口頭答弁 · 2019-04-01 · 議会 13
個人データ保護調査機能
議員は個人データ保護委員会(PDPC)の血液提供者データ漏洩事件における調査職責、および公的機関が『個人データ保護法』(PDPA)に拘束されるべきかどうかについて質問しました。政府はPDPCが関係する民間IT供給業者を調査中であり、公的機関が他の法規によって監督されており、データ保護基準がPDPA以下ではないと対応しました。核心的な論点は、公的機関がPDPA規制から免除されるべきかどうか、およびその責任体制です。
重要なポイント
- • PDPC investigates private vendor
- • Public agencies governed by other regulations
- • Public-agency data protection standards are high
公共機構は専門法規によって規制されており、PDPA ではありません。
公共機構のPDPA免除の合理性に疑問を呈する
公共機構のデータ保護規制の強化
“Public sector agencies have to comply with the Government Instruction Manuals and the Public Sector (Governance) Act.”
参加者 (8)
- Dennis Tan Lip Fong
- Edwin Tong Chun Fai
- Irene Quay Siew Ching
- Minister for Communications and Information
- Cheng Li Hui
- S Iswaran
- Senior Minister of State for Health
- Sylvia Lim
全文翻訳(日本語)
Hansard 原文 · 2026-05-02
第13号質問。Ms Sylvia Limが通信情報大臣に対し、最近の衛生科学局(HSA)データベースにおける80万人を超える献血者の個人情報漏洩事件について質問しました。(a) 個人データ保護委員会はこの事件の調査においてどのような役割を果たしているのか。(b) HSAが個人データ保護に関して合理的な措置を講じたかどうかを確認するための審査が進行中であるか、およびHSAとそのIT供給業者間の契約義務がこれらの関係者に委託された個人情報を適切に保護しているかが含まれるか。
第14号質問。Ms Irene Quay Siew Chingが通信情報大臣に対し、公共IT システムにおいて発生したデータ漏洩事件に鑑み質問しました。(a) 公共機関が『個人データ保護法』(PDPA)から除外される根拠があるのか。(b) 市民が機関への苦情申し立てまたは民事訴訟の追求以外に何か他の救済手段があるのか。(c) これらの公共機関に対して実質的な処罰を課すべきであり、これが公共問責を実現するのか。
通信情報大臣(Mr S Iswaran):議長先生、第13号と第14号の質問をあわせてお答えしてもよろしいでしょうか。
議長:構いません。どうぞ。
Mr S Iswaran:議長先生、HSAに関連する事件に関して、個人データ保護委員会(PDPC)はSecur Solutions Group 私人有限公司を調査中です。この企業はHSAのIT サービス供給業者です。『個人データ保護法』(PDPA)に違反していることが判明した場合、PDPCはこの企業に対して適切な執行行動を講じます。例えば、指令の発令と罰金の課金などです。
衛生上級国務大臣は以前、HSAのデータセキュリティ政策と実務に関する審査の概要を述べました。HSAは政府機関であるため、スマートネーション・デジタルガバメント・グループもこの事件について調査を進めています。
Ms Quayが公共機関がPDPAから除外されることが合理的であるか質問しました。この議員の質問には、公共部門機構がそのデータ保護実務に対して責任を負わない、またはPDPAが適用されないため高い基準に達することが求められていないという暗黙の仮定が含まれています。このような見方は誤りです。事実は異なります。公共部門機構は別の法律および他の規制に拘束されています。特に、公共部門機構は政府指令手冊および『公共部門(ガバナンス)法』(PSGA)を遵守しなければなりません。全体的に言えば、それらのデータ保護基準はPDPAと同等またはそれ以上であり、データセキュリティ違反行為に対して類似の調査および執行行動を講じています。
私は以前、議会でこのアプローチを採用する理由を説明しました。改めて述べますと、PDPAが公共機関に適用されないのは、公共部門の運営方法に根本的な違いが存在し、異なる個人データ保護方法の採用が必要であるためです。これは全政府協力による公共サービス提供を実現するためであり、個人データは公共部門の共有リソースとして管理されなければなりません。民間部門は異なり、商業サービスの提供は全体的なアプローチを期待していません。
市民は公共部門のデータ漏洩の場合、PDPAと同じ救済手段を享受しています。市民が民間機関によるデータ処理が不適切であると疑う場合、PDPCに苦情を申し立てることができます。公共部門機関に関する場合は、GovTechに苦情を申し立てることができます。実際には、苦情申し立てチャネルが円滑に機能しており、苦情は関連機関に転送されてフォローアップされます。影響を受けた個人は調停を求めるか、データ処理が不適切な機関に対して民事訴訟を提起することもできます。
議員は公共問責を実現するために公共機関に対して実質的な処罰を課すべきかどうか質問しました。政府データセキュリティルールに違反し、権限なくデータを悪用または開示する公務員は、PSGAに基づいて刑事責任を負う可能性があります。処罰には最高5,000シンガポールドルの罰金または最高2年の懲役、またはその両方が含まれます。公共機関に罰金を課すことは大きな意味がありません。罰金費用は最終的に公共財政が負担するためです。
