Mail Fulfillment Services Singapore

    Data Intermediary Under the PDPA: What It Means for a Print Vendor

    Handing a file of customer records to a print vendor does not move your accountability for it. Under the PDPA the vendor also carries protection and retention duties of its own. These are the controls that apply to your file while it is with us, and the evidence you can ask for on each.

    Get a quote

    Tell us about your mailing

    Volume, format and the date it needs to land. We come back with an all-in cost within a few business hours.

    By submitting this form you consent to In-Touch Singapore Pte Ltd collecting and using your personal data for the purpose of responding to your enquiry, in accordance with Singapore's Personal Data Protection Act (PDPA).

    What is a data intermediary?

    A data intermediary is an organisation that processes personal data on behalf of another organisation. Singapore's PDPA binds it to two obligations in its own right: protection under section 24 and retention limitation under section 25. The organisation that sent the data keeps every other obligation, and keeps its own accountability for the data.

    The Personal Data Protection Commission has stated the position for this industry directly. Its Guide for Printing Processes for Organisations, published in May 2018, says that because print vendors handle personal data in the process of printing, print vendors are considered data intermediaries.

    So a mailing house is not simply an extension of your compliance perimeter. It is a separately bound party, and the controls below are the ones that obligation attaches to.

    Which assurance route covers this work

    Print-side data handling is governed by the PDPA and by the terms of the engagement, not by the ABS OSPAR audit. Our OSPAR-audited scope is mailroom, messaging and local courier services, and it does not extend to printing or lettershopping — we set that out in full on our page explaining what it means to be OSPAR audited. For the print side, the PDPA is the operative framework, and its obligations on a data intermediary carry financial penalties, so it is not the weaker route. It is the applicable one.

    Which obligations sit with us, and which stay with you

    Section 4(2) of the PDPA applies the Protection Obligation and the Retention Obligation, sections 24 and 25, to a data intermediary processing data under contract. Consent, notification, access and correction are not carved in: those remain with the organisation that collected the data. Section 4(3) then puts it beyond doubt from the other direction, giving the sending organisation the same obligation for data processed on its behalf as if it had processed the data itself. Nothing you send us reduces what the PDPA asks of you. What it does is add a second party who is answerable for the production controls.

    What PDPC asks of a print vendor

    PDPC's printing guide is advisory rather than binding, and it names the controls it expects to see. The roles of do-er and checker should be separated so the check is independent. The checker should be trained in the method of checking. There should be a documentary trail of both. Checks should be proportionate to the volume and sensitivity of the data, and placed at a stage where a correction can still reverse the error rather than record it. We work to that structure, and it is worth reading the guide before you write your next print tender, because it is also the clearest statement of what you are entitled to ask for.

    Why a re-sort invalidates the check before it

    In Aviva Ltd and Toh-Shi Printing Singapore Pte Ltd [2016] SGPDPC 15, statements for 7,794 policyholders went out carrying the wrong information, disclosing the personal data of 8,022 individuals. The client had signed off sample cases before printing. The vendor then sorted the data again, by postal code, overseas address and undeliverable mail, and printed on the strength of the earlier sign-off. The Commission found the breach would have been prevented had the vendor issued fresh samples after that sort and re-run its quality checks against the client's original source data. The operating rule we take from it: any step that reorders or re-associates a file invalidates the check that came before it, so the check runs again, against source, not against the intermediate file.

    Encrypted transfer

    Data should never move by ordinary email. Files travel over SFTP with AES-256 encryption, which keeps them unreadable to anyone intercepting them in transit. PDPC's printing guide names SFTP among the measures it lists for protecting personal data on its way to a print vendor, alongside password protection and encrypting portable media.

    Restricted-access processing

    While a job is running, the live customer file is open to the people running it rather than to the wider business, and for the duration of the job rather than indefinitely.

    Purge after production

    Section 25 asks an organisation to stop retaining personal data once the purpose it was collected for is no longer served and retention is no longer needed for legal or business reasons. In print work that point arrives early, usually at lodgement. Data is removed after production rather than held on a production server, and we will tell you when that happened for your job. PDPC's guide suggests specifying a deletion period and keeping a retention schedule rather than relying on an assurance, so ask for the period in writing.

