Singapore companies ill-prepared for Europe's data-protection law

New law with extra-territorial reach kicks in on May 25, but only 10% of Singapore businesses are ready for it, compared to 33% globally: EY

Annabeth Leow
Published Tue, May 8, 2018 · 09:50 PM

    Singapore

    WITH Europe's formidable new digital privacy standards on the cusp of kicking in, professional services firms in Singapore see an uphill task in making companies here aware of and complying with the new framework.

    The General Data Protection Regulation (GDPR), which takes effect on May 25, has vast extra-territorial reach in its mission to protect the personal information of all European Union residents. It will have the teeth to fine companies up to 4 per cent of their annual global turnover or 20 million euros (S$32 million) for failing to ascertain the kind of personal data they have on customers protected by these rules and how that data is being used.

    Technology lawyer Stella Cramer, a partner at Norton Rose Fulbright, told The Business Times recently: "My concern in Asia is that companies are still getting to grips about whether or not it applies to them. "Even to this day, we're getting new work in from clients who are just realising that GDPR may impact them."

    EY found in a February poll that just 10 per cent of Singapore companies have GDPR compliance plans - well under the global average of 33 per cent.

    Ms Cramer said GDPR compliance has had "a costly and disruptive impact" on her clients; this squares with the results of a PwC study last year, which found that most American companies will fork out between US$1 million and US$10 million to get up to scratch.

    Given the long arm of the GDPR, Singapore companies may be more exposed than executives think.

    Gary Gardiner, head of security engineering for the Asia-Pacific, Middle East and Africa at Check Point Software Technologies, said: "Singapore has a large expat community, so this could hit most sectors of business in Singapore that hold personal data."

    MediaMath, a marketing firm which taps data for the programmatic advertisements that follow Web users around, counts more than 40 clients in Singapore, and they include homegrown brands that target European consumers.

    Alice Lincoln, its vice-president of data policy and governance, said: "As marketers in Singapore are looking to deliver more customer-centric, relevant and meaningful marketing experiences, data-driven marketing through the use of programmatic technology has risen in prominence.

    "There is no doubt that the upcoming GDPR implementation will now prompt questions globally on how the digital advertising ecosystem is using data and will challenge the industry to evolve and adapt to the regulation."

    Data moguls aside, other consumer-facing sectors - such as retail, hospitality, telecoms, healthcare, banking and insurance - are most likely to be hit by the GDPR.

    Gartner research director Manjunath Bhat told BT: "These industries thrive on generating demand by tracking user preferences and directing products and services using targeted advertising or proximity marketing - without explicit user consent. This is exactly what GDPR is trying to avoid."

    Julian Quinn, Asia-Pacific vice-president at data firm Qlik, said the challenge for many organisations lies in "understanding not only what personal data they have in their multiple systems and even individual files, but also understanding the relationships and connections of that personal data, as well as who has access to it".

    Companies here have had some time to get used to Singapore's Personal Data Protection Act (PDPA), which came into force in mid-2014, but Gartner's Mr Bhat noted that not as many inquiries about GDPR have come in from Asia as from Europe and North America.

    Most companies in Asia are ensuring compliance with their country-specific privacy regulations, for example, PDPA in Singapore, he said.

    The GDPR also encompasses greater protections, such as the "right to be forgotten", which lets individuals ask for information about them to be deleted from companies' databases.

    "While the Singapore PDPA has been an excellent step for privacy and protection, companies that have a regional and larger global ambition or footprint will find themselves directly impacted by GDPR legislation, which entails additional investment to deal with broader compliance requirements and more complex issues."

    Ms Cramer of Norton Rose Fulbright, noted that the difference in scope could reflect different societies' objectives in the area of data privacy laws. "There's a more supportive regime for using personal data for business purposes in both the US and Singapore, but what we see in these jurisdictions is greater emphasis around data breach," she said.

