vista infosec white

PDPA Singapore Compliance Audit and Privacy Consulting Services

Secure Personal Data

PDPA Audit and Compliance Consultants in Singapore

Most Singapore organisations have a privacy policy and a named DPO. Fewer can show that consent is recorded, access requests are answered on time, old records are actually deleted, and a breach would be assessed and reported inside the PDPC's three-day window.

We audit how you really handle personal data against the PDPA, show you where the gaps are, and help you close them, with consultants who've done this work, not a template pack.

  • Independent PDPA compliance audit and gap assessment
  • Hands-on remediation: notices, consent, retention, breach response, vendors
  • Risk-ranked findings you can act on, and a follow-up review to prove it

Talk to a Compliance Expert

    Singapore entity

    VISTA Infosec Pte. Ltd., Vision Exchange, Jurong

    CSRO-licensed

    Penetration testing service licence under the Cybersecurity Act 2018

    21+ years

    Audit and compliance work since 2004

    CREST · PCI QSA · CERT-In

    Accredited testing and audit pedigree

    Vendor-neutral

    We don't sell privacy software or hardware

    PDPA compliance in Singapore

    PDPA Compliance Is About Evidence Now, Not Just Policies

    Short answer: the PDPA sets a baseline standard for how organisations collect, use, disclose and care for personal data in Singapore. The Personal Data Protection Commission (PDPC) enforces it, and it lists eleven data protection obligations, ten of which are in force today (the Data Portability Obligation starts only when its regulations are issued).

    What's changed over the last few years isn't the principles. It's the expectation that you can show them working. Mandatory breach notification means you need a tested way to decide, within days, whether an incident is notifiable. Higher penalty caps mean the Protection Obligation gets board attention. And customers, especially enterprise buyers and regulators in financial services, now ask for proof rather than a copy of your privacy policy.

    That's the gap we work in. We don't re-explain the Act to you. We check what your organisation actually does with personal data, compare it with what the PDPA and PDPC guidance expect, and help you fix what doesn't hold up. If you want the plain-English walk-through of the obligations first, our PDPA compliance guide covers it.

    Key dates worth knowing

    1. 2 Jul 2014Main PDPA data protection rules in force (Do Not Call provisions from 2 Jan 2014)
    2. 1 Feb 2021Amendments start taking effect in phases, including mandatory data breach notification
    3. 1 Oct 2022Maximum financial penalty rises to 10% of Singapore turnover for organisations above S$10 million, or S$1 million
    4. Jul 2025Data Protection Trustmark becomes Singapore Standard SS 714:2025

    Sources: PDPC, IMDA.

    PDPA audit

    PDPA Compliance Audit in Singapore

    A PDPA compliance audit is an independent check of whether your organisation meets the PDPA in practice. We compare your policies with the Act and PDPC guidance, then test them: we pull samples, look at system settings and records, and talk to the people who actually handle the data.

    Organisations usually come to us for one of five reasons: the board or a customer wants independent assurance; a data breach or near miss exposed weak spots; a new system, acquisition or overseas vendor changed how data moves; they're preparing for DPTM certification; or nobody has looked properly since the DPO was appointed.

    A quick example of why testing matters. Plenty of retention policies say "delete customer records seven years after account closure." When we query the database, we often find records from accounts closed a decade ago, because the deletion job was never built. The policy reads fine. The practice fails the Retention Limitation Obligation. Only evidence tells you which one you've got.

    What we examine

    • 01Personal data inventory and records of what you hold
    • 02Data flows across systems, teams and vendors
    • 03Data protection policies and how they're communicated to staff
    • 04Collection notices and privacy statements
    • 05Consent capture, records and withdrawal handling
    • 06Purpose limitation: is data used only for notified purposes?
    • 07DPO designation, governance and complaints process
    • 08Access and correction requests: process, timeliness, records
    • 09Accuracy checks where data drives decisions or is disclosed
    • 10Protection: access control, encryption, logging, testing
    • 11Retention schedules and secure disposal in practice
    • 12Data intermediaries and other third parties
    • 13Overseas transfers and the safeguards behind them
    • 14Breach assessment, notification and incident records
    • 15Staff awareness and role-based training
    • 16Do Not Call checks, if you market to Singapore numbers

    Evidence we typically ask for

    Examples only. We agree the evidence list during scoping so nobody wastes time.
    ConsentSign-up forms and screenshots, consent logs with timestamps, withdrawal requests and what happened after them
    Access & correctionRequest log, response times, sample responses, how identity was verified
    ProtectionUser access reviews, privileged-account lists, encryption settings, vulnerability and penetration test results, patch records
    RetentionRetention schedule, deletion job logs, disposal certificates, a sample of records older than the schedule allows
    Third partiesVendor list, data processing clauses, due-diligence records, transfer safeguards for overseas providers
    Breach readinessIncident register (including incidents you decided weren't notifiable), assessment records, last tabletop exercise

    How we rate findings

    High

    A likely breach of an obligation, or a weakness that could plausibly lead to a notifiable breach. Fix first.

