Financial penalties of $10,000 each, were imposed on Propnex Realty and JP Pepperdine for failing to make reasonable security arrangements to prevent unauthorised access of individuals’ personal data stored online.
Propnex was also directed to cease the storage of documents containing personal data via its system until a security scan had been conducted.
On 28 December 2015, the Personal Data Protection Commission (“Commission”) received a complaint from the Complainant in relation to the publication online of the Organisation’s internal Do Not Call list containing the personal data of 1765 individuals, including the Complainant and her sisters (“PropNex DNC List”).
Following the Complainant’s complaint, the Commission then undertook an investigation into the matter.
The Complainant alleged that she and her sisters had been receiving marketing calls and messages from various telemarketers (including moneylenders) on their mobile telephone numbers even though they had not consented to being contacted.
When the Complainant spoke to one of the telemarketers over the phone to ask where he had obtained her telephone number, she was informed that her name and telephone number were available on the Internet. This prompted the Complainant to conduct a search on the Internet for her name. Among the search results was a URL link (“Link”) to the PropNex DNC List dated 29 July 2015 in PDF format.
The PropNex DNC List contained, amongst other things, the Complainant’s full name, mobile number and landline, residential address and internal instructions to the Organisation agents regarding the Complainant.
On 31 December 2015, the Commission informed the Organisation’s Data Protection Officer of the Data Breach Incident and requested that the PropNex DNC List be taken down. The Organisation confirmed that the PropNex DNC List belongs to the Organisation and that it had no knowledge of the Data Breach Incident until it was notified of the complaint.
On 4 January 2016, the Organisation deleted the PropNex DNC List from its VO System and informed Google to exclude the Link from its search results. The Organisation also took steps to prevent a reoccurrence of the Data Breach Incident, by introducing a new way of disseminating the DNC List internally through a secured database and which can be searched using an authenticated web form.
Investigations disclosed that in or around July 2015, the PropNex DNC List was in PDF format and placed in a shared folder for internal use on the VO System which was accessible only by the Organisation agents and staff through authenticated login. Earlier versions of the PropNex DNC List had been placed in the same shared folder since the beginning of 2015.

JP Pepperdine Group Pte. Ltd.

On 25 October 2015, the Complainant informed the Personal Data Protection Commission (the “Commission”) that any member of the public could readily access the personal data of members that had joined the Organisation’s membership programme by entering a randomly simulated membership number on a webpage (http://goo.gl/5BX9Rr, a Google URL Shortener that redirects to http://ascentis.com.sg/microcrm/JacksPlace_memberportal/searchprofil e.aspx) listed on the Organisation’s membership brochure (the “Webpage”).
Members of the public can also perform a search (without inputting any search parameters) using the search functions available on the Webpage.
The Organisation operates a number of restaurants in Singapore under various brands (e.g. Jack’s Place, Eatzi Gourmet). The Organisation has a membership programme for its customers. Participating in the membership programme entitles members to special promotions and discounts across the different restaurants operated by the Organisation.
Each member would be assigned a 7-digit membership number by the Organisation. Membership numbers run sequentially. At the time of the investigation (December 2015), the Organisation had approximately 30,000 members.
The personal data that was publicly accessible through the Webpage included, names of members, gender, marital status, nationality, race, NRIC/Passport number, date of birth, mobile phone number, home phone number, email addresses, residential addresses, and other membership account details.
On 29 October 2015, after receiving the Commission’s notification, the Organisation introduced security features to the Webpage by incorporating a password protection feature such that the Webpage was no longer publicly accessible and could only be accessed after authentication.
The Commission then stated that it emphasises that it takes a very serious view of any instance of non-compliance under the PDPA, and it urges organisations to take the necessary action to ensure that they comply with their obligations under the PDPA. The Commission will not hesitate to take the appropriate enforcement action against the organisation(s) accordingly.

