S Iswaran
Singapore
“The Maritime and Port Authority of Singapore (MPA) has incorporated the requirements of the International Maritime Organization (IMO) 2020 regulation in its Prevention of Pollution of the Sea (Air) Regulations 2022. The Regulations are applicable to Singapore-registered ships and all other ships while they are in Singapore waters.”
“The Maritime and Port Authority of Singapore (MPA) plans to progressively roll out the charging infrastructure for electric harbour craft operations in the Port of Singapore from 2025.”
“Since 2018, the Land Transport Authority (LTA) has imposed minimum bicycle parking provisions covering different types of developments. The requirements are determined by multiple factors, including the developments’ use, location and gross floor area (GFA).”
“I had addressed similar Parliamentary Questions by Mr Gerald Giam on 29 November 2022 and 10 January 2023, as well as in my Ministerial Statement on 8 May 2023. The Member can refer to these past answers and statement as there has been no material change in the allocation of Certificates of Entitlement.”
“To encourage the uptake of electric cars, the Government has rolled out the Electric Vehicle Early Adoption Incentive and enhanced Vehicular Emissions Scheme. When taken together, it provides up to $45,000 off the Additional Registration Fee of an electric car upon registration.”
“The Land Transport Authority studies all potential changes to the Certificate of Entitlement (COE) system carefully, including conducting sensitivity analysis where appropriate.”
The complete record
Every one of 2,300 lines we hold for S Iswaran, in date order, each linked to its source. Free to read, in full, without an account. Page 15 of 46.
“MCI and PDPC have recently completed a review of the Personal Data Protection Act and will propose amendments to enhance organisational accountability in the protection of personal data. The MLC runs the annual Better Internet Campaign which covers issues such as cyber safety, discernment of online information, and cyber bullying. This is reinforced by the National Library Board's "Source. Understand. Research. Evaluate" (S.U.R.E.) programme, which teaches students, working adults and the general public to be responsible producers and consumers of information. Ground-up campaigns initiated by our citizens are an important complement to the Government's efforts. For example, a group of students from the Nanyang Technological University ran a campaign called "Sure Anot" earlier this year to combat fake news. We look forward to more of such efforts. Collectively, these and other initiatives help nurture a discerning and vigilant community of netizens, which is the best defence against evolving threats in a dynamic landscape. MCI and our agencies will continue to work with all stakeholders and partners in this important effort.”
“Hacking, data leaks, and misleading information are global threats in the fast moving digital space. The Ministry of Communications and Information (MCI) aims to promote digital literacy - including awareness of cybersecurity, personal data protection, and misinformation - to help Singaporeans be discerning in their use of technology and in navigating online content. All of us – the Government, businesses and the general public – have a role and the responsibility to take steps to mitigate the risks in the digital space. It was in this spirit that the Government launched Digital Defence as the sixth pillar of Total Defence in February 2019. MCI and our agencies work closely with stakeholders in the private and people sectors to promote digital, media and privacy literacy. For example, MCI consulted stakeholders, including subject matter experts from the Media Literacy Council (MLC), to launch the Digital Media and Information Literacy Framework in July 2019, which aims to inculcate an appreciation of the benefits and risks of technology. A review of the framework is underway and expected to be completed by the first quarter of 2021. The Cyber Security Agency of Singapore (CSA) runs the annual National Cybersecurity Awareness Campaign, which provides tips for internet users to safeguard their digital assets. CSA also published the Safer Cyberspace Masterplan in October 2020 to secure Singapore’s core digital infrastructure, safeguard activities in cyberspace, and promote good cyber hygiene practices. The Personal Data Protection Commission (PDPC) launched the Data Protection Competency Framework and Training Roadmap in 2019 to enable Data Protection Officers to strengthen data protection practices in their organisations.”
“All prime-time news bulletins on Mediacorp's free-to-air TV Channels 5, 8, Suria and Vasantham are subtitled. These news bulletins are broadcast daily in the four official languages and enjoy the highest viewership. News is thus readily accessible to viewers in Singapore in their language of choice through free-to-air TV. The Government recognises the importance of subtitles in enabling access to news and information for the elderly and hard-of-hearing. Together with Mediacorp, we will continue to explore options and assess technological solutions to build on our current efforts, and will progressively expand subtitling as practical solutions emerge.”
“Since the SG Digital Office (SDO) was established in June this year, it has mobilised 1,000 Digital Ambassadors (DAs) to engage more than 36,000 seniors at 35 SG Digital Community Hubs at community centres and libraries island-wide. Amongst these seniors, 1 in 10 are low-income seniors and have benefited from subsidised mobile devices and data plans through the Mobile Access for Seniors scheme. While we help seniors be digitally connected, we must also ensure that they do so safely. Cybersecurity education is therefore part of the core curriculum in the Seniors Go Digital programme and is embedded in every engagement with seniors. Seniors are taught to identify online scams, cyber threats and online falsehoods, as well as the importance of personal data protection. For example, in the case of digital banking, seniors are advised to enable transaction alerts and not to disclose One-Time-Passwords to anyone. Seniors who prefer hands-on learning to build confidence can also sign up for an e-payment learning journey and be guided by DAs to make their first e-transactions. Online resources and webinars are also available on the Infocomm Media Development Authority's (IMDA) website for seniors who wish to learn more. These tips and advisories are developed jointly with the Cyber Security Agency of Singapore, Singapore Police Force and the Media Literacy Council. We will continue working with relevant agencies to identify new topics as the online ecosystem evolves, and ensure that all Singaporeans are able to access the digital world safely.”
“The games development and e-sports industry in Singapore is growing, in tandem with its rise globally, especially in the Asian region. In Singapore, there are about 190 games development and publishing companies,1 many of whom are local players e.g. SEA Group, with a few multinationals e.g. Ubisoft. There are diverse opportunities for PMET jobs in this industry, spanning job roles such as Software Programmer, Games Producer, Games Developer and Project Manager. Over the next two years, the industry will require about 2,700 info-communications and media professionals to support the games sector.2 To locally support the capability needs of this industry, the Government established DigiPen (Singapore) in 2017 as a specialised game school to teach students about digital animation and video game design. At the same time, IMDA is partnering companies to train for job roles to support the games industry and create new career opportunities for Singaporeans. One example is IMDA's partnership with SEA Group to train 500 Data/Business Analysts, Engineers, Product Managers and UI/UX Designers over the next two to three years.”
