learn-data-governance-with-phoebe / Exec session 1 of 4
Learn Data Governance with Phoebe · Executive track · Session 1 of 4

Why data governance is a board issue

The fine that can reach 10% of turnover, the officer the law says you must appoint, and the one test that tells you in thirty seconds whether your company's data is actually governed.

🟢 Exec track C-level & boards No tech required Singapore + EU 30 min self-read · 45 min live
0-3 · Welcome 3-25 · The three ideas 25-42 · The boardroom moment 42-45 · Q&A
Part 0

Why this track exists

Your data team has an 8-session deep track that turns a practitioner into a Data Protection Officer. This track is the other half of the deal: four short sessions that give the people who fund, sponsor, and answer for data - executives, boards, founders - the working ideas in plain language. No tooling, no legal jargon. Just what can go wrong, what the law expects of you personally, and the questions that make you the sharpest person in the room when data comes up.

Live - presented in session Self-study - read after class ★ Ask it in your next meeting PDPA-primary · GDPR mirror
★ What you walk out with today A clear-eyed read on what ungoverned data actually costs, why Singapore law makes a Data Protection Officer mandatory for your organisation (yes, yours), the thirty-second test for whether your data is governed, and a board-ready way to respond when an incident email lands. We follow one company, Himalaya, whose story you will recognise.
Part 1 · what ungoverned data costs

The bill arrives eventually 8 min live

Data risk feels abstract until it is a number with your company's name on it. There are four ways the bill arrives - only one of them is the regulator.

1 · The fine S$1M or 10% of SG turnover, whichever higher. GDPR: EUR 20M or 4% global. 2 · The trust hit Churn + headlines Customers leave quietly; the press release writes itself. 3 · The blocked deal Due diligence Enterprise buyers and investors now audit data practices first. 4 · The distraction Months of cleanup An incident consumes your best people for a quarter. The fine is the smallest of the four. Trust, deals, and time cost more - and no insurance covers them.
🔍 Click to zoom - the four ways the bill arrives
LiveMeet Himalaya - a story you already know3 min

Himalaya is a Singapore-based B2B2C SaaS platform: 1,200 business clients, 8 million end consumers, $40M ARR, growing fast. Like most growth companies, it collected data first and asked questions never. Then three things happened in one quarter:

  • A misconfigured export left consumer records - including health notes - exposed for six days before anyone noticed.
  • Marketing kept blasting SMS and voice campaigns to the 8M consumer base with no do-not-call check - the exact practice a competitor was just fined for.
  • When the CEO asked "what personal data do we actually hold?", nobody could answer. Not the CTO, not the data team. Forty-plus databases, no map.

The board's response was to appoint the company's first Data Protection Officer. This track shows you the story from the CEO's chair - what she should ask, fund, and expect.

Real world

The uncomfortable question: if a journalist called your office today and asked "what personal data do you hold on your customers, and who approved keeping it?" - could anyone in your company give a confident answer within the hour? At Himalaya the honest answer was no. In most companies it still is.

LiveThe numbers that concentrate the mind3 min

Two rulebooks matter to a Singapore company with international customers, and both carry real penalties:

RulebookWho it protectsMaximum penalty
PDPA (Singapore)Anyone whose personal data you hold in SingaporeS$1 million or 10% of Singapore turnover, whichever is higher
GDPR (EU)People in the EU - even if your company is notEUR 20 million or 4% of global turnover, whichever is higher

Note the design: both are percentage-of-turnover penalties. They are sized to hurt companies of every size, and "we are small" is not a defence - the PDPA applies to every organisation in Singapore, full stop.

