SINGAPORE Law and Practice Contributed by: Lim Chong Kin, David N Alfred, Albert Pichlmaier and Goh Boon Yeow, Drew & Napier LLC
ment of whether it is a “notifiable data breach” in a reasonable and expeditious manner. A data breach is a “notifiable data breach” if the data breach (i) results in, or is likely to result in, significant harm to an affected individual; or (ii) is, or is likely to be, on a significant scale (ie, affecting at least 500 persons). According to the Personal Data Protection (Notifica - tion of Data Breaches) Regulations 2021 (the “Data Breach Regulations”), a data breach is deemed to result in significant harm to an individual if it relates to the following: • the individual’s full name or alias or identification number, and any of the personal data or classes of personal data relating to the individual as set out in the schedule to the Data Breach Regulations; and • all of the following personal data relating to an indi - vidual’s account with an organisation: (a) the individual’s account identifier, such as an account name or number; or (b) any password, security code, access code, response to a security question, biometric data or other data that is used or required to allow access to, or use of, the individual’s account. Upon assessing that the data breach is a “notifiable data breach”, the organisation must notify the PDPC in the prescribed form no later than three calendar days after assessment. The organisation must also notify each individual affected by the data breach, if the data breach results in, or is likely to result in significant harm to an affect - ed individual, unless one of the following exceptions applies: • if, on or after assessing that the data breach is a “notifiable data breach”, the organisation takes any action that renders it unlikely that the data breach will result in significant harm to the affected indi - vidual; or • if the organisation had implemented, prior to the occurrence of the data breach, any technologi - cal measure that renders it unlikely that the data
breach will result in significant harm to the affected individual. Where a data intermediary processing personal data on behalf of another organisation has reason to believe a data breach has occurred, it must, without undue delay, notify the primary organisation. 6.2 Cybersecurity and AI Computers or computer systems which support AI solutions may be designated as a CII (or as anoth - er designated entity) under the Cybersecurity Act if they are necessary for the continuous delivery of an essential service, and the loss or compromise of the computer or computer system will have a debilitating effect on the availability of the essential service in Sin - gapore. Following the amendments to the Cybersecu - rity Act that took effect on 31 October 2025, such sys - tems can be physical or virtual, and in certain cases, may be located outside Singapore where the statutory designation criteria are met. For further details, please refer to 1.2 Cybersecurity Laws , 1.3 Cybersecurity Regulators and 2.2 Critical Infrastructure Cyberse- curity Requirements . While there are currently no express cybersecurity obligations relating to AI in Singapore, several volun - tary frameworks and guidelines have been published relating to the development and use of AI. Amongst these, the Model AI Governance Framework for Generative AI sets out a systematic and balanced approach to address generative AI concerns while facilitating innovation. It recommends adapting the “security-by-design” concept. The framework also makes recommendations regarding incident reporting. After incidents happen, organisations need internal processes to ensure timely notification and remedia - tion of the incident. Depending on the impact of the incident and how extensively AI was involved, organi - sations should consider notifying both the public and the government. On 15 October 2024, the CSA published the Guide - lines and Companion Guide on Securing AI Systems (the “Guidelines on Securing AI Systems”). The Guide - lines on Securing AI Systems set clear expectations that AI systems should be secure by design and by
294 CHAMBERS.COM
Powered by FlippingBook