You don't need to read the statute
Nobody is asking you to read the Personal Data Protection Act. You need the shape of the rules your company must live by - and the shape fits in one session: the PDPA in one page, GDPR in five minutes, and the marketing rule that fines companies so regularly it is practically a subscription. Last session you learned what ungoverned data costs. This session you learn what, exactly, the law thinks you promised.
Eleven promises your company is already making 10 min live
Lawyers see eleven obligations. You should see eleven promises - things your company implicitly tells every customer the moment it collects their data. Ten are live law today. The eleventh is signed but waiting. Here they all are, in the language you would actually use.
LiveThe promises, walked through5 min▶
Read the list as four groups and it stops being legal furniture:
- The deal promises (consent, purpose, notification): we told you what we're collecting, you agreed, and we won't quietly repurpose it. Most marketing trouble starts here.
- The care promises (access & correction, accuracy, protection): you can see your data, we keep it right, and we keep it safe. "Safe" means reasonable security actually in place - not a policy PDF.
- The lifecycle promises (retention, transfer): we delete it when the purpose is done, and if it crosses a border it stays just as protected on the other side.
- The grown-up promises (breach notification, accountability): when it goes wrong we own up on a clock, and at any moment we can prove we keep all the promises above - which is why the law makes a DPO mandatory.
And the eleventh - portability, letting people take their data to a competitor - is enacted but not yet in force. Flag it in your planning; do not let a vendor sell you urgency on it.
Score Himalaya from your chair. Consent: murky at best across 8 million consumers. Purpose and notification: forms collecting data with no stated reason. Protection: a consumer table sat exposed for six days. Retention: "keep everything," including ex-clients' data. Accountability: no DPO until the board created one last quarter. Five promises broken before breakfast - and Himalaya is not unusual. That is why this list is worth one page of your attention.
Self-studyThe penalty math, one more time2 min read▶
From session 1, the number worth remembering: breaking these promises can cost up to S$1 million or 10% of your annual Singapore turnover, whichever is higher. Two details make it sharper:
- The regulator publishes its enforcement decisions. Your fine arrives with a public write-up of exactly what your company did wrong - a case study with your name on it, indexed forever.
- The percentage design means growth raises the stakes. Every quarter of revenue growth quietly raises your maximum exposure. The promises do not get cheaper to break as you scale; they get more expensive.
The DNC rule - the one that fines companies weekly 6 min live
Singapore keeps a Do Not Call registry - three registers, actually: no voice call, no text message, no fax. The rule is simple: before marketing to a Singapore phone number, check the register - unless you hold clear consent or an ongoing-relationship exemption applies. Simple, and yet it produces enforcement decisions with metronome regularity, because it fails quietly inside marketing operations where nobody senior is looking.
LiveWhy this rule belongs on your radar, not your lawyer's4 min▶
Here is the reframe that makes the DNC rule manageable: it is not a legal problem. It is a marketing process control - like a spend approval, except the thing being approved is whether a phone number may legally be contacted. The check is cheap, automated, and either wired into your campaign tooling or it is not. There is no sophisticated middle ground.
- The rule: check the relevant register before every voice, text, or fax marketing message to a Singapore number.
- The two ways around it: clear consent from the person, or the ongoing-relationship exemption for existing customers - both narrower than your marketing team will assume.
- The exec move: one question to your CMO - "do we scrub against the DNC before every campaign?" A confident "yes, it's automated, here's the log" ends the conversation. Anything else starts one.
Ilsa's 8-million-consumer problem. From your chair at Himalaya: your CRO's team blasts SMS and voice campaigns to the full consumer base with no DNC check and consent nobody can produce. A competitor was just fined for exactly this. Every campaign that goes out is a spin of the wheel - and the person who approved the campaign budget, not the marketing exec who pressed send, is who the board will look at. That would be you.
GDPR in five minutes 5 min live
Europe's GDPR runs to seven principles and ninety-nine articles. You need three ideas, one warning, and a comparison table - because if you have EU customers, this law already applies to you, no EU office required.
LiveThree ideas, real rights, long reach5 min▶
The whole regulation compresses, for executive purposes, into three ideas:
- Only collect what you need, for a purpose you stated. Data hoarding "in case it's useful later" is exactly the thing this law was written to stop.
- Keep it accurate, and no longer than needed. Storage limits are a legal duty, not a cost optimisation.
- Protect it - and be able to prove all of this. Same accountability idea as the PDPA: documentation, not good intentions.
Two things give GDPR its teeth. First, people hold real rights - to access their data, correct it, delete it, take it elsewhere, and object to how it's used - and your company must respond when they exercise them. Second, it travels: GDPR follows EU customers to wherever their data is processed. Himalaya's EU consumers put a Singapore warehouse squarely in scope.
| Exec question | PDPA (Singapore) | GDPR (EU) |
|---|---|---|
| Maximum penalty | S$1M or 10% of SG turnover | EUR 20M or 4% of global turnover |
| Breach clock | Assess in 30 days; notify PDPC in 3 days if notifiable | Notify the authority within 72 hours |
| DPO mandate | Every organisation, no exemptions | Only in 3 cases - but large-scale consumer platforms usually qualify |
| Reach | Organisations in Singapore | Follows EU customers anywhere in the world |
| Marketing regime | DNC registers - check before you send | Consent-first; pre-ticked boxes don't count |
The marketing campaign approval ★ 15 min · work it live
Back in Mara's chair at Himalaya. Ilsa wants sign-off on the biggest consumer campaign of the year - 8 million recipients, SMS and voice, launching Thursday. The deck is beautiful. Before you say yes, five questions - in this order.
1 · What's the consent basis? "Where did these people agree to hear from us - and can we produce that record?" A pass sounds like "consent captured at signup, records in the CRM." A red flag sounds like "they're our users, so..."
2 · Is this purpose covered? "Did we tell them we'd use their data for this?" Consent to a booking confirmation is not consent to a promo blast.
3 · Has the list been DNC-scrubbed? "Which register, when, and where's the log?" A date and a number is a pass. "The agency handles that" is a red flag wearing a lanyard.
4 · Is withdrawal easy? "Can someone opt out in one step, and does it actually stop the messages?" If unsubscribes take days to process, every extra send is a fresh violation.
5 · Who checked? "Which named person verified 1 through 4?" If the answer is a team, nobody checked. Confident, documented answers to all five: sign it. Anything else: the campaign waits, and that is the cheapest delay you will ever approve.
Three questions to ask this week ◐ 15 min total
- Ask your CMO the DNC question: "do we scrub against the DNC registers before every campaign?" Note whether the answer comes with a log or an adjective.
- Ask where consent records live. Not whether they exist - where. A location is an answer; "in the platform somewhere" is a finding.
- Spot one form or app screen in your own product that collects personal data with no purpose statement attached. There is almost always one. Bring it to Exec session 3.
What this session covers
Executive-level coverage, honestly flagged. Your practitioners get the full treatment in the 8-session DPO track on this site - the obligations in session 2, the marketing mechanics in session 4.
Three questions before you go 🎯 ◐ 90 seconds
1 · When must a company check the DNC registers?
The check comes BEFORE sending, every time - there is no size threshold, and "we'll fix it if someone complains" is how the weekly fines happen.
2 · Which PDPA promise is legislated but not yet in force?
Portability was enacted in the 2020 amendments but awaits regulations. The other ten obligations are live law today.
3 · Your company has no EU office. GDPR...
GDPR is extraterritorial - it attaches to the people, not the premises. EU consumers in a Singapore warehouse put that warehouse in scope.