Personal Data Protection Standard: Security, Retention and Integrity
Under the Personal Data Protection Regulations 2013, a data controller's security policy, retention and data integrity must meet the standards the Commissioner prescribes. Those standards are set out in the Personal Data Protection Standard 2015, which lays down minimum requirements for personal data in both electronic and non-electronic form. In Public Consultation Paper No. 4 of 2025, which ran from 22 August to 8 September 2025, JPDP proposed amending the 2013 Regulations to align them with the 2024 amendments to the Act and developing a Personal Data Protection Standard 2025, with more detailed access controls, stronger protection against external threats, a data breach incident response plan, secure transfers, clear retention policies and disposal schedules, secure destruction, and better data integrity procedures. The revised Standard has not yet been issued.
This one-day course is for DPOs, IT security, records management and operations teams. It works through the 2015 Standard control by control, because it is the enforceable baseline today, and shows where the proposed 2025 revision is likely to raise the bar, so organisations can close the gaps once rather than twice. It links naturally to PDPA for Data Processors, since processors are now bound by the Security Principle directly.
HRD Corp SBL-Khas Claimable
Programme Agenda
9:00 AM - 9:15 AM
Welcome and Programme Overview
Introduction to the session, objectives, and housekeeping.
9:15 AM - 10:15 AM
Where the Standard Fits
Regulations 6, 7 and 8 of the 2013 Regulations, how the Standard gives them content, the 2024 amendments to the Act, and the status of JPDP's 2025 consultation.
10:15 AM - 10:30 AM
Break
10:30 AM - 11:30 AM
The Security Standard, Electronic and Paper
Minimum security controls for personal data in electronic and non-electronic form: access, passwords, physical security, transfers, backups, and requiring processors to meet the same standard.
11:30 AM - 12:30 PM
The Retention Standard
Retention periods, disposal schedules, secure destruction of electronic and paper records, and evidencing that deletion actually happens.
12:30 PM - 1:30 PM
Lunch
1:30 PM - 2:20 PM
The Data Integrity Standard
Keeping personal data accurate, complete and up to date, correction procedures, and monitoring data quality.
2:20 PM - 3:15 PM
The Proposed 2025 Revision
The measures JPDP proposed, from detailed access controls and incident response plans to retention policies and secure destruction, and how to prepare without treating a draft as law.
3:15 PM - 3:30 PM
Break
3:30 PM - 4:45 PM
Workshop: Control Gap Review
Participants assess their own organisation against the 2015 Standard and the proposed measures, and leave with a prioritised control plan.
4:45 PM - 5:00 PM
Wrap-Up and Q&A
Key takeaways, next steps, and close.
Key Outcomes
- Explain how the Personal Data Protection Standard gives effect to the security, retention and integrity principles
- Apply the 2015 security controls to electronic and paper records
- Set retention periods, disposal schedules and secure destruction
- Maintain data integrity through correction and monitoring procedures
- Anticipate the proposed 2025 revision without treating it as law
- Produce a prioritised control plan for your organisation
Training Mode Physical / Online / Hybrid / e-learning
HRD Corp SBL-Khas Claimable
Level Foundation. For DPOs, IT security, records management, operations and compliance staff. Basic PDPA knowledge helpful.
Duration 1 Day (8 Hours) | 9:00 AM to 5:00 PM
Venue In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)
Assessment A control gap review against the Standard, plus a written knowledge check
Certificate Certificate of Completion issued to all participants upon full attendance