Australian International School Pte Ltd
bd_466e5df62940092f · schema v1 · pii pii-v1
Full breach record for Australian International School Pte Ltd →Regulator's decision — not a breach notification
This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.
Background Australian International School Pte Ltd (the “ Organisation ”) notified the Personal Data Protection Commission (the “ Commission ”) on 14 May 2024 of a personal data breach involving a former employee who had improperly accessed and retained documents containing personal data (the “ Incident ”) despite leaving the Organisation’s employment. Investigations revealed that the Organisation had inadvertently failed to properly terminate the former employee’s user account to the Organisation’s system after the last working day on 8 April 2024. The former employee was able to access and download documents containing the personal data from the Organisation’s shared folders on 21 April 2024 and was found to have kept a copy of an Excel spreadsheet containing student information in his/her personal email account. The aforementioned documents contained a combination of personal data belonging to 6,222 of the Organisation’s students. The types of personal data affected included the name, date of birth (for 4 students), NRIC/FIN/Birth Cert number (for 3 students), school grades, type of visa holders, passport country information, email address (for 3 individuals), and for 1 student, the immunisation record and psychological assessment. The names of 6,225 parents were also affected. Upon discovery of the Incident, the Organisation took prompt remedial actions including obtaining a statutory declaration from the former employee that he/she had deleted and not retained any of the documents. The Organisation also launched a new centralised reporting project dashboard in its school management system to reduce unnecessary data transfers or downloads. The Organisation also conducted a review of user accounts in its system to ensure access rights were appropriately segregated according to the relevant roles of its current employees. Voluntary Undertaking Having considered the
P pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Sep 25, 2024
Filed
—
No linked breach filing · watching
Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- outcome + obligations
- fine (SGD) and affected count where a grounds document states them
- discovery date
- notification clock
See the underlying breach notice, if any.