Singapore’s Register of Controllers is a regulatory framework introduced by the Singaporean authorities to enhance data protection and enhance the transparency in data processing among organizations operating within the country’s jurisdiction. Every organization, especially those involved in processing personal data, is mandatorily required to maintain this register, otherwise, they shall face severe repercussions for non-compliance.
A controller is identified as an individual or an entity that determines the purposes and means of processing the personal data in question. When a controller relies on another individual or entity (referred as a processor) to process its personal data on its behalf, the controller, and processor shares joint responsibility with respect to safeguarding the relevant data. Notably, failure to maintain or accurately maintain such register can carry serious legal as well as ethical consequences.
To avoid running afoul the legal framework requires every controller establish, implement appropriate, and adequate security measures regarding personal data so that they achieve appropriate level effectiveness in their compliance efforts. Security measures encompass such safeguards as policies and procedures detailing access control limits; ensuring backup of critical servers and storage as well as access logs for users.