Baseline for Personal Data Protection Act (PDPA) & Ministry of Social and Family Development (MSF)/National Council of Social Service (NCSS) compliance:
Data Protection Essential (DPE)
Designed to be easy-to-implement, holistic and cost-effective, the Data Protection Essentials (DPE) is a Data Protection Management Programme (DPMP) that aims to support organisations – particularly Small and Mid-size Enterprises (SMEs) and Voluntary Welfare Organisations (VWOs) – that are starting on their digitalisation journey or collecting personal data as part of their business operations.
Through the DPE, we assist organisations in:
- Establishing a data protection governance structure
- Developing a data protection and security policy
- Identifying and documenting data flows within and out of the organisation
- Establishing basic security practices, including anti-virus/malware protection, software updates, data backup and incident response
- Ensuring employees’ awareness of their data protection and cybersecurity obligations
- Carrying out reviews and updating, where necessary, established policies and conducting table-top exercises to test the cyber and data breach response plans
CISOaaS (Cyber Essential)
Is your organisation ready to face today’s cybersecurity challenges? At TRS, our CISOaaS (Cyber Essentials) service is designed to strengthen your cybersecurity posture through expert guidance and strategic planning. We partner with you to set clear cybersecurity objectives, identify vulnerabilities, and create a customised plan to address those gaps. Our core focus areas include:
- Assets: Safeguarding your critical assets to prevent unauthorised access.
- Secure/Protect: Implementing robust security protocols to protect your systems and data.
- Update: Ensuring regular software and system updates to reduce exposure to vulnerabilities.
- Backup: Establishing reliable backup solutions to maintain data integrity and availability.
- Response: Developing and refining incident response strategies for efficient threat management.
Our team will support you at every stage, guiding you towards achieving the Cyber Essentials certification and solidifying your commitment to cybersecurity excellence. With TRS’s CISOaaS (Cyber Essentials) service, you’re not just meeting standards—you’re building a resilient defence against evolving cyber threats.
Data Protection Trust Mark (DPTM)
Data Protection is no longer an option but a requirement. Demonstrating a strong accountability over an organisation’s data is becoming a competency that many businesses seek.
Achieving a robust data governance standard through the attainment of the DPTM will help your business to increase its competitive advantage and build trust with your customers. TRS has helped many of our clients put in place responsible data protection practices and embark on their DPTM journey, to experience greater assurance and peace of mind in their businesses. These include:
- Setting out the organisation’s approach to managing personal data for various stakeholders, including employees, customers and partners
- Developing data protection policies and practices that are approved by the management
- Communicating the data protection policies to relevant stakeholders (employees, customers, partners, etc) through appropriate platforms
- Documenting policies and processes to review, update and monitor compliance with data protection policies and practices
- Maintaining a Data Inventory Map to document and track personal data flows in the organisation, to ensure personal data is used and disclosed in accordance with the purposes stated in the notifications and consented to by the individuals at the point of collection
- Establishing a data breach management plan with roles and responsibilities of the data breach management team, and processes for notifying the affected individuals, organisations and relevant authorities
Data Protection Officer as-a-Service (DPOaaS) CISOaaS Add-on Service / Outsourced Data Protection Officer Services
Did you know that all organisations are required to appoint a Data Protection Officer? Our outsourced Data Protection Officer (DPO) services offer you the expertise and support needed to navigate complex data protection regulations and keep your business secure.
With our outsourced DPO services, you can:
- Benefit from the knowledge of seasoned data protection professionals without the overhead of a full-time hire.
- Meet the Data Protection Officer (DPO) obligations under the Personal Data Protection Act (PDPA).
- Ensure compliant personal data handling processes are established.
- Receive regular audits and updates to ensure ongoing compliance with data protection laws.
- Equip your employees with the required knowledge to minimise mishandling of personal data.
Cyber Trust Mark (CTM)
Cyber Trust signifies a mark of distinction for organisations to be recognised as trusted partners with robust cybersecurity solutions in place.
Targeted for larger or more digitalised organisations, our Cyber Trust solutions takes on a risk-based approach to enable them to put in place the relevant cybersecurity preparedness measures that commensurate with their cybersecurity risk profile. Aligned also to the Cyber Security Agency of Singapore’s (CSA’s) cybersecurity risk management framework for organisations, we help our clients in the following areas of development:
- Cyber governance & oversight: Developing and guiding the implementation of a cybersecurity strategy and roadmap in which the organisation’s cyber goals are defined and regularly tracked
- Cyber education: Facilitating training and communication of cybersecurity-related laws, regulations and guidelines to all relevant stakeholders, including employees, customers and partners
- Information asset protection: Establishing and guiding the implementation of asset management of servers and endpoints, system security and backups
- Secure access environment: Auditing the policies, processes, procedures and controls within the access environment, and providing guidance to remediate weaknesses from the findings
- Cybersecurity resilience: Translating cybersecurity strategy into a roadmap to achieve planned targets over a time period, to help achieve cyber resiliency over cyber threats, among people, process and technology