Data Protection Trustmark Certification

About

The Data Protection Trustmark (DPTM) is a voluntary enterprise-wide certification for organisations to demonstrate accountable data protection practices. The DPTM will help businesses increase their competitive advantage and build trust with their customers and stakeholders.

The directory of DPTM-certified organisations can be found here (949.56KB).

Hear from these industry leaders - AIG Singapore, Alibaba Cloud Singapore, M1 and MaNaDr – on why it pays to have the DPTM.

What DPTM means to Consumers

As a consumer, you can rest assured that an organisation certified with the DPTM has put in place responsible data protection practices and will take better care of your personal data. Learn more about DPTM for Consumers here.

Who can apply?

Organisations that have put in place a data protection regime to comply with the obligations of the PDPA can apply for DPTM.

They should be either (1) formed or recognised under the laws of Singapore, or (2) resident, or having an office or a place of business, in Singapore, and in any case, not a public agency (as defined in the Personal Data Protection Act 2012).

Organisations should assess its readiness using the DPTM Certification Checklist (275.80KB) before applying.

Organisations with ISO/IEC 27001 and 27701 may find it easier to attain DPTM certification as they have demonstrated good information security and privacy information management standards.

Upon submission of the application, the Applicant Organisation is bound by the Terms of Agreement (571.68KB) of the DPTM scheme.

Apply Here

 

Certification Costs

i. Application fee:

Application fee of S$535 (inclusive of GST) is payable to IMDA.

To encourage organisations to take up more than one certification (i.e. DPTM, CBPR and PRP), one application fee of S$535 is payable to IMDA when organisations apply for multiple certifications in a single application process.

ii. Assessment Fee:

Assessment fee, payable to the Assessment Body, ranges and depends on the size of the organisation (e.g. annual sales turnover, no. of sites, etc) and the Assessment Body you engaged. Please approach the Assessment Bodies listed in this website for a quotation to confirm the actual fee.

The table below shows the range of pricing paid by companies for the DPTM certification (as of May 2022):

Annual revenue of Enterprises < $10m $10m – $100m > $100m
Range
$3,500 - $10,800 $4,320 - $8,000 $4,000 - $14,300
Average
$4,600 $6,000 $7,900
75% of companies are charged below
$4,500 $6,300 $8,400
50% of companies are charged below $4,320 $6,300 $8,000
25% of companies are charged below
$4,200 $6,000 $6,000

Note:

1. Assessment fees shown exclude GST and are based on actual transacted prices for the past one year. Figures in this table will be updated quarterly.

2. The fees are based on a single entity taking the DPTM certification and exclude companies taking multiple certifications (i.e. DPTM and CBPR/PRP) or covering multiple entities. Information presented is accurate to the best of our effort.

3. Charges that are higher than the benchmarks may not be unreasonable, particularly where a case is complex and requires significantly more time or effort to complete. Kindly approach the assessment bodies to ask for quotations for comparison.

Funding Support:

Eligible organisations can consider applying to Enterprise Singapore (ESG) to seek support for some of the costs for DPTM certification and consultancy services. Details on the criteria and application process can be found below:

Interested organisations may refer to this Quick Guide on Enterprise Development Grant Application (230.61KB).

Eligible non-profit organisations may write to the National Council of Social Services (NCSS) at Tech-and-GO@ncss.gov.sg for more details on funding support.

#As announced at Budget 2022, for the Food Services and Retail sectors, support level will be at up to 80% from 1 April 2022 to 31 March 2023.

Assessment Body

The Assessment Body (AB) acts as an independent body to assess that an organisation’s data protection practices conform to the DPTM requirements. An organisation may select any of the following five ABs:

Assessment Body Contact Person  Contact No  Email 
BSI Group Singapore Stella Kong 6270 0777 DPTM@bsigroup.com
EPI Certification Pte Ltd May Cheow 8823 3347 Audit-support@epi-certification.com
may@epi-certification.com
ISOCert Pte Ltd

Saju S Pillai

9105 4718

saju@isocert.com.sg

Jean Poh

9475 5120 / 6659 0810

DP-Certifications@isocert.com.sg

Setsco Services Pte Ltd Dixon Ng 9795 9875 / 6895 0650 ngds@setsco.com
Laura Koh 6895 0659 laurakoh@setsco.com
TUV SUD PSB Pte Ltd Erichsen Soong 8777 5844 dp_trustmark@tuvsud.com
Edmund Gan
6973 6764

 

For more information on how to be an assessment body, please refer to our information kit (324.47KB).

