Customer Data Was Stored Across Five Unconnected Systems — and None Were PDPA-Compliant
Three weeks before a scheduled PDPC audit, the brand’s leadership discovered they had no unified data protection framework despite collecting personal information from over 45,000 customers through loyalty sign-ups, email subscriptions, and in-store purchases. The data resided in fragmented silos: a cloud-based CRM, two regional email marketing platforms, a legacy POS system, and a third-party logistics partner’s warehouse portal. No data mapping existed, access controls were undefined, and retention policies had never been formalised. With no internal IT or compliance team, the company faced potential enforcement action, reputational damage, and the operational burden of halting data processing activities mid-audit.
No Data Inventory, No Access Logs, No Accountability Trail
When we began our assessment, we found no central record of what personal data the company held, where it was stored, or who had access to it. Customer names, contact details, purchase histories, and even delivery addresses were scattered across unencrypted spreadsheets, CRM exports, and legacy POS backups. No role-based access controls were in place — junior staff could view full customer records, and no audit logs tracked data access. The company had not conducted a Data Protection Impact Assessment (DPIA), lacked a data retention policy, and had no documented process for handling data subject access requests. Worse, the third-party logistics provider had been transferring customer delivery data via unsecured email attachments for over a year, violating Section 22 of the PDPA. The root issue was not technical deficiency alone, but a structural absence of data governance — a common gap in FMCG brands focused on sales velocity over compliance infrastructure.
We Deployed a Tiered Compliance Framework in 21 Days Using Zero-Trust Access and Automated Data Mapping
We initiated a three-phase engagement. First, we conducted a full data discovery sweep using automated discovery tools to identify all repositories containing personal data, tagging each by classification and sensitivity. We consolidated 17 data sources into a central inventory, identifying five high-risk endpoints, including an unsecured Google Drive folder with 8,200 customer records. Next, we implemented zero-trust access controls: we segmented the CRM and POS systems using Azure AD conditional access policies, enforced MFA for all admin accounts, and established role-based permissions aligned with job functions. We migrated sensitive data to a PDPA-aligned cloud storage architecture with AES-256 encryption at rest and in transit. Simultaneously, we drafted a data retention policy specifying 24-month deletion windows for loyalty data and 12 months for marketing contacts, integrated into the CRM’s workflow engine. We also established a DSAR intake process using a secure web form hosted on a SOC 2-compliant platform, with response SLAs mapped to PDPC guidelines. All third-party data flows, including the logistics partner’s, were re-routed through encrypted SFTP with access logs retained for 36 months.
The Audit Passed with Zero Non-Conformities — and the First DSAR Was Processed in 18 Hours
The PDPC audit concluded without findings, marking the first time the company had full visibility and control over its personal data lifecycle. The data inventory now covers 100% of systems, and access logs are reviewed weekly. Since implementation, the company has processed seven data subject access requests, all within the 14-day statutory window, with the fastest completed in 18 hours. Employee training on data handling was rolled out to 89 staff across sales, marketing, and logistics, reducing unauthorised access attempts by 94% in the first quarter. The logistics partner now uses an API-based integration instead of email, eliminating the prior compliance gap. Long-term, the company has adopted a compliance calendar with quarterly access reviews, biannual DPIAs, and mandatory vendor assessments — practices now embedded in their operational rhythm despite the absence of a dedicated IT team.
Compliance Isn’t a Department — It’s a Set of Repeatable Processes Any Team Can Run
Many Singapore SMEs assume data protection requires hiring specialists or overhauling systems. This case proves otherwise. What mattered most was not the technology deployed, but the clarity of process: knowing where data lives, who can touch it, how long it’s kept, and how to respond when someone asks about it. These are operational habits, not technical feats. By documenting workflows, enforcing basic access rules, and automating retention, even lean teams can meet PDPA standards without disrupting business. The real risk isn’t non-compliance — it’s delaying action because you believe you need more resources before starting.
One spreadsheet, one email, one system at a time — compliance begins with visibility. TYPENT helps FMCG brands map and secure customer data without needing a full IT department.