Data Protection

Data Processing Addendum

Engaging a processor does not transfer the obligation. The organisation that determines what happens to the data remains responsible under the Act, and is the one that must notify the Commission if the vendor is breached. This addendum is the control that makes that responsibility manageable — particularly the requirement that the vendor tell you **immediately**.

Download as Word7 pages21 KBFree
[HEADER — replace with your organisation’s letterhead, if used]

Data Processing Addendum

Where a vendor processes personal data on our behalf

Engaging a processor does not transfer the obligation. The organisation that determines what happens to the data remains responsible under the Act, and is the one that must notify the Commission if the vendor is breached. This addendum is the control that makes that responsibility manageable — particularly the requirement that the vendor tell you immediately.

THIS ADDENDUM forms part of the agreement dated [DATE] between:

(1)[COMPANY NAME], UEN [UEN] (the "Organisation"); and

(2)[VENDOR NAME], [registration details] (the "Processor").

Where this Addendum conflicts with the agreement, this Addendum prevails in respect of personal data.

1. Definitions and Scope

1.1"Personal Data" has the meaning given in the Personal Data Protection Act 2012. "Act" means that Act and any subsidiary legislation. "Commission" means the Personal Data Protection Commission.

1.2The Processor processes Personal Data on behalf of and for the purposes of the Organisation. The Organisation determines the purposes and means of processing.

1.3The details of the processing are set out in Schedule 1.

1.4Where the Processor determines its own purposes for any Personal Data, it acts as an organisation in its own right for that processing and bears its own obligations under the Act.

2. Processor Obligations

2.1The Processor shall process Personal Data only on the documented instructions of the Organisation, and only for the purposes in Schedule 1.

2.2The Processor shall not use Personal Data for its own purposes, including to develop, train or improve its own products or models, or for analytics, benchmarking or marketing, without the Organisation’s prior written consent.

2.3The Processor shall not sell, licence or otherwise disclose Personal Data to any third party except as permitted by this Addendum or required by law. Where disclosure is required by law, the Processor shall notify the Organisation first unless prohibited from doing so.

2.4The Processor shall make reasonable security arrangements to protect Personal Data against unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks, at least to the standard in Schedule 2.

2.5The Processor shall ensure that personnel with access to Personal Data are subject to confidentiality obligations, are trained, and have access only on a need-to-know basis.

2.6The Processor shall not retain Personal Data for longer than necessary for the purposes, and shall comply with the retention periods in Schedule 1.

2.7The Processor shall assist the Organisation in meeting its obligations under the Act, including responding to access and correction requests, and shall not respond directly to an individual without the Organisation’s instruction.

3. Data Breach

3.1The Processor shall notify the Organisation of any data breach affecting Personal Data immediately, and in any event within [24] hours of becoming aware of it, by email to [EMAIL] and telephone to [PHONE].

Generated from www.helionerp.com1

6 more pages in the Word file

This is page 1 of the Word document, exactly as it appears when you open it. Fields shown like THIS are placeholders for you to complete.

Notes for use

These notes accompany the template and explain the drafting choices, the compliance points and the mistakes most often made with this document. They appear as a final page in the Word file, intended to be deleted before the document is executed.

The obligation stays with you

Engaging a processor does not transfer responsibility under the Act. The Organisation remains accountable for the data, must assess and notify a breach at the vendor, and answers to the Commission for it. This addendum does not shift the obligation — it gives you the information and control needed to discharge it.

Twenty-four hours is the clause that matters most

Your own notification clock runs from determination, and you cannot determine anything you have not been told about. A vendor contract permitting notification "without undue delay" or "within a reasonable period" makes your own deadline unachievable. Clause 3.1 fixes a number and a named contact, and this is the single most important negotiation point in the document.

Stop the vendor notifying the Commission on your behalf

Clause 3.5 exists because a vendor notifying the regulator about your data, in its own terms, removes your control over an assessment you are accountable for. The vendor may have its own separate legal obligations; it should not discharge yours.

Prohibit use for the vendor’s own purposes

Clause 2.2 addresses the issue that has become most contentious — vendors using customer data to train models, benchmark, or improve their own products. Standard vendor terms increasingly permit this in language that is easy to miss. If it is not expressly prohibited, assume it is happening.

Watch for the vendor becoming an organisation in its own right

Where a vendor determines its own purposes for data, it is no longer merely processing on your behalf and has its own obligations — but that does not help you if you did not authorise the use. Clause 1.4 acknowledges the position without conceding the entitlement.

Sub-processors are where the data actually goes

Most vendors rely on cloud hosts, support providers, analytics tools and offshore teams. The Schedule 3 list is frequently the first time an organisation discovers how many parties touch its data. Require the list, require notice of changes, and keep the vendor liable for all of them.

Overseas transfer needs a comparable standard

Data may only be transferred outside Singapore where the recipient is legally bound to a comparable standard of protection. For a cloud service hosted elsewhere this must be documented rather than assumed, and evidence should be obtainable on request — Clause 5.2 requires it.

Deletion must follow the data

Clause 7.2 extends deletion to backups, archives, logs and sub-processor copies. Deletion from the live production system is what most vendors mean and it is not deletion. Require written confirmation identifying what was deleted from where, and accept a realistic backup timeframe rather than a fictional immediate one.

Get the exit right before you sign

Return of data in a commonly used format matters enormously at termination and is very difficult to negotiate once the relationship has soured. Agree the format, the timeframe and any cost at the outset.

Do not let the liability cap swallow the indemnity

Clause 8.1 flags this deliberately. A data protection indemnity subject to a cap of one month’s fees is not protection — the regulatory exposure and remediation cost of a significant breach will exceed it many times over. Whether the indemnity sits inside or outside the cap is one of the two or three points genuinely worth negotiating hard.

Complete Schedule 1 specifically

A schedule stating the purpose as "provision of the services" and the data as "customer data" documents nothing and provides no basis for assessing a breach when one occurs. Specificity here is what makes the rest of the addendum operable.

Flag the sensitive categories

Identification numbers, financial account details and health information drive breach notifiability because their disclosure is prescribed as likely to result in significant harm. Knowing in advance which vendors hold them tells you which relationships carry real risk.

Audit rights are useful mainly as leverage

Most organisations will never exercise an audit right, and most vendors know it. The practical value is in Clause 6.2 — the right to current certifications, audit reports and answers to questionnaires, which is what you will actually use.

Review the vendor register annually

Processors accumulate. New tools are adopted by individual teams without a data protection review, and the register drifts out of date. Tie the register to the annual policy review so both move together.

Current as of

Reflects Singapore law current as of {{DATE OF USE}}. The Personal Data Protection Act has been amended and further provisions may come into force — have this addendum reviewed by a lawyer before use for a significant engagement, particularly where the vendor is overseas or the data includes sensitive categories.

This is a ready-to-use template provided for convenience. Laws and requirements change, and every situation is different — please have it reviewed by a qualified professional (a lawyer, corporate secretary, or accountant as relevant) before you rely on it.