    Medium

    The control exists but isn't reliable, consistent or evidenced. Fix in the next cycle.

    Low

    Good practice gaps and documentation clean-up. Fix as you go.

    Every finding is tied to the obligation it affects, the evidence we saw, and a specific fix with a suggested owner.

    Three things a PDPA audit from us is not

    • Not a PDPC inspection. It's a private assessment you commission. The PDPC doesn't approve or endorse it.
    • Not a certificate. There's no government "PDPA certificate". Formal certification is DPTM, awarded by IMDA-appointed certification bodies (we aren't one).
    • Not legal advice. Where a question turns on legal interpretation, we'll say so and you should involve counsel.

    How the audit runs

    PDPA Audit Methodology: Nine Steps From Scope to Proof

    For a single-entity organisation with a handful of core systems, fieldwork is usually measured in weeks, not months. We'll give you a timeline in the proposal once scope is clear.

    1. 1

      Scope the assessment

      Agree entities, business processes, systems and vendors in scope, and whether technical testing is included.

    2. 2

      Understand personal data flows

      Workshops with process owners to trace data from collection to disposal, including what leaves Singapore.

    3. 3

      Review documentation

      Policies, notices, consent wording, retention schedule, vendor contracts, DPO terms, breach plan.

    4. 4

      Assess privacy controls

      Walk through how each obligation is met in practice, team by team and system by system.

    5. 5

      Review evidence

      Sample records, logs and settings. This is where policy and reality are compared.

    6. 6

      Identify gaps

      Document each gap against the specific obligation and PDPC guidance it relates to.

    7. 7

      Prioritise findings

      Rate by likelihood and impact on individuals, not just by how easy they are to fix.

    8. 8

      Develop remediation actions

      Specific fixes, owners and target dates your team can actually execute.

    9. 9

      Follow-up review

      We re-test the fixes and update the report, so you can show the gap is closed.

    PDPA consultancy

    PDPA Consultants and Consultancy Support in Singapore

    Hiring a PDPA consultant should get you more than a folder of templates. When you work with our PDPA consultants, the first thing we do is find out how your business actually runs: who collects data, where it lands, which vendors see it, what your team does when a customer asks for their records. Then we fix things in that order of reality, not in the order the Act lists its obligations.

    Our PDPA consultancy work is usually split between governance (who owns what, how the DPO gets heard) and operations (forms, systems, contracts, procedures). We'll draft where drafting is needed, but we'd rather your team owns the result, so we work with them rather than around them.

    What this looks like on a real form

    A membership sign-up page collects NRIC numbers "for verification", bundles marketing consent into the terms, and feeds a CRM that keeps everything forever. A consultant doesn't just flag it. We work out whether the NRIC is needed at all, split the marketing consent so it's optional, rewrite the notice so the purposes match what the business really does, and set a retention rule the CRM can enforce. Four obligations, one form, fixed in one pass.

    Four ways to work with us

    Audit onlyYou have a programme and want independent assurance. We audit, report and re-test.
    Gap assessment + remediationYou're building or rebuilding. We assess, then work alongside your team to fix what we find.
    Periodic reviewYou want a consistent annual view, plus a check after major changes.
    Outsourced DPO supportYou need the DPO function covered. See our outsourced DPO service.

    What our PDPA consultants help with

    • Scoping which data, processes and entities matter most
    • Compliance gap assessment against all obligations in force
    • Privacy governance: DPO role, reporting lines, board updates
    • Personal data mapping and inventory
    • Policy and procedure review or drafting
    • Collection notices and privacy statements
    • Consent capture and withdrawal processes
    • Retention schedules and disposal procedures
    • Overseas transfer assessments and contract clauses
    • Breach assessment and notification playbook
    • Control implementation with your IT and security teams
    • Staff awareness and role-based training
    • Remediation tracking and re-testing
    • Periodic compliance reviews

    PDPA compliance services

    PDPA Compliance Services for Singapore Organisations

    Pick one, or combine them. Most engagements start with a gap assessment or audit and pull in the rest where the findings point.

