Loading…
Singapore's framework combines the PDPA with rules on telemarketing and electronic messages, cybersecurity legislation for critical systems, and sector-specific requirements. Depending on its activities, an organisation may need to consider several of these alongside one another.
The requirements applicable to an organisation depend on its activities, sector, processing operations, and regulatory status.
The PDPA governs the collection, use, and disclosure of personal data by organisations in Singapore. It sets out a series of data protection obligations and is administered by the Personal Data Protection Commission (PDPC).
Depending on applicability, organisations may need to address:
Organisations should assess the PDPA's scope and exceptions, including its treatment of business contact information and public agencies, before determining which obligations apply.
The 2020 amendments introduced mandatory data breach notification, expanded deemed consent, a legitimate interests exception, and stronger enforcement powers, with provisions taking effect in phases from February 2021.
Higher maximum financial penalties took effect in October 2022. A data portability obligation was also introduced but will apply only once it is brought into force.
Organisations should confirm which amended provisions are in force before relying on them.
The PDPA's Do Not Call provisions restrict telemarketing calls, text messages, and faxes to Singapore telephone numbers listed on the Do Not Call Registry, unless clear and unambiguous consent has been obtained.
Organisations that market by phone or message should check numbers against the Registry and keep records of consent.
The Spam Control Act regulates unsolicited commercial electronic messages sent in bulk, including email and certain messaging services.
It requires an unsubscribe facility and accurate labelling of messages, and applies alongside the PDPA for marketing communications.
The Cybersecurity Act establishes a framework for protecting critical information infrastructure and gives the Cyber Security Agency of Singapore powers to prevent and respond to cybersecurity incidents.
Organisations within scope should coordinate cybersecurity incident reporting with personal data breach assessment where an incident may involve personal data.
Businesses operating in regulated industries may face additional obligations beyond general data protection law.
Sector considerations:
The PDPA and related requirements may apply to:
Private-sector organisations that collect, use, or disclose personal data in Singapore.
Businesses based elsewhere that collect, use, or disclose personal data in Singapore, whether or not they have a presence there.
Data intermediaries processing personal data for other organisations, which have their own protection, retention, and breach-reporting duties.
Businesses that market by phone, message, or email, which should consider the Do Not Call provisions and the Spam Control Act.
Organisations handling employee records, recruitment data, and other employment-related personal data.
Regulated institutions, which should also consider Monetary Authority of Singapore requirements.
The precise obligations depend on the organisation's role, processing activities, size, risk profile, and territorial scope.
Every organisation must designate at least one individual as its Data Protection Officer, make that person's business contact information publicly available, and develop and implement data protection policies and practices.
The requirement to designate a Data Protection Officer applies to organisations of all sizes.
Organisations should collect, use, or disclose personal data only with the individual's consent or where an exception applies, only for purposes a reasonable person would consider appropriate, and after notifying the individual of those purposes.
On request, organisations must provide individuals with their personal data and information about how it has been used or disclosed in the past year, and correct errors or omissions, subject to the exceptions in the Act.
Organisations must assess suspected data breaches promptly. A breach that results in, or is likely to result in, significant harm to individuals, or that affects 500 or more individuals, must be notified to the PDPC within three calendar days of that assessment, and to affected individuals where required.
Organisations must protect personal data with reasonable security arrangements and stop retaining it once the purpose for collection is no longer served and retention is not needed for legal or business purposes.
Personal data may be transferred outside Singapore only if the recipient is bound by legally enforceable obligations that provide a comparable standard of protection. These can arise from contracts, binding corporate rules, the recipient's local law, or recognised certifications.
The PDPA gives individuals a number of rights and protections. Depending on the circumstances, these may include:
Individuals may request their personal data and information about how it has been used or disclosed in the past year.
Individuals may ask for errors or omissions in their personal data to be corrected.
Individuals may withdraw consent on reasonable notice, and should be told the likely consequences of doing so.
Individuals should be told the purposes for which their personal data is collected, used, or disclosed.
Individuals should be notified of a data breach that is likely to result in significant harm to them, subject to exceptions.
A right to have data transmitted to another organisation was introduced in 2020 but is not yet in force.
Organisations should assess the exceptions in the PDPA, and any applicable fees and response times, when handling requests.
The PDPA has been implemented and strengthened in stages.
Singapore's Parliament passed the Personal Data Protection Act, creating a general data protection framework for the private sector.
The PDPA's main data protection obligations took effect, following the earlier launch of the Do Not Call Registry.
The first phase of the 2020 amendments came into force, including mandatory data breach notification and expanded deemed consent.
Increased maximum financial penalties took effect, linked to an organisation's annual turnover in Singapore.
Important: not every provision of the 2020 amendments is in force. Confirm the status of each provision using official sources before changing your compliance programme.
The Personal Data Protection Commission (PDPC) administers and enforces the PDPA. It issues advisory guidelines, investigates complaints and data breaches, and can give directions or accept voluntary undertakings from organisations.
Other authorities may be relevant depending on the activity, including the Cyber Security Agency of Singapore under the Cybersecurity Act and the Monetary Authority of Singapore for financial institutions.
Organisations should identify which authorities are relevant to their activities rather than assuming that the PDPC is the only one.
For breaches of the data protection obligations, the PDPC can impose a financial penalty of up to S$1 million or, where an organisation's annual turnover in Singapore exceeds S$10 million, up to 10% of that turnover, whichever is higher.
The PDPC can also direct an organisation to stop collecting or using personal data, or to destroy data collected in breach of the Act. Separate penalties apply to breaches of the Do Not Call provisions, certain egregious mishandling of personal data by individuals is a criminal offence, and affected individuals may bring civil claims.
RegulatoryBridge helps organisations assess Singapore's regulatory requirements and coordinate their compliance activities with wider international programmes.
Review your data handling activities, notices, consent practices, policies, governance arrangements, and operational controls to identify potential gaps.
Review how your Data Protection Officer function is set up, including responsibilities, public contact details, and supporting policies and practices.
Review consent workflows, notifications, request-handling processes, and related documentation against the requirements applicable to you.
Evaluate breach assessment procedures, escalation responsibilities, PDPC notification readiness, and coordination between privacy, security, and legal teams.
Assess data flows out of Singapore, transfer mechanisms, vendor relationships, and contractual controls against the PDPA's transfer requirements.
Help organise requirements across privacy, cybersecurity, financial services, and other regulatory frameworks relevant to your business.
Monitor relevant developments and review compliance plans when legislation, PDPC guidelines, or enforcement decisions change.
The scope of support is tailored to the organisation's activities, risk profile, and applicable legal requirements.
Assess your organisation's activities, role in processing personal data, industry, and connections to Singapore.
Identify applicable provisions, relevant authorities, effective dates, and sector-specific requirements.
Review existing policies, notices, consent mechanisms, contracts, security controls, and operational processes.
Prioritise remediation activities and establish owners, milestones, documentation requirements, and implementation plans.
Review regulatory developments, reassess relevant obligations, and update compliance processes when required.
We support your Data Protection Officer function, PDPC interactions, and breach response - so your global product team doesn't have to.