The Personal Data Protection Act (PDPA) is Singapore's baseline data protection law, setting out eleven obligations that govern how organisations handle personal data.
It is enforced by the Personal Data Protection Commission (PDPC), with financial penalties reaching up to 10% of annual turnover in Singapore.
This article covers who must comply, what counts as personal data, each of the eleven obligations, what the 2020 amendment changed, how penalties work, and where to start a compliance programme.
Key Takeaways
A structured compliance programme helps businesses manage PDPA requirements more consistently
The 11 PDPA obligations cover how businesses collect, use, protect, retain, and manage personal data
Businesses that collect or handle personal data in Singapore may need to comply with the PDPA
What Is the PDPA in Singapore?

The Personal Data Protection Act 2012 is Singapore's general data protection law for the private sector. Its data protection provisions took effect on 2 July 2014, following the Do Not Call Registry provisions earlier that year.
The Act is administered by the Personal Data Protection Commission, which sits within the Infocomm Media Development Authority. The PDPC issues guidelines, investigates complaints, publishes enforcement decisions, and can impose financial penalties and remedial directions.
The PDPA is a baseline rather than a ceiling. Where a sectoral rule under the Banking Act, Insurance Act or healthcare regulation sets a stricter standard, that stricter standard prevails.
Who Must Comply with PDPA Singapore
The Act applies to organisations of any size, including companies, partnerships and sole proprietorships, whether or not they are incorporated.
1. Businesses with no physical Singapore office
The PDPA applies regardless of whether an organisation is formed under Singapore law or has an office here, because jurisdiction follows the data activity rather than the corporate footprint. This captures overseas e-commerce operators selling to Singapore consumers and offshore providers processing Singapore customer records.
2. Common exclusions businesses encounter
Individuals acting in a personal capacity, employees acting in the course of employment, and public agencies fall outside the data protection provisions. Business contact information such as names, job titles and work email addresses is also excluded where it is not provided solely for personal purposes. Data intermediaries processing on behalf of another organisation are subject only to the Protection and Retention Limitation Obligations, plus breach notification to their principal.
"Strong data management gives businesses the clarity they need to stay compliant, reduce risk, and make better decisions."
What Counts as Personal Data Under the PDPA
Personal data means data, true or not, about an individual who can be identified from it, or from it together with other information the organisation has or is likely to have access to.
1. Types of data that qualify under the PDPA
Qualifying data includes direct identifiers such as name, NRIC or FIN number, personal mobile number and residential address; financial data such as bank account and payment records; employment data such as salary, performance and leave records; and health and biometric data. Behavioural data such as location or browsing history qualifies where it links back to an identifiable person. Fields that are not identifying alone can qualify in combination, such as job title plus department in a small team.
2. What does not count as personal data
Business contact information, data about corporate entities, and properly anonymised or aggregated data fall outside the definition, as does data about deceased individuals except for the protection and disclosure provisions that continue for ten years after death. Publicly available data is still personal data; what changes is that an exception permits collection without consent. Pseudonymised data where a re-identification key is retained has not been anonymised.
The 11 PDPA Obligations Every Business Must Meet
The PDPC frames the data protection provisions as eleven obligations. Ten are currently in force, with Data Portability enacted in 2020 but not yet brought into operation.
| # | Obligation | What it requires |
|---|---|---|
| 1 | Consent | Obtain consent before collecting, using or disclosing personal data, unless an exception or deemed consent applies. Individuals may withdraw consent at any time. |
| 2 | Purpose Limitation | Use personal data only for purposes a reasonable person would consider appropriate, and that have been notified. |
| 3 | Notification | Inform individuals of the purposes for collection, use and disclosure on or before collecting the data. |
| 4 | Access and Correction | On request, provide an individual with their data and how it was used or disclosed in the past year, and correct errors. |
| 5 | Accuracy | Make reasonable effort to keep data accurate and complete where it informs a decision affecting the individual or is disclosed onward. |
| 6 | Protection | Make reasonable security arrangements against unauthorised access, use, disclosure, modification or disposal. |
| 7 | Retention Limitation | Cease retention or anonymise data once the purpose is served and retention is no longer needed for legal or business reasons. |
| 8 | Transfer Limitation | Transfer data overseas only where the recipient is bound to a comparable standard of protection. |
| 9 | Data Breach Notification | Assess suspected breaches and notify the PDPC and affected individuals where the notifiable threshold is met. |
| 10 | Accountability | Designate a Data Protection Officer, implement policies, publish contact information, and run a complaints process. |
| 11 | Data Portability (not yet in force) | On request, transmit an individual's data in a machine-readable format to another organisation. Enacted in 2020, pending commencement. |
Consent is the obligation most often misapplied. It must be tied to a specific notified purpose, cannot be bundled across unrelated purposes, and a withdrawal request that is not honoured is a contravention on its own.
