Every company operating in Singapore that collects, uses or discloses personal data must comply with the Personal Data Protection Act 2012 (PDPA). Whether you are a sole proprietor handling customer contact details or a company processing thousands of employee records, the PDPA applies to you. Following the 2021 amendments which took effect on 1 February 2021 (and subsequent regulations), the regime now includes mandatory breach notification, enhanced accountability obligations, and significantly increased financial penalties — up to S$1 million or 10% of annual turnover in Singapore, whichever is higher.

This guide covers the key PDPA obligations, what companies must do in 2026, and the practical steps to build a compliant personal data protection framework.

Who Must Comply with the PDPA?

The PDPA applies to all organisations, whether incorporated or not, that collect, use or disclose personal data in Singapore. “Organisation” is broadly defined to include companies, firms, associations, sole proprietors and even individuals operating in a business context. There is no minimum size threshold — even a two-person company is subject to the PDPA.

There are limited exemptions. The PDPA does not apply to individual personal or domestic use (for example, personal contacts in your own mobile phone), or to public agencies acting in their official capacity. However, private companies doing business in Singapore are fully subject to the Act.

The Nine Obligations Under the PDPA

The PDPA imposes nine core obligations on organisations. Each is explained below.

1. Consent Obligation

You must obtain consent before collecting, using or disclosing personal data, unless an exception applies. Consent must be voluntary, informed and for the specific purpose disclosed. The 2021 amendments introduced two new bases for processing personal data without consent: (a) legitimate interests — where the organisation’s or third party’s legitimate interests outweigh the impact on the individual — and (b) business improvement purposes — for internal analytics and research.

2. Purpose Limitation Obligation

Personal data may only be collected, used or disclosed for purposes that a reasonable person would consider appropriate in the circumstances and that the individual was informed of (or which are otherwise permitted by law).

3. Notification Obligation

Before collecting personal data, you must notify the individual of the purposes for which the data will be collected, used or disclosed. This is commonly done via a Privacy Policy or a collection notice at the point of data collection (e.g., on a website registration form).

4. Access and Correction Obligation

Individuals have the right to request access to their personal data held by your organisation and to request correction of any inaccurate data. You must respond to such requests within 30 days (or provide a written notice of an extension). There are fees restrictions — you may charge a reasonable fee for access requests, but not for correction requests.

5. Accuracy Obligation

You must make reasonable efforts to ensure that personal data collected or used is accurate and complete, especially where the data may be used to make a decision affecting the individual.

6. Protection Obligation

You must implement reasonable security arrangements to protect personal data in your possession or under your control from unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks.

7. Retention Limitation Obligation

Personal data must not be retained longer than necessary for the purposes for which it was collected. Once the data is no longer needed, it must be destroyed or anonymised. Your organisation should have a data retention schedule that specifies the maximum period for which different categories of data are kept.

8. Transfer Limitation Obligation

If personal data is transferred to a third country (i.e., outside Singapore), you must ensure that the receiving organisation provides a standard of protection comparable to that required under the PDPA. This is typically done by contractual clauses or ensuring the recipient country has an adequate data protection framework.

9. Accountability Obligation

Every organisation must designate at least one individual as a Data Protection Officer (DPO). The DPO is responsible for ensuring the organisation’s compliance with the PDPA. The DPO’s business contact information must be made publicly available (for example, on the company’s website). Note that the DPO does not need to be a specific seniority — it can be any employee designated for this role, or it may be outsourced.

Mandatory Data Breach Notification

Since 1 February 2021, organisations are required to notify the Personal Data Protection Commission (PDPC) and/or affected individuals of data breaches that meet the notification threshold.

Notification to PDPC

A data breach must be notified to the PDPC within 3 calendar days of the organisation becoming aware that the breach is likely to be a notifiable data breach. A breach is notifiable to the PDPC if it is likely to cause significant harm to affected individuals, or if the breach involves personal data of 500 or more individuals.

Notification to Individuals

If the breach is likely to result in significant harm to affected individuals (regardless of the number of persons affected), those individuals must also be notified as soon as practicable.

Assessing “Significant Harm”

The PDPC has published guidelines on what constitutes “significant harm”. The list includes exposure of health or financial data, NRIC numbers, passwords, and similar sensitive data. The PDPC’s Guide to Managing Data Breaches provides a decision matrix to help organisations assess whether notification is required.

Practical Steps to Achieve PDPA Compliance

Step 1: Appoint a Data Protection Officer

Designate a DPO and make their contact information publicly available. Update your website’s privacy policy to identify how data subjects can reach the DPO.

Step 2: Conduct a Data Inventory and Mapping Exercise

Identify what personal data your organisation collects, from whom, why, how it is stored, who has access to it, and how long it is retained. A data flow map helps identify risks and gaps in your current arrangements.

Step 3: Review and Update Privacy Notices

Ensure your website Privacy Policy, terms and conditions, employment contracts and customer agreements accurately reflect how you use personal data. Privacy notices should be clear, plain-language documents, not legal boilerplate.

Step 4: Implement Data Security Measures

Review your IT security arrangements, access controls, and incident response plan. Common measures include encryption of sensitive data, two-factor authentication for system access, role-based access control, and regular security testing. Ensure third-party vendors who process personal data on your behalf have adequate security measures and sign data processing agreements.

Step 5: Train Staff

All employees who handle personal data should receive basic PDPA training. The PDPC offers free training materials and e-learning resources at pdpc.gov.sg.

Step 6: Prepare a Data Breach Response Plan

Document your data breach response procedure before a breach occurs. The procedure should assign roles, set out the assessment process, specify notification triggers and timelines, and designate who contacts the PDPC and affected individuals.

PDPA Penalties and Enforcement

The PDPC enforces the PDPA and has the power to issue financial penalties of up to S$1 million, or 10% of the organisation’s annual turnover in Singapore, whichever is higher (following the 2021 amendments). Factors the PDPC considers in setting penalties include the nature, gravity and duration of the breach, whether the organisation cooperated with the PDPC, and any remediation steps taken.

In addition to financial penalties, the PDPC may issue directions to stop collecting data, destroy unlawfully collected data, or implement specific security measures. Decisions are published on the PDPC’s website, making enforcement actions public and reputationally significant.

PDPA and Employment: Employee Data

Employee data is personal data. The PDPA applies to the collection, use and disclosure of employees’ personal data in exactly the same way as customer data. Common compliance gaps include:

  • Collecting more employee data than necessary during recruitment
  • Sharing employee payslips or salary information without consent
  • Using employee images in marketing materials without consent
  • Transferring employee data to overseas payroll providers without adequate safeguards

Employment contracts and HR policies should include a data protection notice for employees that covers how their data will be used during and after employment. For a guide to Singapore payroll obligations, see our Singapore Payroll and CPF Guide 2026.

How Raffles Corporate Services Can Help

PDPA compliance is an ongoing obligation, not a one-time exercise. Raffles Corporate Services can assist with the corporate governance aspects of PDPA compliance, including reviewing your data protection policies, helping you appoint and register a DPO, and ensuring your employment and service contracts include appropriate data protection provisions.

For the latest Singapore business news and regulatory updates, including PDPC enforcement decisions, there are useful resources for business owners and directors. If you need legal advice on your PDPA obligations or data breach response, we can point you in the right direction. Beyond data compliance, sound business and investment planning is equally important for Singapore companies looking to grow sustainably.

To speak with the team at Raffles Corporate Services, you can email [email protected] or call, SMS, or WhatsApp +65 8501 7133. We are happy to assist with any queries.

— The Editorial Team, Raffles Corporate Services