The exec takeaway You do not need to memorise articles or clauses. You need to know the two rulebooks exist, that both can reach your P&L, and that the EU one follows your EU customers to wherever your servers are.
Self-studyWhy this landed on boards now2 min read

Three shifts pushed data governance from the IT basement to the board agenda:

  • The laws grew teeth. Singapore's PDPA gained its 10%-of-turnover penalty cap and mandatory breach notification. Regulators publish their enforcement decisions - your fine becomes a public case study.
  • AI raised the stakes. Every AI initiative is a data initiative. Boards approving AI budgets are, whether they know it or not, approving new ways to collect, combine, and expose personal data.
  • Buyers started asking. Enterprise procurement and investor due diligence now include data-protection questionnaires. A weak answer delays or kills deals - quietly, without ever making the news.
Part 2 · the officer the law requires

You are required to appoint a DPO 7 min live

Here is the fact that surprises most executives: under Singapore's PDPA, every organisation must designate a Data Protection Officer - no exemption for size, sector, or how little data you think you hold. The DPO's business contact must be publicly available. If you cannot name your DPO right now, that is action item one.

Advises Tells the business what the law expects before you act, not after. Watches Monitors compliance, runs training and audits. Your early alarm. Drills Assesses risky projects (incl. AI) and runs the breach playbook. Fronts Is the named contact for the regulator and for your customers. A good DPO is not the department of no - it is the person who lets you say yes safely, and prove it.
🔍 Click to zoom - what a DPO actually does for the executive team
LiveWhat the DPO needs from you3 min

Appointing a DPO is the easy half. The role only protects you if you set it up to work - and the setup is an executive decision, not an HR formality:

  • A real reporting line. The DPO should report to top management - you - not sit three layers down under a manager whose project they might have to flag.
  • Independence. Nobody instructs the DPO on how to judge a data question, and nobody penalises them for an unwelcome answer. A DPO who cannot safely say "not like that" to the CEO is decorative.
  • No conflict of interest. The person who owns the marketing database cannot also be the person judging whether the marketing database is lawful.
  • Actual resourcing. Time, budget, and access - not a title stapled onto someone's existing full-time job. (That last one is the most common failure, and regulators know it.)
Real world

Himalaya's choice. The board briefly considered giving the DPO title to the Head of Platform - the person who runs the very databases a DPO must scrutinise. Classic conflict. They appointed an independent DPO reporting to the CEO instead, and the first thing that DPO produced was a list of risks the platform team had normalised for years.

Self-studyThe EU mirror, in one paragraph1 min read

The GDPR only requires a DPO in three cases: public bodies, companies doing large-scale systematic monitoring of individuals, and companies processing sensitive data at scale. A consumer platform watching millions of users typically qualifies. The practical read for a Singapore company: PDPA obliges you to have a DPO anyway, so the GDPR question is not "do we need one" but "does ours also cover our EU exposure". One good appointment answers both.

Part 3 · what "governed" actually means

The thirty-second governance test 7 min live

Strip away the frameworks and data governance is three questions about any dataset your company holds. If your organisation can answer all three with names and documents - not shrugs - your data is governed. If not, not. It really is that simple, and that hard.

1 · Who decides what happens to this data? Pass: a named owner. Fail: "the pipeline was built that way." 2 · What are the rules, and are they enforced? Pass: a policy people actually follow. Fail: a document nobody has opened since it was written. 3 · Who answers when it goes wrong?
🔍 Click to zoom - the thirty-second test: decision rights, enforcement, accountability
LiveGovernance is deciding, not doing3 min

Executives often hear "we have access controls and a data warehouse" as an answer to the governance question. It is not. That is data management - the doing. Governance is the deciding: who is allowed to make calls about data, what rules bind those calls, and who is accountable for the outcome.

The industry's standard map (DAMA) draws governance as the hub of a wheel with ten capability spokes around it - security, quality, catalogs, and so on. You do not need the spokes. You need the hub insight: capabilities without decision rights are just expensive tools.

Real world

The shrug test at Himalaya. The CEO asked "who decided we keep ex-clients' consumer data forever?" The room went quiet. Nobody had decided - it just accumulated. That silence is what ungoverned looks like from the top: not chaos, just an absence of anyone deciding. Every company has these silences; governance replaces them with names.

