Introduction
On 21 April 2016, the Personal Data Protection Commission (PDPC) issued a press release outlining its enforcement action against 11 organisations for breaches to the Personal Data Protection Act (PDPA).
The highlight penalty was a $50,000 fine and other directions meted out against karaoke chain K Box Entertainment Group Pte Ltd for not putting in place sufficient security measures to protect the personal data of 317,000 members (a list of the members’ details were uploaded onto some website), for inadequate data protection policies and the absence of a Data Protection Officer (DPO). Its IT vendor in charge of managing its content management system, Finantech Holdings Pte Ltd, was also fined.
PDPA breaches can result in financial penalties, valuable work hours spent on investigation proceedings, loss of trust from one’s clients, and reputational harm.
Since the PDPA came into full effect in July 2014, the PDPC has received 667 complaints. 92% of these complaints were resolved through investigation and facilitation between the respective organisations and individuals.
In this article, I consider some key themes in the enforcement action cases highlighted in the 21 April 2016 press release.
Continue reading “Legislative Update: enforcement action for PDPA breaches”