“Mr Chairman, I beg to move the amendment* standing in my name, as indicated in the Order Paper Supplement. [(proc text) *The amendment read as follows: (proc text)] [(proc text) In page 54, line 20: to leave out "(6)" and insert "(5A)". (proc text)] [(proc text) Amendment agreed to. (proc text)] [(proc text) Clause 24, as amended, ordered to stand part of the Bill. (proc text)] [(proc text) Clauses 25 to 46 inclusive ordered to stand part of the Bill. (proc text)] [(proc text) Bill reported with amendment; read a Third time and passed. (proc text)]”
“This is an exercise in judgement, working with the industry and learning from our experience and past practices to arrive at what we think is a reasonable threshold. And I think what will then have to happen is, we see it in practice and learn from experience, and adapt as we go along. I want to assure Mr Louis Ng that PDPC will take a reasonable approach in exercising its powers proportionately and judiciously. PDPC's decisions are also subject to appeal to the Data Protection Appeal Panel and further appeals can be pursued in the Courts. So, there is recourse but in the first instance, PDPC will exercise due care and proportionality. Ms Pereira suggested that organisations notify the PDPC of all data breaches and she also advocated setting a fixed timeframe for notifications to individuals. Setting such a threshold for notification is important, but we have to take into account the compliance costs on organisations and also focus the effort on potentially systemic issues. We have not set a fixed timeframe for an organisation’s notification to affected individuals of a data breach because data breach circumstances can be very varied. Our positions have been developed in consultation with the public and benchmarked against jurisdictions like Australia, Canada, the EU and California. I will not rule out anything, but I think in the first instance we want to move forward and see how this works in practice. There was a question of whether PDPC will exercise its expanded powers appropriately. The new section 48J details a list of factors that the PDPC will consider before imposing financial penalties. To Mr Melvin Yong’s query, this will include whether the organisation had previously failed to comply with the PDPA which can be considered as an aggravating factor.”
“To provide additional clarity on scope of implementation, we have also catered for the following: (a) the scope has been narrowed to only cover individuals with whom the porting organisation has an existing and direct relationship; (b) data portability will be scoped to user activity and user provided data in electronic form and will apply only to prescribed categories of data; and (c) organisations are also not required to port data when the burden of porting, including the cost, is unreasonable. Let me turn to mandatory data breach notification. In the Bill, “significant harm” refers to the impact of a data breach on affected individuals and is used in the context of a data breach notification. I think Mr Leon Perera, Mr Louis Ng and also Mr Shawn Huang had asked about this and I want to tell them that we plan to prescribe in the Regulations, a numerical threshold. This is something that has been developed through consultation and it is a numerical threshold of 500 individuals for what constitutes a data breach of a significant scale. This threshold is based on past enforcement cases and other jurisdictions’ practices as well. The Regulations will also include categories of personal data which, if compromised in a data breach, will be considered likely to result in significant harm to individuals, such as identity theft or fraud. One example of such data is full name and confidential financial information. We will give more guidance through the Regulations but I want to stress – because I think the question was asked how we derived at these numbers. I do not think that there is any rocket science or magic behind it.”
“And that is why the financial penalties have been calibrated in the way that I have described. The proposed maximum financial penalty is comparable with other domestic legislation such as the Telecommunications Act and Competition Act and signals that data protection is of that level of importance in the digital economy. Some have asked – I think Mr Patrick Tay was one of them – whether in light of the current circumstances we can exercise some flexibility in how these penalties and other elements are phased in. As I mentioned earlier, we intend for the revised financial penalty cap to take effect no earlier than one year after the Act comes into force, and the Minister has the discretion under the Act to review the effective date. So, we will be informed by the overall circumstances because we are conscious of not wanting to unduly burden our companies. The revised penalty cap will apply to breaches that occur after the effective date. On compliance costs for the Data Portability Obligation, we want to make sure that the approach is balanced and achieves the intended results. So, to address the concerns over the scope of data that can or has to be portable, we have basically intend to help organisations with this new obligation, and introduce the data portability obligation in phases and will issue Regulations and advisory guidelines to provide clarity. This is new for Singapore. So, we want to make sure we do this in a measured way, clear about where we want to go – our destination – but prepared to be flexible in the path. On Mr Sharael Taha’s query on the safeguards for individuals, the regulations will prescribe consumer protection measures like cooling-off periods when porting certain types of data, in case consumers change their minds.”
“Instead of conducting selective audits for the few as suggested by Ms Joan Pereira, the PDPC will continue to support organisations by providing guidance, training and access to expertise, and recognising accountable organisations, to inculcate good data protection practices as broadly as possible. Essentially, we think a comprehensive upstream approach may be more beneficial. On guidance, PDPC provides accountability tools and resources, such as guides on implementing data protection management programmes, conducting risk assessments and adopting a data protection-by-design approach when developing IT systems. On training, PDPC has been building up data protection capabilities through the Data Protection Competency Framework and Training Roadmap. Since its launch in July last year, more than 6,200 people have been trained. Data Protection Officers or DPOs, trained under this framework will be able to implement robust data protection practices as well as support innovation. On access to expertise, we know and recognise that SMEs may need more help to comply with their data protection obligations. So, we have developed the Data Protection Starter Kit for them and Data Protection-as-a-Service as an affordable alternative for SMEs to outsource some DPO functions. PDPC also makes simple data protection solutions available on its website for free. We launched the DPTM last year to recognise organisations with good data protection standards. And to-date, 37 organisations have already been recognised. There are some concerns about the reasonableness of the increased financial penalty cap. Mr Desmond Choo proposed aligning the financial penalty cap with other Asian jurisdictions. The objective here is to ensure that we achieve the requisite deterrent effect on organisations.”
“For transnational scams, the Police collaborates closely with foreign law enforcement agencies to investigate and, where possible, cripple these syndicates. MCI is part of the Inter-Ministry Committee on Scams formed by MHA to combat scam messages and calls. As many of these scams originate overseas, we have to rely more heavily on technological solutions, as Mr Yip Hon Weng and Mr Melvin Yong have noted. For example, IMDA has required all telcos to implement the "+" prefix for all incoming overseas calls since April this year to help consumers better identify and reject spoof calls. Telcos are also blocking international incoming calls that resemble our Government agency or emergency numbers. So, these are efforts to help consumers discern and avoid being duped. I would urge consumers to carefully look at the numbers when they receive calls from overseas because I think this is one way. We cannot prevent these calls from coming in but we can put up red flags, and this "+" sign and some of these other measures are for that purpose. We will continue to support the Police in their efforts to tackle scams and other illegal activities. There have been questions on compliance costs and higher financial penalties. I think many have asked about what support we are going to give to organisations and clarity for compliance with the new provisions. First, these amendments mark the culmination of a multi-year journey. So, we would like to ask organisations to see this as part of their own investment and effort in building customer trust and commercial reputation.”
