PDPA Singapore: 11 Obligations, Penalties & Compliance Checklist
GOLDEN
MONTH
Promo
up to
30%
1 DAYS LEFTLIMITED QUOTA
Claim Now!Limited to 100 registrants

PDPA Singapore: 11 Obligations, Penalties & Compliance Checklist

PDPA Singapore: 11 Obligations, Penalties & Compliance Checklist

The Personal Data Protection Act (PDPA) is Singapore's baseline data protection law, setting out eleven obligations that govern how organisations handle personal data. 

It is enforced by the Personal Data Protection Commission (PDPC), with financial penalties reaching up to 10% of annual turnover in Singapore.

This article covers who must comply, what counts as personal data, each of the eleven obligations, what the 2020 amendment changed, how penalties work, and where to start a compliance programme.

Key Takeaways

A structured compliance programme helps businesses manage PDPA requirements more consistently

The 11 PDPA obligations cover how businesses collect, use, protect, retain, and manage personal data

Businesses that collect or handle personal data in Singapore may need to comply with the PDPA

Free Demo

What Is the PDPA in Singapore?

PDPA Singapore: 11 Obligations, Penalties & Compliance Checklist illustration

The Personal Data Protection Act 2012 is Singapore's general data protection law for the private sector. Its data protection provisions took effect on 2 July 2014, following the Do Not Call Registry provisions earlier that year.

The Act is administered by the Personal Data Protection Commission, which sits within the Infocomm Media Development Authority. The PDPC issues guidelines, investigates complaints, publishes enforcement decisions, and can impose financial penalties and remedial directions.

The PDPA is a baseline rather than a ceiling. Where a sectoral rule under the Banking Act, Insurance Act or healthcare regulation sets a stricter standard, that stricter standard prevails.

Who Must Comply with PDPA Singapore

The Act applies to organisations of any size, including companies, partnerships and sole proprietorships, whether or not they are incorporated.

1. Businesses with no physical Singapore office

The PDPA applies regardless of whether an organisation is formed under Singapore law or has an office here, because jurisdiction follows the data activity rather than the corporate footprint. This captures overseas e-commerce operators selling to Singapore consumers and offshore providers processing Singapore customer records. 

2. Common exclusions businesses encounter

Individuals acting in a personal capacity, employees acting in the course of employment, and public agencies fall outside the data protection provisions. Business contact information such as names, job titles and work email addresses is also excluded where it is not provided solely for personal purposes. Data intermediaries processing on behalf of another organisation are subject only to the Protection and Retention Limitation Obligations, plus breach notification to their principal.

"Strong data management gives businesses the clarity they need to stay compliant, reduce risk, and make better decisions."

Ricky Halim, B.Sc. Managing Director

What Counts as Personal Data Under the PDPA

Personal data means data, true or not, about an individual who can be identified from it, or from it together with other information the organisation has or is likely to have access to.

1. Types of data that qualify under the PDPA

Qualifying data includes direct identifiers such as name, NRIC or FIN number, personal mobile number and residential address; financial data such as bank account and payment records; employment data such as salary, performance and leave records; and health and biometric data. Behavioural data such as location or browsing history qualifies where it links back to an identifiable person. Fields that are not identifying alone can qualify in combination, such as job title plus department in a small team.

2. What does not count as personal data

Business contact information, data about corporate entities, and properly anonymised or aggregated data fall outside the definition, as does data about deceased individuals except for the protection and disclosure provisions that continue for ten years after death. Publicly available data is still personal data; what changes is that an exception permits collection without consent. Pseudonymised data where a re-identification key is retained has not been anonymised.

The 11 PDPA Obligations Every Business Must Meet

The PDPC frames the data protection provisions as eleven obligations. Ten are currently in force, with Data Portability enacted in 2020 but not yet brought into operation.

#ObligationWhat it requires
1ConsentObtain consent before collecting, using or disclosing personal data, unless an exception or deemed consent applies. Individuals may withdraw consent at any time.
2Purpose LimitationUse personal data only for purposes a reasonable person would consider appropriate, and that have been notified.
3NotificationInform individuals of the purposes for collection, use and disclosure on or before collecting the data.
4Access and CorrectionOn request, provide an individual with their data and how it was used or disclosed in the past year, and correct errors.
5AccuracyMake reasonable effort to keep data accurate and complete where it informs a decision affecting the individual or is disclosed onward.
6ProtectionMake reasonable security arrangements against unauthorised access, use, disclosure, modification or disposal.
7Retention LimitationCease retention or anonymise data once the purpose is served and retention is no longer needed for legal or business reasons.
8Transfer LimitationTransfer data overseas only where the recipient is bound to a comparable standard of protection.
9Data Breach NotificationAssess suspected breaches and notify the PDPC and affected individuals where the notifiable threshold is met.
10AccountabilityDesignate a Data Protection Officer, implement policies, publish contact information, and run a complaints process.
11Data Portability (not yet in force)On request, transmit an individual's data in a machine-readable format to another organisation. Enacted in 2020, pending commencement.

