Singapore legislation
Regulation 4
of Cybersecurity (Cybersecurity Service Providers) Regulations 2022
Regulation 4
Keeping of records
Subregulation 1
For the purposes of section 29(1)(a)(v) of the Act, a licensee must, in relation to each occasion on which the licensee is engaged to provide its cybersecurity service, keep records of the information specified in paragraph (2) in respect of every person who delivers the cybersecurity service on behalf of the licensee.
Subregulation 2
For the purposes of paragraph (1) —
the information for which records must be kept in respect of every individual who delivers any part of the cybersecurity service on behalf of the licensee, whether or not the individual is an employee of the licensee, is the following:
the individual’s name;
the individual’s identity card number, work pass number, passport number or foreign identification number; and
the information for which records must be kept in respect of every business entity which delivers any part of the cybersecurity service on behalf of the licensee is the following:
the business entity’s name;
the business entity’s —
Singapore unique entity number; or
business entity registration number in the foreign country or territory that the business entity is incorporated or registered in.