Data Protection

PDPA Data Protection Policy

Appointing at least one Data Protection Officer is mandatory, and the officer’s business contact information must be made available to the public. Data breach notification has been mandatory since 2021. A policy that describes principles without naming an officer, without a breach procedure and without a retention schedule addresses none of the three things most likely to be asked about.

Download as Word9 pages23 KBFree
[HEADER — replace with your organisation’s letterhead, if used]

Personal Data Protection Policy

[COMPANY NAME]

Appointing at least one Data Protection Officer is mandatory, and the officer’s business contact information must be made available to the public. Data breach notification has been mandatory since 2021. A policy that describes principles without naming an officer, without a breach procedure and without a retention schedule addresses none of the three things most likely to be asked about.

ItemDetail
Organisation[COMPANY NAME], UEN [UEN]
Data Protection Officer[NAME], [DESIGNATION]
DPO contact — published[EMAIL], [PHONE], [POSTAL ADDRESS]
Deputy or alternate DPO[NAME], [EMAIL]
Approved by[NAME], [DESIGNATION], on [DATE]
Effective from[DATE]
Applies toAll employees, contractors and anyone handling personal data for the Company
ReviewAnnually, and on any material change to processing

1. Scope

1.1This policy applies to all personal data the Company collects, uses, discloses or cares for, whether about customers, employees, job applicants, suppliers, visitors or any other individual.

1.2"Personal data" means data about an individual who can be identified from that data, or from that data and other information the Company has or is likely to have access to, whether or not the data is true.

1.3This policy applies to data in any form, including electronic records, paper records, images, recordings and data held by third parties on the Company’s behalf.

2. The Obligations

ObligationWhat it requires of us
ConsentCollect, use or disclose personal data only with consent, or where an exception applies. Consent must be given voluntarily and cannot be a condition of a service beyond what is reasonable
Purpose limitationOnly for purposes a reasonable person would consider appropriate, and that have been notified
NotificationInform the individual of the purposes before or at collection
AccessOn request, provide the personal data held and information on how it has been used or disclosed
CorrectionOn request, correct an error or omission, and send the correction to organisations the data was disclosed to
AccuracyMake reasonable effort to ensure data is accurate and complete where it will be used to make a decision affecting the individual or disclosed
ProtectionMake reasonable security arrangements to prevent unauthorised access, collection, use, disclosure, copying, modification or disposal
Retention limitationCease to retain data when the purpose has ended and retention is no longer necessary for legal or business purposes
Transfer limitationTransfer outside Singapore only where the recipient is bound by a comparable standard of protection
AccountabilityAppoint a Data Protection Officer, publish their contact, implement policies and practices, and be able to demonstrate compliance
Data breach notificationAssess and, where the threshold is met, notify the Commission and affected individuals
Data portabilityWhere in force, transmit specified data to another organisation at the individual’s request
Generated from www.helionerp.com1

8 more pages in the Word file

This is page 1 of the Word document, exactly as it appears when you open it. Fields shown like THIS are placeholders for you to complete.

Notes for use

These notes accompany the template and explain the drafting choices, the compliance points and the mistakes most often made with this document. They appear as a final page in the Word file, intended to be deleted before the document is executed.

Appointing a Data Protection Officer is mandatory

Every organisation must appoint at least one individual as Data Protection Officer and make their business contact information available. The role may be held alongside other duties or outsourced, but it must be filled, and the contact must be genuinely published and monitored. An unstaffed generic mailbox does not satisfy the requirement, and it is among the first things checked.

Name a deputy

Access requests have deadlines and breaches have a three-day notification clock. A single officer on leave stops the process. Clause 3.4 requires an alternate; it costs nothing and prevents the most avoidable failure.

Breach notification: 30 days to assess, 3 days to notify

On becoming aware of a suspected breach, the assessment must be prompt and reasonable, and completed within thirty days. Where the breach is determined notifiable, the Commission must be notified within three calendar days of that determination, and affected individuals as soon as practicable. Note that the three days runs from **determination**, not from discovery — which is why the determination date must be recorded.

Record why a breach was not notifiable

Organisations diligently record notifiable breaches and record nothing about the ones they assessed and dismissed. If a breach is later questioned, the absence of any assessment record looks like no assessment was made. Clause 9.6 and Annexure B both require the reasoning either way.

Significant harm or significant scale — two separate tests

A breach is notifiable if it is likely to result in significant harm to individuals, **or** if it is of significant scale. A small breach of sensitive data can be notifiable on harm; a large breach of low-sensitivity data can be notifiable on scale. Assess both, not one.

Report first, assess later

Clause 9.1 instructs employees to report immediately and **not** to assess or resolve first. The most damaging delays come from a well-meaning employee trying to fix a problem quietly before telling anyone, which loses containment time and often destroys the evidence.

Consent is not the only basis, but exceptions need work

The Act permits collection, use and disclosure without consent in defined circumstances, including legitimate interests and business improvement. These are not free passes — several require an assessment to be carried out and documented before reliance. Identify and record the basis, as Clause 4.4 requires.

Do not bundle consent

Consent obtained by requiring it as a condition of a service, beyond what is reasonably required to provide that service, is not valid. Bundled consent in terms and conditions is a common and long-standing problem. Ask separately, and make withdrawal easy.

Retention is where most organisations quietly fail

The obligation is to cease retaining data once the purpose has ended and retention is no longer necessary. Most organisations keep everything indefinitely because deletion is effortful and nobody owns it. A retention schedule that is written but not implemented is worse than none — it evidences knowledge of an obligation that was not met. Assign the schedule to an owner and audit it.

Deleting from the live system is not disposal

Backups, archives, exports, and copies held by processors all persist. Clause 7.2 says so. When scoping deletion, follow the data rather than the application.

You remain responsible for your processors

Engaging a vendor does not transfer the obligation. The written agreement required by Clause 10.1 is the control, and it must include immediate breach notification — a processor that notifies you a month later makes your own three-day clock impossible to meet.

Overseas transfer needs a comparable standard

Data may be transferred outside Singapore only where the recipient is bound to a comparable standard of protection. For a group using a cloud provider hosted elsewhere, this needs to be documented, not assumed. Maintain the transfer record required by Clause 10.4.

Do Not Call is separate and frequently forgotten

The Do Not Call obligations apply to marketing messages sent to Singapore telephone numbers and operate alongside the data protection obligations. Checking the registry, or holding clear and unambiguous consent in evidential form, is required before sending. Enforcement action here is common and the fixes are simple.

Employee data is personal data

Payroll, performance, health and disciplinary records are all in scope. The employee privacy notice required by Clause 5.2 is not optional in substance — the notification obligation applies to employees as to anyone else.

Current as of

Reflects Singapore law current as of {{DATE OF USE}}. The Personal Data Protection Act has been amended and further provisions, including data portability, may come into force — confirm the current position, and review this policy with an adviser whenever processing changes materially or a new system is introduced.

This is a ready-to-use template provided for convenience. Laws and requirements change, and every situation is different — please have it reviewed by a qualified professional (a lawyer, corporate secretary, or accountant as relevant) before you rely on it.