← LEADERSHIP TERMINAL

PARLIAMENT OF SINGAPORE · FORMER

Josephine Teo

Singapore

IN THEIR OWN WORDS

The Government's risk-calibrated approach to data security in artificial intelligence (AI) systems was explained in a written reply, given on 9 January 2024, to related questions asked by Dr Tan Wu Meng and Mr Gerald Giam.

STRENGTHEN RULES GOVERNING USE OF CLASSIFIED AND UNCLASSIFIED GOVERNMENT DATA GIVEN RAPID DEVELOPMENT OF AI TECHNOLOGIES - 2026-07-07 · READ THE OFFICIAL RECORD

Access to frontier models is helpful for specific use cases, such as advanced research and cybersecurity. However, these form a small proportion of artificial intelligence (AI) demand. For most industry, Government and research uses, capable models are already available.

CONTINUED FRONTIER AI ACCESS FOR SINGAPORE GIVEN US ORDER TO BAR FOREIGN ACCESS TO ANTHROPIC'S FABLE AND MYTHOS MODELS - 2026-07-07 · READ THE OFFICIAL RECORD

The Government tracks the development of technical standards for identifying artificial intelligence (AI)-generated content, including watermarking and digital provenance approaches, as part of broader efforts to manage AI-related risks.

WATERMARKING AND DIGITAL PROVENANCE STANDARDS FOR AI-GENERATED MEDIA, METADATA PRESERVATION AND DISCLOSURE OF ORIGINAL UPLOADERS AND CROSS-PLATFORM COORDINATION MEASURES - 2026-07-07 · READ THE OFFICIAL RECORD

Upon receiving a valid report of intimate image abuse, the Commissioner of Online Safety is empowered by law to direct Online Service Providers (OSPs) to disable access by Singapore users to the specified harmful online material. This direction may be extended to cover identical copies found on the platform.

IMPLEMENTATION OF STAY-DOWN MEASURES FOR NON-CONSENSUAL INTIMATE IMAGES AND SEXUALISED DEEPFAKES UNDER ONLINE SAFETY COMMISSION AND PREVENTING GLOBAL ACCESSIBILITY - 2026-07-07 · READ THE OFFICIAL RECORD

The Government is committed to keeping children safe online. We have announced plans to extend age assurance requirements to designated social media services, including requiring platforms to keep users under 13 off their services.

ADDRESSING BROADER ISSUE OF UNDER-16S' SOCIAL MEDIA ADDICTION - 2026-07-07 · READ THE OFFICIAL RECORD

Under the Online Safety (Relief and Accountability) Act 2025, the Commissioner of Online Safety is empowered to issue directions to platforms to remove specified harmful content, including intimate image abuse.

COMPLIANCE TIMEFRAMES FOR PLATFORMS TO REMOVE NON-CONSENSUAL INTIMATE IMAGES UNDER DIRECTION OF ONLINE SAFETY COMMISSION - 2026-07-07 · READ THE OFFICIAL RECORD

The complete record

Every one of 2,900 lines we hold for Josephine Teo, in date order, each linked to its source. Free to read, in full, without an account. Page 6 of 58.

  1. Mr Speaker, we acknowledge the mistake made in trying to implement the move to stop the incorrect uses of NRIC number. The Government has said so and the Government has also explained that the implementation had not started for the private sector. So, the implementation was supposed to have taken place within the public sector first. In this process of implementation, there were gaps in coordination and these resulted in ACRA misunderstanding what was required of them and disclosing the NRIC numbers in full when they launched their new Bizfile portal. Clearly, there are lessons to be learnt from this incident. This was a mistake. This was a misstep. We would like to have avoided it, but it has happened and we will do our best to learn from it.

    NRIC NUMBERS IN ACRA'S BIZFILE SERVICE - 2025-01-08 · READ THE OFFICIAL RECORD

  2. I should not answer on behalf of Minister Indranee, but I believe the answer to the Member’s last question is yes, there will be a public release of the findings of the after-action review. Minister Indranee can clarify. Ms Hazel Poa had asked about the use of authentication amongst public sector agencies. What I can share with her is that following the circular that was sent out, to the best of our knowledge, all Government, all public sector agencies have ceased the use of NRIC number as authenticators. I do not have, off-hand, who might have been using it before and I do not want to misrepresent. I hope she understands that. There was a middle question that I missed. Singpass, yes. The question of Singpass is a very interesting one. Singpass is available to anyone aged 15 and above, so it is a very wide group of people. In making Singpass available, designers have to find a way to have a unique identifier and so the NRIC number is used as the default identifier. So, it is used only as an ID. It is not used as a password; you set your own password. Although it is the default identifier, Singpass allows anyone to change out their user ID to something that is not their NRIC number. Prior to this incident, maybe not everybody was very aware of it, but it is actually not difficult to change your user ID. It is not difficult to go onto your Singpass app to change your user ID. If you do not wish to have your NRIC number as your user ID, you may change it to something else.

    NRIC NUMBERS IN ACRA'S BIZFILE SERVICE - 2025-01-08 · READ THE OFFICIAL RECORD

  3. Mr Speaker, I thank Mr Xie Yao Quan for his question. He is right to note that in place of masked NRIC numbers, the Government believes that in some instances, there would be no need for the NRIC number at all. He is also right to say that in other instances, we believe that names alone or some other identifier would be sufficient. But I think this is important to state: when interacting with the Government, for example, if you are applying for subsidies, if you are hoping to access some benefits that the Government is able to provide to you, if you are laying claim to something important and something valuable to you, these would be instances where the full NRIC numbers should be used. The whole purpose of making sure that we stop the incorrect uses of NRIC numbers is to enable the confident use of full NRIC numbers when we need to do so. I appreciate where Mr Xie is coming from. There are many, many use cases for the Government. It would not be possible at this point in time to list all of them. There must be hundreds, if not thousands of cases where internally, in correspondence with citizens, there may be a reason to use some form of identification. The decision that we thought that we should take is that each case has to be carefully assessed and each case will merit its own considerations. So, I would ask for Mr Xie's patience. Prior to the Bizfile incident, this process had not been completed. I can share with him that this process had started, but it was not yet complete.

    NRIC NUMBERS IN ACRA'S BIZFILE SERVICE - 2025-01-08 · READ THE OFFICIAL RECORD

  4. Mr Speaker, I thank the Member for his question. I think following the media conference as well as statements that were made in relation to the Bizfile incident, I recall that the Association of Banks had issued a statement on how banks do not have the practice of using the NRIC number as a sole factor of authentication. I think the awareness in certain sectors is certainly reasonably high. I believe the telecommunications companies may also have issued a statement. It was in the festive period, so I apologise if cannot remember specifically who issued what statement. Within the sectors where there are regulators, I think we can say with a good degree of confidence that the awareness about the inappropriateness of using NRIC numbers as a factor of authentication is quite high. But again, we do not want to assume. We still want to go through the rigour of ensuring that such practices stop. I would say that outside of these regulated sectors, there is a very large number of companies; and it would be best for us not to assume that the incorrect uses of NRIC numbers is well understood. So, our working assumption is that outside of the regulated sectors, we have an even bigger challenge. Having said that, I want to go back to the answer that I provided in response to Ms Hany Soh's questions. If you look at the NRIC-related scams that we have observed thus far, most of them relate to the victims thinking that they were dealing with a figure of authority, because that person, the scammer, was able to cite the NRIC number. Police have actually not been able to specifically identify cases of NRIC-related scams where the NRIC number was inputted to steal valuables. That has not so far been the commonplace observation among NRIC-related scams.

