Singapore’s PDPA is a pragmatist’s privacy law. It demands consent, then engineers exceptions where consent adds no protection: deemed consent for obvious purposes, notified purposes with opt-out, a legitimate-interests route with documented assessments, and business-improvement allowances for internal analytics. The regulator matches that temperament, publishing every enforcement decision with reasoning, but since October 2022 it can reach 10% of local turnover, and it made an example of Singapore’s largest healthcare group after the SingHealth breach.
| Regulation | Personal Data Protection Act 2012 (2020 amendment) |
|---|---|
| Max penalty | 10% of SG turnover or SGD 1M (whichever higher) |
| Enforcing authority | PDPC |
| Official text | PDPA on Singapore Statutes Online |
The obligations
The act organizes duties as named obligations, and PDPC decisions cite them by name:
- Consent and Purpose Limitation. Collect, use, disclose only for purposes a reasonable person considers appropriate, with consent or a valid exception, and notify purposes before collection.
- Access and Correction. Respond to access requests (data plus use/disclosure information for the past year) and correction requests, with prescribed exceptions and a modest fee allowance.
- Accuracy, Protection, Retention. Reasonable steps to keep data accurate for decisions, security arrangements proportionate to sensitivity (the obligation behind most fines), and cease-retention when purposes end.
- Transfer Limitation. Offshore transfers only with comparable protection: contractual clauses, group policies, or certification, details in Singapore’s support for APEC CBPR.
- Breach Notification (2021). Assess promptly; notify the PDPC within 3 days of assessing a breach as notifiable (significant harm likely, or 500+ individuals), and affected individuals where harm is likely.
- Accountability. Publish policies, train staff, and appoint a data protection officer, mandatory for every organization, no size threshold.
Enforcement texture
The PDPC’s public register shows a steady cadence: most penalties punish Protection Obligation failures (unpatched systems, misconfigured databases, vendor lapses), with SingHealth/IHiS (SGD 1M combined, 2019) still the ceiling case. The 2020 amendment added individual criminal liability for egregious conduct, knowing unauthorized disclosure or re-identification, up to 2 years imprisonment. Telemarketing violations run through the separate Do Not Call regime, checked per message against the national registries.
The 2020 amendment also legislated data portability, but the provisions have not been brought into force; watch PDPC announcements. For implementation guidance the PDPC’s advisory guidelines are the operative rulebook. Test your Singapore-facing collection surfaces with a free scan.