Accountability carries disproportionate weight in practice. When a complaint reaches the PDPC, the first questions concern whether a DPO was appointed, whether written policies existed, and whether staff were trained on them.
How the 2020 Amendment Changed the PDPA
The Personal Data Protection (Amendment) Act 2020 introduced mandatory breach notification, new consent exceptions, a higher penalty ceiling, and criminal offences applying to individuals rather than organisations.
1. Mandatory data breach notification in practice
Since 1 February 2021, organisations must notify the PDPC of breaches likely to cause significant harm or affecting 500 or more individuals. Organisations must assess breaches within 30 days and notify the PDPC within three calendar days once a breach is confirmed as notifiable. This requires systems that can quickly identify affected individuals and data.
2. Data portability and what it means for your systems
The Data Portability Obligation was enacted in 2020 but is not yet in force, with regulations still pending. It is intended to let individuals transfer their electronic data to another organisation in a machine-readable format. Preparing for this also helps businesses locate and extract individual records for access requests and breach investigations.
PDPA Singapore vs PDPA Malaysia: Why the Difference Matters
Both jurisdictions have a statute abbreviated to PDPA, and the shared name causes real compliance errors in regional operations. They are separate laws with different scope, regulators and penalty structures.
| Aspect | Singapore | Malaysia |
|---|---|---|
| Statute | Personal Data Protection Act 2012 | Personal Data Protection Act 2010, substantially amended in 2024 |
| Regulator | Personal Data Protection Commission, under IMDA | Personal Data Protection Department (JPDP) |
| Scope of activity | Broad application to private sector organisations handling personal data | Historically limited to personal data processed in commercial transactions |
| Registration | No registration regime for organisations | Registration required for prescribed classes of data controller |
| Enforcement outcome | Civil financial penalties calculated against turnover, plus remedial directions | Predominantly criminal fines and, for certain offences, imprisonment |
| Marketing rules | Do Not Call Registry obligations sit within the same Act | No equivalent central registry; handled through consent and opt-out |
A single group-wide privacy policy written to one standard will not discharge both. Singapore's Transfer Limitation Obligation, DNC Registry checks and three-day breach window have no direct Malaysian equivalent, and Malaysia's registration requirement has no Singapore counterpart.
Malaysia's 2024 amendment narrowed several gaps by adding mandatory breach notification, mandatory DPO appointment and a data portability right, phased into force from 2025. Regional programmes written before that amendment should be reviewed rather than assumed current.
PDPA Penalties and Enforcement
The PDPC can impose financial penalties, issue binding directions, and publish its enforcement decisions.
1. Financial penalties and how they are calculated
Since 1 October 2022, the PDPC can impose penalties of up to 10% of annual Singapore turnover for businesses with local turnover above S$10 million, or up to S$1 million, whichever is higher. These are maximum limits, not standard penalties. The PDPC considers factors such as the number of people affected, data sensitivity, exposure period, security measures, and the organisation's response.
2. Other enforcement directions the PDPC can issue
The PDPC can also require an organisation to stop unlawful data collection or use, delete improperly collected data, fulfil access or correction requests, or take remedial steps such as appointing a DPO and training staff. Organisations may also provide voluntary undertakings after taking corrective action. Enforcement decisions and undertakings can be published, creating reputational consequences beyond financial penalties.
Where the 11 Obligations Live Inside Your Business Systems
Most PDPA programmes are written as policy documents and fail at execution, because the obligations are actually discharged inside operational systems.
