Rechtliches
Datenschutzrichtlinie
Wie Meridium Management Consultants Pte. Ltd. personenbezogene Daten nach dem Personal Data Protection Act 2012 von Singapur erhebt, verwendet, offenlegt, schützt und aufbewahrt.
Diese Richtlinie wird in englischer Sprache geführt; die englische Fassung ist maßgeblich. Bei Fragen zum Inhalt wenden Sie sich gern an enquiries@meridium.sg.
Data protection policy
Prepared in accordance with the Personal Data Protection Act 2012 of Singapore and other applicable Singapore laws and regulations.
| Organisation | Meridium Management Consultants Pte. Ltd. (the Company) |
| Document owner | Data Protection Officer (DPO) |
| Version | 1.0 |
| Next review | Annually, or upon material change in law or operations |
| Classification | Internal use, may be shared with clients and partners on request |
1. Introduction and purpose
Meridium Management Consultants Pte. Ltd. (referred to in this policy as Meridium, the Company, we, us or our) provides corporate, advisory and management consulting services to international principals establishing or scaling their operations in Asia. In the course of delivering these services we collect, use, disclose and otherwise handle personal data belonging to our clients, the individuals connected to our clients, our employees, our business partners, our suppliers and members of the public.
Meridium is committed to protecting personal data and to handling it responsibly, lawfully and transparently. This policy sets out how the Company complies with its obligations under the Personal Data Protection Act 2012 (the PDPA) and the subsidiary legislation, advisory guidelines and codes of practice issued by the Personal Data Protection Commission (the PDPC), and how it meets the data protection requirements of the other laws that apply to its business.
The purposes of this policy are to:
- set out the principles and obligations that govern how Meridium handles personal data;
- establish a consistent framework for collection, use, disclosure, protection, retention and disposal of personal data;
- define the roles and responsibilities of the Data Protection Officer, management and all personnel; and
- explain how individuals may exercise their rights and how queries or complaints are handled.
This policy is a binding internal policy. Every director, officer, employee, contractor and temporary or agency staff member of Meridium must read, understand and comply with it. Breach of this policy may result in disciplinary action and, in serious cases, termination of employment or engagement, in addition to any liability that may arise under law.
2. Scope and application
This policy applies to all personal data processed by Meridium, in any form, whether held electronically or in physical records, and regardless of where the data is stored. It applies to all personal data for which Meridium is responsible as an organisation under the PDPA, and to personal data that Meridium processes on behalf of another organisation as a data intermediary.
This policy applies to all personnel of Meridium and to third parties who process personal data on the Company’s behalf. Where Meridium engages a vendor or service provider to process personal data, that arrangement must be governed by a written contract that imposes data protection obligations consistent with this policy and the PDPA.
Where Meridium provides services to clients who are themselves subject to data protection laws outside Singapore, such as the European Union General Data Protection Regulation or the United Kingdom General Data Protection Regulation, the Company will take reasonable steps to support its clients in meeting their obligations and will comply with any additional contractual data protection requirements agreed with those clients.
3. Definitions
The following terms have the meanings set out below. Terms not defined here carry the meaning given to them in the PDPA.
| Term | Meaning |
|---|---|
| Personal data | Data, whether true or not, about an individual who can be identified from that data, or from that data and other information to which the organisation has or is likely to have access. |
| Individual | A natural person, whether living or deceased. The PDPA continues to apply for a limited period to data about a deceased individual. |
| Processing | Any operation performed on personal data, including collection, recording, holding, organisation, use, disclosure, transfer and disposal. |
| Collection, use, disclosure | The gathering, application and sharing of personal data, each of which is separately regulated under the PDPA. |
| Data intermediary | An organisation that processes personal data on behalf of and for the purposes of another organisation, under a written contract. |
| Consent | Agreement by an individual, given freely and on the basis of reasonable notification of purposes, to the collection, use or disclosure of personal data, including deemed consent recognised under the PDPA. |
| DPO | The Data Protection Officer appointed by Meridium to oversee compliance with the PDPA and this policy. |
| CDD | Customer due diligence measures conducted to meet anti-money laundering, countering the financing of terrorism and counter proliferation financing obligations. |
| Data breach | The unauthorised access, collection, use, disclosure, copying, modification or disposal of personal data, or the loss of any storage medium or device on which personal data is stored, in circumstances where unauthorised access is likely. |
4. Our data protection obligations
Meridium structures its handling of personal data around the obligations set out in the PDPA. The Company applies each of the following obligations to its operations.
4.1 Consent obligation
Meridium collects, uses and discloses personal data only with the consent of the individual, unless an exception under the PDPA applies. Consent may be express or, where the conditions are met, deemed. The Company does not obtain consent through false or misleading information or deceptive practices, and does not require an individual to consent to collection, use or disclosure beyond what is reasonable to provide the relevant product or service. An individual may withdraw consent at any time on reasonable notice, and Meridium will inform the individual of the likely consequences of withdrawal and cease the relevant processing unless required or permitted to continue by law.
