구두 답변 · 2019-04-01 · 국회 13
개인 데이터 보호 조사 기능
의원들은 혈액 기증자 데이터 유출 사건에서 개인정보보호위원회(PDPC)의 조사 책임 및 공공 기관이 「개인정보보호법」(PDPA)으로 규제되어야 하는지 질문했습니다. 정부는 PDPC가 관련 민간 IT 공급업체를 조사 중이며, 공공 기관은 다른 법규로 규제되고, 데이터 보호 기준이 PDPA 이하가 아니라고 답변했습니다. 핵심 쟁점은 공공 기관이 PDPA 감시에서 면제되어야 하는지 및 그 책임 메커니즘입니다.
핵심 요점
- • PDPC investigates private vendor
- • Public agencies governed by other regulations
- • Public-agency data protection standards are high
공공 기관은 전문 법규로 규제되며, PDPA 대상 아님
공공 기관의 PDPA 면제 합리성 의심
공공 기관 데이터 보호 감시 강화
“Public sector agencies have to comply with the Government Instruction Manuals and the Public Sector (Governance) Act.”
참여자 (8)
- Dennis Tan Lip Fong
- Edwin Tong Chun Fai
- Irene Quay Siew Ching
- Minister for Communications and Information
- Cheng Li Hui
- S Iswaran
- Senior Minister of State for Health
- Sylvia Lim
전문 번역(한국어)
Hansard 원문 · 2026-05-02
13번 질문. Sylvia Lim 의원이 통신 및 정보부 장관에게 최근 보건과학청(HSA) 데이터베이스에서 80만 명 이상의 헌혈자 개인정보 유출 사건에 관해 질문하였습니다. (a) 개인데이터보호위원회(PDPC)가 본 사건 조사에서 어떤 역할을 하고 있는지; (b) HSA가 개인정보 보호 측면에서 적절한 조치를 취했는지 확인하기 위해 어떤 검토가 진행 중인지, 여기에는 HSA와 그 IT 공급업체 간의 계약 의무가 이들에게 위탁된 개인정보를 적절히 보호하고 있는지 여부를 포함합니다.
14번 질문. Irene Quay Siew Ching 의원이 통신 및 정보부 장관에게 공공 IT 시스템의 데이터 유출 사건을 고려하여 질문하였습니다. (a) 공공기관이 《개인데이터보호법》(PDPA)에서 면제될 정당한 이유가 있는지; (b) 시민이 기관에 민원을 제기하거나 민사소송을 제기하는 것 외에 다른 구제 수단이 있는지; (c) 공공 문책성을 실현하기 위해 이들 공공기관에 실질적인 처벌을 부과해야 하는지.
통신 및 정보부 장관(Mr S Iswaran): 의장님, 13번과 14번 질문을 함께 답변할 수 있도록 허락해 주실 수 있을까요?
의장: 좋습니다. 말씀해주십시오.
Mr S Iswaran: 의장님, HSA와 관련된 사건에 관해서는 개인데이터보호위원회(PDPC)가 HSA의 IT 서비스 공급업체인 Secur Solutions Group 개인유한회사를 조사하고 있습니다. PDPA를 위반한 것으로 발견되는 경우, PDPC는 지시 발령 및 벌금 부과 등 적절한 집행 조치를 취할 것입니다.
보건 고위 국무부 장관이 이전에 HSA 데이터 보안 정책 및 관행에 대한 검토 내용을 개요로 제시하였습니다. HSA가 정부 기관이므로, 스마트 네이션 및 디지털 정부 그룹도 본 사건에 대해 조사를 진행하고 있습니다.
Quay 의원은 공공기관이 PDPA에서 면제되는 것이 합리적인지 질문하였습니다. 해당 의원의 질문은 공공부문 기관이 데이터 보호 관행에 대한 책임이 없거나 PDPA가 적용되지 않기 때문에 높은 표준을 충족할 의무가 없다는 암묵적 가정을 담고 있습니다. 이러한 견해는 잘못되었으며 사실이 아닙니다. 공공부문 기관은 다른 법률 및 기타 규정에 의해 구속됩니다. 특히, 공공부문 기관은 정부 지침 수칙 및 《공공부문(거버넌스)법》(PSGA)을 준수해야 합니다. 전반적으로, 이들의 데이터 보호 표준은 PDPA와 동등하거나 더 높으며, 데이터 보안 위반에 대해 유사한 조사 및 집행 조치를 취합니다.
저는 이전에 의회에서 이러한 조치를 취한 이유를 설명하였습니다. 재언컨대, PDPA가 공공기관에 적용되지 않는 이유는 공공부문의 운영 방식에 근본적인 차이가 있기 때문이며, 정부 전체 협력을 통해 공공 서비스를 제공하기 위해서는 다른 개인정보 보호 방식을 채택해야 하며, 개인정보는 공공부문의 공동 자산으로 관리되어야 하기 때문입니다. 민간부문은 이와 다르며, 상업 서비스의 제공은 전체 접근 방식을 기대하지 않습니다.
시민은 공공부문 데이터 유출 시 PDPA와 동일한 구제 수단을 갖고 있습니다. 시민이 민간기관이 자신의 데이터를 부적절하게 처리한다고 의심하는 경우 PDPC에 민원을 제기할 수 있으며, 공공부문 기관이 관련된 경우 GovTech에 민원을 제기할 수 있습니다. 실제로, 민원 채널이 개방되어 있으며, 민원은 관련 기관으로 전달되어 후속 조치됩니다. 영향을 받은 개인은 또한 조정을 요청하거나 데이터 처리가 부적절한 기관을 상대로 민사소송을 제기할 수 있습니다.
의원은 공공 문책성을 실현하기 위해 공공기관에 실질적인 처벌을 부과해야 하는지 질문하였습니다. 정부 데이터 보안 규칙을 위반하고 무단으로 데이터를 오용하거나 공개한 공무원은 PSGA에 따라 형사 책임을 질 수 있습니다. 처벌에는 최대 5,000 신달러 벌금 또는 최대 2년 징역, 또는 둘 다 포함될 수 있습니다. 공공기관에 벌금을 부과하는 것은 별로 의미가 없습니다. 왜냐하면 벌금 비용은 결국 공공 재정에 의해 부담되기 때문입니다.
의장님, 수년간 정부는 민감한 데이터를 보호하기 위해 보안 조치를 지속적으로 강화해 왔습니다. 정부는 또한 기관의 데이터 접근 및 보호 조치를 검사하기 위해 내부 IT 감사의 수량 및 유형을 증가시켰습니다. 그러나 최근 데이터 관련 사건은 공공부문 데이터 보안 정책 및 관행을 강화할 긴급성을 부각시켰습니다.
따라서 총리는 공공부문 데이터 보안 검토 위원회를 소집하여 전체 공공 서비스의 데이터 보안 관행에 대한 포괄적 검토를 수행하고 있습니다. 검토에는 공공부문 기관 및 정부를 대신하여 개인정보를 처리하는 공급업체가 시민 개인정보 수집 및 보호에 있어 채택하는 조치 및 절차가 포함됩니다. 각 기관이 구체적인 사건을 조사하고 처리하고 있으며, 해당 위원회는 업계 및 전 세계 모범 사례를 참고하여 포괄적 검토를 수행하고 데이터 보안을 강화할 것입니다.
이번 검토는 모든 공공부문 기관이 최고 데이터 거버넌스 표준을 유지하도록 보장할 것입니다. 이는 공중의 신뢰를 유지하고 데이터 활용을 통해 시민에게 고품질 공공 서비스를 제공하는 데 매우 중요합니다. 해당 위원회의 업무는 스마트 네이션 비전 달성을 위한 우리의 노력을 보완할 것입니다. 공공부문 데이터 보안 검토 위원회는 2019년 11월 30일까지 조사 결과 및 권고사항을 총리에게 제출할 예정입니다.
의장: 이전의 의회 질문과 이 두 질문에 대한 추가 질문을 받겠습니다. Ms Cheng Li Hui.
Ms Cheng Li Hui(탐핀): 추가 질문 두 개가 있습니다. 보도에 따르면 서버가 다른 여러 IP 주소로부터도 접근되었다고 합니다. 이러한 접근에 대해 우리는 얼마나 알고 있습니까? 외국인인지 현지인인지? 우리는 그들에 대해 조치를 취할 것입니까? 그들도 헌혈자 정보를 획득했습니까? 건강상 이유로 헌혈할 수 없는 사람들의 민감한 정보도 접근되었습니까?
보건 고위 국무부 장관(Mr Edwin Tong Chun Fai): Cheng 여사의 후자의 질문에 관해서는, 영향을 받은 서버에는 해당 정보가 없었습니다. 서버는 등록 관련 정보만 포함하고 있었습니다. 공급업체 성명서의 관련 부분을 인용하면, 서버의 정보에는 신분증 번호, 성별, 헌혈 횟수, 최근 3회 헌혈 날짜가 포함되며, 때로는 혈액형, 신장 및 체중도 포함됩니다.
첫 번째 질문에 관해서는, 무단 접근이 여러 지점에서 발생했으며, 조사가 진행 중이며, 상황이 더 명확해지면 관련 답변을 제공할 것입니다.
Ms Sylvia Lim(야이): 의장님, Iswaran 장관께 추가 질문 세 개가 있습니다. 먼저, 민간 공급업체 Secur Solutions Group이 PDPA의 관할을 받으며 PDPC가 그 행위를 조사하고 있다는 확인을 들어서 기쁩니다. 제 첫 번째 질문은 PDPC가 HSA 조사 결과를 기다린 후에 조치를 취할 것인지, 아니면 동시에 진행할 것인지 입니다.
두 번째 질문은 총리가 부총리 Zhang Zhi-xian이 주재하는 정부 간 위원회를 소집하여 정부 IT 보안 표준을 검토한다는 점을 언급합니다. 이것이 정부가 현재 공공부문의 표준에 만족하지 않으며 표준이 부족하다고 생각한다는 의미입니까?
마지막으로, 세 번째 질문은 장관의 Ms Quay에 대한 기관 벌금 부과 관련 답변에 관한 것입니다. 그는 공공기관에 벌금을 부과하는 것이 의미가 없다고 언급했습니다. 왜냐하면 벌금 비용이 결국 공공 재정에 의해 부담되기 때문입니다. 하지만 중앙 정부가 공공기관이 벌금 지불을 위해 추가 예산을 받지 않을 것이라고 가정할 수 없으며, 따라서 기관은 벌금을 지불하기 위해 다른 곳에서 지출을 삭감해야 합니다. 예를 들어 고위 관리자 보너스 등? 이는 정부가 한 조직으로서 소기업에 기대하는 것과 동일한 표준을 준수할 의사가 있다는 중요한 신호를 전달하기 때문입니다.
Mr S Iswaran: 의장님, 의원의 질문에 감사합니다. 먼저, PDPC 조사가 동시에 진행되는지에 관해서는 답변은 긍정적입니다. 하지만 분명히, 우리는 또한 다른 관련 활동의 진행 상황을 참고해야 합니다. 왜냐하면 그들이 연관된 요소를 가지고 있기 때문입니다. 조사는 동시에 진행될 것입니다.
두 번째 질문은 공공부문 데이터 보안 검토 위원회의 설립이 의미하는 바에 관한 것입니다. 의원이 이를 정치적으로 활용하려 한다고 생각하지만, 명확히 말씀드리겠습니다. 정부는 계속해서 데이터 보안 표준을 향상시키기 위해 노력해 왔습니다. 수년간 우리는 여러 조치를 취했으며, 의회에서 이에 대해 여러 번 설명했고, 의원 및 다른 의원들의 질문에 대응해 왔습니다.
핵심은 최근의 일련 사건을 고려할 때, 총리와 정부가 포괄적 검토의 필요성을 평가했다는 것입니다. 현존하는 조치들이 부족한 것이 아니라, 우리가 공공부문 데이터 보안이 최고 표준을 충족하도록 전력을 기울여야 한다는 것입니다. 민간부문이나 글로벌 기업의 모범 사례에서 배울 수 있다면, 우리는 그것을 기꺼이 채택하여 정부 관행에 통합할 것입니다.
