Singapore legislation
Clause 69
Clause 69
Policies and practices for ensuring data security and cybersecurity
(1)
A relevant person must establish and implement appropriate policies and practices in respect of the matters mentioned in sections 66(1), (3) and (4)(b), 67(1) and 68(1) and (2)(b).
(2)
Without limiting subsection (1), a relevant person must ensure that the policies and practices mentioned in that subsection provide for any matter prescribed relating to those policies and practices.
(3)
For the purposes of subsection (2), the Minister may prescribe different matters relating to the policies and practices mentioned in subsection (1) in relation to different relevant persons or classes of relevant persons.
(4)
A relevant person must implement processes to ensure that every personnel of the relevant person adhere to the policies and practices mentioned in subsection (1).
(5)
Additionally, a contributor or user must implement processes to ensure that any relevant HDI of the contributor or user and every personnel of that relevant HDI adhere to the policies and practices mentioned in subsection (1).
(6)
A relevant person must, at the prescribed frequency, review and evaluate the policies and practices mentioned in subsection (1) to ensure that the policies and practices are effective.
(7)
For the purposes of subsection (6), different frequencies may be prescribed for different relevant persons or classes of relevant persons.
(8)
A person who contravenes subsection (1), (4), (5) or (6) shall be guilty of an offence and shall be liable on conviction —
in the case of an individual, to a fine not exceeding $200,000 or to imprisonment for a term not exceeding 2 years or to both; or
in any other case, to a fine not exceeding $1 million.
(9)
In this section, “personnel” —
in relation to a relevant person, means an individual who —
is employed or engaged by the relevant person; or
provides, as a volunteer, any service to the relevant person or to any other person acting on behalf of the relevant person; or
in relation to a relevant HDI of a contributor or user, means an individual who is employed or engaged by the relevant HDI.