    NRIC NUMBERS IN ACRA'S BIZFILE SERVICE - 2025-01-08 · READ THE OFFICIAL RECORD

  5. As to the private sector, we had always known that it was going to be difficult and therefore, it was important to both engage in public education as well as consult the public on what would be the appropriate approach. I take the Member's point of view that from an individual standpoint and from an organisation's standpoint, psychologically, there is comfort that not the full NRIC number is known. If it was truly safe, then I think we can certainly consider continued practices of this nature to be not particularly harmful and not particularly something that has to be acted upon. But knowing what we know now, and knowing that there is now the ease of availability of these algorithms, and not doing something about it, that is also not responsible.

    NRIC NUMBERS IN ACRA'S BIZFILE SERVICE - 2025-01-08 · READ THE OFFICIAL RECORD

  6. Mr Speaker, the Member asked whether there are any downsides to using masked NRIC numbers. The same could apply to partial NRIC numbers. I explained earlier in my Ministerial Statement that what has happened is that nowadays, there are quite easily available online, algorithms that can allow you to guess, or work out, or derive, the full NRIC number, particularly if you know the birth year of a person. And actually, to work out the birth year of a person is not at all difficult. Public figures would certainly have Wikipedia pages where your birth year is well known. Even individuals who are not necessarily public figures may have talked about celebrating birthdays on their social media accounts. In which case, a person who is determined to work out the full NRIC number of these individuals from the masked NRIC number or the partial NRIC number, could quite easily use these algorithms to do so. So, the ease of availability of such algorithms will mean that the continued use of masked NRIC number gives this false sense of security that will not go away. And if this false sense of security were to persist and people think that their full NRIC number is still a secret, and they continue to use it as a password or if organisations set it as a default password or use it as an authenticator, that is where the risk of scams is, that is where the risk of harms associated with identity theft will become more commonplace. We thought that the right thing to do whilst the problem is still relatively contained, is to try and bring a stop to these kinds of practices. And the Government should take the lead for our own purposes.

    NRIC NUMBERS IN ACRA'S BIZFILE SERVICE - 2025-01-08 · READ THE OFFICIAL RECORD

  7. Mr Speaker, in response to the Member's question, I do not have the exact date when the discussion started. It would have to be months before that. To his question on whether there were whole-of-Government discussions, as would be typical of a change of this nature, besides issuing circulars, there would also have been briefings which would have allowed for clarifications. Then, upon those clarifications, it would also be quite a common practice amongst Government agencies to compile "frequently asked questions" in order to provide useful references to colleagues. So, I can share with the Member that these things did take place. As to how exactly the incident unfolded, I seek Members' understanding and kind support. At this juncture, even if we were to start pointing to this particular event or that particular occasion, they would still not allow us to piece together the whole picture. And if such episodic events were discussed, you could invite further questions. I think what could be even more difficult is if we gave the impression that there was an effort to conceal certain parts of the process, because we were only talking about other parts. So, I think I would refrain from further citing specific events leading to the launch of the new Bizfile portal on 9 December and the other associated events around it. So, I seek the Members' understanding that it would not be a very good idea for us to keep going into the specific details at this juncture.

    NRIC NUMBERS IN ACRA'S BIZFILE SERVICE - 2025-01-08 · READ THE OFFICIAL RECORD

  8. So, it goes back to the best protection that we can have for each other, and that is: for organisations, not to use NRIC numbers as authenticators or default passwords; and for individuals, not to use these NRIC numbers as passwords. How do we help organisations to do this as quickly as possible? Firstly, we recognise that it may take them time. Not everyone understands this. Even for Members of Parliament, it has taken two Statements and more than an hour to get to this point. So, we do not under-estimate the effort that is going to be required, the public education exercise that will have to be mounted and the many outreach sessions that we are likely to have to conduct, in order to help people understand the risks of continuing to use the NRIC number as an authenticator and as a password. So, we must give it adequate time. But the resources to help these organisations are available. We will do so through PDPC. Between the Infocomm Media Development Authority and the Cyber Security Agency, there are also programmes that will put the organisations in touch with the relevant knowledge experts, service providers that can help them bring about the change. To go back to Ms Tin's first question: has the policy changed? I explained at the outset that the Bizfile incident, without intending to, may have led people to think that the Government now has a new policy of allowing full NRIC numbers to be disclosed on a wide scale. And this is not the case. This is not the direction that we are moving towards. The change is only in respect of stopping the incorrect uses of NRIC numbers as authenticators and as passwords. That is the change. The policy, the guidelines, the duty of care that organisations must exercise when they collect and use NRIC numbers, those have not changed.

    NRIC NUMBERS IN ACRA'S BIZFILE SERVICE - 2025-01-08 · READ THE OFFICIAL RECORD

  9. Mr Speaker, I thank the Member Ms Tin Pei Ling for her questions. There are quite a few. One of them will need to be addressed by Minister Indranee, but I will attempt to address the rest. Let me first say that I appreciate Ms Tin's comments that we should be fair in how we conduct the review proceedings, and I think that is the intent. But the intent is to be rigorous and to be thorough, which also necessarily means that we do not further speculate on what took place. And that is part of the discipline that we will have to observe in order to ensure that, not only do we get to the bottom of matters but also that we are fair to all parties. Ms Tin had a specific question on the Guidelines on NRIC that are issued by PDPC and why were they withdrawn? It was withdrawn for a very short period of time to apply a new label to it, to draw people's attention to the statements that were made subsequently. So, it was intended to basically tell people that the Guidelines remain valid and the new label says so, but to please note these other discussions that have surfaced. So, I hope that addresses the question. Ms Tin also asked what should be done if the NRIC number has still been disclosed, what do you do about preventing scams, what do you do about pushing back against identity theft? I explained in my Ministerial Statement that NRIC-related scams have been around with us for some time. Most of the NRIC-related scams pertain to the scammers giving the impression that they are figures of authority because they are able to cite your NRIC number. Very few of the scams, in fact, it is not quite so easy to pinpoint even one specific instance, where the scammer was able to get hold of the NRIC number and then key that in to unlock valuables.

    NRIC NUMBERS IN ACRA'S BIZFILE SERVICE - 2025-01-08 · READ THE OFFICIAL RECORD

  10. This will allow us to more confidently use the NRIC number as a unique identifier, whenever we need to do so. (In English): Mr Speaker, with your permission, I will respond to any clarifications which Members may have, after Minister Indranee Rajah has also made her Statement. 12.57 pm

    RESPONSIBLE USE OF NRIC NUMBERS - 2025-01-08 · READ THE OFFICIAL RECORD

  11. Subject to law, they must notify and seek consent on use, and ensure protections. These are existing guidelines that will not change. What needs to change are the incorrect uses of the NRIC number. These include using NRIC numbers for authentication or as passwords. It is better to make these changes while the problem is relatively contained. Organisations and individuals can both help by taking steps to stop using NRIC numbers as authenticators or passwords. By taking action as soon as possible, we can increase protection for all of us. This will allow us to more confidently use the full NRIC number as a unique identifier whenever we need to do so. Mr Speaker, please allow me to summarise a few key points in Mandarin, please. (In Mandarin): [Please refer to Vernacular Speech.] Mr Speaker, the Government understands the public's concerns about the correct use of NRIC numbers. I would like to reiterate here that it is not our intention for the full NRIC numbers to become widely disclosed information. NRIC numbers are personal data, and they can only be used and disclosed when there is a need to do so. Unless indicated by law, organisations that wish to collect and hold your NRIC number must first notify and seek consent on its use, and ensure that it receives adequate protection. These existing guidelines will not change. However, what needs to change are some incorrect uses of the NRIC number. For example, we should not use NRIC numbers for authentication or as passwords. It is better to make these changes and rectify the problem while it is still relatively contained. Both organisations and individuals can do their part to stop using NRIC numbers as authenticators or passwords. By taking action as soon as possible, we can increase protection for all of us.

