New Commission's Decisions and Undertakings on 10 March 2023

10 Mar 2023

For breaching the Protection Obligation, a financial penalty of $62,400 was imposed on Eatigo International for failing to put in place reasonable security arrangements to protect the personal data in its possession or under its control. Sembcorp Marine was found not in breach of the PDPA in relation to an incident whereby threat actor(s) exfiltrated personal data by exploiting a zero-day vulnerability present in an application.

The PDPC also accepted an undertaking from one organisation which implemented remediation plans that rectified the immediate breach and addressed systemic shortcomings to ensure continual compliance with the PDPA.

Access the Decisions here and Undertakings here.

Follow us on Telegram for the latest updates on personal data protection: