Quick test. Right now, without looking anything up: could you list every place your business holds customers’ personal data? Every form, every spreadsheet, every inbox, every old system, every vendor?
If you hesitated, you’re in good company — and in trouble worth fixing. When we wrote about Singapore’s biggest data breach, the lesson wasn’t sophisticated hacking; it was a company that lost track of what it owned. One forgotten file, 5.9 million records. And the PDPC’s verdict — it could have been prevented — starts with a discipline almost no SME actually practises: the data inventory.
Here’s the thing: under the PDPA you’re accountable for the personal data in your possession or under your control — whether or not you remember having it. You can’t protect what you don’t know you have, you can’t answer a customer’s access request about it, and when the breach clock starts ticking you can’t assess what leaked. The inventory is the foundation everything else stands on. The good news: for a typical SME it’s a spreadsheet and an afternoon or two. Here’s exactly how to do it.
Step 1: Hunt the data — including where it hides
Grab a spreadsheet and start listing every place personal data lives. Don’t overthink “personal data” — if it can identify a person (name, phone, email, NRIC, photo, address, purchase history), it counts.
The obvious places first: your website’s contact and checkout forms, your CRM, your accounting system, your e-commerce platform, your email marketing list, your booking system.
Now the places that actually cause breaches — the hiding spots:
- The website’s back end. Form submissions often sit in the CMS database forever, long after they’ve been emailed to you. If your site was built years ago, there’s a plugin quietly storing every enquiry since launch.
- Inboxes. Every quotation, CV, and customer email attachment. Email is most SMEs’ largest, least-protected database.
- Spreadsheets and exports. The customer list someone downloaded “temporarily” in 2023, still sitting in a Downloads folder or shared drive.
- Chat apps. WhatsApp threads with customer details, photos of NRICs, delivery addresses — on staff members’ personal phones.
- Old systems. The previous CRM you migrated off but never emptied. The defunct app. The old website still live on a subdomain. (This is precisely the RedDoorz failure mode: “defunct” is not a security status.)
- Your vendors. The payroll provider, the marketing agency, the developer with database access, the cloud storage. Under the PDPA, data your vendors process for you is still your responsibility.
- Paper. Sign-in books, printed invoices, forms in a filing cabinet.
A practical trick for completeness: instead of asking “where is data stored?”, walk through your customer’s journey — enquiry, quote, purchase, delivery, support, marketing — and note every point where information about them gets captured or copied. Data follows process; trace the process and you find the data.
Step 2: Record six things about each entry
For every location you found, fill in six columns. This is the whole inventory — resist the urge to make it fancier:
- What personal data is there (names, contacts, payment details, NRIC, etc.)
- Whose — customers, staff, job applicants, suppliers
- Why you have it — the purpose it was collected for
- Who can access it — which staff, which vendors
- How long you keep it — and whether anything is ever actually deleted
- How it’s protected — password? MFA? Encryption? Or “it’s just… there”?
Two of these columns will hurt, and that’s the point. “Why” exposes data you collected with no real purpose — and under the PDPA’s purpose limitation, that’s data you shouldn’t be holding. “How long” exposes the honest answer at most SMEs: forever, by default — which collides with the retention limitation obligation to stop keeping data once its purpose is served.
Step 3: Act on the three ugly findings
Every first inventory produces the same three discoveries. Deal with them in this order:
Delete what you don’t need. Old enquiries, ex-customers from years back, CVs from closed roles, that 2023 export. This is the highest-value security action there is, and it’s free: data you don’t hold can’t be breached, and you can’t be fined for mishandling data you’ve deleted. Minimisation beats every firewall.
Lock down what you keep. Anything sensitive sitting without MFA, shared logins that five people (and one ex-employee) know, vendor access nobody remembers granting — fix by risk, worst first. Your inventory’s column six is now a prioritised to-do list.
Close the orphans. The old systems, dead subdomains, and forgotten apps get properly emptied and retired — not “we don’t use it anymore,” but actually shut down with the data removed. RedDoorz is the S$74,000 case study in the difference.
Step 4: Keep it alive (this is where everyone fails)
An inventory done once is a photograph; the business keeps moving. Three habits keep it true:
- Name an owner. If you have a Data Protection Officer — which the PDPA requires every organisation to designate — the inventory is naturally theirs. In a small SME that’s often the owner or office manager wearing the DPO hat, and that’s fine; what matters is that it’s someone’s job.
- Update on trigger events, not a schedule you’ll ignore: new tool adopted, new vendor engaged, staff member leaves (revoke access the same week), new form added to the website.
- Re-run the hunt annually. One afternoon a year to catch what crept in. Put it next to your tax filing so it actually happens.
What this buys you
For a few hours of unglamorous work, the inventory quietly solves half your PDPA obligations at once. It’s the backbone of the accountability obligation (you can actually demonstrate what you hold and why). It makes a customer’s access or correction request answerable in minutes instead of a panicked week. It’s what lets you meet the breach-notification clock — you can only assess “what leaked and how many people” within three days if you knew what was where before the incident. And it converts your security spending from guesswork into targeting: protect the crown jewels you’ve now located, not everything vaguely.
There’s a softer payoff too. Customers increasingly ask suppliers — especially B2B — how their data is handled. “Here’s our data inventory and retention policy” is a trust signal most of your competitors cannot produce.
(Usual honesty: this is practical guidance, not legal advice. For edge cases — NRIC handling rules, cross-border transfers, sector-specific requirements — check the PDPC’s guides or ask a professional.)
Where Oasis Web Asia comes in
A surprising amount of any SME’s hidden data lives in its website and digital systems — the form plugin hoarding every submission since 2019, the staging site nobody remembers, the developer access never revoked. When we build or take over a site, mapping and minimising that data footprint is part of the job: forms that don’t hoard, retention that actually deletes, access that gets revoked when people move on, and a clear record of what lives where. It’s the same evidence-first approach behind the web development Singapore SMEs trust us with — and if you’d like a second pair of eyes on the digital half of your inventory, we can tell you quickly where your forgotten files are.
If step one of this guide already surfaced something that made you wince, that’s exactly the conversation we like to have.
Start a conversation → — get a free consultation with our Singapore-based team.