PDPA & DPO · DPO as a Service

The person the law makes you name — what that person actually does all year.

Appointing a DPO takes one line. Being one takes a person who answers the requests, keeps the register honest, runs the breach drill before it is needed, and has the authority to say “stop doing that with customer data”. If nobody in the company has that time, the role can be filled from outside — which is what we do.

What the role is, in plain words

The year, month by month

What an outsourced DPO engagement actually looks like, so you can see what you are paying for.

WhenWhat happensWhat you get
Month 1Data inventory: what personal data you hold, where it lives, who can see it, who it is shared withA register you can read, and the gaps named
Month 1Policies, retention rules, response templates, DPO contact published on your privacy pageA one-page policy set and the published contact
Every monthAccess and correction requests handled; staff questions answered; vendor checks as suppliers changeA log of every request and how it was closed
Every quarterRegister refresh, staff reminders, a short written update on what changedA quarterly note to management, one page
Every yearPolicy review, retention sweep (deleting what you no longer need), and a breach drill run live with your teamAn annual review record, and a team that knows what to do
If a breach happensAssessment, decision on whether it is notifiable, notification inside the three-day window, and the record afterwardsA rehearsed process instead of a panic

Inside or outside: the honest comparison

Internal DPODPO as a Service
CostSomeone's time, taken from their real jobA published fee, no headcount
IndependenceOften the same person who decides what the company does with data — and who is then asked whySomeone who can say no without worrying about their next review
AvailabilityAway when they are on leave, or when they have resignedCovered — the named contact is a service, not a person on holiday
KnowledgeFine, if they have been trained and keep up with the guidanceOur whole job, across many companies and many incidents
Best whenYou have a competent person with genuine spare capacity and full authorityYou do not — which is most SMEs, and every company where data handling is nobody's real job

What we do as your DPO

What we do not do

Questions we get asked

Can an outside company be our DPO?

Yes. The law requires an organisation to appoint a DPO; it does not require that person to be an employee. Many Singapore companies outsource the role, and the contact details published are the DPO's.

What does DPO as a Service cost?

It is a published monthly fee, quoted in writing before you start, and it depends on how much personal data you hold and how many sites are involved. See the pricing page, or ask for a written quote.

Do we still need an internal person?

You should have someone internally who knows the register and can reach the DPO fast. The external DPO does the regulated work; an internal contact makes it work in practice.

What if we already have a DPO named?

Then check three things: do they have published contact details, do they have the register, and has a breach drill ever been run? If the answer to any is no, the role exists on paper only.

How quickly can you start?

The first register session is usually within a week of the request, because the work is with your current systems, not a build.

Where the facts on this page come from

Checked at the source on 20 September 2026. If a rule changes, this page changes with it.

Ask what the role would cost for your company.

Tell us roughly what personal data you hold — staff, customers, CVs, medical notes, ID copies — and where. You get a written quote and the first register session date, with no obligation.