All Insights Personal Data Solution

Managing Third-Party Data Processors: What Your Vendor Contracts Need Under the PDPA

Handing personal data to a payroll provider or a cloud host doesn't hand your Personal Data Protection Act (PDPA) responsibility off with it. If something goes wrong, the Personal Data Protection Commission (PDPC) calls the business that collected the data first, not the vendor holding it.

Compliz Insights · Personal Data Solution · ·

Most SMEs already use several vendors that touch personal data without necessarily thinking of them that way: a payroll processor, a cloud storage provider, an email marketing platform, an accounting software vendor. Each one is processing personal data on your behalf, and the PDPA has specific expectations about how that relationship needs to be set up.

Organisation vs. Data Intermediary: a Distinction That Matters

The PDPA calls a vendor that processes personal data on another organisation's behalf, and not for its own purposes, a "data intermediary." A data intermediary is directly bound by the PDPA's Protection and Retention Limitation obligations for the data it handles, and by the breach notification duty for data processed on your behalf. What it isn't responsible for is obtaining consent or notifying individuals about how their data is used — those obligations stay with you, the organisation that collected the data in the first place.

You Can't Outsource the Obligation, Only the Task

This is the part that surprises businesses that assume a vendor contract shifts liability along with the work. It doesn't. You remain accountable for personal data you've handed to a vendor for processing, which is exactly why the contract governing that relationship matters as much as the vendor's own security practices.

What the Contract Actually Needs

Vendor Due Diligence Before You Sign

Before engaging a vendor that will handle personal data, it's worth checking their security posture and track record, not just their price and features. Ask where their servers and any sub-processors are located — this matters separately under the PDPA's Transfer Limitation Obligation if the answer is outside Singapore, covered in our guide to cross-border data transfers.

Ongoing Controls, Not Just a Signing-Day Checklist

Vendor management doesn't end once the contract is signed. Vendors handling higher-sensitivity data, such as payroll or health information, are worth reviewing periodically rather than assuming the arrangement that was fine at signing is still fine two years later, especially if the vendor has changed ownership, sub-processors, or its own security practices in the meantime.

Not sure your existing vendor contracts actually cover this?

Compliz reviews your vendor agreements against the PDPA's requirements and helps set the clauses that are missing, as part of our Personal Data Solution.

Request a Quote

Frequently Asked Questions

What's the difference between an "organisation" and a "data intermediary" under the PDPA?

An organisation collects and determines the purpose for personal data. A data intermediary processes that data on the organisation's behalf, not for its own purposes, and carries a narrower set of direct PDPA obligations as a result.

Do I still need consent from customers if a vendor processes the data?

Yes. The consent and notification obligations stay with you as the organisation, even when a vendor is the one physically handling the data.

Is my vendor liable if they cause a breach?

A data intermediary has its own breach notification duty for data it processes on your behalf, but you as the organisation remain accountable overall, which is why the contract's breach-notification and security terms matter.

Do I need a written contract, or is a verbal understanding enough?

A written contract with clear data protection clauses is the standard PDPC guidance points to, since it's the only way to actually demonstrate what the vendor was and wasn't authorised to do with the data.

Does this apply to small vendors, like a freelance bookkeeper, or only large providers?

It applies regardless of vendor size. What matters is whether personal data is being processed on your behalf, not how big the vendor is.