Singapore
ComprehensivePersonal Data Protection Act 2012 (PDPA)
Authority: Personal Data Protection Commission (PDPC) | Enforcement: Active | Enacted: July 2014
Overview
Singapore's PDPA is a comprehensive data protection framework that has been progressively enhanced since 2012. The 2020 amendments introduced mandatory breach notification, enhanced consent framework (deemed consent by notification), and increased financial penalties. The PDPC is known for practical, business-friendly guidance while maintaining strong enforcement.
14-Topic Coverage
Data Protection Authority
Fully AddressedThe PDPC oversees enforcement, issues advisory guidelines, and handles complaints. Known for practical approach and extensive guidance including sector-specific advisories.
Consent Requirements
Fully AddressedConsent required with exceptions. 2020 amendments introduced deemed consent by notification and legitimate interests exception, aligning closer to GDPR.
Data Subject Rights
Fully AddressedAccess and correction rights. Data portability obligation introduced in 2020 amendments. No explicit erasure right but retention limitation applies.
Cross-Border Transfer
Fully AddressedTransfers permitted with comparable protection in recipient country, consent, binding corporate rules, or contractual arrangements.
Breach Notification
Fully AddressedMandatory 3-day notification to PDPC for significant breaches (500+ individuals or significant harm). Notification to affected individuals also required.
DPO Requirements
Fully AddressedEvery organisation must designate at least one DPO. Contact details must be publicly available.
Children's Data
Partially AddressedNo specific age threshold. Consent from parent/guardian required for minors. PDPC advisory guidelines provide sector-specific guidance.
Penalties & Enforcement
Fully AddressedUp to SGD 1 million or 10% of annual Singapore turnover (2020 amendment). PDPC can issue directions, financial penalties, and accept undertakings.
Sector-Specific Rules
Fully AddressedMAS guidelines for financial sector, MOH for healthcare, IMDA for telecom. Do Not Call Registry for marketing.
Cookie/Tracking
Partially AddressedNo specific cookie legislation. General consent requirements under PDPA apply to online tracking that involves personal data collection.
AI & Automated Decisions
Partially AddressedModel AI Governance Framework (voluntary). No specific legislation. PDPC guidance on AI and personal data. Singapore is positioning as AI-friendly jurisdiction.
Data Localisation
Not AddressedNo data localisation requirements. Singapore promotes itself as a data hub with free flow of data subject to transfer safeguards.
Significant Data Fiduciary
Not AddressedNo equivalent concept. All organisations processing personal data are subject to the same obligations regardless of size.
Government Data
Partially AddressedGovernment agencies exempt from PDPA but subject to Government Instruction Manual on ICT. Public sector data governance framework applies separately.
Key Statistics
- Maximum Penalty
- SGD 1 million or 10% of annual turnover
- Sections in Law
- 67
- Authority
- PDPC
Coverage Summary
Quick Navigation
Need Compliance Help?
Our data privacy team can help you navigate Singapore's regulations.
Book a Consultation