ICPL ISO Consultants Pte Ltd
Data Protection

Privacy Policy &
Data Protection Notices

ISO Consultants Pte. Ltd. is committed to responsible data stewardship in compliance with Singapore's Personal Data Protection Act 2012 (PDPA) and SS 714:2025 Data Protection Management Programme standard.

PDPA CompliantSS 714:2025 AlignedLast Updated: 20 May 2026
This Privacy Policy is issued by ISO Consultants Pte. Ltd. (UEN 201911816E) in compliance with Singapore's Personal Data Protection Act 2012 (PDPA) and SS 714:2025 — Data Protection Management Programme (IMDA/PDPC). Last updated: 20 May 2026.

1.About This Policy

ISO Consultants Pte. Ltd. ("ICPL", "we", "our", "us") is committed to protecting the personal data of individuals we interact with in accordance with the PDPA and the requirements of SS 714:2025, Singapore's national standard for Data Protection Management Programmes (DPMP).

This Policy applies to all personal data collected, used, disclosed, and stored by ICPL in the course of our business operations — including consultancy, training, events, website, and administrative activities.

2.Data Protection Officer (DPO)

ICPL has appointed a Data Protection Officer (DPO) who is responsible for ensuring compliance with the PDPA and overseeing ICPL's Data Protection Management Programme (DPMP) aligned with SS 714:2025.

Organisation: ISO Consultants Pte. Ltd.

DPO Contact: operations@isoconsultants.sg

Address: 12 Woodlands Square, Tower 1, #09-73, Singapore 737715

Phone: +65 8599 3818

3.Personal Data We Collect

We collect personal data necessary for the purposes described in this Policy. The categories of personal data we may collect include:

  • Identity data: Full name, NRIC/FIN (where required for regulatory purposes), designation, photographs
  • Contact data: Email address, telephone number, mailing address
  • Professional data: Organisation name, industry sector, job title, professional qualifications
  • Financial data: Billing information, bank account details, invoice details (for service billing)
  • Technical data: IP address, browser type, cookies, website usage data
  • Communication data: Enquiries, feedback, correspondence, chat history
  • Event/training data: Registration details, attendance records, certificates
  • Employment data (for job applicants): Résumé, work history, references, educational qualifications

ICPL does not knowingly collect personal data from individuals under 18 years of age without verifiable parental or guardian consent.

4.Purposes of Collection, Use & Disclosure

ICPL collects and uses personal data for the following purposes:

  • Providing ISO, cybersecurity, sustainability, and compliance consultancy services
  • Processing service enquiries, quotations, and contracts
  • Conducting training programmes and issuing certificates of completion
  • Processing event and seminar registrations
  • Billing, invoicing, and financial administration
  • Responding to feedback, complaints, and data access requests
  • Regulatory compliance, legal obligations, and authority submissions
  • Sending service updates, newsletters, and event invitations (with consent where required)
  • Evaluating and processing job applications and recruitment
  • Website analytics, security, and performance improvement
  • Fulfilling obligations under applicable laws, regulations, and court orders

5.Legal Bases & Consent

ICPL relies on the following bases for processing personal data under the PDPA:

  • Contractual necessity: Processing required to perform or enter into a contract with you
  • Legal obligation: Processing required to comply with applicable laws and regulatory requirements
  • Legitimate interests: Processing for ICPL's legitimate business interests (e.g. service improvement, fraud prevention) where not overridden by your rights
  • Consent: Where required by the PDPA, particularly for marketing communications — you may withdraw consent at any time without affecting prior lawful processing

6.Disclosure of Personal Data

ICPL may disclose personal data to the following categories of recipients only to the extent necessary:

  • Certification bodies, accreditation bodies, and regulatory authorities (for certification and compliance purposes)
  • Government agencies and statutory boards (e.g. Enterprise Singapore, CSA, MOM, PDPC) where required
  • Third-party service providers and data intermediaries (e.g. cloud hosting, email platforms, accounting software) under written contractual data protection obligations
  • Professional advisors (lawyers, auditors, insurers) under strict confidentiality obligations
  • Successors or assignees in the event of a business transfer, merger, or acquisition

ICPL does not sell, rent, or trade personal data to any third party for marketing purposes.

7.Transfers Outside Singapore

Where personal data is transferred outside Singapore (e.g. to cloud service providers), ICPL ensures that adequate protection is in place through contractual arrangements, ensuring comparable standards of protection as required under the PDPA.

8.Retention of Personal Data

ICPL retains personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable laws and regulations, whichever is longer. Retention periods are defined in ICPL's Data Retention Schedule, which forms part of our SS 714:2025-aligned DPMP.

General retention guidelines:

  • Client project and contractual records: 7 years after project completion
  • Financial and billing records: 5 years (in accordance with IRAS requirements)
  • Training and event records: 3 years after event/training date
  • Marketing consent records: Duration of consent + 3 years
  • Job applicant records (unsuccessful): 1 year from application date
  • Website analytics data: 26 months

9.Protection of Personal Data

ICPL implements administrative, physical, and technical safeguards aligned with SS 714:2025 requirements and ISO/IEC 27001 principles to protect personal data against unauthorised access, use, disclosure, alteration, or destruction. These measures include:

  • Access controls and role-based data access restrictions
  • Encryption of personal data in transit and at rest
  • Regular security assessments and vulnerability reviews
  • Staff training and data protection awareness programmes
  • Data Protection Impact Assessments (DPIAs) for high-risk processing activities
  • Data breach detection, reporting, and response procedures per PDPA Mandatory Breach Notification requirements

10.Cookies & Website Data

ICPL's website uses cookies and similar tracking technologies to improve your browsing experience and analyse website usage. You may configure your browser to refuse cookies, though this may affect certain website functionality. By continuing to use our website, you consent to the use of cookies in accordance with this Policy.

11.Your Rights Under the PDPA

You have the following rights in respect of your personal data held by ICPL:

  • Right of Access (Section 21 PDPA): Request access to personal data we hold about you and information about how it has been used and disclosed in the past 12 months
  • Right of Correction (Section 22 PDPA): Request correction of inaccurate, incomplete, or misleading personal data we hold about you
  • Right to Withdraw Consent: Withdraw consent for marketing communications at any time
  • Right to Data Portability (Section 26H PDPA): Request transmission of certain personal data in machine-readable format to another organisation (where applicable)

To exercise your rights, submit a written request to our DPO at operations@isoconsultants.sg. We will respond within 30 calendar days of receiving your request. We may charge a reasonable administrative fee for access requests.

12.Data Breach Notification

In the event of a data breach that is likely to result in significant harm to affected individuals, ICPL will notify the Personal Data Protection Commission (PDPC) and affected individuals as required under the PDPA Mandatory Breach Notification obligation, within 3 calendar days of assessing that the breach is notifiable.

13.Do Not Call Registry

ICPL complies with Singapore's Do Not Call (DNC) Registry provisions under the PDPA. We will not send unsolicited telemarketing messages via voice calls, SMS, or fax to Singapore telephone numbers registered on the DNC Registry, unless we have clear and unambiguous consent from the recipient, or an ongoing business relationship applies.

14.Changes to This Policy

ICPL reserves the right to update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable laws, or business operations. The updated Policy will be published on our website with a revised effective date. Material changes will be communicated via appropriate channels.

15.Governing Law & Complaints

This Policy is governed by the laws of Singapore. If you have concerns about our data protection practices, please contact our DPO at operations@isoconsultants.sg in the first instance. You also have the right to lodge a complaint with the Personal Data Protection Commission (PDPC) at pdpc.gov.sg.

Questions about your personal data?

Contact our Data Protection Officer

Chat with us