facebook-pixel

Singapore PDPA: Your Personal Data Protection Rights Explained

L
Lunyb Security Team
··12 min read

Singapore's Personal Data Protection Act (PDPA) is the country's cornerstone privacy law, giving individuals meaningful control over how organisations collect, use, and disclose their personal data. Whether you're a Singapore resident, a foreigner living here, or a business owner trying to stay compliant, understanding your PDPA rights is essential in an era where data breaches, targeted advertising, and unsolicited marketing calls have become everyday concerns.

This comprehensive guide breaks down every right the PDPA grants you, how to exercise those rights, what obligations organisations have, and what happens when things go wrong. By the end, you'll know exactly what to do when a company mishandles your data or refuses your request.

What Is the Singapore PDPA?

The Personal Data Protection Act 2012 is Singapore's primary data protection law, administered by the Personal Data Protection Commission (PDPC). It governs how private-sector organisations collect, use, disclose, and care for personal data, and it also includes the Do Not Call (DNC) Registry provisions that limit telemarketing.

The PDPA came into full force on 2 July 2014, and it was significantly updated by the Personal Data Protection (Amendment) Act 2020, which introduced mandatory breach notification, a data portability right, and stiffer financial penalties. As of 2026, the maximum financial penalty for serious breaches is up to 10% of an organisation's annual turnover in Singapore (or S$1 million, whichever is higher).

Who Does the PDPA Apply To?

The PDPA applies to all private-sector organisations that collect, use, or disclose personal data in Singapore, regardless of whether the organisation is formed or resident in Singapore. Public agencies are covered by a separate framework (the Public Sector Governance Act).

  • Local companies, sole proprietors, and partnerships
  • Foreign companies handling data of individuals in Singapore
  • Data intermediaries processing data on behalf of others
  • Non-profit organisations and clubs (with some carve-outs)

What Counts as Personal Data?

Personal data is any data, true or not, about an individual who can be identified from that data, or from that data combined with other information the organisation has or is likely to have access to. Examples include:

  • Full name, NRIC/FIN, passport number
  • Home address, personal phone number, email
  • Photographs, video footage, voice recordings
  • Biometric data, medical records, financial information
  • Employee records and CV details

Your Core Rights Under the Singapore PDPA

The PDPA grants individuals several enforceable rights over their personal data. Below is a breakdown of each core right and what it means in practice.

1. The Right to Be Informed (Notification Obligation)

Before an organisation collects your personal data, it must inform you of the purposes for which it will be collected, used, or disclosed. This is often done through a privacy notice or consent form. You cannot give meaningful consent if you don't know what you're consenting to.

2. The Right to Consent (and Withdraw It)

Organisations generally need your consent to collect, use, or disclose your personal data. Consent must be freely given, specific, and informed. Crucially, you have the right to withdraw consent at any time by giving reasonable notice.

Once you withdraw consent, the organisation must stop collecting, using, or disclosing your data for those purposes, and it must inform you of the likely consequences (for example, you may no longer be able to use a service).

3. The Right of Access

You have the right to request a copy of the personal data an organisation holds about you, along with information about how it has been used or disclosed within the past year. Organisations must respond as soon as reasonably possible, typically within 30 days.

A reasonable fee may be charged, but it should not be excessive. If the organisation cannot respond within 30 days, it must notify you of the timeframe by which it will respond.

4. The Right of Correction

If you find that data an organisation holds about you is inaccurate or incomplete, you can request a correction. The organisation must correct the data as soon as practicable and send the corrected data to every other organisation to which it disclosed the data within the past year (unless you consent otherwise).

5. The Right to Data Portability (New Under 2020 Amendments)

Once fully operationalised, the data portability right will allow you to request that an organisation transmit your data in a commonly used machine-readable format to another organisation. This makes it easier to switch banks, telcos, or service providers without losing your history.

6. The Right to Be Free From Unsolicited Marketing

Under the Do Not Call (DNC) Registry provisions, you can register your Singapore telephone number to block telemarketing calls, texts, and faxes. Organisations must check the DNC Registry before sending marketing messages unless they have your clear and unambiguous consent.

