Start with the data flow
- List business purposes and the people whose data is involved.
- Map collection points, systems, users, vendors, recipients, transfers, and retention.
- Link each activity to the current notice, consent or other basis, contract, security control, and owner.
- Keep a dated record of reviews, incidents, requests, decisions, and remediation.
Questions for the file
| Area | What to establish |
|---|---|
| Collection and use | What data is collected, for which purpose, and what notice or authority supports it? |
| Vendors and transfers | Which service providers or overseas recipients receive data, and what contract and safeguards apply? |
| Security and incidents | Which controls protect the data, and how are suspected incidents assessed and recorded? |
| Retention and access | How long is data kept, who may access it, and how are correction, access, and deletion requests handled? |
Official Singapore starting points
Use current Singapore authority pages and the organization's own documents before relying on a general summary.
Important limit
This page is a records guide, not a conclusion that an organization complies with Singapore law or any sector-specific, employment, financial, health, communications, or cross-border rule.
Before sharing records
- Keep originals in a controlled file and review a clearly dated working copy.
- Redact sensitive data unless the recipient is authorized and needs it.
- Label each document with its date, parties, version, jurisdiction, and status.
- Ask one focused question and identify the desired business outcome.