    Recipient matching and window checks

    The characteristic failure in mail production is one recipient receiving another recipient's document. A 2D barcode on the page is matched against the envelope before sealing, so a mismatch halts the pack rather than being sealed and lodged. Where an envelope has a window, the position of personal identifiers on the page decides what is visible from outside, so page layout is checked against the window as a privacy control rather than a print-quality one.

    Records you can produce afterwards

    Production steps are logged and reconcilable against your input file, so you can show what was produced, how many pieces, and when they were lodged. For regulated senders this is usually the part that matters most, because an assurance conversation turns on what you can evidence after the fact rather than on what was intended.

    Common questions

    Secure Data Printing — frequently asked

    An organisation that processes personal data on behalf of another organisation, excluding that organisation's own employees. Where it processes under contract, sections 4(2), 24 and 25 of the PDPA bind it to the Protection Obligation and the Retention Obligation. The remaining obligations, including consent and notification, stay with the organisation that collected the data.

    Yes. PDPC's Guide for Printing Processes for Organisations, published in May 2018, states that because print vendors handle personal data in the process of printing, they are considered data intermediaries. That applies to us for every job where you send us a customer file.

    ABS OSPAR — the Association of Banks in Singapore's Outsourced Service Provider's Audit Report — is an independent audit of a service provider's controls against the ABS Guidelines. Singapore banks and financial institutions use it to vet the outsourced providers that handle their customers' data. It is an audit report, not a one-off certification, and is reviewed on an ongoing basis.

    No. Our ABS OSPAR-audited scope is recorded on the ABS public register as mailroom, messaging and local courier services, and it does not extend to printing or lettershopping. Print-side data handling is governed by the PDPA and by the engagement terms instead. Several other providers on the same register do carry statement printing and enveloping in their audited scope, and the register will tell you who.

    No, because there is no such thing. OSPAR is an independent audit report, not a certification, and there is no OSPAR certificate. In-Touch is ABS OSPAR-audited within the scope recorded on the Association of Banks in Singapore's public register, where the listing can be checked directly.

    No, and treat any vendor who says otherwise carefully. Section 4(3) gives your organisation the same obligation for personal data processed on your behalf as if you had processed it yourself. What outsourcing adds is a second party carrying the Protection and Retention Obligations for the production stage. Both apply at once.

    Yes. In Aviva Ltd and Toh-Shi Printing Singapore Pte Ltd [2016] SGPDPC 15 the Commission found the insurer had done appropriate due diligence and was not in breach, and imposed a financial penalty on the print vendor alone for a failure in its sorting and checking process. The decision is public and worth reading before you appoint a mailing house.

    PDPC's printing guide lists what to consider including: the vendor's PDPA obligations, each party's responsibilities during setup and execution, the policies the vendor will implement, the specific handling procedures and supervisory checks, disposal procedures once the data is no longer needed, and your right to review the vendor's processes. We will agree to that review right in writing.

    You remain accountable, and we are separately liable for the Protection and Retention Obligations while the file is with us. That is the reason to ask for evidence of each control rather than to rely on a general security claim.

    Files travel over SFTP with AES-256 encryption rather than by ordinary email, so the contents are unreadable to anyone intercepting them in transit.

    It is purged after production rather than retained indefinitely. Ask us to confirm the retention period in writing for your job, so the commitment sits in the engagement terms rather than on a web page.

    A 2D barcode on the page is read by an inline scanner and matched against the envelope before the pack is sealed. If they do not pair, the line halts rather than sealing the piece — the control prevents the mismatch instead of recording it afterwards. Where a file is re-sorted after your sign-off, the check is run again against your source data rather than against the sorted file.

    You do. A data intermediary's duty runs to the organisation it is processing for: we notify you without undue delay once there are credible grounds to believe a breach has occurred, and you assess whether it is notifiable to PDPC and to affected individuals. Baker McKenzie and Drew & Napier both place this at section 26C(3)(a) of the PDPA.

    Yes. Production steps are logged and reconcilable against your input file, so you can evidence what was produced, in what quantity, and when it was lodged. Tell us what your compliance or audit team needs to see and we will confirm what we can produce before the job starts.

    Yes, including small-point variable data, barcodes and OMR tracks. Legibility of machine-read elements matters operationally as well as visually, because downstream sorting and the insertion check both depend on them scanning reliably.