facebook-pixel

Singapore PDPA: Your Personal Data Protection Rights Explained

L
Lunyb Security Team
··11 min read

Singapore's Personal Data Protection Act (PDPA) is the cornerstone of data privacy law in the country, giving individuals meaningful control over how organisations collect, use, and disclose their personal data. Whether you're a Singapore resident, a business owner handling customer information, or simply someone curious about your digital rights, understanding the PDPA is essential in 2026's data-driven economy.

This guide breaks down your Singapore PDPA rights in plain English, explains how the law has evolved with recent amendments, and shows you exactly how to exercise your rights when an organisation mishandles your information.

What Is the Singapore PDPA?

The Personal Data Protection Act (PDPA) is Singapore's primary data protection law, enacted in 2012 and enforced by the Personal Data Protection Commission (PDPC). It establishes a baseline standard for how private-sector organisations must handle personal data throughout its lifecycle — from collection to deletion.

The Act applies to any organisation that collects, uses, or discloses personal data in Singapore, regardless of whether the organisation itself is based there. This means foreign companies serving Singapore customers must also comply. Public agencies are governed separately under the Public Sector (Governance) Act.

Key Definitions Under the PDPA

  • Personal Data: Any data about an individual who can be identified from that data, or from that data combined with other information the organisation has access to.
  • Organisation: Any individual, company, association, or body of persons — corporate or unincorporated.
  • Data Intermediary: An organisation that processes personal data on behalf of another organisation.
  • Consent: Voluntary and informed agreement to the collection, use, or disclosure of personal data.

The 11 Main Obligations Under the PDPA

Before diving into your rights, it helps to understand what organisations must do. The PDPA imposes 11 core obligations on organisations handling personal data:

  1. Consent Obligation — Obtain consent before collecting, using, or disclosing personal data.
  2. Purpose Limitation Obligation — Only collect data for reasonable purposes that have been notified to the individual.
  3. Notification Obligation — Inform individuals of the purposes for collection, use, and disclosure.
  4. Access and Correction Obligation — Provide access to and allow correction of personal data upon request.
  5. Accuracy Obligation — Ensure personal data collected is accurate and complete.
  6. Protection Obligation — Protect personal data with reasonable security arrangements.
  7. Retention Limitation Obligation — Cease retention when no longer needed for legal or business purposes.
  8. Transfer Limitation Obligation — Ensure overseas transfers meet comparable protection standards.
  9. Accountability Obligation — Appoint a Data Protection Officer (DPO) and develop policies.
  10. Data Breach Notification Obligation — Notify the PDPC and affected individuals of significant breaches.
  11. Data Portability Obligation — Transfer data to another organisation upon request (once fully in force).

Your Core Singapore PDPA Rights Explained

The PDPA grants individuals several important rights over their personal data. Understanding these rights empowers you to protect your privacy and hold organisations accountable.

1. Right to Be Informed

Before an organisation collects your personal data, it must clearly inform you of the purposes for which the data will be collected, used, or disclosed. This is typically communicated through privacy policies, consent forms, or notices at the point of collection.

Watch out for vague catch-all statements like "for business purposes." Under the PDPA, purposes must be specific enough for you to make an informed decision.

2. Right to Give and Withdraw Consent

Consent is the foundation of the PDPA. Organisations generally cannot collect, use, or disclose your personal data without your consent, except in specific circumstances such as legitimate interest, business improvement, or legal obligations.

Importantly, you have the right to withdraw consent at any time by giving reasonable notice. Once withdrawn, the organisation must stop collecting, using, or disclosing your data — though they may still retain it if required by law or for legitimate business reasons.

3. Right of Access

You have the right to request access to your personal data held by an organisation, along with information about how it has been used or disclosed within the past 12 months. Organisations must respond as soon as reasonably possible, typically within 30 days.

A reasonable fee may be charged for access requests, but it cannot be excessive. Organisations must inform you of the fee upfront so you can decide whether to proceed.

4. Right of Correction

If your personal data is inaccurate or incomplete, you can request that the organisation correct it. Organisations are required to correct the data unless they have reasonable grounds not to, and must send the corrected data to any other organisations to which the incorrect data was disclosed within the past 12 months.

