Cybersecurity 2026

SINGAPORE Law and Practice Contributed by: Lim Chong Kin, David N Alfred, Albert Pichlmaier and Goh Boon Yeow, Drew & Napier LLC

For cloud and digital infrastructure services, the amended Cybersecurity Act introduces a framework to regulate major FDI service providers. Foundational digital infrastructure services are currently specified to include cloud computing services and data centre facility services, with definitions that expressly con - template services delivered from systems in Singapore or outside Singapore. In addition, the government has been studying a Digital Infrastructure Act to enhance resilience and security of key digital infrastructure and services, and the IMDA has issued advisory guidelines for cloud services and data centres as interim uplift measures. 4.2 Key Obligations Under Legislation Please refer to 1.2 Cybersecurity Laws , 2.2 Critical Infrastructure Security Requirements , 3.2 ICT Ser- vice Provider Contractual Requirements , 3.3 Key Operational Resilience Obligations , 3.4 Operational Resilience Enforcement and 4.1 Cyber-Resilience Legislation . 5. Security Certification for ICT Products, Services and Processes 5.1 Key Cybersecurity Certification Legislation While there is no prescribed cybersecurity certifica - tion legislation in Singapore, the CSA offers, admin - isters and supports the use of certification schemes to provide assurance to customers that the product has been objectively assessed from a cybersecurity standpoint. The CSA Cybersecurity Certification Centre operates several schemes which cover ICT product security in general. For example, besides the CLS, the Singapore Common Criteria Scheme provides a cost-effective regime to evaluate and certify the security of IT prod - ucts in Singapore against the Common Criteria (CC) standards (ie, ISO/IEC 15408 series). The CSA also operates the National IT Evaluation Scheme. This scheme evaluates IT products for high security assurance by referencing international stand - ards such as the CC.

The PDPC and the IMDA jointly developed the Data Protection Trustmark (DPTM) Certification to help organisations demonstrate compliance with the PDPA. The DPTM Certification also incorporates ele - ments of international benchmarks and data protec - tion best practices. Since 2025, the DPTM has been administered by the Singapore Accreditation Council. 6. Cybersecurity in Other Regulations 6.1 Cybersecurity and Data Protection General Requirements Under the PDPA In the context of personal data protection, organi - sations are required to put in place data protection policies and practices to ensure and demonstrate compliance with their obligations under the PDPA. Specifically, these requirements include: • appointing a data protection officer to oversee compliance with the PDPA; • developing and implementing data protection poli - cies, practices and procedures to ensure proper processing of personal data; and • providing adequate training to staff that handle and process personal data. Protection Obligation Under Section 24 of the PDPA, an organisation is required to make reasonable security arrangements to protect personal data in their possession or under their control. Data Breach Notification A “data breach” is defined in the PDPA to mean: • the unauthorised access, collection, use, disclo - sure, copying, modification, or disposal of personal data; or • the loss of any storage medium or device on which personal data is stored in circumstances where the unauthorised access, collection, use, disclosure, copying, modification, or disposal of the personal data is likely to occur. Where an organisation has reason to believe that a data breach affecting personal data in its possession or control has occurred, it must conduct an assess -

293 CHAMBERS.COM

Powered by