“So, we have the provisions. Whilst they are not identical to the right of erasure, I think they give a substantively similar effect. On unsolicited messages, Mr Melvin Yong asked about our efforts to address spams and scams. In 2019, the PDPC received 2,255 complaints on unsolicited calls and text messages, and has taken action against 427 organisations. These actions range from issuing advisory notices and warnings, to prosecution in Court. The proposed amendments to the PDPA and Spam Control Act establish clear guardrails for sending unsolicited commercial messages, to safeguard consumer interests while permitting legitimate direct marketing. Ms Tin Pei Ling and others have asked about the change in enforcement regime for DNC complaints – why we moved towards a civil administrative regime. The answer is that the assessment we had is that this would allow for a more efficacious enforcement. DNC infringements typically stem from commercial motives. Hence, directions and financial penalties are more effective in addressing poor practices by depriving offenders of the financial or commercial gains that they seek. So, it is not a step down. I think it is a more effective way of dealing with this problem. To Ms Joan Pereira’s and Mr Sharael Taha’s queries, our response to spam that originates overseas will continue to be multi-pronged, comprising a mix of public education, industry self-regulation and international collaboration. Scams, on the other hand – the letter makes all the difference; scams versus spams – scams are serious crimes and they are dealt with by the Police. They are enforced under laws like the Moneylenders Act for unlicensed moneylending; and Penal Code, for example, for cheating offences.”
“Organisations with the trust mark require their suppliers and contractors to also adhere to the same standards. It has a very beneficial ripple effect. There are signs, based on PDPC’s Perception and Awareness Study, that this is having a positive impact on the industry. For secure exchanges of personal data with overseas entities, transferring organisations must put in place contractual arrangements or binding corporate rules, to ensure that receiving organisations provide a level of protection comparable to PDPA. Apart from contractual transfer mechanisms, the PDPC joined the APEC Cross Border Privacy Rules, or CBPR, and Privacy Rules for Processors systems. These are multilateral certifications which require participating businesses to implement data protection policies consistent with the APEC Privacy Framework. Consumers also have a crucial role in safeguarding themselves. I think this is a point that I made earlier, and Mr Sharael Taha and Mr Melvin Yong have reinforced that. That is why on the part of PDPC, it has reached out to almost 70,000 individuals, including youths, through school talks, exhibitions, community roadshows and events. I am also heartened that these efforts have yielded promising results with consumer awareness of the PDPA and PDPC increasing. Mr Desmond Choo has proposed that a right of erasure be explicitly recognised. I believe Mr Louis Chua was also referring to this. Currently, section 16 of the PDPA provides for individuals to withdraw their consent at any time and the organisation would have to cease the collection, use or disclosure of the personal data unless otherwise required or authorised under any legislation. In addition, the PDPC can also direct an organisation to destroy personal data collected in contravention of the Act.”
“I would start by saying firstly, we must recognise, more importantly, organisations must recognise that it is in their self-interest to safeguard personal data as that would foster consumer trust, strengthen their business reputation, and ultimately, their competitiveness and bottom line. To support that and to ensure organisations take their obligations to protect data seriously, we are introducing both incentives and penalties – carrots and sticks, if you will. The PDPC will issue new advisory guidelines with examples and illustrations, so that organisations have ample notice of the expected standard of conduct. As data breaches cannot always be prevented, the PDPC’s enforcement framework reinforces the importance of dealing expeditiously with data breaches to reduce harm, through measures like breach reporting and statutory undertakings. Last year, PDPC investigated 185 cases, issued 58 decisions and ordered 39 organisations to pay a total of $1.7 million in financial penalties and that includes the highest financial penalty sums the PDPC imposed in 2019, which were $750,000 and $250,000 on IHiS and SingHealth respctively. The Bill enhances PDPC’s investigation powers and raises the financial penalty cap, to improve the effectiveness of PDPC’s enforcement. We are also creating market incentives, which can motivate organisations to practise high standards of data protection. I agree fully with Mr Sharael Taha on the value of certification systems and that is why PDPC launched the Data Protection Trust Mark or DPTM in 2019, to make it easier for consumers to recognise organisations with accountable practices and create the demand for good practices along the entire supply and delivery chain.”
“And before relying on deemed consent by notification, organisations must conduct a risk assessment to be sure that there is not likely to be any adverse effect on an individual. Individuals may withdraw their consent even after the opt-out period. The PDPC may also require organisations to produce these assessments for its review. Some Members have asked how these provisions might be operationalised. The PDPC has provided guidance on how to conduct risk assessments. It will also issue detailed guidance on the legitimate interests exception and how to identify adverse effect, which generally refers to any physical harm, harassment, serious alarm or distress to an individual. Exceptions for specific purposes, such as business improvement and research purposes, are tightly scoped. For example, the business improvement exception supports internal use of data within an organisation or a group of companies, with clearly defined limits. And when it comes to sending direct marketing messages, organisations still need to obtain express consent. Mr Sharael Taha enquired about the safeguards for deemed consent by contractual necessity. Essentially, organisations can rely on this provision to share personal data only to the extent necessary to perform their contracts with the individual. So, that is the test. Mr Desmond Choo asked about the “evaluative purposes". This is actually an existing exception in the PDPA which has now been reclassified under the “legitimate interests exception”. There has been another set of queries about how we can ensure or have confidence that organisations can be trusted to use personal data in good faith. I think this is an important point.”
“Current exceptions to consent cater for scenarios such as investigations and responding to emergencies. We are updating this list by adding business improvement and legitimate interests and updating the research exception for the benefit of consumers and organisations in the digital economy. The Bill is also clarifying the deemed consent provision to cover multiple layers of subcontracting when needed to fulfil a contract and to facilitate organisations notifying customers and giving a reasonable period to opt out, before they use data for new purposes. And I would like to reinforce this point and a point that Ms Jessica Tan had also picked up, that ultimately, consumers can opt out at any time and they have the freedom to do so. I want to assure Mr Desmond Choo that all private sector organisations can rely on these new provisions, regardless of the industry they are in. It is meant to apply uniformly. And on the whole, the amendments regularise current practices, provide organisations with clarity and confidence to use data, while protecting consumers' interests. As Mr Yip Hon Weng has noted, this will also enhance Singapore's status as an innovation and commercial hub. Some Members have asked about the safeguards for the new provisions. Stricter process safeguards are prescribed for the general legitimate interests exception and deemed consent by notification, while specific exceptions, such as business improvement and research, are tightly scoped. The safeguards have been designed based on the following principles. Before relying on the legitimate interests exception, organisations have to conduct a risk assessment and be satisfied that the overall benefit outweighs any residual adverse effect to an individual.”
