Praeferre/Frameworks/PDPA
Privacy & Data Protection · Singapore

Personal Data Protection Act

Singapore's data protection law, balancing individual rights with the country's data-driven economy. It's enforced by the PDPC, which also promotes data protection certification and guidance for businesses.

REGULATORPersonal Data Protection Commission (PDPC) REGIONSingapore EFFECTIVE2012, substantially amended 2021

Who it applies to

  • Organisations collecting, using or disclosing personal data in Singapore
  • Both private-sector organisations and, for certain provisions, public agencies
  • Organisations processing data for commercial purposes

Key requirements

  • Consent or a permitted exception before collecting personal data
  • A Data Protection Officer designated and contactable
  • Mandatory breach notification to the PDPC for notifiable breaches
  • Reasonable security arrangements proportionate to risk
  • Data Protection Impact Assessments encouraged for higher-risk processing

Maximum penaltyFinancial penalties up to 10% of annual turnover in Singapore, or S$1 million, whichever is higher

Go to the source

Official resources

Praeferre's summary is a starting point, not legal advice. For the authoritative text and current guidance, go directly to the governing body.

Start your compliance journey

See how Praeferre automates PDPA compliance

Continuous monitoring, evidence and reporting for PDPA — alongside every other framework you need to satisfy.