- Home
- Privacy Policy
Privacy Policy
Last updated: September 2026
1. About this Privacy Policy
This Privacy Policy explains how Tanglin Law LLC (“Tanglin Law”, “we”, “us” or “our”) collects, uses, discloses and protects personal data in connection with your use of our website at www.tanglinlawllc.com and any of its subdomains (the “Website”).
This Privacy Policy applies to personal data collected through the Website and through the enquiry form, email, WhatsApp and other contact channels identified on it. It does not govern the personal data that we collect, use and disclose in the course of acting for a client on a matter. That is dealt with in our terms of engagement and in the separate data protection notice provided to clients.
This Privacy Policy forms part of, and should be read together with, our Terms of Use. Capitalised terms used but not defined in this Privacy Policy have the meanings given to them in the Terms of Use.
We handle personal data in accordance with the Personal Data Protection Act 2012 (the “PDPA”) and, where applicable, our professional obligations of confidentiality and legal professional privilege.
This Privacy Policy describes our practices. Save for the rights conferred by the PDPA, it is not intended to create, and does not create, any contractual or other legally enforceable right in favour of any person.
2. Who we are and how to contact us
Tanglin Law LLC (UEN 202005496H) is a Singapore law practice regulated by the Legal Services Regulatory Authority and by the Law Society of Singapore, with its registered office at City House, 36 Robinson Road #12-01, Singapore 068877.
We have designated a Data Protection Officer. You may contact our Data Protection Officer on any question relating to this Privacy Policy or to your personal data:
Data Protection Officer
Tanglin Law LLC
City House, 36 Robinson Road #12-01, Singapore 068877
Email: dpo@tanglinlawllc.com
Tel: +65 6994 4528
3. Personal data we collect
3.1 Personal data you provide to us. When you contact us through the Website, by email or by WhatsApp, subscribe to our Insights updates, or otherwise correspond with us, we may collect:
- your name, and the name of any organisation you represent;
- your email address, telephone number and other contact details;
- the content of your enquiry or message, including any information about your matter, the parties involved and any documents you choose to send us; and
- any other personal data you choose to provide.
3.2 Personal data collected automatically. When you visit the Website, our hosting provider and any analytics tools we use may automatically collect:
- your IP address and the approximate location derived from it;
- your browser type, operating system, device type and display settings;
- the pages you view, the time and duration of your visit, and the page from which you arrived or to which you navigate; and
- information collected through cookies and similar technologies (see clause 9).
3.3 Personal data from other sources. We may receive your personal data from third-party platforms on which you engage with our content, such as LinkedIn, in accordance with the terms and privacy settings of that platform. We may also collect personal data from publicly available sources, including for the purposes of conflict checks and client due diligence.
4. A note on confidential and sensitive information
Please do not send us confidential, privileged or highly sensitive information through the Website, by email or by WhatsApp unless and until we have confirmed in writing that we are able to act for you and an engagement has been established.
As explained in clause 4 of our Terms of Use, information sent to us before an engagement has been accepted is not treated as confidential or privileged, and our receipt of it does not prevent us from acting, or continuing to act, for another person in the same or a related matter.
Where we receive personal data that we did not request, including personal data about other individuals contained in material you send to us, we reserve the right to process that personal data in such manner and for such purposes as we consider appropriate. This includes retaining it so that we can carry out conflict checks in future.
Email and messaging services are not fully secure. We cannot guarantee the security of any information transmitted to us over the internet, and any information you send to us before an engagement is sent at your own risk.