7. The Right to Breach Notification

Since 1 February 2021, organisations are required to notify the PDPC and affected individuals of data breaches that result in, or are likely to result in, significant harm to affected individuals, or that involve the personal data of 500 or more individuals.

Obligations Organisations Must Follow

The PDPA sets out nine main obligations for organisations. Understanding these helps you know when your rights are being violated.

ObligationWhat It Requires
ConsentObtain valid consent before collecting, using, or disclosing personal data.
Purpose LimitationOnly collect data for purposes a reasonable person would consider appropriate.
NotificationInform individuals of the purposes of collection, use, and disclosure.
Access & CorrectionProvide access and correct data on request.
AccuracyMake reasonable efforts to ensure personal data is accurate and complete.
ProtectionProtect data with reasonable security arrangements.
Retention LimitationCease retention of data when no longer needed.
Transfer LimitationTransfer data overseas only if comparable protection is ensured.
AccountabilityAppoint a Data Protection Officer (DPO) and implement policies.

How to Exercise Your PDPA Rights: A Step-by-Step Guide

Knowing your rights is one thing; enforcing them is another. Here's a practical process for making a PDPA request.

  1. Identify the organisation's Data Protection Officer (DPO). Every organisation must designate a DPO and make their contact details publicly available, usually on the company website or in the privacy policy.
  2. Submit a written request. Send an email or letter clearly stating what you want: access, correction, withdrawal of consent, or another right. Be specific about the data and time period.
  3. Include verification details. The organisation is entitled to verify your identity before releasing data, so provide reasonable proof (but never send your full NRIC image unless legally required).
  4. Wait for the response. Organisations should respond within 30 days. If they need more time, they must tell you when to expect a reply.
  5. Escalate if necessary. If the organisation refuses or ignores you, you can file a complaint with the PDPC.

Sample PDPA Access Request

A short, effective request might read:

"Dear [DPO Name], under the Personal Data Protection Act 2012, I am requesting a copy of all personal data your organisation holds about me, along with details of how it has been used or disclosed in the past 12 months. My details for verification are [name, registered email/phone]. Please respond within 30 days."

When Consent Is Not Required

The PDPA recognises that consent isn't always practical or appropriate. There are several exceptions where organisations may collect, use, or disclose data without your consent, including:

  • Legitimate interests that outweigh any adverse effect on the individual (with an assessment)
  • Business improvement purposes, such as improving products or understanding customer needs
  • Publicly available data
  • Legal or regulatory requirements (e.g., anti-money-laundering checks)
  • Emergencies where life or health is threatened
  • Employment-related purposes for managing employees

Even under these exceptions, organisations must still comply with the accountability, protection, and retention obligations.

The Do Not Call Registry: Blocking Marketing Calls

The DNC Registry is one of the most-used features of the PDPA. Anyone with a Singapore-registered phone number can add it to one or more of the three DNC lists:

  • No Voice Call Register
  • No Text Message Register
  • No Fax Message Register

Registration is free and takes effect within 21 days. Once registered, organisations must not send marketing messages to that number unless you have provided clear and unambiguous consent in writing or another accessible form.

Penalties for Non-Compliance

Since the 2020 amendments came into effect, the PDPC has significant enforcement powers.

Type of BreachMaximum Penalty (2026)
Serious data breach (large organisations)Up to 10% of annual Singapore turnover
Serious data breach (smaller organisations)Up to S$1 million
DNC Registry breachUp to S$200,000 per case (organisations)
Individual liability for egregious mishandlingFines and/or imprisonment up to 3 years

The PDPC also publishes decisions publicly, so reputational damage is often as significant as the financial penalty itself.

Protecting Your Data in Everyday Life

Knowing your rights is only half the battle. Practical steps go a long way toward keeping your personal data safe.

Reduce Your Digital Footprint

Every form you fill in, every loyalty programme you join, and every link you click contributes to your data trail. Before sharing personal details, ask whether the organisation actually needs them. Use secondary email addresses for sign-ups where possible.

Be Careful With Links You Share

Long tracking-heavy URLs can leak personal identifiers, session tokens, or affiliate data. If you share links regularly — whether for work, marketing, or personal use — consider a privacy-respecting shortener like Lunyb, which lets you clean up URLs without the aggressive tracking baked into some competitors. You can see how it compares in our 2026 URL shortener buyer's guide or read our honest Lunyb review.

