The Personal Data Protection Act 2012 sets eleven obligations and is administered by the PDPC. It reaches organisations whether or not they are formed here, and the 2020 Amendment added breach notification, consent exceptions and a higher penalty cap.
Your GDPR programme does not transfer to Singapore’s PDPA.
Same shapes as GDPR, different details - consent, the breach clock, the unconditional DPO and Do Not Call, across eleven obligations.
Our promise
“A DPO is a name. The inventory is evidence.”
Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.
- Each additional system
- $3,000
- Re-audit, same scope
- $8,000
- Renewal, every twelve months
- $10,500 locked
This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.
Request this auditThe PDPA, in three chapters
Most teams arrive holding a GDPR programme and assume it transfers. The shapes match and the details do not: consent has doors GDPR has not, the breach clock starts when you decide rather than when you find out, the DPO is unconditional, and Do Not Call fails on its own terms.
Accountability under this Act is something you show rather than something you assert. We work from the systems inwards so the inventory matches the estate, score every finding against one of the eleven, and rehearse the three-day clock against your own escalation path.
Personal data, wherever you are.
Data about an identifiable individual - and the Act follows the activity, not where you are incorporated.
- Any organisation handling personal data in Singapore
- Overseas services with users in Singapore
- Data intermediaries, on protection and retention
- Anyone messaging a Singapore telephone number
- At collection - the purpose is told, not assumed
- Expeditiously, once a breach comes to light
- Three calendar days from determining it counts
- Before every send, inside the register window
The duty is yours. The processing is theirs.
The organisation that decides
You decide what happens to the personal data, so all eleven obligations land on you - consent and notification at the front, protection and retention through the middle, breach notification and accountability at the end. The Act follows the activity, not the place where you are incorporated.
The people who process for you
Acting on your instructions under a written contract narrows an intermediary to protection and retention. It does not remove the rest, the breach duties still reach them directly, and you remain answerable for the choice of them. Most vendors are both at the same time, for different sets of data.
The DPO is not conditional here
GDPR made the DPO a test that many teams correctly answered no to. The PDPA does not: at least one, always, with the business contact details made publicly available. It is the one obligation anyone can check from outside without asking you first, and it is checked more than you would think.
“We follow GDPR, so Singapore is covered.”
The DPO here is a requirement, not a test.
It is the first thing we have to correct.
- Who it is for
- SaaS & platforms
- Regional HQs
- Fintech & insurance
- Marketing & adtech
- Data intermediaries
Offences now reach individuals, not only organisations - unauthorised disclosure, improper use, and re-identification.
Directions are the common outcome: stop collecting, destroy the data, remediate. They arrive with a penalty, or instead of one.
Prompt notification and cooperation are consistently treated as mitigating. A missing DPO or a missing procedure runs the other way.
Three questions. Then you’ll know.
No email. No signup. A starting point, not a determination.
Your scope check
Four clocks, and one of them has no number.
Each of these runs from an event you do not choose - so they cannot be added up, and they cannot be run in parallel.
-
Assess
ExpeditiouslyThe one step with no number on it, and the one that eats the clock. What is recorded is that a procedure existed.
-
Notify the PDPC
3 calendar daysCalendar days, not working days - running from when you determine it is notifiable, not when you found out.
-
Tell the individuals
Without delayAs soon as practicable, where the harm is significant. Where you decide not to, the reasoning is the record.
-
Check the registers
Every 30 daysA Do Not Call result has a shelf life. Three registers, checked separately, and a stale check counts as none.
Teams schedule the notification and forget the step in front of it. The three days run from the day you determine it is notifiable - so the assessment window carries no number at all, and it is where most of the time actually goes.
What the Act says, what we ship
The PDPC’s 11, and the one that fails separately - 12 rows, each with the artefact that discharges it.
- Consent Or an exception
- Every collection point checked against what the individual is actually shown, and against the exception you rely on where consent is not the basis - including deemed consent, legitimate interests and business improvement.
- Purpose limitation A reasonable person
- Purposes fixed per data set before collection, with a compatibility test for any new use rather than a quiet expansion into one.
- Notification At or before collection
- What you tell people, in plain language, at the point it is collected - and updated when the purpose moves rather than when the notice is next reviewed.
- Access and correction A findable route
- A request route a member of the public can find without help, a proportionate identity check, and a response record that shows the clock was met.
- Accuracy Proportionate to use
- A higher bar where the data drives a decision about the individual, with the source and the currency of each record written down.
- Protection Reasonable security
- The arrangements you actually run, tested rather than attested, including the processors and vendors holding the data on your behalf.
- Retention limitation Cease, do not keep
- A schedule with named owners, a disposal step someone performs, and backups and archives inside the scope rather than beside it.
- Transfer limitation A comparable standard
- Where the data physically lands, the contractual protection covering it, an assessment of the receiving jurisdiction, and whether all three match your own notice.
- Breach notification Three calendar days
- A written assessment procedure against the significant-harm and significant-scale thresholds, the notification pack, and a rehearsal against the clock.
- Accountability DPO, policies, proof
- A DPO appointed and publicly findable, policies communicated to staff with training records, and a complaint route tested from the outside in.
- Data portability Check in-force status
- Enacted by the 2020 Amendment Act. Confirm the in-force position before relying on it either way - and design for it regardless, because the engineering is the long pole.
- Do Not Call Fails separately
- Register checking built into the send path, the validity window respected, and any ongoing-relationship or business-to-business exemption evidenced rather than assumed.