5. How we use personal data
We use personal data collected through the Website for the following purposes:
- to respond to your enquiry and to communicate with you about it;
- to carry out conflict checks and the client due diligence required under the Legal Profession (Prevention of Money Laundering and Financing of Terrorism) Rules 2015, and to decide whether we are able to act;
- to establish and administer an engagement, if one is accepted, after which our terms of engagement and our client data protection notice will apply;
- to operate, maintain, secure and improve the Website, including to diagnose faults, prevent misuse and protect against security incidents;
- to understand how visitors use the Website and to improve its content and performance;
- to send you Insights updates and similar communications that you have asked to receive, and to manage your preferences;
- to consider any application or expression of interest in a position at the firm;
- to comply with our legal, regulatory and professional obligations, including under the Legal Profession Act 1966 and the rules made under it, and to respond to requests from regulators, courts and other authorities; and
- to establish, exercise or defend legal claims and to protect our rights and interests.
Where you subscribe to any of our updates, every message we send will contain an unsubscribe facility, and you may also unsubscribe at any time by emailing dpo@tanglinlawllc.com. Where we send marketing messages to Singapore telephone numbers, we will comply with the Do Not Call provisions in Part 9 of the PDPA.
6. Consent and the basis on which we handle personal data
Where the PDPA requires your consent, we will collect, use or disclose your personal data only with your consent, or where consent is deemed under the PDPA. Consent is deemed, among other cases, where you voluntarily provide personal data to us for a purpose that is reasonably apparent — for example, where you submit an enquiry so that we may respond to it.
We may also collect, use or disclose personal data without consent where the PDPA permits or requires, including for the purposes of legitimate interests and business improvement, and where the collection, use or disclosure is required or authorised by law or by an order of court.
You may withdraw your consent at any time in the manner set out in clause 12. Withdrawing consent may mean that we are unable to respond to your enquiry, continue a communication or provide a service to you. We will tell you the likely consequences before giving effect to a withdrawal.
7. Disclosure of personal data
We do not sell personal data. We may disclose personal data to:
- our partners, lawyers and staff, on a need-to-know basis;
- our IT, hosting, email, document management, cybersecurity, website and communications service providers, who process personal data on our behalf under contractual obligations of confidentiality and security;
- providers of artificial intelligence tools that we use in the course of our practice, under contractual restrictions on the use and retention of the data they process for us;
- our professional advisers, auditors and insurers;
- counsel, experts, agents, process servers and other third parties engaged in connection with a matter, where you become a client;
- courts, tribunals, regulators and law enforcement agencies, including the Legal Services Regulatory Authority, the Law Society of Singapore and the Personal Data Protection Commission, where required or authorised; and
- any other person to whom we are required or permitted by law to make the disclosure.
All disclosure remains subject to our duties of confidentiality and to legal professional privilege.
8. Transfer of personal data outside Singapore
Some of our service providers, including email, document management, hosting and analytics providers, may store or process personal data on servers located outside Singapore.
Where we transfer personal data outside Singapore, we will comply with the Transfer Limitation Obligation under the PDPA. We will take appropriate steps to ensure that the recipient is bound by legally enforceable obligations to provide a standard of protection for the personal data that is comparable to the protection under the PDPA.
9. Cookies and analytics
A cookie is a small text file placed on your device when you visit a website.
We use a small number of cookies that are strictly necessary for the Website to function, including to maintain security and to record your cookie preferences. These do not require your consent.
We may use Google Analytics to understand how visitors find and use the Website, so that we can improve it. Google Analytics sets cookies that collect information about your visit, including the pages you view and the approximate location derived from your IP address. We have configured Google Analytics so that IP addresses are truncated before storage, and we do not use it for advertising or remarketing. Information collected through Google Analytics is processed by Google in accordance with its privacy policy at policies.google.com/privacy. You may opt out of Google Analytics on all websites by installing the browser add-on available at tools.google.com/dlpage/gaoptout.
Where a cookie collects data that identifies you, or that can be combined with other data in our possession to identify you, that data is personal data and is handled in accordance with this Privacy Policy.
10. Protection of personal data
We make reasonable security arrangements to protect personal data in our possession or under our control against unauthorised access, collection, use, disclosure, copying, modification, disposal and similar risks. These include access controls, encryption of data in transit, secure document management, confidentiality obligations on our personnel and periodic training.
