Add Fazzaco to desktop

Add Fazzaco to desktop

Access Fazzaco from desktop next time

Add now
English

Singapore’s Central Depository Fined for Data Privacy Breaches

Source: Regulation Asia Editors, Regulation Asia
211 dividend cheques were sent to outdated mailing addresses, containing client names, NRIC numbers, CDP account numbers, and details of the securities held.
Singapore’s PDPC (Personal Data Protection Commission) has penalised eight organisations for breaching data privacy laws.
A SGD 32,000 financial penalty was issued to The Central Depository (Pte) Limited, a wholly owned subsidiary of SGX (Singapore Exchange) which provides integrated clearing, settlement and depository services in Singapore securities market.
The fine was the result of dividend cheques of some CDP Account Holders being mailed to outdated addresses, resulting in the disclosure of their personal data to other individuals.
The breaches followed CDP’s migration to the new post trade system in December 2018, whereby testing of a module to automate printing of dividend cheques did not include the scenario of change of address.
The programming error was subsequently detected after two CDP Account Holder complained that cheques had been mailed to an outdated address, and remediation measures were put in place.
In total, 211 dividend cheques were sent to an outdated mailing address, revealing client names, NRIC numbers, CDP account numbers, and details of the securities held.
A SGD 10,000 financial penalty was issued to MDIS Corporation for failing to put in place reasonable security arrangements to protect the personal data of individuals, provided for registration purposes to attend its courses.
A SGD 5,000 financial penalty was issued to the Singapore Accountancy Commission for failing to put in place reasonable security arrangements to prevent the unauthorised access of 6,541 Singapore Chartered Accountant Qualification programme personnel and candidates’ personal data.
Warnings were issued to five other companies for failure to prevent the unauthorised disclosure of personal data contained in invoices, resumes, an internal directory, an employee system and payment advice letters.
One of the companies was FWD Singapore, which inadvertently sent 42 payment advice letters to incorrect recipients.
The full details are available here.
Create Company Page