
PDPC enforcement decisions show one failure dominating: inadequate security arrangements under the Protection Obligation. It is the ground in most fines, including the largest to date, S$750,000 against IHiS and S$250,000 against SingHealth over the 2018 health-records breach. This page distils the recurring lessons and is refreshed after each decision cycle.
What are the biggest fines so far?
S$750,000 against IHiS and S$250,000 against SingHealth, imposed in 2019 over the 2018 breach of health records. One incident, two fined organisations, S$1 million between them, and still the benchmark every later decision gets measured against.
The split is the lesson. The PDPC held both organisations involved in the same breach accountable, each fined in its own right. Outsourcing the operation of your systems does not outsource the obligation to protect the data in them. A vendor carries its own liability. It does not absorb yours.
The benchmark is useful for sizing your own exposure honestly. Most penalties in the register sit far below it, because most breaches involve smaller datasets and less sensitive data than a national health system holds. A breach of health records across a national system sits at the extreme end of sensitivity and scale at once, and that is the calculus to run on your own holdings. A business sitting on years of sensitive customer records is closer to the top of the range than its headcount suggests.
Which obligation is breached most?
The Protection Obligation in section 24 of the PDPA, which requires reasonable security arrangements to protect personal data. It is the ground behind most financial penalties in the register. Decisions on other obligations exist; the security ground is the one that keeps producing fines.
The pattern makes sense mechanically. A consent failure harms one relationship at a time. A security failure exposes the whole database at once, so the harm the PDPC weighs is larger and the penalty follows. If you can fund only one stream of compliance work this year, section 24 is where the enforcement risk actually sits.
Note what section 24 does and does not say. "Reasonable security arrangements" is deliberately open-ended, scaled to what you hold rather than prescribing a fixed control list, which means the standard rises with the sensitivity and volume of your data. A five-person firm holding marketing email addresses and a five-person firm holding medical claims are held to different bars under the same nine words.
What "reasonable security arrangements" meant in each case is spelled out in the decisions themselves, and the same causes keep reappearing: accounts and systems carrying more access than the job needs, software left unpatched, test or default credentials never removed, and personal data kept long after the purpose it was collected for had ended.
What do recent decisions add?
The register is the closest thing Singapore has to a running definition of adequate security, which is why it repays reading directly rather than in summary.
Read new decisions the way the regulator writes them: as instructions. Each one names the arrangements the organisation lacked, which amounts to a free specification of what the PDPC currently considers reasonable. When three consecutive decisions cite the same missing control, that control has quietly become mandatory in practice, whatever flexibility the statute's wording appears to leave.
Make the monitoring somebody's job. A quarterly half-hour with the decisions register, summarised in two paragraphs for whoever owns data protection, keeps the moving standard visible without turning it into a project. The decisions are short and the pattern-spotting is not subtle. Most quarters the summary will say nothing changed, and that sentence is worth having on file too.
What would have prevented each?
The table maps each case to the control that was missing. The right-hand column is the transferable part; the fine is just history.
| Organisation | Breach | Fine | The missing control |
|---|---|---|---|
| IHiS | 2018 health-records breach | S$750,000 | Unpatched systems, weak administrative credentials and slow response once the intrusion was detected |
| SingHealth | 2018 health-records breach | S$250,000 | Inadequate oversight of its outsourced IT provider as the data owner |
Then run the column against your own environment. For most SMEs the honest output is a short list of controls you believed you had. Believed is doing a lot of work in that sentence; the organisations in the register believed it too.
Two traps in the exercise. The first is checking whether a policy mentions the control instead of whether the control runs; a patching policy and a patched server are different evidence, and the register is full of organisations that had the first. The second is stopping at your own systems when the decision involved a vendor's. If a case turned on an outsourced provider's failure, the question for your environment is which of your vendors could put you in the same seat, and what your contract and monitoring would show about them today.
The exercise costs an afternoon. The alternative way to learn the same lesson costs a listing in this table.
Zavior links each control in your register to the PDPA obligation it serves, so when a new decision names a missing control you can check for it in minutes rather than convene a project.
Frequently asked questions
Are PDPC decisions public?
Yes. The PDPC publishes enforcement decisions in a register on its website, with the grounds and the reasoning. Reading the most recent handful is free competitor intelligence, and a better afternoon than most training courses.
Can directions issue without fines?
Yes. The PDPC can direct an organisation to remedy failures without imposing a financial penalty, and outcomes short of a fine appear in the register too. A decision with no dollar figure still carries reputational weight, because it is published either way.
How do undertakings work?
An organisation commits to a remediation plan that the PDPC accepts in place of a full investigation running its course, and accepted undertakings are published. The trade is speed and certainty in exchange for making your commitments public.
Zavior · Data Protection
Reading the register tells you which controls the PDPC treats as reasonable; it does not tell you which you actually run. Zavior builds the programme that closes that gap: policies written for your real data flows, classification staff can follow, and DPIAs where new products warrant them, so the distance between the controls you believe you have and the ones operating shows up before a breach makes the point for you.
Book a free 30-minute business assessment →This is general information, not legal advice.