    RESPONSIBLE USE OF NRIC NUMBERS - 2025-01-08 · READ THE OFFICIAL RECORD

  12. The Government's personal data protection standards are set collectively by the Public Sector (Governance) Act, or PSGA, and our own internal rules. The PSGA is aligned with the PDPA and adapted to the Public Service context. Our internal rules are comprehensive and take reference from international and industry standards. We also continually strengthen our data governance practices. ACRA is expected to comply with these rules and the PSGA, which are no less stringent than PDPA requirements. Regular, mandatory audits are conducted to ensure that public agencies, including ACRA, comply with the standards for data protection and the security of information and communications technology systems. The number of data incidents and their severity is published annually. In the most recent whole-of-Government audit exercise on information technology-related data security controls, there were very few significant findings and all of them had been remediated by the agencies concerned. There has also been a reduction in data incidents of medium severity and above. Where necessary, we have also taken public servants to task, for example, in serious cases involving unauthorised disclosure or improper use of information. Members can be reassured that we take these rules and controls very seriously. We will continue to regularly review the safeguards to ensure that they remain relevant. Sir, let me conclude. We understand the public's concerns about NRIC numbers. It was not our intention to make the full NRIC number widely disclosed and we are not heading in that direction. NRIC numbers are personal data and can be collected and used only when there is a need to. Organisations that hold your NRIC number also have a duty of care.

    RESPONSIBLE USE OF NRIC NUMBERS - 2025-01-08 · READ THE OFFICIAL RECORD

  13. They include Mr Zhulkarnain Abdul Rahim, Mr Edward Chia, Mr Christopher de Souza, Mr Ong Hua Han, Mr Liang Eng Hwa, Ms Jessica Tan, Mr Louis Chua, Miss Cheryl Chan, Mr Sharael Taha and Mr Yip Hon Weng. As I have explained, the risks arise from the incorrect use of the NRIC numbers. If individuals stop using NRIC numbers as passwords and organisations stop using NRIC numbers as authenticators, this will go a long way to preventing harms from scams and identity theft. They will give us all better peace of mind to use the NRIC number whenever it is necessary, such as to get medical treatment or apply for jobs. Sir, the Government appreciates that the incorrect uses of the NRIC number may not be well understood. Our public education efforts will raise awareness among organisations and individuals, and to guide them on what they should do. In doing so, we will focus on the points I highlighted above. Mr Gerald Giam asked about alternatives to the current NRIC number system. In fact, the risks do not arise directly from the structure of the NRIC number. Rather, the risks arise when the NRIC number, which is meant to be a unique identifier, is incorrectly used as an authenticator or a password. Even if we were to create an alternative identifier, we would still have a problem if organisations used it as an authenticator and individuals used it as a password. Sir, let me turn now to questions about ACRA's exemption from Personal Data Protection Act (PDPA) requirements and the Government's data protection measures. These were raised by Ms Tin Pei Ling, Ms Sylvia Lim, Mr Saktiandi Supaat and Mr Patrick Tay. The Government has always taken seriously its responsibility to protect the data entrusted to the public sector.

    RESPONSIBLE USE OF NRIC NUMBERS - 2025-01-08 · READ THE OFFICIAL RECORD

  14. The first is to clarify their understanding of the NRIC number. Members like Ms Sylvia Lim asked about this. We have said that our NRIC number is like our name. Even if it is not widely disclosed, it is not secret. In our daily lives, if someone we do not recognise calls out our name and starts to behave as though they know us well, we would be slightly suspicious. We might be polite but not too friendly. Certainly, we should not fully trust this person, just because they know our name. This should also be how we treat anyone who tells us our NRIC number. We should not automatically assume that they know us well or are figures of authority or can be trusted. We should be cautious about revealing more about ourselves, or saying yes to their requests or following their instructions without checking further. The second thing we can do as individuals is to review our passwords. If we have used our NRIC number as a password to access any information or service, we have mistakenly used it as an authenticator and should change the password immediately. Doing so will give us better protection against people who use our NRIC number to get access to information or services. It will also complement efforts by organisations to stop using the NRIC number as a factor of authentication. To Ms Hany Soh's question, NRIC-related scams are not new. Most NRIC-related scams involve victims who think they are speaking to figures of authority and end up taking actions that harmed themselves, such as transferring money without further checks. Very few cases have involved scammers directly using NRIC numbers to unlock access to valuables. Several Members have also asked how to mitigate the risks when NRIC numbers are disclosed.

    RESPONSIBLE USE OF NRIC NUMBERS - 2025-01-08 · READ THE OFFICIAL RECORD

  15. This will include raising their awareness on why the use of NRIC numbers as a factor of authentication is unsafe and working through the Infocomm Media Development Authority and the Cyber Security Agency's programmes to help businesses review and adjust their practices. To questions by Ms Tin Pei Ling, Mr Zhulkarnain Abdul Rahim and Assoc Prof Jamus Lim, I should emphasise that NRIC numbers are personal data. This means that organisations collecting and using NRIC numbers must continue to exercise a duty of care. Subject to applicable law, they must notify and seek consent on use, and also ensure the data is sufficiently protected. Certainly, they should not disclose the NRIC numbers unless there is good reason to do so. Members may also ask, if the NRIC number is not suitable as an authenticator, what about the physical NRIC card, our pink identity card? If we look at our physical NRIC card, we will see that it contains other identifying information, such as our photo and fingerprint. It allows others to check that the information on the card matches me, the person holding the card. In addition, the physical NRIC card is not easily faked. The physical NRIC card is, therefore, suitable as an authenticator, or proof of who I claim to be. But someone providing my NRIC number and claiming to be me, does not have these additional factors of proof. Organisations must know that the physical NRIC card and NRIC number are different. The physical NRIC card can be an authenticator, but the NRIC number should not be used as an authenticator. Organisations should, therefore, not accept my NRIC number alone as proof that the person citing it is indeed me. Besides organisations, individuals, too, have questions about what they should do. There are also two things.

