Privacy & Data Protection Policy

Last updated: 28 July 2026

1. Introduction

CDT Assurance PAC and CDT Corporate Services Pte. Ltd. (collectively referred to as “CDT Professional Services”, “CDT”, “we”, “us” or “our”, as applicable) respect your privacy and are committed to protecting your personal data.

This Privacy & Data Protection Policy (“Policy”) explains how we collect, use, disclose, process, protect and retain personal data in connection with our professional services and business activities.

We comply with the Singapore Personal Data Protection Act 2012 (“PDPA”) and other applicable legal, regulatory and professional requirements.

Where a specific engagement letter, consent notice, statutory requirement or professional obligation applies, this Policy should be read together with such requirements.

2. Personal Data We May Collect

Depending on the nature of our relationship with you and the services provided, we may collect personal data including:

  • identification information, such as your name, NRIC, FIN, passport or other identification details where required or permitted by law;
  • contact information, including address, email address and telephone number;
  • employment, payroll and remuneration information;
  • financial, banking, accounting and tax information;
  • information relating to directors, shareholders, beneficial owners, officers, employees and authorised representatives;
  • information required for client acceptance, know-your-client (“KYC”), anti-money laundering and countering the financing of terrorism (“AML/CFT”), sanctions screening and other regulatory or professional compliance;
  • information contained in accounting records, audit documents, confirmations, contracts, invoices, correspondence and other engagement records;
  • recruitment information, including CVs, qualifications, employment history and references;
  • information submitted through our website or enquiry forms; and
  • website and technical information, including cookies, device and browser information and website usage information.

We seek to collect only personal data that is reasonably necessary for the relevant purpose.

3. How We Collect Personal Data

We may collect personal data directly from you or from other sources, including:

  • the organisation that you represent;
  • our clients and their directors, employees or representatives;
  • counterparties and professional advisers;
  • government agencies, regulators and publicly available sources;
  • banks and financial institutions;
  • professional and business service providers; and
  • other third parties where permitted or required by law.

Personal data may be collected through email, telephone calls, meetings, engagement documents, secure shared folders, professional software, our website, enquiry forms and other appropriate channels.

4. Purposes for Collection, Use and Disclosure

We may collect, use or disclose personal data for purposes including:

  • responding to enquiries and preparing proposals;
  • conducting conflict, independence, client acceptance and continuance procedures;
  • providing audit and assurance, accounting, tax, corporate secretarial, advisory and related professional services;
  • performing KYC, AML/CFT, sanctions and other regulatory or professional checks;
  • preparing, reviewing, filing or submitting information to relevant government agencies, regulators, financial institutions or other authorised recipients;
  • communicating with clients and relevant third parties in connection with our services;
  • billing, collection and financial administration;
  • quality management, internal review, risk management and record keeping;
  • managing staff, recruitment, vendors and other business administration;
  • maintaining the security and operation of our information systems;
  • investigating complaints, security incidents, suspected misconduct or legal claims;
  • complying with applicable laws, regulations, court orders, professional standards and lawful requests; and
  • any other purpose notified to you, reasonably related to the above purposes, or otherwise permitted or required by law.

5. Consent

Where consent is required under the PDPA, we will obtain or rely on consent in accordance with applicable requirements.

Consent may also be deemed in circumstances provided under the PDPA. In certain circumstances, the PDPA or other applicable laws may permit or require us to collect, use or disclose personal data without consent.

If you provide us with personal data relating to another individual, you should ensure that you are authorised to provide such information and, where required, that the individual has been appropriately notified or the necessary consent has been obtained.

6. Disclosure of Personal Data

Where appropriate and subject to applicable requirements, we may disclose personal data to:

  • government agencies, regulators, courts and law enforcement authorities;
  • banks and financial institutions;
  • legal advisers, tax advisers, auditors, experts and other professional advisers;
  • information technology, cloud, document management, accounting, audit, tax, communications and other service providers;
  • insurers, professional bodies and quality reviewers where relevant;
  • other parties involved in or necessary for the provision of our professional services;
  • and any other person authorised by you or permitted or required by law.

