구두 답변 · 2023-11-22 · 국회 14
쇼핑 멤버 데이터 유출 사건 질의
의원이 싱가포르 럭셔리 리조트 운영사의 쇼핑 멤버 데이터 유출 사건의 보고 시간 및 지연된 통지 원인에 대해 질의했습니다. 통신 및 정보부 장관은 당해 사건이 규정된 시간 내에 규제 기관에 보고되었다고 응답하며, 지연된 통지는 먼저 유출을 제어하고, 영향을 평가하며, 통지 요구사항을 확인해야 했기 때문이라고 설명했습니다. 규제 기관은 당해 사건이 개인에게 중대한 해를 초래했는지 여부 및 통지가 적시에 이루어졌는지 여부를 조사 중입니다.
핵심 요점
- • Incident reported within required timeframe
- • Delayed notification to prioritise containment
- • Regulator is investigating
데이터 보호 강조, 엄격한 집행
알림 지연 및 조사 진행 상황 주목
데이터 유출 관리 규범 강화
“Singapore takes breaches of personal data seriously.”
참여자 (3)
- Hany Soh
- Josephine Teo
- Minister for Communications and Information
전문 번역(한국어)
Hansard 원문 · 2026-05-02
9번 의원 Hany Soh는 통신정보부장관에게 싱가포르의 한 럭셔리 리조트 운영사가 운영하는 쇼핑 로열티 프로그램의 약 655,000명 회원의 개인 데이터와 관련된 데이터 보안 사건에 대해 다음을 질문하였습니다. (a) 해당 사건이 관계 당국에 보고되었는지 여부 및 보고된 경우 언제 보고되었는지; (b) 영향을 받은 회원들에 대한 통지를 3주간 지연한 이유가 무엇인지.
통신정보부장관(Josephine Teo 여사)이 답변하였습니다. 의장께서, 2023년 11월 7일 마리나 베이 샌즈(MBS)는 고객 로열티 프로그램 회원 데이터가 2023년 10월 19일과 20일에 유출되었음을 발표하였습니다. MBS는 그 후 영향을 받은 개인들에게 통지하였습니다.
싱가포르는 개인 데이터 유출 사건을 매우 심각하게 여깁니다. 「개인정보보호법」(PDPA)은 모든 조직이 자신이 보유하거나 통제하는 개인 데이터를 보호하기 위해 합리적인 보안 조치를 취하고, 무단 접근, 공개 또는 수정을 방지할 것을 요구합니다. 「PDPA에 따른 데이터 유출 관리 및 통지 지침」은 조직이 준수해야 하는 시간표 및 요구 사항을 명확히 규정하고 있습니다.
MBS는 2023년 10월 20일에 데이터 유출을 발견하였으며, 2023년 10월 24일에 개인정보보호위원회(PDPC)에 통보하였습니다. 이는 상기 지침에서 규정한 PDPC로의 통보 시간 요구 사항을 준수하고 있습니다.
의원들은 즉시 통지가 요구되지 않는 이유에 대해 질문할 수 있습니다. 이는 주로 데이터 유출 발견 후 일반적인 후속 절차에서 조직이 일반적으로 네 가지 작업을 완료해야 하기 때문입니다.
첫째, 유출을 억제하기 위해 즉시 조치를 취해야 하며, 이것이 최우선 과제입니다. 둘째, 데이터 유출로 인한 데이터 손실의 정도와 범위를 평가하기 위해 최선을 다해야 합니다. 셋째, 통지 요구 사항을 준수하는지 여부를 평가해야 하며, 준수하는 경우 보고해야 합니다. 넷째, 억제 조치가 효과적이고 안전한지 여부를 평가해야 합니다.
따라서 이러한 네 가지 단계가 있으며, 억제 및 평가를 우선시하기 때문에 PDPC는 조직이 PDPC에 통지 보고서를 제출하기 전에 일정한 시간을 갖도록 허용합니다.
이러한 배경을 바탕으로, 저는 의원들에게 보증합니다. PDPC는 이 사건을 조사 중이며, 영향을 받은 개인들이 중대한 해를 입었는지 여부와 영향을 받은 개인들이 적시에 통보받았는지 여부를 확인할 것입니다. PDPC는 적절한 시점에 조사 결과를 공개할 것입니다.
