書面答弁 · 2019-05-06 · 議会 13
公的機関のデータ保護免責問題
議員は公的機関が『個人データ保護法』の免除権を享受しているかどうか、およびそのデータ漏洩責任について質問しました。政府は公的機関が『公共部門統治法』および『指令ハンドブック8』などの法規によって拘束され、刑事罰および内部規律処分を設けており、技術的および管理的措置を通じてデータ漏洩を防止していると指摘して対応しました。核心的な論点は、公的機関のデータ保護責任の法的基礎と執行力です。
重要なポイント
- • Public agencies bound by multiple regulations
- • Criminal and disciplinary measures combined
- • Strict technical and management measures
国防と地域安全保障協力の強化を支援する
国防予算の適度な調整を提案します
国防と地域反テロ協力の強化
“The PSGA criminalises the acts of unauthorised disclosure of data, misuse of data and the re-identification of individuals from anonymised data.”
参加者 (2)
全文翻訳(日本語)
Hansard 原文 · 2026-05-02
1 エイリーン・クアイ・ショウセイ女史は総理大臣に、公共機関が「個人データ保護法」の適用から除外されるかについて質問いたします:(a) 現行法律および指引手冊中の具体的な条項であって、公共情報技術システムにおけるデータ漏洩(データの悪用ではなく)に対する公共機関の責任を規定するものをリストアップしていただけるか、(b) これらの法律条項がどのように共同してすべての公共機関に高度な責任基準を課しているかをご説明いただけるか。
チャン・シーシェン先生は総理大臣に代わり、以下のように答弁いたします:公共機関及びその職員は、「公共部門(ガバナンス)法」(PSGA)および「指引手冊8」(IM8)ならびにその他の関連法令に規定されたデータ保護条項を遵守しなければなりません。PSGAは、無許可のデータ開示、データの悪用、および匿名化されたデータから個人の再識別を犯罪行為と定めています。これらの犯罪で有罪判決を受けた公務員は、最高5,000シンガポールドルの罰金および/または最長2年の懲役に処せられる可能性があります。PSGA以外にも、「官方機密法」「銀行法」「所得税法」「統計法」などの他の法律も無許可のデータ開示を犯罪行為と定めています。これらの規定は、公務員によるデータの無責任な使用および処理を抑止し、処罰することを目的としています。関連する法律条項の一覧については、別紙Aをご参照ください。
刑事訴追の他、公務員が管理するデータの保護に関して怠慢と認定された場合、1999年「公共サービス(懲戒手続き)規則」に基づいて内部懲戒処分の対象となることがあります。
これらの立法上の制裁に加えて、政府はデータセキュリティ漏洩の可能性を防止または最小限に抑え、データ漏洩の影響を軽減するための複数の措置を講じています。すべての公共機関はIM8の規定を遵守しなければなりません。IM8はPSGAの広範なデータ条項を補足し、機関が管理・保護すべき政府データを管理・保護するために従うべき規則と要件を明確にしています。IM8は、例えば、インターネットブラウジングの隔離の実装、許可されていないデバイスによるUSBポートへのアクセスの禁止、個人データを含むファイルのパスワード保護の使用など、政府データ保護の具体的な措置を規定しています。またIM8は、適切なアクセス権限の取り消し、非活動ユーザーの検出、システムアクセス権限の定期的な見直しなど、特定のデータ保護プロセスも規定しています。
各機関はIM8のコンプライアンスおよび実装された措置の有効性について定期的に監査を受けています。監査の目的は、機関がデータインシデント発生前に対処すべきプロセスおよびシステムの欠陥を発見するのを支援することです。欠陥が発見された後、機関は特定の期間内にそれらの欠陥を改善するための計画を策定する必要があり、計画の進捗は完全な改善まで継続的に監視されます。定期的なIM8監査に加えて、監査長は機関のデータ管理実践についても監査する可能性があります。監査結果は議会に報告され、公開されます。機関の欠陥改善行動は完了まで追跡されます。重大な違反がある場合は、監査プロセス中に財務省に内部送付され、処理されることがあります。
PSGAおよび他の法律における抑止措置、IM8における規定的措置、および定期的なIM8コンプライアンス監査は、公共機関および公務員に対して高度なデータ保護責任を共同で課しています。データセキュリティは、データを通じた高質量な公共サービスを提供する政府の能力に対する公衆の信頼を維持するために非常に重要です。総理により委任され、シニア上級相チャン・シーシェンが主宰する公共部門データセキュリティレビュー委員会は、技術進歩に歩調を合わせるため、公共部門の既存の政策と実践を強化するための推奨事項を提示します。これには、説明責任措置の最新性を保つこと、データセキュリティが公共サービスリーダーの継続的な優先事項であることを確保すること、および政策と実践が堅牢なデータセキュリティフレームワークを維持するために継続的に改善されることを確保することが含まれます。委員会は2019年11月に総理に対してその調査結果および推奨事項を提出します。
英語原文
SPRS Hansard 原本記録 · 取得日:2026-05-02
1 Ms Irene Quay Siew Ching asked the Prime Minister with regard to public agencies' exemption from the Personal Data Protection Act (a) whether he can list out the specific clauses in the current laws and instruction manuals that provide for public agencies' accountability on data breaches (not misuse of data) in public IT systems; and (b) whether he can explain how these clauses in the laws collectively impose a high standard of responsibility on all public agencies.
