SINGAPORE PDPA · PDPC · AMENDED 2020

Your GDPR programme does not transfer to Singapore’s PDPA.

Same shapes as GDPR, different details - consent, the breach clock, the unconditional DPO and Do Not Call, across eleven obligations.


A compliance professional seated at a desk in a warm, low-lit office, signing a printed document with a pen, further papers and a cup of coffee on the desk beside them and a window throwing daylight across the page.
Personal data, and the record of what you did
11 obligations Deemed consent 3 calendar days Do Not Call Model Framework

Our promise

“A DPO is a name. The inventory is evidence.”

Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.

Each additional system
$3,000
Re-audit, same scope
$8,000
Renewal, every twelve months
$10,500 locked

This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.

Request this audit
The case file

The PDPA, in three chapters

The Act

The Personal Data Protection Act 2012 sets eleven obligations and is administered by the PDPC. It reaches organisations whether or not they are formed here, and the 2020 Amendment added breach notification, consent exceptions and a higher penalty cap.

The Gap

Most teams arrive holding a GDPR programme and assume it transfers. The shapes match and the details do not: consent has doors GDPR has not, the breach clock starts when you decide rather than when you find out, the DPO is unconditional, and Do Not Call fails on its own terms.

The Office

Accountability under this Act is something you show rather than something you assert. We work from the systems inwards so the inventory matches the estate, score every finding against one of the eleven, and rehearse the three-day clock against your own escalation path.

What the Act covers

Personal data, wherever you are.

Data about an identifiable individual - and the Act follows the activity, not where you are incorporated.

Who owes these obligations № 01
  • Any organisation handling personal data in Singapore
  • Overseas services with users in Singapore
  • Data intermediaries, on protection and retention
  • Anyone messaging a Singapore telephone number
PDPA · iDharma · Presented for review
When the obligations bite № 02
  • At collection - the purpose is told, not assumed
  • Expeditiously, once a breach comes to light
  • Three calendar days from determining it counts
  • Before every send, inside the register window
PDPA · iDharma · Presented for review
Whose duty is it

The duty is yours. The processing is theirs.

You

The organisation that decides

You decide what happens to the personal data, so all eleven obligations land on you - consent and notification at the front, protection and retention through the middle, breach notification and accountability at the end. The Act follows the activity, not the place where you are incorporated.

Your intermediary

The people who process for you

Acting on your instructions under a written contract narrows an intermediary to protection and retention. It does not remove the rest, the breach duties still reach them directly, and you remain answerable for the choice of them. Most vendors are both at the same time, for different sets of data.

The catch

The DPO is not conditional here

GDPR made the DPO a test that many teams correctly answered no to. The PDPA does not: at least one, always, with the business contact details made publicly available. It is the one obligation anyone can check from outside without asking you first, and it is checked more than you would think.

What most teams assume

“We follow GDPR, so Singapore is covered.”

What the Act says

The DPO here is a requirement, not a test.

It is the first thing we have to correct.

  • Who it is for
  • SaaS & platforms
  • Regional HQs
  • Fintech & insurance
  • Marketing & adtech
  • Data intermediaries
Why this matters
A black ring binder lying closed on a dark desk under warm light, a blank brass label plate screwed to its spine and a red wax seal holding the page block shut, with a clipped sheet of tabulated figures, reading glasses and a fountain pen laid out beside it.
01 Up to 10% of annual turnover in Singapore, or S$1 million, whichever is higher - the cap the 2020 Amendment Act raised.
02

Offences now reach individuals, not only organisations - unauthorised disclosure, improper use, and re-identification.

03

Directions are the common outcome: stop collecting, destroy the data, remediate. They arrive with a penalty, or instead of one.

04

Prompt notification and cooperation are consistently treated as mitigating. A missing DPO or a missing procedure runs the other way.

The 60-second check

Three questions. Then you’ll know.

No email. No signup. A starting point, not a determination.

0 of 3

Singapore personal data -

The activity, not the incorporation. Collecting, using or disclosing brings the obligations with it. Customers, employees, applicants and users of an overseas service all count.

Your capacity -

Most vendors are both. An organisation for its own data, an intermediary for a customer’s - and the two roles carry different obligations over the same systems.

