Use this checklist to prepare the facts, owners and evidence for a Singapore product launch. It is not a compliance certificate. The PDPC describes the PDPA as governing the collection, use, disclosure and care of personal data by organizations, among other provisions. Which obligations, exceptions and Do Not Call rules apply depends on the actual activity.

1. Name the accountable organization and owner

  • Confirm that the organization has designated at least one data protection officer (DPO) and made the DPO's business contact information publicly available. Record the selected publication route and the person responsible for keeping it current. The PDPC getting-started page, published 1 September 2026, states that appointing a DPO is mandatory and presents PDPC registration or publication on the organization's own website as two ways to publish the contact details.
  • Identify each legal entity collecting, using, disclosing or controlling the relevant personal data.
  • Record the person responsible for data-protection questions, their contact route and their authority to obtain answers from product, security, sales, support, HR and vendors.
  • Map the customer contract, privacy notice and vendor-contract chain to the entity that actually operates the service.
  • Give the launch a named business owner and a date for unresolved privacy decisions.

Evidence to keep: an entity-and-role map, responsibility matrix, public contact wording and approval record. The PDPC's Data Protection Management Programme guide is a useful official reference for governance, policies, operational processes and ongoing review.

2. Build a personal-data inventory around purposes

For each material product, sales, support, employment, analytics and marketing flow, record:

  • the people affected and the personal-data fields involved;
  • the purpose for collecting, using or disclosing each category;
  • the source, receiving entity, system, vendor and human access path;
  • storage and support locations, including overseas access;
  • the retention trigger, period, deletion action and owner;
  • whether the data is needed for launch or is collected only as a convenience.

Compare the inventory with live screens, forms, event payloads, sales processes and vendor settings. A policy should not be the only evidence of what the product does. The PDPC's Data Protection Management Programme guide provides the separate governance and process reference for this inventory work.

3. Connect notice, consent and other relied-on routes to the flow

  • Record what individuals are told, when they see it and which entity is speaking.
  • Identify the operational route relied on for each purpose rather than using one label for the whole product.
  • Test withdrawal and preference changes from the user request through downstream systems.
  • Separate direct-marketing phone and message activity so the team can assess Do Not Call requirements where relevant.
  • Flag any new purpose, data field, audience or disclosure that is absent from the current notice or operating record.

Evidence to keep: current notices, screen captures, consent or preference records, suppression logic, purpose-to-field mapping and approvals for material changes.

4. Map vendors and overseas transfers

  • List cloud, analytics, support, communications, payment, HR and AI providers that can receive or access personal data.
  • Record the provider's legal entity, service, purpose, locations, subprocessor chain and contract owner.
  • Collect data-processing terms, transfer provisions, security evidence, incident contacts, retention and deletion commitments.
  • Identify parent-company, affiliate and remote-support access separately from primary storage.
  • Test whether the vendor can meet the product's access, correction, export, incident and deletion workflow.

A regional account setting does not establish every storage, support or administrative-access location. Keep the verified fact and its date; mark unknowns for review.

5. Test access, correction, retention and disposal as operations

  • Run a sanitized sample request across the main systems and vendors.
  • Record how identity is checked, who finds data, who approves the response and how exceptions are escalated.
  • Connect each retention period to a business or legal reason, a start trigger and a deletion action.
  • Include backups, logs, exports, dormant accounts and vendor copies in the disposal discussion.
  • Keep evidence of the completed test and every manual dependency.

The goal is not to claim that a product button completes the obligation. It is to show the end-to-end route, its owner and any gap that needs a fact-specific decision.

6. Verify security against the real system

  • Map access roles, privileged accounts, authentication, logging and periodic access review.
  • Record encryption, secrets handling, vulnerability and patch ownership, backup and restoration tests, and change controls.
  • Check data minimization in forms, events, logs and support tools.
  • Compare customer and vendor security promises with current evidence and product settings.
  • Assign an owner and deadline to each unresolved material control.

The PDPC's Data Protection Practices for ICT Systems compiles practices and lessons from breach cases, but it also makes clear that controls are not exhaustive and must fit the organization.

7. Prepare the breach route before launch

  • Define what staff and vendors should report, to whom and through which channel.
  • Preserve the discovery time, affected systems, data, people, countries, access path and containment evidence.
  • Name the technical, management, communications and data-protection decision owners.
  • Record how the organization will assess affected individuals, harm, scale and notification questions against current guidance.
  • Prepare regulator and individual contact information without pre-writing a conclusion or deadline that may not fit the facts.

Use the current PDPC breach-management guide when an incident occurs. A checklist should prepare the evidence and escalation route, not decide whether a particular event is notifiable.

8. Record the launch decision and maintenance owner

Before launch, create a one-page decision record containing the material facts, evidence links, accepted controls, unresolved questions, responsible approvers and next review date. Trigger a new review when the purpose, entity, data, vendor, location, audience or system materially changes.

Take the entity map, data inventory, notices and preference flows, vendor and transfer register, rights test, retention record, security evidence, breach plan and open-question list into review. Completing this list does not establish PDPA compliance, legal advice or PDPC endorsement; it makes the next business and professional decision better grounded.

Run the browser-based data compliance check to organize the current evidence, or review JurisLane's data and AI compliance preparation scope for a bounded next step.

Source review

The PDPC source set and live URLs above were checked on 2 September 2026. The getting-started page states a 1 September 2026 publication date. The ICT-systems PDF and other guidance remain source-specific starting points; their presence here does not make this checklist exhaustive or current legal advice.

Sources

Editorial note: This guide supports issue preparation and qualified review. Applicable requirements depend on the facts, entities, markets and current law.