Follow us on LinkedInfor the latest from Zavior
Zavior
For Business

3 Common Mistakes To Learn From: PDPC Decisions 2024 - A Year in Review

The PDPC of Singapore released its 2024 decisions with fines totalling $425,800. Here are the most common data protection failures and key takeaways for organisations.

By Glenn Tan · CEO at Zavior.ai

3 min readInsight
3 Common Mistakes To Learn From: PDPC Decisions 2024 - A Year in Review

The PDPC published its 2024 enforcement decisions. Fines totalled $425,800 across the year.

Three failures show up again and again, and none of them are exotic.

2024's PDPC Decisions compiled by Zavior
15 Decisions Made by the PDPC in 2024
Fines totalling $425,800 for 93% entities
Largest Fine of $120,000 - Whereby up to 20,000 individuals were affected

Top Concerns in Data Protection

1. Weak Password Policies

The most prevalent issue, appearing in 75% of cases, was weak password policies. This alarming statistic underscores the critical need for robust password management across organizations. Companies like Carousell, CH Offshore, and CASE were among those cited for this vulnerability.

2. Lack of Multi-Factor Authentication (MFA)

The second most common mistake, found in 58% of cases, was the absence of multi-factor authentication. Organizations such as Payroll2U and Whiz Communications failed to implement this crucial security measure, leaving their systems more susceptible to unauthorized access.

3. Insufficient Monitoring and Incident Response

Half of the cases reviewed showed inadequate monitoring and incident response protocols. This deficiency, observed in companies like Payroll2U and Keppel T&T, highlights the importance of proactive security measures and swift reaction to potential breaches.

4. Access Controls and System Design

Both inadequate access controls and poor system design/documentation were identified in 42% of cases. Companies like Cortina Watch and CH Offshore struggled with access control issues, while Carousell and PPLingo faced challenges related to system design and documentation.

5. Vendor Management and Patch Management

Poor vendor management and inadequate patch management each appeared in 33% of cases. The Academy of Medicine and Whiz Communications were among those cited for vendor management issues, while CH Offshore faced patch management concerns.

6. Staff Training

Insufficient staff training was explicitly mentioned in 25% of cases, including CASE and Horizon Fast Ferry. This underscores the importance of ongoing education in data protection practices.

Key Takeaways

  1. Prioritize Password Security: Implement strong password policies and consider password management tools.
  2. Implement MFA: Add an extra layer of security to all critical systems and user accounts.
  3. Enhance Monitoring: Develop robust incident response plans and implement continuous monitoring.
  4. Review Access Controls: Regularly audit and update access permissions.
  5. Improve System Design: Ensure proper documentation and secure design principles in all systems.
  6. Manage Vendors Carefully: Establish clear data protection guidelines for all third-party vendors.
  7. Stay Updated: Implement a rigorous patch management process to address vulnerabilities promptly.
  8. Invest in Training: Provide regular, comprehensive data protection training for all staff members.

By addressing these common mistakes, organizations can significantly improve their data protection posture and reduce the risk of PDPC violations. As we move forward in 2025, let's commit to stronger, more resilient data protection practices.

Team Zavior

>>Download the full list of decisions here.<<

Glenn Tan

Written by

Glenn Tan

CEO at Zavior.ai

Build Trust Through Certifications | Cyber Security | AI Governance | Data Protection

Share

Let us be your Zavior.

Zavior helps Singapore organizations build cyber resilience aligned to SG Cyber Safe, the PDPA, and ISO 27001.

Continue reading