• Login
    • Advanced search
    • Title
    • Channel
    • Module
  • Home
  • Client Solutions
    • Digital Transformation
    • Energy Transition
    • Supply Chains
    • Sustainability and ESG
    • Workforce Redesign
  • Sectors
    • Consumer Goods & Retail
    • Energy, Mining & Infrastructure
    • Financial Institutions
    • Healthcare & Life Sciences
    • Industrials, Manufacturing & Transportation
    • Technology
  • Learning Resources
    • Podcasts
    • Video Chats
    • Webinars
  • Area of Law
    • Antitrust & Competition
    • Artificial Intelligence
    • Banking & Finance
    • Capital Markets
    • Cybersecurity & Data Privacy
    • Data & Technology
    • Dispute Resolution
    • Employment & Compensation
    • Environment & Climate Change
    • Financial Services Regulatory
    • Inclusion, Diversity & Equity
    • Intellectual Property
    • International Commercial & Trade
    • Investigations, Compliance & Ethics
    • Mergers & Acquisitions
    • Pensions
    • Private Equity
    • Projects
    • Real Estate
    • Restructuring & Insolvency
    • Tax
  • Location
    • International

    • International
    • Asia Pacific

    • Australia
    • China
    • Hong Kong
    • Indonesia
    • Japan
    • Malaysia
    • South Korea (Korea, Republic of)
    • Singapore
    • Taipei
    • Thailand
    • Philippines
    • Vietnam
    • EMEA

    • Austria
    • Bahrain
    • Belgium
    • Czech Republic
    • Egypt
    • EU
    • France
    • Germany
    • Hungary
    • Italy
    • Kazakhstan
    • Luxembourg
    • Morocco
    • Netherlands
    • Poland
    • Portugal
    • Qatar
    • Russian Federation
    • Saudi Arabia
    • South Africa
    • Spain
    • Sweden
    • Switzerland
    • Türkiye
    • Ukraine
    • United Arab Emirates
    • United Kingdom
    • North America

    • Canada
    • United States
    • Latin America

    • Argentina
    • Brazil
    • Colombia
    • Chile
    • Mexico
    • Peru
    • Venezuela
Baker McKenzie InsightPlus Home
      • Title
      • Channel
      • Module
    • Hit ENTER to search in content
    • Advanced search
    • Login
  • Home
  • Client Solutions
    • Digital Transformation
    • Energy Transition
    • Supply Chains
    • Sustainability and ESG
    • Workforce Redesign
  • Sectors
    • Consumer Goods & Retail
    • Energy, Mining & Infrastructure
    • Financial Institutions
    • Healthcare & Life Sciences
    • Industrials, Manufacturing & Transportation
    • Technology
  • Learning Resources
    • Podcasts
    • Video Chats
    • Webinars
  • Area of Law
    • Antitrust & Competition
    • Artificial Intelligence
    • Banking & Finance
    • Capital Markets
    • Cybersecurity & Data Privacy
    • Data & Technology
    • Dispute Resolution
    • Employment & Compensation
    • Environment & Climate Change
    • Financial Services Regulatory
    • Inclusion, Diversity & Equity
    • Intellectual Property
    • International Commercial & Trade
    • Investigations, Compliance & Ethics
    • Mergers & Acquisitions
    • Pensions
    • Private Equity
    • Projects
    • Real Estate
    • Restructuring & Insolvency
    • Tax
  • Location
    • International

    • International
    • Asia Pacific

    • Australia
    • China
    • Hong Kong
    • Indonesia
    • Japan
    • Malaysia
    • South Korea (Korea, Republic of)
    • Singapore
    • Taipei
    • Thailand
    • Philippines
    • Vietnam
    • EMEA

    • Austria
    • Bahrain
    • Belgium
    • Czech Republic
    • Egypt
    • EU
    • France
    • Germany
    • Hungary
    • Italy
    • Kazakhstan
    • Luxembourg
    • Morocco
    • Netherlands
    • Poland
    • Portugal
    • Qatar
    • Russian Federation
    • Saudi Arabia
    • South Africa
    • Spain
    • Sweden
    • Switzerland
    • Türkiye
    • Ukraine
    • United Arab Emirates
    • United Kingdom
    • North America

    • Canada
    • United States
    • Latin America

    • Argentina
    • Brazil
    • Colombia
    • Chile
    • Mexico
    • Peru
    • Venezuela
  1. Data & Technology
  2. Singapore: PDPC accepts several voluntary undertakings in September 2025

Singapore: PDPC accepts several voluntary undertakings in September 2025

25 Sept 2025    3 minute read
    • Share by email
    • Share on
    • Twitter
    • LinkedIn
    • Facebook
    • Google plus
    • Get link
    • Get QR Code
    • Download
    • Print

In brief

In September 2025, the Personal Data Protection Commission (PDPC) reported that it had accepted several voluntary undertakings, including undertakings from Riway (Singapore) Pte Ltd and Kleen-Pak Products Pte Ltd. In both situations, the personal data breaches that led to these voluntary undertakings involved the data of almost 4,000 individuals. The data breach incidents were found to have arisen due to system vulnerability to SQL injections and inadequacy of cybersecurity and data protection practices.


Contents

In more detail

In both of the mentioned undertakings, the relevant organizations notified the PDPC of personal data breaches, one of which involved unauthorized access to a database through SQL injection via a membership portal and another that involved a ransomware attack on company servers, resulting in an exfiltration of files and publishing of personal data on the dark web.