“It is not just about complying with rules or regulations. At the end of the day, in any competitive domain, businesses will be able to differentiate themselves by their data policy and they will be able to signal the quality of the institution by the kind of approaches they take to safeguard their customers' data. So, they must be accountable and responsible, recognising ultimately that it is in their self-interest. And finally, individuals. I think all of us have the responsibility. Whilst some Members have talked about the so-called power asymmetry, ultimately, I would argue that consumers – individuals like you and me – we are not powerless by any stretch of the imagination. We can choose to decide whom to do business with or whom to give our custom. We can choose to decide what data we want to share. We can choose to decide whether we want to give consent and when we want to withdraw that consent. And, ultimately, we can decide when to sever the relationship if that is what we want. So, I think we should not lose sight of that aspect as well. Ultimately, the legislation must be seen in that perspective. It is one part of an overall architecture that will ensure a vibrant digital economy, but also one where data is respected, it is safeguarded, but also used for appropriate purposes. Let me now turn to some of the specific questions that have been raised by Members. First, on protecting consumers and the data. I think it is important to emphasise PDPA recognises organisations' need to use personal data for legitimate purposes. And today, that is accommodated through exceptions to the consent requirement, or as deemed consent. For all other purposes, organisations have to obtain consent from the individual.”
“There is also the APEC CBPR. I do not think any one of these is universally acclaimed because each has its strengths and its weaknesses. And that is why, in this endeavour of moving this legislative amendment, we have sought to understand the different regimes and to ensure that Singapore is able to remain best-in-class and also ensure that we are nimble and remain interoperable, which is key to our positioning as a node in the international flow of data and digital transactions. And that leads me to the second overall point I want to make, which is we must recognise that whilst legislation and regulation is important, it is not a panacea and neither is it foolproof. And therefore, what it means is whilst we can put in place rules that will govern the data practices and ensure that data is safeguarded to the best of our ability, we cannot eliminate the risk of data breaches. So, it is important that we recognise that whilst the rules must be formulated and enforced, it must be complemented by good practices and that has to evolve over time so that we understand, as an overall economic system and as a society, our respective responsibilities and roles. And that brings me to my third overarching point, which is that it is essential that we recognise all of us have a role to play and a responsibility to discharge in maintaining the security and the usability of our data regime and, in a sense, safeguarding the public commons. So, Government formulates the rules and regulations, enforces, provides guidelines and adapts to changing market situations to ensure that we remain abreast, to the best of our ability, of the developments and ensure that we keep Singapore relevant in the context of a new digital economy. Businesses must recognise that this is in their self-interest.”
“Thank you, Mr Deputy Speaker. Let me start by thanking all 13 Members who have spoken and for their support for this Bill. To be precise, actually, 11 Members have given explicit support and Mr Leon Perera and Mr Louis Chua, I am assuming, I have their deemed consent since I do not think that there is adverse effect on any individual. I also want to thank them for raising important issues this Bill seeks to address. And I think the comments of Members fall broadly into a few areas about: protecting consumers' personal data, endowing consumers with more control and a greater sense of autonomy and confidence while supporting organisations' legitimate use; and supporting businesses in the use of data for growth and innovation. I think in the comments that have been made by Members, it is clear that we all appreciate and recognise that there is an inherent tension between these objectives, and the proposed amendments seek to strike a judicious balance between them. In thinking about these issues and I do propose to address the specific questions raised by Members, it is important that we first recognise that this is a delicate and dynamic balance. It is delicate because if we over-correct in one direction, consumers may not retain their confidence and trust in the system. If we swing the other way, then we shackle our businesses and the very benefits that we seek for our consumers and for our economy will diminish. It is dynamic because technology is changing and the ways data is being generated and being put to use are also changing. And therefore, it is imperative that we find our own balance in the way we regulate the collection and use of data in Singapore. And there are different jurisdictions with different models. GDPR has been cited by several Members.”
“It should be noted that the individual may still withdraw his deemed consent any time after the opt-out period has lapsed. The PDPC will put in place safeguards to ensure that organisations work with anonymised data as much as possible, clearly assess and address any potential adverse effects on individuals, and continue to seek express consent for sending direct marketing messages. Sir, in summary, the proposed amendments to the PDPA will strengthen consumer trust with greater accountability for the protection of personal data; it will give greater certainty for organisations to use data for legitimate business purposes with the requisite safeguards; and it will ultimately enhance Singapore’s status as an important node in the global network of data flows and digital transactions. Sir, I beg to move. [(proc text) Question proposed. (proc text)] 3.28 pm”
“Recognising this commercial reality, Part 5 of the new First Schedule in clause 31 allows related corporations to collect and disclose personal data among themselves for the same purposes. The Bill provides for additional safeguards for intra-group sharing by requiring related corporations to be bound by a contract, agreement or binding corporate rules to implement and maintain appropriate safeguards for the personal data. The current research exception has also been revised in clause 32 to support commercial research and development that is not immediately directed at productisation, in other words, going upstream. This could apply to research institutes carrying out scientific research and development, educational institutes embarking on social sciences research, and organisations conducting market research to identify and understand potential customer segments. Clause 7 introduces the new section 15A, which expands the consent regime by introducing deemed consent by notification. Under this provision, organisations may notify their customers of the new purpose and provide a reasonable period for them to opt out. Before doing so, organisations must conduct a risk assessment and conclude that the collection, use or disclosure of personal data in this manner will not likely have an adverse effect on the individual. To illustrate, this would be useful for organisations that wish to use the personal data of existing customers for new purposes. For example, a financial institution may want to use voice data as an alternative means to authenticate and verify its customers. With these amendments, the financial institution can notify its customers of the intended use of their voice data, provide a reasonable opt-out period, and a contact number for customers’ queries.”
“Crucially, organisations relying on deemed consent for contractual necessity can only collect, use and disclose personal data where it is reasonably necessary to fulfil the contract with the individual. Clause 31 introduces the First Schedule to the PDPA, which sets out a new exception to consent for these legitimate uses of personal data. To rely on this exception, organisations must conduct an assessment to eliminate or reduce risks associated with the collection, use or disclosure of personal data, and must be satisfied that the overall benefit of doing so outweighs any residual adverse effect on an individual. To ensure transparency, organisations must disclose when they rely on this exception. One of many potential use cases is anomaly detection in payment systems to prevent fraud or money-laundering. The next set of enhancements supports innovation and introduction of new services. The new First and Second Schedules introduced in clauses 31 and 32 make clear that organisations may use personal data for business improvement purposes including: operational efficiency and service improvements; developing or enhancing products or services; and knowing the organisations’ customers. As a safeguard, this exception can be relied upon only for purposes that a reasonable person may consider appropriate in the circumstances and where the purpose cannot be achieved without the use of the personal data. Businesses have asked for this exception to also apply to entities within a group as they may consolidate corporate or administrative functions, or concentrate research and development expertise in a single unit that supports the entire group.”
