PDPA Section 37 and Cybersecurity

PDPA Section 37 and Cybersecurity

What Technical Measures Should Organisations Have?

PDPA is not only about privacy documents. It also requires practical security measures that help protect personal data from unauthorised access, use, alteration, or disclosure.

For IT and security teams, the real question is:

Does your organisation have enough technical control to reduce real data security risk?

PDPA Section 37 requires Data Controllers to provide appropriate security measures and review those measures when necessary or when technology changes.

In practice, this should not stop at policy writing.

It should become a set of measurable cybersecurity controls.


Technical Measures Organisations Should Consider

1. Access Control and Least Privilege

Organisations should define who can access personal data and limit access to what is necessary for each role.

Key controls include:

  • Role-based access control
  • Least privilege
  • Privileged access management
  • Periodic access review
  • Timely removal of access for leavers or role changes

2. Identity, Authentication, and MFA

Strong identity control is one of the first layers of personal data protection.

Systems handling sensitive or personal data should include:

  • Strong authentication
  • Multi-factor authentication
  • Password policy enforcement
  • Service account and admin account management
  • Protection against credential reuse

3. Logging and Audit Trails

If something goes wrong, the organisation needs to know who accessed what, when, and what changed.

Important controls include:

  • Access logs
  • Admin activity logs
  • Data modification logs
  • Audit trails for access, changes, and deletion
  • Log retention based on risk

4. Vulnerability Management

Personal data is often exposed through vulnerabilities the organisation did not know existed.

Security programmes should include:

  • Vulnerability Assessment
  • Web Application Testing
  • API Security Testing
  • Network Security Testing
  • Cloud Configuration Assessment
  • Retesting after remediation

5. Secure Configuration and Hardening

Misconfigured systems can create direct paths to personal data exposure.

Organisations should review:

  • Server hardening
  • Database access control
  • Cloud IAM settings
  • Public storage exposure
  • Backup and encryption settings
  • Firewall rules and network segmentation

6. Monitoring and Incident Response

Prevention alone is not enough.

Organisations need the ability to detect, contain, and recover from security incidents.

Key measures include:

  • Security monitoring
  • Alerts for abnormal behaviour
  • Incident Response process
  • Data breach escalation workflow
  • Backup and recovery plan
  • Tabletop or cyber drill exercises

How SecStrike Helps

SecStrike helps organisations turn cybersecurity requirements into practical, testable controls.

Relevant services include:

  • Vulnerability Assessment to identify weaknesses across systems, networks, and applications
  • Penetration Testing to validate real exploitability
  • Web Application and API Testing for systems processing customer data
  • Security Configuration Assessment for hardening, IAM, logging, and security baselines
  • Incident Response and Ransomware Crisis Response for real-world incidents
  • PTX Platform for secure report delivery, real-time dashboards, remediation tracking, and retest tracking

The goal is not only to “comply with PDPA.”

The goal is to understand where sensitive data is exposed, which vulnerabilities create real risk, and what your team should fix first.


Final Thought

PDPA Section 37 makes clear that organisations need appropriate security measures.

From a cybersecurity perspective, those measures should help answer:

  • Who can access personal data?
  • Which systems are vulnerable?
  • Can access and changes be traced?
  • Can the organisation detect, contain, and recover from an incident?


Want to understand whether your technical controls are strong enough to reduce real data security risk?

Book a free scoping call with SecStrike
www.secstrike.ai


2 thoughts on “PDPA Section 37 and Cybersecurity”

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top