Why this track exists
Your data team has an 8-session deep track that turns a practitioner into a Data Protection Officer. This track is the other half of the deal: four short sessions that give the people who fund, sponsor, and answer for data - executives, boards, founders - the working ideas in plain language. No tooling, no legal jargon. Just what can go wrong, what the law expects of you personally, and the questions that make you the sharpest person in the room when data comes up.
The bill arrives eventually 8 min live
Data risk feels abstract until it is a number with your company's name on it. There are four ways the bill arrives - only one of them is the regulator.
LiveMeet Himalaya - a story you already know3 min▶
Himalaya is a Singapore-based B2B2C SaaS platform: 1,200 business clients, 8 million end consumers, $40M ARR, growing fast. Like most growth companies, it collected data first and asked questions never. Then three things happened in one quarter:
- A misconfigured export left consumer records - including health notes - exposed for six days before anyone noticed.
- Marketing kept blasting SMS and voice campaigns to the 8M consumer base with no do-not-call check - the exact practice a competitor was just fined for.
- When the CEO asked "what personal data do we actually hold?", nobody could answer. Not the CTO, not the data team. Forty-plus databases, no map.
The board's response was to appoint the company's first Data Protection Officer. This track shows you the story from the CEO's chair - what she should ask, fund, and expect.
The uncomfortable question: if a journalist called your office today and asked "what personal data do you hold on your customers, and who approved keeping it?" - could anyone in your company give a confident answer within the hour? At Himalaya the honest answer was no. In most companies it still is.
LiveThe numbers that concentrate the mind3 min▶
Two rulebooks matter to a Singapore company with international customers, and both carry real penalties:
| Rulebook | Who it protects | Maximum penalty |
|---|---|---|
| PDPA (Singapore) | Anyone whose personal data you hold in Singapore | S$1 million or 10% of Singapore turnover, whichever is higher |
| GDPR (EU) | People in the EU - even if your company is not | EUR 20 million or 4% of global turnover, whichever is higher |
Note the design: both are percentage-of-turnover penalties. They are sized to hurt companies of every size, and "we are small" is not a defence - the PDPA applies to every organisation in Singapore, full stop.
Self-studyWhy this landed on boards now2 min read▶
Three shifts pushed data governance from the IT basement to the board agenda:
- The laws grew teeth. Singapore's PDPA gained its 10%-of-turnover penalty cap and mandatory breach notification. Regulators publish their enforcement decisions - your fine becomes a public case study.
- AI raised the stakes. Every AI initiative is a data initiative. Boards approving AI budgets are, whether they know it or not, approving new ways to collect, combine, and expose personal data.
- Buyers started asking. Enterprise procurement and investor due diligence now include data-protection questionnaires. A weak answer delays or kills deals - quietly, without ever making the news.
You are required to appoint a DPO 7 min live
Here is the fact that surprises most executives: under Singapore's PDPA, every organisation must designate a Data Protection Officer - no exemption for size, sector, or how little data you think you hold. The DPO's business contact must be publicly available. If you cannot name your DPO right now, that is action item one.
LiveWhat the DPO needs from you3 min▶
Appointing a DPO is the easy half. The role only protects you if you set it up to work - and the setup is an executive decision, not an HR formality:
- A real reporting line. The DPO should report to top management - you - not sit three layers down under a manager whose project they might have to flag.
- Independence. Nobody instructs the DPO on how to judge a data question, and nobody penalises them for an unwelcome answer. A DPO who cannot safely say "not like that" to the CEO is decorative.
- No conflict of interest. The person who owns the marketing database cannot also be the person judging whether the marketing database is lawful.
- Actual resourcing. Time, budget, and access - not a title stapled onto someone's existing full-time job. (That last one is the most common failure, and regulators know it.)
Himalaya's choice. The board briefly considered giving the DPO title to the Head of Platform - the person who runs the very databases a DPO must scrutinise. Classic conflict. They appointed an independent DPO reporting to the CEO instead, and the first thing that DPO produced was a list of risks the platform team had normalised for years.