Where service providers process personal data on our behalf, we take reasonable steps to ensure that appropriate data protection arrangements are in place.

7. Protection of Personal Data

We take reasonable administrative, physical and technical measures to protect personal data in our possession or under our control against unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks.

These measures may include access controls, appropriate authentication measures, secure cloud storage, device protection, controlled document sharing, confidentiality requirements, backups and data breach procedures.

While we take reasonable steps to protect personal data, no method of electronic transmission or storage can be guaranteed to be completely secure. We review our safeguards periodically, taking into account the nature of the personal data and associated risks.

8. Accuracy of Personal Data

We take reasonable steps to ensure that personal data is accurate and complete where it is likely to be used by us to make a decision affecting an individual or disclosed to another organisation.

Please inform us if your personal data changes or if you believe that information held by us is inaccurate or incomplete.

9. Retention of Personal Data

We retain personal data only for as long as it is necessary for the purposes for which it was collected or for other legitimate business, legal, regulatory or professional purposes.

Our retention periods may take into account applicable statutory requirements, professional standards, contractual obligations, quality management requirements and potential legal claims.

When personal data is no longer required, we will cease to retain it or remove the means by which it can be associated with particular individuals, where appropriate.

10. Transfer of Personal Data Outside Singapore

Some of our service providers, technology platforms or professional arrangements may involve the storage, access or processing of personal data outside Singapore.

Where the PDPA’s Transfer Limitation Obligation applies, we will take appropriate steps to ensure that transferred personal data receives a standard of protection comparable to that provided under the PDPA, unless an applicable exception applies.

11. Access and Correction

Subject to the PDPA and applicable exceptions, you may request:

  • access to personal data about you that is in our possession or under our control and information about the ways in which such personal data has been used or disclosed within the preceding year; or
  • correction of an error or omission in your personal data.

We may require information to verify your identity and clarify the scope of your request.

Where permitted under the PDPA, we may charge a reasonable fee for an access request and will provide an estimate where applicable.

We will respond to requests as soon as reasonably possible. If we are unable to provide access or make the requested correction within 30 days after receiving the request, we will inform you in writing within that period of the time by which we expect to respond.

12. Withdrawal of Consent

Where our collection, use or disclosure of personal data is based on consent, you may withdraw your consent by giving us reasonable notice.

We will inform you of the likely consequences of withdrawing consent.

Subject to applicable legal, regulatory, professional or other permitted grounds for continued processing, we will cease the relevant collection, use or disclosure after receiving reasonable notice of withdrawal.

Withdrawal of consent may affect our ability to provide or continue providing certain services.

13. Cookies and Website Analytics

Our website uses cookies and similar technologies for website functionality and analytics.

We use Google Analytics 4 (GA4) to help us understand how visitors use our website and to improve the performance, content and effectiveness of our website.

Google Analytics may collect information such as pages visited, traffic sources, approximate location, device and browser information and interactions with our website.

You may manage or disable cookies through your browser settings. Disabling certain cookies may affect website functionality or the measurement of website usage.

14. Website Enquiries

When you submit an enquiry through our Contact Us form, we may collect information including your name, company, email address, telephone number, service required and the contents of your message.

We use this information primarily to respond to your enquiry, communicate with you and provide information concerning the professional services in which you have expressed an interest.

15. Personal Data Breaches

We maintain procedures to identify, assess and respond to suspected personal data breaches.

Where a personal data breach is notifiable under the PDPA, we will notify the Personal Data Protection Commission and/or affected individuals as required by applicable law.

16. Contacting Our Data Protection Officer

If you have any questions regarding this Policy or our handling of personal data, or wish to make an access, correction or withdrawal request, please contact:

Data Protection Officer
CDT Professional Services
7 Temasek Boulevard
#12-07, Suntec Tower One
Singapore 038987

Email: dpo@cdt.sg

17. Changes to this Policy

We may update this Policy from time to time to reflect changes in our business practices, technology, legal or regulatory requirements.

The latest version will be made available on our website.

Scroll to Top