DisclosureLens
SINGAPOREUnknownLow

Cantley LifeCare Pte Ltd

bd_587bffbb4fae752f · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Aug 2, 2024

To disclose

Affected

Not disclosed

Confidence

90%
Full breach record for Cantley LifeCare Pte Ltd

Regulator's decision — not a breach notification

This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.

Background O n 30 January 2024, the Personal Data Protection Commission (the “ Commission ”) was notified by a complainant of an unauthorised disclosure of her personal data by Cantley LifeCare Pte. Ltd. (the “ Organisation ”) on its website. The complainant had discovered the unauthorised disclosure after conducting a Google search of her own email address (the “ Incident ”). The Commission promptly conducted investigations and on 2 February 2024, the Organisation deleted the file containing its customers’ personal data which was publicly accessible on its website. The file was inadvertently placed in a public folder on the Organisation’s website following a website migration exercise in April 2021. The personal data of 1,130 individuals, including their names, phone numbers, email addresses, addresses and transaction information, was affected. The Organisation was found to be lacklustre in its cybersecurity and data protection practices. First, the Organisation engaged a freelancer for the website migration in April 2021 and did not emphasise the need for personal data protection in this exercise. Second, the Organisation failed to conduct periodic security reviews that could have detected the publicly accessible file on its website. Third, the Organisation also did not have any IT security-related policies such as backup policies, audits and access control policies. In addition, the Organisation did not have any personal data protection policies and internal guidelines for its employees that could have provided guidance when responding to a personal data breach. Voluntary Undertaking Having considered the circumstances of the case and the lack of knowledge by the Organisation in cybersecurity and data protection practices, the Commission accepted a voluntary undertaking (the “ Undertaking ”), which was executed on 1 April 2024, from the Organisation to engage an ex

Incident timeline — partial

? — ?

Breach window unknown

Aug 2, 2024

Filed

No linked breach filing · watching

Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Source ceiling

  • outcome + obligations
  • fine (SGD) and affected count where a grounds document states them
  • discovery date
  • notification clock

See the underlying breach notice, if any.