Raffles Consulting Services
A family office receiving a consent withdrawal must explain likely effects and stop the affected use or disclosure unless another legal basis applies.
A family office withdrawal of consent under Singapore’s Personal Data Protection Act requires a controlled response. The organisation should confirm the person and the purposes affected, inform the individual of the likely consequences, and cease the relevant collection, use or disclosure after reasonable notice unless the PDPA or another written law permits or requires it without consent.
The request does not automatically require every record to be deleted. The correct answer depends on the purpose, the organisation holding the data, other legal bases and continuing business or legal retention needs.
Identify which organisation received the request
A family office can include an operating company, investment vehicles, holding entities, trusts, foundations and external providers. A request sent to one shared mailbox may concern data held by several legal organisations.
For this reason, record the receiving organisation, the individual, the date and the wording used. Map the systems and entities that collect, use or disclose the affected data. Do not assume that one entity can decide for every company in the structure.
If several organisations are involved, coordinate a consistent response while keeping each legal role clear. The individual should know which organisation is answering and how to contact its data protection officer.
Confirm identity without collecting excessive new data
The office should take reasonable steps to confirm that the requester is the individual or an authorised representative. Use information already held where possible. A request about a family member, employee, adviser or beneficiary may require a different authority check.
In practice, do not ask for a full passport copy merely because it is convenient. Match the verification method to the sensitivity and risk. Record the check and restrict access to the supporting material.
If authority is incomplete, explain what is needed and why. Keep the request open rather than rejecting it through a vague response.
Define the consent and purposes affected
The PDPC’s data protection obligations summary states that individuals may withdraw consent with reasonable notice. The organisation must inform them of the likely consequences and then stop the affected collection, use or disclosure.
At the same time, Consent is purpose-specific. A person may withdraw permission for event invitations without objecting to the use of bank details needed to administer an investment. Another person may withdraw consent for photographs but continue an employment or advisory relationship.
Ask the individual to clarify only where the scope is genuinely unclear. Do not make withdrawal difficult or require the person to justify the decision. Record the purposes, data categories, channels, recipients and effective date.
Explain the likely consequences in plain language
The PDPC advisory guidelines on key concepts explain the section 16 process. On receiving notice, the organisation must inform the individual of the likely consequences of withdrawal.
As a result, Describe real operational effects, not threats. If a service cannot continue without the data, explain the specific service and reason. If only a newsletter stops, say so. If records must be retained for tax, employment, anti-money laundering or legal claims, distinguish retention from continuing optional use.
Give the person enough information to understand the result before the withdrawal takes effect. Preserve the message sent and any response.
Use a purpose-by-purpose decision record
| Question | Evidence | Decision |
|---|---|---|
| Who made the request? | Identity and authority check | Verified, pending or rejected with reason |
| Which organisation acts? | Entity and data-role map | Controller and providers involved |
| Which purposes rely on consent? | Notice, consent record and processing inventory | Stop, clarify or continue on another basis |
| What are the consequences? | Service and process assessment | Plain explanation to individual |
| Who must receive the stop instruction? | System, recipient and provider list | Owners and completion dates |
| What remains retained? | Legal and business retention analysis | Data, access limit and deletion date |
Check whether another legal basis applies
Withdrawal of consent affects processing that depends on that consent. The PDPA and other written laws may require or authorise certain collection, use or disclosure without consent. The office should identify the exact basis rather than use a general compliance label.
For example, Examples may include statutory record keeping, tax reporting, employment duties, court orders, legal claims or regulated anti-money laundering obligations. Obtain specialist advice where the basis or scope is uncertain.
Do not switch to another basis after the fact merely to avoid honouring a request. The purpose, necessity and documentation should withstand independent review.
Send stop instructions to systems and providers
The PDPC guidelines state that the organisation must cause its data intermediaries and agents to stop the affected collection, use or disclosure. A change in the customer relationship system is not enough if a mailing provider, administrator, cloud platform or adviser continues the activity.
In addition, create a task list by system and recipient. Remove the person from optional communications, stop planned disclosures, change user preferences and notify processors through the agreed channel. Ask for completion evidence where the provider’s action is material.
The PDPC explanation of organisations and data intermediaries helps distinguish who decides the purpose and who processes on another organisation’s behalf. Use the contract and real conduct, not only the provider’s label.
Separate cessation from retention and deletion
A consent withdrawal does not mean that every copy must be erased immediately. The retention limitation obligation requires the office to stop retaining personal data when it is no longer needed for a business or legal purpose. Some records may still have a valid retention purpose after optional use has stopped.
For this reason, Tag retained data so it is not used for the withdrawn purpose. Limit access, record the retention basis and schedule the next review or deletion date. Backups should follow the office’s documented restoration and expiry process.
If no continuing purpose exists, dispose of the data securely and ensure providers do the same. Keep evidence of the action without recreating the unnecessary personal data in the case log.
Close the request with an auditable response
Tell the individual which activities stopped, the effective date, any consequences and which data remains under another legal or retention basis. Provide the DPO contact for questions. Avoid disclosing sensitive system details that create a security risk.
In practice, review delayed or incomplete actions and record the reason. Repeated withdrawal requests may reveal poor consent notices, unnecessary collection or systems that cannot apply purpose-based restrictions.
The family office governance guide remains the pillar cornerstone. The family office DPO article covers responsibility and contact channels, while the data intermediary contracts article covers provider controls. The Family Office and UHNW Advisory hub lists the full library.
A good family office withdrawal of consent response is narrow, timely and traceable. It stops the correct activity, preserves only justified records and gives the individual a clear account of what changed.