Insights—GRC · PDPA

PDPA for regulated firms: where compliance programmes usually fall short at inspection

Regulated firms often have policies in place. The gaps appear where data protection meets day-to-day operations.

October 2026 · 5 min read

Policies are rarely the problem

Most regulated firms have a privacy notice and a data protection policy. The gaps sit in the operational detail behind them.

Common gaps

  • Records of processing that no longer match the systems and vendors actually in use.
  • Lawful basis chosen by default — often consent — where another basis fits the activity better.
  • Retention that does not reconcile PDPA principles with record-keeping duties under financial regulation.
  • Processors and vendors without data processing terms or oversight.
  • Breach response that has never been rehearsed against the notification timeline.

Connecting PDPA to the rest of the framework

Data protection works best inside the existing risk and compliance framework: the same obligations register, the same control testing, the same reporting to management.

Where to start

Compare the record of processing with the current system and vendor list. Differences between the two usually show where the rest of the work is.

All insights

Start here

Planning a regulated business? Start with a 30-minute assessment.