Specifically, “[e]ffective risk management practices and internal controls should
be instituted to achieve”, among others, data confidentiality, meaning “the protection
of sensitive or confidential information such as customer data from unauthorised
access, disclosure, etc”.
239 Institutions shall also implement (or ensure that service
providers implement) procedures and “to protect the confidentiality and security of
its sensitive or confidential information, such as customer data”.
240 Institutions
should also “keep customers informed of any major incident” and informing the
general public “where necessary”.
241 While the TRMG are “not legally binding, the
degree of observance with the spirit of the [g]uidelines . . . is an area of consideration
in the risk assessment of the [institution] by MAS”.
242
Other regulatory agencies may work with the Commission with regard to data
protection breaches. For instance, MAS stated that “in cases involving disclosure of
banking customers’ personal data”, it would work with the Commission “to review
the matter”.
243
3.7 Electronic Communications
3.7.1 Online Publication of Personal Data
Protection from Harassment (Amendment) Bill
Under the newly introduced (as of writing) Protection from Harassment (Amendment) Bill,
244 it will be an offence of to “publish any identity information” of another
person with the intent to, or which is likely to, cause “harassment, alarm or distress”
to such person (i.e. the act more commonly known as doxxing).
245
“Identity information” means any information that, whether on its own or with other information,
identifies or purports to identify an individual, including:
239 MAS Technology Risk Management Guideline para 4.0.2.
240 MAS Technology Risk Management Guidelines para 5.1.4.
241 MAS Technology Risk Management Guidelines para 7.3.9.
242 MAS Technology Risk Management Guidelines para 1.0.5.
243 This was in reference to an incident where reporters found, in a public area, a trash bag containing
“several corporate statements, loan applications, and internal reports from [a] bank”. Lee J (2016)
MAS probes case of UOB’s unshredded client data. In: The Straits Times. http://www.straitstimes.
com/business/companies-markets/mas-probes-case-of-uobs-unshredded-client-data. Accessed 30
August 2019. The outcome of the investigation remains unclear: Koh WT (2016) UOB under MAS
probe for failing to protect clients’ privacy. In: The Straits Times. http://themiddleground.sg/2016/07/
19/uob-mas-probe-failing-protect-client-privacy. Accessed 30 August 2019.
244 No 11/2019, which will amend POHA.
245 No 11/2019 s 4.
332
E.-I. Ong
be instituted to achieve”, among others, data confidentiality, meaning “the protection
of sensitive or confidential information such as customer data from unauthorised
access, disclosure, etc”.
239 Institutions shall also implement (or ensure that service
providers implement) procedures and “to protect the confidentiality and security of
its sensitive or confidential information, such as customer data”.
240 Institutions
should also “keep customers informed of any major incident” and informing the
general public “where necessary”.
241 While the TRMG are “not legally binding, the
degree of observance with the spirit of the [g]uidelines . . . is an area of consideration
in the risk assessment of the [institution] by MAS”.
242
Other regulatory agencies may work with the Commission with regard to data
protection breaches. For instance, MAS stated that “in cases involving disclosure of
banking customers’ personal data”, it would work with the Commission “to review
the matter”.
243
3.7 Electronic Communications
3.7.1 Online Publication of Personal Data
Protection from Harassment (Amendment) Bill
Under the newly introduced (as of writing) Protection from Harassment (Amendment) Bill,
244 it will be an offence of to “publish any identity information” of another
person with the intent to, or which is likely to, cause “harassment, alarm or distress”
to such person (i.e. the act more commonly known as doxxing).
245
“Identity information” means any information that, whether on its own or with other information,
identifies or purports to identify an individual, including:
239 MAS Technology Risk Management Guideline para 4.0.2.
240 MAS Technology Risk Management Guidelines para 5.1.4.
241 MAS Technology Risk Management Guidelines para 7.3.9.
242 MAS Technology Risk Management Guidelines para 1.0.5.
243 This was in reference to an incident where reporters found, in a public area, a trash bag containing
“several corporate statements, loan applications, and internal reports from [a] bank”. Lee J (2016)
MAS probes case of UOB’s unshredded client data. In: The Straits Times. http://www.straitstimes.
com/business/companies-markets/mas-probes-case-of-uobs-unshredded-client-data. Accessed 30
August 2019. The outcome of the investigation remains unclear: Koh WT (2016) UOB under MAS
probe for failing to protect clients’ privacy. In: The Straits Times. http://themiddleground.sg/2016/07/
19/uob-mas-probe-failing-protect-client-privacy. Accessed 30 August 2019.
244 No 11/2019, which will amend POHA.
245 No 11/2019 s 4.
332
E.-I. Ong
