Not a large-company rule. Not an industry rule. Every organisation that handles personal data — including a one-person business with a customer list. We can be your DPO, or get your system right and back the person you appoint.
There is no size exemption. A sole proprietor holding a customer list has the same duty as an MNC.
You cannot be — registration is not required. Appointing is the duty; telling the PDPC who it is, is not.
You have three calendar days to notify the PDPC. That is not enough time to invent a process.
We do not sell urgency that does not exist. If someone tells you a DPO registration deadline is looming, ask them which instrument creates it. There is not one.
Four clear things, not vague advisory hours.
We are the appointed DPO. Listed on your notices, policies kept current, first-line answers when a data question arrives.
A data inventory of what you hold and where, your privacy notice, consent wording, retention rules and a breach response plan.
A staff refresher including new hires, a practical look at how you handle data, and a plain-English report you keep on file.
A complaint, an access request, a suspected breach, or the PDPC writing to you. Billed only when it actually happens.
A gap analysis runs against all eleven PDPA obligations. What we build:
A consultant is not a DPO. One finishes and leaves; the other stays accountable. If you want the second, that is the retainer rather than the project — and we will say which one you actually need rather than defaulting to the bigger sale.
Yes. Appointing a Data Protection Officer is mandatory under the PDPA for every Singapore organisation, with no size or industry exemption — a one-person company with a customer list included.
No. This is where a lot of advice goes wrong. Appointing a DPO is mandatory; notifying the PDPC of who it is, is not. The Commission encourages it, but nobody is going to fine you for the omission. Anyone telling you a registration deadline is approaching is selling urgency.
A notifiable breach must be reported to the PDPC within three calendar days of becoming aware of it. Three calendar days, not working days — which is why the plan needs to exist before the incident, not after.
A consultant advises and implements, and then leaves. A DPO is an ongoing, accountable role inside your organisation — someone on record who answers when data questions or complaints arrive. We offer both: a one-off implementation, or being your named DPO month to month.
The Data Protection Trustmark, now a national Singapore Standard. It is voluntary and administered by IMDA, assessed by appointed certification bodies with annual surveillance. It proves data protection to customers and buyers rather than merely asserting it.
A short review against your obligations, with a written list of the gaps. It costs nothing, and if you are already in decent shape we will say so.