    RESPONSIBLE USE OF NRIC NUMBERS - 2025-01-08 · READ THE OFFICIAL RECORD

  16. Mr Edward Chia, Mr Liang Eng Hwa, Ms Hazel Poa and Mr Xie Yao Quan have asked specifically what should be done in the private sector. At this stage, we would advise private sector organisations to do two things: first, private sector organisations that are using NRIC numbers as a factor of authentication or as default passwords should stop this practice as soon as possible; and second, private sector organisations that presently collect partial NRIC numbers to identify people can continue to do so. The guidelines for the private sector have not yet changed and we will only consider how they should be updated after consulting the public. To questions by Mr Xie Yao Quan, Mr Melvin Yong and Mr Sharael Taha, we aim to start consultations soon and will provide details when ready. Our initial soundings with the private sector suggest there can be different approaches. Some organisations currently using partial NRIC numbers can stop the practice and replace them with alternative means of identification such as mobile numbers or email addresses or drop them entirely. But there are also organisations that need to accurately identify persons and can justify the collection of full NRIC numbers even if they are not required by law. For example, preschool centres will prefer to collect the full NRIC numbers of visitors rather than just the mobile numbers; the parents will certainly feel more secure. In applications for and disbursements of substantial financial aid, persons would also need to be accurately identified. We will take these considerations on board when updating the guidelines. In any case, I would like to assure Members like Ms Jean See and Mr Ong Hua Han that the Personal Data Protection Commission will support businesses in changing their authentication methods.

    RESPONSIBLE USE OF NRIC NUMBERS - 2025-01-08 · READ THE OFFICIAL RECORD

  17. At no point was our intention to disclose full NRIC numbers on a wide scale. In place of masked NRIC numbers, in some instances, there would be no need for the NRIC number at all. In other instances, names alone or some other identifier would be sufficient. But there could also be instances where full NRIC numbers should be used, instead of masked NRIC numbers. Each case would have to be assessed and decided individually. Members including Mr Leong Mun Wai, Mr Liang Eng Hwa, Mr Xie Yao Quan, Ms Jessica Tan, Mr Dennis Tan and Mr Pritam Singh have asked about the internal processes leading to ACRA's actions. Minister Indranee will say more about it in her Statement later and address Members' questions related to ACRA. Miss Cheryl Chan asked why the efforts to change did not include the private sector. The Government knew that it would take time for public agencies to make the change. We expected that it would take even longer for the private sector because of long-standing practices and habits. The plan was therefore to change the internal practices of Government before moving to change practices in the private sector and non-profit organisations, which Ms Usha Chandradas asked about. We believed that doing so would allow us to better understand the implementation challenges and, as a result, facilitate a smoother transition in the private sector. We had also planned to mount a major effort to help Singaporeans be aware of the risks and to support efforts to stop incorrect practices. The Bizfile incident was an unfortunate misstep which now means these plans need to be brought forward. While we had taken steps to stop the incorrect uses of NRIC numbers in the public sector, we had not started implementation for the private sector.

    RESPONSIBLE USE OF NRIC NUMBERS - 2025-01-08 · READ THE OFFICIAL RECORD

  18. Besides organisations, some individuals also started to use their NRIC numbers as their passwords. They did so under the impression that the full NRIC number is secret. However, as shown by Dr Tan Wu Meng in his question, there are now algorithms that can be found online, that have made it easier to work out the full NRIC number from the partial or masked NRIC number. The easy availability of such algorithms means that the continued use of partial or masked NRIC numbers gives both organisations and individuals a false sense of security. This does not really keep the full NRIC number secret. This also makes the practice of using NRIC numbers as passwords even more inappropriate. To the questions by Dr Tan, Mr Liang Eng Hwa and Ms Sylvia Lim, these developments led the Government to take steps to stop the incorrect uses of the NRIC number. This meant two things: one, not using the NRIC number as an authenticator; and two, moving away from the use of masked NRIC numbers, because it creates a false sense of security. We knew this transition would take time. But it was better to start while the problem is relatively contained and for the Government to take the lead. To the question by Ms Joan Pereira, we proceeded to ask agencies to stop using the NRIC number as an authenticator or as a password. We also asked agencies not to plan new uses, with a view to discontinuing existing uses of masked NRIC numbers eventually. The lapse in coordination between agencies led to ACRA's misunderstanding and the disclosure of full NRIC numbers in the People Search function of its new Bizfile portal. In hindsight, what we should have made clear was that moving away from the use of masked NRIC numbers did not mean automatically using the full NRIC number instead, in every case.

    RESPONSIBLE USE OF NRIC NUMBERS - 2025-01-08 · READ THE OFFICIAL RECORD

  19. " Since the NRIC number's purpose is to be a unique identifier, it cannot be a secret, just as our names are not secret. I should emphasise, however, that while your NRIC number is not a secret, it is not meant to be widely disclosed. This is the concern echoed in Mr Lim Biow Chuan's question. We would only disclose our NRIC number under certain circumstances, for example, when required by law. Some examples include disclosing our NRIC number to our employers, at the clinic or when we subscribe to a mobile telephone line. Because we do have to disclose our NRIC number to others for such purposes, we must assume that at least some people know our NRIC number. Over time, however, NRIC numbers have become increasingly used as more than an identifier. Previously, organisations would require seeing my physical NRIC card to confirm that I am who I claimed to be. However, some organisations assume that if someone can cite my NRIC number, that person must be me! This is clearly wrong. On the assumption that this person is indeed me, some organisations may go further to give the person access to privileged information or services. When used this way, my NRIC number is no longer just an ID, or identifier, but a key to unlock more information or services. In such situations, the NRIC number is being accepted as an authenticator, or proof of who a person claims to be. This is clearly inappropriate. Instead of the full NRIC number, some organisations collect and use a partial NRIC number, usually the last four characters of the NRIC number. They think that this is safe and that revealing only the last four characters still keeps the full NRIC number secret. Among public agencies, even when the agencies had the full NRIC numbers, the use of masked NRIC numbers became more common.

    RESPONSIBLE USE OF NRIC NUMBERS - 2025-01-08 · READ THE OFFICIAL RECORD

  20. Sir, let me start by acknowledging the concerns raised by the public over NRIC policy. The Bizfile incident is unfortunate. Without intending to, it may have led the public to believe that the Government is changing its policy to allow full NRIC numbers to be exposed on a wide scale. This is not the case. We take the public's concerns very seriously and are very sorry that the mistake has caused them much anxiety. I want to reassure the public that NRIC numbers remain personal data. NRIC numbers can only be collected when there is a need to do so. Organisations that collect NRIC numbers also have a duty of care. Subject to applicable law, they must notify and seek consent on use, and ensure protection of the data. These are existing guidelines that will not change. However, there are also some incorrect uses of the NRIC number today. Our plan was to stop these incorrect uses while the problem is relatively contained. Doing so will better protect everyone and allow us to use NRIC numbers with confidence. In this regard, my Statement today will address two issues: the current incorrect uses of NRIC numbers and why we need to change; and what our next steps will be. Sir, when we interact with others daily, we are identified by our names. However, our names may not be unique. For organisations that deal with many people, say, a hospital with several patients named John Tan, they need a better way to uniquely identify them. Their NRIC number is a useful unique identifier in such situations. When the hospital needs to perform an operation or dispense medication, the doctor or nurse must make absolutely sure that it is the right John Tan they are dealing with and they should ask you, "What is your NRIC number?

