Singapore and Hong Kong to collaborate on personal data protection

Published Fri, May 31, 2019 · 09:50 PM

    Singapore

    SINGAPORE and Hong Kong have strengthened their collaboration on personal data protection, and will share their knowledge on data breaches to better prepare for a digital economy.

    With the signing of a memorandum of understanding (MOU), Hong Kong's Office of the Privacy Commissioner for Personal Data (PCPD) and Singapore's Personal Data Protection Commission (PDPC) will share their experiences, exchange best practices and undertake joint research projects and share information on potential or ongoing data-breach investigations, the two sides said in a joint statement on Friday.

    Singapore's PDPC is set up within the Infocomm Media Development Authority of Singapore, and plays the main role in administering and enforcing the Personal Data Protection Act in Singapore.

    At the signing of the MOU at the 51st Asia-Pacific Privacy Authorities' Forum in Tokyo, the PDPC was represented by its deputy commissioner Yeong Zee Kin; on the Hong Kong side, the MOU was signed by Stephen Wong, privacy commissioner for personal data.

    Tan Kiat How, commissioner of Singapore's PDPC, said: "A strong collaborative effort with our counterparts in Hong Kong and other jurisdictions is needed to advance personal data protection and prepare for a digital economy. We look forward to strengthening our working relations to enable all parties to collectively benefit from best practices, research and the sharing of information."

    Mr Wong said: "The MOU marks the joint efforts of Hong Kong and Singapore to strengthen the cooperation between the two jurisdictions, and provides a solid framework for promoting collaborative initiatives and information exchange in personal data protection.

    "It also clearly demonstrates the PCPD's commitment to stepping up cross-jurisdictional collaboration in exchange of expertise and information, so as to better prepare Hong Kong to enter into the new 'post-digital' era."

    This MOU is the outcome of initial talks between the two authorities last September. It also follows recent data breaches in their respective turfs.

    Lapses in Singapore have included the SingHealth data breach, in which hackers stole the personal data of 1.5 million patients; separately, there was a leak of HIV patient data and the personal information of blood donors was improperly made available online by an IT vendor.

    In Hong Kong last October, flag-carrier airline Cathay Pacific announced a data breach that had exposed the personal information of up to 9.4 million passengers.

    With the announcement of the enhanced cooperation between Hong Kong and Singapore, a jointly-developed manual, titled "Guide to Data Protection by Design for ICT (info-communications and technology) Systems", was released.

    This encourages organisations to proactively incorporate data protection considerations from the outset when developing ICT systems, the authorities said.

    The guide is now available for download at www.PCPD.org.hk and www.PDPC.gov.sg.