This page was machine-translated and may differ from the original. View original

Dell EMC Announces 'Data Risk Management Barometer' Comparative of Asia-Pacific Regions

Google 우선 소스Published2018.03.27 11:38
Australia has strict regulations with penalties of up to approximately 1.4 billion won for violations of personal data protection laws.
Strong data governance and security strategies must be applied to respond to increasingly stringent regulations.


IDC released the research report 'Data Risk Management Barometer' at the request of Dell EMC. The report covers a survey of personal data protection regulations and laws related to data sovereignty and business continuity in 14 countries in the Asia-Pacific region, including Korea, Australia, China, Japan, Singapore, and India.

According to the report, while most countries in the Asia-Pacific region have established laws involving punitive damages for data protection, significant differences in regulatory levels across nations require caution from companies expanding overseas. Among the 14 countries in the Asia-Pacific region, Singapore and Australia have the strictest regulations regarding personal data protection; in Singapore, violations of personal data protection laws can result in fines of up to 1 million Singapore dollars (approximately 810 million KRW), while in Australia, fines can reach up to 1.7 million Australian dollars (approximately 1.4 billion KRW).
While Australia has the highest absolute amount, Singapore ranks slightly higher than Australia when measured by the 'Data Risk Management Score,' which calculates each country's fines as a ratio to its GDP. Based on this metric, Hong Kong (up to 1 million Hong Kong dollars, approximately 130 million won) and Indonesia (5 billion Indonesian Rupiah, approximately 390 million won) were assessed as having the next most relatively strict regulations. South Korea, which imposes a maximum fine of 50 million won, ranked 9th based on the metric, placing it in the lower-middle tier among the 14 countries. In the case of Japan, the maximum fine is only about 10 million won, which is the lowest level compared to India (about 8 million won) and Thailand (no relevant laws) based on the scale.



It was found that most surveyed countries have not enacted separate laws regarding business continuity, which require ensuring data availability and the ability to effectively recover data. To date, most countries have established these as non-binding guidelines or recommendations, which are primarily managed by financial regulatory bodies that oversee banks and securities firms.

Regarding country-specific characteristics, Australia and Singapore not only have strict regulations on data protection but also demonstrate a high level of interest in related technologies and policies, requiring special caution from multinational corporations entering these markets. In the case of Australia, legislation is scheduled to be enacted in 2018 requiring notification to affected parties and the implementation of countermeasures in the event of a data breach. Furthermore, all overseas contracts involving data sovereignty issues must be reported to the Australian Prudential Regulation Authority, and notification within 24 hours is mandatory in the event of incidents or accidents that could affect the financial soundness of companies and institutions. In Singapore, violations of personal data protection can result in not only fines but also imprisonment of up to 12 months. The Monetary Authority of Singapore mandates that financial institutions report business continuity-related incidents, such as data center infrastructure failures, within one hour of discovery, and legislation is in place requiring banks to set a Recovery Time Objective (RTO) of four hours or less for each critical system.

In the case of Japan, which ranked at the bottom in terms of data risk management standards, violating data protection laws can result in a fine of 1 million yen (approximately 10 million won) or imprisonment for up to two years, and data sovereignty laws, like those in Korea, only require the consent of individual data owners.

In this report, Dell EMC identified three key areas for response strategies to prevent data breaches: cybersecurity, privacy, and business continuity. First, regarding security, it cited ensuring data is safely preserved from threats such as hacking; second, protecting personal information by strictly managing data access; and third, achieving near-zero Recovery Point Objectives (RPO) and Recovery Time Objectives (RTO) through advanced data recovery and backup capabilities as major challenges for enterprises. Furthermore, it emphasized air-gap solutions equipped with faster recovery capabilities to protect businesses from cyber attacks or ransomware.

"While data management regulations vary significantly by country, they will become more numerous and stricter in the future," said Dmitry Chen, Vice President and COO of Dell EMC Asia Pacific and Japan. "Therefore, multinational corporations operating in overseas markets must pay closer attention to data management, governance, and security, such as establishing a secure IT environment and optimizing infrastructure," he added.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
김학준 기자