DPO Foundation
Since 1 June 2025 the Personal Data Protection Act has required qualifying organisations to appoint a Data Protection Officer, and a great many of those appointments landed on someone who already had a full job. This foundation day is written for that person. It covers what the role is actually responsible for, what it is not, where the authority to say no comes from, and what the first ninety days should produce so that the appointment is more than a name filed with the Commissioner.
Programme Agenda
The Appointment and What Triggers It
Which controllers and processors fall inside the mandatory appointment requirement, notification to the Commissioner, and whether the role can be held internally, shared across group companies, or outsourced.
What the Role Covers, and What It Does Not
Advising, monitoring, and acting as contact point for the Commissioner and for data subjects. Where the DPO advises and where the business decides, and why blurring that line creates a conflict of interest.
Independence and Protection
Reporting lines that preserve independence, conflicts created by holding the role alongside IT or marketing responsibilities, resourcing, and access to senior management.
Building the Record of Processing
The first substantial deliverable. Identifying processing activities, purposes, categories of data and recipients, retention periods and transfer routes, using a method that survives staff turnover.
Handling Data Subject Requests
Access, correction, withdrawal of consent, and the data portability right introduced by the 2024 amendment. Verification, timelines, exemptions, and the response template that keeps handling consistent.
Breach Duties and the Clock
Assessing whether an incident is notifiable, notifying the Commissioner within 72 hours, notifying affected individuals within seven days where there is a risk of significant harm, and maintaining the breach register.
Working With Vendors and Processors
Due diligence before appointment, the terms that belong in a processing agreement, cross-border transfer considerations, and monitoring a processor after the contract is signed.
Your First Ninety Days
Participants build a dated plan: what to inventory, who to meet, which policy to write first, and what to put in front of management at day thirty, sixty and ninety.
Learning Outcomes:
Confirm whether your organisation is required to appoint a DPO and on what basis
State the boundaries of the role and recognise a conflict of interest in it
Establish reporting lines that preserve the independence the role needs
Build a record of processing activities that stays accurate over time
Handle access, correction and portability requests within the statutory timelines
Assess a breach against the notification threshold and meet the 72-hour and 7-day duties
Set processor obligations in contract and monitor them afterwards
Leave with a dated ninety day plan for the role
Duration: 1 Day (8 Hours)
Training Hours: 9:00 AM to 5:00 PM
Level: Beginner
Training Mode: Physical, Online, or Hybrid
HRD Corp SBL-KHAS Claimable
Certificate of Completion included
Frequently Asked Questions
More in Data Protection and Privacy Law
- GDPR Awareness · Beginner, 1 day
- Singapore PDPA (PDPC Compliance) · All levels, 1 day
- China PIPL (Personal Information Protection Law) · All levels, 1 day
- US Privacy Laws (CCPA and CPRA) · All levels, 1 day
- HIPAA Awareness · Beginner, 1 day
- PDPA Awareness and Compliance Training · All staff, 1 day
- Data Protection Officer (DPO) Practical Training · Intermediate, 2 days