    PDPA Gap Assessment

    A structured baseline against every obligation in force. Tells you where you stand and what to fix first.

    PDPA Compliance Audit

    Evidence-based testing of whether your controls work, with risk-ranked findings and a follow-up review.

    Privacy Governance Review

    DPO role, accountability, reporting to management, complaints handling and policy ownership.

    Personal Data Mapping

    An inventory of what you hold, why, where it lives, who can see it and where it goes.

    Policy & Procedure Review

    Data protection policy, notices, consent wording, access and correction procedures, retention schedule.

    Data Breach Preparedness

    Assessment criteria, notification playbook, templates and a tabletop exercise against the three-day window.

    Third-Party & Transfer Review

    Data intermediary contracts, vendor due diligence and safeguards for overseas transfers.

    Privacy Risk Assessment

    Data protection impact assessments for new systems, products or processing, following the PDPC's DPIA approach.

    Remediation Support

    Hands-on help implementing fixes with your legal, IT, security and operations teams.

    Awareness Training

    Short, role-based sessions for frontline, HR, marketing and IT staff, built from your own processes.

    Periodic Compliance Review

    A consistent yearly check, plus reviews after major change, so drift gets caught early.

    Technical Security Testing

    Penetration testing and vulnerability assessment to evidence the Protection Obligation, delivered under our Singapore CSRO licence.

    Technical testing links: penetration testing · vulnerability assessment · web application security assessment.

    PDPA obligations

    The PDPA Obligations, and What an Auditor Looks For

    These are the obligations as the PDPC names them. The middle columns are where audits are won or lost: what the obligation means day to day, and what evidence shows it's met. Exceptions apply to several obligations; the PDPC's advisory guidelines set them out.

    PDPA data protection obligations (source: PDPC)
    ObligationWhat it means operationallyExample evidenceHow we support
    AccountabilityDesignate a DPO, publish their business contact details, develop and implement policies and practices, and have a complaints process.DPO appointment, published contact, policy set, staff communication recordsGovernance review, policy gap check, DPO support
    NotificationTell individuals the purposes for collecting, using or disclosing their data, on or before collection.Collection notices at each touchpoint, privacy statementNotice review against actual processing
    ConsentCollect, use or disclose data only with consent (or where an exception applies), and honour withdrawal.Consent records, withdrawal log, form screenshotsConsent flow testing, withdrawal sampling
    Purpose LimitationUse data only for purposes a reasonable person would consider appropriate and that were notified.Data map linking data to purposesPurpose-to-use mapping
    Access and CorrectionGive individuals access to their data and how it was used or disclosed in the past year, and correct errors.Request log, response times, sample responsesProcedure design, timeliness sampling
    AccuracyMake reasonable efforts to keep data accurate and complete where it's used for decisions or disclosed.Validation checks, update processesProcess review
    ProtectionMake reasonable security arrangements against unauthorised access, collection, use, disclosure and similar risks.Access reviews, encryption, logging, test resultsControl review, penetration testing
    Retention LimitationStop retaining data, or dispose of it properly, once there's no business or legal purpose.Retention schedule, deletion logs, disposal recordsRetention testing on live data
    Transfer LimitationTransfer data overseas only with protection comparable to the PDPA, as prescribed by regulations.Transfer register, contract clauses, vendor assessmentsTransfer review, clause review
    Data Breach NotificationAssess suspected breaches and notify the PDPC and, where required, affected individuals.Incident register, assessment records, playbookPlaybook, templates, tabletop
    Data PortabilityTransmit data to another organisation on request, in a machine-readable format.Not yet in force: takes effect when regulations are issuedReadiness planning only

    PDPA gap assessment

    PDPA Gap Assessment, Audit or DPTM: Which Do You Need?

    These get mixed up a lot, and some providers blur them on purpose. Here's the honest version. If you've never had an independent look, start with a gap assessment. If you've done the work and want proof it holds, go for an audit. If you want a public, recognised mark, that's DPTM, and an audit is good preparation for it.

