Country-specific guidance Current

Storing client identity evidence securely under the PDPA

The standard is reasonable security, matched to the harm a breach would cause.

Collecting and verifying a client's identity document is only half the job; storing it securely is a separate, ongoing obligation under the Personal Data Protection Act. This guide sets out what that obligation practically expects. It is general information, not legal or compliance advice.

Action plan

1 Make reasonable security arrangements around stored identity evidence The PDPA's own language names the specific risks these arrangements need to address.

The PDPA's Protection Obligation requires an organisation to make reasonable security arrangements to protect personal data in its possession or under its control, in order to prevent unauthorised access, collection, use, disclosure, copying, modification, disposal, or similar risks. Client identity documents, being personal data, fall squarely within this obligation.

  • Control who can access stored identity documents
  • Guard against unauthorised copying, modification, or disposal, not only unauthorised access
  • Treat this as an ongoing obligation for as long as the evidence is held, not a one-off setup step

Done when: Security arrangements around stored identity evidence address unauthorised access, use, disclosure, copying, modification, and disposal

Singapore Statutes Online: Personal Data Protection Act 2012
2 Stay responsible for security even where a vendor stores the data for you Outsourcing storage doesn't outsource the obligation.

Where a firm uses an external vendor or data intermediary to store client personal data, the firm remains responsible for ensuring that vendor makes reasonable security arrangements. Check a vendor's security practices before relying on them, rather than assuming the obligation transfers along with the data.

  • Check a storage vendor's security arrangements before relying on them
  • Don't assume the Protection Obligation transfers to the vendor along with the data
  • Review vendor security periodically, not only at the start of the relationship

Done when: A storage vendor's security arrangements were checked, and the firm's own responsibility for them was not assumed away

3 Match the level of security to the harm a breach would cause Reasonable is a standard that scales with sensitivity and risk, not a fixed checklist.

What counts as reasonable is generally understood to scale with the nature of the personal data involved and the harm a security breach could cause. Identity documents used for client verification are sensitive enough to warrant a higher level of protection than routine, low-sensitivity correspondence.

  • Give identity documents a higher level of protection than routine correspondence
  • Reassess security arrangements as the sensitivity of what's held changes
  • Don't apply a single, uniform security standard to everything the firm stores

Done when: The level of security applied to stored identity evidence reflects its sensitivity, not a uniform default

See setting a record-retention schedule