facebook-pixel

Singapore PDPA: Your Personal Data Protection Rights Explained

L
Lunyb Security Team
··11 min read

Singapore's Personal Data Protection Act (PDPA) is the country's cornerstone privacy law, giving individuals meaningful control over how organisations collect, use, and disclose their personal data. Whether you're signing up for a loyalty programme, applying for a job, or clicking a shortened link in a marketing message, the PDPA sets the rules that businesses must follow — and gives you specific rights you can enforce.

This guide breaks down the Singapore PDPA rights every resident should know, explains how the law has evolved since its major 2020 amendments, and walks through the practical steps for exercising your rights or filing a complaint with the Personal Data Protection Commission (PDPC).

What Is the Singapore PDPA?

The Personal Data Protection Act 2012 is Singapore's baseline data protection law, administered by the Personal Data Protection Commission (PDPC). It regulates how private-sector organisations collect, use, disclose, and care for personal data, and it works alongside sector-specific rules (such as banking secrecy and healthcare confidentiality) rather than replacing them.

The PDPA applies to any organisation that handles personal data in Singapore, regardless of where the organisation is based. This means overseas companies serving Singapore customers must also comply. Personal data covers any information — on its own or combined with other information — that can identify a living individual, including names, NRIC numbers, phone numbers, email addresses, photographs, and even IP addresses in some contexts.

Key Milestones in PDPA Evolution

  • 2012: PDPA enacted.
  • 2014: Main data protection obligations take effect, along with the national Do Not Call (DNC) Registry.
  • 2020: Major amendments introduce mandatory data breach notification, expanded consent frameworks, and increased financial penalties.
  • 2021 onwards: Higher fines of up to 10% of annual Singapore turnover (or S$1 million, whichever is higher) come into force.

The Nine Data Protection Obligations Organisations Must Follow

Before diving into your rights, it helps to understand what organisations are required to do. The PDPA imposes nine core obligations that shape how your data is handled.

ObligationWhat It Means
ConsentOrganisations must get your consent before collecting, using, or disclosing your personal data (with limited exceptions).
Purpose LimitationData can only be used for purposes a reasonable person would consider appropriate and that you were informed of.
NotificationYou must be told the purposes for which your data is being collected, used, or disclosed.
Access and CorrectionYou have the right to request access to your data and to correct inaccuracies.
AccuracyOrganisations must make reasonable efforts to ensure your data is accurate and complete.
ProtectionReasonable security arrangements must protect your data from unauthorised access, disclosure, or loss.
Retention LimitationData must be deleted or anonymised when it's no longer needed for the original purpose or legal requirements.
Transfer LimitationData transferred overseas must receive protection comparable to the PDPA.
AccountabilityOrganisations must appoint a Data Protection Officer (DPO) and publish policies on how they handle data.

Your Core PDPA Rights as an Individual

The PDPA translates these obligations into concrete rights you can exercise. Here are the key rights every Singapore resident should know.

1. The Right to Be Informed

Before an organisation collects your personal data, it must tell you what data it's collecting and why. This information is usually provided through privacy notices, terms of service, or verbal explanations. If the purpose changes later, the organisation must inform you and, in most cases, obtain fresh consent.

2. The Right to Give — and Withdraw — Consent

Consent must be meaningful. Organisations cannot bundle consent for unrelated services, and they cannot require you to consent to marketing as a condition of providing a product unless the marketing is essential to the service.

Equally important: you can withdraw consent at any time by giving reasonable notice. Once you withdraw, the organisation must stop the relevant collection, use, or disclosure — though existing legal obligations (like keeping tax records) may still apply.

3. The Right of Access

You can ask an organisation to provide:

  1. The personal data it holds about you.
  2. Information about how that data has been used or disclosed in the past year.

The organisation must respond as soon as reasonably possible, typically within 30 days. A reasonable fee may be charged, but it cannot be used to discourage requests.

