Legal
How Ng & Partners collects, uses, discloses and protects your personal data.
Last modified: 2 September 2026
This Personal Data Protection Policy (the "Policy") sets out how Ng & Partners Pte Ltd ("Ng & Partners", "we", "us" or "our") collects, uses, discloses, retains and protects Personal Data, in accordance with the Personal Data Protection Act 2012 of Singapore ("PDPA") and, where applicable to individuals in the European Union, the General Data Protection Regulation ("GDPR").
It applies to our clients and prospective clients, the beneficiaries and family members whose details are provided to us in the course of our work, users of our website, attendees at our events, and the professional contacts with whom we deal. Please read it so that you understand the purposes for which we handle your Personal Data.
By engaging our services, submitting information to us, or using our website, you consent to the collection, use and disclosure of your Personal Data in the manner described in this Policy. Where we rely on your consent, you may withdraw it at any time in the manner set out in Section 8.
We may amend this Policy from time to time to reflect changes in our practice or in the law. The current version will always be available on our website, and all dealings with us are subject to the version in force at the time.
1.1 "Personal Data" means any data or information about an individual, whether true or not, from which that individual can be identified — either from that data alone or together with other information to which we have or are likely to have access.
1.2 The Personal Data we collect depends on the services you engage us for, and may include:
2.1 We collect Personal Data directly from you wherever possible. We may also receive it from:
2.2 Personal Data is collected when you:
3.1 Ng & Partners is a trust and estate consultancy. We use Personal Data to deliver the services you engage us for, which may include:
3.2 We also use Personal Data for purposes reasonably connected with the above:
3.3 Certain Personal Data, including your NRIC or passport number, is required by law or is necessary to accurately identify the parties to the legal instruments we facilitate. Where we ask for it, we will explain why. If you do not provide it, we may be unable to provide the relevant services.
4.1 We do not sell Personal Data. We disclose it only to the extent necessary for the purposes set out in Section 3, and only to the following classes of recipient:
4.2 Ng & Partners does not hold client assets. Where an engagement involves the administration of assets, that function is performed by an appropriately licensed trustee or financial institution, which will handle your Personal Data under its own data protection policy in addition to this one.
5.1 Some of the service providers and professional partners we work with operate, or store data on servers located, outside Singapore. This includes the cloud-based services we use for email, document storage and record-keeping, and the systems used to receive enquiries submitted through our website.
5.2 Where Personal Data is transferred outside Singapore, we take steps to ensure that it is protected to a standard comparable to that required under the PDPA, including through contractual obligations, the selection of providers with recognised security practices, and the professional and regulatory obligations to which our partners are subject.
6.1 We maintain administrative, physical and technical safeguards designed to prevent unauthorised access, collection, use, disclosure, copying, modification, disposal or loss of Personal Data.
6.2 Access to Personal Data is restricted to staff and partners who require it for the purposes described in this Policy, and who are bound by obligations of confidentiality.
6.3 We use encrypted connections for our website and, where available, for the transmission and storage of documents, and we review our practices periodically. No method of transmission or storage is entirely secure, and we cannot guarantee absolute security; we will, however, act promptly on any indication that Personal Data has been compromised.
7.1 We retain Personal Data for as long as is necessary to fulfil the purpose for which it was collected, and thereafter for as long as is required to satisfy legal, regulatory, accounting or professional obligations — which for most engagements is up to seven years after the relationship ends.
7.2 Owing to the nature of estate planning, certain Personal Data may be retained for substantially longer, and in some cases indefinitely. Instruments such as wills, trusts and Lasting Powers of Attorney may take effect, or be called into question, many years after they are prepared. Records relating to them are retained so that we can respond to future requests from executors, trustees, donees, beneficiaries or courts — for example, by providing evidence of instructions in the event of a dispute.
7.3 When retention is no longer necessary, Personal Data is securely deleted or destroyed.
8.1 Under the PDPA you have the right to:
8.2 If you are located in the European Union, you may have additional rights under the GDPR, including the right to erasure, the right to restrict processing, the right to data portability, and the right to object to processing. We extend these rights to all individuals to the extent that doing so does not prevent us from complying with our legal obligations or delivering the services you have requested.
8.3 To exercise any of these rights, contact our Data Protection Officer using the details in Section 11. We may need to verify your identity before acting on a request. We will respond within thirty days; if we require more time, we will tell you when to expect a response.
8.4 Please note that withdrawing consent, or requesting erasure, may mean we are unable to continue providing certain services, and that we may be required or entitled to retain certain Personal Data notwithstanding your request, as described in Section 7.
9.1 With your consent, we may send you information about our services, events and developments relevant to trust and estate matters, by email, post, telephone, SMS or other messaging services.
9.2 You may opt out at any time by using the unsubscribe mechanism in any message, or by contacting our Data Protection Officer. Opting out of marketing will not affect communications relating to an existing engagement.
9.3 Before sending marketing messages to a Singapore telephone number by voice call, SMS or fax, we check the Do Not Call Registry as required by the PDPA, unless you have given us clear and unambiguous consent to receive such messages.
10.1 Enquiry form. Information you submit through our website enquiry form is transmitted over an encrypted connection, delivered to us by email, and recorded in a secure cloud-based log so that we can respond to and track enquiries. The log records the date and time of your submission and your acceptance of this Policy.
10.2 Server data. Our website is served through a content delivery network which, in the ordinary course of operation, records technical information such as IP address, browser type, pages requested and time of access. This information is used for security, performance and diagnostic purposes.
10.3 Third-party resources. Our website loads typefaces from a third-party service. In doing so, your browser transmits your IP address to that service. We do not otherwise embed third-party tracking on our website.
10.4 Cookies and analytics. Our website does not currently set cookies for tracking or advertising purposes. Should we introduce analytics or similar tools in future, this Policy will be updated to describe them and, where required, your consent will be sought.
11.1 We have designated a Data Protection Officer responsible for ensuring our compliance with the PDPA. Requests, questions and complaints relating to Personal Data may be directed to:
Data Protection Officer
Ng & Partners Pte Ltd
10 Anson Road, #06-17, International Plaza
Singapore 079903
adminoffice@ngandpartners.org
11.2 If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commission of Singapore.
12.1 In the event of a data breach affecting your Personal Data, we will assess it in accordance with the PDPA and, where the breach is notifiable, notify the Personal Data Protection Commission and the affected individuals within the timeframes required by law.
13.1 This Policy is governed by the laws of Singapore.
Enquiries
Tell us what you intend to protect. We will come back with who needs to be in the room.