Self-studyThe EU mirror, in one paragraph1 min read▶
The GDPR only requires a DPO in three cases: public bodies, companies doing large-scale systematic monitoring of individuals, and companies processing sensitive data at scale. A consumer platform watching millions of users typically qualifies. The practical read for a Singapore company: PDPA obliges you to have a DPO anyway, so the GDPR question is not "do we need one" but "does ours also cover our EU exposure". One good appointment answers both.
The thirty-second governance test 7 min live
Strip away the frameworks and data governance is three questions about any dataset your company holds. If your organisation can answer all three with names and documents - not shrugs - your data is governed. If not, not. It really is that simple, and that hard.
LiveGovernance is deciding, not doing3 min▶
Executives often hear "we have access controls and a data warehouse" as an answer to the governance question. It is not. That is data management - the doing. Governance is the deciding: who is allowed to make calls about data, what rules bind those calls, and who is accountable for the outcome.
The industry's standard map (DAMA) draws governance as the hub of a wheel with ten capability spokes around it - security, quality, catalogs, and so on. You do not need the spokes. You need the hub insight: capabilities without decision rights are just expensive tools.
The shrug test at Himalaya. The CEO asked "who decided we keep ex-clients' consumer data forever?" The room went quiet. Nobody had decided - it just accumulated. That silence is what ungoverned looks like from the top: not chaos, just an absence of anyone deciding. Every company has these silences; governance replaces them with names.
Self-studyWhat the deep track builds (so you know what you're funding)2 min read▶
When you fund a governance program, here is what your team actually builds - each is a session in the practitioner track:
| Artifact | What it gives you |
|---|---|
| Data inventory + record of processing | The confident answer to "what do we hold and why" |
| Consent + do-not-call fix | Marketing that cannot trigger a fine |
| Breach playbook | A drilled response instead of a panic, on a legal clock |
| Retention schedule + transfer register | Data deleted on purpose, moved across borders lawfully |
| Operating model (owners, stewards, council) | Governance that survives any one person leaving |
The incident email lands. Now what? ★ 17 min · work it live
Put yourself in Mara's chair - Himalaya's CEO. It is 8:40am and this email is at the top of your inbox: "Potential data exposure identified - consumer records may have been accessible externally. Investigating. More by noon." What you do in the next hour sets the tone for everything that follows.
Do not improvise comms. Your first instinct - reassure clients fast - is the classic mistake. Facts first: what data, whose, how long, still exposed?
Put the DPO in the chair. One person runs the incident and owns the legal clock (in Singapore: assess within 30 days; if notifiable, the regulator hears within 3 days). Everyone else feeds them.
Ask the notifiability question early. "Is this likely to cause significant harm, or does it touch 500+ people?" - that single question tells you whether a regulator notification is coming.
Decide your posture once. Cooperative, factual, fast. Companies get punished less for breaches than for handling them badly.
Schedule the postmortem before the incident closes. The breach is also your once-a-year mandate to fund the fixes nobody wanted to prioritise.
Three questions to ask this week ◐ 15 min total
- "Who is our DPO?" - and is their business contact publicly available, as the PDPA requires? If the answer takes more than a day to come back, you have learned something important.
- "When did we last rehearse a data incident?" - if the answer is never, put the tabletop prompt above in front of your leadership team.
- Run the thirty-second test on the one dataset that would embarrass you most in a headline: who decides, what rules, who answers. Bring the shrugs to Exec session 2.
What this session covers
Executive-level coverage of the frameworks below - the working ideas, honestly flagged where depth lives elsewhere. Your practitioners get the full treatment in the 8-session DPO track on this site.
Three questions before you go 🎯 ◐ 90 seconds
1 · Which Singapore companies must appoint a Data Protection Officer?
The PDPA's DPO mandate is universal - no size, sector, or data-volume exemption. The DPO's contact must also be public.
2 · "We have access controls and a warehouse" answers the governance question. True?
Governance = decision rights, enforced rules, accountability. Tools and controls are the doing that governance directs.
3 · The largest cost of a data incident is usually...
The fine is the smallest of the four bills - and the only one with a legal maximum. Trust, deals, and time have no cap.