Data & Reputation Risk

Quick Navigation

1) PDPA-lite checklist (for F&B)

Area Standard Done Notes
Consent Clear opt-in wording (no hidden consent)
Purpose Only collect what you need (e.g., birthday month, not NRIC)
Storage Access limited + password-protected
Retention Delete inactive data after defined period

2) Review escalation SOP (one page)

Review type Response rule Escalate to Time-to-respond
1–2★ with service issue Acknowledge + apologise + invite offline resolution Manager Same day
Food safety allegation Do not argue; request details; activate incident steps Owner immediately Within 2 hours
Viral/social media post Use holding statement; collect facts first Owner + comms lead Within 1 hour

3) Holding statements (premium)

Scenario Public holding statement (copy/edit)
Food safety concern We take food safety seriously and are looking into this immediately. Please DM us your contact details and order information so we can investigate and follow up directly.
Service issue Thank you for sharing this. We’re sorry your experience fell short. Please DM us your visit details so we can make it right and prevent it from happening again.