A free, printable staff data protection pledge for Singapore employers. Ten specific commitments plus a signature block for the employee and a supervisor or witness. It exists to answer one question cheaply: can you show that the people handling personal data knew what they were required to do?
Ten commitments, an acknowledgement paragraph, and a signature block. Free, no sign-up.
Download the formThe ten commitments, in plain terms:
It closes with an acknowledgement paragraph and a declaration block: employee name, department, signature and date, plus a supervisor or witness signature and date.
The PDPA does not name a staff acknowledgement as a standalone requirement. What the Accountability Obligation requires is that you develop and implement policies and practices, and communicate them to your staff. PDPC guidance expects training records to exist as evidence.
Most breaches start with a person rather than a system: a file sent to the wrong recipient, a mailing list pasted into the To field, records still reachable after someone leaves. Those are not technical failures, and the honest defence is that the person was told, in writing, and confirmed it.
Keep the signed copies with your training records. Together they answer what an investigator asks first. Our PDPA staff training cost breakdown covers the training side, including how often it needs repeating.
[COMPANY NAME].An acknowledgement is only as strong as the policies behind it. A gap assessment tells you which ones you actually have.
Get a Gap AssessmentA signed declaration in which an employee confirms they understand their data protection responsibilities and agree to follow the organisation’s policies. It typically lists specific commitments, such as only accessing data they are authorised to see and reporting suspected breaches immediately, and ends with a signature block for the employee and a supervisor or witness.
It is not named in the Act as a standalone requirement. The Accountability Obligation requires organisations to develop and implement policies and practices and to communicate them to staff, and PDPC guidance expects training records to exist as evidence. A signed acknowledgement is one of the simplest ways to show that communication actually happened and who received it.
At onboarding for anyone who will handle personal data, again after each refresher training session, and whenever your policies change materially. Keep the signed copies with your training records: together they answer the question an investigator asks first, which is whether the people handling personal data knew what they were required to do.
Yes. Download it, put your company name in, adjust the commitments to match your own policies, and have staff sign it. It is a starting point for Singapore SMEs rather than legal advice, and it should reflect what your policies actually say.
Disclaimer: This template and article are for general information only and do not constitute legal or employment advice. Adapt the commitments and any disciplinary wording to your own policies and employment terms, and seek qualified advice where the consequences matter.