Insights · 15 May 2026

The PDPC's recent decisions
have one thing in common.

Every enforcement decision the Commission issues is published in full. Read together, the recent ones show a consistent pattern, and it is not that the attacks were clever.

Every enforcement decision the PDPC issues is published in full. Anyone can read them, including your customers and whoever is evaluating you in a tender. They are also the clearest available statement of what the Commission expects in practice.

Below are three decisions published between October 2025 and January 2026, all of them findings against the Protection Obligation. They are not a survey of the Commission's whole caseload, and we have not weighted them for anything. They are three recent decisions read side by side, and what they have in common is worth noticing: none of them turned on a clever attack.

S$315k
Largest of the three penalties
665,495
Individuals in that one breach
6
Months the exposure went unnoticed
0
Sophisticated attacks involved

Three decisions

Marina Bay Sands, S$315,000, October 2025. The personal data of 665,495 patrons was accessed and taken, and later offered for sale. A software migration in March 2023 left an application interface exposed. One employee had been made responsible for compiling the configuration list by hand, there was no second check, and the exposure went undiscovered for six months.

People Central, S$17,500, January 2026. Databases were deleted and the personal data of roughly 95,000 individuals was taken. The Commission found no multi-factor authentication, insufficient security testing, and no programme of periodic vulnerability assessment or penetration testing.

Singapore Data Hub, S$17,500. A comparable finding against another provider holding data on behalf of others: servers reachable from the internet running outdated operating systems, without firewalls, multi-factor authentication, encryption or network segmentation.

What the pattern is, and what it is not

None of these required a sophisticated attacker. An exposed interface. Missing multi-factor authentication. Unpatched systems facing the internet. A change that nobody checked.

That is an observation about three decisions, not a formula. The Commission weighs a range of factors when setting a penalty, including the nature of the data, how long the exposure ran, and what the organisation did once it knew. But it is a fair reading that Marina Bay Sands was not penalised for a more advanced lapse than the smaller organisations. It held far more records.

That is the part worth noting if you run a smaller company. The statutory standard is reasonable security arrangements, and what counts as reasonable does take account of your circumstances. It is not waived because you are small, and the same basic omissions appear in decisions at both ends of the scale.

Sector matters too. The Commission has indicated that organisations whose business is handling other people's data are held to higher expectations, because their customers have no practical way to inspect the controls they are relying on. If you are a service provider holding client records, that is you.

The gap between the largest penalty
and the smallest is the volume of data,
not the sophistication of the failure.

Being small does not change the standard of care. It changes the size of the number at the end.

What would have helped

Three controls,none of them expensive.

Control 01 · Answers decisions 2 and 3

Multi-factor authentication

On anything reachable from the internet: remote access, administrative consoles, email, and any customer-facing application. This is the omission that appears most often in the findings, and it is close to free.

Control 02 · Answers decision 1

A second pair of eyes

A named reviewer on migrations, firewall changes, permission changes, and anything that opens a system to the outside. A competent employee made one omission and nothing caught it for six months.

Control 03 · Answers decisions 2 and 3

Testing you actually keep to

The findings distinguish organisations that had never tested from those that tested periodically. A modest, regular scan you can evidence carries more weight than an ambitious annual exercise you skipped last year.

No control set guarantees prevention, and each of the three above answers a different one of the failures identified. What is worth noticing is what the list does not contain. No security operations centre. No threat intelligence subscription. No new platform. These are configuration and discipline, which is why the decisions read the way they do.

The uncomfortable questions

If the Commission wrote to you tomorrow, could you produce the following without a scramble?

  • The date of your last restore test, and who ran it. Not that backups are running: that someone recovered something and confirmed it worked.
  • The record of who reviewed your last change to a public-facing system.
  • The list of accounts with administrative rights, and when it was last reviewed.
  • Evidence that your staff completed security awareness training, by name.

Most organisations can describe all four in conversation. Fewer can produce the records. That distinction matters more than it sounds, because an assessor works from what you can show, and a control with no record behind it is difficult to defend as one you were actually operating.

What we would do first

Start with the internet-facing inventory: everything of yours that someone outside can reach. For most SMEs that list is shorter than expected, and it is where each of these three decisions began.

Then check multi-factor authentication across all of it, add a reviewer to changes that touch it, and put a recurring date in the calendar for testing. For most small organisations that is about a week of work, and it addresses the failures the Commission has been penalising.

Where to start

List everything of yours that someone outside can reach. For most SMEs it is a shorter list than expected, and it is where all three of these decisions began.

Want a second opinion?

We will walk the list with you. If you would rather not do it alone, that is a short conversation and we are happy to have it.

There is more of this in our
regulatory watch.