ENHANCE SINGAPORE'S
STANDING AS A TRUSTED HUB
Build a trustworthy data ecosystem
The compromise of personal data can cause
adverse disruptions to the affected individuals
and businesses. With increasing amounts of data
migrating to computer systems and electronic
devices, there is a need to secure these systems
and safeguard individuals’ data against theft and
misuse. At the same time, organisations can
leverage good personal data management to gain
a better understanding of their customers, increase
business efficiency and effectiveness, and boost
customer confidence.
Trust is essential for a data-enabled economy
and society. To build a trusted data ecosystem,
our organisations have to shift from compliance
to accountability.
Singapore will:
Work with organisations to embrace data
protection as part of their corporate culture;
Professionalise Data Protection Officers to
support the effective implementation of data
protection measures; and
Enhance Singapore’s standing as a trusted
data hub by introducing Data Protection
Trustmarks and working with foreign Data
Protection Authorities to facilitate crossborder data flows.
Build a relationship of trust
A reliable and robust data ecosystem
promotes trust and innovation. To
help organisations take ownership
in promoting trust and adopting
a mindset of accountability, the
Personal Data Protection Commission
(PDPC) will develop a Data Protection
Management Programme to help
organisations embrace data protection
as part of their corporate culture.
Robust data protection processes
are needed to enable organisations
to better use data. To do so,
organisations should adopt a DataProtection–by-Design approach,
which factors data protection as
a key consideration in the early
stages of any product or service
development. The rigour of this
framework will also require that
businesses conduct Data Protection
Impact Assessment as part of the
design, rollout and review of systems,
30
CHAPTER 2
Ongoing efforts for personal
data protection
Personal Data Protection Seminar 2016
applications and business processes.
Given that data breaches can and will
still happen despite organisations’
best efforts at securing personal data,
PDPC is studying a mandatory breach
notification for serious data breaches.
Under the Personal Data Protection
Act (PDPA), organisations are to take
reasonable steps to manage and secure
personal information that they hold.
Today, the PDPC adopts a multi-pronged
approach in supporting organisations,
particularly the Small and Medium-sized
Enterprises (SMEs). Through industry
briefings, online training resources, and
advisory guidelines, SMEs are equipped
with information on the requirements of
the PDPA and good data management
practices to adopt.
Professionalise Data
Protection Officers
Enhance Singapore’s standing
as a trusted data hub
Today, Data Protection Officers
(DPOs) hail from a range of
occupations. PDPC will develop
a Data Protection Competency
Framework (DPCF) to grow DPOs
as a professional career dedicated
to overseeing data protection
requirements of organisations.
This will ensure that DPOs are
equipped with the relevant skills,
competencies, and certifications
needed to do their jobs.
PDPC is currently developing
a system of Data Protection
Trustmarks to certify organisations’
data protection processes. By helping
organisations gain mutual confidence
in each other’s transactions involving
personal information, the Trustmarks
will increase compliance and
reinforce Singapore’s standing
as a trusted data hub.
Another focus area is the facilitation
of cross-border data flows. PDPC will
identify areas of collaborations and
cooperation with well-established
foreign Data Protection Authorities.
It will participate in global multilateral
networks to mutually recognise
the adequacy of each economy’s
data protection laws, thus enabling
transfers of data across jurisdictions.
Cleaner Internet
The Internet’s ability in allowing anyone to send
large volumes of any form of information – data,
voice, video - to another user has propelled it to
be the world’s dominant communication platform.
However, this design exposes end-users'
machines to malicious software that can hijack
these devices to blast phishing emails and even
launch cyber-attacks.
The increasing number of infected machines
spewing malicious traffic into the Internet has made
cyberspace less safe for everyone. Just as we would
stop people who eject sewage into clean water
pipes, we will also have to block users who may be
unwittingly polluting the Internet pipeline and alert
them on measures for cleaning up their machines.
As “gatekeepers” managing the Internet gateways
and enabling information flows across the Internet,
local Internet Service Providers (ISPs) play an
essential role to achieve a safer Internet space.
In 2011, the Government issued the first Secure
and Resilient Internet Infrastructure Code of
Practice to designated ISPs to ensure that sound
security is in place to deal with current and
emerging cyber threats. The Info-communications
Media Development Authority (IMDA) will
continue working with the ISPs to secure Internet
infrastructure for businesses and individuals.
Singapore will join the global community to measure
and improve the health state of cyberspace, and
CSA will collaborate with international organisations
on this front. To complement these efforts, the
Singapore Computer Emergency Response Team
(SingCERT) will continue to obtain early warning
of cyber threats and alert users on the preventive
measures they can adopt.
CHAPTER 2
31