PDPA Singapore: What the Personal Data Protection Act Means for You
A plain guide to Singapore's PDPA: what it covers, your consent, access and correction rights, the Do Not Call Registry, breach notification and how to complain to the PDPC.
The PDPA is Singapore’s Personal Data Protection Act 2012, the main law governing how private-sector organizations collect, use and disclose personal data. It generally requires organizations to get your consent and tell you why they want your data, lets you ask for access to and correction of your data, requires notification of serious data breaches, and runs the Do Not Call Registry. It is administered by the Personal Data Protection Commission (PDPC), which is also where you complain if an organization won’t resolve a problem.
This guide explains PDPA Singapore rules from the individual’s side: what you can ask for, what organizations must do, and how to escalate. We’re a reputation management firm operated from Singapore, not a law firm, so treat this as general information and talk to a Singapore lawyer about your specific situation.
What the PDPA is and who it covers
The PDPA was passed in 2012, with its main data protection obligations taking effect in 2014. It was significantly updated by the Personal Data Protection (Amendment) Act 2020, which added mandatory data breach notification, new exceptions to consent and higher financial penalties.
The law applies to organizations that collect, use or disclose personal data in Singapore, including companies, charities and associations, and it can reach overseas organizations that do so. “Personal data” means data, true or not, about an individual who can be identified from that data, or from that data together with other information the organization has or is likely to have access to.
Some things fall outside the main obligations:
- Public agencies. Government bodies are covered by separate public sector rules, not the PDPA’s data protection obligations.
- Individuals acting in a personal or domestic capacity. A neighbor posting about you on social media isn’t regulated by the PDPA in the way a business is. Other laws, such as harassment or defamation law, may apply instead.
- Business contact information. Your work name, title, business phone and email, provided for business purposes, are largely excluded.
- Employees acting for their employer. The employer carries the obligations, not the individual staff member.
The main obligations organizations must follow
The PDPC describes the law as a set of data protection obligations. In plain terms:
| Obligation | What it means for you |
|---|---|
| Consent | An organization generally needs your consent to collect, use or disclose your data, unless the law deems consent or an exception applies. |
| Purpose limitation | Data can only be used for purposes a reasonable person would consider appropriate in the circumstances. |
| Notification | You should be told the purposes before or when your data is collected. |
| Access and correction | You can ask what data an organization holds and how it has been used, and ask for errors to be fixed. |
| Accuracy | Organizations must make reasonable efforts to keep data accurate if it will be used to make decisions about you. |
| Protection | They must make reasonable security arrangements to protect your data. |
| Retention limitation | They should stop keeping data once it’s no longer needed for legal or business purposes. |
| Transfer limitation | Data sent overseas must be protected to a standard comparable to the PDPA. |
| Data breach notification | Serious breaches must be reported to the PDPC and, in some cases, to you. |
| Accountability | Organizations must have policies, designate a data protection officer (DPO) and make the DPO’s business contact details available. |
The 2020 amendments also introduced a data portability obligation, which is meant to let you ask for your data to be moved to another organization. Its practical start depends on regulations, so check the PDPC’s website for whether and how it applies at the time you need it.
Consent under the PDPA, and how to withdraw it
Consent is the starting point, but it isn’t the only basis. The PDPA recognizes deemed consent, for example where you voluntarily hand over your details for an obvious purpose, such as giving your address for a delivery. The 2020 amendments added deemed consent by notification, where an organization tells you about a new purpose and gives you a reasonable chance to opt out.
There are also exceptions where consent isn’t needed at all, including a “legitimate interests” exception, subject to an assessment the organization must carry out, and a business improvement exception. Publicly available data is another exception, which is one reason information that is already public can be hard to control under the PDPA.
You can withdraw consent by giving reasonable notice. The organization must then tell you the likely consequences, for example that it can no longer provide a service, and must stop collecting, using and disclosing your data for that purpose unless the law allows it to continue. Withdrawal doesn’t automatically mean deletion, but the retention limitation obligation means the organization shouldn’t keep data it no longer has a reason to hold.
Your right to access and correct your data
You can ask an organization for the personal data about you that it holds or controls, and for information about the ways that data has been or may have been used or disclosed within the year before your request. This is Singapore’s version of a subject access request. Our guide to making a data subject access request covers the wording in more depth; the PDPA version works in much the same way.
- Find the DPO contact. Organizations must make their data protection officer’s business contact information available, usually in a privacy policy or data protection notice.
- Write a clear request. Say you’re making an access request (or correction request) under the PDPA, identify yourself, and describe the data you want.
- Expect identity checks. The organization can take reasonable steps to confirm you are who you say you are.
- Watch for a fee estimate. An organization may charge a reasonable fee for an access request, but it should give you a written estimate first. Correction requests shouldn’t carry a charge.
- Track the timing. The organization must respond as soon as reasonably possible. Under the PDPC’s regulations, if it can’t respond within 30 days, it must tell you in writing within that time when it will be able to.
Organizations can refuse access in some situations, such as where giving it would reveal another person’s personal data or where the request is frivolous. For corrections, an organization that decides not to change the data should annotate it with the correction you asked for.
The Do Not Call Registry
The PDPA also contains the Do Not Call (DNC) provisions, which cover marketing messages sent to Singapore telephone numbers. The DNC Registry has three separate registers: voice calls, text messages and fax. You can register your number on any or all of them free through the official DNC service run by the PDPC.
Once your number is registered, organizations generally can’t send you telemarketing messages on that channel unless they have your clear and unambiguous consent, given in writing or another accessible form, or an exemption applies. Organizations are expected to check the register before sending marketing messages, and messages must identify the sender and give contact details.