Investigations revealed that the causes behind the incidents include the following:

  • System vulnerability to SQL injections, in particular a lack of adequate data validation and parameterized queries as security features allowing the threat actor to bypass other implemented security measures
  • Lack of procedures for decommissioning IT assets and deleting data, resulting in personal data remaining on a network storage location long after data migration
  • An inadequate password policy
  • No documentation for regular reviews of firewall rules and patch management

Upon discovering the incidents, both organizations took remedial actions, including the following:

  • Identifying root causes and implementing mitigation measures to block unauthorized access and prevent further data exposure
  • Resetting all administrator passwords to deny access to all unauthorized users
  • Immediately patching the identified SQL injection vulnerability and other related security gaps
  • Conducting security configuration to enable the SQL injection protection rules within the web application firewall
  • Notifying all affected individuals
  • Deleting migrated data permanently
  • Updating the data protection policy and conducting staff training on the updated policy
  • Conducting refresher training on IT security for all staff

As part of the undertakings, the organizations will be implementing further remedial actions, including upgrading data encryption methods to industry-compliant standards, conducting regular cybersecurity training and preparing a comprehensive suite of cybersecurity training materials, among others.

The PDPC has stated that it will verify the organizations' compliance with the undertakings and, if necessary, issue a direction to ensure the organizations' compliance.

Key takeaways

The PDPC's regular publishing of the voluntary undertakings it accepts illustrates its continued monitoring of data breaches that occur in Singapore. All companies should ensure their compliance with all applicable requirements under the Personal Data Protection Act 2012. It is important to note the causes of other data breach incidents and the remedial actions that have been taken in response to such incidents, as these remedial measures can be typically considered as a best practice for minimizing data breach incidents and heightening compliance with data protection laws.

If you would like to find out more about such best practices and what you can do to prevent a data breach, please feel free to reach out to your Baker McKenzie contact.

* * * * *

LOGO_Wong&Leow_Singapore

© 2025 Baker & McKenzie. Wong & Leow. All rights reserved. Baker & McKenzie. Wong & Leow is incorporated with limited liability and is a member firm of Baker & McKenzie International, a global law firm with member law firms around the world. In accordance with the common terminology used in professional service organizations, reference to a "principal" means a person who is a partner, or equivalent, in such a law firm. Similarly, reference to an "office" means an office of any such law firm. This may qualify as "Attorney Advertising" requiring notice in some jurisdictions. Prior results do not guarantee a similar outcome.

Contact Information
Andy Leck
Principal
Singapore
Read my Bio
andy.leck@bakermckenzie.com
Ren Jun Lim
Principal
Singapore
Read my Bio
ren.jun.lim@bakermckenzie.com
Ken Chia
Principal
Singapore
Read my Bio
ken.chia@bakermckenzie.com
Sanil Khatri
Local Principal
Singapore
Read my Bio
sanil.khatri@bakermckenzie.com
Daryl Seetoh
Local Principal
Singapore
Read my Bio
daryl.seetoh@bakermckenzie.com
Natalie Joy Huang
Local Principal
Singapore
Read my Bio
natalie.huang@bakermckenzie.com

Copyright © 2025 Baker & McKenzie. All rights reserved. Ownership: This documentation and content (Content) is a proprietary resource owned exclusively by Baker McKenzie (meaning Baker & McKenzie International and its member firms). The Content is protected under international copyright conventions. Use of this Content does not of itself create a contractual relationship, nor any attorney/client relationship, between Baker McKenzie and any person. Non-reliance and exclusion: All Content is for informational purposes only and may not reflect the most current legal and regulatory developments. All summaries of the laws, regulations and practice are subject to change. The Content is not offered as legal or professional advice for any specific matter. It is not intended to be a substitute for reference to (and compliance with) the detailed provisions of applicable laws, rules, regulations or forms. Legal advice should always be sought before taking any action or refraining from taking any action based on any Content. Baker McKenzie and the editors and the contributing authors do not guarantee the accuracy of the Content and expressly disclaim any and all liability to any person in respect of the consequences of anything done or permitted to be done or omitted to be done wholly or partly in reliance upon the whole or any part of the Content. The Content may contain links to external websites and external websites may link to the Content. Baker McKenzie is not responsible for the content or operation of any such external sites and disclaims all liability, howsoever occurring, in respect of the content or operation of any such external websites. Attorney Advertising: This Content may qualify as “Attorney Advertising” requiring notice in some jurisdictions. To the extent that this Content may qualify as Attorney Advertising, PRIOR RESULTS DO NOT GUARANTEE A SIMILAR OUTCOME. Reproduction: Reproduction of reasonable portions of the Content is permitted provided that (i) such reproductions are made available free of charge and for non-commercial purposes, (ii) such reproductions are properly attributed to Baker McKenzie, (iii) the portion of the Content being reproduced is not altered or made available in a manner that modifies the Content or presents the Content being reproduced in a false light and (iv) notice is made to the disclaimers included on the Content. The permission to re-copy does not allow for incorporation of any substantial portion of the Content in any work or publication, whether in hard copy, electronic or any other form or for commercial purposes.

Delete Comment ?

Are you sure want to delete comment ?

Get link
Embed
Share by email
Get QR Code

Scan this QR Code to share this content

  •  
  •  
  •  
HighQ
Copyright Baker McKenzie 2025 | Disclaimers | Supplemental Privacy Statement