口頭答弁 · 2019-02-12 · 議会 13

公共機関のデータ保護適用除外の審議

個人データ保護法を改正し、データ漏洩リスクに対応するために公共機関の適用除外条項を廃止すべきかについての議員質疑。政府は、公共部門はすでにデータセキュリティを確保するための複数の法律および政策を有していること、公共部門のデータ管理は民間部門とは異なり異なる法律体系が適用されていること、および関連規制を継続的に見直すことを強調する対応を示しました。核心的な争点は、公共機関のデータ保護を個人データ保護法の統一的な規制に含めるべきかどうかです。

重要なポイント

  • Public-sector data has multiple legal safeguards
  • Public-sector data management differs from private sector
  • Will continue reviewing the regulations
政府の立場

国防と同盟構築への継続的な投資

質問の立場

国防予算を支持する一方で、資源配分に関心を持ちます

政策シグナル

公共部門データガバナンスの継続的な強化

“Because of these important differences, we need and have adopted different approaches to the protection of personal data in the public and in the private sectors.”

参加者 (3)

全文翻訳(日本語)

Hansard 原文 · 2026-05-02

12番議員のSylvia Lim氏が通信・情報大臣に対し、公共部門のデータ保護違反の深刻性を踏まえ、『個人情報保護法』を改正し、公共機関に対する適用除外を廃止すべきかどうか問いました。

通信・情報大臣(S Iswaran先生)が応答します:議長先生、『個人情報保護法』(PDPA)は2012年に発効しました。デジタル化の進展に伴い、民間部門のデータ保護を強化する必要があることを認識しています。PDPAは民間部門のデータ保護について基本的な基準を設定すると同時に、個人データの合理的な使用の必要性とのバランスを取っています。

政府は常に、公共部門に託されたデータを保護する責任を真摯に果たしており、データガバナンスポリシーを継続的に強化しています。2001年以来、政府ガイダンス・マニュアル(IMs)には、公共機関間の個人データの使用、保持、共有、およびセキュリティを管理するための措置が含まれています。

2018年、『公共部門(ガバナンス)法案』(PSGA)が施行され、公共部門の個人データに対する追加的な保護が提供されました。これには、公務員によるデータの不正使用を刑事犯罪として定義することが含まれています。PSGA内のデータ保護基準もPDPAと一貫性を保っています。さらに、公共部門が収集するデータは、『秘密保護法』、『所得税法』、『感染症対策法』、『統計法』などの特定の法律によって保護されています。これらの法律は、すべての公共機関に対して高い基準の責任を共同で課し、機密データまたは秘密データの保護に対する追加的な要件を有しています。同時に、定期的な強制監査により、公共機関がデータ保護およびICTシステムセキュリティ基準を遵守していることが保証されています。

PSGAは、個人データを公共部門の共有リソースとして管理することを許可し、より良い政策立案とより機敏な公共サービスを促進します。例えば、シンガポール人が社会福祉事務所で経済援助を申請するとき、フロントラインスタッフは、他の関連機関のデータにアクセスできるため、その資格を迅速に評価できます。このように、申請人が提出する必要がある文書の数が減少し、公共サービスの効率性が向上します。対照的に、各民間部門組織は、自らが保有する個人データについて個別に責任を負い、異なるビジネス組織間での類似のサービス統合は期待されていません。

これらの重要な相違を踏まえ、公共部門と民間部門の個人データ保護に関して異なるアプローチを採用しています。これは、PDPAが民間部門にのみ適用され、PSGAおよび他の法律が公共部門のデータ保護を規制する理由です。また、PDPA、PSGA、およびその他の関連する法律を定期的に見直し、公共部門および民間部門の個人データ保護の観点から関連性と有効性を保つことを確認します。

議長:Sylvia Lim女史。

Sylvia Lim女史(Ayer Rajah選挙区):私には4つの補足的な質問があります。まず、大臣が言及した様々な法規とIMは、確かに公共サービスに対する基準を設定しています。しかし、大臣は同意されますか、これらの法規またはIMは、通常、データ漏洩時に市民が採ることができる救済措置について沈黙しているか不十分ですか?それらは違反した公務員に対する罰が比較的厳しいかもしれませんが、通常、市民の権利に対する明確な規定が不足しています。

第二に、大臣は同意されますか、PDPAの利点の一つは、組織によるデータ収集の必要性と個人のデータに対する所有権および保護権のバランスを図ろうとしていることですか?例えば、第3条は、個人データは個人に属し、個人はそのデータを保護する権利を有することを明確に認めています。

