Home › Law library › PDPA
SG
PDPA
Personal Data Protection Act 2012
Sourced. Last verified 9 October 2026
Singapore Privacy
- Status
- In force; amended by the PDPA (Amendment) Act 2020 (mandatory breach notification, higher fines). Data portability obligation not yet in force pending regulations.
- Who it applies to
- Private-sector organisations that collect, use or disclose personal data in Singapore, whether or not they are based or incorporated there. The public sector and business contact information are excluded.
- Size thresholds
- No size threshold. Breach notice to the PDPC is required if significant harm is likely or 500+ individuals are affected. Higher fine cap applies above S$10 million Singapore turnover.
- Regulator
- Personal Data Protection Commission (PDPC)
- Breach or incident reporting
- Assess a suspected breach within 30 days. Notify the PDPC as soon as practicable and no later than 3 days after deciding it is notifiable. Notify affected individuals as soon as practicable if significant harm is likely. Processors must alert the organisation without undue delay.
- Deadline to answer personal data requests
- Respond to access requests as soon as reasonably possible; if you cannot within 30 days, tell the individual in writing within 30 days when you will respond.
- Data protection officer
- Every organisation must designate at least one Data Protection Officer and make its business contact details publicly available. The DPO need not be in Singapore but should be reachable during Singapore business hours.
- Local representative
- No local representative requirement.
- Sending data abroad
- Transfer only if the recipient gives protection comparable to the PDPA, e.g. via contract (PDPC sample clauses), binding corporate rules, certification, consent after notice, or prescribed cases such as contract performance. PDPC can grant exemptions.
- Cookies and consent
- Consent is required unless an exception applies (deemed consent by contract or notification with opt-out, legitimate interests, business improvement). Telemarketing needs consent or a Do Not Call Registry check.
- Maximum penalty
- Up to 10% of annual Singapore turnover if that turnover exceeds S$10 million, otherwise up to S$1 million. Criminal offences for reckless disclosure, re-identification and misuse of data.
Facts marked “Being verified” are still being confirmed and are not given as answers.
What you must do
- Appoint a DPO and publish their business contact details
- Notify purposes and get consent, or document the deemed-consent or legitimate-interests assessment
- Assess breaches within 30 days and notify the PDPC within 3 days of finding them notifiable
- Check the Do Not Call Registry before marketing calls or texts without clear consent
- Use contracts or other safeguards giving comparable protection before transferring data abroad
- Stop using NRIC numbers for login or authentication by 31 Dec 2026
Recent changes
2 Feb 2026: PDPC said private organisations must stop using NRIC numbers (full or partial) for authentication by 31 Dec 2026, with stepped-up enforcement from 1 Jan 2027. No other major 2024-2026 statutory change found.
Sources
- Primary source: https://www.pdpc.gov.sg/overview-of-pdpa/the-legislation/personal-data-protection-act/data-protection-obligations
- Second source: https://www.dlapiperdataprotection.com/index.html?t=law&c=SG
- Regulator: Personal Data Protection Commission (PDPC)
Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].