5. Right to Data Portability

Introduced through the 2020 PDPA amendments, the data portability right allows you to request that an organisation transmit your personal data to another organisation in a commonly used machine-readable format. This right facilitates switching between service providers — for example, moving your data from one bank or telco to another.

6. Right to Be Notified of Data Breaches

Since February 2021, organisations must notify affected individuals and the PDPC when a data breach results in significant harm or affects 500 or more individuals. You have the right to know when your data has been compromised so you can take protective action, such as changing passwords or monitoring for identity theft.

PDPA Rights Comparison: Singapore vs. Other Jurisdictions

Understanding how PDPA rights compare with other major data protection laws helps put Singapore's framework in context.

Right Singapore PDPA EU GDPR UK Data Protection Act
Right of Access Yes (fee may apply) Yes (usually free) Yes (usually free)
Right of Correction Yes Yes (rectification) Yes
Right to Erasure Limited (via withdrawal) Yes (right to be forgotten) Yes
Data Portability Yes (phased in) Yes Yes
Withdraw Consent Yes Yes Yes
Breach Notification 72 hours to PDPC 72 hours to authority 72 hours to ICO
Maximum Fine SGD 1M or 10% of turnover EUR 20M or 4% of turnover GBP 17.5M or 4% of turnover

The Do Not Call (DNC) Registry

A distinctive feature of Singapore's data protection framework is the Do Not Call Registry, established under the PDPA. This lets you opt out of receiving marketing messages sent to your Singapore telephone number.

How to Register for the DNC

  1. Visit the official DNC Registry website or call the DNC hotline.
  2. Choose which channels to block: voice calls, text messages, and/or fax messages.
  3. Register your Singapore phone number (mobile or landline).
  4. Registration takes effect within 30 days.

Once registered, organisations must check the DNC Registry before sending marketing messages to your number. Violations can result in significant fines, and you can lodge complaints directly with the PDPC.

How to Exercise Your PDPA Rights

Knowing your rights is only useful if you can actually enforce them. Here's a step-by-step process for exercising your PDPA rights with any organisation.

Step 1: Identify the Data Protection Officer (DPO)

Every organisation subject to the PDPA must appoint a DPO and publish their contact details. Look for this information in the organisation's privacy policy, usually on their website footer or dedicated privacy page.

Step 2: Submit a Written Request

Send a written request to the DPO clearly stating:

  • Your identity (with verification information)
  • The specific right you're exercising (access, correction, withdrawal, etc.)
  • The scope of your request (which data, timeframe, etc.)
  • Your preferred method of response

Step 3: Await Response Within 30 Days

Organisations should respond as soon as reasonably possible. If they cannot respond within 30 days, they must inform you of the expected timeframe. For access requests, they must provide the data or explain why they cannot.

Step 4: Escalate to the PDPC if Necessary

If the organisation refuses your request without valid reason, fails to respond, or you're dissatisfied with their handling, you can file a complaint with the PDPC through their online portal. The PDPC will assess your complaint and may investigate the organisation.

Recent PDPA Amendments You Should Know

The PDPA has evolved significantly since its introduction, with major amendments in 2020 taking full effect in the years since.

Mandatory Data Breach Notification

Organisations must now notify the PDPC of data breaches that result in significant harm or affect 500+ individuals within 72 hours of assessment. Affected individuals must also be notified without undue delay.

Increased Financial Penalties

Maximum financial penalties for serious PDPA breaches were increased to SGD 1 million or 10% of an organisation's annual turnover in Singapore (whichever is higher), aligning Singapore more closely with international standards.

New Consent Frameworks

The amendments introduced two new bases for processing personal data without consent:

  • Legitimate Interests Exception: Organisations can process data if their legitimate interests outweigh any adverse effects on individuals.
  • Business Improvement Exception: Data can be used for internal business improvement purposes without explicit consent.

Deemed Consent by Notification

Organisations can rely on deemed consent by providing notification and a reasonable opt-out period, provided the processing is not expected to have adverse effects on individuals.