마지막으로, 벌금 및 그 신호 작용에 관해서입니다. 먼저, 「자가 점검」이라는 표현은 그녀의 정당 내 한 의원이 제시한 것이라고 생각합니다. 자신이 자신에게 벌금을 부과한다면, 신호 작용은 확실히 의문의 여지가 있습니다. 더 중요한 것은 신호는 당신이 이 문제를 진지하게 받아들이고 책임 있는 인원에 대해 책임을 추구한다는 것입니다. 따라서 우리의 처벌은 규정 미준수 결정 또는 행위를 한 개별 공무원을 대상으로 하며, 그들이 상응하는 결과를 감수하도록 합니다.
또한, 공공기관에 대한 조치는 그 평판과 리더십에 상당한 영향을 미칩니다. 의원은 이것이 그 자체로도 중요한 신호임을 인정해야 합니다. 왜냐하면 공공 및 민간 기관 모두 평판 훼손을 원하지 않기 때문입니다. 우리는 명확한 책임성을 보장하고 공공부문 데이터 보안이 최고 표준에 도달하도록 보장하기 위해 모든 방식을 검토할 의사가 있습니다. 이것이 또한 해당 위원회를 설립한 이유이며, 의원이 좋은 제안이 있다면 우리는 기꺼이 청취할 것입니다.
Ms Irene Quay Siew Ching(지명 의원): 장관이 의회에 보증했듯이, 우리는 공공기관에 높은 표준의 책임을 부과하는 여러 법률을 가지고 있습니다. 하지만 검토 후, 이들 법률이 데이터 유출에 대한 책임성이 명확하지 않으며, 초점이 데이터 오용에 있는 것으로 보인다는 것을 발견했습니다. 장관이 이를 명확히 할 수 있습니까?
제 두 번째 추가 질문은, 장관이 의회에 공공기관이 데이터 보호 및 ICT 시스템 보안 표준의 준수를 보장하기 위해 정기적 강제 내부 감사를 가지고 있다고 알렸습니다. 그렇다면 이전의 내부 감사가 이러한 잠재적 취약점을 발견하지 못한 이유는 무엇입니까?
Mr S Iswaran: 의장님, 의원께 설명을 부탁드릴 수 있을까요?
의장: 좋습니다. 말씀해주십시오.
Mr S Iswaran: 의원이 법률이 데이터 오용만 언급하고 데이터 유출을 언급하지 않는다고 말씀하신 것이 《공공부문(거버넌스)법》을 지칭하는 것인지 아니면 PDPA를 지칭하는 것인지요?
Ms Irene Quay Siew Ching: 저는 《공공부문(거버넌스)법》, 《국가기밀법》, 《소득세법》 및 《감염병법》을 말합니다.
Mr S Iswaran: 당신은 또한 지침 수칙(IM) 제8호를 검토하셨습니까? 종합적으로 보면, 데이터 문제는 유출이든 오용이든 일정한 연속성을 가지고 있습니다. 안심하세요. 데이터 유출이 발생할 때는 그 원인을 파악해야 합니다. 오용으로 인한 것이라면 한 가지 조치 세트를 취할 것이고; 시스템 결함으로 인한 것이라면 시스템 오류를 시정하기 위해 다른 조치 세트를 취해야 합니다. 누군가가 책임이 있다면, 그들도 책임을 추궁당할 것입니다. 정부 기관의 조치 처리에는 그 절차가 있습니다.
정기적인 IT 감사가 문제를 발견하지 못한 이유에 관해서는, 이것은 오래된 질문입니다. 감사가 IT, 재무 또는 품질 감사든 간에, 시스템이 사람에 의해 운영되고 때때로 오류가 발생하기 때문에 사건 발생을 완전히 방지할 수 없을 수 있습니다. 중요한 것은 사건 발생 후 우리가 이로부터 배우고, 오류를 바로잡으며, 우리의 접근 방식을 투명하게 공개해야 한다는 것입니다.
