database system.
152 A number of public hearings were held to investigate the
breach.
153 The Commission eventually imposed an aggregate financial penalty of
$1,000,000 SGD on the two organisations involved.
154 It found several failings,
including: staff who fell prey to phishing attacks; easily deduced administrator
passwords; failure to apply a systems patch; and an ineffective IT security-incident
team.
155 This incident may result in further changes to the rules and guidelines on
electronic data protection in Singapore.
PS(G)A: Data Processing Data shared under the PS(G)A will be “for analysis and
to develop policies and programmes”.
156 Such data will be anonymised and aggregated.
157 As such, “centralised data custodians” will be set up where “raw data from
different sources will be matched and anonymised, before being released to relevant
agencies for analysis”.
158 Moreover, the user of the data will also be held “accountable for the protection and safeguarding of data passed to” it.
159 Unauthorised
disclosure and improper use of information shared under the PS(G)A will be
punished,
160 as will “unauthorised re-identification of anonymised information”.
161
Public servants’ access to data will also be prescribed based on security clearance
and legitimate need.
162
3.2 Personal Data on Computers
Singapore also has specific laws involving the investigation of personal data on
computers (including web-based servers).
152 Tham I (2018). Personal info of 1.5m SingHealth patients, including PM Lee, stolen in
Singapore’s worst cyberattack. In: The Straits Times. https://www.straitstimes.com/singapore/per
sonal-info-of-15m-singhealth-patients-including-pm-lee-stolen-in-singapores-most. Accessed 30
August 2019.
153 Singapore Health Services Pte Ltd [2019] SGPDPC 03. Tham I (2018). Hearings on SingHealth
cyber breach from Sept 21. In: The Straits Times. https://www.straitstimes.com/singapore/hearingson-singhealth-cyber-breach-from-sept-21. Accessed 30 August 2019.
154 Singapore Health Services Pte Ltd [2019] SGPDPC 03. The financial penalties imposed against
the two organisations involved are, individually, the highest ($750,000 SGD) and second highest
($250,000 SGD) financial penalty amounts imposed by the Commission to date.
155 Singapore Health Services Pte Ltd [2019] SGPDPC 03.
156 Singapore Parliamentary Debates, Official Report (8 January 2018) vol 94.
157 Singapore Parliamentary Debates, Official Report (8 January 2018) vol 94.
158 Singapore Parliamentary Debates, Official Report (8 January 2018) vol 94.
159 Singapore Parliamentary Debates, Official Report (8 January 2018) vol 94.
160 PS(G)A s 7.
161 PS(G)A s 8.
162 Singapore Parliamentary Debates, Official Report (8 January 2018) vol 94. Seow J (2018) New
law on data sharing among govt agencies. In: The Straits Times. http://www.straitstimes.com/
singapore/new-law-on-data-sharingamong-govt-agencies. Accessed 30 August 2019.
324
E.-I. Ong
152 A number of public hearings were held to investigate the
breach.
153 The Commission eventually imposed an aggregate financial penalty of
$1,000,000 SGD on the two organisations involved.
154 It found several failings,
including: staff who fell prey to phishing attacks; easily deduced administrator
passwords; failure to apply a systems patch; and an ineffective IT security-incident
team.
155 This incident may result in further changes to the rules and guidelines on
electronic data protection in Singapore.
PS(G)A: Data Processing Data shared under the PS(G)A will be “for analysis and
to develop policies and programmes”.
156 Such data will be anonymised and aggregated.
157 As such, “centralised data custodians” will be set up where “raw data from
different sources will be matched and anonymised, before being released to relevant
agencies for analysis”.
158 Moreover, the user of the data will also be held “accountable for the protection and safeguarding of data passed to” it.
159 Unauthorised
disclosure and improper use of information shared under the PS(G)A will be
punished,
160 as will “unauthorised re-identification of anonymised information”.
161
Public servants’ access to data will also be prescribed based on security clearance
and legitimate need.
162
3.2 Personal Data on Computers
Singapore also has specific laws involving the investigation of personal data on
computers (including web-based servers).
152 Tham I (2018). Personal info of 1.5m SingHealth patients, including PM Lee, stolen in
Singapore’s worst cyberattack. In: The Straits Times. https://www.straitstimes.com/singapore/per
sonal-info-of-15m-singhealth-patients-including-pm-lee-stolen-in-singapores-most. Accessed 30
August 2019.
153 Singapore Health Services Pte Ltd [2019] SGPDPC 03. Tham I (2018). Hearings on SingHealth
cyber breach from Sept 21. In: The Straits Times. https://www.straitstimes.com/singapore/hearingson-singhealth-cyber-breach-from-sept-21. Accessed 30 August 2019.
154 Singapore Health Services Pte Ltd [2019] SGPDPC 03. The financial penalties imposed against
the two organisations involved are, individually, the highest ($750,000 SGD) and second highest
($250,000 SGD) financial penalty amounts imposed by the Commission to date.
155 Singapore Health Services Pte Ltd [2019] SGPDPC 03.
156 Singapore Parliamentary Debates, Official Report (8 January 2018) vol 94.
157 Singapore Parliamentary Debates, Official Report (8 January 2018) vol 94.
158 Singapore Parliamentary Debates, Official Report (8 January 2018) vol 94.
159 Singapore Parliamentary Debates, Official Report (8 January 2018) vol 94.
160 PS(G)A s 7.
161 PS(G)A s 8.
162 Singapore Parliamentary Debates, Official Report (8 January 2018) vol 94. Seow J (2018) New
law on data sharing among govt agencies. In: The Straits Times. http://www.straitstimes.com/
singapore/new-law-on-data-sharingamong-govt-agencies. Accessed 30 August 2019.
324
E.-I. Ong
