learn-data-governance-with-phoebe / Session 4 of 8
Learn Data Governance with Phoebe · Session 4 of 8

Consent, purpose & marketing (DNC)

The single loudest live risk in the company: an 8M-consumer SMS and voice blast built on murky consent and no Do Not Call check. Today you fix consent, purpose, and the DNC flow before it goes out.

🟠 Getting real DA · DE · DS · AI DPO track PDPA consent + DNC 45 min
0-3 · The campaign 3-23 · Concepts (live cards) 23-42 · Build-along on Himalaya 42-45 · Q&A
Part 0

Himalaya's biggest live risk

Ilsa, the CRO, is thrilled: she is about to blast SMS and voice messages to all 8M end consumers to launch a new cross-sell. There are two problems. First, nobody can show how those consumers consented to marketing - the sign-up flow buried it in a checkbox that also gated the service. Second, nobody scrubbed the list against Singapore's Do Not Call registers. A direct competitor was fined weeks ago for exactly this. Today you fix the consent basis, the purpose, and the DNC flow before Ilsa's campaign leaves the building.

Live - presented in session Self-study - read after class ★ Do it now on Himalaya PDPA-primary · GDPR mirror
★ What you walk out with today A working grasp of the PDPA Consent, Purpose Limitation, and Notification obligations, a clear map of the DNC registry and when you must check it, a one-line read on why the DNC is Singapore-only while GDPR handles marketing through consent plus a right to object, and a go/no-go checklist Ilsa must pass before she sends anything. Cards marked "Live" are what we do together; "Self-study" cards give the full depth at your own pace.
Part 2 · covers the Do Not Call (DNC) Registry

The DNC registry 7 min live

Consent gets you the right to market. The Do Not Call registry is a second, separate gate that sits on top: even with consent chains in place, before you send a telemarketing message to a Singapore number you must check whether that number is on the relevant register - unless a clear exemption applies.

The three registers No Voice Call register No Text Message register No Fax Message register Check the register that matches your channel. Before you send Clear consent on file? Ongoing-relationship exempt? Check the register Yes → send allowed On the register? Yes = do not send Duty runs per channel: an SMS blast checks No Text Message; a voice campaign checks No Voice Call.
🔍 Click to zoom - the 3 registers and the pre-send decision flow
LiveWhat the DNC is + the three registers3 min

The Do Not Call (DNC) registry lets any Singapore telephone-number holder opt out of unsolicited telemarketing. It is run by the PDPC and split into three separate registers, one per channel:

  • No Voice Call register - telemarketing phone calls.
  • No Text Message register - marketing SMS and MMS.
  • No Fax Message register - marketing faxes.

Your obligation is a check-before-you-send duty: before sending a marketing message to a Singapore number, you must check the register that matches the channel and not send if the number is listed (unless an exemption applies). A confirmation of your check is valid for a set period, so a fresh scrub before each campaign is the safe habit.

Real world

Himalaya has never scrubbed. Ilsa's team pulls the full 8M list and hands it to the SMS and voice vendors - no register check at any point. For the Singapore numbers in that list, every message to a listed number is a separate breach. The fix is a mandatory DNC check step in the send pipeline: scrub against No Text Message for the SMS half and No Voice Call for the voice half, and drop listed numbers before the vendor ever sees them.

LiveThe exemptions - consent and ongoing relationship2 min

You do not always have to check the register. Two main exemptions let you send without a scrub - but each is narrower than it looks:

  • Clear and unambiguous consent - if the individual has given clear, specific consent to receive your marketing messages on that channel, and has not withdrawn it, the register check is not required for that number. Weak, bundled, or assumed consent does not qualify.
  • Ongoing relationship - you may send messages related to an existing, ongoing relationship (for example, to an existing subscriber about a similar product), within defined limits and only while that relationship is live. Every such message must still offer an easy opt-out.

For a DPO, the safe reading is: treat the register check as the default, and only skip it where you can evidence a qualifying exemption for that specific number and channel.

DPO instinct "We have consent" is a claim you must be able to prove per number, not a blanket to wave over 8M rows. If you cannot show where and how a number consented, treat it as no consent and scrub it.
Self-studyGetting it wrong - the competitor's fine2 min read

The DNC rules have teeth. Sending marketing to a listed number without an exemption, or failing to check, exposes the organisation to enforcement action and financial penalties under the PDPA regime.

  • Under the PDPA, financial penalties can reach up to S$1M, or 10% of annual Singapore turnover, whichever is higher - the same ceiling that backs the data-protection obligations.
  • Enforcement is public: the PDPC publishes decisions, so a fine is also a reputational hit and a gift to competitors.
Real world

The reason you have a job this week. A direct Himalaya competitor was just penalised for blasting marketing SMS without checking the No Text Message register. Mara, the CEO, read the decision and does not want Himalaya's name in the next one. That single enforcement case is exactly why the board created your role - and why Ilsa's campaign cannot ship until the DNC step is real.

Part 3 · covers the GDPR consent standard (mirror)

GDPR contrast for marketing 3 min live

Himalaya markets to EU consumers too, so hold up the mirror. The DNC registry is a Singapore-specific regime with no GDPR equivalent. Under GDPR, marketing is governed by the consent standard plus a right to object - not by a national opt-out list.

LiveGDPR consent + the absolute right to object3 min

GDPR does not run a do-not-call list. Instead it raises the bar on consent and hands the individual a powerful right to object:

  • Valid consent must be freely given, specific, informed, and unambiguous - a clear affirmative act. Pre-ticked boxes and bundled consent do not count.
  • The right to object to direct marketing is absolute. When a person objects, you must stop marketing to them, full stop - there is no balancing test to weigh against it.
  • You must tell people about that right clearly, at the first communication at the latest.
Real world

Himalaya's EU consumers. There is no register for you to scrub in the EU - but the same bundled checkbox that fails PDPA consent also fails GDPR's "freely given, specific, unambiguous" test. And the moment an EU consumer clicks "stop these messages," their objection is final. Your fix for Singapore consent doubles as your fix for EU consent: one clean, unbundled opt-in that satisfies both rulebooks.