第三に、我々は最近SingHealth事件について議論しました。大臣は同意されますか、SingHealthはPDPA監視の範囲内にある機関であり、法案で定義される公共機関ではないため、SingHealthのサイバー攻撃事件は、PDPC(個人データ保護委員会)が公共の利益に関連して非常に有用な役割を果たすことができることを示していますか?PDPCはこの事件で、市民がそのデータがSingHealthによって十分に保護されていないと苦情を述べたことを指摘し、PDPCの調査結果がSingHealthおよび統合医療情報システム(IHiS)の改善を促す可能性があると述べています。

最後に、PDPAは確かに苦情手続きを提供しており、大臣がこれが市民にとって非常に有用であることを確認されることを希望しています。なぜなら、それは市民が損害を理由に政府機関に対して訴訟を起こすことを強要しないからです。これはPDPAが市民にもたらす実質的な利点です。

S Iswaran先生が応答します:議長先生、議員のご意見をお聞きしありがとうございました。すべてが質問だとは確定していませんが、いくつかはより観察に聞こえます。しかし、説明を試みます。

まず強調したいのは、我々が公共部門がPDPAから「除外される」と述べるとき(議員が使用した言葉のように)、これは公共部門がデータセキュリティと保護の観点から低い基準または異なる基準を有していることを意味しません。実際、先ほど述べたように、公共部門、特にPSGAの下では、PDPAを参照し、おおよそこれと一致しています。しかし同時に、公共サービスが高効率なサービスを提供するためにデータを使用する方法と期待が異なることを明確に認識しており、したがって異なるデータガバナンスアプローチが必要です。これが我々が異なるアプローチを採用する理由です。PSGA以外に、我々は他の関連法律も有しています。

議員へのご参考ですが、このアプローチを採用している国は我々だけではありません。例えば、カナダの連邦レベルでも、民間部門と公共部門に異なる法律を適用しています。したがって、これは基準が異なるまたはしきい値が異なるということではありません。実際、我々は公共部門に対して同一、あるいはさらに高いデータガバナンス基準を課しています。なぜなら、公共部門に託されたデータは信頼に基づいており、安全に処理される必要があるからです。

議員から提起された多くの質問がPDPA関連の要素、例えば苦情申し立て手続きに関連しており、一般市民はPDPCにデータ権に関する問題について苦情を申し立てることができます。議員はPDPAが個人データ権の保護と企業によるデータ使用権の間でバランスをとっていることを指摘しており、これは公共部門であれ民間部門であれ、私たちが努力している方向です。公共部門も個人データを保護する必要があり、同時にそれを公共資源として市民にさらに良いサービスを提供するために利用する必要があります。私たちが当たり前と思っている多くのサービスは、バックエンドでのデータ共有に依存しています。

苦情申し立て手続きについて、自分のデータが不当に処理されたと考えるいかなる個人も苦情を申し立てることができ、複数のチャネルがあります。

SingHealth事件について、議員はPDPCが有用な提案を提出したことを述べました。実際のところ、この事件全体の重要な提案は政府が設置した調査委員会(COI)から来ています。PDPCは早期に苦情を受け取ったため、COIの調査結果を参考にして、関連機関(SingHealthおよびIHiS)が違反しているかどうか、およびどのような処罰を受けるべきかを判断することにしました。ほとんどの提案は政府が主導するCOI手続きを通じて提示されたものであり、法律による強制ではありません。

救済に関して、一般市民が自分のデータが不当に処理されたと考える場合、大臣や関連部門に苦情を申し立てる権利があり、政府は措置を講じます。犯罪を構成していると考える場合、警察に報告することもでき、警察が調査します。

要するに、私たちは公共部門に対して同じく、またはより厳格なデータガバナンス基準を課しています。そうしなければ、スマートシティの建設とデジタル技術を活用した公共サービスの向上という私たちの取り組みは妨げられるでしょう。これが私たちがこの問題を真摯に扱う理由です。全体として、PSGAは公共部門のデータガバナンスに関する法律としてPDPAを参照しており、私たちは特定の分野に対する他の法律も持っています。

議長:シルビア・リム女史。

シルビア・リム女史:二つの追加質問があります。まず、大臣は先ほど、一般市民が自分の情報が公共機関により不当に処理されたと考える場合、苦情を申し立てることができると述べました。問題は、誰に苦情を申し立てるのかです。大臣は大臣に苦情を申し立てることができると述べました。個人データ保護に焦点を当てるPDPCが、この種の苦情を受け付ける役割を担うべきであることに大臣は同意しますか。結局のところ、彼らは個人データ保護分野の専門家です。