    RESPONSIBLE USE OF NRIC NUMBERS - 2025-01-08 · READ THE OFFICIAL RECORD

  21. Mr Speaker, Members have filed a total of 51 Parliamentary Questions (PQs) on the National Registration Identity Card (NRIC) policy and the disclosure of NRIC numbers on the Accounting and Corporate Regulatory Authority's (ACRA's) Bizfile portal. Second Minister for Finance Ms Indranee Rajah and I will be making Ministerial Statements to address the issues raised. Our Statements will address Question Nos 1 to 37 for oral answer in yesterday’s Order Paper; Question Nos 3 to 8 and 39 to 44 for written answer in yesterday’s Order Paper; Question No 52 for oral answer in today’s Order Paper, and related questions that have been filed for subsequent Sittings.

    RESPONSIBLE USE OF NRIC NUMBERS - 2025-01-08 · READ THE OFFICIAL RECORD

  22. This Parliamentary Question will be addressed through a Ministerial Statement by the Minister for Digital Development and Information during the Parliament Sitting on 8 January 2025. [Please refer to "Responsible Use of NRIC Numbers", Official Report, 08 January 2025, Vol 95, Issue 149, Ministerial Statements section.]

    REPORTS OF SUSPECTED SCAM CALLS BY PERSONS CITING FULL NRIC NUMBERS OBTAINED POSSIBLY FROM ACRA'S BIZFILE PORTAL - 2025-01-07 · READ THE OFFICIAL RECORD

  23. This Parliamentary Question will be addressed through a Ministerial Statement by the Minister for Digital Development and Information during the Parliament Sitting on 8 January 2025. [Please refer to "Responsible Use of NRIC Numbers", Official Report, 8 January 2025, Vol 95, Issue 149, Ministerial Statements section.]

    PUBLIC EDUCATION ON NEW ADVISORY TO MOVE AWAY FROM MASKED NRIC NUMBERS - 2025-01-07 · READ THE OFFICIAL RECORD

  24. This Parliamentary Question will be addressed through a Ministerial Statement by the Minister for Digital Development and Information during the Parliament Sitting on 8 January 2025. [Please refer to "Responsible Use of NRIC Numbers", Official Report, 8 January 2025, Vol 95, Issue 149, Ministerial Statements section.]

    SEPARATE UNIQUE IDENTIFIER FOR SINGAPORE RESIDENTS THAT IS DIFFERENT FROM NRIC NUMBER FOR USE IN DIGITAL SYSTEMS - 2025-01-07 · READ THE OFFICIAL RECORD

  25. This Parliamentary Question will be addressed through a Ministerial Statement by the Minister for Digital Development and Information during the Parliament Sitting on 8 January 2025. [Please refer to "Responsible Use of NRIC Numbers", Official Report, 8 January 2025, Vol 95, Issue 149, Ministerial Statements section.]

    PRIVACY RISKS OF CURRENT NRIC NUMBER STRUCTURE AND PROPOSAL TO ALLOW ALTERNATIVE CHECKSUM SYSTEM OR OTHER SAFEGUARDS - 2025-01-07 · READ THE OFFICIAL RECORD

  26. This Parliamentary Question will be addressed through a Ministerial Statement by the Minister for Digital Development and Information during the Parliament Sitting on 8 January 2025. [Please refer to "Responsible Use of NRIC Numbers", Official Report, 8 January 2025, Vol 95, Issue 149, Ministerial Statements section.]

    MEASURES TO PROTECT PUBLIC FROM FRAUD AND GUIDE BUSINESSES ON COLLECTION OF NRIC NUMBERS GIVEN NEW NRIC ADVISORY - 2025-01-07 · READ THE OFFICIAL RECORD

  27. This Parliamentary Question will be addressed through a Ministerial Statement by the Minister for Digital Development and Information during the Parliament Sitting on 8 January 2025. [Please refer to "Responsible Use of NRIC Numbers", Official Report, 8 January 2025, Vol 95, Issue 149, Ministerial Statements section.]

    REASONS BEHIND GOVERNMENT'S DECISION TO STOP PRACTICE OF PARTIALLY MASKING NRIC NUMBERS - 2025-01-07 · READ THE OFFICIAL RECORD

  28. NLB even facilitates the sale of books by local authors at selected events. NLB will continue with such efforts to create a vibrant reading ecosystem in Singapore. The promotion of literacy and a love for books creates a society that is more likely to support local authors.

    PUBLIC LENDING RIGHTS SCHEME FOR LOCALLY WRITTEN OR PUBLISHED WORKS TO ADDRESS LOSS OF SALES WHEN WORKS ARE BORROWED FROM LIBRARIES - 2025-01-07 · READ THE OFFICIAL RECORD

  29. A Public Lending Right (PLR) scheme is premised on the idea that authors or other rightsholders should receive some form of compensation for the loan of their books by public or other libraries. This has been implemented in some countries, such as the United Kingdom, Denmark and Norway. However, there is no international consensus on the need for or benefits of PLR. The International Federation of Library Associations and Institutions' (IFLA's) position is that there is little evidence that library lending causes such loss to authors that demand compensation through PLR. As such, IFLA does not support the principles of PLR, which can threaten free access to public library services. Instead, IFLA advocates for more appropriate and efficient ways to support authors. This is the position shared by the vast majority of libraries around the world. Given the lack of international consensus on the benefits of PLR schemes, the Government has not put in place legislation that requires libraries in Singapore, including the National Library Board (NLB), to implement such a scheme. The lending by NLB promotes equitable access to knowledge and enjoyment through reading and is a key platform for the discovery of local authors and publishers. NLB supports local authors and publishers through the purchase of their books and raising awareness of Singapore Literature, authors and publishers through a broad range of initiatives. These include NLB's signature events like Read! Fest and the National Reading Movement, which aim to nurture a vibrant reading culture here. NLB also works with many partners across the literary ecosystem to organise talks by authors, support book launches as well as arrange discussions and hands-on workshops with Singapore writers.

    PUBLIC LENDING RIGHTS SCHEME FOR LOCALLY WRITTEN OR PUBLISHED WORKS TO ADDRESS LOSS OF SALES WHEN WORKS ARE BORROWED FROM LIBRARIES - 2025-01-07 · READ THE OFFICIAL RECORD

  30. SDO also collaborates with different partners to organise learning journeys and workshops for seniors. Seniors may join digital interest groups, known as Digital for Life: Digital Clubs, to learn digital skills alongside their peers at Community Clubs and community spaces. More than 340,000 seniors3 have been trained through these initiatives. Based on IMDA's Annual Survey on Infocomm Usage by Individuals, 96% of seniors are communicating online in 2023, up from 87% in 2017, suggesting improvements in connectivity with seniors using technology to connect with one another online since the COVID-19 pandemic. Through the IMDA, the Government will continue its efforts to strengthen digital literacy among seniors to help them age actively and remain socially connected.

    IMPROVING AND MEASURING EFFECTIVENESS OF DIGITAL LITERACY PROGRAMMES FOR ELDERLY CITIZENS - 2025-01-07 · READ THE OFFICIAL RECORD

  31. The Government supports seniors to age actively, stay socially connected and be cared for within their communities through Age Well SG. For example, the Silver Generation Office conducts outreach to all seniors aged 60 and above to identify their needs and refers them to relevant support or services. This includes the Active Ageing Centres, where seniors can participate in active ageing programmes and receive buddying and befriending services. Meaningful engagement with technology is one of the ways that can help to improve social connectivity. A study by the DUKE-NUS Centre for Ageing Research and Education found that the regular use of digital technology among local seniors is associated with a lower likelihood of being at-risk of social isolation1. In this regard, Singapore has made good progress in helping seniors participate in an increasingly digital environment and levelling up digital literacy. This is achieved through efforts led by the Infocomm and Media Development Authority (IMDA). The Mobile Access for Seniors scheme was launched in 2020 to support lower-income seniors with subsidised smartphone and mobile plans. More than 13,000 lower-income seniors2 have benefited from the scheme. The SG Digital Office (SDO) and the Seniors Go Digital programme were established in 2020 to accelerate efforts to equip less-digitally-savvy individuals, including seniors, with basic digital tools and skills for daily living. Building on this, the Digital Skills for Life framework was launched in January 2024 as a nationwide effort to equip Singaporeans with essential digital competencies, including the use of smartphones to communicate, transact and find information online as well as how to stay safe while connecting with others online.

    IMPROVING AND MEASURING EFFECTIVENESS OF DIGITAL LITERACY PROGRAMMES FOR ELDERLY CITIZENS - 2025-01-07 · READ THE OFFICIAL RECORD

  32. We are actively working with industry partners to avail access to the compute resources needed to maintain our global competitiveness.

    CURRENT AND PROJECTED AI-SPECIFIC COMPUTING POWER AVAILABLE AND PLANS FOR NATIONAL CLOUD - 2024-11-13 · READ THE OFFICIAL RECORD

  33. Singapore is a regional data centre hub with a total capacity exceeding 1.4 gigawatts. We have one of the highest concentrations of data centres in the region and our operational data centre capacity per capita exceeds that of regional markets, such as Beijing, Hong Kong, Seoul, Sydney and Tokyo. To support continued growth and innovation in Singapore, we aim to provide at least 300 megawatts of additional capacity in the near term and more through working with the industry to explore green energy deployments. The amount of AI-specific compute resources available in these data centres depends on the workloads that the private and public sectors expect to process and how these workloads are distributed. It changes dynamically in response to needs and available alternatives. Our compute needs for AI research are being met through a combination of on-premise and commercial cloud capacities. This approach is more responsive to demand than mandating contributions from private data centres. The National Supercomputing Centre (NSCC) is a significant contributor to the compute resources available for our research ecosystem, including for AI research. The launch of the ASPIRE 2A and 2A+ research supercomputers in October 2024, which have 30 PFLOPS of aggregated compute power, will help to address the growing demand for high performance computing resources, complement existing infrastructure and enable new research opportunities. NSCC is also developing the next supercomputer that will enhance Singapore's high performance computing capabilities to support national research initiatives. Developing Singapore's compute infrastructure is vital to support our National AI Strategy 2.0 ambitions.

    CURRENT AND PROJECTED AI-SPECIFIC COMPUTING POWER AVAILABLE AND PLANS FOR NATIONAL CLOUD - 2024-11-13 · READ THE OFFICIAL RECORD

  34. The Protection from Online Falsehoods and Manipulation Act 2019 (POFMA) allows the Government to address online falsehoods expeditiously, by requiring the correct facts to be put up alongside the falsehood. This establishes an honest and factual basis for public discourse on issues of public interest. Accredited media outlets have long established practices to publish editor's notes or corrections if there are inaccuracies in their reports. Such processes allow the Government to work with accredited media to quickly clarify any factual errors in a timely manner. Non-accredited media outlets as well as individuals do not have such established processes for clarifications and corrections to be made.

    PROVIDING MEDIA AND PERSONS OPPORTUNITY TO CORRECT INACCURATE INFORMATION BEFORE ISSUING CORRECTION DIRECTION UNDER POFMA - 2024-11-13 · READ THE OFFICIAL RECORD

  35. The Government plans to make all high-traffic Government websites1 accessible by 2030. To do this, we will engage and work with local design practitioners, as needed. This includes getting feedback on the design of Government digital services and organising workshops and trainings for design professionals. We agree that non-Government entities should also improve the accessibility of their digital services. The Government provides support in various ways. For example, the Government Technology Agency (GovTech) has developed the Oobee tool, previously known as Purple A11y, which is an open-source web accessibility testing tool. This is freely available for use. GovTech has also launched the Co-Creation Lab during the A11y week in May 2024, which brought together representatives from Government agencies, the private sector as well as community users, to better understand accessibility-related challenges. The first run of the Co-Creation Lab brought together 95 representatives from the Government agencies and the private sector, such as banks and e-commerce firms, as well as users from the senior and persons with disabilities (PWDs) communities. This multi-stakeholder dialogue has enhanced the product teams' understanding of diverse user needs, including those of PWDs and seniors, and yielded valuable insights that will directly inform the development of current and future digital services from both the public and private sectors. We will continue to build on these efforts and engage with the private sector and community partners to raise awareness, facilitate knowledge sharing and encourage efforts to make non-Government digital services accessible to all Singaporeans.

    ENSURING HIGH TRAFFIC GOVERNMENT WEBSITES CONFORM TO WCAG 2.1 AND GETTING BUY-IN FROM DIGITAL SPACE STAKEHOLDERS - 2024-11-12 · READ THE OFFICIAL RECORD

  36. Applicants for arts entertainment licences (AELs) are required to submit their applications to the Infocomm Media Development Authority (IMDA) at least 40 working days before the commencement of the arts entertainment. This timeline recognises the unique nature of each application and the need for case-by-case review. Applications are usually processed within 20 working days upon receipt of complete information. In 2023, 95 per cent of AELs were issued within the service standard of 20 working days upon the receipt of complete information. A longer processing time may be needed if an application contains incomplete or inaccurate information, or if the content is contentious and requires consultation with the Arts Consultative Panel or other relevant stakeholders. Applicants are, therefore, encouraged to submit their materials early for IMDA's assessment.

    EXPEDITED PROCESSING CHANNELS FOR URGENT REVIEW AND ISSUANCE OF ARTS ENTERTAINMENT LICENCES - 2024-11-12 · READ THE OFFICIAL RECORD

  37. The National Library Board (NLB) has worked with the Urban Redevelopment Authority and the Housing and Development Board to ensure the future provision of a library as part of the land use plans for Tengah New Town. When planning for a library, NLB considers factors, such as resident population size and convenience of location, including, but not limited to, the site's proximity to transport nodes and the town centre. However, as the plan for the new town is still taking shape, we are unable to confirm the location and completion date at this juncture.

    PLANS FOR PUBLIC LIBRARY IN TENGAH NEW TOWN - 2024-11-12 · READ THE OFFICIAL RECORD

  38. The Infocomm Media Development Authority (IMDA) is investigating recent disruptions to mobile, broadband and subscription television services. Preliminary findings suggest that the disruptions were caused by technical issues. There is no evidence of sabotage or cyberattacks. My Ministry recognises the increasing importance of digital services to the day-to-day activities of consumers and businesses, and the significant impact when disruptions occur. Under the Telecommunications Act and Broadcasting Act, key telecommunications and broadcast service operators are required to put in place robust measures to minimise service disruptions. Operators are held to high levels of service standards in line with international benchmarks. They are required to conduct regular audits and reviews of their network infrastructure and business continuity plans to ensure the resilience of their services. I would like to assure the House that all service disruptions are taken seriously. Should IMDA’s investigations reveal lapses on the part of operators, firm action will be taken against them, including the imposition of financial penalties and directions to undertake the necessary measures to remedy gaps found. While every effort should be made to minimise service disruptions, we should plan on the basis that they will not be eliminated. This is especially so, given the increasing scale, functionality and complexity of digital systems. The Government will regularly review our regulations for relevance and effectiveness. At the same time, businesses should consider stepping up resilience measures to minimise inconvenience to their customers when disruptions occur.