Build-along · everyone builds

Fix Himalaya's 8M-consumer campaign ★ 19 min · on Himalaya

Ilsa wants to hit send this week. Your job is not to block her - it is to make the campaign lawful. We audit what she has, rebuild the consent and DNC flow, and hand her a checklist she must pass before a single message goes out. Follow along on Himalaya, then run the same steps on a campaign in your own organisation for homework.

Your company

Himalaya - B2B2C SaaS, Singapore-headquartered, 8M end consumers across SG, EU, and SE Asia. Ilsa (CRO) is launching an SMS + voice cross-sell to the entire consumer base. Consent was captured through one bundled sign-up checkbox that also gated the service; phone numbers were originally collected for booking reminders; no DNC register check has ever run; the SMS and voice vendors receive the raw list. A competitor was just fined for unchecked marketing SMS.

Audit the current flow. Write down how consent was captured (the bundled checkbox), and whether the purpose actually covers marketing (numbers were collected for booking reminders, not cross-sell). Name every gap you find.

Design the consent notice. Draft a separate, unbundled marketing opt-in: plain-language purpose, named channels (SMS, voice), and a note that declining does not affect the service. This is your Purpose Limitation + Notification fix.

Build the DNC check step. Insert a mandatory scrub before the vendor handoff: Singapore numbers in the SMS segment go against the No Text Message register; the voice segment against No Voice Call. Listed numbers are dropped unless a documented exemption applies.

Write the withdrawal mechanism. Every message carries an easy opt-out; the opt-out cascades to the vendor and the warehouse within a reasonable time, and the consumer is told the consequence ("you will stop getting offers; your account is unaffected").

Produce the go/no-go checklist. One page Ilsa must sign off before sending: consent unbundled and evidenced, purpose covers marketing, DNC scrub done per channel, exemptions documented, withdrawal working, EU segment on the same clean opt-in.

★ Do it now - the pre-campaign checklist promptYou are helping me, a Data Protection Officer in Singapore, vet a marketing campaign before it is sent. Campaign: [paste the Himalaya campaign summary above, or describe your own campaign in 4-5 lines]. Legal lens: PDPA-primary (Consent, Purpose Limitation, Notification, and the Do Not Call registry), with GDPR as a mirror for EU recipients. Produce a pre-campaign consent + DNC compliance checklist: 1. A table: check item | why it is required (obligation or register) | pass / fail / needs evidence | fix if failing 2. The DNC step spelled out: which register(s) to scrub for each channel, and the exemptions that would let me skip a number 3. A one-line go / no-go verdict, and the single biggest risk if we send today Flag anything you would need to confirm as an open question rather than assuming it is fine.
Data tip Do not paste the real 8M list into a practice chat. Describe its shape ("a list of consumer phone numbers and SG/EU region flags") and let the assistant reason about the flow. Scrubbing personal data out of your own tools is the Protection Obligation applied to you - Session 5's whole topic.
Homework

Try it yourself - this week ◐ 30-45 min total

Source material

What this session covers

This session teaches the working content of the obligations and rules below. Certification exams, member-only frameworks, and legal advice stay with their official sources - this page makes you fluent in the body of knowledge, honestly flagged where depth lives elsewhere.

Consent Obligation + withdrawalPart 1 · consent required; withdrawal on notice with consequences (pdpc.gov.sg)
Purpose Limitation + NotificationPart 1 · appropriate purpose; notify at/before collection; no excessive-consent condition
Deemed consent (incl. by notification)Part 1 · deemed consent + legitimate-interests / business-improvement exceptions
DNC - 3 registers + when to checkPart 2 · Voice / Text / Fax registers; check-before-send duty (pdpc.gov.sg)
DNC exemptions (ongoing relationship, clear consent)Part 2 · the two main exemptions, evidenced per number
ePrivacy / EU marketing rulesPart 3 · GDPR consent + right-to-object contrast only (gdpr-info.eu)
Check yourself

Three questions before you go 🎯 ◐ 90 seconds

1 · You are about to send a marketing SMS to Singapore numbers. When do you check the DNC register?

The DNC duty is a check-before-you-send obligation, per channel. You scrub against the relevant register first, not after.

2 · A consumer wants to stop your marketing. What must the consent flow allow?

Consent must allow withdrawal at any time. You explain the consequences and then stop the use within a reasonable time.

3 · Himalaya markets to EU consumers. Which is true about the DNC registry there?

The DNC registry is Singapore-specific. GDPR has no equivalent list - it governs marketing through the consent standard plus an absolute right to object.

Session 4 cheat sheet · pin this

Consent ObligationCollect / use / disclose only for consented purposes. Consent must be unbundled and freely given.
WithdrawalAllowed any time on reasonable notice. Explain consequences, then stop - and cascade to vendors.
Purpose LimitationOnly purposes a reasonable person finds appropriate. No excessive consent as a condition of service.
NotificationTell people the purpose at or before collection. New purpose = notify (usually re-consent).
Deemed consentBy conduct or by notification (opt-out window). Narrow - not a back door for cold marketing.
DNC 3 registersNo Voice Call · No Text Message · No Fax Message. Check the channel's register before sending.
DNC exemptionsClear unambiguous consent, or an ongoing relationship. Evidence it per number, or scrub.
GDPR mirrorNo DNC list. Consent = freely given / specific / informed / unambiguous; right to object is absolute.