議長先生、長年にわたり政府は機密データを保護するための安全措置を継続的に強化してきました。政府はまた、機関のデータアクセスと保護措置を検査するために、内部IT監査の数と種類を増やしてきました。しかし、最近のデータ関連事件は、公共部門のデータセキュリティ政策と実務を強化する緊急性を浮き彫りにしています。
したがって、首相は公共部門データセキュリティ審査委員会を召集しており、公共サービス全体のデータセキュリティ実務に関する包括的な審査を進めています。審査には、公共部門機構および政府を代表して個人データを処理する供給業者による市民の個人データ収集および保護に関する措置とプロセスが含まれます。各機関は具体的な事件の調査と処理を進めており、この委員会は包括的な審査を実施し、業界および世界的なベストプラクティスに学び、データセキュリティを強化します。
今回の審査は、すべての公共部門機構が最高のデータガバナンス基準を維持することを確保します。これは公衆の信頼を維持し、データの利用を通じて市民に高質な公共サービスを提供することにとって重要です。この委員会の業務は、スマートネーション・ビジョンを実現するための私たちの取り組みを補完するものです。公共部門データセキュリティ審査委員会は2019年11月30日までに調査結果と提言を首相に提出します。
議長:私たちは以前の議会提問およびこれら2つの質問に関する追加的な質問を受け付けます。Ms Cheng Li Hui。
Ms Cheng Li Hui(淡滨尼):追加質問が2つあります。報道によると、サーバーは複数の他のIPアドレスからもアクセスされたと言われています。これらのアクセスについてどの程度情報を持っていますか。外国人ですか、それとも現地の人ですか。彼らに対して措置を講じるつもりですか。彼らも献血者情報を入手しましたか。病気のため献血できなかった者の機密情報もアクセスされたのでしょうか。
衛生上級国務大臣(Mr Edwin Tong Chun Fai):Cheng女史の後の質問に関して、影響を受けたサーバーにはその情報はありません。サーバーには登録関連情報のみが存在します。供給業者声明の関連部分を引用すると、サーバー上の情報は身分証明書番号、性別、献血回数、最近3回の献血日付が含まれ、時には血液型、身長、体重も含まれます。
最初の質問に関して、権限のないアクセスは複数の場所からのものであり、調査はまだ進行中です。状況がより明確になるまで、私たちは関連する回答を提供します。
Ms Sylvia Lim(亚逸):議長先生、Iswaran大臣への追加質問が3つあります。まず、民間供給業者Secur Solutions GroupがPDPAの管轄下にあり、PDPCが彼らの行為を調査していることを確認した彼の言葉を聞いて、私は嬉しく思います。私の最初の質問は、PDPCはHSAの調査結果を待ってから行動するのか、それとも同時に進めるのかです。
第2の質問は、首相が副首相張志賢が主催する政府横断的な委員会を召集して政府IT安全基準を審査したと述べたことについてです。これは政府が現在の公共部門の基準に不満であり、基準が不十分であると考えていることを意味するのでしょうか。
最後に、第3の質問は、大臣のMs Quayに対する機関への罰金課金に関する回答は興味深いものです。彼は公共機関への罰金は無意味であると述べました。罰金は最終的に公共財政が負担するためです。しかし、中央政府が公共機関に罰金を支払うための追加的な割り当てを行わないと想定することはできないのでしょうか。したがって、機関は他の場所から支出を削減して罰金を支払う必要があります。例えば、シニア管理層のボーナスなど。これはまだ重要なシグナル効果を持っています。政府が組織として、小企業に期待するのと同じ基準に従うことをいとわないことを示しています。
Mr S Iswaran:議長先生、議員の質問をありがとうございます。まず、PDPC調査が同時に進められるかについては、答えはイエスです。しかし、明らかに、私たちは他の関連活動の進展も参考にする必要があります。なぜなら、それらに関連する要素が存在するからです。調査は同時に進められます。
第2の質問は、公共部門データセキュリティ審査委員会の設立が何を意味するかについてです。議員が得点を稼ごうとしていると思いますが、私は明確に述べます。政府はデータセキュリティ基準を継続的に向上させるための努力を続けています。長年にわたって、私たちは多くの措置を講じており、議会はこれについて複数回説明してきており、議員およびその他の議員の質問に対応してきました。
鍵となることは、最近の一連の事件に鑑み、首相および政府が包括的な見直しが必要であると評価したことです。現在の措置が不十分ではなく、むしろ公共部門のデータセキュリティが最高基準に達することを確保するために全力を尽くすべきであるということです。民間部門またはグローバル企業のベストプラクティスから学べることがあれば、私たちは喜んでそれを採用し、政府の実務に組み込みます。
最後に、罰金とそのシグナル効果に関して。まず、「自分で自分をチェックする」というアプローチは、彼女の党内の別の議員によって提起されたと思われます。自分が自分に罰金を課す場合、シグナル効果は確かに疑問です。より重要なことに、重要なシグナルは、あなたがこの問題に真摯に取り組み、責任のある人々を追及することです。したがって、私たちの処罰は、違反決定や行為を行った個人の公務員に焦点を当てており、相応の結果を負わなければなりません。
さらに、公共機関に対して行動を起こすことは、その評判と指導部への影響が大きいです。議員はこれ自体も重要なシグナルであることを認めるべきです。なぜなら、公共および民間の両方の機関が評判の損傷を望まないからです。私たちはすべての方法を議論することをいとわず、明確な問責を確保し、公共部門のデータセキュリティが最高基準に達することを確保します。これもこの委員会を設立した理由です。議員が良い提案を持っていれば、私たちは喜んでそれを聞きます。
