Raffles Consulting Services
A family office access request needs verified authority, preserved records, an exceptions review and one controlled response process.
A family office access request should be logged and verified as soon as it arrives. The office must identify the individual and the scope, preserve relevant records, check whether the PDPA access duty applies and respond without exposing another person’s data or protected material.
Family office records often combine principal, relative, employee, adviser and counterparty information. A rushed export from email or a document system can disclose far more than the requester is entitled to receive.
Recognise a family office access request
A request does not need a legal heading to matter. An individual may ask what information the office holds, how it used or disclosed the information, or for an error to be corrected. Send possible requests to the data protection officer rather than leaving each employee to answer.
For this reason, the PDPC’s data protection obligations state that organisations must provide access to an individual’s personal data and information about use or disclosure within the year before the request, subject to exceptions. Errors or omissions must be corrected as soon as practicable.
Record the date received, channel, requester, wording and systems likely to contain relevant data. Preserve the original request and acknowledgement.
Verify identity and authority
Use proportionate identity checks. Do not ask for more sensitive information than necessary. If a lawyer, family member, guardian or representative makes the request, confirm the legal authority to act for the individual.
In practice, Match the request to the entity that controls the data. A family office group may include an employer, investment manager, trustee, holding company and charitable vehicle. One shared email address does not make every entity the same organisation under the PDPA.
If the request concerns several entities, assign an owner for each and coordinate the response. Avoid duplicate searches and inconsistent explanations.
Clarify scope without delaying the work
Ask the requester to clarify a very broad request where a date range, relationship or record type would help. Start preserving likely records while clarification is pending. Do not use clarification as a reason to do nothing.
At the same time, Translate the request into search locations: email, human resources, customer records, investment reporting, meeting files, security logs and service-provider systems. Record the custodians and search terms.
Separate the access request from a complaint, dispute or employment issue. The same message may contain both, but each needs an appropriate owner.
Track the 30-day response point
The PDPC’s Advisory Guidelines on Key Concepts say an organisation must respond as soon as reasonably possible. If it cannot respond within 30 days, it should tell the individual in writing within that period when it will be able to respond.
As a result, set an internal review date earlier than day 30. The data protection officer needs time to check the search, exceptions, redactions and delivery method.
The PDPC access-review checklist also points individuals to the 30-calendar-day response period. A holding message should give a realistic revised date and should not overstate what the organisation will disclose before review is complete.
Review exceptions and other people’s data
An access result may contain personal data about relatives, employees or advisers. It may also contain evaluative information, investigation material, privileged legal advice or records subject to another exception or prohibition.
For example, do not release or reject the whole file automatically. Review each record, apply redaction where appropriate and document the legal basis for withheld material. Obtain Singapore legal advice where the exception or privilege position is uncertain.
A family disagreement does not by itself remove the PDPA duty. At the same time, the family relationship does not give one person access to another person’s personal data.
Use a response control table
| Stage | Owner | Evidence |
|---|---|---|
| Receive and acknowledge | Data protection officer | Request log and acknowledgement |
| Verify requester | Data protection and legal | Identity and authority check |
| Search and preserve | System and record owners | Search record and preserved copies |
| Review and redact | Data protection and legal | Decision schedule and redacted set |
| Deliver securely | Named response owner | Final letter and delivery confirmation |
Handle corrections across connected organisations
Check the source of the disputed data and ask for supporting evidence where needed. Correct a genuine error or omission as soon as practicable. Keep the former value, corrected value, reason and approval in the audit trail.
In addition, the PDPC states that corrected data may need to be sent to other organisations to which it was disclosed within the preceding year, subject to the applicable rules and the individual’s consent. Map the disclosure history before closing the request.
A correction request is not a right to rewrite a professional opinion or accurate historical record. Distinguish fact from opinion and preserve the reason for the conclusion.
Deliver the response securely
Use a channel suited to the sensitivity and volume of the data. Confirm the recipient before sending a password, link or physical package. Send the password through a separate channel where appropriate.
For this reason, keep a clean copy of what was delivered, the response letter and proof of delivery. Do not retain unnecessary working copies in personal downloads or email attachments.
The family office governance guide remains the pillar cornerstone. The data retention guide covers disposal decisions, while the data breach response guide covers incidents. The Family Office and UHNW Advisory hub connects the library.
A sound response can be reconstructed later. It shows what the individual asked, who verified the request, where the office searched, what it disclosed or withheld and how any correction reached the right downstream records.