ARTICLE
31 March 2022

Singapore Red Cross Society's Remedial Measures To Address Data Breaches

GA
Global Advertising Lawyers Alliance (GALA)
Contributor
With firms representing more than 90 countries, each GALA member has the local expertise and experience in advertising, marketing and promotion law that will help your campaign achieve its objectives, and navigate the legal minefield successfully. GALA is a uniquely sensitive global resource whose members maintain frequent contact with each other to maximize the effectiveness of their collaborative efforts for their shared clients. GALA provides the premier worldwide resource to advertisers and agencies seeking solutions to problems involving the complex legal issues affecting today's marketplace.
Singapore Red Cross Society ran a website that permitted the community to schedule appointments to donate blood.
Singapore Privacy
To print this article, all you need is to be registered or login on Mondaq.com.

The following case reiterates the need for a proper password protection policy and periodic security checks to guard against data breaches under Singapore's Personal Data Protection Act ("the Act).

Singapore Red Cross Society ("Red Cross") ran a website that permitted the community to schedule appointments to donate blood. To this end, Red Cross kept personal records of people including their names, contact details, e-mail addresses and blood types ("the data"). The data was kept in Red Cross's database.

On 9 May 2019, Red Cross informed the Personal Data Protection Commission ("PDPC") of a data breach that compromised the data of about 4,297 persons from the database ("the Incident").

Red Cross promptly took the following measures:

  • Took out the function that enabled making appointments to briefly stop gathering data; and
  • Enhanced its protocols to comply with the Act.

Red Cross understood that it had breached its protection obligation by not taking enough action to protect the data. In particular, Red Cross had not adequately monitored the vendor's work on its website. The password management policy did not require strong passwords. The failure to carry out periodic security checks resulted in an administrative tool that was used to manage the database remaining connected after the website was fully operational. This oversight coupled with the allowance of weak passwords left the website vulnerable to unauthorised access.

Red Cross also understood that it had breached the retention limitation obligation under the Act by keeping data of about 900 persons. Red Cross only told its vendor to remove some parts of such data, and failed to supervise this purging exercise.

The PDPC considered Red Cross's submissions and reduced the amount of the fine imposed, given:

  • Red Cross's early confession;
  • Red Cross's prompt and wide-ranging actions to address the data breach, including lodging a police report, telling all affected persons about the Incident, and removing the database from its website; and
  • Red Cross's implementation of better security measures including detaching important systems from the website and testing them, educating staff on passwords, improving standard operating procedures, and closely monitoring vendor conduct.

In this exceptional case, the PDPC reduced the financial penalty to $5,000

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

ARTICLE
31 March 2022

Singapore Red Cross Society's Remedial Measures To Address Data Breaches

Singapore Privacy
Contributor
With firms representing more than 90 countries, each GALA member has the local expertise and experience in advertising, marketing and promotion law that will help your campaign achieve its objectives, and navigate the legal minefield successfully. GALA is a uniquely sensitive global resource whose members maintain frequent contact with each other to maximize the effectiveness of their collaborative efforts for their shared clients. GALA provides the premier worldwide resource to advertisers and agencies seeking solutions to problems involving the complex legal issues affecting today's marketplace.
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More