Data processing agreement

Draft — pending legal review, not yet in force

This page is an outline of what the final document will cover. It is not legal text and creates no rights or obligations.

What this document will cover

  1. Roles: the customer as the organisation in control of its data, Consoletium as data processor
  2. Scope: the personal data customers store in their Consoletium system
  3. Obligations under the Singapore and Malaysia PDPA
  4. Where data is hosted (Singapore) and the sub-processors used
  5. Security measures, including encryption, backups and access control
  6. Notification of data breaches
  7. Return and deletion of data when the agreement ends
  8. Audits and assistance with requests from individuals

Questions in the meantime: contact us.