Three decisions
Marina Bay Sands, S$315,000, October 2025. The personal data of 665,495 patrons was accessed and taken, and later offered for sale. A software migration in March 2023 left an application interface exposed. One employee had been made responsible for compiling the configuration list by hand, there was no second check, and the exposure went undiscovered for six months.
People Central, S$17,500, January 2026. Databases were deleted and the personal data of roughly 95,000 individuals was taken. The Commission found no multi-factor authentication, insufficient security testing, and no programme of periodic vulnerability assessment or penetration testing.
Singapore Data Hub, S$17,500. A comparable finding against another provider holding data on behalf of others: servers reachable from the internet running outdated operating systems, without firewalls, multi-factor authentication, encryption or network segmentation.
What the pattern is, and what it is not
None of these required a sophisticated attacker. An exposed interface. Missing multi-factor authentication. Unpatched systems facing the internet. A change that nobody checked.
That is an observation about three decisions, not a formula. The Commission weighs a range of factors when setting a penalty, including the nature of the data, how long the exposure ran, and what the organisation did once it knew. But it is a fair reading that Marina Bay Sands was not penalised for a more advanced lapse than the smaller organisations. It held far more records.
That is the part worth noting if you run a smaller company. The statutory standard is reasonable security arrangements, and what counts as reasonable does take account of your circumstances. It is not waived because you are small, and the same basic omissions appear in decisions at both ends of the scale.
Sector matters too. The Commission has indicated that organisations whose business is handling other people's data are held to higher expectations, because their customers have no practical way to inspect the controls they are relying on. If you are a service provider holding client records, that is you.