What it is
The Personal Data Protection Act 2012 (PDPA) is Singapore's general data protection law for the private sector. Its main data protection rules came into force in 2014 and it was significantly amended in 2020, adding mandatory breach notification, new bases for processing without consent and higher penalties. It is administered by the Personal Data Protection Commission (PDPC).
Who it applies to
The PDPA applies to private-sector "organisations", which includes companies, associations and individuals acting in a business capacity, whether or not they are formed or resident in Singapore, if they collect, use or disclose personal data in Singapore. A "data intermediary" that processes data on behalf of another organisation has a narrower set of duties. Public agencies are covered by separate government rules, and individuals acting in a personal or domestic capacity are excluded.
Core principles
The Act builds on several obligations: consent, purpose limitation, notification, access and correction, accuracy, protection, retention limitation, transfer limitation, data breach notification and accountability. Organisations may collect, use or disclose personal data only for purposes a reasonable person would consider appropriate, and generally with the individual's consent after notifying them of the purposes.
Legal bases
Besides express consent, the PDPA recognises deemed consent (for example by conduct, by contractual necessity, or by notification with an opt-out period) and a set of exceptions to consent. The 2020 amendments added a legitimate interests exception, subject to an assessment of the risks and benefits, and a business improvement exception. Other exceptions cover situations such as emergencies, investigations and research.
Individual rights
Individuals can withdraw consent, request access to their personal data and information on how it has been used or disclosed in the preceding year, and request correction of errors. Organisations must respond within the prescribed timeframes and may charge a reasonable fee for access. The Act in its current form does not contain a general right to erasure.
Key obligations
Every organisation must appoint at least one data protection officer and make the contact details available, develop and publish policies and practices, and make reasonable security arrangements to protect personal data. Personal data must not be kept longer than needed, and transfers outside Singapore are allowed only if the recipient is bound by legally enforceable obligations to give comparable protection. The Do Not Call Registry provisions restrict sending marketing messages to Singapore telephone numbers listed on the register, and further offences cover unauthorised disclosure, improper use and re-identification of anonymised information.
Data breaches
Organisations must assess a suspected data breach promptly, within a prescribed period of becoming aware of it. If the breach is likely to cause significant harm to individuals or is of significant scale, the organisation must notify the PDPC as soon as practicable and within three calendar days of making that assessment, and notify affected individuals where significant harm is likely.
Enforcement and penalties
The PDPC can investigate, order compliance, accept voluntary undertakings and impose financial penalties. For organisations above a turnover threshold, the maximum financial penalty is a percentage of annual turnover in Singapore, or S$1 million if that is higher. Certain offences by individuals, such as unauthorised disclosure or improper use of personal data, are criminal, and individuals who suffer loss or damage can bring a private action.
The official text
The authoritative version is the Personal Data Protection Act 2012 on Singapore Statutes Online, maintained by the Attorney-General's Chambers. Use that text, not this summary, for anything that matters.
Below is the source we understand to be the official text (English, official). We cannot guarantee it is correct, current, complete, or the authoritative version, and we may have linked or labelled it wrong, so please check it yourself and do not rely on it or on our summary:
Go to the source →