PDPA-Oriented System Modernisation Checklist
Modernisation changes where personal data moves and who can access it. Privacy responsibilities should be mapped into the delivery work, not left until launch.
Questions to answer first
- What personal data is held, why is it needed, and which business process uses it?
- Which staff, vendors, environments, integrations, exports, and backups can access it?
- Will real personal data be copied into development, testing, analytics, or migration tools?
- How will retention and deletion work in the old system, new system, backups, and exports?
- Who verifies migration completeness and prevents unintended disclosure during cutover?
A practical review sequence
Create a data map
Document categories, purposes, sources, recipients, systems, exports, retention needs, and accountable owners.
Reduce unnecessary copies
Use synthetic or masked test data where practical and control migration extracts, temporary files, and support access.
Design access deliberately
Map roles to the minimum required data and include joiner, mover, leaver, privileged-access, and periodic-review processes.
Plan retention and disposal
Specify how records and temporary migration artefacts are retained, archived, or securely removed across every environment.
Keep evidence
Record decisions, approvals, test results, vendor responsibilities, reconciliations, and the final disposal of temporary data.
Red flags
- Production data is copied freely into test environments
- The old system has no reliable retention or deletion mechanism
- Shared accounts prevent access accountability
- Migration exports remain on personal devices or unmanaged shared folders
- Vendor responsibilities are assumed but not documented
Useful output
A practical data-handling workstream integrated into modernisation scope, testing, cutover, vendor management, and handover. This is operational readiness, not legal advice.
Explore Cybersecurity & Compliance Readiness