Consent is the obligation most often misapplied. It must be tied to a specific notified purpose, cannot be bundled across unrelated purposes, and a withdrawal request that is not honoured is a contravention on its own.

Accountability carries disproportionate weight in practice. When a complaint reaches the PDPC, the first questions concern whether a DPO was appointed, whether written policies existed, and whether staff were trained on them.

How the 2020 Amendment Changed the PDPA

The Personal Data Protection (Amendment) Act 2020 introduced mandatory breach notification, new consent exceptions, a higher penalty ceiling, and criminal offences applying to individuals rather than organisations.

1. Mandatory data breach notification in practice

Since 1 February 2021, organisations must notify the PDPC of breaches likely to cause significant harm or affecting 500 or more individuals. Organisations must assess breaches within 30 days and notify the PDPC within three calendar days once a breach is confirmed as notifiable. This requires systems that can quickly identify affected individuals and data.

2. Data portability and what it means for your systems

The Data Portability Obligation was enacted in 2020 but is not yet in force, with regulations still pending. It is intended to let individuals transfer their electronic data to another organisation in a machine-readable format. Preparing for this also helps businesses locate and extract individual records for access requests and breach investigations.

PDPA Singapore vs PDPA Malaysia: Why the Difference Matters

Both jurisdictions have a statute abbreviated to PDPA, and the shared name causes real compliance errors in regional operations. They are separate laws with different scope, regulators and penalty structures.

AspectSingaporeMalaysia
StatutePersonal Data Protection Act 2012Personal Data Protection Act 2010, substantially amended in 2024
RegulatorPersonal Data Protection Commission, under IMDAPersonal Data Protection Department (JPDP)
Scope of activityBroad application to private sector organisations handling personal dataHistorically limited to personal data processed in commercial transactions
RegistrationNo registration regime for organisationsRegistration required for prescribed classes of data controller
Enforcement outcomeCivil financial penalties calculated against turnover, plus remedial directionsPredominantly criminal fines and, for certain offences, imprisonment
Marketing rulesDo Not Call Registry obligations sit within the same ActNo equivalent central registry; handled through consent and opt-out

A single group-wide privacy policy written to one standard will not discharge both. Singapore's Transfer Limitation Obligation, DNC Registry checks and three-day breach window have no direct Malaysian equivalent, and Malaysia's registration requirement has no Singapore counterpart.

Malaysia's 2024 amendment narrowed several gaps by adding mandatory breach notification, mandatory DPO appointment and a data portability right, phased into force from 2025. Regional programmes written before that amendment should be reviewed rather than assumed current.

PDPA Penalties and Enforcement

The PDPC can impose financial penalties, issue binding directions, and publish its enforcement decisions.

1. Financial penalties and how they are calculated

Since 1 October 2022, the PDPC can impose penalties of up to 10% of annual Singapore turnover for businesses with local turnover above S$10 million, or up to S$1 million, whichever is higher. These are maximum limits, not standard penalties. The PDPC considers factors such as the number of people affected, data sensitivity, exposure period, security measures, and the organisation's response.

2. Other enforcement directions the PDPC can issue

The PDPC can also require an organisation to stop unlawful data collection or use, delete improperly collected data, fulfil access or correction requests, or take remedial steps such as appointing a DPO and training staff. Organisations may also provide voluntary undertakings after taking corrective action. Enforcement decisions and undertakings can be published, creating reputational consequences beyond financial penalties.

Where the 11 Obligations Live Inside Your Business Systems

Most PDPA programmes are written as policy documents and fail at execution, because the obligations are actually discharged inside operational systems.

ObligationWhere it is discharged
ConsentCRM and marketing systems — consent captured against the contact record with timestamp, purpose and source; withdrawal applied across all channels.
Purpose LimitationAccess rights configuration restricting which roles can use which data.
NotificationWeb forms, sign-up flows, POS and onboarding screens where the notice appears at the point of capture.
Access and CorrectionSearch and reporting across CRM, HR, e-commerce and support systems, plus an audit trail of prior use.
AccuracyMaster data management — one customer and employee record rather than duplicates diverging across systems.
ProtectionRole-based access control, authentication policy, encryption and access logging.
Retention LimitationRetention rules per data category with scheduled purge or anonymisation and a legal-hold exception path.
Transfer LimitationHosting and integration architecture — knowing which systems route data offshore and which contracts cover them.
Data Breach NotificationAccess logs and record-level traceability allowing affected individuals to be scoped within three days.
AccountabilityDocumented policies, DPO appointment and registration, training records and a logged complaints process.
Data PortabilityExport capability producing one individual's records in a machine-readable format across systems.

One requirement repeats down that column: the ability to locate every record about one individual, across every system, quickly and completely. A single integrated ERP platform satisfies that structurally; six disconnected applications satisfy it manually, every time.


Retention and disposal obligations in particular depend on where documents physically sit, which is why a document management system with retention rules and access logs carries more of the compliance load than most businesses expect.

How to Start Your PDPA Compliance Programme

Four steps establish the foundation that every other obligation depends on.

1. Appoint and register your Data Protection Officer

Every organisation must appoint at least one DPO and make their business contact details available. The role can be handled internally or outsourced, but a named person must be responsible. Singapore companies must also provide DPO contact details to ACRA.

2. Conduct a data inventory and mapping exercise

Record what personal data you collect, why you collect it, where it is stored, who can access it, who it is shared with, whether it leaves Singapore, and how long it is kept. Include sources such as emails, spreadsheets, CCTV, visitor logs, recruitment records, and event lists.

3. Review and update your privacy notice

Your privacy notice should clearly explain how personal data is collected, used, and disclosed. Make sure it is available when data is collected and reflects your current practices, including any third-party disclosures. Your notice should also align with the internal rules your teams already follow, so review it alongside your existing customer data privacy policy rather than treating the two as separate documents.



4. Configure retention schedules in your business systems

Set a retention period and reason for each type of personal data, while considering any legal requirements. Configure these rules in your systems with automated deletion or anonymisation where possible, and keep records of deletion activities.

Conclusion

PDPA compliance requires businesses to manage personal data carefully, from collection and storage to access, retention, and breach response. 

A clear compliance process and reliable systems can help reduce risks and keep data protection practices consistent.

If you want to strengthen your data management and compliance processes, consult with our experts for free to explore how HashMicro can support your business.

pricing scheme

If you want to strengthen your data management and compliance processes, consult with our experts for free to explore how HashMicro can support your business.

FAQ

Yes. The Personal Data Protection Act 2012 imposes legally binding obligations on private sector organisations that collect, use or disclose personal data in Singapore, regardless of business size or whether the organisation has a physical presence in the country. The Personal Data Protection Commission can impose financial penalties of up to 10% of annual turnover in Singapore or S$1 million, whichever is higher, along with remedial directions.

The eleven obligations are Consent, Purpose Limitation, Notification, Access and Correction, Accuracy, Protection, Retention Limitation, Transfer Limitation, Data Breach Notification, Accountability, and Data Portability. Ten are currently in force. The Data Portability Obligation was enacted through the 2020 amendment but has not yet been brought into operation.

Examples include full name, NRIC or FIN number, passport number, personal mobile number, personal email address, residential address, photographs, bank account and payment details, salary and employment records, medical records, and biometric data such as fingerprints. Data is personal data whether it is accurate or not, and fields that are not identifying alone can qualify when combined with other information the organisation holds.

The Personal Data Protection Commission (PDPC), which sits within the Infocomm Media Development Authority, administers and enforces the PDPA. It investigates complaints, issues advisory guidelines, publishes enforcement decisions, imposes financial penalties, and can direct organisations to stop a practice, destroy unlawfully collected data, or implement specified remedial measures.

Yes. Employee personal data such as salary, performance records, leave history, bank details and next-of-kin information is protected under the PDPA. Specific exceptions allow collection, use and disclosure that is reasonable for managing or terminating the employment relationship without separate consent, but the protection, accuracy and retention obligations continue to apply. Business contact information such as a work email address or job title is excluded from the data protection provisions.

Appoint a Data Protection Officer and complete a data inventory. The DPO appointment is a standing requirement under the Accountability Obligation and must be registered with ACRA for Singapore-registered companies. The data inventory, recording what personal data is held, why, where, who can access it and how long it is kept, is the foundation for the retention schedule, the privacy notice, access request handling and breach scoping.


Grace Tan

Content Writer

Grace Tan writes general business articles that cover a wide range of topics relevant to professionals and entrepreneurs. She ensures each article is insightful, practical, and aligned with current trends. Her focus on SEO and readability helps drive sustained engagement.

Ricky Halim is a professional in the field of technology and business development who focuses on innovative corporate solutions. With extensive experience in product management and growth strategy, Ricky has played a key role in making HashMicro the leading ERP solution in Southeast Asia, a breakthrough that combines system intelligence with modern operational needs.

HashMicro follows strict editorial standards and uses primary sources such as regulations, industry guidance, and trusted publications to keep content accurate and relevant.

LEAVE A REPLY

Please enter your comment!
Please enter your name!