DPO and policies -

This is the one checked from outside. The DPO obligation is unconditional under the PDPA, and the business contact details have to be publicly available - so anyone can test it without asking you.

The calendar

Four clocks, and one of them has no number.

Each of these runs from an event you do not choose - so they cannot be added up, and they cannot be run in parallel.

  1. Assess

    Expeditiously

    The one step with no number on it, and the one that eats the clock. What is recorded is that a procedure existed.

  2. Notify the PDPC

    3 calendar days

    Calendar days, not working days - running from when you determine it is notifiable, not when you found out.

  3. Tell the individuals

    Without delay

    As soon as practicable, where the harm is significant. Where you decide not to, the reasoning is the record.

  4. Check the registers

    Every 30 days

    A Do Not Call result has a shelf life. Three registers, checked separately, and a stale check counts as none.

The trap

Teams schedule the notification and forget the step in front of it. The three days run from the day you determine it is notifiable - so the assessment window carries no number at all, and it is where most of the time actually goes.

Requirement & coverage

What the Act says, what we ship

The PDPC’s 11, and the one that fails separately - 12 rows, each with the artefact that discharges it.

Consent Or an exception
Every collection point checked against what the individual is actually shown, and against the exception you rely on where consent is not the basis - including deemed consent, legitimate interests and business improvement.
Purpose limitation A reasonable person
Purposes fixed per data set before collection, with a compatibility test for any new use rather than a quiet expansion into one.
Notification At or before collection
What you tell people, in plain language, at the point it is collected - and updated when the purpose moves rather than when the notice is next reviewed.
Access and correction A findable route
A request route a member of the public can find without help, a proportionate identity check, and a response record that shows the clock was met.
Accuracy Proportionate to use
A higher bar where the data drives a decision about the individual, with the source and the currency of each record written down.
Protection Reasonable security
The arrangements you actually run, tested rather than attested, including the processors and vendors holding the data on your behalf.
Retention limitation Cease, do not keep
A schedule with named owners, a disposal step someone performs, and backups and archives inside the scope rather than beside it.
Transfer limitation A comparable standard
Where the data physically lands, the contractual protection covering it, an assessment of the receiving jurisdiction, and whether all three match your own notice.
Breach notification Three calendar days
A written assessment procedure against the significant-harm and significant-scale thresholds, the notification pack, and a rehearsal against the clock.
Accountability DPO, policies, proof
A DPO appointed and publicly findable, policies communicated to staff with training records, and a complaint route tested from the outside in.
Data portability Check in-force status
Enacted by the 2020 Amendment Act. Confirm the in-force position before relying on it either way - and design for it regardless, because the engineering is the long pole.
Do Not Call Fails separately
Register checking built into the send path, the validity window respected, and any ongoing-relationship or business-to-business exemption evidenced rather than assumed.
The engagement

Personal data, independently reviewed

From the CRM to the marketing send path.

  1. Intake

    What personal data you hold, where it came from and where it goes.

  2. Test

    All eleven obligations against the estate, plus the register checks.

  3. Sign off and evidence

    You see the draft first. Then the inventory, policies and drills - dated.

Request a PDPA review
An auditor in a black trouser suit over a black top, with a dark bob, standing against a warm pale wall and pointing into the open space alongside.
The record is the evidence - that is what you are buying.
Struck in your favour

Why teams choose iDharma for their PDPA review

Scored by obligation

Every finding lands on one of the eleven, so the report reads in the PDPC’s own structure.

The clock, rehearsed

The three-day notification drilled against your own escalation path, not a generic template.

Do Not Call included

Register checks and exemption claims reviewed in the same scope, because they fail separately.

Model Framework mapped

Findings tagged to the Model AI Governance Framework where you want to evidence alignment.

Four marks, struck on every report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

PDPA review report

The full review: what you hold, on what footing, under which obligation - and where each one is discharged or is not. Findings land on the PDPC’s own eleven so the report reads in the structure a regulator uses, with the Do Not Call position and the Model Framework alignment stated separately rather than folded in.

Workbook

Personal data inventory

What you hold, where it came from, which purpose it serves, who it is disclosed to and where it goes overseas - built from the systems inwards.

Register

Consent and exception log

What was shown at the moment of collection, withdrawal honoured downstream, and the assessment recorded where an exception is used.

Runbook

Breach procedure and drill

The assessment procedure against both thresholds, the notification pack for the PDPC and for individuals, and one rehearsal against the clock.

Templates

Access and correction pack

A request route a member of the public can find, a proportionate identity check, and a response record showing the clock was actually met.

Assessment

Transfer and DNC review

Where data actually lands and under what protection, plus register checking built into the send path and every exemption claim evidenced.

Documents

Policy template pack

The core PDPA set, the incident and breach set, and the AI governance set - tailored to your estate rather than handed over as a generic pack.

Format & fee

Real numbers, upfront.

Scope
Set by the Act
Inputs
Your systems and your registers
Re-review
Every twelve months - $10,500 against your known baseline

The Act fixed the obligations, so the fee is flat - nothing to meter, and nothing charged until you approve it.

Request this review
PDPA · Named engagement $12,500 flat
  • Findings on the PDPC’s eleven
  • Breach drill against the clock
  • Do Not Call register checks
  • 29 policy templates, tailored
Show your hand

Four things you have to be able to produce

The PDPA is not graded on intent. Each of these is either in your hand on the day someone asks, or it is not.

The officer,
findable

At least one DPO, with business contact details a member of the public can reach without asking. Unconditional here, and the one obligation checked from outside.

The inventory,
current

What you hold, why, who it goes to and where it lands overseas. Almost every other obligation is answered out of this one document, so it is built first.

The drill,
dated

A breach assessment written before the incident, not during it. The three days run from your determination, so the undated window is where the deadline goes.

The register,
checked

A Do Not Call result inside its validity window on the day the message goes out, against the right one of the three registers. And it fails separately from the rest.

Four cards, and the date on each one is part of the card.

FAQ

Plain answers

Scope, the officer, the breach clock and the AI frameworks. Answered straight.

Request this review
Does the PDPA apply to us if we are not in Singapore?

Very likely, if you collect, use or disclose the personal data of people in Singapore. The Act is written around the activity rather than around where the organisation is incorporated, and overseas services with Singapore users are routinely in scope.

Do we need to appoint a Data Protection Officer?

Yes - at least one, and their business contact information has to be made publicly available. It can be an existing employee and it can be a shared role; what it cannot be is unnamed or unfindable from the outside.

When do we have to report a data breach?

When it results in, or is likely to result in, significant harm to affected individuals, or is of significant scale. The assessment must be conducted expeditiously, and once you determine it is notifiable the PDPC must be told within three calendar days.

Is Singapore’s Model AI Governance Framework mandatory?

No. It is voluntary guidance from IMDA and the PDPC, and so is AI Verify. Neither replaces the PDPA - if your AI touches personal data, the eleven obligations apply in full regardless of how well you align to the Model Framework.

What does an iDharma PDPA review cost, and what do we get?

A flat fee for the named engagement, agreed before anything is charged. What lands is the review report, the personal data inventory, the consent and exception log, the breach procedure and drill, the access and correction pack, the transfer and DNC review, and the policy template pack.

Get started

Request your PDPA review

Tell us where personal data lives and we come back with a scoping call in a day.

What we need from you

Nothing you do not already have. Most of this comes out of a morning with your engineering and people teams, and we name exactly which extracts before you commit.

  1. Which systems hold personal data, and what for
  2. Whether any of the people are in Singapore
  3. Whether you are an organisation, an intermediary or both
  4. Your DPO appointment, and where it is published
  5. How marketing sends are checked against the registers

What happens next

  1. You send the five items we need.
  2. We call to scope it within one business day.
  3. Nothing is charged until you approve the scope.
Request a PDPA review
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • Personal Data Protection Act 2012, and PDPC guidance
  • AI Verify Foundation, on the testing framework
Enacted
2012
Amended
2020

What it means

  • General information about what the Act requires — not legal advice, and no professional relationship.
  • Where a scope question is genuinely arguable, our reports say so rather than pick the convenient answer.

Scope & limitation

  • This reading has not been checked line by line against the Act — the penalty cap and AI Verify’s status are the two worth confirming at source.
  • Do not rest a binding decision on it; engage qualified counsel, and use it as the start of a scoping conversation rather than as your final word.

Something on this page out of date?

Tell us