口頭答弁 · 2023-11-22 · 議会 14

ショッピング会員データ漏洩事件への質問

AI と国家安全保障 争点度 2 · 軽度質問

議員は、シンガポールの高級リゾート運営者のショッピング会員データ漏洩事件の報告時間および遅延通知の原因について質問しました。通信・情報大臣は、事件は規定の時間内に規制当局に報告されたこと、遅延通知は漏洩をまず制御し影響を評価し通知要件を確認する必要があったことを説明しました。規制当局は、事件が個人に重大な危害を与えたかどうかおよび通知がタイムリーであったかどうかを調査中です。

重要なポイント

  • Incident reported within required timeframe
  • Delayed notification to prioritise containment
  • Regulator is investigating
政府の立場

AIを活用して警察能力を積極的に向上させる

質問の立場

AI応用の成果と展望についての質詢

政策シグナル

公共安全におけるAI応用の深化

“Singapore takes breaches of personal data seriously.”

参加者 (3)

全文翻訳(日本語)

Hansard 原文 · 2026-05-02

第9番議員のハニー・ソー氏が通信・情報省長に質問いたしました。シンガポール国内のあるラグジュアリーリゾート運営事業者が経営するショッピングロイヤルティプログラムの約655,000名の会員の個人データに関するデータセキュリティ事件について、(a)当該事件が関連当局に報告されているかどうか、報告されている場合はいつ報告されたのか。(b)影響を受けた会員への通知が3週間遅延した理由を説明してください。

通信・情報省長(ジョセフィーヌ・テオ女史)の答弁:議長、2023年11月7日、マリーナベイサンズ(MBS)はそのカスタマーロイヤルティプログラム会員データが2023年10月19日及び20日に漏洩したことを発表いたしました。MBSはその後、影響を受けた個人に対して通知いたしました。

シンガポールは個人データ漏洩事件を極めて重視しています。『個人データ保護法』(PDPA)は、すべての組織が保有または管理する個人データを保護するための合理的なセキュリティ対策を講じ、不正なアクセス、開示または変更を防止することを要求しています。『PDPA下のデータ漏洩の管理及び通知ガイドライン』は、組織が遵守しなければならないスケジュールと要件を明確に規定しています。

MBSは2023年10月20日にデータ漏洩を発見し、2023年10月24日に個人データ保護委員会(PDPC)に通知いたしました。これは上述のガイドラインで規定されているPDPCへの通知時間要件に適合しています。

議員は、なぜ即座の通知が要求されないのかについて質問されるかもしれません。これは主に、データ漏洩の発見後の通常の後続処理において、組織は通常4つのタスクを完了する必要があるためです。

第一に、漏洩を遏制するための措置を直ちに講じなければなりません。これが最優先事項です。第二に、データ漏洩によるデータ損失の範囲と規模を評価するために最大限の努力を払わなければなりません。第三に、通知要件に適合しているかどうかを評価しなければならず、適合している場合は報告を行わなければなりません。第四に、遏制措置が有効かつ安全であるかどうかを評価しなければなりません。

したがって、これら4つのステップがあり、遏制と評価を優先させるため、PDPCは組織がPDPCへの通知報告を提出する前にある程度の時間を設けることを認めています。

この背景に基づいて、私は議員に保証いたしますが、PDPCは当該事件について調査を実施中であり、影響を受けた個人に重大な害が生じたかどうか、及び影響を受けた個人が適時に知らされたかどうかを確認いたします。PDPCは適切な時期に調査結果を公表いたします。

議長:ハニー・ソー女史。

ハニー・ソー女史(Marsiling-Yew Tee選挙区):大臣が私の議会質問に対してご回答いただき、ありがとうございます。補足的な質問が何点かございます。

まず、PDPCの調査結果について、完了予定時期はありますか?調査結果はその後、公衆に対して公開されるのでしょうか?

次に、MBSがPDPCに報告した後、PDPCは影響を受けた会員からいかなる報告も受け取っているか、特にこのイベントがこれらの会員に与えた影響、およびさらなる支援があるかについて、いかがでしょうか。

第三に、関連部門またはPDPCが、大量の個人データを保有する組織に対して、より具体的または厳密な義務を課すことを検討しているかどうか、例えば、許可条件(該当する場合)を通じてについて、いかがでしょうか。

Josephine Teo女史の答弁:「議長様、議員の補充質問をいただきありがとうございます。私は順番に回答させていただきます。」

まず、調査結果が公開されるかどうかについて——答えはイエスです。要する時間についてですが、調査の複雑性に左右されるため、具体的な期間を事前に特定することは困難です。

2番目の質問は、影響を受けたMBS会員からの後続報告があるかどうかです。PDPCは2人の影響を受けた会員から報告を受け取りました。彼らは主にPDPCをこの件に注意喚起することが目的で、その他の会員がまだ通知されていない、またはPDPCがまだこのデータ漏洩事象を認識していない場合に備えています。次に、彼らはまたPDPCがこのデータ漏洩に対するMBSの責任を追求することを要求しました。PDPCはもともとそうするつもりでした。

MBSが影響を受けた会員をどのように支援したかについて、まず、最も重要なことは、会員にこのデータ漏洩に関連するデータの種類を理解させることです。MBSが影響を受けた会員に通知する際に、漏洩したデータの種類が姓名、連絡先、居住国、会員番号、会員レベルを含むことを明確に述べました。これはMBSが確認できるデータ漏洩の範囲です。

さらに、MBSは影響を受けた会員に対して、自分たちのMBSアカウントおよび他の個人情報を保護する方法についての助言を提供しました。責任ある措置として、MBSは影響を受けた会員による後続の質問や他の関連事項の確認のための連絡先を提供しました。