第二に、大臣は公共部門の機関が相互に接続しており、したがって異なるアプローチが必要であることを述べました。しかし、SingHealth事件も医療分野に一種の人為的な区別が存在することを示しています。SingHealthはPDPA定義の公共機関ではありませんが、保健省(MOH)と密接に関連しており、実際にはMOH Holdingsに所有されており、医療機関と親部門の間で頻繁にデータを交換しています。大臣は同意しますか、私のデータが医療グループの診療所に引き渡された場合、PDPCに苦情を申し立てることができますが、データが保健省に送信され、そこで漏洩が発生した場合、PDPCを通じて救済を求めることができないのです。これは医療分野に一種の人為的な区別を生じさせています。

S・イスワラン氏:議長、公共医療制度に関する大臣声明が間もなく行われることを考慮すると、私の回答は簡潔なものになります。その後、声明後にさらに詳しく説明することができます。

強調したいのは、「救済」という言葉がこの交流を通じて何度も出現しているということです。重要な点は、救済手段が存在する必要があるということです。救済がPDPCを通じたものであれ、PDPA、法律、その他の完全なメカニズムを通じたものであれ、重要な点は救済が存在する必要があるということです。

個人が具体的な状況に応じて苦情を申し立てることができると述べました。ついでながら、PDPCは時々公共部門に関連する苦情も受け取ります。受信者として、PDPCは拒否しませんが、管轄権に基づいてPDPA範囲外の事件を関連する政府機構に送付します。政府技術局(GovTech)は政府のデータセキュリティと保証システムを担当し、政府機関がIMおよび関連規則を遵守していることを確認するためレビューを行います。さらに、監査院も定期的にセキュリティレビューを行います。

私の見解は、一般市民は救済手段の欠如を心配する必要がないということです。実際のところ、彼らは複数の救済チャネルを持っています。民間部門と比較すると、公共部門は特定の側面でより多くのチャネルと手段を持つかもしれません。民間部門は通常、PDPCに苦情を申し立てるか、自分で訴訟を起こすことしかできませんが、公共部門はPDPC、GovTech、関連省庁、さらには警察への報告など、複数の手段を通じて支援を求めることができます。

したがって、議員の皆さんは安心していただきたいのです。適切な救済メカニズムを持っています。公共部門のデータガバナンス基準は決して民間部門より低くなく、むしろより高いです。これが私たちの期待です。

英語原文

SPRS Hansard 原本記録 · 取得日:2026-05-02

12 Ms Sylvia Lim asked the Minister for Communications and Information given the gravity of data protection breaches in the public sector, whether the Personal Data Protection Act should be amended to remove the exemptions for public agencies.

The Minister for Communications and Information (Mr S Iswaran) : Mr Speaker, the Personal Data Protection Act (PDPA) came into force in 2012. With the gathering pace of digitalisation, we recognised the need to strengthen data protection in the private sector. PDPA establishes a baseline standard for data protection in the private sector, balanced against its need to use personal data for reasonable purposes.

On its part, the Government has always taken seriously its responsibility to protect the data entrusted to the public sector and we continue to strengthen our data governance policies. Since 2001, the Government Instruction Manuals (IMs) already include measures to govern the use, retention, sharing and security of personal data among public agencies .

In 2018, the Public Sector (Governance) Act (PSGA) was introduced and it provided for additional safeguards for personal data in the public sector, including criminalising the misuse of data by public servants. The data protection standards in PSGA are also aligned with the PDPA. In addition, data collected by the public sector is also protected by specific legislation, such as the Official Secrets Act, the Income Tax Act, the Infectious Diseases Act and the Statistics Act. Collectively, these laws impose a high standard of responsibility on all public agencies, with additional requirements for the protection of sensitive or confidential data. Also, regular mandatory audits are conducted to ensure that public agencies comply with the standards for data protection and the security of information and communications technology systems.

PSGA allows personal data to be managed as a common resource within the public sector for better policymaking and also for more responsive public services. For example, when a Singaporean applies for financial assistance at a Social Service Office, the frontline officers are able to quickly evaluate his or her eligibility for financial assistance because they have access to data from other relevant agencies. In this way, we minimise the documents that need to be submitted by the applicant and improve the delivery of public services. In contrast, each private sector organisation is expected to be individually accountable for the personal data in its possession, and there is no expectation of a similar integrated delivery of services across different commercial organisations.

