learn-data-governance-with-phoebe / Exec session 2 of 4
Learn Data Governance with Phoebe · Executive track · Session 2 of 4

The rules in plain English

The eleven promises Singapore law makes on your behalf, the marketing rule that fines companies weekly, and the five minutes of GDPR you actually need. No statute reading required.

🟢 Exec track C-level & boards No tech required PDPA + GDPR 30 min self-read · 45 min live
0-3 · Welcome 3-25 · The three rulebooks 25-42 · The boardroom moment 42-45 · Q&A
Part 0

You don't need to read the statute

Nobody is asking you to read the Personal Data Protection Act. You need the shape of the rules your company must live by - and the shape fits in one session: the PDPA in one page, GDPR in five minutes, and the marketing rule that fines companies so regularly it is practically a subscription. Last session you learned what ungoverned data costs. This session you learn what, exactly, the law thinks you promised.

Live - presented in session Self-study - read after class ★ Ask it in your next meeting PDPA-primary · GDPR mirror
★ What you walk out with today The eleven PDPA obligations translated into promises you would recognise from any handshake deal, the one question to ask your CMO before the next campaign goes out, a four-line version of GDPR that covers what an executive needs, and a five-question checklist for signing off any marketing campaign without signing up for a fine.
Part 1 · the PDPA in one page

Eleven promises your company is already making 10 min live

Lawyers see eleven obligations. You should see eleven promises - things your company implicitly tells every customer the moment it collects their data. Ten are live law today. The eleventh is signed but waiting. Here they all are, in the language you would actually use.

Consent We only use data people agreed to give us. Purpose limitation And only for what we said we'd use it for. Notification We tell people what we collect and why, up front. Access & correction People can see their data and fix what's wrong. Accuracy We keep it right before we act on it. Protection We keep it safe - real security, actually in place. Retention limitation We don't keep it forever. Transfer limitation It stays protected wherever in the world we send it. Breach notification When it goes wrong, we own up - on a legal clock. Accountability We can prove all of the above. And we have a DPO. Data portability People can take their data with them. enacted - not yet in force Ten promises are live law today. The eleventh - portability - is enacted but waiting for regulations. Don't let anyone tell you it is already in force.
🔍 Click to zoom - the eleven PDPA obligations, translated into promises
LiveThe promises, walked through5 min

Read the list as four groups and it stops being legal furniture:

  • The deal promises (consent, purpose, notification): we told you what we're collecting, you agreed, and we won't quietly repurpose it. Most marketing trouble starts here.
  • The care promises (access & correction, accuracy, protection): you can see your data, we keep it right, and we keep it safe. "Safe" means reasonable security actually in place - not a policy PDF.
  • The lifecycle promises (retention, transfer): we delete it when the purpose is done, and if it crosses a border it stays just as protected on the other side.
  • The grown-up promises (breach notification, accountability): when it goes wrong we own up on a clock, and at any moment we can prove we keep all the promises above - which is why the law makes a DPO mandatory.

And the eleventh - portability, letting people take their data to a competitor - is enacted but not yet in force. Flag it in your planning; do not let a vendor sell you urgency on it.

Real world

Score Himalaya from your chair. Consent: murky at best across 8 million consumers. Purpose and notification: forms collecting data with no stated reason. Protection: a consumer table sat exposed for six days. Retention: "keep everything," including ex-clients' data. Accountability: no DPO until the board created one last quarter. Five promises broken before breakfast - and Himalaya is not unusual. That is why this list is worth one page of your attention.

