SGPDPC 19; The Cellar Door Pte Ltd [2016]
SGPDPC 22.
145 Watami Food Service Singapore Pte Ltd [2018] SGPDPC [12].
146 See K Box Entertainment Group Pte. Ltd. [2016] SGPDPC 01; Institution of Engineers [2016]
SGPDPC 02; Aviva Ltd [2016] SGPDPC 15; Comfort Transportation Pte Ltd [2016] SGPDPC 17.
147 See Aviva Ltd [2016] SGPDPC 15; Central Depository (Pte) Limited [2016] SGPDPC 11;
Challenger Technologies Limited [2016] SGPDPC 06.
148 See, e.g., K Box Entertainment Group Pte. Ltd. [2016] SGPDPC 01; Fu Kwee Kitchen Catering
Services [2016] SGPDPC 14; National University of Singapore [2017] SGPDPC 05; Tiger Airways
Singapore Pte Ltd [2017] SGPDPC 06; M Stars Movers & Logistics Specialist Pte Ltd [2017]
SGPDPC 15.
149 See Central Depository (Pte) Limited [2016] SGPDPC 11; Challenger Technologies Limited
[2016] SGPDPC 06; Spear Security Force Pte. Ltd. [2016] SGPDPC 12; ABR Holdings Limited
[2016] SGPDPC 16.
150 See Institution of Engineers [2016] SGPDPC 02.
151 See Institution of Engineers [2016] SGPDPC 02; Fei Fah Medical Manufacturing Pte. Ltd.
[2016] SGPDPC 03; Yes Tuition Agency [2016] SGPDPC 05; Singapore Computer Society [2016]
SGPDPC 09; Central Depository (Pte) Limited [2016] SGPDPC 11; Singapore Management
University Alumni Association [2018] SGPDPC 6.
Singapore Report: Data Protection in the Internet
323