Ms Irene Quay Siew Ching(指名議員):大臣は議会に対して保証しています。公共機関に対する高い基準の責任を課す複数の法律があります。しかし、審査後、これらの法律はデータ漏洩に対する問責が十分に明確ではなく、重点がデータ悪用にあるようです。大臣は説明していただけますか。
私の第2の追加質問は、大臣が議会に告知したことについてです。公共機関は定期的な義務的内部監査を行い、データ保護およびICTシステムセキュリティ基準への準拠を確保しています。その場合、なぜ以前の内部監査はこれらの潜在的な脆弱性を発見できなかったのでしょうか。
Mr S Iswaran:議長先生、議員に説明していただけますでしょうか。
議長:構いません。どうぞ。
Mr S Iswaran:法律がデータ悪用のみを言及し、データ漏洩を言及していないと言ったのですが、『公共部門(ガバナンス)法』を指すのか、それともPDPAを指すのか。
Ms Irene Quay Siew Ching:『公共部門(ガバナンス)法』、『公式機密法』、『所得税法』および『伝染病法』を指しています。
Mr S Iswaran:指令手冊(IM)第8号もご覧になられたでしょうか。総合的に見ると、データ問題は漏洩であろうと悪用であろうと、ある程度の連続性が存在します。ご安心ください。データ漏洩が発生した場合、原因を特定する必要があります。悪用が原因の場合は、1つの対策セットを講じます。システムの欠陥が原因の場合は、システム性エラーを修正するための別の対策セットを講じる必要があります。誰かがこれに対して責任があれば、彼らも責任を追及されます。政府機関の行動を処理することにはそのプロセスがあります。
定期的なIT監査がなぜ問題を発見できなかったかについては、これは常に論じられてきた問題です。監査がIT監査であれ、財務監査であれ、品質監査であれ、システムは人によって操作されており、時折エラーが生じるため、インシデントの発生を完全に防止することはできません。重要なのは、インシデント発生後に、そこから学習し、誤りを是正し、私たちのアプローチを透明かつ公開的に開示することです。
議長:Mr Dennis Tan。
Mr Dennis Tan Lip Fong(非選挙区議員):衛生上級国務大臣 Edwin Tong にお尋ねいたします。私の質問の一部についてご回答いただけますでしょうか。
Mr Edwin Tong Chun Fai:議員は、ご質問のどの側面がまだご回答されていないかについてご説明いただけますでしょうか。
Mr Dennis Tan Lip Fong:私の質問についてですが、既にご回答いただいているかどうか確実ではございません。
Mr Edwin Tong Chun Fai:Dennis Tan議員のご質問は、情報がなぜサーバーに保存されていたのか、データがどのようにアクセスされたのか、違法であるかどうかなど、こうした事項に関わっています。これらはすべて現在進行中の調査の範囲内にあり、事実が明らかになった後、私たちは可能な限り関連情報をご提供いたします。
英語原文
SPRS Hansard 原本記録 · 取得日:2026-05-02
13 Ms Sylvia Lim asked the Minister for Communications and Information regarding the recent data leak of more than 800,000 blood donors' personal information from the database of HSA (a) what is the role of the Personal Data Protection Commission in investigating this incident; and (b) whether any review is being done to ascertain whether HSA has acted reasonably in protecting the personal data including whether the contractual obligations between HSA and its IT vendor reasonably safeguarded the personal information entrusted to these parties.
14 Ms Irene Quay Siew Ching asked the Minister for Communications and Information in view of data breaches across public IT systems (a) whether it is justifiable for public agencies to be exempted from Personal Data Protection Act; (b) what recourse do citizens have, other than to complain to agencies or seek civil action; and (c) whether there should be a tangible penalty meted out to these public agencies for public accountability.
The Minister for Communications and Information (Mr S Iswaran) : Mr Speaker, may I have your permission to take Question Nos 13 and 14 together, please?
Mr Speaker : Yes, please.