Mr Teo Chee Hean (for the Prime Minister): Public agencies and their officers are subject to data protection provisions set out in the Public Sector (Governance) Act (PSGA) and the Instruction Manual 8 (IM8), as well as in other related legislation. The PSGA criminalises the acts of unauthorised disclosure of data, misuse of data and the re-identification of individuals from anonymised data. Public officers found guilty of these offences can be fined up to $5,000 and/or face a jail term of up to two years. Besides the PSGA, other legislation also criminalise the act of unauthorised disclosure of data, such as the Official Secrets Act, the Banking Act, the Income Tax Act, and the Statistics Act. These provisions serve to deter public service officers from and punish them for the irresponsible use and handling of data. Please refer to Annex A for a list of the relevant clauses in the aforementioned Acts.
Apart from criminal proceedings, public officers found to be negligent in protecting data under their control can face internal disciplinary actions, as provided for in the Public Service (Disciplinary Proceedings) Regulations 1999.
Apart from such legislative sanctions, the government has a number of measures to prevent or minimize the chances of a data security breach and to minimise the consequences of a data breach. All public agencies are required to comply with the provisions of the IM8. The IM8 complements the broad data provisions in the PSGA by setting out the rules and requirements that agencies have to adhere to in order to manage and protect government data under their control. The IM8 prescribes specific measures to protect government data. For example, the IM8 mandates Internet surfing separation, the disabling of USB ports from being accessed by unauthorised devices, and the use of passwords to protect files that contain personal data. The IM8 also prescribes certain data protection processes, such as the prompt removal of access rights, the detection of inactive users and the regular review of system access rights.
Agencies are regularly audited for their compliance with the IM8 requirements, as well as the effectiveness of the measures implemented. The objective of audits is to enable agencies to uncover process and system gaps that should be addressed before a data incident occurs. Where such gaps are identified, agencies are required to draw up plans to close these gaps within a specific timeframe, and the progress of these plans are monitored until the gaps are fully closed. Besides regular IM8 audits, agencies' data management practices may also be audited by the Auditor-General. The outcomes of these audits are reported in Parliament and publicly available; agencies' actions to close the gaps are tracked until completion. Serious irregularities can be brought to the attention of the Ministry of Finance for internal action, as part of the audit process.
The deterrent measures in the PSGA and other legislation, the prescriptive measures in the IM8, as well as the regular IM8 compliance audits, collectively impose upon public agencies and public officers a high level of responsibility for data protection. Data security is essential to upholding public confidence in the Government's ability to deliver a high quality of public service to our citizens through the use of data. The Public Sector Data Security Review Committee, commissioned by the Prime Minister and chaired by Senior Minister Teo Chee Hean, will recommend ways to enhance the policies and practices the public sector already has, to keep pace with advances in technology. This includes keeping accountability measures up-to-date to ensure that data security remains a priority among public service leaders, and to ensure that policies and practices are continually improved to maintain a robust data security regime. The Committee will present its findings and recommendations to the Prime Minister in November 2019.