Self-assessment · 9 questions · about two minutes

DPO Readiness Scorecard

Facts checked on 28 September 2026 · how this fits with an audit

Nine questions about what is actually written down in your company. You get a score out of 9, the items not yet in place, and the one thing to do first.

Who this is for: a Singapore business that holds customer or staff personal data, may or may not have appointed a DPO, and wants the real position before a customer, a tender or a lawyer asks. It is also the honest first step if you are considering a DPO retainer: find out what is missing before you pay anyone.

The questions

1. Is at least one person formally designated as your Data Protection Officer?

PDPA section 11(3) requires an organisation to designate one or more individuals responsible for ensuring it complies with the PDPA.

2. Is that person business contact information available to the public?

PDPA section 11(5) requires the business contact information of at least one designated individual to be made available, usually on your website and in the PDPC DPO Registry.

3. Do you have a written list of the personal data you hold, and where it lives?

Staff records, customer records, CCTV footage, access logs, enquiry forms, spreadsheets, cloud accounts.

4. Is there a notice telling people what you collect and why, and is consent actually recorded?

5. If personal data were lost or exposed today, is there a written process: who assesses it, who decides, who notifies?

A breach is notifiable if it is likely to cause significant harm, or affects 500 or more individuals. Where it is notifiable, the PDPC must be told as soon as practicable and no later than 3 calendar days after the organisation determines that it is notifiable (PDPA s.26B-26D, in force 1 February 2021).

6. Have your staff been walked through the handling rules in the last 12 months?

7. Do your agreements with vendors and service providers say what happens to personal data?

Anyone handling personal data on your behalf: payroll, IT support, cloud software, a call centre, a courier.

8. Is there a retention and disposal rule you actually follow?

9. Before you call or text a Singapore number for marketing, do you check the Do Not Call Registry?

What the score means

Each question is about something you can show someone: a name on paper, a list, a notice, a record, a clause in a contract. A low score is a to-do list, in order. It is not a verdict, and it is not a percentage of compliance.

Two things sit at the bottom of almost every gap we see in small Singapore firms. First, the DPO exists but nothing is written down, so nothing survives the person leaving. Second, there is no breach plan until there is a breach, and the notification clock starts from the moment you determine a breach is notifiable, which is exactly the moment you cannot afford to be designing the process.

What this is. A self-assessment of things you can point at: what is written down, who owns it, what is recorded. It is not an audit, not a compliance percentage and not a legal opinion. Ark Private prepares businesses for certification and never certifies, accredits or audits; the certification body or the MOM-registered Auditing Organisation decides. Nothing you select is sent anywhere: the score is worked out in your own browser.

Where these rules come from

Questions people ask about this

Do we legally have to appoint a DPO?

Yes. The PDPC states that appointing a DPO is the mandatory first step in complying with the PDPA, and that the DPO contact information must be made available. PDPA section 11(3) requires the designation; section 11(5) requires the business contact information of at least one designated individual to be made available. The designated person does not have to be an employee.

Can an outside person be our DPO?

Yes. PDPC guidance is that the designated individual need not be an employee of the organisation, and that legal responsibility for complying with the PDPA stays with the organisation either way. That is what DPO as a Service is: a named person who holds the role, with the policies and the records that make it real.

How quickly must a data breach be reported?

A breach is notifiable if it is likely to result in significant harm to an individual, or if it affects 500 or more individuals. Where it is notifiable, the organisation must notify the PDPC as soon as practicable and no later than 3 calendar days after it determines that the breach is notifiable (PDPA s.26B-26D). Affected individuals must also be notified where significant harm is likely.

Does a small company really need all of this?

The PDPA has no size exemption. What scales with size is the paperwork, not the obligation. A five-person company needs a name, a one-page inventory, a notice, a breach page and a retention rule: a few hours of work, not a project.