4.2 Purpose limitation obligation
Meridium collects, uses and discloses personal data only for purposes that a reasonable person would consider appropriate in the circumstances and that have been notified to the individual. Personal data is not used for new purposes without fresh consent or a valid exception.
4.3 Notification obligation
Meridium informs individuals of the purposes for which their personal data will be collected, used or disclosed, on or before collection, unless an exception applies. Notification is provided through this policy, engagement documents, data protection notices, consent forms and the Company website.
4.4 Access and correction obligation
On request, and subject to the exceptions in the PDPA, Meridium will provide an individual with access to their personal data in the Company’s possession or control, and information about the ways in which that data has been or may have been used or disclosed within a year before the request. The Company will correct an error or omission in personal data on request, unless it is satisfied on reasonable grounds that a correction should not be made. Where appropriate, corrected data will be sent to other organisations to which the data was disclosed within a year before the correction.
4.5 Accuracy obligation
Meridium makes reasonable efforts to ensure that personal data it collects is accurate and complete, particularly where the data is likely to be used to make a decision affecting the individual or is likely to be disclosed to another organisation.
4.6 Protection obligation
Meridium protects personal data in its possession or under its control by making reasonable security arrangements to prevent unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks, and the loss of any storage medium or device on which personal data is stored. The security measures applied by the Company are described in section 12.
4.7 Retention limitation obligation
Meridium ceases to retain personal data, or removes the means by which the data can be associated with particular individuals, as soon as it is reasonable to assume that retention no longer serves the purpose for which the data was collected, and is no longer necessary for legal or business purposes. Retention is governed by section 11.
4.8 Transfer limitation obligation
Meridium transfers personal data outside Singapore only where it has taken appropriate steps to ensure that the recipient is bound by legally enforceable obligations to provide a standard of protection comparable to that under the PDPA. Cross-border transfers are addressed in section 10.
4.9 Data breach notification obligation
Meridium assesses data breaches affecting personal data in its possession or control and, where a breach is notifiable, notifies the PDPC and affected individuals within the timelines required by the PDPA. The Company’s breach management procedure is set out in section 13.
4.10 Accountability obligation
Meridium is accountable for the personal data in its possession or control. The Company has appointed a Data Protection Officer, has developed and implemented this policy and supporting practices, makes information about its policies and practices available on request, and trains its personnel. The Company keeps written records sufficient to demonstrate its compliance.
5. Personal data we handle and why
The categories of personal data that Meridium handles, and the principal purposes for handling them, include the following. This is not an exhaustive list, and the specific data handled in any engagement depends on the services provided.
| Category of individual | Typical personal data | Principal purposes |
|---|---|---|
| Clients and prospective clients | Name, contact details, role, business correspondence | Responding to enquiries, providing proposals, delivering services, billing, relationship management |
| Directors, shareholders, beneficial owners and officers of client entities | Name, nationality, identification document details, residential and contact details, source of wealth or funds information | Incorporation and corporate secretarial services, statutory filings, customer due diligence and AML compliance |
| Employees and job applicants | Identification, contact, employment, remuneration, tax, bank account and next of kin details | Recruitment, payroll, statutory contributions, work pass administration, performance and HR management |
| Suppliers, partners and referrers | Name, contact details, banking details where relevant | Procurement, payment, partnership and referral administration |
| Website visitors and event attendees | Contact details, communications, technical and usage data | Responding to enquiries, marketing where consent is given, event administration and website operation |
6. Lawful bases and exceptions to consent
In addition to obtaining consent, Meridium relies, where appropriate, on the exceptions recognised by the PDPA. These include the following, applied only where the relevant statutory conditions are satisfied:
- deemed consent, including deemed consent by contractual necessity and deemed consent by notification, where the conditions in the PDPA are met;
- legitimate interests, where the benefit to Meridium or another party outweighs any adverse effect on the individual and an assessment has been documented;
- business improvement, for purposes such as improving services, operational efficiency and developing new offerings;
- legal or regulatory requirement, where collection, use or disclosure is required or authorised under other written law, including the obligations described in sections 7 and 8; and
- other PDPA exceptions, such as where collection, use or disclosure is necessary for an investigation or proceedings, or in the interest of the individual where consent cannot be obtained in a timely way.
Where Meridium relies on the legitimate interests or business improvement exceptions, the relevant assessment is documented and retained by the DPO.
7. National identifiers and sensitive personal data
Meridium handles national identification numbers, such as the NRIC or FIN, and copies of identification documents only where the collection, use or disclosure is required under law, or is necessary to accurately establish or verify an individual’s identity to a high degree of fidelity. This approach is consistent with the PDPC’s guidance on the handling of national identifiers. Where identity verification can be achieved by other means, Meridium uses those means instead. The Company does not use national identification numbers as a default reference, login or account identifier.
