Skip to content

Singapore · Main data protection obligations since 2014; significant amendments took effect from 2021

Singapore — Personal Data Protection Act (PDPA)

Singapore's private-sector data protection law: a set of clearly enumerated obligations covering consent, purpose, notification, access, accuracy, protection, retention, transfer, accountability and breach notification, plus the Do Not Call registry.

Regulator: Personal Data Protection Commission (PDPC)Last reviewed August 2026

The PDPA governs the collection, use and disclosure of personal data by organisations in Singapore. It sits alongside sector rules and does not displace other legal obligations that require or permit particular handling of data.

Rather than broad principles, the Act sets out enumerated obligations that map cleanly onto operational controls: consent, purpose limitation, notification, access and correction, accuracy, protection, retention limitation, transfer limitation, accountability and data breach notification.

Amendments introduced mandatory data breach notification, an offence framework for egregious mishandling of personal data by individuals, and additional bases for using personal data such as legitimate interests and business improvement.

The Act also contains the Do Not Call provisions, which regulate telemarketing to Singapore telephone numbers and operate separately from the data protection obligations.

Who and what it applies to

Organisations
Applies to organisations collecting, using or disclosing personal data in Singapore, whether or not formed or resident there. Public agencies are covered by a separate government framework.
Data intermediaries
Organisations processing personal data on behalf of another are subject to the protection, retention and breach notification obligations.
Employees
Business contact information is treated differently from other personal data, and specific provisions cover employment-related collection and use.

Core principles

  • Consent — obtain consent, or rely on deemed consent or a specified exception, before collecting, using or disclosing personal data.
  • Purpose limitation — only for purposes a reasonable person would consider appropriate in the circumstances.
  • Notification — inform individuals of purposes at or before collection.
  • Access and correction — provide access to personal data and information on use and disclosure, and correct errors.
  • Accuracy — make reasonable effort to ensure accuracy and completeness where used for decisions or disclosed.
  • Protection — reasonable security arrangements to prevent unauthorised access, collection, use, disclosure or similar risks.
  • Retention limitation — cease retention when the purpose is no longer served and retention is not required legally or for business purposes.
  • Transfer limitation — transfer overseas only where the recipient is bound by comparable protection.
  • Accountability — appoint a Data Protection Officer, develop policies and make information about them available.
  • Data breach notification — assess and notify notifiable breaches.

Individual rights

Access

Request personal data in the organisation's possession or control and information about how it has been used or disclosed in the past year.

Correction

Request correction of an error or omission, with corrections sent to organisations the data was disclosed to.

Withdraw consent

Withdraw consent on reasonable notice, with the organisation obliged to explain likely consequences.

Data portability

A portability obligation has been provided for in the Act, to be operationalised through regulations.

Do Not Call

Register Singapore telephone numbers to opt out of specified marketing messages.

Organisational obligations

Appoint a DPO

Every organisation must designate at least one individual responsible for ensuring PDPA compliance and make their business contact information available.

Breach notification

Notify the PDPC as soon as practicable, and no later than 3 calendar days, where a breach is notifiable, and notify affected individuals where significant harm is likely.

Reasonable security

Implement security arrangements proportionate to the sensitivity and volume of personal data.

Retention limits

Cease retention or anonymise personal data once purposes are served and no legal or business need remains.

Transfer conditions

Ensure overseas recipients are bound to a comparable standard through contract, binding corporate rules, certification or law.

Do Not Call checks

Check the relevant Do Not Call registers before sending specified marketing messages, unless an exemption applies.

Cross-border considerations

  • Personal data may only be transferred outside Singapore if the transferring organisation takes appropriate steps to ensure comparable protection.
  • Accepted mechanisms include contractual clauses, binding corporate rules, certifications such as APEC CBPR, and reliance on the recipient being subject to comparable law.
  • The transferring organisation should record the mechanism relied on for each overseas recipient, alongside the purpose of the transfer.

Enforcement overview

  • The PDPC investigates complaints, issues directions to stop or remediate processing, and can impose financial penalties.
  • The amendments raised the maximum financial penalty for larger organisations, calculated by reference to a percentage of annual turnover in Singapore above a monetary floor.
  • The PDPC publishes decisions, which set clear expectations about security practice and are worth reviewing as a compliance benchmark.
  • Offences exist for individuals who knowingly or recklessly mishandle personal data in specified ways.

Implementation checklist

  1. 1Appoint and publish a Data Protection Officer contact.
  2. 2Document the consent, deemed consent or exception relied on for each data flow.
  3. 3Operate an access and correction process, including the past-12-months disclosure information.
  4. 4Set retention triggers and evidence that data is actually ceased to be retained or anonymised.
  5. 5Record the comparable-protection mechanism for every overseas transfer.
  6. 6Build a breach assessment process that can reach a notification decision within 3 calendar days.
  7. 7Apply Do Not Call checks to telemarketing workflows.

Frequently asked questions

How quickly must a notifiable breach be reported in Singapore?

The PDPC must be notified as soon as practicable and in any case no later than 3 calendar days after the organisation determines the breach is notifiable.

Is consent always required under the PDPA?

No. Deemed consent and specified exceptions — including legitimate interests and business improvement in defined circumstances — can support processing without express consent.

Official sources

Privacy Practice Lab publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation. This page was last reviewed on August 2026.