    AttributeGap assessmentCompliance auditDPTM certificationPDPC investigation
    PurposeFind out what's missingTest whether controls workFormal, voluntary certificationEnforcement after a complaint or breach
    Who performs itConsultant or internal teamIndependent assessor (e.g. us)IMDA-appointed certification bodyThe PDPC
    DepthDocuments and interviewsDocuments, interviews and sampled evidenceAssessment against SS 714:2025Whatever the PDPC requires
    OutputGap list and roadmapRisk-ranked findings, remediation plan, re-testCertificate and use of the DPTM logo, with annual surveillance auditsDecision, directions or financial penalty
    Legally required?NoNoNo, voluntaryNot something you choose

    About the Data Protection Trustmark (DPTM)

    DPTM is a voluntary, enterprise-wide certification for organisations to demonstrate accountable data protection practices. Since July 2025 it has been part of the national Singapore Standards as SS 714:2025. Certification is carried out by certification bodies appointed by IMDA and overseen by the Singapore Accreditation Council, and certified organisations go through annual surveillance audits.

    We are not a DPTM certification body and we don't award DPTM. What we can do is assess you against the PDPA beforehand so the certification audit doesn't turn up surprises. Details and the current list of certification bodies are on IMDA's DPTM page.

    Before you contact anyone

    The PDPC's free PDPA Assessment Tool for Organisations gives you a quick self-check. It's a good way to see how far off you are. When you need someone to test the answers against evidence, that's where we come in.

    Request a PDPA Gap Assessment

    Data protection governance

    The Data Protection Officer and PDPA Governance

    What the PDPA requires

    Under the Accountability Obligation, every organisation must designate at least one individual to be responsible for ensuring it complies with the PDPA, and make that person's business contact information available to the public. The PDPA doesn't prescribe a qualification. The role can sit with an employee or an outsourced provider, and designating a DPO doesn't move legal responsibility away from the organisation.

    You'll also need data protection policies and practices, a way to communicate them to staff, and a process to receive and respond to complaints.

    What we usually find in audits

    • A DPO named on paper, but with no time, budget or line to senior management
    • Contact details on the website pointing to a shared inbox nobody monitors
    • No record of complaints or access requests, so nothing to show the PDPC
    • Policies written once and never communicated to the teams that handle data

    If you'd rather have the function covered externally, VISTA Infosec offers an outsourced DPO service. Either way, our audit checks whether the DPO arrangement actually works.

    Personal data lifecycle

    Following Personal Data From Collection to Disposal

    We audit along the lifecycle, because that's how data really moves and it's where handovers between teams break down.

    1. Collect

      Notification · Consent

      Is the notice shown before collection? Is consent separate from terms?

    2. Use

      Purpose Limitation · Accuracy

      Is data used only for the notified purposes? Is it accurate where it drives decisions?

    3. Disclose

      Consent · Transfer Limitation

      Who receives it, under what contract, and in which country?

    4. Protect

      Protection

      Who has access, how is it secured, and when was that last tested?

    5. Respond

      Access and Correction · Breach Notification

      Can you answer a request or assess a breach on time, with records?

    6. Retain & dispose

      Retention Limitation

      Is data actually deleted when the schedule says so?

    Data breach preparedness

    Data Breach Assessment and Notification Under the PDPA

    The three-day clock starts when you decide a breach is notifiable, not when it happened. That's why the assessment step matters: the PDPC expects it to be done quickly, and a documented assessment is what you'll be asked for.

    1. STEP 1

      Suspect

      Someone reports or detects an incident involving personal data. Your data intermediaries must tell you without undue delay.

    2. STEP 2

      Assess

      Assess in a reasonable and expeditious manner: what data, how many people, how it happened, whether harm is likely.

    3. STEP 3

      Decide

      Notifiable if it's likely to result in significant harm to individuals, or involves 500 or more people.

    4. STEP 4

      Notify PDPC

      As soon as practicable, and no later than 3 calendar days after you determine it's notifiable.

    5. STEP 5

      Notify individuals

      Where significant harm is likely, notify affected individuals too, unless an exception applies.

    Where teams usually slip

    • Nobody is sure who decides whether a breach is notifiable, so the decision drifts
    • Incidents judged "not notifiable" aren't recorded, so there's no trail to defend the call
    • Vendor contracts don't require prompt breach notice back to you
    • The breach plan has never been rehearsed with the people who'd actually run it

    How we help

    We build the assessment criteria, decision log, notification templates and escalation path, then run a tabletop exercise against a scenario that fits your business. Read the PDPC's guide on managing and notifying data breaches for the official position.

    Get Breach-Ready

    Third parties and transfers

    Data Intermediaries, Vendors and Overseas Transfers

    Most personal data in a modern Singapore business sits with someone else: a payroll provider, a cloud CRM, a marketing platform, a group company overseas. The PDPA still holds you responsible for data processed on your behalf.