Self-studyThe penalty math, one more time2 min read

From session 1, the number worth remembering: breaking these promises can cost up to S$1 million or 10% of your annual Singapore turnover, whichever is higher. Two details make it sharper:

  • The regulator publishes its enforcement decisions. Your fine arrives with a public write-up of exactly what your company did wrong - a case study with your name on it, indexed forever.
  • The percentage design means growth raises the stakes. Every quarter of revenue growth quietly raises your maximum exposure. The promises do not get cheaper to break as you scale; they get more expensive.
The exec takeaway You will never be asked to recite the eleven. You will be asked - by a buyer, an investor, or a journalist - whether your company keeps them. The one-page version above is enough to know whether the answer you're given is real.
Part 2 · the marketing rule

The DNC rule - the one that fines companies weekly 6 min live

Singapore keeps a Do Not Call registry - three registers, actually: no voice call, no text message, no fax. The rule is simple: before marketing to a Singapore phone number, check the register - unless you hold clear consent or an ongoing-relationship exemption applies. Simple, and yet it produces enforcement decisions with metronome regularity, because it fails quietly inside marketing operations where nobody senior is looking.

Campaign ready SMS or voice to SG phone numbers Clear consent, or ongoing relationship? for this exact channel OK to send consented or cleared numbers only Scrub the DNC registers no voice call · no text · no fax - every campaign, every time yes no number not listed The one question for your CMO: "do we scrub against the DNC before every campaign?"
🔍 Click to zoom - the before-you-send flow every SG campaign must pass
LiveWhy this rule belongs on your radar, not your lawyer's4 min

Here is the reframe that makes the DNC rule manageable: it is not a legal problem. It is a marketing process control - like a spend approval, except the thing being approved is whether a phone number may legally be contacted. The check is cheap, automated, and either wired into your campaign tooling or it is not. There is no sophisticated middle ground.

  • The rule: check the relevant register before every voice, text, or fax marketing message to a Singapore number.
  • The two ways around it: clear consent from the person, or the ongoing-relationship exemption for existing customers - both narrower than your marketing team will assume.
  • The exec move: one question to your CMO - "do we scrub against the DNC before every campaign?" A confident "yes, it's automated, here's the log" ends the conversation. Anything else starts one.
Real world

Ilsa's 8-million-consumer problem. From your chair at Himalaya: your CRO's team blasts SMS and voice campaigns to the full consumer base with no DNC check and consent nobody can produce. A competitor was just fined for exactly this. Every campaign that goes out is a spin of the wheel - and the person who approved the campaign budget, not the marketing exec who pressed send, is who the board will look at. That would be you.

Part 3 · the EU mirror

GDPR in five minutes 5 min live

Europe's GDPR runs to seven principles and ninety-nine articles. You need three ideas, one warning, and a comparison table - because if you have EU customers, this law already applies to you, no EU office required.

LiveThree ideas, real rights, long reach5 min

The whole regulation compresses, for executive purposes, into three ideas:

  • Only collect what you need, for a purpose you stated. Data hoarding "in case it's useful later" is exactly the thing this law was written to stop.
  • Keep it accurate, and no longer than needed. Storage limits are a legal duty, not a cost optimisation.
  • Protect it - and be able to prove all of this. Same accountability idea as the PDPA: documentation, not good intentions.

Two things give GDPR its teeth. First, people hold real rights - to access their data, correct it, delete it, take it elsewhere, and object to how it's used - and your company must respond when they exercise them. Second, it travels: GDPR follows EU customers to wherever their data is processed. Himalaya's EU consumers put a Singapore warehouse squarely in scope.

Exec questionPDPA (Singapore)GDPR (EU)
Maximum penaltyS$1M or 10% of SG turnoverEUR 20M or 4% of global turnover
Breach clockAssess in 30 days; notify PDPC in 3 days if notifiableNotify the authority within 72 hours
DPO mandateEvery organisation, no exemptionsOnly in 3 cases - but large-scale consumer platforms usually qualify
ReachOrganisations in SingaporeFollows EU customers anywhere in the world
Marketing regimeDNC registers - check before you sendConsent-first; pre-ticked boxes don't count
Where the depth lives This is deliberately the compressed version. Your practitioners get the full treatment - principles, lawful bases, all eight rights, and the marketing mechanics - in DPO sessions 2 and 4 on this site.
The boardroom moment

The marketing campaign approval ★ 15 min · work it live

Back in Mara's chair at Himalaya. Ilsa wants sign-off on the biggest consumer campaign of the year - 8 million recipients, SMS and voice, launching Thursday. The deck is beautiful. Before you say yes, five questions - in this order.

