Himalaya's biggest live risk
Ilsa, the CRO, is thrilled: she is about to blast SMS and voice messages to all 8M end consumers to launch a new cross-sell. There are two problems. First, nobody can show how those consumers consented to marketing - the sign-up flow buried it in a checkbox that also gated the service. Second, nobody scrubbed the list against Singapore's Do Not Call registers. A direct competitor was fined weeks ago for exactly this. Today you fix the consent basis, the purpose, and the DNC flow before Ilsa's campaign leaves the building.
Consent, purpose, notification 8 min live
Three PDPA obligations sit under every marketing message. You may only collect, use, or disclose personal data for purposes a person consented to; those purposes must be ones a reasonable person would consider appropriate; and you must have notified the person of them at or before collection. Get one wrong and the whole campaign is unlawful, however good the copy is.
LiveThe Consent Obligation - and the right to withdraw3 min▶
The core PDPA rule: an organisation may only collect, use, or disclose personal data for purposes the individual has consented to (or where a PDPA exception applies). Consent is the default gate, and it is not a one-time trophy - it must be honoured over the whole life of the data.
The flip side is withdrawal. An individual can withdraw consent at any time, on reasonable notice. When they do, you must:
- Inform them of the likely consequences of withdrawing - for example, "you will stop receiving offers, but your account still works."
- Stop the relevant collection, use, or disclosure within a reasonable time, and cascade the stop to any downstream systems and vendors.
- Never make withdrawal harder than giving consent was - no burying the unsubscribe, no "call this hotline in office hours only."
Himalaya's sign-up trap. The consumer flow has one checkbox: "I agree to the terms and to receive offers." Ilsa treats every sign-up as marketing consent. But bundling service consent with marketing consent means the marketing consent was never freely, separately given - and there is no clean withdrawal path once an offer lands. Before any 8M blast, that single checkbox has to become a separate, unbundled marketing opt-in with a working "unsubscribe" that actually cascades to the SMS vendor.
LivePurpose Limitation + Notification3 min▶
Consent is only meaningful if the person knew what they were agreeing to, so two more obligations lock it in place.
- Purpose Limitation - you may only collect, use, or disclose personal data for purposes that a reasonable person would consider appropriate in the circumstances. "Because it might be useful later" is not a purpose. And you cannot require consent to more than is reasonably needed to provide a product or service as a condition of that service.
- Notification - you must inform the individual of the purposes at or before collection. No secret second uses. If a new purpose appears later, you notify and, usually, seek fresh consent.
Together these kill the two most common marketing sins: over-collecting "just in case," and quietly repurposing service data into a marketing list.
Himalaya's silent repurpose. Consumers gave their phone numbers so a booking could send them an SMS reminder - a service purpose. Ilsa now wants to use those same numbers for cross-sell marketing. That is a new purpose the reasonable consumer never agreed to, and it was never notified. You cannot fold "delivery reminders" into "marketing blasts" - the purpose does not stretch that far, and forcing it would breach both Purpose Limitation and Notification.
Self-studyDeemed consent + the PDPA exceptions2 min read▶
Consent does not always have to be a checkbox. The PDPA recognises deemed consent and a set of exceptions - but they are narrower than marketers wish.
- Deemed consent by conduct - if a person voluntarily provides data for an obvious purpose (handing over an address to get a delivery), consent for that purpose is deemed.
- Deemed consent by notification - you may notify the individual of a new purpose, give them a reasonable opt-out period, and proceed if they do not object. It requires an assessment that the new use is not likely to cause adverse effect - it is not a shortcut for marketing to a cold list.
- Legitimate interests and business improvement exceptions - allow certain uses without consent when the benefit outweighs adverse effect (legitimate interests) or for internal improvement of goods, services, and operations (business improvement). Direct marketing to consumers generally does not ride on these.
Rule of thumb for a DPO: deemed consent and the exceptions are for reasonable, expected uses - not a back door to skip a real marketing opt-in.
The DNC registry 7 min live
Consent gets you the right to market. The Do Not Call registry is a second, separate gate that sits on top: even with consent chains in place, before you send a telemarketing message to a Singapore number you must check whether that number is on the relevant register - unless a clear exemption applies.
LiveWhat the DNC is + the three registers3 min▶
The Do Not Call (DNC) registry lets any Singapore telephone-number holder opt out of unsolicited telemarketing. It is run by the PDPC and split into three separate registers, one per channel:
- No Voice Call register - telemarketing phone calls.
- No Text Message register - marketing SMS and MMS.
- No Fax Message register - marketing faxes.
Your obligation is a check-before-you-send duty: before sending a marketing message to a Singapore number, you must check the register that matches the channel and not send if the number is listed (unless an exemption applies). A confirmation of your check is valid for a set period, so a fresh scrub before each campaign is the safe habit.
Himalaya has never scrubbed. Ilsa's team pulls the full 8M list and hands it to the SMS and voice vendors - no register check at any point. For the Singapore numbers in that list, every message to a listed number is a separate breach. The fix is a mandatory DNC check step in the send pipeline: scrub against No Text Message for the SMS half and No Voice Call for the voice half, and drop listed numbers before the vendor ever sees them.
LiveThe exemptions - consent and ongoing relationship2 min▶
You do not always have to check the register. Two main exemptions let you send without a scrub - but each is narrower than it looks:
- Clear and unambiguous consent - if the individual has given clear, specific consent to receive your marketing messages on that channel, and has not withdrawn it, the register check is not required for that number. Weak, bundled, or assumed consent does not qualify.
