facebook-pixel

Singapore PDPA: Your Personal Data Protection Rights Explained

L
Lunyb Security Team
··10 min read

Singapore's Personal Data Protection Act (PDPA) is the cornerstone of how personal information is handled in the Lion City. Whether you're a resident wondering what happens to your data when you sign up for a loyalty programme, or a business owner navigating compliance, understanding your PDPA rights is essential. This guide breaks down every right the law grants you, how to exercise them, and what recent updates mean for you in 2026.

What Is the Singapore PDPA?

The Personal Data Protection Act (PDPA) is Singapore's primary data protection law, enacted in 2012 and enforced by the Personal Data Protection Commission (PDPC). It governs how organisations collect, use, disclose, and care for personal data, while giving individuals specific rights over their information.

The PDPA applies to all private-sector organisations operating in Singapore, regardless of whether the organisation itself is based locally. Public agencies are governed by a separate framework, the Public Sector (Governance) Act. Since major amendments in 2020 and further guidance issued through 2024–2025, the PDPA has evolved to include mandatory data breach notification, enhanced consent frameworks, and stricter financial penalties.

Who Does the PDPA Protect?

The PDPA protects any individual whose personal data is collected, used, or disclosed by an organisation in Singapore. "Personal data" is defined broadly: any data — true or false — about an identifiable individual, whether the data alone or combined with other information the organisation has access to.

Examples include your NRIC number, mobile phone number, email address, biometric data, financial records, and even behavioural data like your browsing habits when linked to your identity.

Your Core PDPA Rights as an Individual

The PDPA gives Singapore residents and anyone whose data is processed by Singapore-based organisations several enforceable rights. These rights form the backbone of the law's individual-centric approach.

1. The Right to Be Informed (Notification Obligation)

Before or at the point of collecting your personal data, an organisation must inform you of the purposes for collection, use, and disclosure. This isn't optional — it's a legal requirement. If a company wants to use your data for a new purpose later, they must notify you and obtain fresh consent unless an exception applies.

2. The Right to Consent (and Withdraw It)

Consent is central to the PDPA. Organisations generally cannot collect, use, or disclose your personal data without your consent. Equally important, you have the right to withdraw consent at any time by giving reasonable notice. Once you withdraw consent, the organisation must stop using your data for those purposes and inform you of the likely consequences (for example, being unable to continue receiving a service).

3. The Right of Access

You can request that an organisation provide you with:

  1. The personal data they hold about you.
  2. Information about how your data has been used or disclosed within the past 12 months.

The organisation must respond within 30 days. If they cannot meet this timeline, they must inform you in writing and provide the data as soon as reasonably possible. A reasonable fee may be charged, but it cannot be excessive.

4. The Right of Correction

If you discover that an organisation holds inaccurate or incomplete data about you, you can request a correction. The organisation must correct the data as soon as practicable and send the corrected data to every other organisation to which the original data was disclosed within the past 12 months — unless you consent otherwise.

5. The Right to Data Portability (New in 2021, Fully Operational)

Under amendments introduced in 2020 and being progressively operationalised, you have the right to request that an organisation transmit your personal data (in a commonly used machine-readable format) to another organisation. This is particularly relevant for banking, telecommunications, and utility services, giving you greater freedom to switch providers.

6. The Right to Be Notified of Data Breaches

Since 1 February 2021, organisations are legally required to notify the PDPC and affected individuals of any data breach that is likely to result in significant harm to individuals, or that involves 500 or more affected individuals. Notification must happen within 3 calendar days to the PDPC.

PDPA Rights at a Glance

RightWhat It MeansOrganisation's Deadline
NotificationBe informed of collection purposesAt or before collection
Consent / WithdrawalGrant or revoke consent for data useImmediate cessation upon withdrawal
AccessObtain a copy of your dataWithin 30 days
CorrectionFix inaccurate dataAs soon as practicable
Data PortabilityTransfer data to another organisationReasonable timeframe (guidelines pending full operation)
Breach NotificationBe alerted to significant breachesWithout undue delay after PDPC notified

How to Exercise Your PDPA Rights

Knowing your rights is only useful if you can act on them. Here's a step-by-step process for exercising any PDPA right.

Step 1: Identify the Data Protection Officer (DPO)

Every organisation in Singapore must appoint a DPO and publish their contact details. Look for this on the organisation's website, usually in the privacy policy or a dedicated "Contact Us" section.

Step 2: Submit a Written Request

Send a clear, written request via email or an online form. Include:

  1. Your full name and contact details.
  2. Verification of identity (as required by the organisation).
  3. A specific description of the right you're exercising (access, correction, withdrawal, etc.).
  4. The scope of data or timeframe involved, if relevant.

Step 3: Await a Response

The organisation must respond within 30 days for access requests, or as soon as practicable for corrections and consent withdrawals. If they refuse, they must explain why in writing.

Step 4: Escalate to the PDPC

If the organisation fails to comply or you're dissatisfied with the response, you can lodge a complaint with the Personal Data Protection Commission. The PDPC can investigate, issue directions, and impose financial penalties.

Financial Penalties Under the PDPA

The 2020 amendments significantly increased the maximum financial penalty for breaches. As of 1 October 2022, organisations with annual turnover in Singapore exceeding S$10 million can be fined up to 10% of that turnover, or S$1 million — whichever is higher. Smaller organisations face a maximum penalty of S$1 million.

Recent enforcement actions have shown the PDPC's willingness to impose substantial fines on companies that fail to protect customer data, particularly in sectors handling large volumes of sensitive information such as healthcare, e-commerce, and telecommunications.

Special Categories: Do Not Call Registry and Marketing

The PDPA also governs the Do Not Call (DNC) Registry, which allows Singapore telephone subscribers to opt out of receiving marketing messages, calls, and faxes. Organisations must check the DNC Registry before sending marketing communications to any Singapore number, unless they have clear and unambiguous consent.

Registering with the DNC

You can register your Singapore mobile or landline number free of charge at the DNC Registry website. Registration takes effect within 30 days, after which most unsolicited marketing communications should stop. Violations by organisations can result in significant fines.

PDPA and Overseas Data Transfers

When a Singapore organisation transfers your personal data outside the country, they must ensure the receiving country provides a comparable standard of protection. This is known as the Transfer Limitation Obligation. Common mechanisms include contractual clauses, binding corporate rules, and certification schemes.

As a data subject, you have the right to ask an organisation how they safeguard your data during overseas transfers. If they cannot provide a satisfactory answer, this may itself be a PDPA violation.

Protecting Yourself Beyond the PDPA

While the PDPA gives you strong legal rights, proactive digital hygiene is equally important. Here are practical steps every Singapore resident should consider:

  1. Minimise data sharing: Only provide personal information when strictly necessary. Question why a merchant needs your NRIC number for a simple transaction.
  2. Use privacy-focused tools: Encrypted messaging apps, private DNS resolvers, and browsers with strong tracking protection reduce the data trail you leave behind.
  3. Audit app permissions: Review permissions granted to mobile apps every few months. Revoke access that isn't essential.
  4. Shorten and mask sensitive links: When sharing links containing tracking parameters or affiliate tags, use a trusted shortener like Lunyb to strip identifying query strings and gain analytics without exposing personal data. Learn more in our honest review of Lunyb.
  5. Monitor breach notifications: Use services like HaveIBeenPwned to check whether your email has appeared in known breaches.
  6. Enable two-factor authentication: Especially on Singpass, banking, and email accounts.

PDPA for Businesses: Compliance Essentials

If you run a business in Singapore, PDPA compliance isn't optional. Beyond the individual rights above, organisations must fulfil 11 main data protection obligations, including consent, purpose limitation, accuracy, protection, retention limitation, and accountability.

Key Compliance Checklist for Businesses

  1. Appoint a Data Protection Officer and publish their contact details.
  2. Develop and publish a clear privacy policy.
  3. Train staff on PDPA obligations and breach response.
  4. Implement technical safeguards: encryption, access controls, secure disposal.
  5. Maintain a data inventory and retention schedule.
  6. Establish a breach response plan aligned with the 3-day PDPC notification window.
  7. Review contracts with data intermediaries and overseas processors.

For link-based marketing campaigns, choose tools that treat data responsibly. Compare options in our 2026 URL shortener buyer's guide, or read our Rebrandly review to understand how enterprise-grade shorteners handle click data.

Recent PDPA Developments in 2024–2026

The PDPC has continued to refine the PDPA framework with new guidelines on:

  • Generative AI and personal data: Advisory guidelines released in 2024 clarify how organisations should handle personal data when training or deploying AI models.
  • Children's personal data: Enhanced expectations around obtaining parental consent for users under 13.
  • Deemed consent by notification: A refined framework allowing organisations to rely on deemed consent under specific circumstances, provided they conduct a risk assessment.
  • Legitimate interests exception: Businesses can now process personal data for legitimate interests without consent, subject to a balancing test.

Frequently Asked Questions

Does the PDPA apply to me if I'm not a Singapore citizen?

Yes. The PDPA protects any individual whose personal data is collected, used, or disclosed by an organisation in Singapore, regardless of your nationality or residency status. If you gave your data to a Singapore-based business, you have PDPA rights.

How long do organisations have to respond to my data access request?

Organisations must respond within 30 calendar days. If they cannot meet this deadline, they must inform you in writing of the reason and provide the data as soon as reasonably possible.

Can I sue an organisation for a PDPA breach?

Yes. Under Section 48O of the PDPA, individuals who suffer loss or damage directly as a result of a PDPA contravention have a private right of action to seek civil remedies, including damages, injunctions, or declarations, once the PDPC has made a decision on the matter.

What's the difference between the PDPA and GDPR?

Both laws protect personal data, but the GDPR (European Union) is generally broader in scope, imposes stricter consent requirements, and carries higher maximum penalties (up to 4% of global turnover). The PDPA is more business-friendly in areas like deemed consent and legitimate interests, but has strengthened significantly since 2020.

Is my NRIC number protected under the PDPA?

Yes, and it receives special treatment. Since 1 September 2019, organisations are generally prohibited from collecting, using, or disclosing NRIC numbers (or copies of the NRIC) except where required by law or necessary to accurately establish or verify an individual's identity to a high degree of fidelity.

Conclusion

Singapore's PDPA gives you meaningful control over your personal data — the rights to know, access, correct, withdraw, port, and be notified. But rights only work when you use them. Take a few minutes today to review the privacy policies of services you use most, register with the Do Not Call Registry if you haven't already, and set a calendar reminder to audit your digital footprint quarterly.

For businesses, PDPA compliance is both a legal obligation and a trust-building opportunity. Organisations that treat personal data with genuine care don't just avoid fines — they earn customer loyalty in an increasingly privacy-conscious market.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles