Most Singapore organisations have a privacy policy and a named DPO. Fewer can show that consent is recorded, access requests are answered on time, old records are actually deleted, and a breach would be assessed and reported inside the PDPC's three-day window.
We audit how you really handle personal data against the PDPA, show you where the gaps are, and help you close them, with consultants who've done this work, not a template pack.
Singapore entity
VISTA Infosec Pte. Ltd., Vision Exchange, Jurong
CSRO-licensed
Penetration testing service licence under the Cybersecurity Act 2018
21+ years
Audit and compliance work since 2004
CREST · PCI QSA · CERT-In
Accredited testing and audit pedigree
Vendor-neutral
We don't sell privacy software or hardware
PDPA compliance in Singapore
Short answer: the PDPA sets a baseline standard for how organisations collect, use, disclose and care for personal data in Singapore. The Personal Data Protection Commission (PDPC) enforces it, and it lists eleven data protection obligations, ten of which are in force today (the Data Portability Obligation starts only when its regulations are issued).
What's changed over the last few years isn't the principles. It's the expectation that you can show them working. Mandatory breach notification means you need a tested way to decide, within days, whether an incident is notifiable. Higher penalty caps mean the Protection Obligation gets board attention. And customers, especially enterprise buyers and regulators in financial services, now ask for proof rather than a copy of your privacy policy.
That's the gap we work in. We don't re-explain the Act to you. We check what your organisation actually does with personal data, compare it with what the PDPA and PDPC guidance expect, and help you fix what doesn't hold up. If you want the plain-English walk-through of the obligations first, our PDPA compliance guide covers it.
PDPA audit
A PDPA compliance audit is an independent check of whether your organisation meets the PDPA in practice. We compare your policies with the Act and PDPC guidance, then test them: we pull samples, look at system settings and records, and talk to the people who actually handle the data.
Organisations usually come to us for one of five reasons: the board or a customer wants independent assurance; a data breach or near miss exposed weak spots; a new system, acquisition or overseas vendor changed how data moves; they're preparing for DPTM certification; or nobody has looked properly since the DPO was appointed.
A quick example of why testing matters. Plenty of retention policies say "delete customer records seven years after account closure." When we query the database, we often find records from accounts closed a decade ago, because the deletion job was never built. The policy reads fine. The practice fails the Retention Limitation Obligation. Only evidence tells you which one you've got.
| Consent | Sign-up forms and screenshots, consent logs with timestamps, withdrawal requests and what happened after them |
|---|---|
| Access & correction | Request log, response times, sample responses, how identity was verified |
| Protection | User access reviews, privileged-account lists, encryption settings, vulnerability and penetration test results, patch records |
| Retention | Retention schedule, deletion job logs, disposal certificates, a sample of records older than the schedule allows |
| Third parties | Vendor list, data processing clauses, due-diligence records, transfer safeguards for overseas providers |
| Breach readiness | Incident register (including incidents you decided weren't notifiable), assessment records, last tabletop exercise |
High
A likely breach of an obligation, or a weakness that could plausibly lead to a notifiable breach. Fix first.
Medium
The control exists but isn't reliable, consistent or evidenced. Fix in the next cycle.
Low
Good practice gaps and documentation clean-up. Fix as you go.
Every finding is tied to the obligation it affects, the evidence we saw, and a specific fix with a suggested owner.
How the audit runs
For a single-entity organisation with a handful of core systems, fieldwork is usually measured in weeks, not months. We'll give you a timeline in the proposal once scope is clear.
Agree entities, business processes, systems and vendors in scope, and whether technical testing is included.
Workshops with process owners to trace data from collection to disposal, including what leaves Singapore.
Policies, notices, consent wording, retention schedule, vendor contracts, DPO terms, breach plan.
Walk through how each obligation is met in practice, team by team and system by system.
Sample records, logs and settings. This is where policy and reality are compared.
Document each gap against the specific obligation and PDPC guidance it relates to.
Rate by likelihood and impact on individuals, not just by how easy they are to fix.
Specific fixes, owners and target dates your team can actually execute.
We re-test the fixes and update the report, so you can show the gap is closed.
PDPA consultancy
Hiring a PDPA consultant should get you more than a folder of templates. When you work with our PDPA consultants, the first thing we do is find out how your business actually runs: who collects data, where it lands, which vendors see it, what your team does when a customer asks for their records. Then we fix things in that order of reality, not in the order the Act lists its obligations.
Our PDPA consultancy work is usually split between governance (who owns what, how the DPO gets heard) and operations (forms, systems, contracts, procedures). We'll draft where drafting is needed, but we'd rather your team owns the result, so we work with them rather than around them.
What this looks like on a real form
A membership sign-up page collects NRIC numbers "for verification", bundles marketing consent into the terms, and feeds a CRM that keeps everything forever. A consultant doesn't just flag it. We work out whether the NRIC is needed at all, split the marketing consent so it's optional, rewrite the notice so the purposes match what the business really does, and set a retention rule the CRM can enforce. Four obligations, one form, fixed in one pass.
PDPA compliance services
Pick one, or combine them. Most engagements start with a gap assessment or audit and pull in the rest where the findings point.
A structured baseline against every obligation in force. Tells you where you stand and what to fix first.
Evidence-based testing of whether your controls work, with risk-ranked findings and a follow-up review.
DPO role, accountability, reporting to management, complaints handling and policy ownership.
An inventory of what you hold, why, where it lives, who can see it and where it goes.
Data protection policy, notices, consent wording, access and correction procedures, retention schedule.
Assessment criteria, notification playbook, templates and a tabletop exercise against the three-day window.
Data intermediary contracts, vendor due diligence and safeguards for overseas transfers.
Data protection impact assessments for new systems, products or processing, following the PDPC's DPIA approach.
Hands-on help implementing fixes with your legal, IT, security and operations teams.
Short, role-based sessions for frontline, HR, marketing and IT staff, built from your own processes.
A consistent yearly check, plus reviews after major change, so drift gets caught early.
Penetration testing and vulnerability assessment to evidence the Protection Obligation, delivered under our Singapore CSRO licence.
Technical testing links: penetration testing · vulnerability assessment · web application security assessment.
PDPA obligations
These are the obligations as the PDPC names them. The middle columns are where audits are won or lost: what the obligation means day to day, and what evidence shows it's met. Exceptions apply to several obligations; the PDPC's advisory guidelines set them out.
| Obligation | What it means operationally | Example evidence | How we support |
|---|---|---|---|
| Accountability | Designate a DPO, publish their business contact details, develop and implement policies and practices, and have a complaints process. | DPO appointment, published contact, policy set, staff communication records | Governance review, policy gap check, DPO support |
| Notification | Tell individuals the purposes for collecting, using or disclosing their data, on or before collection. | Collection notices at each touchpoint, privacy statement | Notice review against actual processing |
| Consent | Collect, use or disclose data only with consent (or where an exception applies), and honour withdrawal. | Consent records, withdrawal log, form screenshots | Consent flow testing, withdrawal sampling |
| Purpose Limitation | Use data only for purposes a reasonable person would consider appropriate and that were notified. | Data map linking data to purposes | Purpose-to-use mapping |
| Access and Correction | Give individuals access to their data and how it was used or disclosed in the past year, and correct errors. | Request log, response times, sample responses | Procedure design, timeliness sampling |
| Accuracy | Make reasonable efforts to keep data accurate and complete where it's used for decisions or disclosed. | Validation checks, update processes | Process review |
| Protection | Make reasonable security arrangements against unauthorised access, collection, use, disclosure and similar risks. | Access reviews, encryption, logging, test results | Control review, penetration testing |
| Retention Limitation | Stop retaining data, or dispose of it properly, once there's no business or legal purpose. | Retention schedule, deletion logs, disposal records | Retention testing on live data |
| Transfer Limitation | Transfer data overseas only with protection comparable to the PDPA, as prescribed by regulations. | Transfer register, contract clauses, vendor assessments | Transfer review, clause review |
| Data Breach Notification | Assess suspected breaches and notify the PDPC and, where required, affected individuals. | Incident register, assessment records, playbook | Playbook, templates, tabletop |
| Data Portability | Transmit data to another organisation on request, in a machine-readable format. | Not yet in force: takes effect when regulations are issued | Readiness planning only |
PDPA gap assessment
These get mixed up a lot, and some providers blur them on purpose. Here's the honest version. If you've never had an independent look, start with a gap assessment. If you've done the work and want proof it holds, go for an audit. If you want a public, recognised mark, that's DPTM, and an audit is good preparation for it.
| Attribute | Gap assessment | Compliance audit | DPTM certification | PDPC investigation |
|---|---|---|---|---|
| Purpose | Find out what's missing | Test whether controls work | Formal, voluntary certification | Enforcement after a complaint or breach |
| Who performs it | Consultant or internal team | Independent assessor (e.g. us) | IMDA-appointed certification body | The PDPC |
| Depth | Documents and interviews | Documents, interviews and sampled evidence | Assessment against SS 714:2025 | Whatever the PDPC requires |
| Output | Gap list and roadmap | Risk-ranked findings, remediation plan, re-test | Certificate and use of the DPTM logo, with annual surveillance audits | Decision, directions or financial penalty |
| Legally required? | No | No | No, voluntary | Not something you choose |
DPTM is a voluntary, enterprise-wide certification for organisations to demonstrate accountable data protection practices. Since July 2025 it has been part of the national Singapore Standards as SS 714:2025. Certification is carried out by certification bodies appointed by IMDA and overseen by the Singapore Accreditation Council, and certified organisations go through annual surveillance audits.
We are not a DPTM certification body and we don't award DPTM. What we can do is assess you against the PDPA beforehand so the certification audit doesn't turn up surprises. Details and the current list of certification bodies are on IMDA's DPTM page.
The PDPC's free PDPA Assessment Tool for Organisations gives you a quick self-check. It's a good way to see how far off you are. When you need someone to test the answers against evidence, that's where we come in.
Request a PDPA Gap AssessmentData protection governance
Under the Accountability Obligation, every organisation must designate at least one individual to be responsible for ensuring it complies with the PDPA, and make that person's business contact information available to the public. The PDPA doesn't prescribe a qualification. The role can sit with an employee or an outsourced provider, and designating a DPO doesn't move legal responsibility away from the organisation.
You'll also need data protection policies and practices, a way to communicate them to staff, and a process to receive and respond to complaints.
If you'd rather have the function covered externally, VISTA Infosec offers an outsourced DPO service. Either way, our audit checks whether the DPO arrangement actually works.
Personal data lifecycle
We audit along the lifecycle, because that's how data really moves and it's where handovers between teams break down.
Collect
Notification · Consent
Is the notice shown before collection? Is consent separate from terms?
Use
Purpose Limitation · Accuracy
Is data used only for the notified purposes? Is it accurate where it drives decisions?
Disclose
Consent · Transfer Limitation
Who receives it, under what contract, and in which country?
Protect
Protection
Who has access, how is it secured, and when was that last tested?
Respond
Access and Correction · Breach Notification
Can you answer a request or assess a breach on time, with records?
Retain & dispose
Retention Limitation
Is data actually deleted when the schedule says so?
Data breach preparedness
The three-day clock starts when you decide a breach is notifiable, not when it happened. That's why the assessment step matters: the PDPC expects it to be done quickly, and a documented assessment is what you'll be asked for.
STEP 1
Someone reports or detects an incident involving personal data. Your data intermediaries must tell you without undue delay.
STEP 2
Assess in a reasonable and expeditious manner: what data, how many people, how it happened, whether harm is likely.
STEP 3
Notifiable if it's likely to result in significant harm to individuals, or involves 500 or more people.
STEP 4
As soon as practicable, and no later than 3 calendar days after you determine it's notifiable.
STEP 5
Where significant harm is likely, notify affected individuals too, unless an exception applies.
We build the assessment criteria, decision log, notification templates and escalation path, then run a tabletop exercise against a scenario that fits your business. Read the PDPC's guide on managing and notifying data breaches for the official position.
Get Breach-ReadyThird parties and transfers
Most personal data in a modern Singapore business sits with someone else: a payroll provider, a cloud CRM, a marketing platform, a group company overseas. The PDPA still holds you responsible for data processed on your behalf.
We check that you know who processes personal data for you, that contracts set out protection, retention and breach-notice duties, and that you've done proportionate due diligence. Where it's useful, we fold this into your wider third-party risk management.
Typical finding: a marketing agency with full customer-list access and no data clauses in its contract.
Personal data can only be transferred overseas in line with the Transfer Limitation Obligation and its regulations, so that the recipient provides a standard of protection comparable to the PDPA. We map which systems send data abroad and check the legally enforceable obligations or other safeguards behind each one.
Also subject to GDPR or India's DPDP Act? We can map controls once across frameworks: see GDPR, DPDP and AuditFusion360.
From assessment to remediation
The most common failure we see isn't a bad audit. It's a good audit that sat in a drawer. So every engagement is set up to reach the Validate step, where we re-test the fixes and you get an updated report showing what's closed.
Scope and test against the obligations in force.
Document each gap with evidence.
Rank by risk to individuals and to you.
Fix with owners, dates and our help.
Re-test and update the report.
Periodic review and change triggers.
Deliverables
A two-page view for management and the board: overall position, top risks, what it'll take to fix.
Each gap mapped to the PDPA obligation and PDPC guidance it relates to, with the evidence we saw.
High, medium and low ratings, suggested owners and target dates, in a format you can track.
Specific comments on notices, consent wording, retention rules, vendor clauses and security controls.
Sequenced actions: quick wins first, structural changes planned, dependencies called out.
A re-test of the fixes and an updated report showing which findings are closed.
Why VISTA Infosec
We've spent 21+ years testing controls against standards like PCI DSS, SOC 2 and ISO 27001. That habit of asking for evidence is exactly what a PDPA audit needs.
Singapore engagements are contracted through VISTA Infosec Pte. Ltd., which holds a CSRO Penetration Testing Service Licence under the Cybersecurity Act 2018.
The Protection Obligation is where most PDPC enforcement lands. We can test the technical side ourselves, as a CREST-accredited firm, rather than taking a screenshot on trust.
Subject to GDPR, India's DPDP Act, MAS TRM or ISO 27001 too? We map shared controls once instead of auditing you four times.
We don't sell consent platforms or data-discovery tools, so our recommendations aren't shaped by a product.
Your engagement is run by VISTA Infosec staff. Team credentials include CISSP, CISA, CRISC and ISO 27001 Lead Auditor.
Financial institution? Our MAS TRM audit work often runs alongside PDPA. Pursuing ISO 27001? Many PDPA protection controls overlap.
Cost
We don't publish a price, because a 20-person agency with one CRM and a multi-entity group with overseas processing aren't the same job. What drives the effort:
Tell us a little about your organisation. We'll run a short scoping call, then send a fixed fee with a defined timeline, so there are no surprises halfway through.
Request a PDPA AssessmentFAQ
A PDPA compliance audit is an independent review of how your organisation actually collects, uses, discloses, protects, retains and transfers personal data, measured against the obligations in Singapore's Personal Data Protection Act 2012 and the PDPC's advisory guidelines. We look at your documents and at evidence of what really happens, then give you risk-ranked findings and a remediation plan. It's a private assessment you commission, not an inspection by the PDPC.