Meridium recognises that certain personal data, such as identification documents, financial information, and information about source of wealth and funds, carries a higher risk of harm if compromised. Such data is subject to enhanced protection, access restriction and oversight.
8. Customer due diligence and AML, CFT and counter proliferation financing
Where Meridium provides corporate services within the meaning of the Corporate Service Providers Act 2024, which took effect on 9 June 2025, it is required to register with the Accounting and Corporate Regulatory Authority and to comply with obligations relating to anti-money laundering, countering the financing of terrorism and counter proliferation financing. To meet these obligations, Meridium collects, uses, discloses and retains personal data through customer due diligence measures, including identification and verification of clients, beneficial owners and controllers, screening, and ongoing monitoring.
Personal data collected for customer due diligence is handled as follows:
- it is collected and processed to meet legal and regulatory obligations, and the relevant PDPA exceptions are relied upon where consent is not the basis of processing;
- it is accessible only to personnel who require it to perform compliance and client onboarding functions;
- it may be disclosed to ACRA, the Suspicious Transaction Reporting Office, other competent authorities and screening service providers where required or permitted by law; and
- it is retained for at least five years after Meridium stops providing corporate services to the customer, in line with the record keeping requirement under the Corporate Service Providers Act 2024 and its regulations, and for longer where another law requires.
Where a disclosure to a competent authority is required by law, Meridium makes that disclosure in accordance with the relevant statutory regime, including any confidentiality and tipping off restrictions that apply.
9. Data intermediaries and third party processors
Meridium engages third party service providers, such as IT, cloud, payroll, screening and professional service providers, that process personal data on its behalf. The Company carries out reasonable due diligence on such providers and enters into written contracts that require the provider to protect personal data to a standard at least equivalent to that required by the PDPA, to process the data only on Meridium’s instructions and for the agreed purposes, to assist with access and correction requests and breach response, and to return or securely dispose of the data on termination.
Where Meridium acts as a data intermediary for a client, the Company processes personal data only in accordance with its contract with that client, and complies with the Protection and Retention Limitation Obligations and the data breach notification requirements that apply to data intermediaries under the PDPA, including notifying the client without undue delay where it has credible grounds to believe a breach has occurred.
10. Cross border transfers of personal data
Meridium operates across Asia and works with international principals, and may transfer personal data outside Singapore for the purposes described in this policy. Before transferring personal data outside Singapore, Meridium takes appropriate steps to ensure that the recipient is bound by legally enforceable obligations to provide a standard of protection comparable to that under the PDPA. These steps may include contractual clauses, intra group data protection arrangements, binding corporate rules, or reliance on a recognised certification, as appropriate. Where a transfer relies on consent, the individual is informed of the transfer before it takes place.
11. Data retention and disposal
Meridium retains personal data only for as long as it is needed for the purposes for which it was collected, or to meet legal, regulatory, accounting or contractual requirements. Retention periods are set having regard to the requirements of the applicable laws, including the following examples:
| Record type | Indicative minimum retention |
|---|---|
| Customer due diligence and AML records | At least 5 years after the end of the corporate services relationship |
| Accounting and tax records | At least 5 years, in line with the Income Tax Act and Goods and Services Tax Act |
| Corporate and statutory records | As required under the Companies Act 1967 |
| Employee records | Duration of employment plus the periods required under the Employment Act and related law |
| General client engagement records | Duration of the engagement plus the applicable limitation period |
When personal data is no longer required and no retention obligation applies, Meridium disposes of it securely, or anonymises it so that individuals can no longer be identified. Physical records are shredded or otherwise securely destroyed, and electronic data is securely erased.
12. Security of personal data
Meridium applies reasonable administrative, technical and physical measures to protect personal data, proportionate to the sensitivity of the data and the risks involved. These measures include:
- Organisational measures: access on a need to know basis, confidentiality undertakings, this policy and supporting procedures, staff training, and vendor management.
- Technical measures: access controls and authentication, encryption of data in transit and, where appropriate, at rest, network and endpoint protection, logging and monitoring, secure backups, and patching.
- Physical measures: secured premises, locked storage for physical records, clear desk practices, and controlled disposal of documents and media.
Personnel must report any suspected weakness, loss or compromise of personal data to the DPO immediately, in accordance with section 13.
13. Data breach management and notification
Meridium maintains a data breach response procedure based on the PDPC’s framework of containing the breach, assessing its impact, reporting where required, and evaluating the response to prevent recurrence.
Any person who becomes aware of an actual or suspected data breach must report it to the DPO without delay. The DPO leads the assessment of whether the breach is notifiable. A breach is notifiable where it results in, or is likely to result in, significant harm to the affected individuals, or where it is of significant scale, which means it affects 500 or more individuals.