“The options for direct communications have evolved since the enactment of the PDPA’s DNC provisions and the Spam Control Act’s spam control provisions. For example, instant messaging on mobile devices has become the communication channel of choice for many consumers. With the proposed amendments, organisations can offer consumers a unified experience in managing their subscription to commercial communications. The Bill also recognises the development of an industry of third party DNC checkers, and delineates the responsibilities and obligations of DNC checkers and the organisations that commission them. Sir, the final set of amendments aims to provide organisations greater clarity on the use of personal data. Currently, the PDPA recognises organisations’ need to use personal data for legitimate purposes, and accommodates them through exceptions to the consent requirement, or as deemed consent. For all other purposes, organisations have to obtain consent from the individual. The proposed amendments update, restructure and clarify the lawful purposes recognised as exceptions under the PDPA, and the deemed consent provisions. Let me elaborate how changes to exceptions and deemed consent accommodate modern commercial arrangements and essential purposes such as security, and support business innovation. Multiple layers of contracting and outsourcing are common in modern commercial arrangements. Clause 6 therefore expands deemed consent to cater for scenarios where personal data is passed from an organisation to successive layers of contractors for the organisation to fulfil the contract with its customer.”
“The new section 48O under clause 23 of the Bill updates the current right of private action by a person who suffers loss or damage directly as a result of a breach of the data protection provisions. The right of private action will be extended to organisations and public agencies that suffer direct loss or damage arising from contraventions of the new business-to-business obligations in the Bill. Sir, the third set of amendments confers consumers with greater autonomy over data generated by their use of services and more control over how they receive commercial communications. Under the PDPA, individuals have the right to access their personal data, and request for corrections to be made or a copy to be provided. Clause 14 extends this right by providing for a new Data Portability Obligation, which will enable individuals to request for a copy of their personal data to be transmitted to another organisation. Data portability is expected to spur competition and benefit consumers by encouraging the development of substitute as well as novel services. Sir, though data portability has been introduced in practice in jurisdictions like Australia, California and the EU, it is a relatively new concept in Singapore. The PDPC will therefore work closely with all stakeholders for a phased implementation. Regulations will be issued in the coming months on the categories of data that should be portable and other technical and consumer protection details. Clauses 22 and 41 update both the PDPA and the Spam Control Act to rationalise and harmonise the requirements across all modern digital channels for direct commercial communication with consumers.”
“Clause 37 empowers the PDPC to require the attendance of an individual or employee to give statements and produce documents that are relevant to its investigations. Clause 24 increases the maximum financial penalty for breaches of Parts III to VI, and the new Parts VIA and VIB, to 10% of an organisation’s annual turnover in Singapore or $1 million, whichever is higher. This penalty framework is similar to that in other domestic regulation and legislation, including the Competition Act and the Telecommunications Act. During public consultations, concerns were raised about the higher financial penalties. I would like to assure Members, as well as the broader community, that the PDPC will ensure that financial penalties imposed are proportionate to the severity of the data breach. The Bill also provides for Ministerial discretion to review the effective date for these penalties to commence and we intend for the revised financial penalty cap to take effect no earlier than one year after the Act comes into force. Sir, I also wish to highlight, at this juncture, that I will be moving a Notice of Amendment during the Committee Stage to address a clerical error in clause 24 of the Bill. Clause 23 sets out amendments providing for the enforcement of the Do Not Call or DNC provisions under the same civil administrative regime as the data protection provisions. The new Part IXA of clause 22 also prohibits the use of dictionary attacks and address-harvesting software when sending messages to telephone numbers. Under clause 24, the maximum financial penalty that may be imposed on an organisation is 5% of annual turnover in Singapore or $1 million, whichever is higher, and $200,000 for an individual.”
“The clause provides for defences to the new offences, such as independent testing of anonymisation deployed in information security systems. Also, these offences should not apply in situations where the conduct is solely in the nature of a private dispute, which should continue to be resolved through civil suits or other forms of dispute resolution. Sir, let me now move to the second cluster of amendments, which seeks to enhance the flexibility and effectiveness of the PDPC’s enforcement. Clause 23 introduces section 48L, a statutory scheme under which the PDPC may, in lieu of a full investigation, accept written voluntary undertakings from organisations to remedy breaches and prevent their recurrence. For example, such undertakings may be accepted when organisations with effective monitoring and breach management systems notify the PDPC of a data breach, and undertake in writing to implement their breach management plan. Several jurisdictions, like Australia, Canada and the UK, accept voluntary undertakings as part of their enforcement regimes. The PDPC will exercise this option only if it assesses that it will achieve an outcome similar or superior to a full investigation. For transparency, the undertakings, as well as the PDPC’s decisions and considerations for accepting them, will be made public. In the event of non-compliance, the PDPC may issue a direction requiring the organisation to comply with its undertakings, or initiate investigations. Section 48G of clause 23 empowers the PDPC to establish dispute resolution schemes for the resolution of customer complaints. The PDPC may also direct complainants and organisations to attempt to resolve disputes via mediation, without the need to secure the consent of both parties.”
“To further strengthen organisations’ accountability, clause 13 introduces a system for mandatory notification to the Personal Data Protection Commission, or PDPC, when a data breach occurs. Under this Clause, organisations must notify the PDPC of data breaches that are of significant scale. In addition, organisations must notify both the PDPC and affected individuals when data breaches result, or are likely to result, in significant harm to individuals. This places the onus on organisations to assess the scale and impact of data breaches, ensures they are duly accountable to individuals for the personal data in their care, and empowers individuals to take timely measures to protect themselves if a data breach occurs. Sir, the Bill also incorporates the recommendations of the Public Sector Data Security Review Committee in its report of November 2019. First, clause 3 removes the current exclusion for agents of Government, thereby making clear that all private sector organisations are subject to the PDPA, even when they are acting on behalf of public agencies. Second, the Bill strengthens individual accountability for the egregious mishandling of data. Clause 22 sets out new offences for (a) disclosure of personal data; (b) use of personal data that results in personal gain for the offender or another person, or harm or loss to another person; and (c) re-identification of anonymised information. Related amendments will also be made to the Public Sector (Governance) Act and the Monetary Authority of Singapore Act to align the public and private sector data regimes. While the primary responsibility and liability for breaches of the PDPA rest with organisations, these new offences are aimed at individuals who know that their actions are not authorised or who act recklessly.”
“Consumers must have the confidence that their personal data will be secure and used responsibly, even as they benefit from digital opportunities and data-driven services. Organisations need certainty to harness personal data for legitimate business purposes, with the requisite safeguards and accountability. The proposed amendments to the PDPA seek to strike this balance so as to maximise the potential benefits and minimise the risks of collecting and using personal data. In drafting the Bill, we have studied the data protection practices in jurisdictions like Australia, Canada, the European Union, Hong Kong and New Zealand. The proposed amendments also incorporate valuable feedback received through four public consultation exercises. Sir, I will elaborate on the amendments which aim to: first, strengthen consumer trust through organisational accountability; second, ensure effective enforcement; third, enhance consumer autonomy; and fourth, support data use for innovation. Firstly, to strengthen consumer trust, organisations must undertake responsibility for the personal data in their possession or control. Today, this principle of accountability is implied in sections 11 and 12 of the PDPA. Clause 4 of the Bill inserts a specific reference to accountability at Part III to make the principle explicit and to underscore its centrality. This shift towards an accountability approach is in line with international trends and best practices in data protection laws. It supports interoperability, allowing multi-national corporations to more easily adapt global best practices in Singapore, and minimises compliance costs for Singapore-based companies which are expanding globally.”
