ENHANCE SINGAPORE'S STANDING AS A TRUSTED HUB Build a trustworthy data ecosystem The compromise of personal data can cause adverse disruptions to the affected individuals and businesses. With increasing amounts of data migrating to computer systems and electronic devices, there is a need to secure these systems and safeguard individuals’ data against theft and misuse. At the same time, organisations can leverage good personal data management to gain a better understanding of their customers, increase business efficiency and effectiveness, and boost customer confidence. Trust is essential for a data-enabled economy and society. To build a trusted data ecosystem, our organisations have to shift from compliance to accountability. Singapore will: Work with organisations to embrace data protection as part of their corporate culture; Professionalise Data Protection Officers to support the effective implementation of data protection measures; and Enhance Singapore’s standing as a trusted data hub by introducing Data Protection Trustmarks and working with foreign Data Protection Authorities to facilitate crossborder data flows. Build a relationship of trust A reliable and robust data ecosystem promotes trust and innovation. To help organisations take ownership in promoting trust and adopting a mindset of accountability, the Personal Data Protection Commission (PDPC) will develop a Data Protection Management Programme to help organisations embrace data protection as part of their corporate culture. Robust data protection processes are needed to enable organisations to better use data. To do so, organisations should adopt a DataProtection–by-Design approach, which factors data protection as a key consideration in the early stages of any product or service development. The rigour of this framework will also require that businesses conduct Data Protection Impact Assessment as part of the design, rollout and review of systems, 30 CHAPTER 2 Ongoing efforts for personal data protection Personal Data Protection Seminar 2016 applications and business processes. Given that data breaches can and will still happen despite organisations’ best efforts at securing personal data, PDPC is studying a mandatory breach notification for serious data breaches. Under the Personal Data Protection Act (PDPA), organisations are to take reasonable steps to manage and secure personal information that they hold. Today, the PDPC adopts a multi-pronged approach in supporting organisations, particularly the Small and Medium-sized Enterprises (SMEs). Through industry briefings, online training resources, and advisory guidelines, SMEs are equipped with information on the requirements of the PDPA and good data management practices to adopt. Professionalise Data Protection Officers Enhance Singapore’s standing as a trusted data hub Today, Data Protection Officers (DPOs) hail from a range of occupations. PDPC will develop a Data Protection Competency Framework (DPCF) to grow DPOs as a professional career dedicated to overseeing data protection requirements of organisations. This will ensure that DPOs are equipped with the relevant skills, competencies, and certifications needed to do their jobs. PDPC is currently developing a system of Data Protection Trustmarks to certify organisations’ data protection processes. By helping organisations gain mutual confidence in each other’s transactions involving personal information, the Trustmarks will increase compliance and reinforce Singapore’s standing as a trusted data hub. Another focus area is the facilitation of cross-border data flows. PDPC will identify areas of collaborations and cooperation with well-established foreign Data Protection Authorities. It will participate in global multilateral networks to mutually recognise the adequacy of each economy’s data protection laws, thus enabling transfers of data across jurisdictions. Cleaner Internet The Internet’s ability in allowing anyone to send large volumes of any form of information – data, voice, video - to another user has propelled it to be the world’s dominant communication platform. However, this design exposes end-users' machines to malicious software that can hijack these devices to blast phishing emails and even launch cyber-attacks. The increasing number of infected machines spewing malicious traffic into the Internet has made cyberspace less safe for everyone. Just as we would stop people who eject sewage into clean water pipes, we will also have to block users who may be unwittingly polluting the Internet pipeline and alert them on measures for cleaning up their machines. As “gatekeepers” managing the Internet gateways and enabling information flows across the Internet, local Internet Service Providers (ISPs) play an essential role to achieve a safer Internet space. In 2011, the Government issued the first Secure and Resilient Internet Infrastructure Code of Practice to designated ISPs to ensure that sound security is in place to deal with current and emerging cyber threats. The Info-communications Media Development Authority (IMDA) will continue working with the ISPs to secure Internet infrastructure for businesses and individuals. Singapore will join the global community to measure and improve the health state of cyberspace, and CSA will collaborate with international organisations on this front. To complement these efforts, the Singapore Computer Emergency Response Team (SingCERT) will continue to obtain early warning of cyber threats and alert users on the preventive measures they can adopt. CHAPTER 2 31

Select target paragraph3