| Obligation | Where it is discharged |
|---|---|
| Consent | CRM and marketing systems — consent captured against the contact record with timestamp, purpose and source; withdrawal applied across all channels. |
| Purpose Limitation | Access rights configuration restricting which roles can use which data. |
| Notification | Web forms, sign-up flows, POS and onboarding screens where the notice appears at the point of capture. |
| Access and Correction | Search and reporting across CRM, HR, e-commerce and support systems, plus an audit trail of prior use. |
| Accuracy | Master data management — one customer and employee record rather than duplicates diverging across systems. |
| Protection | Role-based access control, authentication policy, encryption and access logging. |
| Retention Limitation | Retention rules per data category with scheduled purge or anonymisation and a legal-hold exception path. |
| Transfer Limitation | Hosting and integration architecture — knowing which systems route data offshore and which contracts cover them. |
| Data Breach Notification | Access logs and record-level traceability allowing affected individuals to be scoped within three days. |
| Accountability | Documented policies, DPO appointment and registration, training records and a logged complaints process. |
| Data Portability | Export capability producing one individual's records in a machine-readable format across systems. |
One requirement repeats down that column: the ability to locate every record about one individual, across every system, quickly and completely. A single integrated ERP platform satisfies that structurally; six disconnected applications satisfy it manually, every time.
Retention and disposal obligations in particular depend on where documents physically sit, which is why a document management system with retention rules and access logs carries more of the compliance load than most businesses expect.
How to Start Your PDPA Compliance Programme
Four steps establish the foundation that every other obligation depends on.
1. Appoint and register your Data Protection Officer
Every organisation must appoint at least one DPO and make their business contact details available. The role can be handled internally or outsourced, but a named person must be responsible. Singapore companies must also provide DPO contact details to ACRA.
2. Conduct a data inventory and mapping exercise
Record what personal data you collect, why you collect it, where it is stored, who can access it, who it is shared with, whether it leaves Singapore, and how long it is kept. Include sources such as emails, spreadsheets, CCTV, visitor logs, recruitment records, and event lists.
3. Review and update your privacy notice
Your privacy notice should clearly explain how personal data is collected, used, and disclosed. Make sure it is available when data is collected and reflects your current practices, including any third-party disclosures. Your notice should also align with the internal rules your teams already follow, so review it alongside your existing customer data privacy policy rather than treating the two as separate documents.
4. Configure retention schedules in your business systems
Set a retention period and reason for each type of personal data, while considering any legal requirements. Configure these rules in your systems with automated deletion or anonymisation where possible, and keep records of deletion activities.
Conclusion
PDPA compliance requires businesses to manage personal data carefully, from collection and storage to access, retention, and breach response.
A clear compliance process and reliable systems can help reduce risks and keep data protection practices consistent.
If you want to strengthen your data management and compliance processes, consult with our experts for free to explore how HashMicro can support your business.
If you want to strengthen your data management and compliance processes, consult with our experts for free to explore how HashMicro can support your business.
FAQ
Yes. The Personal Data Protection Act 2012 imposes legally binding obligations on private sector organisations that collect, use or disclose personal data in Singapore, regardless of business size or whether the organisation has a physical presence in the country. The Personal Data Protection Commission can impose financial penalties of up to 10% of annual turnover in Singapore or S$1 million, whichever is higher, along with remedial directions.
The eleven obligations are Consent, Purpose Limitation, Notification, Access and Correction, Accuracy, Protection, Retention Limitation, Transfer Limitation, Data Breach Notification, Accountability, and Data Portability. Ten are currently in force. The Data Portability Obligation was enacted through the 2020 amendment but has not yet been brought into operation.
Examples include full name, NRIC or FIN number, passport number, personal mobile number, personal email address, residential address, photographs, bank account and payment details, salary and employment records, medical records, and biometric data such as fingerprints. Data is personal data whether it is accurate or not, and fields that are not identifying alone can qualify when combined with other information the organisation holds.
The Personal Data Protection Commission (PDPC), which sits within the Infocomm Media Development Authority, administers and enforces the PDPA. It investigates complaints, issues advisory guidelines, publishes enforcement decisions, imposes financial penalties, and can direct organisations to stop a practice, destroy unlawfully collected data, or implement specified remedial measures.
Yes. Employee personal data such as salary, performance records, leave history, bank details and next-of-kin information is protected under the PDPA. Specific exceptions allow collection, use and disclosure that is reasonable for managing or terminating the employment relationship without separate consent, but the protection, accuracy and retention obligations continue to apply. Business contact information such as a work email address or job title is excluded from the data protection provisions.
Appoint a Data Protection Officer and complete a data inventory. The DPO appointment is a standing requirement under the Accountability Obligation and must be registered with ACRA for Singapore-registered companies. The data inventory, recording what personal data is held, why, where, who can access it and how long it is kept, is the foundation for the retention schedule, the privacy notice, access request handling and breach scoping.