Practical Privacy Tips for Singapore Residents

Beyond exercising your PDPA rights, there are practical steps you can take to protect your personal data online.

1. Read Privacy Policies (At Least Skim Them)

Before signing up for services, check what data is collected, how it's used, and whether it's shared with third parties. Look for red flags like broad third-party sharing clauses or indefinite retention periods.

2. Use Privacy-Respecting Tools

When sharing links online, use services that respect your privacy and don't harvest excessive data. For example, when shortening URLs, choose a provider like Lunyb that focuses on clean, secure link management without invasive tracking. You can read our honest Lunyb review or compare options in our 2026 buyer's guide to URL shorteners.

3. Limit Data Sharing on Forms

Only provide the minimum information required. If a field isn't marked as mandatory, consider whether it's really necessary to share.

4. Enable Two-Factor Authentication

Even the strongest privacy laws can't prevent breaches caused by weak account security. Use 2FA on all important accounts, especially banking, email, and government services.

5. Regularly Review Consent Settings

Audit the marketing subscriptions, app permissions, and consent settings you've agreed to over time. Withdraw consent for services you no longer use.

PDPA Obligations for Businesses in Singapore

If you run a business in Singapore, understanding your obligations under the PDPA is critical to avoiding penalties and building customer trust.

Appoint a Data Protection Officer

Every organisation must designate at least one individual as DPO and make their contact details publicly available. The DPO can be an employee or an outsourced service provider.

Develop Written Policies and Practices

Create internal data protection policies, staff training programmes, and procedures for handling access requests, correction requests, and data breaches.

Conduct Data Protection Impact Assessments

Before implementing new systems or processes that involve personal data, conduct a DPIA to identify and mitigate privacy risks.

Implement Reasonable Security Arrangements

Protect personal data through appropriate technical and administrative measures, including encryption, access controls, staff training, and regular security audits.

Frequently Asked Questions About Singapore PDPA Rights

Can I request deletion of my personal data under the PDPA?

The PDPA does not include an explicit "right to erasure" like the GDPR. However, you can withdraw your consent, which requires the organisation to stop collecting, using, or disclosing your data. Organisations are also required to cease retaining data when it's no longer needed for legal or business purposes under the Retention Limitation Obligation.

How long does an organisation have to respond to my access request?

Organisations should respond as soon as reasonably possible, and typically within 30 days. If they cannot meet this timeframe, they must inform you in writing of when a response can be expected. Unreasonable delays can be reported to the PDPC.

What happens if an organisation breaches the PDPA?

The PDPC can impose financial penalties of up to SGD 1 million or 10% of the organisation's annual turnover in Singapore (whichever is higher) for serious breaches. Organisations may also face directions to stop certain practices, publish apologies, or implement remedial measures. Affected individuals may also pursue civil action for damages.

Does the PDPA apply to personal data collected before 2012?

Yes, the PDPA applies to personal data regardless of when it was collected. However, organisations may continue to use pre-existing data for the purposes it was originally collected for, subject to the individual's right to withdraw consent going forward.

Can I file a PDPA complaint anonymously?

The PDPC generally requires complainants to identify themselves so they can investigate properly and communicate outcomes. However, information provided is treated confidentially, and organisations under investigation are not automatically told who filed the complaint. In cases of serious concern, you can also raise issues through whistleblowing channels.

Conclusion

Singapore's PDPA provides a robust framework for protecting personal data while balancing the legitimate needs of businesses to use information for lawful purposes. Your rights under the PDPA — including access, correction, withdrawal of consent, data portability, and breach notification — give you meaningful control over how organisations handle your information.

The key to benefiting from these rights is knowing they exist and being willing to exercise them. Whether you're checking what data a company holds, correcting inaccurate information, or opting out of marketing calls through the DNC Registry, taking action helps maintain a healthy data protection ecosystem in Singapore.

As the digital economy continues to evolve, staying informed about your PDPA rights — and choosing privacy-respecting services for your online activities — remains one of the most powerful tools you have for protecting your personal information in 2026 and beyond.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles