Note

What PDPA has to do with a control-application log

Mei Ling Tan

Bound documents on a desk used for a formal review

The Personal Data Protection Act 2010 is not an industrial-control statute. It still shows up in our work because control applications keep names.

A good command log says who asked for a setpoint, from which station, and whether it was accepted. That “who” is a person. Retention, access, and transfer of that log need a sentence in the site’s privacy notice and a limit on who in the vendor organisation can export it.

We have seen vendors pull full operator histories to a regional support centre to debug a trend. That may be legitimate processing. It should not be a surprise to the people whose names are in the file, and it should not travel with the process values to a marketing analytics tool.

Our audit does not replace legal advice. We will flag where a control application exports identity-bearing logs, where those exports are unencrypted, and where there is no deletion path when a staff member leaves. Operations can then take that list to counsel or to the data protection officer rather than discovering it during a subject-access request.

Do not “solve” PDPA by removing names from the log. An anonymous control log fails the incident review. Solve it by collecting the minimum, keeping it for a stated period, and restricting who can read it.

All notes