Managing Third-Party Data Processors: What Your Vendor Contracts Need Under the PDPA
Handing personal data to a payroll provider or a cloud host doesn't hand your Personal Data Protection Act (PDPA) responsibility off with it. If something goes wrong, the Personal Data Protection Commission (PDPC) calls the business that collected the data first, not the vendor holding it.
Most SMEs already use several vendors that touch personal data without necessarily thinking of them that way: a payroll processor, a cloud storage provider, an email marketing platform, an accounting software vendor. Each one is processing personal data on your behalf, and the PDPA has specific expectations about how that relationship needs to be set up.
Organisation vs. Data Intermediary: a Distinction That Matters
The PDPA calls a vendor that processes personal data on another organisation's behalf, and not for its own purposes, a "data intermediary." A data intermediary is directly bound by the PDPA's Protection and Retention Limitation obligations for the data it handles, and by the breach notification duty for data processed on your behalf. What it isn't responsible for is obtaining consent or notifying individuals about how their data is used — those obligations stay with you, the organisation that collected the data in the first place.
You Can't Outsource the Obligation, Only the Task
This is the part that surprises businesses that assume a vendor contract shifts liability along with the work. It doesn't. You remain accountable for personal data you've handed to a vendor for processing, which is exactly why the contract governing that relationship matters as much as the vendor's own security practices.
What the Contract Actually Needs
- Scope of processing. What the vendor is permitted to do with the data, and nothing beyond that.
- Security requirements. The protective measures the vendor commits to, matched to the sensitivity of the data involved.
- Breach notification back to you, promptly. A vendor's own breach notification duty runs to you; your contract should set a clear, short timeframe for them to tell you, so your own PDPC notification clock isn't running down before you even know there's a problem.
- Sub-processor restrictions. Whether the vendor can pass the data to a further sub-contractor, and under what conditions, since each additional hand the data passes through is another point of exposure.
- Return or deletion at the end of the engagement. What happens to the data once the contract ends, stated specifically enough to be checked, not just promised.
Vendor Due Diligence Before You Sign
Before engaging a vendor that will handle personal data, it's worth checking their security posture and track record, not just their price and features. Ask where their servers and any sub-processors are located — this matters separately under the PDPA's Transfer Limitation Obligation if the answer is outside Singapore, covered in our guide to cross-border data transfers.
Ongoing Controls, Not Just a Signing-Day Checklist
Vendor management doesn't end once the contract is signed. Vendors handling higher-sensitivity data, such as payroll or health information, are worth reviewing periodically rather than assuming the arrangement that was fine at signing is still fine two years later, especially if the vendor has changed ownership, sub-processors, or its own security practices in the meantime.
Not sure your existing vendor contracts actually cover this?
Compliz reviews your vendor agreements against the PDPA's requirements and helps set the clauses that are missing, as part of our Personal Data Solution.
Request a QuoteFrequently Asked Questions
What's the difference between an "organisation" and a "data intermediary" under the PDPA?
An organisation collects and determines the purpose for personal data. A data intermediary processes that data on the organisation's behalf, not for its own purposes, and carries a narrower set of direct PDPA obligations as a result.
Do I still need consent from customers if a vendor processes the data?
Yes. The consent and notification obligations stay with you as the organisation, even when a vendor is the one physically handling the data.
Is my vendor liable if they cause a breach?
A data intermediary has its own breach notification duty for data it processes on your behalf, but you as the organisation remain accountable overall, which is why the contract's breach-notification and security terms matter.
Do I need a written contract, or is a verbal understanding enough?
A written contract with clear data protection clauses is the standard PDPC guidance points to, since it's the only way to actually demonstrate what the vendor was and wasn't authorised to do with the data.
Does this apply to small vendors, like a freelance bookkeeper, or only large providers?
It applies regardless of vendor size. What matters is whether personal data is being processed on your behalf, not how big the vendor is.
