Terms

The GDPRLocal Master Service Agreement and additional Terms herein govern our products, services and customer relationships.

There are no requirements to purchase services.  No credit card needed to sign up, and once registered services may be purchased and activated at any time.

Singapore DPO Services

This Schedule forms part of the Master Services Agreement (“Agreement”) between the Customer (acting in the capacity of “Organisation” under the PDPA) and GDPRLocal Ltd (“GDPRLocal”). It sets out the scope of Singapore Data Protection Officer services delivered by GDPRLocal in the appointed statutory role under section 11 of the Personal Data Protection Act 2012 of Singapore (“PDPA”). Terms used in this Schedule have the same meaning as in the Master Services Agreement.

In this Schedule: “PDPA” means the Personal Data Protection Act 2012 of Singapore, together with all subsidiary legislation, advisory guidelines and codes of practice issued by the Personal Data Protection Commission (“PDPC”) from time to time; “DPO” means the Data Protection Officer designated by the Organisation under PDPA §11; “PDPC DPO Register” means the register of Data Protection Officers maintained by the Personal Data Protection Commission of Singapore.

This Service is provided on an appointment-only basis with a limited monthly advisory allocation. Substantive PDPA compliance work, policy and procedure development, data subject inquiry handling, incident response, and substantive PDPC engagement fall outside the subscription and are available as Additional Services under §6.

1. Scope of Services

1.1 Appointment. With effect from the Service Start Date, the Customer appoints GDPRLocal to act as its Data Protection Officer for the purposes of section 11 of the PDPA. This Schedule constitutes the written designation of the DPO. The appointment does not transfer any Organisation obligation to GDPRLocal, does not confer authority to make substantive compliance decisions on the Customer’s behalf, and does not constitute legal advice or legal representation.

1.2 Included statutory role. As part of the subscription, GDPRLocal shall:

  • act as the appointed Data Protection Officer of record under PDPA §11 for the purposes of statutory identification;
  • provide the Customer with the designated DPO contact information for publication and for entry on the PDPC DPO Register (the Customer remains responsible for the register submission itself);
  • act as the first point of contact for communications received directly by the DPO from data subjects and from the PDPC, forwarding such communications to the Customer for handling in accordance with §2;
  • provide up to one (1) hour of general PDPA advisory support to the Customer’s designated contact per calendar month, in accordance with §1.3.

1.3 Monthly advisory allocation. The subscription includes up to one (1) hour of general PDPA advisory support per calendar month, provided by email or scheduled call. The allocation does not carry over to subsequent months, and does not accumulate. The allocation is limited to best-effort advisory guidance; it does not include incident response, substantive documentation drafting, PDPC investigation support, data subject inquiry handling, audit work, or any of the activities set out in §5. Time required beyond the monthly allocation, or for any activity outside the included scope, is available as an Additional Service under §6 and billed at the Professional Services Rate set out in the Rate Card.

1.4 PDPC Register listing. The Customer is responsible for submitting the DPO designation to the PDPC (whether via the PDPC’s business filing service or otherwise) and for maintaining that submission current. GDPRLocal will provide the designated DPO contact information required for the submission, and will notify the Customer of any change to the designated DPO contact within thirty (30) business days.

2. Independence and Professional Conduct

2.1 Professional independence. GDPRLocal shall perform the DPO role with reasonable care and skill and shall not accept instructions from the Customer in respect of the performance of tasks that would compromise the professional integrity of the DPO role or the requirements of the PDPA.

2.2 No delegation of the Customer’s statutory role. The designation of GDPRLocal as DPO does not relieve the Customer of any statutory responsibility under the PDPA. The Customer remains the Organisation for all purposes under the PDPA and retains sole operational responsibility for PDPA compliance, including for compliance with the Data Protection Provisions, the Do Not Call Provisions, and section 26 (transfers of personal data outside Singapore).

3. Service Levels

3.1 Response window. Within the monthly advisory allocation set out in §1.3, GDPRLocal shall aim to respond to the Customer’s designated contact within three (3) Singapore business days. Response windows apply to acknowledgement, not to substantive resolution of any matter.

3.2 First-response forwarding. Where GDPRLocal receives a communication from a data subject or the PDPC directed to the appointed DPO, GDPRLocal shall forward that communication to the Customer’s designated contact promptly, and typically within three (3) Singapore business days of receipt. Substantive handling of, and response to, the communication is the Customer’s responsibility.

3.3 Reasoned PDPC requests. Where GDPRLocal receives a request from the PDPC that specifies a deadline for response, GDPRLocal shall notify the Customer’s designated contact without undue delay and specify the deadline. If the Customer fails to provide the necessary information or instructions in time, GDPRLocal may (a) provide a holding acknowledgement to the PDPC, or (b) notify the PDPC that the matter is being forwarded to the Organisation. GDPRLocal shall not be responsible for missed deadlines caused by the Customer’s failure to provide timely information or instructions.

