Know what is on your site before a plaintiff’s firm does.Free website scanScan Your Site
Log in Sign up Book a demo
Solutions / PDPA · SINGAPORE
SINGAPORE PDPA · ACCOUNTABILITY · DATA PROTECTION

Singapore’s PDPA offers flexibility — but requires evidence behind every decision.

Singapore’s Personal Data Protection Act combines consent, carefully defined exceptions, accountability, security, individual rights, overseas-transfer controls, breach notification and separate Do Not Call rules. Captain Compliance helps organizations discover personal-data activity, document purposes and decision-making, manage requests and preferences, map vendors and transfers, and coordinate defensible response workflows via our PDPA privacy software solutions.

Consent and exception recordsThree-day breach workflowTransfer and DPO evidence

The greatest PDPA risk is often the gap between policy and proof.

DPO
Accountability and a designated DPO

Appoint at least one individual to oversee data-protection responsibilities, make the DPO’s business contact information publicly available, establish policies and complaint-handling processes, and maintain evidence of governance. Appointing a DPO does not transfer the organization’s legal responsibility to that person.

Notice
Notice and appropriate purposes

Tell individuals the purposes for collecting, using and disclosing personal data on or before the relevant activity. Limit processing to purposes a reasonable person would consider appropriate in the circumstances, and provide new notice before using data for a materially different purpose unless an exception applies.

Consent
Consent and deemed-consent controls

Obtain valid consent where required, avoid making unnecessary consent a condition of service, and operationalize withdrawal. Deemed consent may arise by conduct, contractual necessity or notification, but each route has conditions. Deemed consent by notification requires an adverse-effect assessment, reasonable mitigation, notice, a reasonable opt-out period and an effective opt-out method.

Exceptions
Legitimate interests and other exceptions

Legitimate interests is an exception to the consent requirement, not a form of consent. Before relying on it, assess whether the legitimate interests outweigh likely adverse effects, implement reasonable safeguards and disclose that reliance. Business-improvement and other statutory exceptions have their own conditions. Record the exception and the analysis instead of labelling every activity “consent”.

30 days
Access, correction and data quality

Support requests for access to personal data and information about its use or disclosure, and correct errors where required, subject to statutory exceptions. Organizations generally should respond within 30 calendar days, or tell the individual in writing how much additional time is needed. Use reasonable efforts to keep data accurate and complete when it may affect the individual or be disclosed to another organization.

Retention
Security, retention and processor oversight

Use reasonable security arrangements, restrict access, monitor service providers and define data-intermediary responsibilities. Stop retaining documents containing personal data, or remove the means of association, when the original purpose is no longer served and retention is no longer necessary for legal or business purposes.

Transfers
Comparable protection for transfers

Before transferring personal data outside Singapore, establish a lawful mechanism providing protection comparable to the PDPA. Depending on the circumstances this may involve enforceable contracts, binding corporate rules, specified certifications or another permitted basis. Map destinations, recipients, safeguards and onward-transfer controls before the transfer occurs. Using an overseas vendor does not remove accountability.

3 days
Notifiable data-breach response

Assess suspected breaches expeditiously. Notify the PDPC when a breach is likely to cause significant harm or is of significant scale — generally 500 or more affected individuals. Once the organization determines that a breach is notifiable, notify the PDPC as soon as practicable and no later than three calendar days. Notify affected individuals as soon as practicable when significant harm is likely.

DNC
Do Not Call rules run alongside

The DNC provisions generally regulate specified marketing messages sent to Singapore telephone numbers by voice call, text message or fax. Before sending a covered message an organization generally must check the relevant DNC Register unless it has clear and unambiguous consent in evidential form or another exception applies. A registry check is generally valid for 21 days. Identification, contact-information and opt-out requirements also apply. Email is not automatically a DNC-regulated channel merely because it is marketing, though the data-protection obligations and other laws may still apply.

Turn PDPA obligations into repeatable evidence.

