Raffles Consulting Services

Family office data retention: keep only what has a purpose

Family office data retention should use a record-by-record purpose, legal and business test instead of keeping identity and family data indefinitely.

Family office data retention should not mean keeping every passport copy, family record, employee file and investment document forever. Singapore’s Personal Data Protection Act requires an organisation to stop retaining personal data, or remove the means of association, when the original purpose is no longer served and there is no legal or business reason to keep it.

Use a schedule that names the record, person, purpose, retention trigger, review date and disposal method. Apply other legal or regulatory record duties first, then avoid extending personal-data retention merely because storage is cheap.

Inventory the records by purpose

A family office may hold identity documents, family relationship evidence, employment records, bank and custodian information, investment files, tax records, travel details, health information, philanthropy records and security logs. The sensitivity and purpose differ.

For this reason, list each record class and system. Record whether the SFO, a fund vehicle, a trust, an employer or a service provider controls it. Note every copy, including email attachments, shared drives, messaging exports and backup systems.

The EDB SFO guide shows how an office can combine governance, investment, banking, staffing and regulatory work. That breadth makes a single blanket retention period unreliable.

Apply the purpose and legal-business tests

The PDPC’s data protection obligations say personal data should be disposed of when it is no longer needed for a business or legal purpose. The PDPA does not prescribe one fixed period for every record.

In practice, For each class, write why the information was collected. Then identify any continuing legal, regulatory, contractual, tax, employment, dispute or operational reason. Record the event that starts the retention period, such as account closure, employee departure, investment disposal or end of a service contract.

A vague label such as future reference is not enough. If the purpose cannot be explained to the data protection officer and record owner, review whether the data should be deleted or anonymised.

Separate documents from data fields

A transaction file may need to be retained while a spare passport copy inside it does not. A family tree may support an active regulatory assessment, but old contact details or identity numbers may no longer be necessary.

At the same time, Design the schedule at a useful level. Identify the minimum fields required for the continuing purpose. Redact, detach or anonymise unnecessary personal information while preserving the business record that must remain.

Keep evidence of the decision. A deletion log can state the record class, date, system, method, approver and any legal hold. It should not reproduce the personal data being deleted.

Use different triggers for different records

Record class Possible trigger Review question
Identity and family evidence End of the active verification purpose Is the full copy still required, or will a verified result suffice?
Employee and candidate files Employment or recruitment outcome Which employment, tax or dispute duties continue?
Investment and transaction files Disposal, closure or end of mandate Which legal, tax, audit or contractual records remain necessary?
Visitor and security logs End of the security review period Is an incident or investigation still open?
Service-provider copies Contract end or instruction Has every intermediary returned, deleted or lawfully retained its copy?

These are decision prompts, not fixed legal periods. Confirm the law and contract that applies to the entity and record before setting a duration.

Control outsourced copies

As a result, the PDPC explains the difference between organisations and data intermediaries. An organisation remains responsible for the wider data-protection obligations when a provider processes personal data on its behalf, while the intermediary has specified protection, retention and breach-notification duties.

Contracts should state the processing purpose, access limits, location, retention, return or deletion method, breach escalation and evidence required at termination. Ask providers about backups and replicated storage rather than accepting a statement that the active folder was deleted.

When a mandate ends, inventory the data held by administrators, accountants, payroll providers, cloud services, advisers and former employees. Obtain confirmation for completed return or deletion actions.

Apply legal holds without freezing everything

For example, a dispute, investigation, audit or regulator request may justify retaining relevant records beyond the ordinary schedule. Define the hold by matter, custodian, record class and date. Notify the people who control those records.

Review the hold periodically and release it when the reason ends. Do not use one open issue to suspend disposal across every family and investment record.

Where legal privilege, trusts, tax or regulated investment activity affects the decision, obtain suitable Singapore legal or professional advice. Record the conclusion without placing privileged advice in a general retention tracker.

Review and dispose securely

In addition, the PDPC’s key concepts guidance recommends regular review and an appropriate retention policy. Schedule reviews by risk and volume. Identity media and highly sensitive family data deserve closer control than ordinary public contact information.

Use secure deletion, physical destruction or tested anonymisation. Check access permissions after disposal and verify that automated exports do not recreate deleted records.

The family office governance guide remains the pillar cornerstone. The outsourcing oversight guide covers provider control, while the employment records guide covers entity and duty evidence. The Family Office and UHNW Advisory hub connects the wider library.

For this reason, a sound schedule lets the office explain both decisions: why a record is still held, and why it will stop being held at the chosen trigger. That is more defensible than indefinite storage or a single period applied to everything.