![]() |
| Image created with Microsoft Designer |
Back in August, I received an email from PDPC Singapore reminding me that my small company had yet to register a DPO with the Personal Data Protection Commission (PDPC).
Since I run a one-person business, I wasn't exactly panicked. But something needed to be done, especially when I received the Final Reminder on 17th September. After all, it's mandatory for all organisations to appoint a DPO and make their business contact details publicly available. So, I decided to do it just to fulfil the requirement.
After giving it some thought, I realised that this wasn't just about ticking a box for compliance. It was actually an opportunity to learn something new.
Since I no longer work in the corporate world, I'm not always up to date with the latest regulatory changes. Understanding data protection and compliance has become a valuable skill, especially as businesses—big or small—handle more personal data. This felt like the perfect chance to stay current and gain insights into an important aspect of modern business.
Soon after receiving the email, I started getting marketing messages from agencies offering DPO-as-a-Service—basically outsourcing the role for a fee.
Out of curiosity, I reached out to a corporate secretary to inquire about the pricing. Unsurprisingly, the fees weren't cheap. That's when I had a thought: Could I appoint myself as the DPO?
I checked the official PDPC website (https://www.pdpc.gov.sg), which outlined the responsibilities of a DPO:
- Ensuring PDPA Compliance
- Fostering a Data Protection Culture within the organisation
- Handling Data Inquiries from customers or authorities
- Advising Management on data protection risks
- Liaising with PDPC when required
Since I was running a one-person business, I figured—why not? I could handle these responsibilities myself, and it wouldn't hurt to gain some knowledge along the way.
After registering, I was automatically a part of the DPO community, gaining access to benefits such as:
- Free access to workshops & resources
- Latest updates on PDPA & compliance
- Exclusive networking events with other DPOs
- Insights on data breaches & prevention strategies
I also plan to take the Fundamentals of the Personal Data Protection Act (2020) course soon, just to get a better grasp of the requirements.
So, here I am—officially my own DPO. What started as a compliance task has turned into a valuable learning opportunity. Let's see where this goes!
A Quick Disclaimer
This is based on my personal experience and understanding of the DPO registration process. If you're running a business and need to register, I'd recommend checking official sources for the most accurate and up-to-date requirements. You can visit:
At the end of the day, what seemed like just another admin task turned out to be a chance to learn and stay updated—which, for a one-person business like mine, is always a plus.
Let's see where this new responsibility takes me!
May x

No comments:
Post a Comment