Cybersecurity and Personal Data Protection: Where the Obligations Overlap
Good cybersecurity and the Personal Data Protection Act (PDPA) compliance aren't legally the same requirement. For most SMEs, though, nearly every practical security measure that matters satisfies both at once.
It's easy to assume "cybersecurity" and "data protection" are two names for the same compliance task. They're actually two different laws with different scope and different triggers — but for a typical SME, the practical security work needed to satisfy each of them looks almost identical.
Two Different Laws, One Practical Overlap
The Cybersecurity Act 2018 is narrower than its name suggests: its core purpose is protecting Critical Information Infrastructure (CII), the computer systems needed to deliver essential services across 11 sectors such as energy, water, banking and finance, healthcare, transport and government. Most SMEs aren't CII owners, so the Act itself usually doesn't apply to them directly. The PDPA's Protection Obligation, by contrast, applies to virtually every organisation in Singapore that handles personal data, regardless of sector or CII status.
What the PDPA's Protection Obligation Actually Requires
The obligation calls for "reasonable security arrangements" appropriate to the sensitivity of the data involved. It's deliberately not a fixed checklist, because what's reasonable for a small retail business's customer contact list differs from what's reasonable for a business holding health or financial data. In practice, the Personal Data Protection Commission (PDPC)'s own guidance and enforcement history point to a consistent set of measures.
Practical Measures That Satisfy Both
- Access control. Staff should only be able to reach the personal data their role actually requires, not the entire customer or employee database by default.
- Encryption. Both at rest (stored data) and in transit (data moving between systems), particularly for anything sensitive.
- Staff confidentiality obligations and device policies. Written obligations on staff handling personal data, plus rules for remote work and personal devices accessing company systems.
- Vendor vetting. Covered in more depth in our guide to managing third-party data processors, since a vendor's weak security becomes your PDPA exposure.
- Patching and multi-factor authentication. Unglamorous, but consistently among the measures PDPC guidance treats as baseline "reasonable" practice.
CII Designation Doesn't Replace PDPA Obligations
Even where a business's systems are designated as CII and the Cybersecurity Act applies directly, that designation doesn't substitute for PDPA compliance. A CII owner that suffers a personal data breach still has to separately notify PDPC under the PDPA's own notification duty, within three calendar days of determining the breach is notifiable — the two obligations run in parallel, not as alternatives to each other. See our breach notification guide for the full timeline.
When the Cybersecurity Act Might Actually Reach an SME
CII designation is rare outside the 11 essential-service sectors, but it isn't purely a large-enterprise concern: a smaller business providing IT or managed services to a CII owner can be brought into scope indirectly, through obligations the CII owner's own compliance imposes on its vendors. Worth checking if your client base includes any essential-service operators.
Not sure your current security measures would count as "reasonable" under the PDPA?
Compliz reviews your access controls, vendor arrangements and security practices against the PDPA's Protection Obligation, and helps close the gaps.
Request a QuoteFrequently Asked Questions
Does the Cybersecurity Act apply to my SME?
Only if the Cyber Security Agency designates your systems as Critical Information Infrastructure, which is rare outside the 11 essential-service sectors. Most SMEs are governed by the PDPA's Protection Obligation instead.
What security measures does the PDPA actually require?
"Reasonable" security arrangements appropriate to the sensitivity of the data, rather than one fixed checklist. In practice this typically means access control, encryption, staff confidentiality obligations and vendor vetting.
If my systems are CII-designated, do I still need to follow the PDPA?
Yes. CII designation under the Cybersecurity Act doesn't replace PDPA obligations; a personal data breach still triggers the PDPA's own notification duty separately.
How fast must a data breach be reported to PDPC?
Within three calendar days of determining the breach meets the notification threshold, for organisations of any size or CII status.
Do I specifically need MFA and encryption to be PDPA compliant?
The PDPA doesn't name specific technologies, but MFA and encryption are among the measures PDPC's guidance consistently treats as satisfying "reasonable security arrangements" for data of ordinary sensitivity.