Captain Compliance connects website discovery, consent and preference records, notices, data inventories, request handling, vendor oversight and incident workflows. It helps privacy teams replace scattered spreadsheets and screenshots with an accountable operating record while preserving human review for legal judgments. The operating loop runs: Discover websites, systems, trackers, forms, vendors and personal-data flows. Classify data categories, purposes, individuals, recipients, locations and retention needs. Choose and document consent, deemed-consent conditions or the relevant statutory exception and assessment. Control notices, preferences, security, retention, intermediaries and transfers. Respond to access, correction, complaint, withdrawal and incident workflows through accountable owners. Monitor by re-scanning, reviewing evidence, remediating changes and maintaining an audit history.

S

Website tracker discovery

Scan websites for cookies, pixels, tags and similar technologies, identify changes over time and route findings for classification. Discovery supports the analysis; it does not decide by itself whether a device identifier is personal data or whether consent is legally required.

C

Consent and preference evidence

Capture choices, notice versions, timestamps, channels and withdrawal events. Separate actual consent from deemed-consent or exception-based processing so the record reflects the organization’s real legal rationale.

N

Purpose and notice mapping

Connect data categories and collection points to purposes, recipients, notices and retention rules. Flag new or changed processing for review before old language is reused automatically.

R

Access and correction workflows

Intake, verify, assign and track access or correction requests; collect responsive data from business owners; record exemptions and approvals; and maintain a defensible response history.

G

DPO and governance workspace

Centralize ownership, policies, assessments, approvals, training evidence, complaints and remediation tasks so the DPO can see where controls are working and where follow-up is overdue.

I

Breach-assessment workflow

Coordinate discovery, containment, affected-person counts, harm analysis, decision records, approvals and notification tasks. Surfaces the three-calendar-day PDPC deadline after a breach is determined to be notifiable, without making that legal determination for you.

T

Vendor and transfer mapping

Record data intermediaries, countries, purposes, contract safeguards, security reviews, subprocessors and evidence of comparable protection for overseas transfers.

D

DNC and marketing governance

Maintain channel permissions, consent evidence, suppression records, campaign checks and proof of registry-screening activity. Captain Compliance manages the governance and evidence around DNC obligations; it does not itself query the PDPC registry.

Two Singapore developments to track in 2026 and 2027.

Data portability is enacted, not yet operational. Singapore enacted a Data Portability Obligation in the 2020 Amendment Act, but it has not been brought into general operation as of August 2026. It should not be described as a currently exercisable PDPA right, and no live response deadline should be built around it. This status should be updated when commencement details are issued. Phase out NRIC numbers as authenticators. The PDPC has called on private-sector organizations to stop using full or partial NRIC numbers for authentication by December 31, 2026, with stepped-up enforcement beginning January 1, 2027. Treat an NRIC number as an identifier, not a secret credential, and inventory affected login, verification and customer-service processes now.

Book a Singapore PDPA review
A ROLLOUT BUILT AROUND RISK AND EVIDENCE
  • Stage 1 — Baseline — Inventory processing, websites, vendors, overseas transfers, notices, DNC activity, DPO ownership and current controls
  • Stage 2 — Consent and notices — Correct notice timing and purpose descriptions, distinguish consent from exceptions, and implement withdrawal and preference workflows
  • Stage 3 — Rights and retention — Configure access and correction intake, identity checks, assignments, response evidence, retention schedules and deletion tasks
  • Stage 4 — Vendors, security and incidents — Map intermediaries and transfers, capture safeguards, connect risk findings to remediation, and rehearse the breach-assessment and notification process
  • Stage 5 — Continuous monitoring — Track website changes, evidence updates, DNC governance, incidents, regulatory developments and the eventual commencement of data portability

From scattered proof to an accountable operating record.

