The Personal Data Protection Act 2012 (PDPA) governs the collection, use, disclosure, and care of personal data in Singapore. With the significant amendments that took effect in February 2021 — including mandatory data breach notification, enhanced enforcement powers, and increased financial penalties — PDPA compliance has become a serious legal obligation for virtually every Singapore business.
This guide explains what the PDPA requires, how it has evolved, and the practical steps your company should take to achieve and maintain compliance in 2026.
What Is the PDPA and Who Does It Apply To?
The PDPA establishes a baseline framework for the protection of personal data in Singapore. It applies to virtually all private sector organisations that collect, use, or disclose personal data — including companies, partnerships, sole proprietors, and associations. It does not apply to public agencies (government bodies) or to personal data that individuals collect for their own personal or domestic use.
“Personal data” is defined broadly as data about an individual who can be identified from that data, or from that data and other information the organisation has or is likely to have access to. This includes names, NRIC numbers, email addresses, phone numbers, photographs, location data, and more.
The Nine Data Protection Obligations
The PDPA imposes nine main obligations on organisations:
1. Consent Obligation
Organisations must obtain the individual’s consent before collecting, using, or disclosing their personal data, and may only do so for purposes that a reasonable person would consider appropriate in the circumstances. Consent must be informed — individuals should know what they are consenting to. The 2021 amendments introduced “deemed consent by contractual necessity” and “deemed consent by notification,” giving businesses more flexibility while maintaining accountability.
2. Purpose Limitation Obligation
Personal data may only be collected, used, or disclosed for purposes that were notified to the individual and for which consent was obtained (or which fall within a permitted exception). Data cannot be repurposed without fresh consent.
3. Notification Obligation
Before collecting personal data, organisations must notify individuals of the purposes for which the data is being collected. This is typically done through a Privacy Policy or Data Protection Notice.
4. Access and Correction Obligation
Individuals have the right to request access to their personal data held by an organisation and to request corrections. Organisations must respond to access requests within 30 calendar days (or inform the individual of the expected timeline if more time is needed) and must not charge an excessive fee for access.
5. Accuracy Obligation
Organisations must make reasonable effort to ensure that personal data collected is accurate and complete, particularly where it is likely to be used to make a decision that affects the individual, or to be disclosed to another organisation.
6. Protection Obligation
Organisations must protect personal data by implementing reasonable security arrangements to prevent unauthorised access, collection, use, disclosure, copying, modification, disposal, or similar risks. The level of protection should be proportionate to the sensitivity of the data and the harm that a breach could cause.
7. Retention Limitation Obligation
Personal data should not be retained longer than necessary for the purposes for which it was collected. Organisations must establish a data retention schedule and securely dispose of data when it is no longer needed.
8. Transfer Limitation Obligation
When personal data is transferred outside of Singapore, organisations must ensure the receiving jurisdiction provides a standard of protection comparable to the PDPA. This is typically achieved through contractual arrangements (standard contractual clauses) with overseas recipients.
9. Accountability Obligation
Organisations must appoint at least one Data Protection Officer (DPO), develop and implement data protection policies, and make information about these policies publicly available. The DPO need not be a full-time dedicated role — the function can be assigned to an existing employee or an external service provider.
Mandatory Data Breach Notification
One of the most significant changes introduced by the 2021 PDPA amendments is the mandatory data breach notification requirement. Organisations must:
- Notify the Personal Data Protection Commission (PDPC) within three calendar days of assessing that a breach is notifiable (i.e., it is, or is likely to be, of significant scale or causes, or is likely to cause, significant harm to affected individuals)
- Notify affected individuals as soon as practicable if the breach is likely to result in significant harm to them
A breach need not be a hack — it includes any unauthorised access, collection, use, disclosure, copying, modification, or disposal of personal data. This includes accidental disclosures, such as sending an email to the wrong recipient containing personal data.
Organisations that fail to notify the PDPC within the three-day window face enforcement action, including financial penalties.
Financial Penalties Under the PDPA
The 2021 amendments significantly increased the maximum financial penalty that the PDPC can impose:
- For organisations with annual turnover exceeding S$10 million: Up to 10% of the organisation’s annual turnover in Singapore, or S$1 million, whichever is higher
- For organisations with annual turnover of S$10 million or below: Up to S$1 million
In addition, individuals (including directors) can face criminal prosecution for egregious misuse of personal data, such as selling data without consent or misusing data for criminal purposes.
Key PDPA Compliance Steps for Singapore Companies
Step 1: Appoint a Data Protection Officer
Every organisation covered by the PDPA must designate at least one DPO. The DPO is responsible for ensuring compliance with PDPA, handling data protection queries and complaints, and coordinating breach response. Register your DPO with the PDPC via the Bizfile portal.
Step 2: Conduct a Data Inventory and Mapping Exercise
Before you can protect personal data, you need to know what data you hold, where it came from, where it is stored, who has access to it, and how long it is retained. A data inventory (sometimes called a data mapping or Records of Processing Activities) is the foundation of any PDPA compliance programme.
Step 3: Draft and Publish a Privacy Policy
Your organisation must have a Privacy Policy (or Data Protection Notice) that explains to individuals: what personal data is collected, the purposes of collection, how long data is retained, and individuals’ rights. The privacy policy should be easily accessible — typically posted on your website and provided at the point of data collection.
Step 4: Review Consent Mechanisms
Review how your organisation obtains consent. Ensure that consent forms, website checkboxes, and other consent mechanisms are clear, specific, and not pre-ticked. Review whether any data collection relies on deemed consent by notification or contractual necessity, and document the basis.
Step 5: Implement Security Measures
Implement technical and organisational measures to protect personal data:
- Access controls: Limit access to personal data on a need-to-know basis
- Encryption: Encrypt sensitive personal data, both in transit and at rest
- Password policies: Enforce strong passwords and multi-factor authentication
- Vendor management: Ensure third-party processors who handle personal data on your behalf have adequate security measures and are contractually bound to protect the data
Step 6: Establish a Data Breach Response Plan
Given the mandatory breach notification requirements, every organisation should have a documented breach response plan that covers: how to detect and contain a breach, how to assess whether it is notifiable, the steps to notify PDPC within three days, and how to notify affected individuals if required.
Step 7: Train Your Staff
PDPA compliance is not just a policy exercise — it requires your staff to handle personal data appropriately every day. Regular training on data protection obligations, handling of personal data, and breach reporting procedures is essential.
PDPA and Employees: What Singapore Companies Must Know
The PDPA does not apply to employee data in the context of the employment relationship (i.e., the Act excludes personal data collected, used, or disclosed “solely in the context of the individual’s employment relationship”). However, this exclusion is narrower than many employers assume — it does not cover:
- Data collected from prospective employees (job applicants) before an employment offer is made
- Former employees’ personal data in many circumstances
- Employee personal data used for purposes outside the employment relationship
It is therefore prudent for Singapore companies to extend their PDPA compliance practices to employee data handling as well.
How Raffles Corporate Services Can Help
Raffles Corporate Services assists Singapore companies with PDPA compliance, including:
- Registering your Data Protection Officer with the PDPC
- Drafting and reviewing Privacy Policies and Data Protection Notices
- Advising on consent mechanisms and data handling practices
- Supporting data breach response and PDPC notification
- Providing ongoing corporate secretarial support to ensure your governance framework covers data protection obligations
With the PDPC stepping up enforcement activity in 2026, now is the time to ensure your company’s PDPA compliance is in order. Contact us today for a consultation.