의장께서: Hany Soh 여사.
Hany Soh 여사(Marsiling-Yew Tee 선거구): 저의 국회 질문에 대한 부장관님의 답변에 감사합니다. 몇 가지 추가 질문이 있습니다.
첫째, PDPC의 조사 결과와 관련하여 예상 완료 시간이 있습니까? 조사 결과가 추후 대중에게 공개될 예정입니까?
둘째, MBS가 PDPC에 보고한 후 PDPC가 영향을 받은 회원으로부터 어떤 보고를 받았습니까? 특히 이 사건이 이 회원들에게 미친 영향과 추가 지원 여부는 어떠합니까?
셋째, 관련 부처 또는 PDPC가 대량의 개인 데이터를 보유한 조직에 더 구체적이거나 더 엄격한 의무를 부과할 것을 고려하고 있는지에 관해, 예를 들어 라이센스 조건(해당하는 경우)을 통해서입니까?
Josephine Teo 여사가 답변하였습니다. 의장께서, 의원님의 추가 질문에 감사합니다. 저는 하나씩 답변하겠습니다.
첫째, 조사 결과가 공개될 것인지에 관한 질문 — 답변은 그렇습니다. 소요 시간과 관련하여, 이는 조사의 복잡성에 달려 있으므로 사전에 구체적인 기간을 확정하기 어렵습니다.
두 번째 질문은 영향을 받은 MBS 회원으로부터 추적 보고가 있었는지 여부입니다. PDPC는 영향을 받은 두 명의 회원으로부터 보고를 받았으며, 그들의 주요 목적은 PDPC에 이 문제에 주의를 환기하는 것으로, 아직 통보받지 않았거나 PDPC가 아직 유출 사건을 알지 못할 수도 있기 때문입니다. 둘째, 그들은 또한 PDPC가 MBS에 이 유출에 대한 책임을 추궁할 것을 요구하였으며, PDPC는 이미 그렇게 할 의도를 가지고 있습니다.
MBS가 영향을 받은 회원을 지원하는 방법과 관련하여, 우선 가장 중요한 것은 회원들이 이 유출이 어떤 유형의 데이터를 포함하는지 알도록 하는 것입니다. MBS는 영향을 받은 회원들에게 통보할 때 유출된 데이터 유형이 성명, 연락처, 거주 국가, 회원 번호 및 회원 등급을 포함한다고 명확히 명시하였습니다. 이것이 MBS가 확인할 수 있는 유출 범위입니다.
또한 MBS는 영향을 받은 회원들에게 자신의 MBS 계정 및 기타 개인 정보를 보호하는 방법에 대한 조언을 제공하였습니다. 책임 있는 조치로서 MBS는 영향을 받은 회원들이 추가 문의 및 기타 관련 사항을 명확히 하기 위해 사용할 수 있는 연락처를 제공하였습니다.
세 번째 질문은 대량의 데이터를 보유한 조직과 관련됩니다. 우리의 현재 입장은, 조직이 대량의 다양한 유형의 개인 데이터 또는 보험, 의료 및 금융 데이터와 같은 더 민감한 데이터를 보유할 때, 더 높은 표준의 개인 데이터 보호를 요구한다는 것입니다.
이 경우, 조직은 PDPC가 공개한 「정보통신기술(ICT) 시스템 데이터 보호 실무 지침」에 따라 강화된 데이터 보호 조치를 실시해야 합니다.
또한 PDPC는 데이터 보호 조항 집행에 관한 지침을 발표하였으며, 대량의 민감한 개인 데이터에 대해 충분한 보호 조치를 취하지 못한 것이 가중 처벌의 요소가 될 수 있음을 명확히 하고 있습니다. 위의 답변이 의원님의 질문을 해소하기를 바랍니다.
영어 원문
SPRS Hansard 원본 기록 · 수집일: 2026-05-02
9 Ms Hany Soh asked the Minister for Communications and Information with regard to the data security incident involving the personal data of about 655,000 members of a shopping loyalty programme operated by a luxury resort operator in Singapore (a) whether the incident was reported to the authorities and, if so, when was it reported; and (b) what was the reason provided to the authorities for the three-week delay in notifying affected members.
