Singapore · Data Protection

PDPA begins
from data card

We translate customer journey, HR, vendors, cloud and marketing into purposes, roles, safeguards, retention and managed incident response.

DPOappointment and public business contact
Purposenotification, consent or exception
Comparableoverseas transfer protection
3 daysdeadline PDPC notice after determination

01

Personal data is determined by the possibility of identification

PDPA applies to data about an identifiable individual, collected, used or disclosed organization. Customer, employee, UBO, director, website/device and support data are included in the scope according to the facts. Business contact information and public data have special rules, but should not be automatically excluded without verification.

02

Organization and data intermediary have different responsibilities

The Organization defines the purposes and means and is responsible for a full set of obligations. Data intermediary processes data on behalf of another and directly bears primarily protection, retention and breach-notification duties, but the contract distributes operational controls and assistance to the principal organization.

Organisation
Purpose, notice, consent/exception, rights, security and transfer
Data intermediary
Processing on behalf; security, retention and incident notice
DPO
Governance owner and public business contact
Business owner
Purpose, necessity and access approval
Vendor
Contract, controls, sub-processing and evidence

03

Consent is not the only basis, but also not a decorative one

Collection, use and disclosure must comply with a notified reasonable purpose and applicable consent or exception. Deemed consent, legitimate interests and business improvement are used only after conditions and assessment; The withdrawal process is associated with consequences for the service.

04

Privacy notice follows customer journey

Notice explains categories, purposes, recipients, overseas transfers, retention, rights and DPO contact before the corresponding processing. Cookie banner, onboarding form, KYC, HR notice and marketing preference must not contradict the contract or actual integrations.

One general text does not replace purpose inventory

Each data flow must have an owner, purpose, legal route, recipients, retention and security classification.

05

Reasonable security depends on risk

Identity

MFA, least privilege, joiner/mover/leaver and admin controls.

Data

Classification, encryption, masking and secure deletion.

Systems

Patching, logging, testing, backup and recovery.

People

Training, confidentiality, phishing and incident escalation.

06

Cloud and processor are registered before data transfer

Due diligence checks hosting locations, certifications, access, encryption, incident history, sub-processors and exit. Contract fixes instructions, security, confidentiality, breach timing, audit evidence, deletion/return and overseas-transfer protection.

07

Overseas transfer requires comparable protection

The company determines the destination, recipient and onward transfers, then uses a legally recognized mechanism and contractual/organisational safeguards that provide protection comparable to PDPA. Group company abroad is not an automatic exception.

Map
Country, recipient, dataset and purpose
Mechanism
Contract or other permitted basis under regulations
Security
Access, encryption, localization and incident route
Onward transfer
Limiting sub-processors and further recipients
Evidence
Assessment, contract and periodic review

08

Access and correction requests require a route

The Organization provides access to personal data and usage/disclosure information for the applicable period, corrects errors and omissions and takes into account exceptions, third-party data and identity verification. The retention schedule stops storage when the data is no longer needed for a legal or business purpose.

09

First contain, then determine and notify

The organization stops exposure, stores evidence, identifies affected data/individuals and assesses significant harm or scale. If the breach is notifiable, PDPC is notified as soon as practicable and no later than 3 calendar days after determination; affected individuals - as soon as practical, when required.

  1. 01
    Contain

    Credentials, systems, vendor and exfiltration path.

  2. 02
    Assess

    Data, people, harm, scale and ongoing risk.

  3. 03
    Notify

    PDPC, individuals, partners and other regulators.

  4. 04
    Remediate

    Root cause, controls, monitoring and documented lessons.

10

PDPA operating file

  1. 01

    Data inventory, systems, vendors, countries and owners.

  2. 02

    Purpose/consent/exception matrix and notices.

  3. 03

    Retention, access, transfer and vendor controls.

  4. 04

    DPO, request workflow and staff training.

  5. 05

    Breach playbook and tabletop test at least according to the risk cycle.

Official base

PDPC: obligations, transfers and breaches

01

PDPC — Data Protection Obligations

The main responsibilities of organizations under the PDPA.

Open source
02

PDPC — Key Concepts Guidelines

Consent, purpose, access, security, transfer and accountability.

Open source
03

PDPC — Organisations and Data Intermediaries

Distribution of responsibilities between controller-like organization and processor-like intermediary.

Open source
04

PDPC — Reporting a Data Breach

Assessment and notification to PDPC within three days.

Open source
05

PDPC — Transfer Limitation

Comparable protection for overseas transfer.

Open source

Data Protection

Let's put together a PDPA program for the product

Data map, notices, vendors, transfers and incident response.

Discuss data
WAWhatsAppTGTelegram