Because of these important differences, we need and have adopted different approaches to the protection of personal data in the public and in the private sectors. That is also why the PDPA applies only to the private sector, while the PSGA and other legislation govern data protection in the public sector. We will regularly review the PDPA, PSGA and other legislation to ensure that they remain relevant and effective in safeguarding personal data in both the public and private sectors.

Mr Speaker: Ms Sylvia Lim.

Ms Sylvia Lim (Aljunied) : I have four supplementary questions for the Minister. The first question is, I acknowledge that the various statutes and the IMs, as the Minister mentioned, do set out standards for the Public Service to comply with. Does the Minister agree, however, that these instruments, legislation or IMs are usually silent or weak on the recourse that citizens may have if there is a data breach? They may be strong on penalties for errant officers but, generally, we get silences on the rights of citizens.

Secondly, does the Minister also agree that for the PDPA itself, I suppose one of the advantages or assets of the PDPA is its approach to try to balance the need of organisations to collect data and, at the same time, if we look at section 3, it also recognises that personal data belongs to individuals, and individuals have a right to protect that data?

The third question is, we talked recently about the SingHealth incident. Does the Minister agree, because SingHealth is a body that comes within the purview of PDPA, it is not a Public Agency as defined in the Act, and the SingHealth cyberattack case has shown that the Personal Data Protection Commission (PDPC) can actually play a very useful role as far as the public is concerned? The PDPC's judgement in the cyberattack case mentioned that members of the public complained to it that their data had not been adequately protected by SingHealth. PDPC actually made some findings which will likely lead to improvements on the part of SingHealth and the Integrated Healthcare Information Systems (IHiS) as well.

Perhaps the last question for now is that one of the things that the PDPA does provide is a complaints procedure which I would like the Minister to confirm that this is something that is very useful to the citizens, which does not force the citizens to commence a lawsuit against a Government agency should one suffer damage and so on. So, these are very real advantages of the PDPA which I believe citizens can benefit from.

Mr S Iswaran : Mr Speaker, I thank the Member for her comments. I am not sure all of them were questions because some of them were observations. But let me interpret them.

Let me start by making a more general point. I think the key conclusion we have to draw is this. When we say exempt – and that is the language that the Member has used in her question – that the public sector is exempt from the PDPA, that does not mean that the public sector is somehow subject to a different or lower standard, as might be implied, in terms of data security and safety. In fact, and that was the thrust of my reply that, one, the public sector and the PSGA, in particular, takes reference, and it is in broad alignment with PDPA. But having said that, there is a clear recognition that the mode of operation and the expectation of how data is used in order to provide an effective and efficient Public Service, implies that we do need a different methodology in the way we govern public sector data governance. That is why we have this differentiated approach. In addition to the PSGA, as I had said, we do have other legislations in place.

Just for Members' information, we are by no means alone in this approach. The Canadians, for example, at the federal level, also have different laws in terms of its application to the private sector and its application to the public sector. So, it is not about differing standards or somehow having a different threshold when it comes to the public sector. In fact, we subject the public sector to the same kind of standards, if not higher standards, precisely because we know that the data that is being entrusted to the public sector is done with the confidence that it would be dealt with in a secure manner.

So, many of the questions that the Member has raised pertain more to whether there are elements of the PDPA. For example, there is a complaints procedure where they can complain to the PDPC on, for example, the right to data. I think the Member made the point that the PDPA strikes the balance between the right to data of the individual versus the right to use the data of the enterprises. Indeed, that is the balance we are trying to strike, whether it is in the public domain or in the private domain. Because essentially, you can say the same sets of considerations apply in the public sector – that we want to ensure individual data is protected, accorded due safeguards, but, at the same time, it should be a common resource that public sector agencies can tap on in order to better serve citizens. Many of the services that we take quite for granted today actually rely on that backend sharing. So, when it comes to a complaints procedure today, there is nothing stopping an individual who feels aggrieved that their data has somehow been mishandled to launch a complaint. And they have different channels for doing so.

On the SingHealth piece, the Member made the point that PDPC came out with the recommendations and so on which were very useful and so on. But actually, if you look at the morphology of the entire incident, the key recommendations that came out of this was actually from the Committee of Inquiry (COI) which the Government established. That is the process through which we derived a whole set of very detailed recommendations. What the PDPC did, because it received the complaint early in the process, was to say that it will take reference from the COI's process in determining whether there was a breach by the relevant agencies, in this case SingHealth and IHiS, and, if so, what penalty should be meted out. But the substantial portion of the recommendations was actually made through the COI process which was, in fact, initiated by the Government, not mandated by any legislation but something that was because of the judgement that was exercised.

