PERSONAL DATA PROTECTION ACT 2012 · PDPC · AMENDED 2020

Singapore PDPA compliance, made checkable.

Eleven obligations, a breach clock that starts when you decide, and a Do Not Call regime that fails separately from all of it. This page is what the Act asks for, and what the proof looks like.


A black ring binder on a dark desk under warm light, labelled audit report and marked confidential Illustrative materials
Personal data, and the record of what you did with it
PDPC 11 obligations 3 calendar days DNC Registry Model AI Framework
The statute

What the PDPA actually asks of you

Broader than “companies registered in Singapore”. The Act follows the data and the activity, not the incorporation certificate.

It follows the activity, not the address

The Personal Data Protection Act 2012, administered by the PDPC — the Personal Data Protection Commission, part of IMDA. Data protection provisions in force from July 2014; Do Not Call from January 2014. It reaches organisations regardless of whether they are formed or resident in Singapore.

Eleven obligations, and one is being able to show the other ten

Consent, purpose limitation, notification, access and correction, accuracy, protection, retention limitation, transfer limitation, breach notification, accountability and data portability. Accountability is the one that turns the rest into documents — policies, practices, a DPO, and the ability to demonstrate all three.

A DPO is not optional here

At least one Data Protection Officer, with business contact details made publicly available. It can be an existing employee and it can be a shared role. What it cannot be is unnamed, or unfindable from the outside.

Who this lands on

Five situations, ordered by how often the reader gets them wrong. The last two are the ones that catch people.

  • Any organisation handling personal data in Singapore The Act reaches organisations regardless of whether they are formed or resident in Singapore, if they collect, use or disclose personal data there.
  • Overseas organisations serving Singapore users Extraterritorial in practice: a service used by people in Singapore brings the data protection obligations with it.
  • Data intermediaries Processing on another organisation's behalf under contract narrows your obligations to protection and retention — it does not remove them.
  • Anyone sending marketing messages The Do Not Call provisions bind whoever sends a specified message to a Singapore telephone number, and they sit separately from the data protection obligations.
  • Organisations deploying AI on personal data The PDPA applies unchanged. The Model AI Governance Framework and AI Verify sit alongside it as voluntary guidance, not as a substitute.
11 Data protection obligations The PDPC’s own framing of the Act
3 calendar days To notify the PDPC From determining a breach is notifiable — not from the breach
1 DPO Minimum, publicly contactable Required of every organisation, not conditional
The 2020 Amendment Act

If you last looked at this before 2020

Four changes, and each one is something you would not have built a process for.

Breach notification became mandatory

Assess expeditiously. Notify the PDPC within three calendar days of determining a breach is notifiable. Tell affected individuals as soon as practicable where the harm is significant.

New exceptions to consent

Legitimate interests, and business improvement. Consent stopped being the only door — which means “we got consent” is now sometimes the wrong answer rather than the safe one.

Offences for egregious mishandling

Unauthorised disclosure, improper use, and unauthorised re-identification of anonymised data — reaching individuals, not only organisations.

A higher penalty cap, and data portability

The financial penalty cap rose materially, and data portability was enacted. Both sit on this page’s verification queue rather than being asserted as settled.

Two of these are on this page’s verification queue. The penalty figures and the criminal-offence provisions are the least certain numbers here, and the in-force position of data portability is an open question rather than a settled one. Where this page is not sure, it says so instead of rounding to confident.

The obligations

11 data protection obligations

The PDPC’s own framing of what the Act requires. Grouped by when they bite: before the data arrives, while you hold it, and when something happens.

Getting it lawfully

Before the data arrives

Consent

Collected, used or disclosed with consent, or under an exception

  • Consent that is informed and freely given
  • Deemed consent by conduct or by contractual necessity
  • Legitimate interests and business improvement exceptions
  • A working route to withdraw consent

Purpose limitation

Only for purposes a reasonable person would consider appropriate

  • Purposes fixed before collection
  • No quiet expansion into new uses
  • Secondary use assessed, not assumed

Notification

Tell people the purpose before or at the time of collection

  • Stated in plain language
  • Given at the point of collection
  • Updated when the purpose changes

Holding it properly

While you have it

Access and correction

People can ask what you hold and have it corrected

  • A request route that a member of the public can find
  • Response within a reasonable time
  • Corrections passed on to third parties where required

Accuracy

Reasonable effort to keep data accurate and complete

  • Proportionate to how the data will be used
  • Higher bar where a decision affects the individual
  • Source and currency recorded

Protection

Reasonable security arrangements

  • Access control and encryption where appropriate
  • Vendor and processor controls
  • Testing rather than assertion

Retention limitation

Cease retention when the purpose is served

  • A retention schedule with owners
  • Disposal that is actually carried out
  • Backups and archives included in scope

Transfer limitation

Overseas transfers to a comparable standard of protection

  • Contractual protection for the receiving party
  • Assessment of the receiving jurisdiction
  • Records of where data actually goes

Answering for it

When something happens, or somebody asks

Data breach notification

Notify the PDPC, and individuals where harm is significant

  • Assessment conducted expeditiously
  • PDPC notified within three calendar days of determining it is notifiable
  • Affected individuals told as soon as practicable where significant harm

Accountability

Policies, practices, a DPO, and the ability to show all three

  • At least one Data Protection Officer appointed
  • Business contact details made public
  • Policies communicated to staff
  • A complaint route that works

Data portability

Check in-force position

Transmit data to another organisation on request

  • Enacted by the 2020 Amendment Act
  • Confirm the in-force position before relying on it either way
  • Worth designing for regardless — the engineering is the long pole

Data portability is marked, and the mark is deliberate. It was enacted by the 2020 Amendment Act; whether it is in force is the thing to confirm before you rely on it either way. Rendering it exactly like the other ten would imply a certainty this page does not have. It is worth designing for regardless — the engineering is the long pole, not the drafting.

Notification

The three days start when you decide

Which is why the assessment is the real deadline. The clock to the PDPC runs from the moment you determine a breach is notifiable — so nearly all of the pressure sits in the window before that.

  1. Assess

    Conducted expeditiously — and this step carries no fixed number, which is the trap.

    You must be able to show That the procedure existed before the incident, and when the assessment started.

  2. Is it notifiable?

    Likely to result in significant harm to affected individuals — or of significant scale.

    You must be able to show The reasoning, either way. A “not notifiable” call is a decision you have to be able to defend later.

  3. Tell the PDPC

    Within three calendar days of determining it is notifiable.

    You must be able to show The determination date, and what was sent.

  4. Tell the individuals

    As soon as practicable, where the harm is significant.

    You must be able to show Who was told, when and how — and why not, where you did not.

The branch most people miss. Significant scale takes you to the PDPC. Significant harm is what takes you to the individuals. They are not the same test and they do not always fire together — a large breach of low-sensitivity data and a small breach of highly sensitive data go to different places.

This is the shape of the decision, not the decision. It computes nothing, stores nothing and sends nothing. The thresholds are exactly where judgement lives, and this page is guidance on how we scope a readiness review — not legal advice, and not something to run a live incident from. If you are in one now, call your counsel, not a web page.

Marketing

The Do Not Call Registry

A separate regime under the same Act, with its own contraventions. Four things that catch organisations out.

Three registers, checked separately

No Voice Call, No Text Message and No Fax Message are distinct. A check against one is not a check against another.

A check has a shelf life

Register results are valid for a limited window — thirty days at the time of writing. A stale check is the same as no check.

Exemptions are conditional

Ongoing-relationship and business-to-business exemptions exist and are narrower than most marketing teams assume. Claim one, and you have to be able to evidence it.

It fails separately from the rest

DNC breaches are their own contravention. A flawless data protection programme does not protect you from one, which is why this sits in the same engagement.

Alongside the Act

Singapore’s AI governance framework

Voluntary guidance for responsible AI deployment. Neither of these replaces the PDPA — if your AI touches personal data, the eleven obligations apply in full regardless of how well you align to either.

Guidance

Model AI Governance Framework

IMDA and the PDPC's framework for deploying AI responsibly — internal governance, human involvement in decision-making, operations management, and stakeholder communication. A generative-AI edition followed. Voluntary, and widely used as the structure Singapore regulators recognise.

  • Internal governance
  • Human involvement
  • Operations management
  • Stakeholder communication
Testing

AI Verify

An AI governance testing framework and software toolkit, developed by IMDA and now stewarded by the AI Verify Foundation. It does not certify a system; it produces a standardised report of technical tests and process checks against the Model Framework's principles.

  • Technical tests
  • Process checks
  • Standardised report
  • Not a certification
Translation

A GDPR programme does not transfer unchanged

The shape is familiar — consent, purpose, access, retention, transfer, breach. These four are where the familiarity costs you.

The lawful route
Under GDPR

A basis from the Article 6 list.

Under the PDPA

Consent — including deemed consent by conduct or by contractual necessity — or an exception, now including legitimate interests and business improvement.

The breach clock
Under GDPR

72 hours from awareness.

Under the PDPA

Assess expeditiously, then three calendar days from determining it is notifiable — on significant harm or significant scale.

The DPO
Under GDPR

Article 37, conditional. Plenty of teams correctly concluded they did not need one.

Under the PDPA

At least one, always — with business contact details made publicly available.

Marketing
Under GDPR

No analogue inside the same statute.

Under the PDPA

The Do Not Call regime — a separate contravention under the same Act.

A clean GDPR programme is a strong head start on eight of the eleven. It is not a head start on these four — and the DPO row is the one that surprises people most, because it is the one where GDPR let them off.

Penalties and enforcement

Three routes, and they are not alternatives — a single incident can attract a financial penalty, a direction, and in the worst cases a prosecution of the individuals involved.

10% or S$1m
Financial penalty

Up to 10% of annual turnover in Singapore, or S$1 million, whichever is higher — the higher cap introduced by the 2020 Amendment Act.

Criminal
Egregious mishandling

The 2020 Amendment created offences for unauthorised disclosure, improper use and unauthorised re-identification of anonymised data, reaching individuals as well as organisations.

Directions
Enforcement posture

The PDPC can direct an organisation to stop collecting, to destroy data, or to remediate. Directions and undertakings are common outcomes alongside — or instead of — a penalty.

What drives an outcome worse

  • Failure to appoint or publicise a DPO
  • No breach assessment procedure when one was needed
  • Security arrangements that were never tested
  • Repeat findings from an earlier case
  • Retention long past the purpose being served

What consistently helps

  • Prompt voluntary notification and cooperation
  • Remediation already underway before contact
  • A genuine programme with records behind it
  • Undertakings accepted and delivered
  • Harm contained and individuals told quickly
How we help

How iDharma supports PDPA compliance

Structured around the obligations themselves, so the report reads in the PDPC’s own vocabulary rather than in ours — and all eleven are in scope, not a selection.

Obligation areaWhat the assessment does
Consent and notificationEvery collection point reviewed against what is actually said to the individual, and against the exception you are relying on if consent is not the basis.
Purpose and retentionPurposes mapped per data set, with a retention schedule that names owners and a disposal step someone actually performs.
ProtectionSecurity arrangements tested rather than attested, including the processors and vendors that hold the data on your behalf.
Transfer limitationWhere the data physically goes, under what contractual protection, and whether that matches what your notice says.
Breach notificationThe assessment procedure, the three-day clock, and a rehearsal — most of the window is spent deciding whether it is notifiable.
AccountabilityDPO appointment and visibility, policies, training records, and the complaint route from the outside in.
Do Not CallRegister checking, the thirty-day validity window, and whether your exemption claims survive inspection.
AI on personal dataPDPA obligations read against the model as deployed, and mapped to the Model AI Governance Framework where you want to show alignment.

Personal data inventory and mapping

What personal data you hold, where it came from, which purpose it serves, who it is disclosed to and where it goes overseas. Almost every other obligation is answered from this one document.

Addresses: Purpose limitation, Transfer limitation

Consent management and exception records

Consent captured with what was shown at the time, withdrawal honoured downstream, and where you rely on legitimate interests or business improvement, the assessment recorded rather than assumed.

Addresses: Consent obligation, Notification obligation

Breach assessment and notification drill

A written assessment procedure against the significant-harm and significant-scale thresholds, and a rehearsal against the clock — because the expensive part is deciding, not reporting.

Addresses: Breach notification, Protection obligation

Access and correction workflow

A request route a member of the public can find without help, an identity check that is proportionate, and a response record that shows the clock was met.

Addresses: Access and correction, Accuracy obligation

Retention schedule and disposal evidence

Ceasing retention is an action, not a policy. Schedules with owners, disposal that reaches backups and archives, and evidence that it happened.

Addresses: Retention limitation, Protection obligation

Cross-border transfer assessment

Where data actually lands, the contractual protection covering it, and whether the receiving jurisdiction gives a comparable standard — checked against your own notice.

Addresses: Transfer limitation, Accountability obligation

Every activity is recorded with a timestamp, a named owner and the method used. Under a regime where self-reporting and demonstrable programmes are consistently treated as mitigating, that trail is worth more than the documents on their own.

Built for Singapore PDPA from the ground up

Obligation-level scoring

Every finding lands on one of the eleven obligations, so the report reads in the PDPC's own structure.

Three-day notification drill

The breach clock rehearsed against your own escalation path, not against a generic template.

DNC Registry included

Register checking and exemption claims reviewed in the same engagement, because they fail separately from the data obligations.

Model Framework mapping

Findings tagged to the Model AI Governance Framework where you want to evidence alignment alongside the statute.

Getting there

24-week implementation roadmap

A practical path to PDPA compliance with clear milestones. The weeks are elapsed position, not effort — the phases overlap in practice.

  1. Phase 1 Weeks 1–6

    Foundation and gap analysis

    Find out what you actually hold

    • Appoint or confirm the DPO and publish contact details
    • Build the personal data inventory
    • Map collection points and stated purposes
    • Gap-assess against all eleven obligations
  2. Phase 2 Weeks 7–12

    Policy and governance

    Write down what you will actually do

    • Data protection policy and internal practices
    • Consent and notification wording revised
    • Retention schedule with owners
    • Transfer assessments and contract terms
  3. Phase 3 Weeks 13–18

    Operational implementation

    Make the obligations something people do

    • Access and correction request workflow
    • Breach assessment procedure and escalation
    • DNC register checking built into the send path
    • Staff training with attendance recorded
  4. Phase 4 Weeks 19–24

    Monitoring and continuous compliance

    Evidence that it keeps working

    • Breach notification drill against the clock
    • Vendor and processor review cycle
    • Internal audit of the obligations
    • Review cadence fixed and owned
Policy templates

PDPA-compliant policy repository

29 ready-to-use templates covering the eleven obligations, breach handling, the Do Not Call regime and AI on personal data.

Core PDPA policies

  • Data Protection Policy
  • Consent & Notification Standard
  • DPO Appointment & Terms
  • Access & Correction Procedure
  • Retention Schedule
  • Complaint Handling Procedure

+ 4 more policies

Incident & breach

  • Breach Assessment Procedure
  • PDPC Notification Template
  • Individual Notification Template
  • Incident Register
  • Post-Incident Review
  • Escalation Matrix

+ 3 more policies

AI governance

  • AI Use of Personal Data Standard
  • Model Framework Alignment Record
  • Human Involvement Design Note
  • Transfer Impact Assessment
  • Vendor & Processor Terms
  • DNC Checking Procedure

+ 4 more policies

Questions

Frequently asked questions

What comes up in every PDPA scoping call. Filter to the one you came for.

