Skip to content
GlanceDeskJurisdiction

Home › Law library › PDPA

SG

PDPA

Personal Data Protection Act 2012

Sourced. Last verified 9 October 2026

Singapore Privacy

Status
In force; amended by the PDPA (Amendment) Act 2020 (mandatory breach notification, higher fines). Data portability obligation not yet in force pending regulations.
Who it applies to
Private-sector organisations that collect, use or disclose personal data in Singapore, whether or not they are based or incorporated there. The public sector and business contact information are excluded.
Size thresholds
No size threshold. Breach notice to the PDPC is required if significant harm is likely or 500+ individuals are affected. Higher fine cap applies above S$10 million Singapore turnover.
Regulator
Personal Data Protection Commission (PDPC)
Breach or incident reporting
Assess a suspected breach within 30 days. Notify the PDPC as soon as practicable and no later than 3 days after deciding it is notifiable. Notify affected individuals as soon as practicable if significant harm is likely. Processors must alert the organisation without undue delay.
Deadline to answer personal data requests
Respond to access requests as soon as reasonably possible; if you cannot within 30 days, tell the individual in writing within 30 days when you will respond.
Data protection officer
Every organisation must designate at least one Data Protection Officer and make its business contact details publicly available. The DPO need not be in Singapore but should be reachable during Singapore business hours.
Local representative
No local representative requirement.
Sending data abroad
Transfer only if the recipient gives protection comparable to the PDPA, e.g. via contract (PDPC sample clauses), binding corporate rules, certification, consent after notice, or prescribed cases such as contract performance. PDPC can grant exemptions.
Cookies and consent
Consent is required unless an exception applies (deemed consent by contract or notification with opt-out, legitimate interests, business improvement). Telemarketing needs consent or a Do Not Call Registry check.
Maximum penalty
Up to 10% of annual Singapore turnover if that turnover exceeds S$10 million, otherwise up to S$1 million. Criminal offences for reckless disclosure, re-identification and misuse of data.

Facts marked “Being verified” are still being confirmed and are not given as answers.

What you must do

Recent changes

2 Feb 2026: PDPC said private organisations must stop using NRIC numbers (full or partial) for authentication by 31 Dec 2026, with stepped-up enforcement from 1 Jan 2027. No other major 2024-2026 statutory change found.

Sources

Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].