4. The Right to Correction

If your data is inaccurate or incomplete, you can request a correction. The organisation must correct the data as soon as practicable and notify any other organisation to whom the incorrect data was disclosed within the past year (unless you agree otherwise).

5. The Right to Data Portability (Coming Into Force)

The 2020 amendments introduced a data portability obligation, allowing individuals to request that their data be transmitted to another organisation in a commonly used machine-readable format. Implementation depends on subsidiary legislation being brought into force, but businesses are already expected to prepare.

6. The Right to Be Notified of Data Breaches

Since February 2021, organisations must notify the PDPC — and affected individuals — of data breaches that are likely to result in significant harm or affect 500 or more people. Notifications must be made within specific timeframes (generally within 3 calendar days to the PDPC after assessing the breach).

7. The Right to Opt Out of Marketing (Do Not Call Registry)

Singapore's Do Not Call (DNC) Registry lets you opt out of telemarketing calls, texts, and faxes. Registration is free at dnc.gov.sg, and organisations must check the registry before sending marketing messages to Singapore numbers.

How to Exercise Your PDPA Rights: Step-by-Step

Knowing your rights matters only if you can act on them. Here's a practical walkthrough.

Step 1: Identify the Organisation and Its DPO

Every PDPA-regulated organisation must appoint a Data Protection Officer and publish their business contact information. Check the company's privacy policy, website footer, or app settings for DPO contact details.

Step 2: Submit a Written Request

Send a clear, written request (email is typically sufficient) that includes:

  1. Your full name and identifying information.
  2. The specific right you're exercising (access, correction, withdrawal of consent, etc.).
  3. Enough detail to help them locate your records.
  4. Your preferred format for receiving a response.

Step 3: Wait for the Response

The organisation should acknowledge receipt promptly and respond within 30 days. If they need more time, they must tell you why and give a revised timeline.

Step 4: Escalate if Necessary

If the organisation refuses your request, fails to respond, or you believe they've mishandled your data, you can file a complaint with the PDPC through the online complaint form at pdpc.gov.sg.

Filing a Complaint With the PDPC

The PDPC investigates complaints and can issue directions, financial penalties, and public reprimands. Here's what to expect.

Before You Complain

The PDPC generally expects you to raise the issue with the organisation first and give them a reasonable chance to resolve it. Keep records of your correspondence, dates, and any responses received.

What to Include in Your Complaint

  • Your contact details.
  • The organisation's name and DPO contact.
  • A clear description of what happened and when.
  • Copies of relevant emails, screenshots, or documents.
  • The outcome you're seeking.

Possible Outcomes

Depending on the severity of the breach, the PDPC may:

  • Issue a warning or advisory.
  • Direct the organisation to stop certain practices or destroy data.
  • Impose financial penalties up to S$1 million or 10% of annual Singapore turnover (whichever is higher for organisations with local turnover above S$10 million).
  • Publish the enforcement decision publicly.

PDPA and Everyday Digital Life

The PDPA isn't just about big data breaches — it shapes small, everyday interactions too. Consider how it applies to common scenarios.

Shortened Links and Marketing Campaigns

Marketers often use link shorteners in SMS, email, and social campaigns to track click-throughs. Under the PDPA, if that tracking data can be linked back to you, it counts as personal data and must be handled accordingly. Businesses should choose shortening tools that offer transparent analytics and secure link handling. Platforms like Lunyb focus on clean, privacy-conscious short links without invasive tracking scripts — a helpful consideration for Singapore businesses building PDPA-aligned campaigns. For a broader comparison of shortening options, our 2026 buyer's guide to URL shorteners is a useful starting point.

Employer-Employee Data

Employers can collect, use, and disclose employee personal data for reasonable employment-related purposes without consent, but they must still notify employees of the purposes and follow the other obligations (protection, retention, accuracy).

CCTV and Building Access

CCTV footage that identifies individuals is personal data. Building managers must display notices, restrict access to recordings, and delete footage when it's no longer needed.

Cross-Border Data Transfers

If a Singapore company sends your data overseas — for example, to a cloud provider in the US or EU — it must ensure comparable protection through contractual clauses, binding corporate rules, or certifications like APEC CBPR.

Exceptions and Limitations to Your Rights

PDPA rights are strong, but not absolute. Common exceptions include:

  • Legal or regulatory requirements: Organisations may retain or disclose data when required by law.
  • Investigations and proceedings: Data may be disclosed for legal proceedings, fraud investigations, or law enforcement requests.
  • Publicly available data: Consent obligations don't apply to genuinely public information.
  • Business asset transactions: Data may be transferred during mergers, acquisitions, or reorganisations under specific safeguards.
  • Legitimate interests: Introduced in 2020, this exception allows certain uses where the organisation's legitimate interest outweighs any adverse effect on the individual (with a required assessment).

How the PDPA Compares to Other Privacy Laws

Singapore's PDPA sits within a global patchwork of privacy laws. Here's how it stacks up against two major frameworks.

FeatureSingapore PDPAEU GDPRCalifornia CCPA/CPRA
Consent modelConsent-based with exceptionsMultiple lawful basesOpt-out for sale/sharing
Right of accessYesYesYes
Right to erasureLimited (via withdrawal + retention)Yes (explicit right to be forgotten)Yes
Data portabilityYes (pending full implementation)YesYes
Breach notificationYes (since 2021)Yes (72 hours)Yes
Maximum penaltyS$1M or 10% of SG turnover€20M or 4% of global turnoverUS$7,500 per intentional violation

Practical Tips to Protect Your Personal Data in Singapore

Beyond legal rights, proactive habits go a long way.

  1. Register on the DNC Registry to reduce telemarketing.
  2. Read privacy notices — even skimming for retention periods and third-party sharing helps.
  3. Use unique passwords and enable two-factor authentication on important accounts.
  4. Be cautious with NRIC numbers. Since 2019, organisations generally cannot collect or use NRIC numbers except where required by law.
  5. Check shortened links before clicking, especially in unsolicited messages. Preview features on reputable platforms — such as those discussed in our honest Lunyb review — let you see the destination before committing.
  6. Review app permissions regularly and revoke access you no longer need.

Frequently Asked Questions

Does the PDPA apply to government agencies?

No. Singapore public sector agencies are governed by the Public Sector (Governance) Act and internal government instruction manuals, not the PDPA. However, private contractors handling data on behalf of the government may still have PDPA obligations for their non-government work.

Can I sue an organisation directly under the PDPA?

Yes. The PDPA provides a private right of action, meaning individuals who suffer loss or damage due to a PDPA contravention can bring a civil claim once the PDPC has made a finding of non-compliance (or in certain other circumstances).

How long does an organisation have to respond to my access request?Generally within 30 days. If they cannot respond in time, they must inform you in writing of the delay and provide a revised timeframe. Unreasonable delays can be reported to the PDPC.

What counts as a notifiable data breach?

A breach is notifiable if it results in, or is likely to result in, significant harm to affected individuals, or if it affects 500 or more individuals. Organisations must notify the PDPC as soon as practicable, and no later than 3 calendar days after assessing that the breach is notifiable.

Can I ask a company to delete all my data?

The PDPA doesn't have an explicit "right to erasure" like the GDPR, but you can withdraw consent, which requires the organisation to stop collecting, using, or disclosing your data. Combined with the retention limitation obligation, this often results in deletion — unless the organisation has a legal reason to keep the data.

Final Thoughts

Singapore's PDPA gives you genuine control over your personal data — but those rights only work when you know about them and use them. Whether it's requesting access to your records, withdrawing marketing consent, or reporting a suspicious data practice to the PDPC, taking small actions builds a culture where organisations treat privacy as a priority rather than an afterthought.

Stay informed, keep records of your data interactions, and don't hesitate to escalate when something feels off. Your data is valuable — and under the PDPA, so is your voice.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles