Privacy & Data Protection · Singapore
Personal Data Protection Act
Singapore's data protection law, balancing individual rights with the country's data-driven economy. It's enforced by the PDPC, which also promotes data protection certification and guidance for businesses.
REGULATORPersonal Data Protection Commission (PDPC)
REGIONSingapore
EFFECTIVE2012, substantially amended 2021
Who it applies to
- Organisations collecting, using or disclosing personal data in Singapore
- Both private-sector organisations and, for certain provisions, public agencies
- Organisations processing data for commercial purposes
Key requirements
- Consent or a permitted exception before collecting personal data
- A Data Protection Officer designated and contactable
- Mandatory breach notification to the PDPC for notifiable breaches
- Reasonable security arrangements proportionate to risk
- Data Protection Impact Assessments encouraged for higher-risk processing
Maximum penaltyFinancial penalties up to 10% of annual turnover in Singapore, or S$1 million, whichever is higher
Go to the source
Official resources
Praeferre's summary is a starting point, not legal advice. For the authoritative text and current guidance, go directly to the governing body.
Start your compliance journey
See how Praeferre automates PDPA compliance
Continuous monitoring, evidence and reporting for PDPA — alongside every other framework you need to satisfy.