1 Scope and application
Does PDPA apply to my organisation if we are not in Singapore?

Very likely, if you collect, use or disclose the personal data of people in Singapore. The Act is written around the activity rather than around where the organisation is incorporated, and overseas services with Singapore users are routinely in scope.

What are the key changes in the 2020 Amendment Act?

Mandatory data breach notification, new exceptions to consent including legitimate interests and business improvement, offences for egregious mishandling of personal data, provisions on data portability, and a substantially higher financial penalty cap.

Do we need to appoint a Data Protection Officer?

Yes — at least one, and their business contact information has to be made publicly available. It can be an existing employee and it can be a shared role; what it cannot be is unnamed or unfindable from the outside.

What is the difference between an organisation and a data intermediary?

A data intermediary processes personal data on another organisation's behalf under a written contract. That narrows its own obligations to protection and retention, but the organisation instructing it remains answerable for the rest — and for choosing it.

2 Breaches and requests
When do we have to report a data breach?

When the breach results in, or is likely to result in, significant harm to affected individuals, or is of significant scale. The assessment has to be conducted expeditiously, and once you determine it is notifiable the PDPC must be told within three calendar days. Affected individuals are told as soon as practicable where the harm is significant.

How long do we have to respond to an access request?

Within a reasonable time, with the PDPC's guidance setting an expectation measured in weeks rather than months, and an obligation to tell the individual if you cannot meet it. The practical constraint is almost always locating the data, which is a reason to keep the inventory current.

Can we refuse an access or correction request?

In defined circumstances, yes — and the exceptions are narrower than they look. Refusing is a decision you have to be able to explain later, so it is worth recording the reasoning at the time rather than reconstructing it.

What happens if we self-report a breach?

Prompt notification and cooperation are consistently treated as mitigating. The pattern in published decisions is that organisations which found the problem, told the PDPC and had remediation underway fare materially better than those which did not.

3 AI, marketing and the frameworks
Is Singapore's Model AI Governance Framework mandatory?

No. It is voluntary guidance from IMDA and the PDPC, and so is AI Verify. Neither replaces the PDPA — if your AI touches personal data, the eleven obligations apply in full regardless of how well you align to the Model Framework.

What is AI Verify?

A testing framework and software toolkit that runs technical tests and process checks against the Model Framework's principles and produces a standardised report. It is not a certification and it does not assert that a system is fair or safe — it documents what was tested and what came out.

How do I handle the Do Not Call Registry?

Check the relevant register before sending a specified message to a Singapore number, keep the result inside its validity window, and treat the three registers as separate. Ongoing-relationship and business-to-business exemptions exist, are narrow, and have to be evidenced if relied on.

How does this compare to GDPR?

The shape is familiar — consent, purpose, access, retention, transfer, breach — but the details differ enough that a GDPR programme does not transfer unchanged. Consent exceptions, the notification thresholds and the DNC regime are the three places teams most often assume equivalence and are wrong.

How long does a PDPA readiness review take?

Typically four to eight weeks depending on how much of the personal data inventory already exists. Where it does not, building it is the work — everything else is derived from it. Scope is agreed with you before anything is charged.

Further reading

Read it at source

This page is a working summary. Where a decision turns on the wording, the Act and the PDPC’s guidance are public and free.

Get started

Ready to make PDPA provable?

Inventory first, then the eleven obligations, then the breach drill and the DNC path. Scoped with you before you are charged.

This page is guidance on how we scope a PDPA readiness review, not legal advice. Singapore counsel should confirm anything you intend to rely on.

From Insights

Before you commission one