PDPA compliance checklist for outsourced marketing teams
What "data intermediary" means for outsourced marketing
When a fractional marketer accesses your CRM, email list, or customer data on your behalf, the PDPA treats them as a data intermediary — an organisation processing personal data for another organisation. A data intermediary carries specific, direct obligations of its own: the Protection Obligation (reasonable security around the data) and the Retention Limitation Obligation (not keeping data longer than needed), plus a duty to notify you if it becomes aware of a data breach.
A practical checklist before engaging outsourced marketing help
- Get a written contract that specifically addresses data protection obligations — not just general service terms
- Define exactly what data access the placement needs, and provision only that — not broad access by default
- Confirm the breach notification process on both sides, including timelines
- Set clear retention and deletion terms for any data the placement handles
- Confirm your own Data Protection Officer contact is current and publicly available, as PDPA requires for every organisation regardless of size
The breach notification timeline to know
If a data breach is assessed as notifiable — generally because it causes significant harm or affects 500 or more individuals — organisations must notify Singapore's Personal Data Protection Commission (PDPC) within 3 calendar days of making that assessment. This applies regardless of whether the breach originated with your team or a data intermediary you've engaged.
Don’t have a DPO appointed yet?
A named external DPO and PDPC registration, live within 5 business days — no full-time hire required.
See DPO plans →Frequently asked questions
Does hiring a fractional marketer make them a data intermediary under PDPA?
Yes, if they access or process personal data on your behalf — they become directly responsible for the Protection and Retention Limitation obligations, while you remain accountable for the rest.
Do I still need a Data Protection Officer if I outsource marketing?
Yes — every organisation in Singapore must appoint a DPO and make their contact details publicly available, regardless of size or how much work is outsourced.
How fast do data breaches need to be reported?
Within 3 calendar days of assessing that a breach is notifiable to the PDPC — generally when it causes significant harm or affects 500 or more individuals.
- Personal Data Protection Act 2012 (Singapore), as amended by the Personal Data Protection (Amendment) Act 2020
- PDPC Guide on Data Protection Clauses for Agreements Relating to the Processing of Personal Data
- CMS Expert Guide to Data Protection and Cybersecurity Laws — Singapore chapter, 2025