Typically your personal data inventory and data flows, notices and consent, purpose limitation, the DPO and accountability arrangements, access and correction handling, accuracy, security arrangements under the Protection Obligation, retention and disposal, data intermediaries and other third parties, overseas transfers, data breach assessment and notification procedures, and staff awareness. If you send marketing messages to Singapore telephone numbers, we can include Do Not Call checks. We agree the scope with you before fieldwork starts.
No. The PDPA doesn't require organisations to commission an audit, annual or otherwise. It does require you to meet the data protection obligations and, under the Accountability Obligation, to develop and implement the policies and practices needed to meet them. An independent audit is a practical way to check that those policies work in practice and to show your board, customers or the PDPC what you've done.
A PDPA consultant helps you work out what the Act means for your specific operations and then helps you put it right. In practice that means scoping which data and processes matter, mapping data flows, reviewing notices, consent and retention, designing breach-response and access-request procedures, advising your DPO, training staff and checking fixes once they're in. Good consultancy ends with things working, not just a report.
A gap assessment compares your current policies and practices with the PDPA to show what's missing, and it's usually the first step. An audit goes further and tests whether controls actually operate, using samples and evidence such as consent records, access-request logs, retention schedules and breach registers. Many organisations start with a gap assessment, remediate, then audit.
The PDPA applies to organisations that collect, use or disclose personal data in Singapore, including companies and non-profits, whether or not they are incorporated in Singapore. It generally doesn't apply to individuals acting in a personal or domestic capacity, employees acting in the course of their employment, or public agencies. Business contact information is also generally outside the data protection provisions.
Yes. The Accountability Obligation requires every organisation to designate at least one individual, commonly called the Data Protection Officer, to be responsible for ensuring it complies with the PDPA, and to make that person's business contact information available to the public. The DPO can be an employee or an outsourced provider, but the organisation stays responsible for compliance either way.
Once you have reason to believe a breach has occurred, you must assess it in a reasonable and expeditious manner. If it is notifiable, meaning it is likely to result in significant harm to affected individuals or involves 500 or more people, you must notify the PDPC as soon as practicable and no later than three calendar days after you determine it is notifiable. Where significant harm is likely, you must also notify the affected individuals, subject to limited exceptions.
No. PDPA compliance is a legal obligation for organisations within scope. The Data Protection Trustmark (DPTM), now the Singapore Standard SS 714:2025, is a voluntary enterprise-wide certification administered by IMDA and assessed by IMDA-appointed certification bodies, with annual surveillance audits. Certification can help you show accountable practices, but the PDPA doesn't require it.
No. There is no government-issued PDPA certificate, and we are not a DPTM certification body. What we issue is an assessment report under our own name. It states the scope, period and method, what we tested, what we found and what you should fix. If you want formal certification, DPTM through an IMDA-appointed certification body is the route, and our assessment can help you prepare for it.
The PDPA doesn't set a review frequency. We recommend a review at least once a year and whenever something significant changes, such as a new system, a new vendor handling personal data, an acquisition or a data breach. That's our recommendation, not a legal requirement.
It depends on scope. The main drivers are the number of business processes and systems that handle personal data, how many entities and locations are involved, the volume and sensitivity of the data, how many data intermediaries and overseas transfers you rely on, how mature your current programme is, and whether you want remediation support or technical testing added. We scope first and then give you a fixed-fee proposal.
Expert Auditors. Faster Certification.
European Operations
European engagements are delivered through Zulon Audits OÜ, the European practice of VISTA InfoSec.
Visit Zulon Audits →
VISTA InfoSec LLC,347 Fifth Ave,
Suite 1402-526, New York, NY 10016
© Copyright 2026. VISTA InfoSec. All Rights Reserved. | Disclosure Policy | Privacy Policy | Sitemap
Enquire Now
WhatsApp us