4. Customer Obligations

In addition to the obligations set out in MSA §6, the Customer shall:

4.1 provide GDPRLocal with a designated contact for the Service, together with such information, documents and cooperation as are reasonably necessary for GDPRLocal to perform the appointed DPO role;

4.2 submit and maintain the DPO designation on the PDPC DPO Register (or any successor register maintained by the PDPC) using the designated DPO contact information provided by GDPRLocal, and update the register promptly on any change notified by GDPRLocal;

4.3 retain sole operational responsibility for PDPA compliance, including without limitation for: compliance with the Data Protection Provisions and Do Not Call Provisions of the PDPA; the development, maintenance and implementation of policies and practices necessary to meet the Organisation’s PDPA obligations; the handling, assessment and response to access, correction and other data subject requests; the identification, containment, investigation, remediation and notification of data breaches and other data protection incidents; internal PDPA training and awareness; and cooperation with the PDPC in respect of any investigation, inquiry, direction or enforcement action;

4.4 comply with section 26 of the PDPA in respect of any transfer of personal data outside Singapore, and retain sole responsibility for putting in place the legally required standard of protection for such transfers;

4.5 promptly notify GDPRLocal of (a) any suspected or actual data breach; (b) any communication from the PDPC; (c) any material change to the Customer’s processing activities or business that would affect the DPO role; and (d) any litigation, enforcement, or regulatory proceeding relating to the Customer’s PDPA compliance;

4.6 respond promptly to communications forwarded by GDPRLocal and provide timely instructions and decisions necessary for the handling of such communications;

4.7 not take any action, or require GDPRLocal to take any action, that would (a) expose GDPRLocal to enforcement or regulatory sanctions other than as an unavoidable consequence of the appointed DPO role; (b) require GDPRLocal to make any inaccurate representation to the PDPC or any other authority; or (c) cause GDPRLocal to act in violation of Applicable Regulations.

5. Services Outside the Scope

5.1 The Services are limited to the appointed statutory role and the included advisory allocation described in §1. The Services do not include, and shall not be represented to third parties as including, any of the following (each an Additional Service under §6):

  • substantive PDPA compliance advisory work beyond the monthly one-hour allocation;
  • development, drafting, review, or implementation of policies, notices, procedures, registers, or other documentation;
  • assessment, handling, or response to data subject access, correction, withdrawal, or other requests;
  • data protection incident or breach response, including containment, investigation, remediation, notification, or engagement with the PDPC in respect of a breach;
  • substantive engagement with the PDPC beyond first-response forwarding under §3.2, including PDPC investigation support, direction response, or enforcement engagement;
  • data protection impact or risk assessments;
  • audits, gap analyses, or compliance readiness assessments;
  • data protection training, workshops, awareness programmes, or culture-building activities;
  • legal advice, legal opinions, or legal representation. Where legal advice is required, the Customer should seek independent legal counsel.

5.2 GDPRLocal does not assume management responsibility, operational control, or substantive decision-making authority in respect of the Customer’s PDPA compliance, all of which remain with the Customer as the Organisation.

5.3 GDPRLocal does not warrant that the Customer is, or will be, compliant with the PDPA. Compliance with the PDPA is the Customer’s sole responsibility.

6. Additional Services

6.1 Scope. The Services are limited to those set out in §1.

6.2 Additional Services. Where the Customer requires services outside the scope of §1 (including any of the items listed at §5.1), GDPRLocal shall notify the Customer in writing (email sufficient) together with a good-faith estimate of the additional time or cost involved. Additional Services shall not commence until authorised by the Customer in writing (email sufficient).

6.3 Billing. Additional Services authorised under §6.2 are billed at the applicable Professional Services Rate set out in the Rate Card, unless the parties expressly agree a different fee in writing prior to the work commencing.

6.4 Records. GDPRLocal maintains records of time and activity performed under the Service and any Additional Services, and shall make these available to the Customer on reasonable request.

7. Confidentiality (Service-specific supplement to MSA §7)

7.1 The parties acknowledge that GDPRLocal, in its capacity as appointed DPO, is subject to a duty of confidentiality in respect of information received in the performance of the DPO role. This duty operates independently of and in addition to the mutual confidentiality obligations in MSA §7. In particular:

  • GDPRLocal may disclose the Customer’s Confidential Information without prior consent where required to do so by the PDPC or by Applicable Regulations in the performance of the appointed DPO role;
  • GDPRLocal shall not be required to disclose to the Customer the identity of any individual who has provided information to the DPO where maintaining such confidentiality is required for the performance of the DPO role, including where a data subject or employee has raised a concern with the DPO in confidence; and
  • the Customer shall not instruct or request GDPRLocal to disclose the source of any information received in confidence in the exercise of the DPO’s functions. Any such instruction shall be void and of no effect.

8. Liability and Indemnity (Service-specific supplement to MSA §10 / §11)

8.1 Advisory nature. GDPRLocal’s role under this Schedule is limited to the appointed statutory function and the included advisory allocation. GDPRLocal does not warrant the Customer’s PDPA compliance and does not accept responsibility for any decision taken, or action performed, by the Customer on the basis of advice provided under the monthly allocation. The Customer retains sole operational responsibility for PDPA compliance as set out in §4.3.

8.2 Limitation of Liability (service-specific). Subject to §8.4, the aggregate liability of either party under this Schedule shall not exceed the total fees paid or payable by the Customer in respect of the Service in the twelve (12) month period immediately preceding the event giving rise to the claim. Neither party shall be liable for indirect, consequential, special, or punitive loss.

8.3 Customer responsibility. Without limiting §8.2, GDPRLocal shall have no liability for, and the Customer retains sole responsibility for: any financial penalty, direction, or sanction imposed on the Customer by the PDPC; any loss arising from the Customer’s failure to submit, maintain, or update the DPO designation on the PDPC DPO Register; any loss arising from the Customer’s failure to comply with the PDPA (including without limitation section 26 in respect of cross-border transfers); any loss arising from the Customer’s failure to notify a matter under §4.5; and any loss arising from GDPRLocal’s good-faith forwarding of communications to the Customer where the Customer failed to respond adequately.

8.4 Exclusions from Limitation. The cap in §8.2 does not apply to: liability for death or personal injury caused by negligence; fraud or fraudulent misrepresentation; or any other liability that cannot be limited by Applicable Regulations.

9. Term and Termination (Service-specific)

9.1 Term. This Schedule commences on the Service Start Date and continues for an initial term of twelve (12) months (the “Initial Term”), unless terminated earlier in accordance with this §9 or MSA §12. It auto-renews for successive twelve (12) month Renewal Terms unless a party gives written notice of non-renewal in accordance with §9.2.

9.2 Termination for Convenience. Notwithstanding MSA §12.3, either party may terminate this Schedule for convenience by providing at least thirty (30) days’ prior written notice to the other party by email, such notice to be effective prior to the start of the next monthly billing cycle.

9.3 Termination for statutory integrity. GDPRLocal may terminate this Schedule with immediate effect where (a) the Customer’s non-cooperation, non-compliance, or instructions would put GDPRLocal in an untenable position as the appointed DPO of record (including where continued performance would require GDPRLocal to act in violation of the PDPA or to make inaccurate representations to the PDPC); or (b) the Customer provides materially inaccurate information such that GDPRLocal cannot in good faith continue to hold itself out as the appointed DPO. The Customer accepts sole responsibility for any regulatory consequence arising from such a termination, including any resulting coverage gap on the PDPC DPO Register.

9.4 Consequences of Termination. On termination or expiry: GDPRLocal ceases holding out as the Customer’s DPO within five (5) Business Days; the Customer shall promptly update the PDPC DPO Register to remove the GDPRLocal designation and appoint a replacement DPO where required by the PDPA; and the Customer shall pay all outstanding fees and costs. Clauses 4.3, 7, 8, and this §9 survive termination.

Appendix to Schedule 7: Statement of Work (Singapore DPO Services)

This Statement of Work (“SOW”) is appended to and forms part of Service Schedule 7 (Singapore DPO Services), which in turn forms part of the Master Services Agreement between the Customer and GDPRLocal Ltd. Capitalised terms have the same meaning as in the Schedule or the Agreement.

The SOW is generated and recorded by GDPRLocal at the point of Service activation. Placeholder fields (highlighted below) are populated from the Customer’s account and the Service Activation Record.

1. Customer (Organisation) Details

Company Name[Company Name]
Registered address[Registered address]
Primary Contact[Contact Name]
Role[Contact Role]
Email[Contact Email]
Telephone[Contact Number]

2. Service Scope

TerritorySingapore (PDPA)
Statutory basisAppointment as Data Protection Officer under PDPA §11
Included subscriptionStatutory appointment + PDPC DPO contact information + first-response forwarding + up to 1 hour of general advisory support per calendar month (use-it-or-lose-it)
Business units / processing activities in scope[list of business units, functions or processing activities in scope of the appointed DPO role]
Scope exclusions (if any)[otherwise “none”]

3. Service Fees

All fees for this Service are set out in the MSA Rate Card. The Service comprises the following fee categories:

Singapore DPO subscriptionAs set out in the Rate Card. Payable monthly from the Service Start Date. Includes statutory appointment, PDPC DPO contact information, first-response forwarding, and up to 1 hour of general advisory per calendar month.
Additional Services (advisory beyond the 1-hour monthly allocation, incident response, policy work, DSAR handling, PDPC investigation support, and all other items listed at Schedule §5.1)At the Professional Services Rate set out in the Rate Card, subject to prior written authorisation under Schedule §6.
Billing cadence[monthly / annual]
CurrencyGBP, exclusive of VAT and any applicable taxes.

