← All Authorities
Singapore
protection obligationcybersecuritydata intermediary
Re SingHealth
[2019] SGPDPC 3
Key Principle
Under the PDPA's Protection Obligation (s 24), an organisation and its data intermediary must implement reasonable and appropriate security measures commensurate with the size, nature and sensitivity of the personal data held; failure to do so — including through inadequate staffing, weak passwords, dormant accounts, and insufficient incident escalation procedures — constitutes a breach even where the attacker is sophisticated.
Area of Law
data-protection
Related Cases
Ask CommonBench about this case
Get a detailed analysis of Re SingHealth and how it applies to your situation.
Explain Re SingHealth