Skip To Content
Identify Risks Associated with Collection, Use, Disclosure and Storage of Personal Data is a Program

Identify Risks Associated with Collection, Use, Disclosure and Storage of Personal Data


Sorry! The enrollment period is currently closed. Please check back soon.

Full program description

Identify Risks Associated with Collection, Use, Disclosure and Storage of Personal Data

Course Overview

Download E-Brochure

Learners will understand basic data classification and risk assessment techniques so as to

enable them to identify, assess and address personal data protection risks. At the end of the

course, learners are able to identify and resolve risks in relation to data protection and DNC

provisions, business processes and data intermediaries. Learners will also learn how to conduct

a Data Protection Impact Assessment.

Who Should Attend

Targetted at Data Protection Executives, or team members assisting Data Protection Officers.

Course Duration

2 Days/16 hours

Course Outline

1. Introduction

1.1. Data classification

1.2. Data lifecycle

1.3. Risk identification and risk assessment techniques

2. Data protection risks relating to:

2.1. DP and DNC processes

2.2. Business processes

2.3. Data Intermediaries

2.4. Electronic processing of personal data

3. Risk rating/scoring

4. Responding to risks

4.1. Risk modification

4.2. Risk retention

4.3. Risk avoidance

4.4. Risk sharing

5. Data Protection Impact Assessment (DPIA)

5.1 Conduct risk assessment using a DPIA

6. Managing contracts in compliance with PDPA

6.1 Consent clauses

6.2 Contracts and technical agreements

7. Managing risks with third parties/vendors/data intermediaries

7.1 Conduct due diligence

7.2 Monitor activities and performance

7.3 Terms of contractual agreements

Mode of Assessment

Learners will be required to undergo assessment, consisting of a written test which will be

conducted in the classroom

Course Objectives

Learners will have knowledge of the following:

  • Basic data classification, data lifecycle, and risk identification and assessment techniques.
  • Internal protocols, past solutions and widely-known best practices in risk management or prevention with respect to data protection.
  • Risk management measures and implementation steps.

1.  Data protection risks in relation to:

2.  DP and DNC provisions

3.  Business processes

4.  Data Intermediaries

5.  Electronic processing of Personal Data

  • Data Protection Impact Assessment (DPIA) to identify, assess and address personal data protection risks.

Learners will be able to perform the following:

  • Identify risks and use SOPs to mitigate risks
  • Conduct risk assessment using the DPIA
  • Highlight red flags and other key findings in risk assessment report
  • Propose processes and actions steps to address risks
  • Propose enhancements to risk countermeasures
  • Monitor and check compliance to personal data content clauses, contracts and technical/commercial agreements
  • Manage contracts with third parties (including data intermediary) for products and services
  • Monitor activities and performance of vendors
  • Document changes and updates to contracts and agreements
  • Monitor the effectiveness of security initiatives
  • Identify security risks, threats and vulnerabilities
  • Assist users on various techniques that can anonymise personal data.


1. Learner has attended and is competent for module titled Fundamentals of Personal Data

Protection Act or its equivalent

2. Learners are assumed to be able to:

  • Understand relevant organisational strategies, objectives, culture, policies, processes and products/services;
  • Have information gathering skills to gather and collate necessary data;
  • Have analytical skills to assess policies and procedures;
  • Have business writing skills to prepare management report;
  • Have interpersonal and communication skills to interact with relevant stakeholders;
  • Have facilitation skills to ask the right questions to elicit necessary information; and
  • Be aware of compliance requirements of organisation.


 Before GSTWith GST
Original Course Fee$760.00$813.20
Course Fee after Funding for both Individual and 
Company Sponsored Candidates 50% e2i Funding 
capped at $15/hr for Singaporeans and PRs