Mr S Iswaran : Mr Speaker, with regard to the incident involving HSA, the Personal Data Protection Commission (PDPC) is investigating Secur Solutions Group Pte Ltd, which is a private company and vendor of IT services to HSA. If found to be in breach of the Personal Data Protection Act (PDPA), PDPC will take the appropriate enforcement actions against the company, such as issuing directions and imposing financial penalties.
The Senior Minister of State for Health has earlier outlined the review of HSA’s data security policies and practices that is being undertaken. As HSA is a Government agency, the Smart Nation and Digital Government Group is also conducting an investigation into the incident.
Ms Quay has asked if it is justifiable that public agencies are exempted from the PDPA. Implicit in the Member’s question is the presumption that public sector agencies are not accountable for their data protection practices or not held to a high standard because the PDPA does not apply to them. That is wrong and simply not the case. Public sector agencies are subject to a different piece of legislation and other regulations. In particular, public sector agencies have to comply with the Government Instruction Manuals and the Public Sector (Governance) Act (PSGA). Collectively, they have comparable if not higher standards of data protection compared to the PDPA, and similar investigations and enforcement actions are taken against data security breaches.
I have previously explained in Parliament why we have adopted this approach. To reiterate, the PDPA does not apply to public agencies because there are fundamental differences in how the public sector operates, which requires a different approach to personal data protection when compared to the private sector. In order to enable a whole-of-Government approach to the delivery of public services, personal data has to be managed as a common resource within the public sector. The considerations are different in the private sector, as there is no such expectation of a holistic approach to the delivery of commercial services across private organisations.
Citizens have the same recourse for a data breach in the public sector as with the PDPA. Where citizens suspect that their data has been mishandled by a private sector organisation, they can lodge a complaint with PDPC; or with GovTech, if a public sector agency is involved. In practice, there are no wrong doors and the complaint will be directed to the relevant agencies for follow-up. Affected individuals can also seek mediation or take civil action against the organisation or agency which mishandled the data.