    PENALTIES FOR SERVICE OUTAGES THAT AFFECTED MOBILE NETWORK, BROADBAND INTERNET AND SUBSCRIPTION TELEVISION SERVICES IN 2024 - 2024-11-12 · READ THE OFFICIAL RECORD

  39. The Ministry’s internal task force has completed its study of the incident and distilled lessons, particularly relating to software supply chain risks and patch management. The Cyber Security Agency of Singapore will be issuing advisories on them in due course. The task force also identified enhancements to improve incident response when such disruptions occur, and to strengthen the resilience of our Critical Information Infrastructure (CII) and Foundational Digital Infrastructure (FDI). Work by the respective Ministry of Digital Development and Information agencies and other Government stakeholders are underway. As updated to Parliament previously, the Crowdstrike incident did not significantly affect our CII or FDI. The impact to other entities has also been relatively modest. In any case, it is up to affected entities to decide whether or not to take legal action against Crowdstrike or their intermediaries. Not all disruptions can be prevented, nor will their impact be equally severe. Nonetheless, it is important to have the plans in place to recover quickly from unexpected disruptions and to have business continuity plans. I encourage all businesses to step up their efforts by tapping on resources, such as SingCERT’s advisory on building digital resilience, CSA’s cybersecurity toolkits and cybersecurity roadmaps in Infocomm Media Development Authority’s Industry Digital Plans.

    POSSIBLE LEGAL PROCEEDINGS BY SINGAPORE AGENCIES THAT SUFFERED LOSS FROM CROWDSTRIKE CYBERSECURITY INCIDENT - 2024-11-12 · READ THE OFFICIAL RECORD

  40. The Infocomm Media Development Authority (IMDA) adopts a co-regulatory approach with online streaming content providers, such as Netflix, Disney+ and Amazon Prime. Such service providers are required to adhere to IMDA's Content Code for Over-the-Top, Video-On-Demand and Niche Services, including fulfilling the necessary access control requirements to protect the young from unsuitable content. These requirements include rating all content on their services, presenting the rating prominently and providing parental locks for content rated NC16 or higher. The selection of content offered on these platforms are commercial decisions, but are expected to meet the above requirements. Where breaches are reported, IMDA will engage the platforms to rectify There are currently no plans to convene a Censorship Review Committee. The Government takes into consideration Singapore's prevailing media and social landscape in deciding if and when to convene content regulatory reviews and the appropriate format for such reviews. On content, policies and standards that are specific to different media platforms, the IMDA continues to consult a range of advisory committees. These varied approaches provide greater flexibility and timeliness in responding to shifts in the media landscape, community sentiments and societal norms.

    PROVISION OF ALTERNATIVE VERSIONS OF CONTENT IN AGE-APPROPRIATE CATEGORIES BY ONLINE MEDIA STREAMING PLATFORMS - 2024-11-11 · READ THE OFFICIAL RECORD

  41. However, in this instance, the failover did not happen seamlessly, which caused the intermittent service disruption. There is no evidence to suggest that the incident was related to a sabotage or cyberattack. IMDA is continuing its investigations. The telecommunication network in Singapore is a key infrastructure that supports our nation's connectivity needs and requirements. IMDA holds key service providers, like Singtel, to high service standards and requires them to conduct regular audits on their network and infrastructure. This includes, ensuring the security of network design, redundancy measures and business continuity plans. Service providers must also ensure that their networks are resilient against disruptions. IMDA will not hesitate to take strong action under the Telecommunication Act, including imposing financial penalties, should any lapses be identified. IMDA is working with MHA, SCDF and SPF to conduct a comprehensive after-action review on the availability of our emergency hotlines when disruptions occur.

    IMPACT OF SINGTEL'S 8 OCTOBER 2024 OUTAGE ON ACCESS TO EMERGENCY HOTLINES AND SERVICES AND STEPS TO ADDRESS VULNERABILITIES - 2024-11-11 · READ THE OFFICIAL RECORD

  42. I will answer Parliamentary Question Nos 11 to 16 on today's Order Paper as well as written Parliamentary Question No 23 on today's Order Paper, filed by Member of Parliament See Jinli Jean, together as they relate to the same incident. [Please refer to "Root Cause for Singtel's Recent Outage, Impact of Disruption to Essential Services and Measures to Ensure Telecom Operational Continuity and Resilience", Official Report, 11 November 2024, Vol 95, Issue 145, Oral Answers to Questions section.] On 8 October 2024, Singtel's fixed line voice service faced intermittent service disruption. This affected some residential and corporate users, including Government emergency phone lines, such as the Singapore Civil Defence Force's (SCDF's) 995 and Singapore Police Force's (SPF's) 999, and customer service lines for some Government agencies, healthcare organisations and companies. The Ministry of Home Affairs (MHA) and the Ministry of Health will be responding to queries on the service impact on their respective sectors arising from the incident. During the disruption, it is estimated that half of the calls could still be connected. All services were progressively restored over four hours after the start of the incident. The Infocomm Media Development Authority (IMDA) takes a serious view of this incident and is investigating the cause of this disruption and whether Singtel's incident response was adequate. Preliminary findings suggest that there was a technical issue, which affected the proper functioning of a network component in one of the two systems supporting Singtel's fixed line voice service. The two systems, located in separate telephone exchanges, are designed to immediately take over the full load of the other when one system malfunctions.

    IMPACT OF SINGTEL'S 8 OCTOBER 2024 OUTAGE ON ACCESS TO EMERGENCY HOTLINES AND SERVICES AND STEPS TO ADDRESS VULNERABILITIES - 2024-11-11 · READ THE OFFICIAL RECORD

  43. The primary role of GovTech is to harness and develop info-communications technology solutions and capabilities to drive our Digital Government and Smart Nation efforts. From financial year (FY) 2021 to FY2023, GovTech’s average annual expenditure was $1.7 billion, which was less than 2% of total Ministry expenditure. GovTech is almost fully funded from (a) central grants from the Government and (b) other Government agencies paying for the use of GovTech’s services and products. This is unlikely to change significantly in the near future.

    ANNUAL COST OF GOVTECH AS A COST CENTRE AND EXPECTED TIMELINE TO INCREASE REVENUE-GENERATING CAPACITIES - 2024-11-11 · READ THE OFFICIAL RECORD

  44. Our local vernacular print and digital media serve as important platforms to amplify Singapore’s perspectives in the international domain and reflect our values and way of life to external audiences. This is in addition to their primary responsibility of providing timely and trusted information for all Singaporeans, catering especially to the needs of our vernacular communities. As previously shared with Members, Government funding is provided to support the vernacular capabilities of our Public Service Media entities, alongside other areas, such as talent and technological development. In doing so, the Government works closely with both Singapore Press Holdings Media and Mediacorp to ensure resources are put to good use.

