Skip to content

Privacy

Data Protection &
Privacy Policy.

We respect the trust placed in us and handle personal data with care.

Last updated 13 September 2026

One Legal LLC (“One Legal”, “we”, “us” or “our”) is committed to respecting and protecting your personal data. We collect, use, disclose, store and otherwise process personal data in accordance with the Personal Data Protection Act 2012 (“PDPA”), other applicable laws and the professional duties that apply to us as a Singapore law practice.

This policy explains how we handle personal data in connection with our legal services, our business operations and this website. It should be read together with any more specific notice, engagement terms or consent that we give or agree with you.

Questions, requests, withdrawals of consent and complaints may be sent to our Data Protection Officer using the contact details on this page. You can learn more about the PDPA from the Personal Data Protection Commission.

01

How we collect personal data

In this policy, “personal data” means data, whether true or not, about an individual who can be identified from that data or from that data together with other information to which we have or are likely to have access. Whether information is personal data is determined in accordance with the PDPA and applicable guidance issued by the Personal Data Protection Commission (“PDPC”).

We may collect personal data directly from you, from your organisation, from other persons involved in a matter, from public or commercial sources, or automatically when you use our website. This may happen when:

  • you or your organisation asks us to provide legal or related services;
  • information about you is given to us for a client matter or prospective matter;
  • you contact us, submit a website enquiry or correspond with us;
  • you attend a meeting, seminar or other event involving us;
  • you apply for a position, training contract or internship; or
  • collection is otherwise permitted by law or notified to you.

Depending on the circumstances, the data may include your name, contact and employment details, identification information, financial or transaction information, information relevant to a legal matter, recruitment information, correspondence, images or recordings, and technical information such as an IP address and website usage data.

Please provide personal data about another person only if you are authorised to do so and, where required, have told that person how we will use it.

02

Why we use personal data

We may collect, use and disclose personal data for purposes that include:

  • considering whether we can act, including conflict and client due-diligence checks;
  • providing legal and related services and managing our relationship with clients;
  • communicating with you, responding to enquiries and administering payments;
  • meeting legal, regulatory, insurance, professional and risk-management obligations;
  • organising events and, where permitted, sending legal updates or other communications;
  • assessing applications for employment, training or internships;
  • operating, securing, analysing and improving our website and services;
  • establishing, exercising or defending legal claims; and
  • any other purpose notified to you, reasonably connected with the above, or permitted or required by law.

We rely on consent or deemed consent where the PDPA requires it. We may also process personal data without consent where the PDPA or another law permits or requires this, including for legitimate interests, business improvement, investigations, emergencies, the public interest or matters affecting the public, business asset transactions, and compliance with court orders.

03

Who we may disclose data to

Where reasonably necessary for the purposes above, we may disclose personal data to our members and employees; clients and persons connected with a matter; opposing parties and their advisers; counsel, experts, consultants and other professional advisers; courts, tribunals, regulators and public authorities; insurers, auditors and banks; and service providers that support our technology, communications, records, events or business operations.

Our website and enquiry form use Wix services. A relevant provider may process information for us under its own security and data-processing arrangements. We require recipients acting for us to handle personal data appropriately and only for authorised purposes.

Nothing in this policy changes our duties concerning legal professional privilege or confidentiality. We disclose privileged or confidential material only where authorised or permitted by law and our professional duties.

04

Consent and withdrawal

By providing personal data to us, directly or through an authorised person, you consent to our handling it for the purposes notified to you or described in this policy, unless another legal basis applies.

You may withdraw consent by writing to our Data Protection Officer and stating your name, contact details, the personal data concerned and the processing you wish to stop. We will explain any likely consequences and give effect to a valid withdrawal within a reasonable time, subject to legal and contractual restrictions. Withdrawal does not affect processing already carried out, any liability, debt or obligation accrued before the withdrawal takes effect, or processing that the law permits or requires us to continue. A withdrawal may prevent us from providing some services.

05

Access and correction

You may ask for access to personal data in our possession or control, information about how it was used or disclosed during the period prescribed by law, or correction of an error or omission. Please write to our Data Protection Officer with enough information for us to identify you, understand your request and locate the relevant records.

Access and correction rights are subject to the PDPA’s exceptions. We may verify your identity, ask for further details and charge a reasonable fee for an access request after first giving you a written estimate. We will respond as soon as reasonably possible and, if we cannot respond within the period required by law, tell you when we expect to do so.

06

Accuracy, protection and data breaches

We take reasonable steps to keep personal data accurate and complete where it is likely to be used to make a decision affecting you or disclosed to another organisation. Please tell us if your details change.

Where you provide personal data directly to us, we may assume it is accurate and complete.

We maintain reasonable administrative, physical and technical safeguards against unauthorised access, collection, use, disclosure, copying, modification, loss, disposal and similar risks. No system is completely secure, but we review our safeguards and the way our service providers handle data.

If a data breach occurs, we will assess it and notify the Personal Data Protection Commission and affected individuals where the PDPA requires us to do so.

07

Retention and overseas transfers

We retain personal data for as long as it is reasonably needed for the purpose for which it was collected and for legal, regulatory, professional, insurance and legitimate business purposes. When retention is no longer necessary, we will cease retaining it or remove the means by which it can be associated with an individual, where practicable and required by law.

If personal data is transferred outside Singapore, we will take steps required by the PDPA to ensure that it receives a standard of protection comparable to that provided under the PDPA.

08

Our website

Our website and its service providers may use cookies and similar technologies that are necessary for the site to operate, remember preferences, protect the site and understand its use. These technologies may process device information, browser information, IP addresses and activity data. You can control cookies through your browser settings, although parts of the site may then work differently.

Our servers and service providers may record information about visits, including IP address, date and time, pages viewed, referring page and browser or device type. We use this information to operate, secure, evaluate and improve the website.

Links from our website may lead to sites operated by other organisations. Their privacy practices apply when you use those sites, and we are not responsible for them.

09

Other information and updates

If we receive personal data that we did not request, we may use or dispose of it as reasonably appropriate after considering why it was provided and our legal and professional duties. We may also create aggregated or anonymised information. Once information can no longer identify an individual, we may use it for analysis, administration and service improvement.

We may revise this policy when our practices or legal obligations change. The current version will be posted on this page with its effective date.

10

Enforceability

Without prejudice to an individual’s rights under the PDPA, nothing in this Privacy Policy shall create or confer any legally enforceable right whether by way of contract, tort, equity or otherwise under the law.