The Member has asked whether tangible penalties should be imposed on public agencies for public accountability. Public officers who flout the Government’s data security rules, and are found to have misused or disclosed data in an unauthorised manner, could be held criminally liable under the PSGA. The penalties include fines of up to $5,000 or a jail term of up to two years, or both. It is not meaningful to impose financial penalties on public sector agencies because the cost of such penalties would ultimately have to be borne by the same public purse.
Mr Speaker, over the years, the Government has progressively enhanced security measures to safeguard sensitive data. The Government has also increased the number and types of internal IT audits, to check on agencies’ data access and data protection measures. Nevertheless, recent data-related incidents have underscored the urgency to strengthen data security policies and practices in the public sector.
Therefore, the Prime Minister has convened a Public Sector Data Security Review Committee to conduct a comprehensive review of data security practices across the entire Public Service. This includes measures and processes related to the collection and protection of citizens’ personal data by public sector agencies, as well as vendors who handle personal data on behalf of the Government. While individual agencies are investigating and taking action on the specific incidents, this Committee will undertake a comprehensive review across the public sector, and incorporate industry and global best practices to strengthen data security.
This review will help to ensure that all public sector agencies maintain the highest standards of data governance. This is essential to uphold public confidence and deliver a high quality of public service to our citizens through the use of data. The work of this Committee will complement our efforts to achieve our Smart Nation vision. The Public Sector Data Security Review Committee will submit its findings and recommendations to the Prime Minister by 30 November 2019.
Mr Speaker : We will take the supplementary questions for the earlier Parliamentary Questions as well as for these two. Miss Cheng Li Hui
Miss Cheng Li Hui (Tampines) : I have two supplementary questions. It was reported that the server was also accessed by several other IP addresses. What do we know about this access? Is it by foreigners or locals and will we be pursuing any actions on them? Do they have the information on the blood donors as well? For those who failed to donate their blood due to illnesses, can this sensitive information be accessed?
The Senior Minister of State for Health (Mr Edwin Tong Chun Fai) : On Miss Cheng's latter question, that information was not on the server that was compromised. Only registration related information was on that server. And if I can just cite for Miss Cheng this relevant portion from the vendor's statement. It says that the information that was on that server were NRIC, gender, number of blood donations, dates of the last three blood donations and in some cases, blood type, height and weight.
As for the first point, the unauthorised access is from various locations. That is still being looked into and when we have a fuller position on this and have more clarity, we will provide those answers.
Ms Sylvia Lim (Aljunied) : Mr Speaker, I have three supplementary questions for Minister Iswaran. The first is, I am glad to hear that he confirmed that the private sector vendor Secured Solutions Group is actually governed by the PDPA and that PDPC is looking into their conduct. My first question will be, is the PDPC going to wait for the outcome of the HSA investigation and then, follow on from there or is it concurrent?
The second question is, it was mentioned that the Prime Minister has now convened a cross-Government committee chaired by Deputy Prime Minister Teo to look into standards of Government IT security. Does this confirm that the Government is actually not satisfied and that the standards so far have been wanting in the public sector?
Finally, the third question, which is an interesting one, is Minister's answer to Nominated Member Quay's question about financial penalties on organisations. He mentioned that it was not meaningful to fine public agencies because the fine would in the end come from the public purse. But can the central Government not operate on the premise that no additional money is going to be provided to public agencies to pay fines, and therefore, the agencies would just have to cope with cuts somewhere else to pay these fines, whether it is from bonuses of Senior Management or whatever it is? Because there is still an important signalling effect that the Government is prepared, as an organisation, to abide by the same standards it expects of small businesses.
Mr S Iswaran : Mr Speaker, I thank the Member for her questions. Firstly, on whether the PDPC's investigations would be concurrent, the answer is yes. But clearly, we would have to be informed by what is happening also in some of the other activities because they have some inter-related factors. But the answer is, the investigations will proceed concurrently.
The second question is, what does the establishment of the Public Sector Data Security Review Committee mean. I think the Member is trying to score a political point here and I want to make it categorically clear. The Government has been working, that is why I said so in my answer, consistently working and improving data security standards. There is a list of things that we have been doing over the years and I think this has been explained in the House many times in response to the Member's questions and that of many other Members as well.