    EXPECTATION AND FUNDING OF LOCAL VERNACULAR PRINT AND DIGITAL MEDIA TO CONTINUE PROJECTING SINGAPORE'S VOICE INTERNATIONALLY - 2024-11-11 · READ THE OFFICIAL RECORD

  45. For families who suspect their child is struggling with mental health issues arising from digital technology use, including interactions with AI platforms, they can seek help from community service providers, such as TOUCH Community Services, which runs counselling and intervention programmes for youths affected by cyber and mental wellness issues. Young users may also approach Youth Community Outreach Teams (or CREST-Youth) and Youth Integrated Teams, which provide mental health services to youths aged 12 to 25.

    SUPPORT MECHANISMS AVAILABLE TO MITIGATE MENTAL HEALTH IMPACT ON YOUNG USERS OF AI PLATFORMS - 2024-11-11 · READ THE OFFICIAL RECORD

  46. Research on the impact of artificial intelligence (AI) platforms on mental health is still nascent and there is no conclusive evidence to date. The Government’s approach has been to equip Singaporeans, including young users, to use technology in a safe, healthy and balanced manner. For example, Cyber Wellness and Mental Health Education lessons are taught in schools as part of the Ministry of Education’s Character and Citizenship Education curriculum. Through the lessons, students are taught to be safe, respectful and responsible online users. They also learn to take care of their mental well-being, differentiate between stress and distress, regulate their emotions and seek help early. Across various subjects, students also acquire relevant digital literacies, such as to critically evaluate communication with AI technologies, collaborate with one another using AI, and use AI tools safely and responsibly. To equip parents to guide their children’s online interactions and support their digital well-being, the Infocomm Media Development Authority (IMDA) offers bite-sized resources on the Digital for Life (DfL) portal. In addition, programmes, such as the recently concluded DfL Festival, provide opportunities for parents and children to learn about emerging technologies and how to protect themselves against online harms. The National Library Board’s Source, Understand, Research, Evaluate (S.U.R.E.) initiative also offers resources on the benefits and risks of technology, including generative AI.

    SUPPORT MECHANISMS AVAILABLE TO MITIGATE MENTAL HEALTH IMPACT ON YOUNG USERS OF AI PLATFORMS - 2024-11-11 · READ THE OFFICIAL RECORD

  47. Under the Online Safety Code, designated SMSs must assess these reports and take appropriate actions in a timely and diligent manner. If the report is not frivolous or vexatious, these SMSs must inform the user who submitted the report of their decision and actions taken. Where criminal offences are disclosed, acts of cyberbullying may be also investigated by the Police. These include offences under the Protection from Harassment Act and the Penal Code, such as distribution of voyeuristic images or recordings. Under the Protection from Harassment Act, victims of cyberbullying can apply for a Protection Order to direct an individual or an entity to take down published images that cause harassment, alarm or distress. Offenders who breach the Protection Order would be liable, on conviction, to a fine not exceeding $5,000, or to imprisonment for a term not exceeding six months, or to both. The Government plans to introduce new legislation and measures to provide stronger support and assurance to victims of online harms, such as cyberbullying. This will include the setting up of a dedicated agency to help secure timely relief from perpetrators as well as the social media platforms. More details will be shared when ready.

    STRATEGIES TO COMBAT CYBERBULLYING AMONG YOUTHS - 2024-10-16 · READ THE OFFICIAL RECORD

  48. My response will also address a similar Parliamentary Question for Written Answer raised by Mr Yip Hon Weng for this Sitting. The Singapore Government takes a serious view on online harms, including cyberbullying. We have introduced a range of measures and are continuing efforts to strengthen online safety. Under the Broadcasting Act, the Infocomm Media Development Authority (IMDA) has designated six Social Media Services (SMSs) with significant reach or impact in Singapore. They are Facebook, HardwareZone, Instagram, TikTok, X (formerly Twitter) and YouTube. These SMSs must comply with the Code of Practice for Online Safety (Online Safety Code), which took effect on 18 July 2023. They must have additional measures to enhance the online safety of children, which include: (a) ensuring that children are not targeted to receive content that SMSs are reasonably aware to be detrimental to their physical or mental well-being, such as cyberbullying content; (b) having in place more restrictive account settings for children; and (c) providing tools for children or their parents to manage their safety. IMDA closely monitors the designated SMSs’ compliance throughout the year and will engage them if it detects systemic lapses that impact online safety for Singapore end-users. Designated SMSs are required to submit annual reports about measures, systems and processes that they have put in place to combat harmful content. IMDA is currently reviewing the first set of reports and will publish the outcome of its review in due course. These SMSs also have their own community guidelines against harmful content and provide tools for users to report such content. Singaporeans who encounter cyberbullying on SMSs should report these incidents.

    STRATEGIES TO COMBAT CYBERBULLYING AMONG YOUTHS - 2024-10-16 · READ THE OFFICIAL RECORD

  49. Under the Online Safety Code, designated SMSs must assess these reports and take appropriate actions in a timely and diligent manner. If the report is not frivolous or vexatious, these SMSs must inform the user who submitted the report of their decision and actions taken. Where criminal offences are disclosed, acts of cyberbullying may be also investigated by the Police. These include offences under the Protection from Harassment Act and the Penal Code, such as distribution of voyeuristic images or recordings. Under the Protection from Harassment Act, victims of cyberbullying can apply for a Protection Order to direct an individual or an entity to take down published images that cause harassment, alarm or distress. Offenders who breach the Protection Order would be liable, on conviction, to a fine not exceeding $5,000, or to imprisonment for a term not exceeding six months, or to both. The Government plans to introduce new legislation and measures to provide stronger support and assurance to victims of online harms, such as cyberbullying. This will include the setting up of a dedicated agency to help secure timely relief from perpetrators as well as the social media platforms. More details will be shared when ready.

    DEFINITION OF CYBERBULLYING THAT CAN BE REPORTED AND ENFORCEMENT PROCEEDED WITH - 2024-10-16 · READ THE OFFICIAL RECORD

  50. My response will also address a similar Question for Written Answer raised by Dr Wan Rizal for this Sitting. The Singapore Government takes a serious view on online harms, including cyberbullying. We have introduced a range of measures and are continuing efforts to strengthen online safety. Under the Broadcasting Act, the Infocomm Media Development Authority (IMDA) has designated six Social Media Services (SMSs) with significant reach or impact in Singapore. They are Facebook, HardwareZone, Instagram, TikTok, X (formerly Twitter), and YouTube. These SMSs must comply with the Code of Practice for Online Safety (Online Safety Code), which took effect on 18 July 2023. They must have additional measures to enhance the online safety of children, which include: (a) ensuring that children are not targeted to receive content that SMSs are reasonably aware to be detrimental to their physical or mental well-being, such as cyberbullying content; (b) having in place more restrictive account settings for children; and (c) providing tools for children or their parents to manage their safety. IMDA closely monitors the designated SMSs’ compliance throughout the year and will engage them if it detects systemic lapses that impact online safety for Singapore end-users. Designated SMSs are required to submit annual reports about measures, systems and processes that they have put in place to combat harmful content. IMDA is currently reviewing the first set of reports and will publish the outcome of its review in due course. These SMSs also have their own community guidelines against harmful content and provide tools for users to report such content. Singaporeans who encounter cyberbullying on SMSs should report these incidents.

    DEFINITION OF CYBERBULLYING THAT CAN BE REPORTED AND ENFORCEMENT PROCEEDED WITH - 2024-10-16 · READ THE OFFICIAL RECORD