The email lands in your inbox from PDPC. The subject line: "Action required: Verify your DPO details before 1 September 2026."

It asks you to do one thing: check that your DPO details are correct before that date.

It's the kind of email that's easy to file under "later." Worth two minutes now, though, because it quietly tests something most businesses assume they've sorted and haven't.

What the DPO Registry actually is

From 1 September, PDPC's DPO Registry becomes publicly searchable on its website. The idea is simple. If a member of the public has a data protection concern about your organisation, they can look up your DPO's business contact and reach out. If you registered a DPO with PDPC, that name and business email is what appears.

Registering with PDPC is voluntary. You can register up to five DPOs for your organisation. The registry going public doesn't change that, and it isn't a new obligation to register. What changes is visibility. If you're on it, you're now findable.

The part that catches people out

Two groups get caught here.

The first kept their details but let them go stale. The DPO who was named two years ago has left. The email points to a mailbox nobody reads. The entry is technically there, and technically useless.

The second is the bigger one. Plenty of businesses never appointed a DPO at all, or never made the contact public. And here is the part people forget. Appointing a DPO is not optional, and it is not only for large companies. Under the PDPA, every organisation that handles personal data has to designate at least one, from a sole proprietor upward. The business contact has to be publicly accessible. That was already the law. The registry doesn't create the duty. It just makes the gap easy to see.

Why it slips

It slips for the same reason a lot of data protection work slips. Nobody owns it.

The DPO gets named once, on a form, often years ago. The person moves on. Their email is decommissioned. Nobody circles back to update it, because until now, nobody outside the company was looking. Almost every DPO I meet, data protection is one of several jobs they hold. The moment things get busy, the small maintenance tasks are the first to fall off.

A public registry changes the audience. The person checking might now be a customer with a complaint, or the regulator following one up.

What to check before 1 September

You don't need a project for this. You need to answer a few questions about what's actually on the record.

  • Is your DPO listed, and are the name and business email current? Verify on the registry, and update through PDPC's form if anything is wrong.
  • If the person listed has left, appoint someone who can actually take on the role, and update the details.
  • If you never appointed a DPO, this is the real gap, and it needs more than a name on a form. It can be someone you already employ, so it isn't about hiring. But whoever takes it on carries the actual responsibilities: knowing what personal data the organisation actually holds, keeping you compliant with the PDPA, handling access and correction requests, managing data protection risk, and being your point of contact with the PDPC. Name someone who can genuinely do the work, not just fill the field.
  • Register your DPO, if you haven't. Registration itself is voluntary, but making the DPO's business contact publicly accessible is not. Registering is simply the cleanest way to meet that obligation, and it's what puts you on the registry the public will now be searching. Skipping it doesn't remove the duty. You'd still have to make the contact reachable another way, usually your privacy notice or website. As a DPO, I'd register.
  • Then the real test. If a customer emailed that DPO address today, who in your organisation would actually see it?

The registry is a small change on paper. Public contact details, searchable in one place. But it moves one piece of your compliance from private to visible, and it's worth being the business that looks reachable rather than the one with a dead link.

Keeping a DPO contact current is exactly the kind of small, ownerless task that quietly goes stale. Part of what we do at Veritos is keep that kind of thing structured, so it's clear who holds the responsibility and the details stay current, not just filed once and forgotten.