Jade E-Services Singapore Pte Ltd
ent_ac5b693a163e54ef0dc420e2
Disclosures
2
Singapore PDPC · 1 jurisdiction
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
456,868
nationwide · Singapore PDPC SG
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Jade E-Services Singapore Pte Ltd
- Normalized
- jade e services singapore pte— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (2)newest first
- SINGAPORESingapore PDPCas victim2022-04-21
Background The Personal Data Protection Commission (the “Commission”) received a data breach notification on 11 September 2021 from Jade E-Services Singapore Pte. Ltd. (“Organisation”) following an incident where a marketing email was wrongly sent, as a result of an employee’s lapse. The marketing email was sent to the email addresses belonging to 456,868 individuals who had withdrew their consent to receive such marketing emails. The recipients included 165 individuals who had previously requested for their account to be terminated. It was established that the Organisation lacked sufficiently robust processes to identify and correct any human error by their employees in the use of its system. The Organisation also did not have sufficiently robust retention policies. This resulted in the retention of email addresses of individuals who had unsubscribed to the Organisation’s newsletter and did not have any account with the Organisation. Remedial Actions After the incident, as part of a remediation plan, the Organisation: (a) immediately stopped any further sending of automated emails that had yet to be processed; (b) corrected the system settings; (c) implemented an additional layer of approval for all automated emails that have been modified by an employee to prevent erroneous changes; (d) sent apology emails to individuals who had received the erroneous emails; and (e) issued social media communications to inform all customers of the incident. Undertaking Having considered the circumstances of the case, including the remedial steps taken by the Organisation to improve its personal data protection practices, the Commission accepted an undertaking from the Organisation to improve its compliance with the Personal Data Protection Act 2012. The undertaking was executed on 3 December 2021 (the “Undertaking”). The Undertaking provided that the Organisation was to complete th
- SINGAPORESingapore PDPCas victim2018-09-11
A warning was issued to Jade E-Services for failing to make reasonable security arrangements to prevent webpages containing customers’ personal data from being cached and displayed to other customers. Click here to find out more.