Why should Singapore SMEs care about EU's General Data Protection Regulation?
ORGANISATIONS all over the world have been scrambling to prepare for the European Union (EU) General Data Protection Regulation (GDPR), which came into force on May 25. Many multinational corporations, with sufficient resources to create a robust data security framework, would have started preparing their organisations months in advance to ensure they are GDPR compliant.
Indeed, the GDPR is affecting millions of companies worldwide, requiring any business that captures, stores or processes the personal data of EU residents to comply with the GDPR. This also includes small and medium-sized enterprises (SMEs) in Singapore.
It doesn't concern me, does it?
Believing that they are too small to be affected, SMEs may think that the GDPR can do them no harm. However, with more Singapore SMEs providing their services to customers internationally, the impact of the GDPR will be more widely felt than expected.
Globalisation has provided more opportunities for local SMEs to expand their horizons and sell their products and services to foreign markets or to provide services to companies that do. In fact, according to a survey from DP Information Group, the combined profits of the top 1,000 SMEs in Singapore plunged by 17.1 per cent to S$2.9b in 2017, as local SMEs channel their business towards foreign markets.
This could potentially imply that there is a greater chance that local SMEs are coming into contact with EU residents, either directly or indirectly, sometimes without being explicitly aware of it. As such, SMEs may need to pay greater attention to the GDPR and how it may impact their business.
An unbearable cost for SMEs . . . not to comply
In the grand scheme of things, data security is usually a relatively low priority for SME business owners, who may have other more pressing matters to attend to, such as financial concerns and other day-to-day operational issues.
For instance, the 2017 SME Development (SMED) Survey found that 35 per cent of SMEs have finance-related issues - a 13 per cent jump in the last 12 months and the highest percentage since the survey began tracking this issue in 2011.
However, GDPR can hit Singapore SMEs' bottom line. Hard. Local regulation, the Personal Data Protection Act (PDPA), may impose a maximum fine of S$1 million on any organisation which is found to have breached its regulations. This pales in comparison to the penalties laid out by the GDPR.
Any organisation that is found to have breached regulations under the GDPR can be fined up to 20 million euros or 4 per cent of an organisation's global turnover. If we convert that to Singapore dollars, that could easily be more than S$30 million - 30 times larger than a PDPA fine!
While these numbers may seem daunting to hear, complying with the GDPR may not necessarily be that expensive, especially if SMEs are already PDPA compliant.
Organisations need to ensure that they protect any personal data within their control and destroy data that no longer serves the purpose for which it was required.
SMEs that comply with the PDPA are well on their way to being GDPR compliant as well. With awareness of their obligations under the PDPA at 92 per cent, Singapore organisations are in a strong position to protect their data and comply with the GDPR.
The importance of adopting a holistic data security policy
To comply with the PDPA and GDPR, SMEs are encouraged to adopt a holistic approach to data security, paying attention to both digital and physical data.
With the Singapore government providing over S$80 million in grants to help SMEs digitise, it is apparent that many SMEs are still on the road to becoming fully digital. As such, there is still ample confidential data stored on hard copy.
Physical data that is left unprotected can make it easier for a physical data breach to happen, accidental or deliberate, if the data isn't securely destroyed. It is still possible for personal data to be stolen from physical documents which are not destroyed securely. For instance, this year a youth stole a physical list of NRIC numbers from a community event and used the personal information he obtained to illegally apply for mobile phone plans.
What SMEs can do to safeguard their data
Even if SMEs feel that data security is important, they may lack the resources or the know-how to enforce GDPR compliance. However, SMEs can take small steps to ensure that their organisation protects all data in their care, be it digital or physical. Engaging the services of a trusted document destruction provider can help SMEs securely destroy all unwanted confidential data. If in doubt, SMEs can consider shredding all documents to fully prevent any personal data from falling into the wrong hands.
Furthermore, SMEs should familiarise themselves with the PDPA and review their current data protection practices. Appointing a Data Protection Officer (DPO) is mandatory under the PDPA. Despite this, a recent 2017 PDPC Industry Survey found that only 51 per cent of organisations have appointed a DPO so far.
DPOs can greatly assist in promoting a culture of data security, ensuring that SMEs stay on track with the PDPA and GDPR compliance requirements. In addition, being aware of changes in the data security landscape and staying open to new practices can help SMEs protect all data in their care and uphold their reputations as businesses that can be trusted.
TRENDING NOW
Fed hike throws Singapore banks a margin lifeline; UOB most likely to feel impact
He built the Vingroup empire. Now South-east Asia’s richest man is handing some key roles to his sons
Real-estate veteran Desmond Sim quits from CEO roles at Realion, ETC
Chagee, Mixue and Luckin won the market. Sustaining their edge is the harder part