Cybersecurity 2026

SINGAPORE Law and Practice Contributed by: Lim Chong Kin, David N Alfred, Albert Pichlmaier and Goh Boon Yeow, Drew & Napier LLC

It is an offence for any person to fail to co-operate with the CSA without reasonable excuse and such persons shall be liable on conviction to be punished in accordance with the fines, terms of imprisonment or both, as set out in the relevant statutory provisions. Under the upcoming Section 18K(1) in Part 3D of the amended Cybersecurity Act, the Commissioner may require major FDI service providers to furnish informa - tion. If the major FDI service provider fails to, without reasonable excuse, furnish the required cybersecurity- related information within the specified period or con - tinues providing the designated FDI service despite the non-compliance, they shall be guilty of an offence. They shall be liable for a fine not exceeding the greater of SGD200,000 or 10% of the annual turnover of the service provider’s business in Singapore. The upcoming Section 18L(1) also empowers the Commissioner to issue written instructions to major FDI service providers which may relate to the action to be taken by the provider in relation to a cybersecu - rity threat, compliance with any prescribed technical standards relating to cybersecurity, among others. Any major FDI service provider who fails to comply with such a written direction and continues to pro - vide FDI infrastructure service after the deadline for compliance will be liable on conviction to a fine not exceeding the greater of SGD200,000 or 10% of the annual turnover of the person’s business in Singapore. Further, under the upcoming Section 18M (1), major FDI service providers must notify the Commissioner of the occurrence of a prescribed cybersecurity inci - dent in respect of the major FDI, where the incident results in a disruption or degradation to the continu - ous delivery of the foundational digital infrastructure service or the major FDI service provider’s business operations in Singapore. Any major FDI service pro - vider who, without reasonable excuse, fails to comply with this obligation shall be guilty of an offence and liable on conviction to a fine not exceeding the greater of SGD200,000 or 10% of the annual turnover of the person’s business in Singapore. As the provisions relating to the obligations for major FDI service providers have not yet commenced, there are no enforcement decisions against major FDI ser -

vice providers for the failure to comply with the Cyber - security Act. 3.5 International Data Transfers There are no specific obligations imposed by MAS in relation to financial institutions carrying out interna - tional data transfers. However, organisations transfer - ring personal data overseas must comply with Section 26 of the PDPA. Under Section 26, organisations need to ensure that the personal data transferred overseas is accorded a standard of protection that is compara - ble to the protection under the PDPA. Under the Personal Data Protection Regulations 2021 (the “PDP Regulations”), the transferring organisation must take appropriate steps to ascertain whether, and to ensure that, the recipient of the personal data is bound by legally enforceable obligations (as defined under the PDP Regulations) to provide to the trans - ferred personal data a standard of protection that is at least comparable to the protection under the PDPA. Alternatively, this requirement is deemed to have been met if: • the data subject whose personal data is to be transferred gives their consent to the transfer of their personal data, after being provided with a rea - sonable summary in writing of the extent to which the personal data transferred to those countries and territories will be protected to a standard com - parable to the protection under the PDPA; or • the transfer is necessary for the performance of a contract between the organisation and the data subject, or to do anything at the data subject’s request with a view to his/her entering a contract with the organisation. As good practice, organisations are encouraged to rely on the above circumstances only if they are una - ble to rely on legally enforceable obligations or speci - fied certifications. 3.6 Threat-Led Penetration Testing Critical Information Infrastructure Under the CII Cybersecurity Code, owners of CII are required to conduct regular penetration testing on

291 CHAMBERS.COM

Powered by