Subscribe
Notify of
0 Comments
Inline Feedbacks
View all comments
You May Also Like

送坐轮椅老人到目的地 外籍工友善举赢掌声

阿叔满载着东西,推着轮椅缓缓而行,看到这一幕一位外籍工友毅然放下手头工作,推着老人家到诺维娜广场Velocity。见到这一幕的网友备受感动,在天桥下拍下照片,将温馨分享到网上。 署名Nicola Peck的网友于周二(11月5日),在脸书上分享了这一幕。 他指出,当时在人行天桥上,看到诺维娜教堂附近,汤申路靠近法院巷工地的一名外籍工人,突然刚下工作走出工地。原来他是在看到一名经常在诺维娜广场,坐在轮椅上进行乞讨的老伯经过现场时,毅然趋前主动帮忙推着轮椅,将老人家送到目的地去。 这一幕令网友感动非常,他在帖文写道“你是否知道,有多少拥有更好的教育背景,且来自更好社会经济环境的人士会做这些?这些人值得我们的支持。” “他们应该享有更好的工作环境、更好的生活条件以及更高的酬薪。最重要的,他们值得我们尊重。” 网民们纷纷认同其说法,并展现的是人性。 他们也指出,这不仅限于外国员工,但是有些从事低收入工作者,都反而拥有更宽广的胸怀。

Deliveroo newly introduced tipping functionality amassed nearly S$30,000 to support its restaurant partners

On 13 May, Deliveroo Singapore announced a string of measures to support its…

抄袭王瑞杰? 马国旅游局:我们也有东海岸计划!

还记得提名日(6月30日)当天,临危上阵东海岸集选区的原副总理王瑞杰,似乎还未准备好与选区有关的致辞稿,结果演说只能不断重复“东海岸”,成为选举期间的热门笑料之一。 当时在成功提名后,王瑞杰发表感言,指出:“对于东海岸的居民,我们都有针对东海岸的计划。我们有…东海岸…新加坡…我们都有东海岸的计划。我们关心东海岸。” 不过,不知是否纯属巧合还是存心恶搞,长提对岸的马来西亚旅游局,竟也“抄袭”王瑞杰,在旅游宣传广告中标榜“我们也有东海岸计划”! 在马国旅游局的脸书贴文,也写道:“我们也有东海岸的计划,我们有东海岸-马来西亚。我们都共同有,东海岸计划,我们关心您,马国驻新加坡旅游局”。接着不忘介绍该国东海岸的知名景点,如热浪岛、刁曼岛等等。 不过不仅仅是马来西亚,就连泰国旅游局也要来恶搞!泰国旅游局也借机推广泰国东海岸的景点,例如芭达雅、春武里府、庄他武里等。 不得不重温下王瑞杰的经典演说:

涉发布刘凯案事故照片 前国民服役人员被判罚款3000元

全职国民服役人员刘凯军训中丧命案,21岁前国民服役人员因散传播事故现场照片,违反官方机密法令,被判罚款3000元。 该名被告是现年21岁的海卡尔(译音,Mohamad Haikal),被控抵触三项官方机密法令,当时被告仍是一名民防部队的全职国民服役人员,位于裕廊消防局服役,而控方以其中两项提控,被告随后也认罪。 22岁的全职国民服役人员刘凯是在去年11月3日上午10时许,假惹兰慕莱军训地区参加野外训练时,所驾驶的路虎遭倒退的Bionix步兵战车撞上,当场昏迷,随后重伤离世。 根据案情显示,意外发生后,民防部队派遣了15名民防部队人员到场救援,其中也包括被告,当时他与另名同僚以手机拍下现场照片,共7张,事后再将照片通过Whatsapp群组外泄出去。该群组内共有24名成员,同时它也将照片发给一名正在新加坡武装部队服役的朋友。据了解,照片均拍到Bionix步兵战车压在路虎军车上方的情况。 而时任裕廊消防局局长迪内斯(上尉)同一天接获举报后,立刻召集消防局的所有人员,并且展开调查,确认了两名非法拍照者。 根据被告律师表示,他目前已退伍,正在新加坡国立大学念书。对于所犯下的错误感到后悔,并表示不会再犯同样的错。 除了被告以外,日前亦三人被控散播现场照片,有其中两人莫哈末阿里夫(Muhammad Arif,22岁)和陈建杰(Brandon Tan Jien Jet,21岁)在案发时,是民防国民服役人员,而另一外人莫哈末扎其(Muhammad…