The point on recourse comes back to the same thing again. If a member of the public feels that, in some way, their data has been mishandled, then they have every opportunity to lodge a complaint with the Minister, the Ministry, the relevant department, and action will be taken. And you can also, if you think a crime has been committed, make a Police report, and that will also be investigated.

So, if I can summarise, we subject our public sector to the same, if not higher, rigorous standards of data governance. And we have to do that, because if we do not, then a lot of our other efforts, in terms of wanting to build a Smart Nation and delivering, harnessing the digital technologies and all these in order to deliver better public services will all be thwarted. So, that is exactly why we take this very seriously. By and large, the PSGA, in other words, the legislation that governs the public sector data governance, takes reference from the PDPA and we also have other legislation for specific sectoral matters which can also be implied in addition.

Mr Speaker: Ms Sylvia Lim.

Ms Sylvia Lim : Two supplementary questions for the Minister. First, the Minister, in his answer earlier, mentioned that for members of the public who are aggrieved that their information has been mishandled by a public agency can always make a complaint. The question is: to whom? And the Minister mentioned that it could be to the Minister. Does the Minister not agree that the PDPC itself, which is focused on personal data protection, should have a role to receive such complaints because they are, after all, the domain expert on personal data protection?

The second supplementary question is: Minister mentioned the issue of public sector agencies being interconnected and, therefore, there needs to be a different approach. But I think the SingHealth incident also illustrates some artificiality in what is actually happening in the healthcare sector. If we look at the setup of SingHealth, for example, no doubt, it is not under the definition of public agency under the PDPA. But the fact is that it is very connected to the Ministry of Health (MOH). In fact, it is owned by MOH Holdings, and there is a frequent, I believe, exchange of data between such healthcare bodies and the parent Ministry. So, it would come to a stage, does Minister not agree that, if my data is given to a clinic, for example, under a cluster, I may be able to complain to the PDPC, but once that data goes to the Ministry and the breach happens there, I do not have recourse under the PDPC? So, there is some artificiality in the distinction as far as the healthcare sector is concerned.

Mr S Iswaran : Mr Speaker, because there will be a Ministerial Statement governing many of the matters pertaining to the public healthcare system, I will keep my comments in response to the Member's queries limited, and I think we can take up clarifications after the Ministerial Statement as well.

The key point I want to emphasise in my response to the Member is this: the term "recourse" for the public has been used several times in the course of this exchange. The fact of the matter is that you need recourse. It does not matter whether the recourse is under the PDPC or PDPA, the legislation or there are other established improved mechanisms. But the key point is you must have recourse.

And that is my point when I said that individuals, depending on where or what circumstances they find themselves in, they can make complaints. By the way, the PDPC does receive complaints sometimes pertaining to the public sector. So, as a recipient of such complaints from the public, it does not turn them away. Rather, the standing arrangement is that they look at it and, if the jurisdiction is such that it does not come under the PDPA, they then refer it to the Government agencies involved to then follow through. In the case of the Government, the Government Technology Agency (GovTech), for example, is overall in-charge of the security and safeguard systems for data. And GovTech is the agency that does many of the reviews and ensures that the Government agencies are in compliance with the IMs and other provisions and so on. Moreover, there is also the Auditor-General's review as well, which occurs from time to time, and it includes security.

My point is that members of the public should not at all be concerned that they do not have recourse. They do, and, in fact, they have a multiplicity of recourse. And I would add that, in the case of the public sector, they probably have more channels and more avenues of recourse in some ways, compared to what you see in the context of the private sector. Because essentially, for private sectors, you go to the PDPC, or you take out a specific legal action against the company on your own. Here, you have got more options because you can go through the PDPC. It would be referred to the relevant agencies. You can go to GovTech, you can go to the Ministry that oversees the relevant department, you can also make a Police report if you feel that it warrants such action.

So, there should be no doubt in Members' minds that we have the appropriate recourse mechanisms. There should also be no doubt in Members' minds that the public sector's data governance standards are in no way inferior to the standards that we impose on the private sector. And, if anything, we impose a higher set of standards. That is the expectation that we have.

この記録を引用

シンガポール AI 観測. 公共機関のデータ保護適用除外の審議. 取得日 2026-08-20, https://sgai.md/ja/debates/oral-answer-1902/

同じテーマの続き