3番目の質問は、大量のデータを保有する組織に関するものです。私たちの現在の立場は、組織が大量の異なるタイプの個人データ、またはより敏感なデータ(保険、医療、金融データなど)を保有する場合、より高い基準の個人データ保護を要求することです。

このような場合、組織はPDPCが発行した『情報通信技術(ICT)システムデータ保護実践ガイドライン』に従って、強化されたデータ保護対策を実施しなければなりません。

さらに、PDPCはデータ保護条項の執行に関するガイドラインを発行しており、大量の敏感な個人データに対して十分な保護措置を講じられなかったことが、加重処罰の要因として機能し得ることを明確に述べています。以上の答弁が議員のご質問にお応えできることを願っております。

英語原文

SPRS Hansard 原本記録 · 取得日:2026-05-02

9 Ms Hany Soh asked the Minister for Communications and Information with regard to the data security incident involving the personal data of about 655,000 members of a shopping loyalty programme operated by a luxury resort operator in Singapore (a) whether the incident was reported to the authorities and, if so, when was it reported; and (b) what was the reason provided to the authorities for the three-week delay in notifying affected members.

The Minister for Communications and Information (Mrs Josephine Teo) : Mr Speaker, on 7 November 2023, Marina Bay Sands (MBS) announced a breach of its customers' loyalty programme membership data that took place on 19 and 20 October 2023. MBS has since notified affected individuals.

Singapore takes breaches of personal data seriously. The Personal Data Protection Act (PDPA) requires all organisations to put in place reasonable security measures to protect the personal data in their possession or control, to prevent unauthorised access, disclosure or modification. The Guide on Managing and Notifying Data Breaches under the PDPA sets out clear timelines and requirements that organisations must comply with.

MBS discovered the data breach on 20 October 2023, and notified the Personal Data Protection Commission (PDPC) on 24 October 2023. This meets the timeframes for notification to PDPC as set out in the earlier mentioned guide.

The Member may ask why notifications are not required to be made immediately. That is really because in the usual follow-up to the discovery of a data breach, there are usually four things that we would like the organisations to undertake.

First is that they must immediately seek to contain the breach. So, that is the immediate priority. The second is that they must then make best efforts to assess the degree and the extent to which the data breach has resulted in loss of data. The third is then they must assess whether this falls within the requirements for notification, and if it does, then they must proceed to make the report. And the fourth is that they must then evaluate their containment efforts, whether they are secure.

So, there are these four steps, and because the priority is on containment and assessment, PDPC does give the organisation a little bit of time before they make the notification report to the PDPC.

With that as background, let me assure the Member that PDPC is conducting investigations into this incident. It will ascertain whether there was significant harm to affected individuals and correspondingly, whether affected individuals were notified in a timely manner. PDPC will provide their findings in due course.

Mr Speaker : Ms Hany Soh.

Ms Hany Soh (Marsiling-Yew Tee) : I thank the Minister for her response to my Parliamentary Question. I have a few supplementary questions in relation to that.

Firstly, in relation to the PDPC's investigation findings, do we have an estimated timeline as to when that will be completed and whether that would be subsequently published to the public for information?

Secondly, subsequent to the reporting by MBS to the PDPC, whether the PDPC has received any reports from members who are affected, especially, and how this particular incident has affected these members and whether any of them has been further assisted since then?

Thirdly, this is in relation to whether the Ministry or the PDPC would consider it necessary to impose further specific or enhancement of obligations to these organisations that possesses large volumes of personal data, for example, through licensing conditions, where applicable?

Mrs Josephine Teo : Mr Speaker, I thank the Member for her supplementary questions. Let me try to address them in turn.

The first is on whether the findings of its investigations will be made public – the answer is yes. As to how long that will take, it goes to the complexity of the investigations. And so, it is difficult to say in advance what the duration is likely to be.

Her second question relates to whether there were any follow-ups from affected members of MBS. The PDPC received reports from two of those members who were affected. Essentially, they wanted to draw the PDPC's attention to this, in case it was not notified, or it was not yet aware of the breach. And the second is that they also asked that the PDPC take MBS to account for this breach which, of course, the PDPC intended to do in any case.

As to how these affected members were being assisted by MBS, I think, in the first place, it is most important for the members to know what types of data have been accessed or revealed as a result of this breach. And so, when MBS notified the affected members, it did clarify that the types of personal data that were revealed, included the name, contact information, country of residence and membership number as well as tier. This was the extent of the breach that the MBS was able to ascertain.

It further provided advice to the affected members on how they could safeguard their accounts with MBS, as well as other kinds of personal information. As a responsible measure, they provided a contact for follow-up enquiries, in case the affected members wanted to clarify on various other aspects.

Ms Soh's third question had to do with the organisations that could be in possession of large volumes of data. Our position today already states that a higher standard of personal data protection is required when organisations hold large quantities of different types of personal data or hold data that might be more sensitive, such as insurance, medical and financial data.

In such cases, organisations are required to implement enhanced data protection practices as stipulated in the PDPC's guide to data protection practices for information and communications technology (ICT) systems.

In addition, the PDPC has issued an advisory guideline on enforcement for data protection provisions that makes clear that failure to put in place adequate safeguards for large volumes of sensitive personal data can be taken as an aggravating factor in calculating the level of penalties to be imposed on an organisation. I hope that addresses the Member's questions.

この記録を引用

シンガポール AI 観測. ショッピング会員データ漏洩事件への質問. 取得日 2026-08-20, https://sgai.md/ja/debates/oral-answer-3383/

同じテーマの続き