top of page

Privacy Is the Sale, Not the Chore

Aug 29
4 min read
Joshua Woo speaking at Co-work Friday

Joshua Woo did not come to Friday to talk like the lawyer in the room. "I am not here to do that today," he said. "I wanted a conversation with you." He runs Perfraction, a fractional general counsel practice for companies that cannot yet justify a full-time in-house lawyer. He has sat both sides of the deal: as the vendor's counsel, and as the legal gate at Goldman Sachs asking the questions that stall a sale.


The hard part, he argued, is not convincing a buyer you have a good product. The hard part starts when that buyer says, "Let me just loop in procurement." From that moment, the deal is no longer between you and the person who wants the product. It is a third-party risk review. And data protection is how that review finds you.


The Regulator You Actually Meet


Enterprise questionnaires can run forty or fifty pages. A big chunk is your security and data protection posture. Then comes the paper: "Are you willing to sign our DPA?" If you are a small startup, saying no often means the deal dies. Saying yes, unread, is the other trap.


Twenty, thirty, forty pages of someone else's template, agreed under deal pressure, sometimes unread.

You do not know the shape of the contract. You do not know the edges. "How do you comply with something that you don't know what you said yesterday?" You find out at the worst moment: an incident, a renewal, or an audit.


The line he wanted the room to keep was this. In-house counsel at a roundtable the day before had described themselves as minnows hoping not to get bitten by regulators. Joshua's view was the opposite of that fear.


In most of the cases, data protection won't bite you through the regulator. I find you through the sales, through the contract, through the obligation.

The person owed the obligation is your client. Sometimes that obligation shows up mid-relationship. Sometimes it is the bar that keeps you from walking in the door.


Singapore's PDPA is real. Protection, retention, transfer, and breach notification all matter, and "reasonable" security is doing a lot of work in the statute. What is reasonable for a bank is not reasonable for a two-person startup. Encryption at rest, role-level access, MFA, and not leaving a database open to the internet are the baseline, not a SOC. The statutory breach clock is three calendar days after you finish assessing a notifiable incident, with roughly thirty days to assess. Fines can reach 10 percent of turnover for large organisations, or a million dollars for the rest.


That is still not usually what kills a startup sale. The DPA is.


What You Can Push Back On


A DPA is often harder than the law. Clients ask for 24- or 48-hour breach notice when the statute gives three days. Data protection liability sits outside the general cap, sometimes uncapped, sometimes under a "super cap," sometimes as liquidated damages: if this happens, you pay X. Sub-processor clauses demand approval before you add a cloud vendor, an analytics tool, or an AI model provider. The biggest buyers ask for on-site audit rights.


Joshua's map for a small team was practical. Negotiate a super cap so privacy liability is not unlimited. Push audit rights from "we show up at your office" to an annual questionnaire. Tie notice windows back to the statute. Swap sub-processor "approval" for "notification." Accept the parts that will not move: baseline security annexes, a commitment to data protection law, and returning or deleting customer data on exit. "If you are selling to other businesses, the data is not yours."


The room felt that slide. One first-time Friday attendee wrote that the most useful thing in the session was exactly that split: what to push back on with an enterprise customer, and what you cannot.


Build the Pack Before the Questionnaire


The last twenty minutes were a starter kit, not a lecture. One spreadsheet that maps what personal data you hold, where it lives, why you have it, and who can touch it. A privacy notice written in honest language that matches what you actually do, not a template that still says "insert something here." Least-privilege access. A sub-processor register that follows the data journey. A one-page breach plan that lives on a phone or a printout, because the plan on the server is useless if the incident locks you out of the server.


You need a fire escape plan before there's a fire, not when the fire hits.

None of that is theatre for a regulator. It is how you stop losing days every time procurement lands.


The refrain I want to leave everyone with is that this is not compliance overhead. These are not hoops you have to jump through. These are sales essentials, right? And these help you cut sales time.

Next questionnaire, you copy and adjust. You do not start from scratch.


Enterprise buyers will put their paper on you through the contract whether you prepare or not. The choice is the one he closed on: do it early and cheaply, or do it late, under deal pressure.


SQ Collective hosts Coworking Fridays for founders, operators, and AI builders working through real product questions in Singapore.


Join an upcoming Coworking Friday: https://lu.ma/ai-labs

Explore SQ Collective: https://www.sq-collective.com

Michael

 
 
 

Recent Posts

See All
AGI, Experiments, Alignment

“We're going to go into the future today,” Jeremy said to a room of business folks and engineers after returning from San Francisco. He started not with a product pitch, but with a reference to a 2024

 
 
 

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page