“Thank you, Mr Speaker. I beg to move, “That the Bill be now read a Second time”. Sir, the Personal Data Protection Act, or PDPA, was enacted in 2012. Since then, there have been profound changes in the data landscape, most notably in the sheer variety and volume of data that is being generated and its economic significance. The typology of data is diverse – ranging from personal and machine-generated to meta data – with different risk implications. The volume of data is growing at an unprecedented rate. Today, Tera/Peta/Zetta bytes of data – you can pick your prefix – are being generated by ubiquitous Internet-of-Things or IoT devices and sensors, our real and virtual world activities, and smart machines in manufacturing and supply chains. The International Data Corporation estimates that the volume of data that will be created in the next three years will eclipse the total data generated over the past 30 years. Data is also a key economic asset in the digital economy. Data analytics provides valuable insights that inform decisions, generate efficiencies, enhance products and services, and power innovation. It is a critical resource for emerging technologies like artificial intelligence, which hold much transformative potential. Our regulatory architecture must evolve and keep pace with these magnitudinal shifts. For example, we have initiated digital economy Agreements to position Singapore as a key node in the global network of digital flows and transactions. The proposed amendments to the PDPA are another step to ensure our legislative and regulatory regime is fit for purpose for a digital economy with a complex data landscape. Our digital economy must be built on a solid foundation of trust.”
“Built in 1959, the National Archives of Singapore (NAS) building was gazetted for conservation in 2005. The revamp of the NAS building that started in 2017 is the first major one since NAS officially opened at its current site in 1998. The original budget was $37 million and included three categories of work: restoration and building construction works; digital infrastructure; and provision of equipment. The projected cost for the first category, i.e. restoration and building construction works, was $20.53 million. However, the final cost increased by $1.72 million to $22.25 million, after taking into account works to address unanticipated structural safety issues and site conditions. Despite the higher cost for restoration and building construction works, the National Library Board (NLB) kept within the overall budget of $37 million and did not require any additional funding for the project. Notwithstanding this, NLB takes a serious view of the lapses identified by the AGO in its 2019/2020 financial year report. NLB has since completed its internal review of the lapses and has further tightened its procurement and contract management processes.”
“There must also be public awareness and understanding of potential dangers in the online space. That is why the Government and the Media Literacy Council (MLC) have been promoting safe and responsible online behaviour to create a better internet. For example, the MLC's 2020 Better Internet Campaign highlights the need to protect children from online harms and risks arising from the increased time spent online. The campaign also encourages online users to exercise judgment about the content that they come across online. We will continue to build on such efforts.”
“The Infocomm Media Development Authority (IMDA) administers the regulatory regime for broadcast media, including Over-The-Top (OTT) and Video-on-Demand (VOD) streaming services. OTT and VOD service providers are required to adhere to IMDA's Content Code for these services, including rating all content on their services and presenting the rating prominently such that consumers are aware of the programme's rating before deciding to view or purchase it. Under the Code, the programme’s theme and message are important considerations in its classification. Due to the potential impact on the young, programmes with mature themes such as suicide, depending on how it is depicted, are generally classified NC16, M18 or R21. Service providers that offer content rated NC16 or higher must provide parental locks for such content. R21 content may only be offered if it is protected by a reliable age verification mechanism. All R21 content must be locked by default, and accessible only via an R21 Personal Identification Number (PIN). These measures ensure that content provided on streaming services protect the young from unsuitable content, while enabling adults to make informed viewing choices. Should IMDA receive feedback about content on streaming services, IMDA will review the content and, when necessary, engage service providers to rectify inappropriately-rated content. More generally, IMDA also requires Internet Access Service Providers to offer Internet parental control services to its subscribers. Parents may subscribe to such services to manage their children’s access to websites and online services. Given the dynamic and borderless nature of the Internet, it is not possible to block every website with undesirable content. Regulation alone is not enough.”
“NLB takes a serious view of the lapses identified by the AGO in its 2019/2020 financial year report. It has since completed its internal review of the lapses and has further tightened its procurement and contract management processes. Enhancements have been made to the contract variation and project monitoring processes to ensure timely and well-documented approvals for all variation works. NLB has also taken disciplinary action against the staff involved in these lapses.”
“The National Library Board (NLB) is currently piloting the book dispenser at Lot One shopping mall, as a temporary replacement for the Choa Chu Kang Public Library (CCKPL), which is being revamped. With the book dispenser, patrons can borrow from a selection of curated books and collect reserved items. Between its launch on 17 July and 15 September 2020, the book dispenser has generated around 4,200 loans. NLB will review the utilisation and cost effectiveness at the end of this pilot project when CCKPL reopens in 2021, before evaluating whether to deploy the book dispenser more widely. Any further deployment should complement the existing network of 26 public libraries across Singapore, which makes public libraries accessible for most Singaporeans. NLB also runs outreach programmes to bring library books to under-reached and under-privileged groups. In addition, reading corners have been set up in partner spaces such as Community Centres, Senior Activity Centres and Family Service Centres.”
“Since the SG Digital Office (SDO) was established in June this year, it has mobilised 1,000 Digital Ambassadors (DAs) to drive e-payment adoption among stallholders under the 'Hawkers Go Digital' programme, and equip seniors with digital skills under 'Seniors Go Digital'. Through these efforts, more than 7,200 stallholders have signed-up for the SGQR Unified e-Payment solution. Our DAs have also engaged more than 21,500 seniors at the 34 SG Digital Community Hubs at community centres that SDO has set up island-wide. 21 more community hubs will be set up at our libraries in the coming months. There have been good outcomes from SDO’s efforts. In a survey of seniors who completed SDO’s training programmes in July, 95% were satisfied with the training they received, and 80% continued to apply at least one digital skill that they had learnt. We have also seen a 65% increase in SGQR transactions since the launch of Hawkers Go Digital. SDO is also working with partners to amplify its efforts. To support digital skilling of seniors, SDO has partnered with community organisations such as Youth Corps Singapore to support the rollout of digital training at Senior Activity Centres. For businesses and hawkers, SDO has been working closely with grassroot volunteers to reach out to stallholders, and is supporting IMDA and ESG's joint efforts to uplift digitalisation capabilities in the heartlands. SDO will sustain its efforts to support all Singaporeans as Singapore continues its digitalisation journey. We encourage our seniors to visit SDO’s community hubs and engage with our DAs and volunteers, who can help them to go digital.”
