PDPA (SG)
Personal Data Protection Act 2012 (Singapore)
Consent-based privacy law with mandatory breach notification since 2021.
The law in brief
Singapore's Personal Data Protection Act (PDPA) governs how private-sector organizations collect, use and disclose personal data. It is consent-based but practical: it recognizes deemed consent and a legitimate interests exception, it requires a data protection officer, and since February 2021 it requires notification of significant data breaches.
It also houses Singapore's Do Not Call Registry rules for marketing messages to Singapore numbers.
Who it applies to
- Organizations collecting, using or disclosing personal data in Singapore, including those outside Singapore.
- Public agencies are excluded; organizations acting on their behalf have limited duties.
- Data intermediaries processing data for another organization have protection, retention and breach notification duties.
What it requires
Accountability and a DPO
Designate one or more individuals responsible for compliance, develop policies and practices, and make information about them available.
Consent, purpose and notification
Collect, use or disclose personal data only with consent (including deemed consent) or under an exception, for purposes a reasonable person would consider appropriate, notified to the individual.
Protection and retention
Make reasonable security arrangements to protect personal data, and stop retaining it when no longer needed for legal or business purposes.
Transfer limitation
Transfer personal data outside Singapore only where the recipient is bound to a comparable standard of protection.
Breach notification
Assess a suspected breach within 30 days, and notify the Commission no later than three calendar days after determining it is notifiable, and affected individuals where there is likely significant harm.
People's rights
Individuals can withdraw consent with reasonable notice, access their personal data and information about how it was used or disclosed in the past year, and ask for corrections.
Enforcement and penalties
Financial penalties of up to 10% of the organization's annual turnover in Singapore where that turnover exceeds S$10 million, or up to S$1 million otherwise. The Personal Data Protection Commission publishes its enforcement decisions, which frequently concern the protection obligation.
What to do first
- Appoint a data protection officer and publish their business contact information.
- Check your consent basis for each purpose, including deemed consent and legitimate interests assessments.
- Tighten protection: most enforcement cases involve inadequate security arrangements.
- Set a breach process: assess within 30 days and notify the Commission within three calendar days of determining a breach is notifiable.
- Check marketing to Singapore numbers against the Do Not Call Registry.
Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.
Recent developments
Nothing reported yet. Regulatory Watch lists new rules, enforcement and court decisions as they arrive.
Sources
- Personal Data Protection Act 2012 Singapore Statutes Online · Official text or regulator