Where a breach is assessed to be notifiable, Meridium notifies the PDPC as soon as practicable, and in any case no later than three calendar days after the day the Company determines that the breach is notifiable. Where the breach is likely to result in significant harm to affected individuals, Meridium also notifies those individuals, at the same time as, or after, notifying the PDPC, unless an exception to individual notification applies. The Company conducts its assessment expeditiously and does not delay it unreasonably.
Where Meridium acts as a data intermediary, it notifies the organisation on whose behalf it processes the personal data without undue delay from the time it has credible grounds to believe that a breach has occurred, so that the organisation can meet its own obligations.
Meridium keeps a record of all data breaches, whether or not notifiable, together with the assessment and the remedial action taken.
14. Individual rights and how to exercise them
Individuals may, in relation to personal data held by Meridium:
- request access to their personal data and information about how it has been used or disclosed;
- request correction of an error or omission in their personal data;
- withdraw consent previously given, on reasonable notice; and
- raise a query or complaint about how their personal data is handled.
Requests should be made in writing to the Data Protection Officer at enquiries@meridium.sg. Meridium will respond to an access or correction request as soon as reasonably possible, and will inform the individual within thirty days where it is unable to respond within that period. A reasonable fee may be charged for an access request, and the individual will be informed of any fee in advance. Meridium may decline a request where the PDPA permits or requires it to do so, and will inform the individual of the reason where it is required to.
15. Marketing messages and the Do Not Call provisions
Where Meridium sends marketing messages, it does so in compliance with the consent and Do Not Call provisions of the PDPA and with the Spam Control Act 2007. Before sending a specified message to a Singapore telephone number, Meridium checks the relevant Do Not Call Registry unless it has clear and unambiguous consent in evidential form, or another exception applies. Marketing messages identify the Company as the sender, provide contact information, and offer a means to unsubscribe. Meridium acts on unsubscribe requests within the period required by law.
16. Roles and responsibilities
16.1 Data Protection Officer
The Company has appointed a Data Protection Officer who is responsible for overseeing compliance with the PDPA and this policy, acting as the contact point for individuals and the PDPC, fostering a culture of data protection, advising on data protection matters, handling access, correction and withdrawal requests, leading data breach response, and maintaining records of compliance. The DPO may be contacted at enquiries@meridium.sg. The appointment of a DPO does not relieve Meridium of its obligations under the PDPA.
16.2 Management
Management is responsible for supporting the DPO, allocating adequate resources, and ensuring that data protection is embedded in business processes and in the selection and oversight of vendors.
16.3 All personnel
All personnel must comply with this policy, handle personal data only as authorised and necessary for their role, keep personal data secure and confidential, report breaches and weaknesses promptly, and complete data protection training.
17. Training and awareness
Meridium provides data protection training to personnel on induction and at regular intervals, and additional training where roles involve higher data protection risk, such as client onboarding, compliance, payroll and IT. The DPO maintains a record of training delivered.
18. Applicable laws and regulatory framework
This policy is designed to be consistent with the laws and regulatory instruments that apply to Meridium’s handling of personal data, including the following. This list is not exhaustive and is read together with any guidance issued by the relevant authorities from time to time:
- the Personal Data Protection Act 2012 and its subsidiary legislation, including the Personal Data Protection (Notification of Data Breaches) Regulations 2021;
- the advisory guidelines, codes of practice and decisions issued by the Personal Data Protection Commission;
- the Corporate Service Providers Act 2024 and the Corporate Service Providers Regulations, and related AML, CFT and counter proliferation financing requirements;
- the Spam Control Act 2007 in relation to electronic marketing messages;
- the Companies Act 1967, the Income Tax Act 1947 and the Goods and Services Tax Act 1993 in relation to record keeping and retention;
- the Employment Act 1968 and related law in relation to employee records; and
- where applicable to a particular engagement, foreign data protection laws such as the European Union and United Kingdom General Data Protection Regulations, as agreed with the relevant client.
Where any provision of this policy is inconsistent with a mandatory requirement of applicable law, that requirement prevails, and the remainder of the policy continues to apply.
19. Queries, complaints and contact
Any query or complaint about how Meridium handles personal data should be directed to the Data Protection Officer at enquiries@meridium.sg or to the registered office at 143 Cecil Street, #09-01 GB Building, Singapore 069542. Meridium will acknowledge and investigate complaints and respond in a reasonable time. If an individual is not satisfied with the Company’s response, the individual may refer the matter to the Personal Data Protection Commission.
20. Review and governance
This policy is reviewed at least annually, and whenever there is a material change in the applicable law, in the PDPC’s guidance, or in Meridium’s operations or systems. The DPO is responsible for proposing updates, and material changes are approved by management. The current version of this policy supersedes all previous versions.