Introduction
Data protection is a core compliance area for companies operating in Singapore. This article, Data Protection Obligations for Singapore Companies: PDPA Basics and Registers, explains the practical obligations under the Personal Data Protection Act (PDPA) and the records and registers that help demonstrate compliance.
Understanding PDPA basics and maintaining suitable registers supports regulatory compliance, builds customer trust and helps companies respond quickly to access requests or data breaches. The guidance below is general in nature and intended to help corporate secretaries, directors and officers understand what companies need to consider.
Who this applies to
The PDPA applies to organisations that collect, use or disclose personal data in Singapore. This includes:
- Private companies incorporated in Singapore (local and foreign-owned).
- Sole proprietorships and partnerships operating in Singapore.
- Organisations that process personal data of individuals in Singapore, including employees, customers and suppliers.
Companies that process employee personal data should also consider obligations under the Employment Act, CPF rules and other employment-related legislation when applying PDPA principles.
Key rules and requirements in Singapore
Under the PDPA and PDPC guidance, organisations must comply with several core obligations. Key obligations include:
- Consent obligation — Obtain valid consent for the collection, use and disclosure of personal data, unless an exception applies.
- Purpose limitation — Collect, use or disclose personal data only for purposes that a reasonable person would consider appropriate and that the individual has been informed of.
- Notification obligation — Notify individuals of the purpose(s) for which their personal data is collected, used or disclosed.
- Access and correction — Provide individuals with access to their personal data and allow correction where necessary.
- Protection obligation — Make reasonable security arrangements to protect personal data in your possession or under your control.
- Retention limitation — Not retain personal data longer than necessary for business or legal purposes.
- Transfer limitation — Ensure that personal data transferred overseas receives a standard of protection comparable to the PDPA.
- Accountability — Be able to demonstrate compliance, which typically requires documented policies, appointed personnel and appropriate records.
PDPC guidance also sets out when organisations must notify the PDPC and affected individuals of a data breach — notably where the breach results, or is likely to result, in significant harm to affected individuals or is of a significant scale. Organisations should consult the PDPC’s Data Breach Notification Guide for thresholds and the process.
Step-by-step process
Follow these steps to implement a practical PDPA compliance programme and maintain useful registers.
- 1. Appoint responsibilities
- Designate a person or team to oversee data protection (a Data Protection Officer is recommended though not mandatory).
- 2. Map personal data
- Conduct a data inventory to identify categories of personal data collected, purposes, storage locations and data flows (including overseas transfers).
- 3. Document policies and procedures
- Publish a privacy policy, internal handling procedures, access and correction processes, and a data breach response plan.
- 4. Maintain recommended registers
- Personal Data Inventory/Register — records categories, sources, purposes and retention periods.
- Consent Register — records consent obtained (what, when and how) and withdrawal of consent.
- Access and Correction Register — logs requests, dates and actions taken.
- Data Disclosure Register — tracks disclosures to third parties and contractual safeguards.
- Data Breach Register — documents incidents, assessments, notifications and remedial actions.
- Retention/Destruction Register — records data deletion or anonymisation actions.
- 5. Implement technical and organisational measures
- Apply access controls, encryption, secure backups and staff training. Align measures with the sensitivity of data processed.
- 6. Review contracts and third-party arrangements
- Ensure data protection clauses in vendor agreements, including cross-border transfer safeguards and audit rights.
- 7. Test and review
- Regularly audit records and processes, run tabletop exercises for data breaches and update registers as circumstances change.
Common mistakes to avoid
- Failing to keep a centralised data inventory — fragmented records make it difficult to respond to access requests and breaches.
- Relying on implied consent where explicit consent is required, or failing to record consent adequately in a consent register.
- Not updating retention schedules — keeping personal data longer than necessary increases risk and may breach the retention limitation obligation.
- Weak vendor oversight — inadequate contracts or failure to verify a vendor’s security measures.
- Poor incident documentation — failing to maintain a data breach register can complicate PDPC notifications and remediation.
- Assuming employment-related data is exempt — employee personal data remains subject to PDPA in most circumstances and must be handled appropriately alongside CPF and payroll obligations.
Practical examples
Example 1 — Customer consent and marketing:
- A retail company collects email addresses at point of sale. The company should record the consent type (marketing or transactional), maintain a consent register and honour opt-outs promptly.
Example 2 — Employee records and retention:
- An employer stores employee health information for leave management. The company should limit access, define retention periods consistent with employment law and log any disclosures to third-party insurers.
Example 3 — Vendor disclosures and overseas transfers:
- A tech company uses a cloud provider overseas. Before transferring personal data, the company should document transfer safeguards, update the data disclosure register and ensure contractual protections are in place.
How a corporate secretary can help
A corporate secretary in Singapore plays a practical role in governance and compliance. They can:
- Advise on documentation and board reporting related to PDPA compliance.
- Help establish and maintain registers, meeting minutes and policies demonstrating accountability.
- Coordinate with HR, IT and third-party vendors to align data-handling processes with corporate records and retention schedules.
- Assist with administrative aspects of PDPC notifications and regulatory correspondence where appropriate.
Raffles Corporate Services can support companies with secretarial filings, compliance checks and practical administration. We also provide accounting, tax and payroll support that helps ensure personal data related to employees and contractors is managed correctly across systems involving CPF contributions and payroll deductions.
Frequently Asked Questions
Do all companies need to appoint a Data Protection Officer (DPO)?
The PDPA does not mandate a DPO for all organisations, but appointing a responsible person or team is best practice to coordinate compliance activities, maintain registers and liaise with the PDPC where needed.
What records should be kept for a data breach?
Maintain a data breach register that documents the nature of the breach, affected data, assessment of harm, remedial actions, notifications made (to PDPC and affected individuals) and lessons learned.
How long should personal data be retained?
Retention depends on the purpose and any legal or contractual obligations. Businesses should document retention periods in a retention register and securely destroy or anonymise data once the retention period expires.
How does PDPA interact with employment data and CPF filings?
Employment data remains subject to PDPA. Employers should limit access, use data only for employment-related purposes and ensure payroll and CPF processes (including submissions to CPF and IRAS) are secured and documented.
Key takeaways
- PDPA compliance requires documented policies, practical controls and the ability to demonstrate accountability.
- Maintaining registers — such as a personal data inventory, consent register and data breach register — helps organisations respond to requests and incidents.
- Regular reviews, staff training and vendor oversight reduce risk and support compliance with PDPC expectations.
- Corporate secretaries can help coordinate governance, maintain records and support regulatory communication.
- For operational support, Raffles Corporate Services can assist with compliance, secretarial filings, accounting, tax and payroll administration.
If you would like to find out more about how Raffles Corporate Services can assist with your company’s compliance and corporate secretarial requirements, please get in touch with the team at [email protected].
Yours sincerely,
The editorial team at Raffles Corporate Services
Requirements may change, so always check the latest guidance from ACRA, IRAS or MOM, or consult a professional adviser.
Disclaimer: This does not constitute legal advice. If you require legal advice, please contact a lawyer.
