Ask most executives what's publicly findable about them and the answer undersells it significantly. Between data brokers, public registries and years of digital footprint, the actual exposure is usually broader than expected — and only part of it is addressable.
What's actually out there
- Data broker and aggregator sites. Services that scrape and compile personal information — address history, phone numbers, relatives, sometimes estimated income — into a searchable profile, often monetised through a "pay to see more" model.
- Property records. Singapore property transactions are part of the public record, and ownership details are legitimately searchable through official channels.
- Company filings. ACRA records tie directors and substantial shareholders to residential addresses in certain filing categories, and this data frequently propagates to third-party aggregator sites.
- Social media metadata. Tagged locations, visible connections, and photo metadata can reveal more than the visible content itself.
- Historical data breaches. Credentials and personal details from past breaches, unrelated to the executive's own security practices, circulating on data-breach aggregation sites.
What can genuinely be removed
Data aggregator and broker sites are the most addressable category — many operate opt-out processes, and Singapore's Personal Data Protection Act provides grounds to request removal where there's no legitimate basis for processing. This is meaningfully different from removing official public records, which generally isn't possible or appropriate — property and company registries exist by statutory design and operate under separate legal frameworks from commercial data brokers.
The goal isn't erasing a public footprint entirely — parts of it are supposed to be public. It's removing what's being commercially aggregated without basis, and managing exposure on what can't be removed.
Why removal alone doesn't hold
Data broker sites re-scrape source data on their own schedules, meaning a successful removal request can be undone months later when the same site re-indexes the same public source. This is why ongoing monitoring, not a single removal pass, is what actually keeps exposure down over time.
What to prioritise
Data broker removal first. Highest volume of genuinely addressable exposure, and the category with the clearest opt-out and PDPA-based removal path.
Review what's tied to your address specifically. Residential address exposure carries genuine personal safety implications beyond reputation, and is worth prioritising over less sensitive categories.
Accept and manage what can't be removed. For public registry data, the realistic goal is knowing what's there and being prepared to explain it, not pursuing removal that won't succeed.
This work connects directly to brand and executive monitoring — privacy exposure is one of the categories a proper monitoring programme should be tracking on an ongoing basis, not addressing once and assuming it stays resolved.