← All Authorities
Singapore protection obligationcybersecuritydata intermediary

Re SingHealth

[2019] SGPDPC 3
JurisdictionSingapore
CourtSingapore Personal Data Protection Commission
Year2019
StatusBinding authority

Key Principle

Under the PDPA's Protection Obligation (s 24), an organisation and its data intermediary must implement reasonable and appropriate security measures commensurate with the size, nature and sensitivity of the personal data held; failure to do so — including through inadequate staffing, weak passwords, dormant accounts, and insufficient incident escalation procedures — constitutes a breach even where the attacker is sophisticated.

Area of Law

data-protection

Related Cases

Kalen, Alexandru v World Exchange Services Pte Ltd [2026] SGHC 31
Wong Mei Lee Millie v Ngor Shing Rong Jake [2026] SGCA 27
Kardachi, Jason Aleksander (private trustee of Rajesh Bothra) and another v Deepak Mishra and others [2025] SGHC 218

Ask CommonBench about this case

Get a detailed analysis of Re SingHealth and how it applies to your situation.

Explain Re SingHealth