This guide is for small law practices, accounting firms and corporate secretarial firms in Singapore. Firms like these hold more sensitive personal data than their size suggests: NRIC and passport copies for client due diligence, payroll and tax records, shareholder and director registers, and case files. It covers the PDPA only. Your professional body's rules on confidentiality and record keeping sit alongside it.
Does the PDPA apply to your firm?
Yes, if you collect, use or disclose personal data in Singapore, which every client-facing firm does. Size and headcount make no difference to whether the Act applies.
Two points change how it applies to professional services work.
- Business contact information is largely outside the Act. A client contact's work email and office number, given for business purposes, is excluded from most obligations. Their NRIC, home address, salary and family details are not.
- You may be a data intermediary for some clients. When an accounting or corporate secretarial firm processes personal data on a client's behalf, such as running payroll or keeping a register, it can be that client's data intermediary. Intermediaries carry the protection and retention obligations and must tell the client about a breach they detect.
The same logic runs the other way. Your cloud email, document storage and practice management vendors are your data intermediaries, and you remain accountable for the personal data they hold for you.
The PDPA obligations in plain English
The PDPC sets out the data protection obligations in full. For a small firm, they come down to this.
| Obligation | What it means for a small firm |
|---|---|
| Consent, purpose and notification | Tell clients why you collect their data, collect only what that purpose needs, and use it only for that purpose. |
| Access and correction | Be able to tell a client what personal data you hold about them, and correct it when asked. |
| Accuracy | Take reasonable care that data you rely on is correct and complete. |
| Protection | Make reasonable security arrangements against unauthorised access, loss and misuse, including for data your vendors hold for you. |
| Retention limitation | Stop keeping personal data once you no longer need it for business or legal purposes, and dispose of it properly. |
| Transfer limitation | If data goes overseas, for example to a cloud service hosted abroad, make sure it is protected to a comparable standard. |
| Accountability | Appoint a DPO, write and follow data protection policies, and tell staff about them. |
| Data breach notification | Assess suspected breaches promptly, and notify the PDPC and affected people when the breach is notifiable. |
The penalties are set by the Act. The PDPC can impose a financial penalty of up to S$1 million, or 10 per cent of annual turnover in Singapore for organisations whose turnover there exceeds S$10 million, whichever is higher.
Appointing a Data Protection Officer
Every organisation must designate at least one person to be responsible for its PDPA compliance. The PDPC's DPO page is clear that this applies whatever the size of the organisation, and that the DPO's business contact details must be available to the public.
In a firm of five to fifty people, the DPO is usually a partner, a director or the office manager. It is a role, not a new hire. You can have an outside provider do the work, but the firm stays responsible, so someone inside it still needs to own the decisions.
A workable DPO brief for a small firm covers five things:
- Know what you hold. Keep a simple list of the personal data the firm collects, where it lives (email, shared drive, practice software, paper) and who can reach it.
- Own the policies. A short data protection policy, a retention schedule and a breach response plan, all written down and shown to staff.
- Answer requests. Be the published contact for client access and correction requests and complaints.
- Check the vendors. Know which providers hold client data for you and what their contracts say about security and breaches.
- Run the breach clock. Be the person who starts the assessment the day a suspected breach surfaces.
The PDPC also asks organisations to register their DPO's business contact details. The route has changed before, so use the current instructions on the PDPC's DPO page.
Breach notification: the 30-day and 3-day clocks
Since February 2021 the PDPA has carried a mandatory breach notification duty. The PDPC's Guide on Managing and Notifying Data Breaches sets out how the two clocks work.
- Assess within 30 calendar days. Once you have credible grounds to believe a breach has happened, you must take reasonable and expeditious steps to assess whether it is notifiable, within 30 calendar days. Document every step: the PDPC may ask for it.
- Decide whether it is notifiable. A breach is notifiable if it is likely to result in significant harm to the people affected, or if it affects 500 or more people. Regulations list the kinds of data deemed to cause significant harm; the PDPC's examples include credit card details and financial information such as wages, commission and bonuses.
- Notify the PDPC within 3 calendar days. Once you decide a breach is notifiable, notify the PDPC as soon as practicable and no later than 3 calendar days after that decision. The PDPC's own example: decide on 1 January, notify by 4 January.
- Tell the people affected. Where the breach is likely to cause them significant harm, notify them as soon as practicable, at the same time as or after you notify the PDPC.
For a professional services firm, the second step is rarely close. Client files routinely hold exactly the financial and identity information the regulations have in mind, so a compromised mailbox or a lost laptop can be notifiable on day one.
The breach most small firms meet first
It is usually ordinary: an email sent to the wrong client, a staff mailbox opened by a phishing link, or a laptop left in a taxi. Each one starts the 30-day clock. Firms that cope well have decided in advance who assesses, who calls the PDPC and who writes to clients.
What reasonable security looks like in a small firm
The Act does not list technical controls. It asks for arrangements that are reasonable for the data you hold, and client files in professional services are sensitive. In practice that means:
- Protection on every device. Anti-malware on each laptop and desktop, with updates switched on.
- Strong, separate logins. No shared accounts, a password manager, and two-factor authentication on email and cloud storage.
- Safer links and email. Blocking of known phishing and malicious sites, plus a check that your website and email domain are set up securely.
- People who know the tricks. Short, regular training on phishing and invoice scams, which target firms that move client money.
- Access that ends when people leave. A leaver's accounts closed on their last day.
- A rehearsed plan. A breach response plan someone has walked through at least once.
How StrongKeep helps, and what it does not do
StrongKeep is a self-serve platform for small firms without an IT team. The two plans map onto the obligations above.
- The Protection plan covers the security layer. Anti-malware and a web filter on every device, website and email security scans, a password manager, and cyber awareness and phishing training. A cyber crisis simulation and an incident diagnostic tool help you rehearse the breach clock before you need it.
- The Compliance plan adds the paperwork that shows it. Generated policies, evidence tracking, regular reminders and audit logs, so your DPO can show what was in place and when. It also guides you through CSA's Cyber Essentials, which an external assessor certifies, and through Data Protection Essentials (DPE). DPE is an IMDA and PDPC programme with a DPE logo as recognition. It is not a certification.
What StrongKeep does not do matters as much for a firm that holds privileged material. It does not read or inspect your documents or emails: it works from device and security logs. It does not act as your DPO or make the legal call on whether a breach is notifiable. And no tool can guarantee a breach will not happen; what it can do is make one less likely and leave you with the records to show you took reasonable care.
See StrongKeep for law firms, for professional services, or what each plan includes.
Frequently asked questions about the PDPA for professional services
Does a small law, accounting or corporate secretarial firm need a Data Protection Officer?
Yes. Section 11(3) of the PDPA requires every organisation to designate at least one person to be responsible for its compliance, whatever its size. It can be an existing partner, director or office manager, and their business contact details must be made available to the public.
Can we outsource the Data Protection Officer role?
You can have an outside provider carry out the work, but the firm stays responsible for complying with the PDPA. Someone inside the firm still needs to own the decisions and know where the records are.
How quickly do we have to report a data breach to the PDPC?
Once you have credible grounds to believe a breach has happened, you have up to 30 calendar days to assess whether it is notifiable. If it is, you must notify the PDPC as soon as practicable and no later than 3 calendar days after that determination. A breach is notifiable if it is likely to cause significant harm to the people affected, or if it affects 500 or more people.
Is Data Protection Essentials a certification?
No. Data Protection Essentials (DPE) is an IMDA and PDPC programme that helps small businesses put basic data protection and security practices in place, with a DPE logo as recognition. It is not a certification and it does not replace your PDPA obligations.
Sources are linked inline and were accessed on 2 October 2026. This guide is general information, not legal advice. Confirm current obligations with the PDPC or your own adviser.