Oral Answer by Senior Minister of State for Law Mr Murali Pillai on the Singapore Land Authority Data Security Incident
5 August 2026 Posted in Parliamentary speeches and responses
Name and Constituency of Member of Parliament
Mr Low Wu Yang Andre (Non-Constituency Member of Parliament)
Question
To ask the Minister for Law regarding unauthorised access to a vendor-managed Singapore Land Authority test environment containing real personal data of about 70,000 individuals (a) how did the data enter and remain in a dataset intended for mock or anonymised data; (b) when was the environment last audited against Government data-security requirements; and (c) what contractual action will be considered after investigations.on.
Oral Answer:
1. Mr Speaker, Sir, the data security incident involved unauthorised access to a data set in a development and systems-integration testing cloud environment managed by IBM. IBM was the vendor appointed to support and maintain SLA’s Singapore Titles Automated Registration System (STARS) and eLodgment System (ELS). The affected environment was separate from SLA’s live operational systems, which were not affected.
2. The data set was created in 1998 for major system tests and updated periodically over the subsequent years. Although the data set was intended to contain only mock and anonymised testing data based on property ownership and lodgement records, SLA subsequently uncovered that the data set contained personal information which was not anonymised. STARS and ELS are subject to regular audits, with the most recent audit carried out in 2025.
3. The appropriate contractual action will be determined after the full facts and respective responsibilities have been established. SLA is investigating the matter.