의장: Mr Dennis Tan.
Mr Dennis Tan Lip Fong (비선거구 의원): 보건 고위 국무부장관 Edwin Tong님께 질문드립니다. 제 일부 질문에 답변해 주실 수 있을까요?
Mr Edwin Tong Chun Fai: 의원님, 아직 답변을 받지 못하신 부분이 어느 것인지 말씀해 주실 수 있을까요?
Mr Dennis Tan Lip Fong: 제 질문과 관련하여 답변을 받았는지 확실하지 않습니다.
Mr Edwin Tong Chun Fai: Dennis Tan 의원의 질문은 정보가 왜 서버에 저장되었는지, 데이터가 어떻게 접근되었는지, 그리고 이것이 불법인지 여부 등의 사항들을 포함하고 있습니다. 이러한 모든 사항은 현재 진행 중인 조사 범위 내에 있으며, 조사가 완료되어 사실이 규명된 후에는 가능한 한 관련 정보를 제공하겠습니다.
영어 원문
SPRS Hansard 원본 기록 · 수집일: 2026-05-02
13 Ms Sylvia Lim asked the Minister for Communications and Information regarding the recent data leak of more than 800,000 blood donors' personal information from the database of HSA (a) what is the role of the Personal Data Protection Commission in investigating this incident; and (b) whether any review is being done to ascertain whether HSA has acted reasonably in protecting the personal data including whether the contractual obligations between HSA and its IT vendor reasonably safeguarded the personal information entrusted to these parties.
14 Ms Irene Quay Siew Ching asked the Minister for Communications and Information in view of data breaches across public IT systems (a) whether it is justifiable for public agencies to be exempted from Personal Data Protection Act; (b) what recourse do citizens have, other than to complain to agencies or seek civil action; and (c) whether there should be a tangible penalty meted out to these public agencies for public accountability.
The Minister for Communications and Information (Mr S Iswaran) : Mr Speaker, may I have your permission to take Question Nos 13 and 14 together, please?
Mr Speaker : Yes, please.
Mr S Iswaran : Mr Speaker, with regard to the incident involving HSA, the Personal Data Protection Commission (PDPC) is investigating Secur Solutions Group Pte Ltd, which is a private company and vendor of IT services to HSA. If found to be in breach of the Personal Data Protection Act (PDPA), PDPC will take the appropriate enforcement actions against the company, such as issuing directions and imposing financial penalties.
The Senior Minister of State for Health has earlier outlined the review of HSA’s data security policies and practices that is being undertaken. As HSA is a Government agency, the Smart Nation and Digital Government Group is also conducting an investigation into the incident.
Ms Quay has asked if it is justifiable that public agencies are exempted from the PDPA. Implicit in the Member’s question is the presumption that public sector agencies are not accountable for their data protection practices or not held to a high standard because the PDPA does not apply to them. That is wrong and simply not the case. Public sector agencies are subject to a different piece of legislation and other regulations. In particular, public sector agencies have to comply with the Government Instruction Manuals and the Public Sector (Governance) Act (PSGA). Collectively, they have comparable if not higher standards of data protection compared to the PDPA, and similar investigations and enforcement actions are taken against data security breaches.
I have previously explained in Parliament why we have adopted this approach. To reiterate, the PDPA does not apply to public agencies because there are fundamental differences in how the public sector operates, which requires a different approach to personal data protection when compared to the private sector. In order to enable a whole-of-Government approach to the delivery of public services, personal data has to be managed as a common resource within the public sector. The considerations are different in the private sector, as there is no such expectation of a holistic approach to the delivery of commercial services across private organisations.
Citizens have the same recourse for a data breach in the public sector as with the PDPA. Where citizens suspect that their data has been mishandled by a private sector organisation, they can lodge a complaint with PDPC; or with GovTech, if a public sector agency is involved. In practice, there are no wrong doors and the complaint will be directed to the relevant agencies for follow-up. Affected individuals can also seek mediation or take civil action against the organisation or agency which mishandled the data.
