// CYBERSECURITY & COMPLIANCE READINESS

PDPA-Oriented System Modernisation Checklist

Modernisation changes where personal data moves and who can access it. Privacy responsibilities should be mapped into the delivery work, not left until launch.

Published 2026-08-04Reviewed 2026-08-047 minute checklist

Questions to answer first

  • What personal data is held, why is it needed, and which business process uses it?
  • Which staff, vendors, environments, integrations, exports, and backups can access it?
  • Will real personal data be copied into development, testing, analytics, or migration tools?
  • How will retention and deletion work in the old system, new system, backups, and exports?
  • Who verifies migration completeness and prevents unintended disclosure during cutover?

A practical review sequence

01

Create a data map

Document categories, purposes, sources, recipients, systems, exports, retention needs, and accountable owners.

02

Reduce unnecessary copies

Use synthetic or masked test data where practical and control migration extracts, temporary files, and support access.

03

Design access deliberately

Map roles to the minimum required data and include joiner, mover, leaver, privileged-access, and periodic-review processes.

04

Plan retention and disposal

Specify how records and temporary migration artefacts are retained, archived, or securely removed across every environment.

05

Keep evidence

Record decisions, approvals, test results, vendor responsibilities, reconciliations, and the final disposal of temporary data.

Red flags

  • Production data is copied freely into test environments
  • The old system has no reliable retention or deletion mechanism
  • Shared accounts prevent access accountability
  • Migration exports remain on personal devices or unmanaged shared folders
  • Vendor responsibilities are assumed but not documented

Useful output

A practical data-handling workstream integrated into modernisation scope, testing, cutover, vendor management, and handover. This is operational readiness, not legal advice.

Explore Cybersecurity & Compliance Readiness

AUTHORITATIVE REFERENCES