This article comes out of a recent incident I was managing.

The organisation reported what looked like a limited exposure. A small number of records. A specific set of fields. Manageable.

Then the investigation started.

What we found inside the vendor platform was significantly more than the business believed it was holding. Older records that no one had reviewed. Additional fields collected for processes that had ended. Copies of documents attached to accounts that had been inactive for years.

The business had not been careless. It had simply stopped looking.

This is the pattern I want to talk about, because it is more common than most business owners realise.

The comfortable assumption

The assumption usually sounds reasonable.

"The vendor handles the data for us."

The platform holds the data. The vendor is certified. The IT provider manages the access. So the responsibility, somehow, feels like it has moved.

It hasn't.

Under the PDPA, the organisation remains responsible for personal data in its possession or under its control. A vendor processing data on your behalf may be acting as a data intermediary, but your obligations as the organisation do not transfer to them.

The system may store the data. You still need to know what it is storing.

What an audit actually means

Most business owners hear "data audit" and picture a technical exercise involving IT. It isn't.

A data audit is an operational exercise. It asks four practical questions:

  • What personal data do we collect?
  • Where does it sit?
  • Who has access to it?
  • How long has it been there?

You will find that the answers are scattered across your teams. Sales holds customer records in one system. HR keeps employee files in a shared drive. Finance stores identification details and bank information for payroll. Marketing has an email list that has been growing for six years. Someone, somewhere, still has an export of a customer database from a promotion that ended three years ago.

None of this is malicious. It is just how businesses accumulate data.

Retention is not a single number

Retention limits are where most SMEs quietly fall short.

The PDPA's Retention Limitation Obligation requires an organisation to stop retaining personal data — or remove the means of associating it with individuals — when the purpose it was collected for is no longer being served and there is no longer a legal or business need to keep it.

This does not mean every category of data follows the same period. Accounting records may need to be kept for one length of time, employee files for another, unsuccessful job applications for something much shorter.

The point is that these periods should be decided and documented.

"Keep everything forever" is not a retention policy. Neither is whatever the default settings on your software happen to be.

Why it drifts

Data holdings don't become unmanageable overnight. They drift.

A new form adds two fields. A team exports a spreadsheet for a report. Someone saves a copy to work from home. The business changes vendors but keeps access to the old platform "just in case". A process ends, but nobody deletes the data collected for it.

Over time, what the business actually holds stops matching what management believes it holds.

An inventory completed three years ago no longer describes the business today. Systems change. Vendors change. Employees create workarounds. Old processes quietly remain in place.

The wrong time to find out

The reason this matters comes into focus during an incident.

The first question, always, is: what personal data was affected?

That question becomes difficult to answer when the organisation does not already know what the system contains, who has access to it, whether older records are included, or whether copies exist elsewhere.

The investigation takes longer. Early assumptions turn out to be wrong. You start out believing a limited set of information is involved, and end up discovering the same records also held identification details, transaction histories or internal notes no one remembered were there.

The size of the exposure is rarely known at the start. It is discovered.

What to do next

You don't need a complete audit today. Start with three steps.

First, list every system, platform and location where personal data currently lives in your business. Include shared drives, email archives, personal laptops, exported spreadsheets and outsourced vendors — not only the official systems.

Second, for each one, identify who owns it, who has access, and roughly what type of data it contains.

Third, ask when each category of data was last reviewed and whether any of it should have been deleted by now.

This is not a one-time exercise. Data protection is ongoing operational work that needs to be revisited as your business changes.

The one rule

You cannot outsource ownership of your data.

You can outsource storage, processing, security and even parts of your DPO function. But the responsibility for knowing what data you hold, why you hold it, and how long you keep it stays with the organisation.

The best time to build that clarity is before you need it.


If you would like help structuring a practical data audit for your organisation, or setting up a retention framework that actually works day-to-day, that is the kind of work we do at Veritos.