DisclosureLens
SINGAPOREUnknownLow

Australian International School Pte Ltd

bd_466e5df62940092f · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Sep 25, 2024

To disclose

Affected

Not disclosed

Confidence

90%
Full breach record for Australian International School Pte Ltd

Regulator's decision — not a breach notification

This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.

Background Australian International School Pte Ltd (the “ Organisation ”) notified the Personal Data Protection Commission (the “ Commission ”) on 14 May 2024 of a personal data breach involving a former employee who had improperly accessed and retained documents containing personal data (the “ Incident ”) despite leaving the Organisation’s employment. Investigations revealed that the Organisation had inadvertently failed to properly terminate the former employee’s user account to the Organisation’s system after the last working day on 8 April 2024. The former employee was able to access and download documents containing the personal data from the Organisation’s shared folders on 21 April 2024 and was found to have kept a copy of an Excel spreadsheet containing student information in his/her personal email account. The aforementioned documents contained a combination of personal data belonging to 6,222 of the Organisation’s students. The types of personal data affected included the name, date of birth (for 4 students), NRIC/FIN/Birth Cert number (for 3 students), school grades, type of visa holders, passport country information, email address (for 3 individuals), and for 1 student, the immunisation record and psychological assessment. The names of 6,225 parents were also affected. Upon discovery of the Incident, the Organisation took prompt remedial actions including obtaining a statutory declaration from the former employee that he/she had deleted and not retained any of the documents. The Organisation also launched a new centralised reporting project dashboard in its school management system to reduce unnecessary data transfers or downloads. The Organisation also conducted a review of user accounts in its system to ensure access rights were appropriately segregated according to the relevant roles of its current employees. Voluntary Undertaking Having considered the

Incident timeline — partial

? — ?

Breach window unknown

Sep 25, 2024

Filed

No linked breach filing · watching

Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Source ceiling

  • outcome + obligations
  • fine (SGD) and affected count where a grounds document states them
  • discovery date
  • notification clock

See the underlying breach notice, if any.