The Member has asked whether tangible penalties should be imposed on public agencies for public accountability. Public officers who flout the Government’s data security rules, and are found to have misused or disclosed data in an unauthorised manner, could be held criminally liable under the PSGA. The penalties include fines of up to $5,000 or a jail term of up to two years, or both. It is not meaningful to impose financial penalties on public sector agencies because the cost of such penalties would ultimately have to be borne by the same public purse.
Mr Speaker, over the years, the Government has progressively enhanced security measures to safeguard sensitive data. The Government has also increased the number and types of internal IT audits, to check on agencies’ data access and data protection measures. Nevertheless, recent data-related incidents have underscored the urgency to strengthen data security policies and practices in the public sector.
Therefore, the Prime Minister has convened a Public Sector Data Security Review Committee to conduct a comprehensive review of data security practices across the entire Public Service. This includes measures and processes related to the collection and protection of citizens’ personal data by public sector agencies, as well as vendors who handle personal data on behalf of the Government. While individual agencies are investigating and taking action on the specific incidents, this Committee will undertake a comprehensive review across the public sector, and incorporate industry and global best practices to strengthen data security.
This review will help to ensure that all public sector agencies maintain the highest standards of data governance. This is essential to uphold public confidence and deliver a high quality of public service to our citizens through the use of data. The work of this Committee will complement our efforts to achieve our Smart Nation vision. The Public Sector Data Security Review Committee will submit its findings and recommendations to the Prime Minister by 30 November 2019.
Mr Speaker : We will take the supplementary questions for the earlier Parliamentary Questions as well as for these two. Miss Cheng Li Hui
Miss Cheng Li Hui (Tampines) : I have two supplementary questions. It was reported that the server was also accessed by several other IP addresses. What do we know about this access? Is it by foreigners or locals and will we be pursuing any actions on them? Do they have the information on the blood donors as well? For those who failed to donate their blood due to illnesses, can this sensitive information be accessed?
The Senior Minister of State for Health (Mr Edwin Tong Chun Fai) : On Miss Cheng's latter question, that information was not on the server that was compromised. Only registration related information was on that server. And if I can just cite for Miss Cheng this relevant portion from the vendor's statement. It says that the information that was on that server were NRIC, gender, number of blood donations, dates of the last three blood donations and in some cases, blood type, height and weight.
As for the first point, the unauthorised access is from various locations. That is still being looked into and when we have a fuller position on this and have more clarity, we will provide those answers.
Ms Sylvia Lim (Aljunied) : Mr Speaker, I have three supplementary questions for Minister Iswaran. The first is, I am glad to hear that he confirmed that the private sector vendor Secured Solutions Group is actually governed by the PDPA and that PDPC is looking into their conduct. My first question will be, is the PDPC going to wait for the outcome of the HSA investigation and then, follow on from there or is it concurrent?
The second question is, it was mentioned that the Prime Minister has now convened a cross-Government committee chaired by Deputy Prime Minister Teo to look into standards of Government IT security. Does this confirm that the Government is actually not satisfied and that the standards so far have been wanting in the public sector?
Finally, the third question, which is an interesting one, is Minister's answer to Nominated Member Quay's question about financial penalties on organisations. He mentioned that it was not meaningful to fine public agencies because the fine would in the end come from the public purse. But can the central Government not operate on the premise that no additional money is going to be provided to public agencies to pay fines, and therefore, the agencies would just have to cope with cuts somewhere else to pay these fines, whether it is from bonuses of Senior Management or whatever it is? Because there is still an important signalling effect that the Government is prepared, as an organisation, to abide by the same standards it expects of small businesses.
Mr S Iswaran : Mr Speaker, I thank the Member for her questions. Firstly, on whether the PDPC's investigations would be concurrent, the answer is yes. But clearly, we would have to be informed by what is happening also in some of the other activities because they have some inter-related factors. But the answer is, the investigations will proceed concurrently.
The second question is, what does the establishment of the Public Sector Data Security Review Committee mean. I think the Member is trying to score a political point here and I want to make it categorically clear. The Government has been working, that is why I said so in my answer, consistently working and improving data security standards. There is a list of things that we have been doing over the years and I think this has been explained in the House many times in response to the Member's questions and that of many other Members as well.
The key point here is that, because there has been a series of these incidents in recent times, the Prime Minister and the Government have assessed that we need to take a holistic look again. That does not mean, that what we have is inadequate or lacking, but what it does mean is we should ensure that we put total effort to ensure that we leave no stones unturned in ensuring the highest standards of are met in the public sector when it comes to data security. If there is something that is to be learnt, whether it is from best practices in the private sector or from global companies, that is something we will be very happy to learn from and incorporate in the Government's practices.
Finally, on the point on financial penalties, and the Member makes the point about signalling effect. I would say, that first of all, in fact I think the term "ownself check ownself" was coined by a Member of her party. So, if you fine yourself, you do ask the question, what is the signalling effect there. It is far important that the signalling effect is that, you are taking this issue seriously and holding relevant people accountable. So, that is why, in the way we go about this, the penalties are focused on the individuals, officers, who have made decisions or taken actions which were deemed to be not compliant, and therefore, there are the consequences that I spelled out.
Having said that, I think, when you take action against an organisation in the public sector, the reputational impact on that organisation and leadership is significant. I think the Member will concede that, that in itself is also a major signalling point, because no organisation, public or private, wants to have its reputation tarnished. Having said that, we are prepared to look at all means, to ensure there is clear accountability and ensure that in the public sector we have the highest standards of data security. That is why, this committee has been set up and we will be open to suggestions. If the Member has interesting ideas on this, we would be happy to hear from her.
Ms Irene Quay Siew Ching (Nominated Member) : The Minister reassured the House that we have the various acts to impose a high standards of responsibility on public agencies. However, upon reviewing that, there seems to be a lack of clarity in this Act regarding accountability for data breaches. The focus seems to be on misuse of data. Can Minister clarify?
My second supplementary question is, Minister informed the House that the public agencies have regular mandatory internal audits in place to ensure public agencies comply with these standards for data protection and security of ICT systems. In that case, why are these potential lapses not surfaced during previous internal audit checks?
Mr S Iswaran : May I just seek a clarification from the Member, Speaker?
Mr Speaker : Yes, please.
Mr S Iswaran : When you say the Act does not refer to data breeches, only data misuse, are you referring to the Public Sector (Governance) Act or are you referring to PDPA?
Ms Irene Quay Siew Ching : I am referring to the Public Sector (Governance) Act, Official Secrets Act, Income Tax Act and Infectious Diseases Acts.
Mr S Iswaran : Yes, and have you also looked at the Instructions Manual (IM) 8? Because I think when you look at them holistically, it will be clear, that the issues with data, whether it is a breach or misuse, and when can I argue that there is a kind of continuum here. But let me assure you, when you have a breach of data, you have to establish why it occurred. If it is because of misuse, there will be a certain set of actions. If it is because your systems were not in place, it has to result in a different set of actions to correct the systemic errors. If there were certain people accountable for that systemic error, then they have to be held to account as well. So, I think there is a flow in the way this will proceed, in terms of action against Government organisations.
The second point on regular IT audits, why did they not throw up such issues in the past. I think that is an age-old question. You can have audits, I think it is not just in IT, you have it in financial audits, you have got quality audits, but you still have incidents. This is because it is human beings running the system and from time to time, it can happen. I think what is important is that when they occur, we learn from these incidents and set them right, and be transparent about what we are doing and how we are going about it.
Mr Speaker : Mr Dennis Tan.
Mr Dennis Tan Lip Fong (Non-Constituency Member) : A question for Senior Minister of State Edwin Tong. Is the Senior Minister of State able to answer any aspect of my questions?
Mr Edwin Tong Chun Fai : Can the Member elaborate on what other aspects have not been answered?
Mr Dennis Tan Lip Fong : No, on my question. Not sure my question has been answered.
Mr Edwin Tong Chun Fai : Mr Dennis Tan's question relate to the circumstances in which the information is placed on the server. How it is that there was access that was gained to the data and whether there was a breach of any law? Those are all matters that are covered by the investigations that are currently on-going, and to the extent possible, when this has been ascertained, we will provide those information.