“My Ministry and IMDA consider it important for telcos to offer consumers flexibility in service termination. Current service contracts typically include a notice period for service termination, which may vary across telcos. Subscribers are generally not required to notify the telcos on a specific date in order to terminate their services. IMDA has asked the sole telco that used to have this requirement to exercise greater flexibility, and it has complied. Service contracts usually span a minimum period, ranging from three months to two years, during which subscribers may enjoy discounted subscription rates. At the end of the minimum subscription period, telco services roll over automatically to ensure that there is no disruption to access. If the service contracts are not terminated or renewed, consumers may see an increase in subscription rates as they will have to pay the non-discounted rates. Consumers will have the flexibility to renew existing contracts or sign up for new contracts any time after the minimum subscription period ends. Some telcos also offer consumers this flexibility before the end of the minimum subscription period. To safeguard the interest of consumers, IMDA requires telcos to inform subscribers of key contractual obligations upfront, when they sign up for or renew their service contracts. This includes changes to subscription rates after the minimum period.”
“To this end, we established the SG Digital Office (SDO) and mobilised 1,000 Digital Ambassadors to drive e-payment adoption under the Hawkers Go Digital programme and equip seniors with digital skills under the Seniors Go Digital programme. More than 7,600 stallholders now offer the SGQR Unified e-Payment solution, and over 28,000 seniors have been trained. To support home-based learning needs, IMDA enhanced the NEU PC Plus programme, to subsidise a second computer for larger low-income families with school-going children. More than 10,000 households have benefitted in the past nine months; double the 2019 total. An additional 7,000 low-income households and seniors have further benefited from subsidised broadband, devices or mobile data through the Home Access and the Mobile Access for Seniors schemes. These efforts reflect the Government’s strong commitment to support our businesses and Singaporeans to thrive in a digital environment. We will continue to review and refine our efforts, to ensure that all Singaporeans will benefit in our shared digital future.”
“COVID-19 has underscored the imperative for Singapore to digitalise. The Government is committed to support businesses and individuals on their digitalisation journey, no matter their starting point. Since March, digital adoption rates have increased significantly. PayNow NRIC registrations have increased by 410,000, while PayNow mobile registrations have grown by 200,000. About 25,000 enterprises are now registered on the Nationwide E-invoicing Network, up from 1,000 in March 2020. With an enhanced Productivity Solutions Grant (PSG), more than 4,600 SMEs have adopted technologies to enforce public health safety requirements and adapt to remote work. Under the Grow Digital initiative, 1,400 enterprises are tapping into overseas markets through pre-approved e-commerce platforms. Beyond accelerating economy-wide digital transformation in the immediate term, we will invest in innovation to catalyse new products, services and business models. This includes collaborating with academia and industry to strengthen research and development (R&D) outcomes. We will develop capabilities of local enterprises and workers, to be more competitive and create economic value for Singapore, in areas such as data, AI, cybersecurity, immersive media and 5G. The Government will continue to digitise services for convenient citizen access to government services. For example, the recent Primary 1 registration exercise was done fully online. As the Government positions our economy for the future, we are equally committed to ensuring that vulnerable segments, including low-income families, seniors and small businesses, are well supported.”
“The Government is committed to working with companies to create good career progression opportunities for Singaporeans. We urge Singaporeans to likewise invest in themselves and take advantage of these skills training opportunities, so that they can participate in the digital economy, and stay competitive in this dynamic landscape.”
“Digital technology (tech) jobs are in high demand across all sectors of our economy. Over the last three years, tech talent in Singapore has grown by about 10,000 year-on-year. In light of COVID-19, the urgency for companies to digitalise and transform has only accelerated, which will intensify demand for people who can perform these jobs. Notwithstanding the current global economic crisis, net job creation for tech roles remains positive in our economy. In mid-September 2020, there were nearly 10,000 tech-related job postings on WSG’s MyCareersFuture web portal alone. In addition, the Government is partnering industry to create another 6,800 jobs, traineeships and skills opportunities over the course of the year via IMDA’s TechSkills Accelerator (TeSA) and WSG’s SGUnited Jobs and Skills initiatives. Fresh graduates from our Institutes of Higher Learning (IHLs), and aspiring mid-career professionals keen to pursue a tech career, will benefit from these opportunities. Over the longer term, we expect the demand for tech talent to continue outstripping supply. We have made deliberate efforts to widen our tech talent pipeline by expanding our Pre-Employment Training (PET) intake in IHLs and investing in Continuing Education and Training (CET) programmes led by IMDA and WSG. Over the next three years, our PET pipeline from IHLs will generate around 20,000 local tech talent supplemented by at least 6,250 from place-and-train CET programmes, to keep pace with growing demand, in functions such as Digital Marketing, Software Engineering, and Cybersecurity. Of these 6,250 opportunities, IMDA aims to place some 2,500 mid-career professionals aged 40 and above in good tech jobs.”
“The Home Access 3.0 programme was launched in April 2020 and has supported close to 1,500 beneficiaries to date. The speed of broadband provided under Home Access has improved over the years, in response to consumer needs. Earlier this year, the minimum broadband speed offered was raised from 300Mbps to 500Mbps, with no increase in the monthly co-payment for beneficiaries that opt for a broadband-only plan. This is higher than the minimum speed available on the market, and is sufficient to support common daily activities such as internet surfing, video calls, and video streaming. More than 80% of beneficiaries have opted for the minimum broadband speed of 500Mbbps. Home Access also offers a 1Gbps option for households that prefer higher speed broadband. We will continue to review the Home Access scheme regularly, to ensure that its offerings keep pace with the needs of citizens.”
“The Government is committed to equipping all Singaporeans with a baseline of affordable digital access. Compared to deploying Wireless@SG at HDB rental blocks, the Home Access scheme is a more targeted and practical solution that provides internet connectivity to lower-income households in their homes. Wireless@SG supplements this with free out-of-home connectivity at public sites with high human traffic, such as transport nodes and community facilities such as community centres, libraries, and hawker centres. Under the Home Access scheme, all households residing in HDB rental units are eligible for a heavily subsidised broadband subscription at $9/month, which is about 70% less than comparable commercial plans. For households with ComCare recipients, the out-of-pocket expense could be even lower, at $6/month. Broadband is also provided for free to households with school-going children or persons with disabilities who are beneficiaries of the NEU PC Plus programme. Low-income households can apply to IMDA for these schemes. Low-income households may approach MSF's Social Service Offices (SSOs) to apply for ComCare. If they require home broadband, the SSOs can help with their application for the Home Access scheme and, if needed, provide additional financial assistance for a basic broadband plan.”
