Data Protection Matters
← All privacy laws

Singapore

PDPA

Personal Data Protection Act 2012 (Singapore)

Keywords

PDPASingaporePersonal Data Protection Act 2012PDPCconsentdeemed consentlegitimate interestsdata protection officerDPOnotifiable data breachDo Not Call Registrydata intermediarytransfer limitationfinancial penaltyaccountability
Plain-English overview, not the law. This is a general summary we wrote to help you get oriented. It is not legal advice, it is not binding, and it may simplify, omit, or get things wrong. We also cannot guarantee that the source we link to is the correct, current, or official text; we may have linked or labelled it wrong. For anything that matters, find and read the law itself and seek advice for your situation.

What it is

The Personal Data Protection Act 2012 (PDPA) is Singapore's general data protection law for the private sector. Its main data protection rules came into force in 2014 and it was significantly amended in 2020, adding mandatory breach notification, new bases for processing without consent and higher penalties. It is administered by the Personal Data Protection Commission (PDPC).

Who it applies to

The PDPA applies to private-sector "organisations", which includes companies, associations and individuals acting in a business capacity, whether or not they are formed or resident in Singapore, if they collect, use or disclose personal data in Singapore. A "data intermediary" that processes data on behalf of another organisation has a narrower set of duties. Public agencies are covered by separate government rules, and individuals acting in a personal or domestic capacity are excluded.

Core principles

The Act builds on several obligations: consent, purpose limitation, notification, access and correction, accuracy, protection, retention limitation, transfer limitation, data breach notification and accountability. Organisations may collect, use or disclose personal data only for purposes a reasonable person would consider appropriate, and generally with the individual's consent after notifying them of the purposes.

Besides express consent, the PDPA recognises deemed consent (for example by conduct, by contractual necessity, or by notification with an opt-out period) and a set of exceptions to consent. The 2020 amendments added a legitimate interests exception, subject to an assessment of the risks and benefits, and a business improvement exception. Other exceptions cover situations such as emergencies, investigations and research.

Individual rights

Individuals can withdraw consent, request access to their personal data and information on how it has been used or disclosed in the preceding year, and request correction of errors. Organisations must respond within the prescribed timeframes and may charge a reasonable fee for access. The Act in its current form does not contain a general right to erasure.

Key obligations

Every organisation must appoint at least one data protection officer and make the contact details available, develop and publish policies and practices, and make reasonable security arrangements to protect personal data. Personal data must not be kept longer than needed, and transfers outside Singapore are allowed only if the recipient is bound by legally enforceable obligations to give comparable protection. The Do Not Call Registry provisions restrict sending marketing messages to Singapore telephone numbers listed on the register, and further offences cover unauthorised disclosure, improper use and re-identification of anonymised information.

Data breaches

Organisations must assess a suspected data breach promptly, within a prescribed period of becoming aware of it. If the breach is likely to cause significant harm to individuals or is of significant scale, the organisation must notify the PDPC as soon as practicable and within three calendar days of making that assessment, and notify affected individuals where significant harm is likely.

Enforcement and penalties

The PDPC can investigate, order compliance, accept voluntary undertakings and impose financial penalties. For organisations above a turnover threshold, the maximum financial penalty is a percentage of annual turnover in Singapore, or S$1 million if that is higher. Certain offences by individuals, such as unauthorised disclosure or improper use of personal data, are criminal, and individuals who suffer loss or damage can bring a private action.

The official text

The authoritative version is the Personal Data Protection Act 2012 on Singapore Statutes Online, maintained by the Attorney-General's Chambers. Use that text, not this summary, for anything that matters.

Below is the source we understand to be the official text (English, official). We cannot guarantee it is correct, current, complete, or the authoritative version, and we may have linked or labelled it wrong, so please check it yourself and do not rely on it or on our summary:

Go to the source →