- Ongoing relationship - you may send messages related to an existing, ongoing relationship (for example, to an existing subscriber about a similar product), within defined limits and only while that relationship is live. Every such message must still offer an easy opt-out.
For a DPO, the safe reading is: treat the register check as the default, and only skip it where you can evidence a qualifying exemption for that specific number and channel.
Self-studyGetting it wrong - the competitor's fine2 min read▶
The DNC rules have teeth. Sending marketing to a listed number without an exemption, or failing to check, exposes the organisation to enforcement action and financial penalties under the PDPA regime.
- Under the PDPA, financial penalties can reach up to S$1M, or 10% of annual Singapore turnover, whichever is higher - the same ceiling that backs the data-protection obligations.
- Enforcement is public: the PDPC publishes decisions, so a fine is also a reputational hit and a gift to competitors.
The reason you have a job this week. A direct Himalaya competitor was just penalised for blasting marketing SMS without checking the No Text Message register. Mara, the CEO, read the decision and does not want Himalaya's name in the next one. That single enforcement case is exactly why the board created your role - and why Ilsa's campaign cannot ship until the DNC step is real.
GDPR contrast for marketing 3 min live
Himalaya markets to EU consumers too, so hold up the mirror. The DNC registry is a Singapore-specific regime with no GDPR equivalent. Under GDPR, marketing is governed by the consent standard plus a right to object - not by a national opt-out list.
LiveGDPR consent + the absolute right to object3 min▶
GDPR does not run a do-not-call list. Instead it raises the bar on consent and hands the individual a powerful right to object:
- Valid consent must be freely given, specific, informed, and unambiguous - a clear affirmative act. Pre-ticked boxes and bundled consent do not count.
- The right to object to direct marketing is absolute. When a person objects, you must stop marketing to them, full stop - there is no balancing test to weigh against it.
- You must tell people about that right clearly, at the first communication at the latest.
Himalaya's EU consumers. There is no register for you to scrub in the EU - but the same bundled checkbox that fails PDPA consent also fails GDPR's "freely given, specific, unambiguous" test. And the moment an EU consumer clicks "stop these messages," their objection is final. Your fix for Singapore consent doubles as your fix for EU consent: one clean, unbundled opt-in that satisfies both rulebooks.
Fix Himalaya's 8M-consumer campaign ★ 19 min · on Himalaya
Ilsa wants to hit send this week. Your job is not to block her - it is to make the campaign lawful. We audit what she has, rebuild the consent and DNC flow, and hand her a checklist she must pass before a single message goes out. Follow along on Himalaya, then run the same steps on a campaign in your own organisation for homework.
Himalaya - B2B2C SaaS, Singapore-headquartered, 8M end consumers across SG, EU, and SE Asia. Ilsa (CRO) is launching an SMS + voice cross-sell to the entire consumer base. Consent was captured through one bundled sign-up checkbox that also gated the service; phone numbers were originally collected for booking reminders; no DNC register check has ever run; the SMS and voice vendors receive the raw list. A competitor was just fined for unchecked marketing SMS.
Audit the current flow. Write down how consent was captured (the bundled checkbox), and whether the purpose actually covers marketing (numbers were collected for booking reminders, not cross-sell). Name every gap you find.
Design the consent notice. Draft a separate, unbundled marketing opt-in: plain-language purpose, named channels (SMS, voice), and a note that declining does not affect the service. This is your Purpose Limitation + Notification fix.
Build the DNC check step. Insert a mandatory scrub before the vendor handoff: Singapore numbers in the SMS segment go against the No Text Message register; the voice segment against No Voice Call. Listed numbers are dropped unless a documented exemption applies.
Write the withdrawal mechanism. Every message carries an easy opt-out; the opt-out cascades to the vendor and the warehouse within a reasonable time, and the consumer is told the consequence ("you will stop getting offers; your account is unaffected").
Produce the go/no-go checklist. One page Ilsa must sign off before sending: consent unbundled and evidenced, purpose covers marketing, DNC scrub done per channel, exemptions documented, withdrawal working, EU segment on the same clean opt-in.
Try it yourself - this week ◐ 30-45 min total
- Take one real marketing message your organisation sends. Trace its consent basis: where was consent captured, was it bundled with anything, and can you evidence it per recipient?
- Check whether a DNC scrub happens before that message goes out, and against which register(s). If the answer is "we assume everyone consented," you have found a live risk.
- Find the withdrawal path a recipient would use. Time how many clicks it takes and whether it actually cascades to your vendor. Note anything harder than the opt-in was.
- For any EU recipients, confirm the same consent would pass GDPR's "freely given, specific, informed, unambiguous" test - and that a right-to-object works.
- Optional: run the pre-campaign checklist prompt on a real (described, not pasted) campaign and bring the go/no-go verdict to Session 5.
What this session covers
This session teaches the working content of the obligations and rules below. Certification exams, member-only frameworks, and legal advice stay with their official sources - this page makes you fluent in the body of knowledge, honestly flagged where depth lives elsewhere.
Three questions before you go 🎯 ◐ 90 seconds
1 · You are about to send a marketing SMS to Singapore numbers. When do you check the DNC register?
The DNC duty is a check-before-you-send obligation, per channel. You scrub against the relevant register first, not after.
2 · A consumer wants to stop your marketing. What must the consent flow allow?
Consent must allow withdrawal at any time. You explain the consequences and then stop the use within a reasonable time.
3 · Himalaya markets to EU consumers. Which is true about the DNC registry there?
The DNC registry is Singapore-specific. GDPR has no equivalent list - it governs marketing through the consent standard plus an absolute right to object.