“Singapore aims to leverage on the opportunities and benefits of digital technologies, while keeping our communications infrastructure and computer networks secure and resilient. The Government is committed to working with partners, including overseas government counterparts, and technology and service providers in both bilateral and multilateral settings, to ensure that our infrastructure is reliable, safe and world-class. We closely monitor all initiatives, including the US Clean Networks programme. Our regulatory and security agencies will continue to work with trusted partners and in relevant multilateral platforms to enhance the security, diversity and resilience of our network systems.”
“Stallholders may also approach NETS personnel or SDO's Digital Ambassadors on the ground should they need further assistance.”
“In recent years, the Government has made a concerted push to drive the adoption of cashless payment solutions by merchants. We have made significant strides in developing a single, interoperable e-payment solution which unifies different payment schemes under a single Singapore Quick Response (SGQR) label, making it easy, convenient and secure for users. There are understandable concerns about fraud, errors and security threats behind cashless payment solutions, among merchants as well as consumers. Beyond existing verification measures and safeguards within payment systems, merchants and consumers are encouraged to exercise vigilance to combat such scams, keep devices secure with the latest security patches, and maintain their password secrecy. Recently, concerns were raised that merchants unfamiliar with cashless payments may face greater risk of payment scams. In June 2020, IMDA launched the Hawkers Go Digital programme, as part of a nationwide effort to help micro-enterprises like stallholders at NEA hawker centres, HDB coffeeshops and wet markets and JTC industrial canteens, to accelerate the adoption of the unified SGQR solution. We also established the SG Digital Office (SDO), mobilising 1,000 Digital Ambassadors to work together with NETS to engage and guide stallholders. Along with the deployment of the SGQR code, NETS will also help stallholders install the NETSBiz App on their digital device and teach them how to verify successful payment transactions in real-time. This App provides real-time notifications of successful payment transactions in English or Mandarin, has a voice notification capability in English and Mandarin, and allows stallholders to view their transaction histories.”
“Singapore’s digital infrastructure has been able to accommodate the rise in Internet traffic arising from COVID-19. Traffic volume remains well within each telecom operator’s network capacity, with a healthy buffer of at least 30%. IMDA has also put in place measures to minimise the risk of network disruptions, and ensure a speedy recovery if such disruptions were to occur. For example, IMDA requires key telecom operators to conduct regular audits to ensure that the resilience of their networks is on par with international best practices. IMDA also requires telecom operators to comply with requirements in areas such as redundancy and diversity. The Cyber Security Agency of Singapore (CSA) also requires telecom operators that own Critical Information Infrastructure to adhere to mandatory cybersecurity requirements prescribed under the Cybersecurity Act. My Ministry and IMDA continue to enhance our digital infrastructure for the next bound of growth in our digital economy. For example, we are working with our telecom operators to deploy world-class nationwide 5G networks that are secure and resilient. In parallel, the Government is also taking steps to better protect Singaporeans and our enterprises against cyber threats. CSA will launch the Safer Cyberspace Masterplan later this year, to secure our core digital infrastructure and safeguard our cyberspace. Earlier in March, CSA also released an advisory that provides tips for individuals to stay cyber-safe while telecommuting; for example, by using a secure Wi-Fi network, and sending important and sensitive information over a Virtual Private Network.”
“The Government is committed to building an inclusive digital society, where all Singaporeans, including our seniors, are empowered with digital skills and have the means to access digital platforms. Under IMDA’s Home Access (HA) programme, eligible low-income households, including those with senior citizens, can enjoy two years of subsidised home broadband services, and the option to own one subsidised device per household. The fees for broadband installation, as well as fees for installing the first termination point, are waived for beneficiaries. The Home Access programme has benefitted many seniors, with 75% of current beneficiaries comprising households with seniors aged 60 and above. In this year alone, nearly 4,000 seniors have benefitted from the Home Access scheme. IMDA also recently introduced subsidies for low-income seniors to obtain personal smartphones and mobile plans under the Mobile Access for Seniors (MAS) scheme. The scheme supports low-income seniors with on-the-go connectivity, and complements the SG Digital Office's efforts to raise the digital skills of seniors. 800 seniors have benefited from this scheme since its launch in July. Our efforts at ensuring digital inclusion of seniors have been well-received. To-date, 16,000 seniors have taken part in the SG Digital Office's digital skilling initiatives. Many of the seniors, some of whom I recently met at Teck Ghee Community Centre, are eager to learn and possess a can-do spirit. With the support of our corporate and community partners, Digital Ambassadors and volunteers, we will continue our efforts to ensure that seniors are not left behind in Singapore's digitalisation journey.”
“Mr Speaker, I think Minister Ong has made the point very clear. I just want to go back to a point I made in my speech. As Parliamentarians, we must be not just the Voice of the People. That is important, which I think the Member has been articulating – the concerns of the people that he has spoken to. But we must also be the Voice of Reason. Do not take that lightly. Because what we say cannot be unsaid. It is there for the record, for the future and everyone. Singaporeans, new citizens or Singapore born. Others who are here will all be looking at this. I think we in this House as elected representatives must hold ourselves up to a higher standard. If we do not, then I think we fail our duties as Members of Parliament and I think we ultimately do a disservice to Singaporeans.”
“So, the question I would put to Mr Leong is after this debate and all the information that has been shared, does he still lament that DBS does not have a homegrown CEO? Does he acknowledge that as one example – and I am only talking about DBS because he raised it – whether he acknowledges that, in fact, much has been done in the organisation. There are, in fact, a large number of Singaporeans at the senior levels. In fact, this is a clarification made by one of our colleagues Derrick Goh. Unfortunately, the Member was not in the Chamber when the clarification was made.”
“Mr Speaker, I thank the NCMP for his clarification. Let me start by saying this. The process of reviewing and evolving our policy predates the Fourteenth Parliament, predates the Thirteenth Parliament. It is, in fact, an on-going venture and if you look at any one of our policies – and the foreign worker policy, the manpower policy is no exception to this – it is an evolutionary effort because it has to respond to the economic environment, the population's needs and concerns; and we have to then adapt and move along. Indeed, in this Parliament, if the Member had heard the detailed exposition by the Minister for Manpower, for example, we are taking even further measures. And the Prime Minister has already spelt out that the Government will look at various policies in detail, but never compromising on the fundamentals and always keeping our eye on the long-term interests of Singaporeans. So, the issue is not about process. The process can continue. And, indeed, in my comment, I have made the point that we can always advocate the case for doing more for Singaporeans and I have no problems with that. The issue is when we lament that a Singaporean occupying a certain position is somehow not homegrown. Then, I think we really have to ask ourselves the question: as Parliamentarians, as elected representatives, what is the message we are sending to our citizens? I am not sure what the Members means by homegrown, but all our citizens but also, in particular, to those who have, as I said, out of conviction, chosen to be Singaporeans, given up their home citizenship to take up Singapore Citizenship. And also, what does it say to those who are the spouses, the children of Singapore Citizens who have become naturalised Singaporeans?”