Navigating Data Breach Challenges: Insights for Organisations
Navigating a potential data breach poses numerous questions for organisations. What should my organisation do when there is a potential data breach? Should the organisation directly submit to the Personal Data Protection Commission (PDPC) for the incident to be handled under an Expedited Breach Decision Procedure? Should the organisation first request the matter to be handled under a Voluntary Undertaking Procedure instead? When can the organisation expect the PDPC to respond to its requests? Lawyers or in-house counsel may encounter these questions when faced with data breaches and communications with the PDPC, especially those who may not be familiar with data protection and cybersecurity practices given it might not be their areas of expertise.
The Personal Data Protection Act 2012 (PDPA) came into effect on 2 July 2014 to govern the way organisations handle the vast amount of personal data in their possession and/or control, and the PDPC was established on 2 January 2013 to assist with the enforcement of the PDPA and its regulations. Since the inception of the PDPA and PDPC, it is understandable that navigating the intricacies of data protection and data breaches may pose challenges for organisations. At the same time, circumstances and considerations happen that guidelines might not foresee, leaving organisations and lawyers/in-house counsel potentially in a bind when faced with difficulties.
This article will analyse a few observations and possible challenges that organisations and their lawyers/in-house counsel may face, taking into account some of the commercial considerations that are important to the organisations.
Disclosure of Information in Developing Cases
Generally, when there is a data breach, either a complaint is made to the PDPC or a self-report is made by the organisation to the PDPC. When facing a notifiable data breach, organisations are required to promptly notify the PDPC, within three calendar days, providing as much details about the breach as possible. However, in scenarios where information is still developing from investigations and facts are not entirely clear, organisations might grapple with the extent of information disclosure required to the PDPC and the appropriate timing for updates. While an initial report can be generated by the organisations, uncertainty could arise regarding the necessity of ongoing investigations to continuously update the PDPC. Organisations might not know if they could/should wait for a major development before updating the PDPC. While the straightforward approach suggests continuous updates as information unfolds, this process may often result in multiple exchanges between the organisation and the PDPC, leading to possible increased time and resources spent — a less than ideal scenario from a commercial perspective.
Potential Implications of Disclosure of Information to the PDPC
In the course of investigations, organisations often struggle with determining the extent of information disclosure required to comply with the PDPA. While Singapore recognises legal professional privilege, where certain confidential communications between a client and a lawyer are protected from disclosure, lawyers and in-house counsel unfamiliar with data breach investigations might be unsure on the issue of privileges and whether it is advisable to utilise the legal professional privilege religiously.
For example, when a data breach forensic report is being commissioned and subjected to legal professional privilege, should the full forensic report be shared with the PDPC or can counsel selectively disclose information? This becomes particularly pressing when organisations might not wish to disclose less-than-favorable information found in forensic reports that are unrelated to the data breach, fearing repercussions for the organisation. Consequently, the issue of privilege demands clarity, especially for multi-jurisdictional matters where differing privilege rules complicate the situation further.
There are also questions on whether it is more advantageous for organisations to provide a full forensic report as a demonstration of complete cooperation. Conversely, would organisations be penalised for failing to produce forensic reports and to engage forensic consultants? If an organisation that had taken prompt remedial actions (but did not engage forensic consultants as part of such actions), found it challenging to determine the exact cause of the breach – would the organisation face penalties during a PDPC investigation?
Moreover, could organisations be penalised for disclosing unrelated but unfavorable information, as mentioned earlier? In other jurisdictions, it is noted that several enforcement/judicial decisions went against companies that engaged forensic advisors and submitted written reports. These are among the possible questions organisations might have to grapple with.
Communications with the PDPC
Another difficulty that lawyers and in-house counsel face is the unclear timelines. Currently, there appears to be no specific timelines as to when the PDPC will respond to a lawyer or in-house counsel’s requests and notifications on behalf of the organisations. Thus, representatives do not know how long they should be waiting. Given the amount of work needed, the PDPC understandably might not be able to commit to specific timelines. That being said, representatives of such organisations do not wish to rush the PDPC, yet at the same time, they need to know how to manage or assuage their stakeholders’ concerns, leaving them in a bind.
Another area of concern for counsel is the tone of communication during the investigation process. When is the investigations process a friendly fact-finding exercise with the PDPC and at which point might it become potentially adversarial? This ambiguity is significant to the organisations’ lawyers/in-house counsel as they aim to maintain a cooperative atmosphere to facilitate efficient investigations while knowing when to appropriately step in to protect the interests of their clients. Based on what some legal practitioners familiar with data breach investigations have observed to date, the investigations are generally conducted by the PDPC in an inquisitive but non-aggressive manner.
Mitigating Factors
Considering that penalties and fines meted out could be hefty, organisations are keen to know what are some ways that they could mitigate their losses when such data breaches occur. Currently, the PDPC has helpfully set out in its Advisory Guidelines on Enforcement of the Data Protection Provisions past enforcement decisions in which factors were considered in the processing of determining the financial penalties. For instance, the disclosure of sensitive personal data (in particular medical condition) might be treated as an aggravating factor. Conversely, if the number of affected individuals, and the number and type of personal data compromised is small, a lower financial penalty might potentially be issued.
To perhaps take it one step further, self-reporting arrangements even before any data breaches occur might be considered by an organisation to encourage preventive practice. Prevention is always better than cure. Organisations may deliberately choose to come clean to the PDPC when they discover any incorrect or dubious data protection practices and seek assistance or advice to prevent any data breaches before they happen. In return, the PDPC could offer a non-binding confirmation if no issues are found. If faults were identified, the PDPC could offer leniency and allow organisations to rectify the issues without penalties.
While it is understandable that giving a blanket position on mitigating factors would be difficult, due to the unique nature of each case each, outlining the PDPC’s guiding principles when determining penalties (which the PDPC has done so) offers valuable insight for organisations navigating data breach situations.
Collaboration with the PDPC
Thus far, the article has been discussed from the perspective of the lawyers/in-house counsel of organisations. Shifting focus to the perspective of the PDPC, it is also important for counsel and organisations to recognise that the PDPC perhaps operates slightly differently from standard prosecutorial authorities. As mentioned, the PDPC appears to generally favour a cooperative and friendly approach to investigations. However, it has been observed that the organisations’ lawyers/in-house counsel might often adopt an adversarial stance, perhaps due to their conservative nature and position to fully protect their clients/employers’ interests.
While it is understandable that counsel prioritise protecting their clients and mitigating losses, withholding information might force the PDPC’s investigation officers to escalate matters due to perceived non-cooperation. This escalation may not align with the PDPC’s preferred approach of resolving issues collaboratively.
It is beneficial for lawyers and in-house counsel to be aware that balancing the interests of all parties involved, including the PDPC, organisations, and their lawyers/in-house counsel, is crucial for fostering a productive and efficient investigative process. Amicable communication and cooperation from all sides can facilitate smoother resolutions and minimise unnecessary escalations.
Conclusion
In conclusion, the complexities surrounding data breaches demand clear guidance and effective communication channels between organisations and the PDPC, which the PDPC has sought to achieve through its various advisory guidelines issued to date. As stakeholders continue to interact with PDPA, it is only natural that new challenges may potentially crop up due to unforeseen gaps. By addressing challenges in aspects such as disclosure of information and communications timelines, a smoother path might be paved for all stakeholders involved. With proactive measures and transparent protocols from the PDPC, organisations and counsel can navigate the intricacies of data breaches with confidence, ensuring compliance with regulations while mitigating potential damages to the organisations.
Cybersecurity and Data Protection Committee 2024