Personal data, independently reviewed
From the CRM to the marketing send path.
-
Intake
What personal data you hold, where it came from and where it goes.
-
Test
All eleven obligations against the estate, plus the register checks.
-
Sign off and evidence
You see the draft first. Then the inventory, policies and drills - dated.
Why teams choose iDharma for their PDPA review
Scored by obligation
Every finding lands on one of the eleven, so the report reads in the PDPC’s own structure.
The clock, rehearsed
The three-day notification drilled against your own escalation path, not a generic template.
Do Not Call included
Register checks and exemption claims reviewed in the same scope, because they fail separately.
Model Framework mapped
Findings tagged to the Model AI Governance Framework where you want to evidence alignment.
Four marks, struck on every report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
PDPA review report
The full review: what you hold, on what footing, under which obligation - and where each one is discharged or is not. Findings land on the PDPC’s own eleven so the report reads in the structure a regulator uses, with the Do Not Call position and the Model Framework alignment stated separately rather than folded in.
Personal data inventory
What you hold, where it came from, which purpose it serves, who it is disclosed to and where it goes overseas - built from the systems inwards.
Consent and exception log
What was shown at the moment of collection, withdrawal honoured downstream, and the assessment recorded where an exception is used.
Breach procedure and drill
The assessment procedure against both thresholds, the notification pack for the PDPC and for individuals, and one rehearsal against the clock.
Access and correction pack
A request route a member of the public can find, a proportionate identity check, and a response record showing the clock was actually met.
Transfer and DNC review
Where data actually lands and under what protection, plus register checking built into the send path and every exemption claim evidenced.
Policy template pack
The core PDPA set, the incident and breach set, and the AI governance set - tailored to your estate rather than handed over as a generic pack.
Real numbers, upfront.
- Scope
- Set by the Act
- Inputs
- Your systems and your registers
- Re-review
- Every twelve months - $10,500 against your known baseline
The Act fixed the obligations, so the fee is flat - nothing to meter, and nothing charged until you approve it.
Request this review- Findings on the PDPC’s eleven
- Breach drill against the clock
- Do Not Call register checks
- 29 policy templates, tailored
Four things you have to be able to produce
The PDPA is not graded on intent. Each of these is either in your hand on the day someone asks, or it is not.
The officer,
findable
At least one DPO, with business contact details a member of the public can reach without asking. Unconditional here, and the one obligation checked from outside.
The inventory,
current
What you hold, why, who it goes to and where it lands overseas. Almost every other obligation is answered out of this one document, so it is built first.
The drill,
dated
A breach assessment written before the incident, not during it. The three days run from your determination, so the undated window is where the deadline goes.
The register,
checked
A Do Not Call result inside its validity window on the day the message goes out, against the right one of the three registers. And it fails separately from the rest.
Four cards, and the date on each one is part of the card.
Plain answers
Scope, the officer, the breach clock and the AI frameworks. Answered straight.
Request this reviewDoes the PDPA apply to us if we are not in Singapore?
Very likely, if you collect, use or disclose the personal data of people in Singapore. The Act is written around the activity rather than around where the organisation is incorporated, and overseas services with Singapore users are routinely in scope.
Do we need to appoint a Data Protection Officer?
Yes - at least one, and their business contact information has to be made publicly available. It can be an existing employee and it can be a shared role; what it cannot be is unnamed or unfindable from the outside.
When do we have to report a data breach?
When it results in, or is likely to result in, significant harm to affected individuals, or is of significant scale. The assessment must be conducted expeditiously, and once you determine it is notifiable the PDPC must be told within three calendar days.
Is Singapore’s Model AI Governance Framework mandatory?
No. It is voluntary guidance from IMDA and the PDPC, and so is AI Verify. Neither replaces the PDPA - if your AI touches personal data, the eleven obligations apply in full regardless of how well you align to the Model Framework.
What does an iDharma PDPA review cost, and what do we get?
A flat fee for the named engagement, agreed before anything is charged. What lands is the review report, the personal data inventory, the consent and exception log, the breach procedure and drill, the access and correction pack, the transfer and DNC review, and the policy template pack.
Request your PDPA review
Tell us where personal data lives and we come back with a scoping call in a day.
What we need from you
Nothing you do not already have. Most of this comes out of a morning with your engineering and people teams, and we name exactly which extracts before you commit.
- Which systems hold personal data, and what for
- Whether any of the people are in Singapore
- Whether you are an organisation, an intermediary or both
- Your DPO appointment, and where it is published
- How marketing sends are checked against the registers
What happens next
- You send the five items we need.
- We call to scope it within one business day.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- Personal Data Protection Act 2012, and PDPC guidance
- AI Verify Foundation, on the testing framework
- Enacted
- 2012
- Amended
- 2020
What it means
- General information about what the Act requires — not legal advice, and no professional relationship.
- Where a scope question is genuinely arguable, our reports say so rather than pick the convenient answer.
Scope & limitation
- This reading has not been checked line by line against the Act — the penalty cap and AI Verify’s status are the two worth confirming at source.
- Do not rest a binding decision on it; engage qualified counsel, and use it as the start of a scoping conversation rather than as your final word.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
Startups, Meet Your AI Stack: Budget‑Friendly Tools That Scale
For early-stage founders, building an AI-powered toolkit doesn’t have to break the bank. From ideation to growth mode, here’s how startups can tap into affordable, effective AI tools to autom