Before Captain Compliance
  • Consent screenshots and notice versions live in different folders
  • Legitimate interests is selected without a recorded assessment
  • The DPO cannot see request, vendor and incident status in one place
  • Overseas-transfer safeguards are buried in contracts
  • DNC checks and campaign decisions are difficult to reconstruct
  • Breach timing depends on email and memory
With Captain Compliance
  • Purposes, notices, choices and legal rationales are connected
  • Assessments, safeguards and approvals form an evidence trail
  • Access, correction, withdrawal and complaint tasks have owners
  • Vendors, destinations and transfer safeguards are mapped
  • DNC governance and suppression evidence are centralized
  • Incident decisions and notification deadlines are coordinated

Singapore’s PDPA, answered plainly.

Who does Singapore’s PDPA apply to?+
The PDPA generally applies to private-sector organizations that collect, use or disclose personal data in Singapore, including many organizations based outside Singapore when their activities fall within the Act. Statutory exclusions and exceptions apply, including different treatment for public agencies, individuals acting in a personal or domestic capacity, and certain business-contact information.
Does the PDPA always require express consent?+
No. Consent may be express or validly implied, and the Act recognizes deemed-consent routes and exceptions to consent. The correct route depends on the facts and statutory conditions. Flexibility should not be treated as permission to skip notice, purpose analysis, safeguards or documentation.
What is deemed consent?+
Deemed consent can arise in defined circumstances, including conduct, contractual necessity and notification. Deemed consent by notification has specific controls: assess likely adverse effects, take reasonable steps to eliminate or mitigate them, notify the individual, allow a reasonable opt-out period and provide an effective way to opt out.
Is legitimate interests a form of consent?+
No. Legitimate interests is an exception to the consent requirement. Before relying on it, an organization should assess whether the legitimate interests outweigh likely adverse effects on individuals, implement reasonable safeguards and disclose that it is relying on the exception.
Does the PDPA require a cookie banner?+
The PDPA is not a cookie-specific statute, and it does not impose one universal banner design. Cookies, pixels and device identifiers may be personal data depending on whether an individual can be identified from the data alone or together with other information. The organization must evaluate its collection, purposes, notice, consent or exception, disclosure and security obligations for the actual technology and use case.
Must every organization appoint a DPO?+
An organization must designate at least one individual responsible for ensuring that it complies with the PDPA, and make the DPO’s business contact information publicly available. The DPO may hold another role or be supported externally, but the organization remains responsible for compliance.
How quickly must access and correction requests be answered?+
PDPC guidance states that an organization generally should respond to an access or correction request within 30 calendar days. If it cannot do so, it should inform the individual in writing within that period of when it expects to respond. Exceptions and procedural requirements may affect the result.
When must a data breach be reported?+
A breach is notifiable to the PDPC when it is likely to result in significant harm to affected individuals or is of significant scale, generally involving 500 or more individuals. After determining that the breach is notifiable, the organization must notify the PDPC as soon as practicable and no later than three calendar days. Affected individuals must be notified as soon as practicable when significant harm is likely.
What do the Do Not Call rules require?+
The DNC provisions generally cover specified marketing voice calls, text messages and faxes sent to Singapore telephone numbers. Unless clear and unambiguous consent in evidential form or an exception applies, the sender generally must check the relevant register; a check is generally valid for 21 days. Identification, contact and opt-out requirements also apply. Email is not itself a DNC channel.
Is PDPA data portability currently in force?+
Not as a generally operational obligation as of August 2026. The Data Portability Obligation was enacted through the 2020 amendments, but commencement and detailed implementation depend on further regulatory action. Organizations should track this status rather than assume a current portability request deadline applies.

Make Singapore privacy obligations visible, owned and repeatable.

Captain Compliance helps privacy, legal, security and marketing teams connect data discovery to the records and workflows behind Singapore PDPA operations. See where personal data moves, document consent and exceptions, coordinate requests and incidents, and maintain evidence that can be reviewed and improved over time. Captain Compliance provides technology and operational support, not legal advice. Use qualified Singapore counsel for interpretations and decisions specific to your organization.

Book a Singapore PDPA review View pricing