Raffles Consulting Services
A family office data intermediary contract should define each party’s role, processing limits, security, breach notice and exit handling under the PDPA.
A family office data intermediary contract should begin by stating whose purposes the provider follows and which personal data it processes. The label in the agreement is not enough. The actual role determines whether a provider is acting on behalf of the family office, acting for its own purposes or doing both in different parts of the service.
Private banks, administrators, payroll firms, cloud services, background-screening providers and advisers may hold overlapping family, employee and counterparty data. One provider register should show the legal entity instructing each service and the controls that follow the data.
Decide the role for each processing activity
The PDPC’s organisation and data intermediary guidance explains that a data intermediary processes personal data on behalf of another organisation. An organisation decides its own purposes and means of processing.
For this reason, a provider can hold different roles for different activities. A payroll processor may act on the family office’s instructions for salary calculations while using contact data for its own account administration. Describe the activities separately instead of assigning one broad label to the entire relationship.
Map the family office entity that controls each dataset. A holding company, employer, investment manager, trustee and charitable vehicle should not be treated as one organisation merely because they share staff or technology.
Keep the family office responsible for its instructions
PDPC guidance says an organisation remains responsible for the personal data in its possession or under its control. Engaging a data intermediary does not transfer all PDPA responsibility to the vendor.
In practice, For processing under a written contract, a data intermediary is directly subject to the protection and retention limitation duties and must notify the organisation of a data breach without undue delay. The family office still needs to manage purposes, consent where required, access and correction, overseas transfers and any notifiable-breach assessment that falls to it.
Name a business owner and a data-protection owner for every provider. The business owner confirms the service need. The data-protection owner checks the data scope, instructions and controls.
Write the processing instructions precisely
The PDPC’s data-protection clauses guide provides sample provisions for service agreements. Adapt them to the service and seek Singapore legal advice for the final contract where needed.
At the same time, list the data subjects, data fields, permitted purposes, processing steps, locations, systems and retention period. State what the provider may not do, including marketing, analytics, model training or reuse for another customer unless separately and lawfully agreed.
Set an instruction process. An email from any employee should not silently expand the approved purpose. Material changes should be documented and reviewed before new data is uploaded.
Use a provider control record
| Control | Contract point | Operating evidence |
|---|---|---|
| Role | Organisation or intermediary for each activity | Current processing map |
| Purpose | Specific permitted processing and prohibited reuse | Approved instructions |
| Access | Authorised roles, authentication and logging | User-access review |
| Subcontractors | Approval, location and equivalent obligations | Current subprocessor list |
| Breach | Immediate escalation details and evidence support | Tested response contacts |
| Exit | Return, deletion, certification and transition support | Closed-service checklist |
Set security and breach duties before an incident
The PDPC obligation overview requires reasonable security arrangements. Specify controls that match the data, such as encryption, access approval, multi-factor authentication, logging, backup, secure development and staff confidentiality.
As a result, Define the provider’s breach-notice channel, information requirements and response time. The phrase without undue delay needs an operating contact that works outside ordinary office hours. Require preservation of logs and cooperation with assessment, containment and notices.
Test the escalation using a simple scenario. A misplaced investor file should reach the family office data-protection owner quickly, not remain in a service desk queue because the ticket was classified as a document problem.
Control subprocessors and overseas transfers
The PDPC guide to managing data intermediaries covers governance, risk assessment, service management and exit management. Ask which subcontractors and locations form part of the actual service.
For example, Require notice or approval for a material subprocessor change. Check whether the contract passes down the security, retention, breach and deletion duties. An overseas cloud region or support team also needs the family office’s transfer-limitation analysis.
Maintain a live list of hosting, backup and support locations. Marketing language such as global infrastructure does not answer where the data is processed or accessed.
Coordinate access, correction and retention work
The family office may need the provider to search, export, correct or preserve data when an individual makes a request. Set timeframes and a secure delivery route. The intermediary should not answer the individual directly unless the family office has given a lawful, verified instruction.
In addition, Define deletion by dataset and legal purpose. Backup expiry, archived email, security logs and litigation holds may follow different schedules. The provider should explain what deletion means in each system.
Review the contract and operating evidence at least annually and after a material service change. Record unresolved findings, responsible owners and completion dates.
End the service without losing control
Before termination, decide which data returns to the family office, which moves to a successor and which must be deleted. Confirm the format, encryption, access period and destruction evidence. Remove service accounts and integration keys after the verified transfer.
For this reason, the family office governance guide remains the pillar cornerstone. The outsourcing oversight guide covers wider provider governance, while the PDPA request guide explains individual requests. The Family Office and UHNW Advisory hub connects the library.
A useful contract lets the family office answer five questions at any time: who controls the data, why the provider has it, where it goes, how an incident is reported and what happens when the service ends.