Appointing a DPO takes one line. Being one takes a person who answers the requests, keeps the register honest, runs the breach drill before it is needed, and has the authority to say “stop doing that with customer data”. If nobody in the company has that time, the role can be filled from outside — which is what we do.
What an outsourced DPO engagement actually looks like, so you can see what you are paying for.
| When | What happens | What you get |
|---|---|---|
| Month 1 | Data inventory: what personal data you hold, where it lives, who can see it, who it is shared with | A register you can read, and the gaps named |
| Month 1 | Policies, retention rules, response templates, DPO contact published on your privacy page | A one-page policy set and the published contact |
| Every month | Access and correction requests handled; staff questions answered; vendor checks as suppliers change | A log of every request and how it was closed |
| Every quarter | Register refresh, staff reminders, a short written update on what changed | A quarterly note to management, one page |
| Every year | Policy review, retention sweep (deleting what you no longer need), and a breach drill run live with your team | An annual review record, and a team that knows what to do |
| If a breach happens | Assessment, decision on whether it is notifiable, notification inside the three-day window, and the record afterwards | A rehearsed process instead of a panic |
| Internal DPO | DPO as a Service | |
|---|---|---|
| Cost | Someone's time, taken from their real job | A published fee, no headcount |
| Independence | Often the same person who decides what the company does with data — and who is then asked why | Someone who can say no without worrying about their next review |
| Availability | Away when they are on leave, or when they have resigned | Covered — the named contact is a service, not a person on holiday |
| Knowledge | Fine, if they have been trained and keep up with the guidance | Our whole job, across many companies and many incidents |
| Best when | You have a competent person with genuine spare capacity and full authority | You do not — which is most SMEs, and every company where data handling is nobody's real job |
Yes. The law requires an organisation to appoint a DPO; it does not require that person to be an employee. Many Singapore companies outsource the role, and the contact details published are the DPO's.
It is a published monthly fee, quoted in writing before you start, and it depends on how much personal data you hold and how many sites are involved. See the pricing page, or ask for a written quote.
You should have someone internally who knows the register and can reach the DPO fast. The external DPO does the regulated work; an internal contact makes it work in practice.
Then check three things: do they have published contact details, do they have the register, and has a breach drill ever been run? If the answer to any is no, the role exists on paper only.
The first register session is usually within a week of the request, because the work is with your current systems, not a build.
Checked at the source on 20 September 2026. If a rule changes, this page changes with it.
Tell us roughly what personal data you hold — staff, customers, CVs, medical notes, ID copies — and where. You get a written quote and the first register session date, with no obligation.