    Sally Murphy, a senior associate at law firm Clifford Chance, echoed this, saying: "The European trend in data protection legislation has always been to focus heavily on the rights of an individual, whereas I think Asian jurisdictions tend to take a slightly more business-friendly approach - 'We still need to encourage e-commerce, we still need to encourage trade'."

    Homegrown corporations approached by BT said they have been preparing for the rules, with at least one of them expecting business to benefit from GDPR requirements.

    Singapore Airlines confirmed that it will be subject to the GDPR. "We are taking appropriate actions, including updating our privacy policy," its spokesman said, but declined to give more details.

    Transport operator ComfortDelGro, which runs in Britain and Ireland, expects to be ready by May 25, said group corporate communications officer Tammy Tan. The team in Britain, in particular, has been tackling GDPR compliance since mid-2017.

    "Areas we have paid particular attention to include data minimisation, pseudonymisation and increased transparency," she said.

    Keppel Corporation - which owns a data centre trust, Keppel DC Reit - even stands to gain from the tight rules on personal data moving out of Europe. A spokesman said: "Over the past two years, the onshoring of data within EU member countries has driven demand for high-availability data centre space in anticipation of the GDPR's implementation.

    "These range from newbuild and fit-out requests that leverage Keppel data centres' extensive development experience and the Alpha Data Centre Fund's access to capital to leasing enquiries for Keppel DC Reit from various multinational companies."

    Ms Lincoln from MediaMath said individual companies might be daunted by compliance responsibilities, but that the marketing industry "has worked to provide mechanisms which advertisers can adopt to strengthen their compliance".

    MediaMath now chairs the Interactive Advertising Bureau's Europe working group on consent, which has built a transparency and consent framework to help industry players get into shape for the GDPR.

    Ms Cramer told BT that, for clients this late in the game, the priority should be in bringing themselves up to code with the rules on notifying end-users about privacy and restricting the transfer of personal data, as breaches in these areas carry heftier penalties.

    But she said: "We think there'll be quite a bit of remediation work continuing, post-May 25."

    Meanwhile, Alastair Sim, vice-president of global marketing for the Asia-Pacific at data analytics firm SAS, said: "As Singapore businesses internationalise and engage with customers around the world, they need to ensure the right data privacy and protection processes are in place. ... We foresee more companies adopting the standards as a new benchmark in the digital economy."

    Yet, even after the GDPR takes effect, industry watchers warned businesses against resting on their laurels. Other jurisdictions could come up with their own standards, while emerging technologies might fall afoul of the tightened rules.

    For example, the permanence of the distributed blockchain ledger - in theory, an indelible record shared by all users on the chain - would pose a challenge to GDPR protections, such as the right to be forgotten.

    Clifford Chance partner Luke Grubb argued: "It's about getting the balance right between protecting consumers and the rights of the individual, versus embracing new technology and being able to gain an advantage from the use of that new technology."

    David Kemp, an information management and governance business consultant at enterprise tech giant Micro Focus, told BT: "The GDPR, of course, was set up for harmonisation within the European Union countries.

    "But which are four or five countries that are extremely keen to be compliant with this, because they're dealing with EU citizen data? The United Kingdom, with Brexit, Norway, Switzerland, Israel, and Turkey. . . .

    "It's to do with the totally multi-jurisdictional, multi-market way in which money is grown. So that means that even the poorer economies, as they're coming up, will need to include some of these standards in order to safeguard their citizens, to keep the wealth there."

    Ms Cramerremarked: "What's been interesting with GDPR is that we see different countries across Asia appear to adopt different parts of it, so legislators in the region likely have been looking at GDPR and are saying: 'This looks interesting; I'll take the right to be forgotten and drop that into my law', or, 'I'm going to take the mandatory breach requirements and drop them into my law'. . . . So you see parallels, but no global standard, unfortunately."

    Ms Murphy described an Asia-wide privacy law as "a very sensible step", but added: "There are so many different levels of privacy compliance across Asia. With Europe harmonising the individual member state rules under a single regulation - there's 30 years' worth of privacy compliance and it still took them years to come up with a regulation. I think, for Asia, the gap is much bigger."