The key point here is that, because there has been a series of these incidents in recent times, the Prime Minister and the Government have assessed that we need to take a holistic look again. That does not mean, that what we have is inadequate or lacking, but what it does mean is we should ensure that we put total effort to ensure that we leave no stones unturned in ensuring the highest standards of are met in the public sector when it comes to data security. If there is something that is to be learnt, whether it is from best practices in the private sector or from global companies, that is something we will be very happy to learn from and incorporate in the Government's practices.
Finally, on the point on financial penalties, and the Member makes the point about signalling effect. I would say, that first of all, in fact I think the term "ownself check ownself" was coined by a Member of her party. So, if you fine yourself, you do ask the question, what is the signalling effect there. It is far important that the signalling effect is that, you are taking this issue seriously and holding relevant people accountable. So, that is why, in the way we go about this, the penalties are focused on the individuals, officers, who have made decisions or taken actions which were deemed to be not compliant, and therefore, there are the consequences that I spelled out.
Having said that, I think, when you take action against an organisation in the public sector, the reputational impact on that organisation and leadership is significant. I think the Member will concede that, that in itself is also a major signalling point, because no organisation, public or private, wants to have its reputation tarnished. Having said that, we are prepared to look at all means, to ensure there is clear accountability and ensure that in the public sector we have the highest standards of data security. That is why, this committee has been set up and we will be open to suggestions. If the Member has interesting ideas on this, we would be happy to hear from her.
Ms Irene Quay Siew Ching (Nominated Member) : The Minister reassured the House that we have the various acts to impose a high standards of responsibility on public agencies. However, upon reviewing that, there seems to be a lack of clarity in this Act regarding accountability for data breaches. The focus seems to be on misuse of data. Can Minister clarify?
My second supplementary question is, Minister informed the House that the public agencies have regular mandatory internal audits in place to ensure public agencies comply with these standards for data protection and security of ICT systems. In that case, why are these potential lapses not surfaced during previous internal audit checks?
Mr S Iswaran : May I just seek a clarification from the Member, Speaker?
Mr Speaker : Yes, please.
Mr S Iswaran : When you say the Act does not refer to data breeches, only data misuse, are you referring to the Public Sector (Governance) Act or are you referring to PDPA?
Ms Irene Quay Siew Ching : I am referring to the Public Sector (Governance) Act, Official Secrets Act, Income Tax Act and Infectious Diseases Acts.
Mr S Iswaran : Yes, and have you also looked at the Instructions Manual (IM) 8? Because I think when you look at them holistically, it will be clear, that the issues with data, whether it is a breach or misuse, and when can I argue that there is a kind of continuum here. But let me assure you, when you have a breach of data, you have to establish why it occurred. If it is because of misuse, there will be a certain set of actions. If it is because your systems were not in place, it has to result in a different set of actions to correct the systemic errors. If there were certain people accountable for that systemic error, then they have to be held to account as well. So, I think there is a flow in the way this will proceed, in terms of action against Government organisations.
The second point on regular IT audits, why did they not throw up such issues in the past. I think that is an age-old question. You can have audits, I think it is not just in IT, you have it in financial audits, you have got quality audits, but you still have incidents. This is because it is human beings running the system and from time to time, it can happen. I think what is important is that when they occur, we learn from these incidents and set them right, and be transparent about what we are doing and how we are going about it.
Mr Speaker : Mr Dennis Tan.
Mr Dennis Tan Lip Fong (Non-Constituency Member) : A question for Senior Minister of State Edwin Tong. Is the Senior Minister of State able to answer any aspect of my questions?
Mr Edwin Tong Chun Fai : Can the Member elaborate on what other aspects have not been answered?
Mr Dennis Tan Lip Fong : No, on my question. Not sure my question has been answered.
Mr Edwin Tong Chun Fai : Mr Dennis Tan's question relate to the circumstances in which the information is placed on the server. How it is that there was access that was gained to the data and whether there was a breach of any law? Those are all matters that are covered by the investigations that are currently on-going, and to the extent possible, when this has been ascertained, we will provide those information.