Singapore

Comprehensive

Personal Data Protection Act 2012 (PDPA)

Authority: Personal Data Protection Commission (PDPC) | Enforcement: Active | Enacted: July 2014

Overview

Singapore's PDPA is a comprehensive data protection framework that has been progressively enhanced since 2012. The 2020 amendments introduced mandatory breach notification, enhanced consent framework (deemed consent by notification), and increased financial penalties. The PDPC is known for practical, business-friendly guidance while maintaining strong enforcement.

14-Topic Coverage

Data Protection Authority

Fully Addressed

The PDPC oversees enforcement, issues advisory guidelines, and handles complaints. Known for practical approach and extensive guidance including sector-specific advisories.

PDPA Part II

Data Subject Rights

Fully Addressed

Access and correction rights. Data portability obligation introduced in 2020 amendments. No explicit erasure right but retention limitation applies.

PDPA Sections 21-22, Part VIA

Cross-Border Transfer

Fully Addressed

Transfers permitted with comparable protection in recipient country, consent, binding corporate rules, or contractual arrangements.

PDPA Section 26

Breach Notification

Fully Addressed

Mandatory 3-day notification to PDPC for significant breaches (500+ individuals or significant harm). Notification to affected individuals also required.

PDPA Part VIA, Sections 26A-26E

DPO Requirements

Fully Addressed

Every organisation must designate at least one DPO. Contact details must be publicly available.

PDPA Section 11(3)

Children's Data

Partially Addressed

No specific age threshold. Consent from parent/guardian required for minors. PDPC advisory guidelines provide sector-specific guidance.

PDPA Advisory Guidelines

Penalties & Enforcement

Fully Addressed

Up to SGD 1 million or 10% of annual Singapore turnover (2020 amendment). PDPC can issue directions, financial penalties, and accept undertakings.

PDPA Section 48J

Sector-Specific Rules

Fully Addressed

MAS guidelines for financial sector, MOH for healthcare, IMDA for telecom. Do Not Call Registry for marketing.

PDPA Parts IX-X, MAS Technology Risk Management Guidelines

AI & Automated Decisions

Partially Addressed

Model AI Governance Framework (voluntary). No specific legislation. PDPC guidance on AI and personal data. Singapore is positioning as AI-friendly jurisdiction.

Model AI Governance Framework 2020

Data Localisation

Not Addressed

No data localisation requirements. Singapore promotes itself as a data hub with free flow of data subject to transfer safeguards.

PDPA Section 26

Significant Data Fiduciary

Not Addressed

No equivalent concept. All organisations processing personal data are subject to the same obligations regardless of size.

PDPA general application

Government Data

Partially Addressed

Government agencies exempt from PDPA but subject to Government Instruction Manual on ICT. Public sector data governance framework applies separately.

PDPA Section 4(1)(c), Public Sector Governance Act

Key Statistics

Maximum Penalty
SGD 1 million or 10% of annual turnover
Sections in Law
67
Authority
PDPC

Coverage Summary

Fully Addressed8/14
Partially Addressed4/14
Not Addressed2/14
Pending0/14

Need Compliance Help?

Our data privacy team can help you navigate Singapore's regulations.

Book a Consultation