Publications

How to appoint yourself as a Data Protection Officer

20 Jan 2026 4 min read Running the business Beginner

A working guide to the DPO role, appointment records and public contact details, with regulatory points flagged for verification.


Every business in Singapore, whether a start-up or an established SME, must protect the personal data it collects. The Personal Data Protection Act (PDPA) requires businesses to appoint a Data Protection Officer to oversee compliance.

If you are a business owner, you might wonder whether you can appoint yourself. You can. This is how.

What a DPO actually does

A Data Protection Officer is the person responsible for making sure your business follows the PDPA. The DPO manages how personal data is collected, used, stored and shared.

Personal data is broader than most people assume. It includes names, contact details, payment information and anything else that identifies a person.

The role exists to:

  • Ensure compliance with data protection law
  • Handle data access requests from customers or employees
  • Respond to data breaches quickly and properly
  • Show customers that their information is taken seriously

Without a DPO you risk investigations, financial penalties and reputational damage. For a start-up or SME with limited resources, any of those is expensive.

The five steps

1. Make the appointment official

Register yourself with PDPC through their Data Protection Officers page.

Then write a formal letter or internal memo recording the appointment. It should state:

  • Your full name and position
  • The date of appointment
  • Confirmation that you will handle all PDPA related duties

Keep it in your company records. If PDPC ever asks, this is the document that answers them.

2. List the personal data you collect

Write down every type of personal data your business holds. For most small businesses that is:

  • Customer names and contact details
  • Employee information
  • Payment and billing data
  • Email addresses collected for marketing

You cannot protect what you have not listed.

3. Write down your rules

A data protection policy does not need to be long. It needs to be real. The basics:

  • Collect data only with consent
  • Use data only for the purpose you stated
  • Store it securely, with password protection at minimum
  • Keep it only as long as necessary
  • Let individuals access their own data on request

4. Publish a privacy notice

Your customers and employees need to know how you handle their data. Cover:

What to stateWhy
What data you collectSo consent is informed
Why you collect itPurpose limitation
How you protect itDemonstrates the protection obligation
How long you keep itRetention limitation
How to contact the DPORequired for access requests

Put it on your website, or display it at your premises.

5. Make your DPO contact details public

This is the step most businesses miss. Provide at minimum an email address. A phone number and physical address are optional.

If someone cannot find how to reach your DPO, you have not satisfied the obligation.

The five duties, in plain terms

Consent. Get clear permission before collecting, using or sharing personal data. If you collect email addresses for delivery, you cannot then use them for marketing without fresh consent.

Purpose. Use data only for the reason you gave. Purposes do not quietly expand.

Protection. Keep data safe from theft, loss and unauthorised access. Strong passwords, encryption where it matters, and access limited to people who need it.

Retention. Keep data only as long as necessary. For customers, that is usually the contract period plus a reasonable window for legal and tax reasons. Then delete or anonymise.

Access. Individuals can ask what you hold about them. You must respond within 30 days and provide a copy if asked. You may charge a reasonable fee.

Handling a data access request

When someone asks to see their data:

  1. Verify their identity first. Handing data to the wrong person is itself a breach.
  2. Check your records.
  3. Provide it in a format they can actually read.
  4. Explain how you use it, if that is not obvious.
  5. Respond within 30 days.

Keep a log of every request and your response. It costs nothing and it is the first thing anyone will ask for.

If there is a breach

A data breach is any loss, theft, or unauthorised access to personal data. If it happens:

  • Contain it first. Stop further loss before anything else.
  • Notify affected individuals if the breach poses a risk of harm.
  • Report to PDPC where required.
  • Review what let it happen.

Why this is worth doing properly

Appointing a DPO shows customers and partners that you take data protection seriously. For a small business that is a competitive position, not just a compliance box.

The alternative is an investigation, a penalty, and a conversation with your customers that you would rather not have.

What to do next

Register the appointment, write the memo, publish the notice, put the contact details somewhere findable. That is an afternoon of work.

The harder part is the discipline afterwards: only collecting what you need, only keeping it as long as you need it, and actually answering access requests inside 30 days.


Written by JM Atelier. Published 20 Jan 2026. General information, not advice for your specific situation. Verify anything time-sensitive against the relevant authority before you act on it.

Running the business, how we help All publications

Would rather not do this yourself?

Tell us where you are and we will tell you what is actually required, including the parts you can skip.

Message us on WhatsApp Open Clair client portal