DPTM Certification Requirements and Resources

The DPTM Certification Framework was developed based on adopting and aligning it with Singapore’s enhanced PDPA and incorporating elements of international benchmarks and best practices. Organisations that are interested to incorporate DPTM into their audit, certification, sectoral frameworks, etc can email Data_Protection_Certifications@imda.gov.sg for discussion.

*For more information about the enhanced PDPA, visit the PDPC website.

List of DPTM Consultancy Service Providers

Organisations may approach any of the following consultancy service providers to prepare them for the DPTM certification. A listing of a DPTM consultancy service provider in this directory does not signify that the DPTM consultancy service provider is in any way accredited, endorsed or certified by the IMDA. It also does not imply a referral or recommendation by the IMDA. Please exercise due care and judgement prior to engaging any of the DPTM consultancy service providers listed below.

 

Any engagement of the DPTM consultancy service providers is strictly on a private basis between the DPTM consultancy service provider and yourself and the IMDA is not a party to such an engagement. You are therefore solely responsible for the private engagements that you may enter into with the DPTM consultancy service providers. If there is a disagreement arising from the engagement with the DPTM consultancy service providers, you may wish to seek independent legal advice.

DPTM consultancy service providers who are interested to be listed can contact us at data_protection_certifications@imda.gov.sg.

S/N Entity Name Is DPTM-certified  Has CQI-listed consultant(s) Business Address  Contact Person
1 Lloyd McGill Pte Ltd
 

230 Victoria Street
#15-01/08, B07, Bugis Junction
S(188024)
Name: Marinissa Reyes
Tel: 6352 1566
Email: admin@lloydmcgill.com 
2 P2D Solutions Pte Ltd Suntec Tower Three, #42-01,
8 Temasek Boulevard
S(038988)
Name: Desmond Chow
Tel: 9228 3782
Email: desmond.chow@p2dsolutions.com.sg
3 Straits Interactive Pte Ltd 43D Beach Road
Evershine & Century Complex
S(189681)
Name: Lina Wong
Tel: 6602 8010 ext 14
Email: dpaas_sme@straitsinteractive.com
4 TRS Forensics Pte Ltd 90 Lorong 23 Geylang #05-01
Agrow Building 
S(388393) 
Name: Tan Swee Wan
Tel: 9755 7010
Email: tansweewan@trsforensics.com
5 DSP ISO Consultants Pte Ltd -
11 Woodlands Close 
#08-20, Woodlands 11
S(737853)
Name: Dinesh Balakrishnan 
Tel: 9226 9011
Email: nesh@dspiso.com
6 QuESH Consultants (Pte) Ltd - 50 Bukit Batok Street 23 #07-10 
Midview Building
S(659578)
Name: Ngo Seow Kuan 
Tel: 6316 6602
Email: sales@quesh.com.sg

Added Benefit For Certified Organisations

DPTM-certified organisations that apply for cyber insurance can enjoy faster application processing and competitive offers. QBE Insurance Singapore, Delta Insurance, Pandamatics Underwriting, and Beazley have recognised DPTM in their cyber insurance underwriting process, as the certification assures insurers that an applicant has sound and responsible data protection practices in place.

Please contact the participating cyber insurers to find out more.

S/N Cyber Insurer Cyber Insurance Products
1 QBE Insurance (Singapore) Pte. Ltd. Cyber and Data Security (Auto-bind) Policy
2 Delta Underwriting Pte Ltd Delta Cyber Liability Insurance Policy
Pandamatics Underwriting Bamboo Shoot
Beazley Syndicates at Lloyd’s Beazley’s InfoSec 2.0

Resources

Contact

For questions, please refer to our FAQs.

For queries, please email Data_Protection_Certifications@imda.gov.sg or call 6377 3800.

Last updated on: 20 Jun 2022