No method of transmission over the internet or of electronic storage is completely secure, and we cannot guarantee absolute security.
To the maximum extent permitted by law, and subject to our compliance with the PDPA, we accept no responsibility for the unauthorised use of your personal data by any third party.
Where a data breach occurs that results in or is likely to result in significant harm to affected individuals, or is of a significant scale, we will notify the Personal Data Protection Commission and the affected individuals as required under Part 6A of the PDPA.
11. Retention of personal data
We retain personal data for as long as it is necessary for the purposes for which it was collected, or as required for our legal, regulatory, professional or business purposes.
Where an enquiry does not result in an engagement, we will generally retain the enquiry and the record of our response. We do so in order to carry out future conflict checks and to evidence that no engagement was accepted. We may retain it for longer where a limitation period, a regulatory requirement or a potential claim makes that necessary.
When personal data is no longer needed for any legal or business purpose, we will cease to retain it, or will remove the means by which it can be associated with an individual.
Our retention periods are set out in our internal retention schedule. Specific retention periods are available on request from our Data Protection Officer.
12. Your rights
Access. You may request information about the personal data about you that is in our possession or under our control, and about the ways in which it has been used or disclosed in the 12 months before the request. A reasonable fee may apply for an access request, and we will inform you of the fee before proceeding.
Correction. You may ask us to correct personal data about you that is inaccurate or incomplete. Where we make a correction, we will send the corrected data to every other organisation to which the data was disclosed in the 12 months before the correction, unless that organisation does not need it for any legal or business purpose.
Withdrawal of consent. You may withdraw your consent to our collection, use or disclosure of your personal data at any time, on reasonable notice. We will seek to process a withdrawal request within 10 business days of receiving it.
Accuracy. You are responsible for ensuring that the personal data you provide to us is accurate and complete, and for informing us of any change to it. We will not be liable for relying on incomplete or inaccurate personal data that you have provided.
How to make a request. Please send your request to our Data Protection Officer at dpo@tanglinlawllc.com. We may need to verify your identity before responding. We will respond as soon as reasonably possible and in any event within 30 days. Where we are unable to respond within 30 days, we will tell you within that period when we will respond.
Limits on access and correction. Certain personal data is exempt from access and correction under the PDPA. This includes data subject to legal professional privilege, data that would reveal confidential information about another individual, and opinion data kept solely for an evaluative purpose. Where an exception applies, we will tell you.
13. Minors
The Website is not directed at individuals under 18 years of age, and we do not knowingly collect their personal data through it. If you believe that a minor has provided personal data to us through the Website, please contact our Data Protection Officer and we will take appropriate steps to delete it.
14. Third-party websites and platforms
The Website contains links to third-party websites and platforms, including LinkedIn. This Privacy Policy does not apply to those websites and platforms, and we are not responsible for their content or privacy practices. You should review the privacy policy of any third-party website or platform before providing personal data to it.
15. Complaints
If you have a concern about the way in which we have handled your personal data, please contact our Data Protection Officer at dpo@tanglinlawllc.com in the first instance. We will investigate your concern and respond to you.
If you remain dissatisfied, you may lodge a complaint with the Personal Data Protection Commission of Singapore.
16. Changes to this Privacy Policy
We may amend this Privacy Policy from time to time. The date at the top of this page shows when it was last updated.
Any amendment takes effect when the updated Privacy Policy is published on the Website. Your continued use of the Website following publication constitutes your acceptance of the updated Privacy Policy. You should review this Privacy Policy each time you access the Website.
17. Contact us
If you have any questions about this Privacy Policy or about how we handle personal data, please contact:
Data Protection Officer
Tanglin Law LLC
City House, 36 Robinson Road #12-01, Singapore 068877
Email: dpo@tanglinlawllc.com
Tel: +65 6994 4528