Cybersecurity 2026

SINGAPORE Law and Practice Contributed by: Lim Chong Kin, David N Alfred, Albert Pichlmaier and Goh Boon Yeow, Drew & Napier LLC

if the offence had been committed within Singapore under specific scenarios. Personal Data Protection Act 2012 (PDPA) The PDPA applies to all private sector organisations that collect, use, disclose or otherwise process per - sonal data (both electronic and non-electronic data). Personal data is defined as data about an individual who can be identified from that data, or from that data and other information to which the organisation has or is likely to have access. As part of complying with the PDPA, organisations are required to make reasonable security arrangements to protect personal data in their possession or under their control to prevent (i) unauthorised access, collec - tion, use, disclosure, copying, modification, disposal, or similar risks; or (ii) the loss of any storage device or medium on which personal data is stored. Under the PDPA, the Personal Data Protection Commission (PDPC) is empowered to issue advisory guidelines which indicate the manner in which the PDPC will interpret the provisions of the PDPA. The PDPA also includes notification requirements in the event of a data breach (see 6.1 Cybersecurity and Data Protection ). The Do Not Call (DNC) provisions under the PDPA regulate the sending of certain marketing messages to Singapore telephone numbers. These provisions are intended to give individuals more control over the type of marketing messages they may receive by allowing individuals to register their telephone numbers with the DNC Registry and imposing obligations on organi - sations in respect of sending marketing messages. This thereby reduces the number of unsolicited mes - sages received by individuals and the risk of being exposed to cybersecurity attacks. Spam Control Act 2007 (SCA) The SCA provides for the control of spam and for mat - ters connected with spam in Singapore. The SCA gen - erally regulates the sending of electronic messages with a Singapore link and contains specific obliga - tions relating to senders of unsolicited commercial electronic messages in bulk. The SCA also prohibits the sending of an electronic message to an electron -

ic address obtained through the use of a dictionary attack or address-harvesting software. The SCA is a civil penalty regime where non-compliance with these requirements may result in civil actions against the spammer. Public Sector (Governance) Act 2018 (PSGA) Aside from the confidentiality and secrecy provisions found across various legislation, data protection and management in the public sector is also governed under the PSGA. The PSGA imposes criminal penal - ties on public officers who recklessly or intentionally disclose data without authorisation, misuse data for a gain or re-identify anonymised data. Specific data security policies are further set out in the Government Instruction Manual on IT Management. Other Sectoral Frameworks Two notable examples are in the telecommunications and banking and finance sectors. First, the telecoms and media regulator, the Info-com - munications Media Development Authority (IMDA), has published a Telecommunications Cybersecurity Code of Practice to enhance cybersecurity prepared - ness of designated telecommunication licensees such as internet service providers in Singapore. This Code of Practice, which was formulated in line with inter - national standards and best practices including the ISO/IEC 27011 and IETF Best Current Practices, sets out requirements on security incident management and other controls to help licensees prevent, protect, detect and respond to cybersecurity threats. Second, the Singapore financial regulatory author - ity, the Monetary Authority of Singapore (MAS), has issued its Technology Risk Management (TRM) Guide - lines (the “TRM Guidelines”), which set out risk man - agement principles and best practices to guide finan - cial institutions (FIs) in establishing sound and robust technology risk governance and oversight, as well as in maintaining IT and cyber-resilience. In conjunction with this, the MAS has also issued legally binding Notices on TRM and Cyber Hygiene which give effect to some of the requirements in the TRM Guidelines. Please also see 3.1 Scope of Financial Sector Opera- tion Resilience Regulation for further details.

284 CHAMBERS.COM

Powered by