The Personal Data Protection Act (PDPA) is now fully in force, and enforcement is getting stricter all the time. This article summarizes a checklist executives can use to assess their organization's readiness on their own, in a short amount of time.
Category 1: Governance and Policy
- The organization has a written personal data protection policy that has been communicated to employees
- A Data Protection Officer (DPO) or clearly designated responsible person has been appointed
- Senior management understands and supports the organization's PDPA efforts
Category 2: Data Management
- An up-to-date Record of Processing Activities (RoPA) is maintained
- The organization knows what personal data it holds, where it's stored, and who can access it
- Data is classified according to sensitivity
Category 3: Data Subject Rights
- There are channels and processes to handle rights requests (access, correction, deletion)
- Consent is obtained properly and evidence of it can be kept on record
- A clear Privacy Notice is published on every channel where data is collected
Category 4: Security and Incident Response
- Appropriate data security measures are in place
- A data breach response plan exists, and the organization knows it must notify within 72 hours
- Data Processor Agreements are in place with partners
How to Score Yourself
If you answered "yes" to fewer than 6 items, your organization carries high risk and should start a Gap Assessment as soon as possible. A score of 6–9 means you're on a good track but still have gaps to close, and 10 or more puts your organization in good standing, with the main task being to keep it up consistently.
PDPA isn't a one-and-done project — it's an ongoing process. Our team can help assess the gap, plan the fixes, and advise on the DPO role every step of the way.