PDPA Compliance

Last update: 26 August 2026

----------

## 1. About This Statement

Integrated Retail Pte Ltd ("Integrated Retail", "we", "us", "our") supplies, implements, hosts and supports retail technology solutions — including retail management and point-of-sale software, analytics platforms, in-store sensors and related hardware.

We operate across Singapore, Malaysia, Thailand and Indonesia. Each of these markets has its own personal data protection law, and our clients need to know that the solutions we deliver sit comfortably within them.

This statement explains how we meet those obligations across our whole portfolio. It is written for clients and their IT, legal and compliance teams, and is deliberately solution-independent — it applies equally to a point-of-sale rollout, an analytics platform or a sensor deployment.

This statement is for information only. It is not legal advice, and it does not vary the terms of any contract between us and a client.

  

## 2. The Laws That Apply to Us

| Market | Law | Regulator |
|--|--|--|
|Singapore  | Personal Data Protection Act 2012 (PDPA) | Personal Data Protection Commission (PDPC)
|Malaysia|Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024 |Personal Data Protection Commissioner (JPDP)
|Thailand|Personal Data Protection Act B.E. 2562 (2019)|Office of the Personal Data Protection Committee (PDPC)
|Indonesia|Personal Data Protection Law No. 27 of 2022 (UU PDP)|Personal data protection authority designated under the PDP Law


The four regimes differ in detail but share the same architecture: tell people what you are doing with their data, use it only for that purpose, keep it accurate and secure, don't keep it longer than you need, control where it goes, let people access and correct it, and report breaches promptly.

Because of that common structure, we run one set of internal practices calibrated to the strictest applicable requirement, rather than four separate compliance programmes. Where a market imposes a shorter deadline or a stricter test, that becomes our working standard everywhere.

  

## 3. Terminology Across the Four Markets

The same two roles appear in all four laws under different names. This table is included because clients often need to map our position onto their own documentation.

|Concept|Singapore|Malaysia|Thailand|Indonesia
|--|--|--|--|--|
|The party that decides why and how data is used|Organisation|Data Controller|Data Controller|Data Controller
|The party that processes data on another's instructions|Data Intermediary|Data Processor|Data Processor|Data Processor
|The individual the data is about|Individual|Data Subject|Data Subject|Data Subject

Throughout this statement we use controller and processor, which correspond to these terms in each market.

  

## 4. Our Two Roles

**We are a controller** when we decide why and how personal data is used — our own client and prospect contacts, supplier records, job applicants, employees and website visitors.

**We are a processor** when we handle personal data on a client's instructions — the customer, loyalty, transaction, workforce or analytics data held in a system we implement, host or support.

Where we act as processor, the client is the controller. The client determines the purpose, establishes the lawful basis, issues notices to individuals, and is the first point of contact for requests from individuals. We support the client in meeting those obligations but do not assume them.

This split is set out in more detail in our Privacy Policy.

  

## 5. How We Meet the Core Obligations

### 5.1 Notification and consent

We are transparent about what we collect and why. Our Privacy Policy sets this out for data we hold as controller. Where we act as processor, the obligation to notify individuals and obtain any required consent sits with our client, and we provide the technical detail they need to describe a solution accurately in their own notices.

### 5.2 Purpose limitation

We use client data only to deliver, support, secure and improve the contracted service. We do not use it for our own commercial purposes, do not sell it, and do not share one client's data with another client.

### 5.3 Accuracy

We provide the tools for clients to correct and update records in their systems, and we correct data we hold as controller when told it is wrong.

### 5.4 Protection

We maintain organisational, technical and physical safeguards proportionate to the sensitivity of the data — role-based access control, hashed passwords, encryption in transit and at rest where supported, logical separation of client environments, access and activity logging, authenticated remote support, staff training and confidentiality obligations, and vendor due diligence. Our Privacy Policy describes these in full.

We also maintain a documented **Disaster Recovery Plan** covering encrypted daily backups, off-site and immutable copies, tiered recovery objectives and periodic restoration testing.

### 5.5 Retention limitation

We keep personal data only as long as it is needed for the purpose it was collected, or as long as the law requires. Retention periods for client data are set in the applicable service agreement or as instructed by the client, and we help clients configure retention settings where the platform supports it. At the end of a contract we delete or return client data in line with the agreement; residual copies in backup media are removed on the normal backup expiry cycle rather than immediately, and remain protected by the same controls until they are.

### 5.6 Transfer limitation

See section 8.

### 5.7 Access and correction

See section 7.