4. Designated Personnel

Appointed DPO (of record)GDPRLocal Ltd
Named individual performing the DPO role[Name to be notified on activation]
Registered address1st Floor Front Suite, 27-29 North Street, Brighton, England, BN1 1EB, United Kingdom
Emailcontact@gdprlocal.com
Tel+44 1772 217 800

The Customer shall use the above designated contact information for the PDPC DPO Register submission and for publication in the Customer’s privacy notices where required. GDPRLocal will notify the Customer of any change to the named individual within thirty (30) business days.

5. DPO Contact Details for Publication and PDPC Register

The Customer shall submit the following DPO designation to the PDPC DPO Register (or any successor register) and shall publish the DPO contact information in its privacy notices in accordance with the PDPA:

“Data Protection Officer (Singapore PDPA §11): GDPRLocal Ltd, 1st Floor Front Suite, 27-29 North Street, Brighton, England, BN1 1EB, United Kingdom. Contact: contact@gdprlocal.com, +44 1772 217 800.”

6. DPO Services and Deliverables

The table below sets out the DPO Service scope. Items marked “Included” fall within the subscription. Items marked “On demand” are Additional Services under Schedule §6, available at the Professional Services Rate on prior written authorisation.

ServiceDescriptionTimeline / Inclusion
Statutory appointmentFormal designation as the Customer’s Data Protection Officer under PDPA §11; provision of designated DPO contact informationIncluded / Ongoing
PDPC DPO Register listingGDPRLocal provides the designated DPO contact information; Customer submits and maintains the register entryIncluded / Ongoing
First-response forwardingReceive communications directed to the DPO from data subjects and PDPC; forward to the Customer within 3 Singapore business daysIncluded / Ongoing
Monthly advisory allocationUp to 1 hour of general PDPA advisory support per calendar month, use-it-or-lose-it, no carry-overIncluded / Monthly (1 hour cap)
Substantive PDPA advisory beyond 1 hourAdvisory support beyond the monthly allocationOn demand (Additional Service)
Policy and procedure developmentDrafting, review, or implementation of PDPA policies, notices, procedures, or registersOn demand (Additional Service)
Data subject inquiry handlingAssessment, handling, or response to access, correction, withdrawal, or other requestsOn demand (Additional Service)
Data breach / incident responseContainment, investigation, remediation, notification, and PDPC engagement in respect of a breachOn demand (Additional Service)
Substantive PDPC engagementPDPC investigation support, direction response, or enforcement engagement beyond first-response forwardingOn demand (Additional Service)
Data protection impact or risk assessmentsPDPA-focused impact or risk assessmentsOn demand (Additional Service)
Audits and gap analysesPDPA compliance readiness assessments, gap analyses, or internal audit supportOn demand (Additional Service)
Data protection training and cultureTraining, workshops, awareness programmes, culture-building activitiesOn demand (Additional Service)

7. Review of Services

This SOW may be reviewed and updated by written agreement between the parties where required to reflect material changes to the Customer’s processing activities, service requirements, or compliance priorities. Any such update will be recorded as a revised SOW associated with the Customer’s account.

8. Acceptance

This SOW is deemed accepted by the Customer at the moment of Service activation (whether via in-portal activation or written confirmation accepted by GDPRLocal).

▼  RATE CARD ENTRIES  ▼  COPY / PASTE INTO THE MSA RATE CARD  ▼

This section is not part of the Service Schedule. It sets out the pricing entries that need to be added to the MSA Rate Card so that the fee references in Schedule §6.2 and Appendix §3 resolve correctly. Copy the block below into the Rate Card as a new subsection under “Core Subscription Services”.

Singapore DPO Services (PDPA §11 Appointment)

ServiceFee
Singapore DPO subscription (statutory appointment + PDPC DPO contact information + first-response forwarding + 1 hour of general advisory per calendar month, use-it-or-lose-it)£150 / month
Additional Services (advisory beyond the monthly 1-hour allocation, or any item listed at Schedule §5.1)At the discounted Professional Services Rate already set out in the Rate Card

All fees exclusive of VAT and any applicable taxes.