    Data intermediaries and vendors

    We check that you know who processes personal data for you, that contracts set out protection, retention and breach-notice duties, and that you've done proportionate due diligence. Where it's useful, we fold this into your wider third-party risk management.

    Typical finding: a marketing agency with full customer-list access and no data clauses in its contract.

    Transfers outside Singapore

    Personal data can only be transferred overseas in line with the Transfer Limitation Obligation and its regulations, so that the recipient provides a standard of protection comparable to the PDPA. We map which systems send data abroad and check the legally enforceable obligations or other safeguards behind each one.

    Also subject to GDPR or India's DPDP Act? We can map controls once across frameworks: see GDPR, DPDP and AuditFusion360.

    From assessment to remediation

    A Report Isn't the Goal. Closed Gaps Are.

    The most common failure we see isn't a bad audit. It's a good audit that sat in a drawer. So every engagement is set up to reach the Validate step, where we re-test the fixes and you get an updated report showing what's closed.

    1. 1 / 6

      Assess

      Scope and test against the obligations in force.

    2. 2 / 6

      Identify

      Document each gap with evidence.

    3. 3 / 6

      Prioritise

      Rank by risk to individuals and to you.

    4. 4 / 6

      Remediate

      Fix with owners, dates and our help.

    5. 5 / 6

      Validate

      Re-test and update the report.

    6. 6 / 6

      Maintain

      Periodic review and change triggers.

    Deliverables

    What You Get From a PDPA Audit

    1. 1

      Executive summary

      A two-page view for management and the board: overall position, top risks, what it'll take to fix.

    2. 2

      Obligation-by-obligation findings

      Each gap mapped to the PDPA obligation and PDPC guidance it relates to, with the evidence we saw.

    3. 3

      Risk-ranked findings register

      High, medium and low ratings, suggested owners and target dates, in a format you can track.

    4. 4

      Policy and control observations

      Specific comments on notices, consent wording, retention rules, vendor clauses and security controls.

    5. 5

      Remediation roadmap

      Sequenced actions: quick wins first, structural changes planned, dependencies called out.

    6. 6

      Follow-up assessment

      A re-test of the fixes and an updated report showing which findings are closed.

    What we won't promise you

    • A government or "legally admissible" PDPA certificate. It doesn't exist.
    • PDPC approval or endorsement of your programme
    • DPTM certification. Only IMDA-appointed certification bodies award it.
    • Guaranteed compliance. Compliance depends on what you do after we leave.

    Why VISTA Infosec

    Why Work With VISTA Infosec on PDPA

    Auditors first

    We've spent 21+ years testing controls against standards like PCI DSS, SOC 2 and ISO 27001. That habit of asking for evidence is exactly what a PDPA audit needs.

    Local entity, local licence

    Singapore engagements are contracted through VISTA Infosec Pte. Ltd., which holds a CSRO Penetration Testing Service Licence under the Cybersecurity Act 2018.

    Privacy and security in one team

    The Protection Obligation is where most PDPC enforcement lands. We can test the technical side ourselves, as a CREST-accredited firm, rather than taking a screenshot on trust.

    Multi-framework without duplication

    Subject to GDPR, India's DPDP Act, MAS TRM or ISO 27001 too? We map shared controls once instead of auditing you four times.

    Vendor-neutral

    We don't sell consent platforms or data-discovery tools, so our recommendations aren't shaped by a product.

    No subcontracting

    Your engagement is run by VISTA Infosec staff. Team credentials include CISSP, CISA, CRISC and ISO 27001 Lead Auditor.

    Financial institution? Our MAS TRM audit work often runs alongside PDPA. Pursuing ISO 27001? Many PDPA protection controls overlap.

    Cost

    How Much Does a PDPA Audit or Consultancy Engagement Cost?

    We don't publish a price, because a 20-person agency with one CRM and a multi-entity group with overseas processing aren't the same job. What drives the effort:

    • Size of the organisation and number of legal entities
    • Volume and types of personal data, especially NRIC, financial or health data
    • Number of business processes and systems in scope
    • Number of locations, including overseas operations
    • How mature your current programme is
    • Number of data intermediaries and overseas transfers
    • Audit depth: document review only, or sampled evidence testing
    • Remediation support and follow-up review
    • Technical testing such as penetration testing

    Get a scoped, fixed-fee proposal

    Tell us a little about your organisation. We'll run a short scoping call, then send a fixed fee with a defined timeline, so there are no surprises halfway through.

    Request a PDPA Assessment

    FAQ

    Frequently Asked Questions About PDPA Compliance in Singapore

    What is a PDPA compliance audit?

