PDPA basics for prospecting: consent, purpose and records

You will be able to collect and store prospect details in a way that follows the PDPA's main obligations.

After a busy trade event you come home with a stack of business cards and a dozen new phone numbers typed into your contacts. A week later, you add them all to your monthly newsletter, send a few marketing texts, and pass two names to a friend who sells something related. It all feels like normal follow-up. Some of it is, and some of it is the kind of thing Singapore's data protection law is written to stop.

This lesson covers the parts of the Personal Data Protection Act, the PDPA, that matter most when you prospect: why you collect someone's details, what you tell them, what you record, and what you do when they ask you to stop. It is an outline of how the rules work, not legal advice. The PDPC, which administers the PDPA, publishes guidelines that go into far more detail, and your compliance team or a lawyer can advise on a specific case.

Collect for a purpose they would expect

The PDPA is built around purpose. You collect, use and disclose someone's personal data for purposes a reasonable person would consider appropriate in the circumstances, and you tell them what those purposes are. In most prospecting situations, that means getting consent for what you plan to do, and making sure the person knows what they are agreeing to.

In practice this comes down to a simple question you ask at the point of collection: what am I going to do with these details, and does this person know? If Mei collects a founder's number at an event to arrange a follow-up chat about bookkeeping, and says so, that is a purpose the founder would expect. Adding the same number to a weekly promotional broadcast, or passing it to someone else, is a different purpose, and the founder did not agree to it.

Tell people your purpose in plain words when you collect their details. "Can I take your number so I can send you a time for a coffee next week?" does the job in conversation. An enquiry form on your website should say what you will use the details for. If you later want to use the data for something new, you generally need to tell them and get consent for that new purpose too.

A business card is not a blanket yes

A business card handed over at an event says "you may contact me about what we discussed". It does not say "add me to every list you have".

There is a nuance here. The PDPA treats business contact information, such as a name, job title and work phone number given for business purposes, differently from personal data used in a personal context, and much of the Act's consent and purpose regime does not apply to it. The PDPC's guidance on business contact information explains where the line sits. But that does not make every use of a card fair game. Many cards carry a personal mobile number, the Do Not Call rules from lesson 5.1 still apply to marketing calls and texts to Singapore numbers, and a person who finds themselves on lists they never asked for will not take your next message well.

So the working habit is simple: use what someone gave you for the purpose they gave it, and ask before you use it for more.

Keep a record of source and consent

If someone asks where you got their number, you should be able to answer in seconds. And if you are relying on consent for marketing, you should be able to show when and how it was given.

Two fields in your contact list do most of this work. A source field records where each contact came from: "met at an F&B trade event, March", "website enquiry", "introduced by Siti". A consent note records what they agreed to, in plain words, with a date: "agreed to a follow-up call about bookkeeping, 12 March", "opted in to monthly newsletter via website form, 3 April", "no consent for marketing texts".

Darren adds these fields to every new contact the same day he meets them. It takes seconds when the memory is fresh and is nearly impossible to rebuild months later from a pile of unlabelled names. Lesson 6.3, The minimum CRM fields worth tracking, makes both fields part of your standard setup.

Act on stop requests at once

People can withdraw their consent. When someone asks you to stop contacting them, or to remove them from a list, act on it promptly and note it in your CRM straight away: the date, what they asked for and what you did.

This matters for two reasons beyond the law. First, a person who asked to stop and then hears from you again is a person who will complain. Second, if you work with others or use several tools, a request noted in only one place can easily be missed by the next campaign. The note in your CRM is what stops the second message from going out.

Make stopping easy, too. Every marketing message should tell people how to stop hearing from you, a point lesson 5.4 builds into your checklist.

Start with your recent contacts

You do not need to audit every contact you have ever made today. Start with the most recent ones, where you still remember how you met and what was said. The activity below asks you to add a source field and a consent note field to your contact list and fill them in for your twenty most recent contacts.

Add a source field and a consent note field to your contact list and fill them in for your twenty most recent contacts.

Course

Junxiong-WFG Organisation is an authorised representative of AIA Financial Advisers Private Limited (Reg. No. 201715016G).