DisclosureLens
SINGAPOREUnknownLow

JWEN Marketing Pte Ltd

bd_4877f6380f1c23ed · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Oct 2, 2025

To disclose

Affected

Not disclosed

Confidence

90%
Full breach record for JWEN Marketing Pte Ltd

Regulator's decision — not a breach notification

This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.

Background On 25 March 2025, the Personal Data Protection Commission (the “ Commission ”) received a complaint about the handling of jobseekers’ personal data by JWEN Marketing Pte. Ltd. (the “ Organisation ”) in ways not complying with the Personal Data Protection Act (“PDPA”). The Organisation places job listings on behalf of hiring companies and refers jobseekers to the hiring companies. There was no evidence of collection, use or disclosure of personal data without consent or without notifying jobseekers of the purpose as: (a) The Organisation had obtained unambiguous consent from individuals who submitted applications directly for job listings posted online by the Organisation, for purposes limited to being contacted by the Organisation (on behalf of the hiring company) regarding that specific job listing; (b) While the Organisation had proactively contacted jobseekers, this was after obtaining their resumes from publicly available sources, to inform them about open job position(s). In addition, the Organisation had a process in place when contacting the jobseekers, to inform them on the purpose of using their resumes to arrange interviews, and obtaining confirmation from the jobseeker before proceeding. However, t he Organisation was lacklustre in its cybersecurity and data protection practices. At the time of the complaint, it had not implemented any policies or measures to comply with its obligations under sections 11, 12 and 24 of the PDPA, including not having designated a data protection officer, the lack of documented internal and external data protection policies and no process to receive PDPA-related complaints. Voluntary Undertakings Having considered the circumstances of the case and the lack of knowledge by the Organisation in cybersecurity and data protection practices, the Commission accepted a voluntary undertaking (the “ Undertaking ”), which was

Incident timeline — partial

? — ?

Breach window unknown

Oct 2, 2025

Filed

No linked breach filing · watching

Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Source ceiling

  • outcome + obligations
  • fine (SGD) and affected count where a grounds document states them
  • discovery date
  • notification clock

See the underlying breach notice, if any.