New Commission's Decisions and Undertakings on 23 May 2024

23 May 2024

This month, the Commission has issued three Decisions and six Undertakings.

The first Decision resulted in a financial penalty of $74,000 for (i) failing to put in place reasonable security arrangements to protect individuals' personal data in its possession or under its control, and (ii) not appointing any individual to ensure its compliance with PDPA.

The second Decision involved Directions for failing to put in place reasonable security arrangements to protect individuals' personal data in its possession or under its control.

The third Decision imposed a financial penalty of $28,000 for failing to put in place reasonable security arrangements to protect its platform users' personal data in its possession or under its control.

In the Undertakings, six organisations implemented remediation plans to improve its compliance with the PDPA. The PDPC has accepted these undertakings having considered the number of affected individuals, the types of personal data involved and the impact of the Incident.

Access the Decisions here and Undertakings here.