### 5.8 Accountability

We maintain records of the processing we carry out for clients, keep vendor and subprocessor documentation current, review our policies periodically, and make relevant documentation available to clients on request.

  

## 6. Data Protection Officer

We have appointed a Data Protection Officer responsible for our compliance across all four markets, for handling enquiries and complaints from individuals, and for coordinating our response to any incident involving personal data. Our DPO's contact details are published in our Privacy Policy and registered with the relevant regulator where a market requires registration.

**Contact**: connect@integratedretail.com

  

## 7. Rights of Individuals

All four laws give individuals rights over their personal data. The common core is the right to **access** and the right to **correct**. Malaysia, Thailand and Indonesia additionally provide, to varying degrees, rights to withdraw consent, object to certain processing, request erasure, and request data portability.

Our practice is to support the fullest set of rights across all markets rather than applying a different standard in each.

-   **Where we are the controller**, individuals may contact us directly. We verify identity before responding, and respond within the period set by the applicable law. Where a request is unclear, we may ask for clarification before the response period begins.
    
-   **Where we are the processor**, requests should go to the client who controls the data. If an individual approaches us, we refer them to the client and do not respond substantively without the client's instruction. We provide reasonable assistance — including the technical means to locate, export, correct or delete records — so the client can meet its own deadline.
    

  

## 8. Cross-Border Transfers

Delivering services across Southeast Asia means personal data may be transferred to, stored in, or accessed from a country other than the one where it was collected — including Singapore, Malaysia, Thailand, Indonesia, and the locations of our cloud providers and technology vendors.

All four laws restrict cross-border transfers in broadly the same way: the receiving jurisdiction must offer a comparable standard of protection, or the transfer must be covered by appropriate contractual safeguards or another recognised basis.

Our approach is to:

-   keep client data within the region wherever the solution architecture allows;
    
-   confirm, before a transfer, where the receiving party stores and accesses data;
    
-   put contractual data protection commitments in place with vendors and subprocessors;
    
-   disclose data locations and subprocessors to clients on request, so they can complete their own transfer assessments.
    

  

## 9. Personal Data Breaches

We maintain an incident response process covering detection, containment, assessment, notification, remediation and post-incident review. It forms part of our Disaster Recovery Plan and is tested periodically.

Notification deadlines differ across our markets:
|Market|Notify the regulator|Notify affected individuals|
|--|--|--|
|Singapore|As soon as practicable, and no later than 3 calendar days after assessing the breach as notifiable. The assessment itself must be carried out expeditiously — generally within 30 days of discovery.|As soon as practicable, where significant harm is likely|
|Malaysia|As soon as practicable, and in any event within 72 hours|Without unnecessary delay, and within 7 days of notifying the Commissioner, where significant harm is likely|
|Thailand|Without undue delay and, where feasible, within 72 hours of becoming aware|Without delay, where the breach is likely to result in high risk to rights and freedoms|
|Indonesia|Written notice within 3 × 24 hours of becoming aware|Within the same 3 × 24 hours|

Because the tightest of these clocks starts running quickly, our practice is to treat **72 hours from becoming aware** as the internal working deadline for assessing any incident involving personal data, regardless of which market it affects.

**Where we act as processor**, we notify the affected client without undue delay after becoming aware of a breach, with the information they need to assess the incident and meet their own notification obligations. **Where we act as controller**, we notify the relevant regulator and affected individuals as required in each market.

Deadlines and thresholds in this section are current as at the date of this statement and are reviewed at each update.

  

## 10. What We Ask of Our Clients

Compliance for a deployed solution is a shared responsibility. As controller, our clients are responsible for:

-   establishing the lawful basis for the processing carried out in their systems, and obtaining consent where required;
    
-   providing notices to their customers and employees, including in-store signage where sensors or cameras are in use;
    
-   configuring retention settings and user access rights appropriately;
    
-   carrying out access reviews — we recommend at least annually — and promptly removing accounts that are no longer needed;
    
-   responding to requests from individuals relating to their data, with our support;
    
-   notifying regulators and individuals of breaches affecting their data, with our support;
    
-   instructing us in writing where processing beyond the agreed scope is required.
    

We do not create, modify or delete client data without the client's instruction.

  

## 11. Governance and Review

This statement is owned by our Data Protection Officer, who is responsible for its accuracy and for reviewing it at least annually, and whenever there is a material change to our services, to the markets we operate in, or to applicable law. The current version is always published on our website.

**Integrated Retail Pte Ltd** Data Protection Officer Email: connect@integratedretail.com

If you are not satisfied with our response to an enquiry or complaint, you may contact the regulator in your market, listed in section 2.