    A PDPA compliance audit is an independent review of how your organisation actually collects, uses, discloses, protects, retains and transfers personal data, measured against the obligations in Singapore's Personal Data Protection Act 2012 and the PDPC's advisory guidelines. We look at your documents and at evidence of what really happens, then give you risk-ranked findings and a remediation plan. It's a private assessment you commission, not an inspection by the PDPC.

    What does a PDPA audit cover?

    Typically your personal data inventory and data flows, notices and consent, purpose limitation, the DPO and accountability arrangements, access and correction handling, accuracy, security arrangements under the Protection Obligation, retention and disposal, data intermediaries and other third parties, overseas transfers, data breach assessment and notification procedures, and staff awareness. If you send marketing messages to Singapore telephone numbers, we can include Do Not Call checks. We agree the scope with you before fieldwork starts.

    Is a PDPA audit a legal requirement in Singapore?

    No. The PDPA doesn't require organisations to commission an audit, annual or otherwise. It does require you to meet the data protection obligations and, under the Accountability Obligation, to develop and implement the policies and practices needed to meet them. An independent audit is a practical way to check that those policies work in practice and to show your board, customers or the PDPC what you've done.

    What does a PDPA consultant do?

    A PDPA consultant helps you work out what the Act means for your specific operations and then helps you put it right. In practice that means scoping which data and processes matter, mapping data flows, reviewing notices, consent and retention, designing breach-response and access-request procedures, advising your DPO, training staff and checking fixes once they're in. Good consultancy ends with things working, not just a report.

    What's the difference between a PDPA gap assessment and a PDPA audit?

    A gap assessment compares your current policies and practices with the PDPA to show what's missing, and it's usually the first step. An audit goes further and tests whether controls actually operate, using samples and evidence such as consent records, access-request logs, retention schedules and breach registers. Many organisations start with a gap assessment, remediate, then audit.

    Who has to comply with the PDPA?

    The PDPA applies to organisations that collect, use or disclose personal data in Singapore, including companies and non-profits, whether or not they are incorporated in Singapore. It generally doesn't apply to individuals acting in a personal or domestic capacity, employees acting in the course of their employment, or public agencies. Business contact information is also generally outside the data protection provisions.

    Does every organisation need a Data Protection Officer?

    Yes. The Accountability Obligation requires every organisation to designate at least one individual, commonly called the Data Protection Officer, to be responsible for ensuring it complies with the PDPA, and to make that person's business contact information available to the public. The DPO can be an employee or an outsourced provider, but the organisation stays responsible for compliance either way.

    When must a data breach be reported to the PDPC?

    Once you have reason to believe a breach has occurred, you must assess it in a reasonable and expeditious manner. If it is notifiable, meaning it is likely to result in significant harm to affected individuals or involves 500 or more people, you must notify the PDPC as soon as practicable and no later than three calendar days after you determine it is notifiable. Where significant harm is likely, you must also notify the affected individuals, subject to limited exceptions.

    Is PDPA compliance the same as DPTM certification?

    No. PDPA compliance is a legal obligation for organisations within scope. The Data Protection Trustmark (DPTM), now the Singapore Standard SS 714:2025, is a voluntary enterprise-wide certification administered by IMDA and assessed by IMDA-appointed certification bodies, with annual surveillance audits. Certification can help you show accountable practices, but the PDPA doesn't require it.

    Can VISTA Infosec issue a PDPA certificate?

    No. There is no government-issued PDPA certificate, and we are not a DPTM certification body. What we issue is an assessment report under our own name. It states the scope, period and method, what we tested, what we found and what you should fix. If you want formal certification, DPTM through an IMDA-appointed certification body is the route, and our assessment can help you prepare for it.

    How often should we review PDPA compliance?

    The PDPA doesn't set a review frequency. We recommend a review at least once a year and whenever something significant changes, such as a new system, a new vendor handling personal data, an acquisition or a data breach. That's our recommendation, not a legal requirement.

    How much does a PDPA compliance audit cost?

    It depends on scope. The main drivers are the number of business processes and systems that handle personal data, how many entities and locations are involved, the volume and sensitivity of the data, how many data intermediaries and overseas transfers you rely on, how mature your current programme is, and whether you want remediation support or technical testing added. We scope first and then give you a fixed-fee proposal.

    Expert Auditors. Faster Certification.

     

    European Operations
    European engagements are delivered through Zulon Audits OÜ, the European practice of VISTA InfoSec.
    Visit Zulon Audits →