Singapore: PDPC accepts undertaking from MindChamps
The Personal Data Protection Commission ('PDPC') announced, on 21 September 2021, that it had accepted an undertaking from MindChamps PreSchool Limited, regarding its compliance with the Personal Data Protection Act of 2012 (No. 26 of 2012) ('PDPA') following a data breach in 2020. In particular, the undertaking states that a dataset containing the personal data of the users of MindChamps mobile application was publicly accessible via an internet link and included the personal data of approximately 6,521 users. In addition, the undertaking highlights the birth certificate numbers of 607 minors were also at risk of unauthorised disclosure.
Following the incident, the undertaking confirms that MindChamps PreSchool took the following remedial actions:
- engaged an external IT consultant to determine the cause of the incident;
- performed a password reset for all the user accounts of its mobile application; and
- migrated all users to a newly designed mobile application.
Furthermore, the PDPC outlined that it had reviewed the matter and determined that MindChamps has complied with the terms of the Undertaking.