Data Protection

Data Protection Officer Appointment

Appointing at least one Data Protection Officer is mandatory, and the officer’s business contact information must be made available to the public. The two failures that matter are appointing nobody, and appointing someone who has the title but neither the authority nor the time to do anything with it.

Download as Word6 pages19 KBFree
[HEADER — replace with your organisation’s letterhead, if used]

Data Protection Officer

Appointment and terms of reference

Appointing at least one Data Protection Officer is mandatory, and the officer’s business contact information must be made available to the public. The two failures that matter are appointing nobody, and appointing someone who has the title but neither the authority nor the time to do anything with it.

ItemDetail
Organisation[COMPANY NAME], UEN [UEN]
Data Protection Officer[NAME], [DESIGNATION]
Appointed with effect from[DATE]
Reports to, for this role[the Board / the Managing Director]
Deputy or alternate[NAME], [DESIGNATION]
Published contact — email[EMAIL]
Published contact — telephone[PHONE]
Published contact — postal[ADDRESS]
Published at[WEBSITE PRIVACY PAGE AND ANY OTHER LOCATION]
Time allocation for this role[PERCENTAGE OR DAYS PER MONTH]
Approved by[NAME], [DESIGNATION], on [DATE]

Appointment Letter

[COMPANY NAME]  Date: [DATE]

[NAME], [DESIGNATION]

Dear [FIRST NAME],

Appointment as Data Protection Officer

I am writing to confirm your appointment as the Company’s Data Protection Officer with effect from [DATE], in accordance with the Personal Data Protection Act 2012.

The role. You are responsible for ensuring the Company complies with the Act. Your terms of reference are set out in the Schedule to this letter.

Your contact details will be published. The Act requires the business contact information of the Data Protection Officer to be made available to the public. Your details as set out above will appear on the Company’s website and in its privacy notices. Please tell me if any of them need to change.

Authority and access. You have direct access to [the Board / the Managing Director] on any matter concerning data protection, without going through your usual reporting line. You may require any part of the business to provide information, and may instruct that a process be paused where you consider there is a serious risk of contravention, pending a decision by [the Board / the Managing Director].

Time and resources. The Company has allocated [PERCENTAGE OR DAYS] to this role. A budget of S$ [AMOUNT] is available for training, tools and external advice. If the allocation proves inadequate, tell me rather than absorbing it.

Training. The Company will fund training appropriate to the role and will support your continued professional development in this area.

Generated from www.helionerp.com1

5 more pages in the Word file

This is page 1 of the Word document, exactly as it appears when you open it. Fields shown like THIS are placeholders for you to complete.

Notes for use

These notes accompany the template and explain the drafting choices, the compliance points and the mistakes most often made with this document. They appear as a final page in the Word file, intended to be deleted before the document is executed.

Appointment is mandatory; publication is part of it

Every organisation must appoint at least one individual as Data Protection Officer and make their business contact information available. Appointing someone but publishing nothing, or publishing an address nobody monitors, does not satisfy the requirement in substance and is easily checked.

Publish a role address, not only a personal one

A functional address such as a dedicated data protection mailbox survives the individual leaving, whereas a personal email does not. Ensure whichever is published is actually monitored, and that the deputy has access to it.

The role can be part-time or outsourced — but it must be real

The Act does not require a full-time officer, and many organisations assign the role alongside an existing job or outsource it. What it does require is that the person can actually discharge the responsibilities. An appointment with no time allocation, no budget and no authority is a title, and it will not help when a breach occurs.

Name a deputy — the deadlines do not pause

Access requests carry response deadlines and breach notification runs on a short clock from determination. A single officer on leave stops the process. Clause 5.1 is the cheapest control in this document.

Avoid the conflict of interest

Where the officer also owns the commercial use of personal data — running marketing, or owning the customer database strategy — they are assessing their own decisions. Clause 3.2 addresses it. In a small organisation perfect separation is impossible, but the conflict should at least be recognised and the assessment documented.

Consultation before launch, not after

Clause 2.4 requires the officer to be involved before a new system, vendor or processing activity goes live. Data protection problems discovered after launch are expensive to fix and often require the very thing the business least wants — turning something off. Build the sign-off into the project process.

Record advice that is not followed

Clause 2.5 requires both the advice and the contrary decision to be recorded. This protects the officer, gives management a clear-eyed view of accepted risk, and is precisely the record that matters if the risk materialises.

Protect the officer explicitly

An officer who fears career consequences for saying no will stop saying it, which defeats the appointment. The protection in Clause 3.1 is stated in the letter as well as the terms of reference because the person needs to have read it.

Give the role real time

The responsibilities in Section 1 — inventory, registers, request handling, breach response, vendor assessment, training, retention — are not absorbable in an afternoon a quarter. Estimate honestly and review the allocation, as Clause 4.1 requires. An officer quietly failing for lack of time is the most common form this appointment takes.

The inventory underpins everything else

Responsibility 3 — knowing what personal data is held, why, where and for how long — is the foundation for retention, breach assessment, access requests and vendor management. An organisation that cannot answer those questions cannot do any of the rest properly, and building the inventory is usually the officer’s first substantial task.

Breach response is the responsibility that will be tested

Assessment must be prompt and completed within thirty days; where notifiable, the Commission must be notified within three calendar days of that determination and individuals as soon as practicable. The officer should have a written response plan and should have walked through it before it is needed.

Do Not Call sits here too

Marketing to Singapore telephone numbers engages separate obligations, and enforcement in this area is common. Responsibility 13 puts it explicitly within the role rather than leaving it with marketing, where it is frequently overlooked.

Handover matters

When the officer changes, the registers, open requests, live breach matters and vendor records must transfer, and the published contact must be updated promptly. Appointing a successor only after the incumbent has left leaves a gap in a mandatory role.

Report quarterly, in writing

A written report to management on the compliance position, incidents and risks does two things: it keeps data protection visible at the level that can fund it, and it evidences that the appointment is operating. Verbal updates leave no record that the role existed.

Current as of

Reflects Singapore law current as of {{DATE OF USE}}. The Personal Data Protection Act has been amended and further provisions, including data portability, may come into force — confirm the current requirements and guidance, and review these terms of reference annually.

This is a ready-to-use template provided for convenience. Laws and requirements change, and every situation is different — please have it reviewed by a qualified professional (a lawyer, corporate secretary, or accountant as relevant) before you rely on it.