1 · What's the consent basis? "Where did these people agree to hear from us - and can we produce that record?" A pass sounds like "consent captured at signup, records in the CRM." A red flag sounds like "they're our users, so..."

2 · Is this purpose covered? "Did we tell them we'd use their data for this?" Consent to a booking confirmation is not consent to a promo blast.

3 · Has the list been DNC-scrubbed? "Which register, when, and where's the log?" A date and a number is a pass. "The agency handles that" is a red flag wearing a lanyard.

4 · Is withdrawal easy? "Can someone opt out in one step, and does it actually stop the messages?" If unsubscribes take days to process, every extra send is a fresh violation.

5 · Who checked? "Which named person verified 1 through 4?" If the answer is a team, nobody checked. Confident, documented answers to all five: sign it. Anything else: the campaign waits, and that is the cheapest delay you will ever approve.

★ Ask it in your next meeting - the campaign interrogation promptYou are my data protection adviser. I am an executive being asked to approve a consumer marketing campaign. Here are the details: [channel - SMS / voice / email; audience size and country mix; where the contact list came from; what the message offers]. Interrogate this campaign before I sign off: 1. Ask me the five approval questions one at a time (consent basis, purpose coverage, DNC scrub for Singapore numbers, ease of withdrawal, who verified) and evaluate each answer I give 2. Tell me which answers are passes, which are red flags, and why - in plain business language 3. Flag anything in Singapore's PDPA or DNC rules this campaign could breach, and what the realistic downside is 4. End with a clear recommendation: approve, approve with conditions, or hold - and the one-line reason I can give the marketing team Where my answers are vague, say so - do not fill gaps with optimism.
Why the order matters The five questions run from strategy to mechanics on purpose. If question 1 fails, the rest are moot - and you have learned in thirty seconds what a post-fine investigation would have told you in three months.
Homework

Three questions to ask this week ◐ 15 min total

Source material

What this session covers

Executive-level coverage, honestly flagged. Your practitioners get the full treatment in the 8-session DPO track on this site - the obligations in session 2, the marketing mechanics in session 4.

PDPA 11 obligations - the promise framingPart 1 · exec-level (pdpc.gov.sg); full depth in DPO session 2
DNC registry - 3 registers + before-you-send rulePart 2 · worked in detail in DPO session 4
GDPR principles + rights - compressed to 3 ideasPart 3 · full treatment in DPO sessions 2 and 4
Data Portability ObligationEnacted 2020, not yet in force - taught as pending, never as live
Check yourself

Three questions before you go 🎯 ◐ 90 seconds

1 · When must a company check the DNC registers?

The check comes BEFORE sending, every time - there is no size threshold, and "we'll fix it if someone complains" is how the weekly fines happen.

2 · Which PDPA promise is legislated but not yet in force?

Portability was enacted in the 2020 amendments but awaits regulations. The other ten obligations are live law today.

3 · Your company has no EU office. GDPR...

GDPR is extraterritorial - it attaches to the people, not the premises. EU consumers in a Singapore warehouse put that warehouse in scope.

Exec session 2 cheat sheet · pin this

The eleven, in one breathOnly what they agreed · only for what we said · kept right and safe · not forever · protected abroad · we own up on a clock · and we can prove it.
The penalty mathS$1M or 10% of SG turnover, whichever higher - and the PDPC publishes every enforcement decision.
The pending promiseData portability: enacted, not yet in force. Plan for it; don't panic over it.
The DNC ruleThree registers - voice, text, fax. Check before marketing to any SG number unless clear consent or ongoing relationship.
The CMO question"Do we scrub against the DNC before every campaign?" Accept a log, not an adjective.
GDPR in one lineCollect less, for a stated purpose, keep it briefly, prove compliance - and it follows EU customers anywhere.
Real rightsAccess, correction, deletion, portability, objection - people can make your company act, on a deadline.
The five campaign questionsConsent basis · purpose covered · DNC scrubbed · withdrawal easy · who checked. Documented answers or the campaign waits.