The DNC rules deal with marketing, not scams. If you’re getting scam calls or texts, report them through Singapore’s anti-scam channels and to your telco rather than relying on the DNC Registry. For general steps on cutting down unwanted calls, see our guide to removing your phone number from spam lists.
Data breach notification
Since the 2020 amendments came into force, organizations must assess suspected data breaches promptly. Under the breach notification rules, a breach is notifiable if it results in, or is likely to result in, significant harm to affected individuals, or if it affects 500 or more individuals, as set out in the PDPC’s regulations.
- Notifying the PDPC. The organization must notify the PDPC as soon as practicable, and no later than 3 calendar days after it assesses that a breach is notifiable.
- Notifying you. If the breach is likely to cause you significant harm, the organization must generally tell you too, so you can take steps such as changing passwords or watching for fraud. There are limited exceptions, for example where law enforcement asks for notification to be delayed.
If you receive a breach notice, follow the steps it gives, change passwords you’ve reused, and be wary of follow-up messages that ask for more details. For how organizations should handle the public side of a breach, see our guide to data breach notification laws.
Not sure where to start?
Get a free audit of your search results and review profiles, with a prioritized fix list.
Get a free auditHow to complain to the PDPC
The PDPC expects you to raise the issue with the organization first, usually through its DPO. Many problems, such as marketing you didn’t agree to or an ignored access request, get fixed at that stage.
- Write to the organization’s DPO. Describe what happened, what you want, and give dates. Keep a copy.
- Give a reasonable time to respond. For an access request, allow the time the law gives the organization.
- Gather your evidence. Screenshots of messages, copies of emails, dates of calls, and the organization’s replies or silence.
- Submit a complaint to the PDPC. Use the complaint or feedback route on the PDPC’s official website. Explain what happened, which organization was involved and what you’ve already tried.
- Respond to follow-up. The PDPC may ask for more information, refer the matter for mediation, or decide whether to investigate.
The PDPC can investigate, give directions to an organization, such as to stop collecting data or to provide access, and impose financial penalties. The 2020 amendments raised the maximum financial penalty, which for larger organizations is now linked to their annual turnover in Singapore. The PDPC publishes enforcement decisions on its website.
For access and correction disputes, you can ask the PDPC to review an organization’s refusal, a fee it charged or a correction it declined. The PDPA also gives individuals who suffer loss or damage directly from certain breaches a right to bring a private civil action in court. That is a legal step, so speak to a lawyer before taking it.
What the PDPA can and can’t do for your reputation
For reputation problems, the PDPA is useful in some cases and limited in others.
- It helps with businesses holding or misusing your data. A company that keeps marketing to you, leaked your data or won’t show you what it holds is squarely within the law.
- It rarely helps with posts by individuals. Someone posting about you personally isn’t acting as an organization. Harassment, doxxing and defamation laws are usually the right tools. Our guide to Singapore defamation law explains that side.
- It doesn’t reach most public or news content. Publicly available data and news activity have exceptions, so a published article generally isn’t removable under the PDPA alone.
- It doesn’t control Google directly. Search engines have their own removal routes for certain personal information, which work regardless of the PDPA.
A worked example
This is an illustrative scenario, not a real client. Wei Ling, a Singapore-based physiotherapist, keeps getting text messages from a property agency she never dealt with. She registered her number on the DNC text message register months ago.
- She writes to the agency’s DPO, using the contact in its privacy notice, asking where it got her number, what else it holds, and asking it to stop.
- The agency replies that it bought a contact list from a third party, and says it has removed her.
- The texts stop for a while, then start again from a different sender name linked to the same agency.
- She files a complaint with the PDPC, attaching screenshots, her DNC registration confirmation and the agency’s earlier reply.
The PDPC decides how to handle it. Wei Ling can’t control the outcome, but she has given the regulator exactly what it needs to act, and she has a written record if the problem continues.
Common mistakes
- Going straight to the PDPC. It will usually expect you to have tried the organization first.
- Expecting a deletion right. The PDPA works through consent withdrawal and retention limits, not a GDPR-style erasure right.
- Using the PDPA against an individual. Personal and domestic activity is outside it.
- Handing over your NRIC number by default. The PDPC’s advisory guidelines say organizations generally shouldn’t collect NRIC numbers or copies unless the law requires it or it’s necessary to verify identity to a high degree. Ask why before you share it.
- Keeping no record. Dates, screenshots and copies of your requests make any complaint far stronger.
When to get help
Most PDPA issues can be handled with a clear letter to a DPO and, if needed, a complaint to the PDPC. It’s worth getting help when the problem is bigger than one organization: your details are spread across people-search and listing sites, harmful search results sit alongside the data issue, or you’re dealing with harassment. Our content removal service handles removal requests and the search side, and we’ll tell you plainly what can and can’t be removed. For legal claims, talk to a Singapore lawyer.
Frequently asked questions
What does PDPA stand for in Singapore?
It stands for the Personal Data Protection Act 2012, Singapore’s main law on how private-sector organizations collect, use and disclose personal data. It is administered by the Personal Data Protection Commission (PDPC).
Does the PDPA give me a right to have my data deleted?
Not in the general way the GDPR does. You can withdraw consent, after which the organization must stop using your data for that purpose unless the law allows otherwise, and organizations shouldn’t keep data once they no longer need it.
How do I register for the Do Not Call Registry?
Use the official DNC service run by the PDPC. You can register your Singapore number free on the voice, text message and fax registers separately or together.
Can the PDPC get me compensation?
The PDPC can investigate, give directions and impose financial penalties, but compensation for loss is a matter for the courts. The PDPA gives individuals who suffer loss or damage directly from certain contraventions a right of private action, so talk to a lawyer about that route.
Does the PDPA apply to government agencies?
Public agencies aren’t subject to the PDPA’s data protection obligations. The public sector has its own data governance rules, and concerns about a government agency are handled through those channels.