Self-studyWhat the deep track builds (so you know what you're funding)2 min read

When you fund a governance program, here is what your team actually builds - each is a session in the practitioner track:

ArtifactWhat it gives you
Data inventory + record of processingThe confident answer to "what do we hold and why"
Consent + do-not-call fixMarketing that cannot trigger a fine
Breach playbookA drilled response instead of a panic, on a legal clock
Retention schedule + transfer registerData deleted on purpose, moved across borders lawfully
Operating model (owners, stewards, council)Governance that survives any one person leaving
The boardroom moment

The incident email lands. Now what? ★ 17 min · work it live

Put yourself in Mara's chair - Himalaya's CEO. It is 8:40am and this email is at the top of your inbox: "Potential data exposure identified - consumer records may have been accessible externally. Investigating. More by noon." What you do in the next hour sets the tone for everything that follows.

Do not improvise comms. Your first instinct - reassure clients fast - is the classic mistake. Facts first: what data, whose, how long, still exposed?

Put the DPO in the chair. One person runs the incident and owns the legal clock (in Singapore: assess within 30 days; if notifiable, the regulator hears within 3 days). Everyone else feeds them.

Ask the notifiability question early. "Is this likely to cause significant harm, or does it touch 500+ people?" - that single question tells you whether a regulator notification is coming.

Decide your posture once. Cooperative, factual, fast. Companies get punished less for breaches than for handling them badly.

Schedule the postmortem before the incident closes. The breach is also your once-a-year mandate to fund the fixes nobody wanted to prioritise.

★ Ask it in your next meeting - the incident rehearsal promptYou are my data protection adviser. Our company: [3-4 lines - what you do, roughly what customer data you hold, Singapore-based, any EU customers]. Walk me through a 45-minute tabletop exercise for this scenario: an internal alert says customer records may have been externally accessible for several days. Give me: 1. The first five questions I should ask my team, in order 2. Who should be in the room, and who runs it 3. The legal clocks that might start ticking (Singapore PDPA; GDPR if EU customers) 4. The three decisions that are mine alone as the executive 5. One paragraph I could honestly say to the board that afternoon Keep it plain language. Where facts are missing, list what you would need rather than guessing.
Why rehearse Every step above is obvious - after you have done it once. A one-hour tabletop a year buys you composure that cannot be bought during a real incident. Your DPO will happily run it; your job is to show up and take it seriously, because everyone else's seriousness is calibrated to yours.
Homework

Three questions to ask this week ◐ 15 min total

Source material

What this session covers

Executive-level coverage of the frameworks below - the working ideas, honestly flagged where depth lives elsewhere. Your practitioners get the full treatment in the 8-session DPO track on this site.

PDPA - penalties, mandatory DPO, accountabilityParts 1-2 · exec framing (pdpc.gov.sg)
GDPR - penalty scale + when a DPO is requiredParts 1-2 · the mirror (gdpr-info.eu)
DAMA-DMBOK2 - governance as the hubPart 3 · one insight; the wheel in DPO session 1
Breach notification mechanicsBoardroom moment · full clock in DPO session 5
Check yourself

Three questions before you go 🎯 ◐ 90 seconds

1 · Which Singapore companies must appoint a Data Protection Officer?

The PDPA's DPO mandate is universal - no size, sector, or data-volume exemption. The DPO's contact must also be public.

2 · "We have access controls and a warehouse" answers the governance question. True?

Governance = decision rights, enforced rules, accountability. Tools and controls are the doing that governance directs.

3 · The largest cost of a data incident is usually...

The fine is the smallest of the four bills - and the only one with a legal maximum. Trust, deals, and time have no cap.

Exec session 1 cheat sheet · pin this

The four billsFine · trust hit · blocked deals · distraction. The fine is the smallest.
The two rulebooksPDPA: S$1M or 10% SG turnover. GDPR: EUR 20M or 4% global - and it follows your EU customers.
DPO mandateEvery SG organisation must appoint one, contact public. If you can't name yours, that's action item one.
DPO setupReports to the top · independent · no conflicts · actually resourced. Decorative DPOs protect nobody.
Thirty-second testWho decides? What rules, enforced? Who answers? Names and documents = governed. Shrugs = not.
Governance vs managementDeciding vs doing. Capabilities without decision rights are expensive tools.
Incident hour oneFacts before comms · DPO in the chair · ask the notifiability question · pick a cooperative posture once.
The rehearsal ruleOne tabletop a year buys composure no budget can buy mid-incident.