When is a vendor a data intermediary under the Singapore PDPA?
A vendor is a data intermediary when it processes personal data on behalf of another organisation and for that organisation's purposes under a contract that is made or evidenced in writing. The label in the contract helps, but the role follows the actual processing arrangement: who decides the purpose, who controls the permitted use, and whether the vendor is acting within that scope.
Treat the same company role-by-role. A payroll provider may be a data intermediary for customer payroll processing while still acting as an organisation for its own employee records, recruitment, billing, security logs, and marketing activities.
- Record the processing purpose, the organisation that decides that purpose, and the personal-data categories handled by the vendor.
- Mark the vendor as outside the data intermediary role for any use or disclosure beyond the customer's remit, because that activity can make the vendor responsible as an organisation for that processing.
- Do not route access, correction, consent, notification, or transfer decisions to the intermediary unless the contract gives it an operational support role; the organisation remains responsible for those PDPA duties.
Supports the role test for data intermediaries, including processing on behalf of another organisation and the possibility that one company can hold different PDPA roles for different processing activities.
Supports the practical distinction between an organisation deciding purposes and means and a data intermediary handling data under the organisation's instructions.