Review App Permissions

Mobile apps often request more permissions than they need. Periodically audit which apps have access to your contacts, location, microphone, and camera, and revoke anything unnecessary.

Use Strong, Unique Passwords

A password manager combined with two-factor authentication drastically reduces the risk of credential stuffing attacks, which remain a leading cause of data breaches reported to the PDPC.

Watch for Phishing Impersonating PDPA Requests

Scammers sometimes send fake "PDPA verification" emails claiming your data will be deleted unless you click a link. Legitimate organisations never ask for your password or full NRIC via email.

Filing a Complaint With the PDPC

If an organisation ignores or unreasonably denies your PDPA request, you can escalate to the PDPC.

  1. Attempt resolution directly. The PDPC expects you to have engaged the organisation first.
  2. Gather evidence. Keep copies of emails, request timestamps, and any responses received.
  3. Submit a complaint online via the PDPC website, providing details of the organisation, the nature of the breach, and any evidence.
  4. Consider dispute resolution. Since 2020, the PDPC has offered mediation and other alternative dispute resolution paths.
  5. Private right of action. Under Section 48O, you may bring a civil claim if you suffer loss or damage directly from a PDPA contravention.

PDPA vs. GDPR: How Singapore Compares

Singapore's PDPA is often compared to the EU's General Data Protection Regulation (GDPR). Both share common principles but differ in scope and stringency.

FeatureSingapore PDPAEU GDPR
Consent standardDeemed and express consent both allowedExplicit, unambiguous consent
Right to erasureLimited (via withdrawal of consent)Explicit "right to be forgotten"
Data portabilityIntroduced, being operationalisedFully in force
Max penalty10% of Singapore turnover or S$1M4% of global turnover or €20M
Breach notificationMandatory since Feb 2021Mandatory within 72 hours
Extraterritorial reachApplies to overseas orgs handling SG dataApplies to overseas orgs handling EU data

What's Next for the PDPA?

The PDPC continues to update guidelines to keep pace with technology. Recent and upcoming focus areas include:

  • AI and personal data: Guidance on using personal data to train and deploy AI systems responsibly
  • Children's data: Enhanced protections for minors online
  • Cross-border data flows: Alignment with ASEAN Model Contractual Clauses and APEC CBPR
  • Biometric and health data: Stricter expectations around sensitive categories

Frequently Asked Questions

Can foreigners in Singapore exercise PDPA rights?

Yes. The PDPA protects personal data of individuals in Singapore regardless of their nationality or residency status. If your data is being handled by an organisation subject to the PDPA, you can exercise the same rights as a citizen.

How long does an organisation have to respond to my PDPA request?

Organisations must respond "as soon as reasonably possible," which the PDPC generally interprets as within 30 days. If they need longer, they must tell you the timeframe within which they'll respond and the reason for the delay.

Can I request deletion of my data under the PDPA?

The PDPA does not have an explicit "right to erasure" like the GDPR. However, you can withdraw consent, which effectively forces the organisation to stop using your data. Under the Retention Limitation Obligation, organisations must also cease retaining data once it's no longer needed for the original purpose.

What should I do if my data is breached?

If you're notified of a breach (or suspect one), change any affected passwords immediately, enable two-factor authentication, monitor your financial accounts, and consider filing a complaint with the PDPC if you believe the organisation didn't adequately protect your data. You may also have grounds for a private civil claim if you suffered loss.

Does the PDPA apply to my personal social media activity?

The PDPA generally does not apply to individuals acting in a personal or domestic capacity. However, if you're using social media for business purposes — such as running an online shop or professional influencer account — the PDPA obligations may apply to how you handle other people's data.

Final Thoughts

The Singapore PDPA gives you real, enforceable rights over your personal data — but those rights are only as strong as your willingness to exercise them. Whether you're requesting access to your records, correcting inaccurate information, or reporting an organisation that ignored your rights, being informed is your best defence.

Combine your legal rights with practical privacy habits — minimising the data you share, using privacy-respecting tools, and staying alert to phishing — and you'll have a robust personal data protection strategy that goes well beyond simply hoping organisations do the right thing.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles