3.6.1 Data Breach Obligations
Regarding data breach notifications: Singapore intends to adopt a mandatory data
breach notification regime.
233 It has been reported that relevant legislation is
intended to be tabled in Parliament in 2019.
234 While such amendments are being
prepared, the Commission has issued specific guidelines to be followed.
235 Under
these guidelines, the organisation will have up to 30 days to assess the suspected
breach.
236 Additionally:
• When there is a data breach that is (a) likely to result in “significant harm” or
“impact to the individuals to whom the information relates”; or (b) of a “significant scale” (i.e. the breach involves the personal data of 500 or more individuals),
the organisation must notify the Commission within 72 h of establishing any of
the above; and
• When there is a data breach that is likely to result in “significant harm” or “impact
to the individuals to whom the information relates”, the organisation must notify
affected individuals “as soon as practicable”.
237
Others The Monetary Authority of Singapore (“MAS”) has issued Technology
Risk Management Guidelines
238 which are applicable to, among others, banks,
finance companies and institutions, insurance companies, financial advisers, and
financial holding companies. It provides comprehensive guidelines for securing,
both physically and online, the institutions’ computer systems, networks, data
centres, operations and backup facilities.
233 PDPC Response to Feedback on the Public Consultation on Approaches to Managing Personal
Data in the Digital Economy Part III.
234 Tham I (2018) Breach reporting part of revised data privacy laws to be tabled in Parliament. In:
The Straits Times. https://www.straitstimes.com/tech/breach-reporting-part-of-revised-data-pri
vacy-laws-to-be-tabled-in-parliament. Accessed 30 August 2019.
235 PDPC Guide to Managing Data Breaches 2.0. Issued in May 2019, these guidelines appear to
supersede the directions given in the PDPC Response to Feedback on the Public Consultation on
Approaches to Managing Personal Data in the Digital Economy (issued in February 2018).
236 PDPC Guide to Managing Data Breaches 2.0, p. 18.
237 PDPC Guide to Managing Data Breaches 2.0, pp. 18, 32. In the PDPC Response to Feedback on
the Public Consultation on Approaches to Managing Personal Data in the Digital Economy, it was
also stated that an organisation will not have to notify affected individuals of an breach which is the
subject of an ongoing or potential investigation under the law, if such notification will: compromise
investigations or prejudice enforcement efforts (“law-enforcement exception”); a breach of data
which has been encrypted to a reasonable standard, unless the data can be decrypted (“technological
protection exception”); and/or an eligible breach if the organisation has taken actions to reduce the
potential harm or impact to affected individuals, if the organisation demonstrates that as a result of
its actions the breach is not likely to have any significant harm or impact to such individuals.
However, as exceptions to notification were not addressed in the PDPC Guide to Managing Data
Breaches 2.0, it is unclear whether these exceptions still apply.
238 Monetary Authority of Singapore (MAS) (2013) Technology Risk Management Guidelines.
Singapore Report: Data Protection in the Internet
331
Précédent

- 333/540

Suivant