The Minister for Communications and Information (Mrs Josephine Teo) : Mr Speaker, on 7 November 2023, Marina Bay Sands (MBS) announced a breach of its customers' loyalty programme membership data that took place on 19 and 20 October 2023. MBS has since notified affected individuals.
Singapore takes breaches of personal data seriously. The Personal Data Protection Act (PDPA) requires all organisations to put in place reasonable security measures to protect the personal data in their possession or control, to prevent unauthorised access, disclosure or modification. The Guide on Managing and Notifying Data Breaches under the PDPA sets out clear timelines and requirements that organisations must comply with.
MBS discovered the data breach on 20 October 2023, and notified the Personal Data Protection Commission (PDPC) on 24 October 2023. This meets the timeframes for notification to PDPC as set out in the earlier mentioned guide.
The Member may ask why notifications are not required to be made immediately. That is really because in the usual follow-up to the discovery of a data breach, there are usually four things that we would like the organisations to undertake.
First is that they must immediately seek to contain the breach. So, that is the immediate priority. The second is that they must then make best efforts to assess the degree and the extent to which the data breach has resulted in loss of data. The third is then they must assess whether this falls within the requirements for notification, and if it does, then they must proceed to make the report. And the fourth is that they must then evaluate their containment efforts, whether they are secure.
So, there are these four steps, and because the priority is on containment and assessment, PDPC does give the organisation a little bit of time before they make the notification report to the PDPC.
With that as background, let me assure the Member that PDPC is conducting investigations into this incident. It will ascertain whether there was significant harm to affected individuals and correspondingly, whether affected individuals were notified in a timely manner. PDPC will provide their findings in due course.
Mr Speaker : Ms Hany Soh.
Ms Hany Soh (Marsiling-Yew Tee) : I thank the Minister for her response to my Parliamentary Question. I have a few supplementary questions in relation to that.
Firstly, in relation to the PDPC's investigation findings, do we have an estimated timeline as to when that will be completed and whether that would be subsequently published to the public for information?
Secondly, subsequent to the reporting by MBS to the PDPC, whether the PDPC has received any reports from members who are affected, especially, and how this particular incident has affected these members and whether any of them has been further assisted since then?
Thirdly, this is in relation to whether the Ministry or the PDPC would consider it necessary to impose further specific or enhancement of obligations to these organisations that possesses large volumes of personal data, for example, through licensing conditions, where applicable?
Mrs Josephine Teo : Mr Speaker, I thank the Member for her supplementary questions. Let me try to address them in turn.
The first is on whether the findings of its investigations will be made public – the answer is yes. As to how long that will take, it goes to the complexity of the investigations. And so, it is difficult to say in advance what the duration is likely to be.
Her second question relates to whether there were any follow-ups from affected members of MBS. The PDPC received reports from two of those members who were affected. Essentially, they wanted to draw the PDPC's attention to this, in case it was not notified, or it was not yet aware of the breach. And the second is that they also asked that the PDPC take MBS to account for this breach which, of course, the PDPC intended to do in any case.
As to how these affected members were being assisted by MBS, I think, in the first place, it is most important for the members to know what types of data have been accessed or revealed as a result of this breach. And so, when MBS notified the affected members, it did clarify that the types of personal data that were revealed, included the name, contact information, country of residence and membership number as well as tier. This was the extent of the breach that the MBS was able to ascertain.
It further provided advice to the affected members on how they could safeguard their accounts with MBS, as well as other kinds of personal information. As a responsible measure, they provided a contact for follow-up enquiries, in case the affected members wanted to clarify on various other aspects.
Ms Soh's third question had to do with the organisations that could be in possession of large volumes of data. Our position today already states that a higher standard of personal data protection is required when organisations hold large quantities of different types of personal data or hold data that might be more sensitive, such as insurance, medical and financial data.
In such cases, organisations are required to implement enhanced data protection practices as stipulated in the PDPC's guide to data protection practices for information and communications technology (ICT) systems.
In addition, the PDPC has issued an advisory guideline on enforcement for data protection provisions that makes clear that failure to put in place adequate safeguards for large volumes of sensitive personal data can be taken as an aggravating factor in calculating the level of penalties to be imposed on an organisation. I hope that addresses the Member's questions.