facebook-pixel

Singapore PDPA: Your Personal Data Protection Rights Explained

L
Lunyb Security Team
··10 min read

Singapore's Personal Data Protection Act (PDPA) is the cornerstone of data privacy law in the Republic, giving individuals meaningful control over how organisations collect, use, and disclose their personal information. Whether you're a Singapore resident wondering what happens to your data when you sign up for a service, or a business owner trying to stay compliant, understanding your Singapore PDPA rights is essential in 2026.

This guide breaks down every right you have under the PDPA, explains how to exercise them, and shows what recent amendments mean for you.

What Is the Singapore PDPA?

The Personal Data Protection Act 2012 (PDPA) is Singapore's primary data protection law, administered by the Personal Data Protection Commission (PDPC). It governs how private sector organisations collect, use, disclose, and care for personal data, while balancing individuals' rights against the legitimate needs of businesses.

The PDPA came into full force on 2 July 2014 and has been significantly updated since. The Personal Data Protection (Amendment) Act 2020, which took effect in stages through 2021 and 2022, introduced mandatory data breach notification, higher financial penalties, and new rights like data portability. As of 2026, the PDPA remains one of the most business-friendly yet individual-protective data laws in Asia-Pacific.

Who Does the PDPA Cover?

The PDPA applies to all private sector organisations that collect, use, or disclose personal data in Singapore, regardless of whether the organisation is based in Singapore. Public sector agencies are governed by a separate framework, the Public Sector (Governance) Act.

"Personal data" under the PDPA means data about an identifiable individual — this includes your name, NRIC number, phone number, email address, biometric data, and even data that, combined with other information, could identify you.

Your Core Rights Under the Singapore PDPA

The PDPA gives you nine key rights over your personal data. Each of these rights is enforceable, and organisations must respond to your requests within statutory timeframes.

1. The Right to Be Informed (Notification Obligation)

Before or at the time an organisation collects your personal data, they must inform you of the purposes for which the data will be collected, used, or disclosed. If those purposes change later, they must notify you again and obtain fresh consent.

In practice, this is why you see privacy notices, consent checkboxes, and pop-ups when signing up for services. If a company collects your data without telling you why, they are in breach of the PDPA.

2. The Right to Consent

Organisations generally cannot collect, use, or disclose your personal data without your consent. Consent must be given freely and cannot be a condition of providing a product or service beyond what is reasonable.

There are exceptions — such as legitimate interests, business improvement, legal obligations, and emergencies — but these are narrowly defined. You also cannot be forced to consent to marketing communications as a condition of buying a product.

3. The Right to Withdraw Consent

You can withdraw consent at any time, for any reason, by giving reasonable notice to the organisation. Once you withdraw consent, the organisation must stop collecting, using, or disclosing your data — though they may retain it if required by law.

The organisation must inform you of the likely consequences of withdrawal (for example, they may no longer be able to provide the service). They cannot prohibit withdrawal or charge a fee for processing the request.

4. The Right to Access Your Personal Data

You have the right to request a copy of the personal data an organisation holds about you, as well as information about how it has been used or disclosed in the past year. This is often called a Data Access Request.

Organisations must respond as soon as reasonably possible — typically within 30 days. They may charge a reasonable fee to cover administrative costs, but the fee cannot be excessive. If they cannot respond within 30 days, they must tell you when they will.

5. The Right to Correction

If the personal data an organisation holds about you is inaccurate or incomplete, you can request a correction. The organisation must correct the data as soon as practicable and send the corrected version to every other organisation to which the data was disclosed within the past year (unless you tell them not to).

6. The Right to Data Portability (New)

The Data Portability Obligation, introduced under the 2020 amendments, gives you the right to request that an organisation transmit your data in a commonly used, machine-readable format to another organisation. This makes it easier to switch service providers without losing your data history.

While the provisions are in the Act, the operational rules and prescribed data categories are being rolled out progressively — check the PDPC website for the current scope.

7. The Right to Data Accuracy and Protection

Organisations must make reasonable efforts to ensure your personal data is accurate and complete, and must protect it with reasonable security arrangements. This includes protection against unauthorised access, collection, use, disclosure, copying, modification, or disposal.

8. The Right to Data Breach Notification

Since 1 February 2021, organisations must notify the PDPC and affected individuals of a data breach that results in, or is likely to result in, significant harm — or that involves personal data of 500 or more individuals. Notification to the PDPC must occur within 3 calendar days of determining a notifiable breach.

9. The Right to Opt Out of Marketing (Do Not Call Registry)

The PDPA includes the Do Not Call (DNC) provisions, which allow you to register your Singapore telephone number to opt out of unsolicited marketing calls, SMS, and faxes. Organisations must check the DNC Registry before sending marketing messages, unless they have your clear and unambiguous consent.

How to Exercise Your PDPA Rights: A Step-by-Step Guide

Knowing your rights is one thing — exercising them is another. Here's the practical process for making a request under the PDPA:

  1. Identify the organisation's Data Protection Officer (DPO). Every organisation must appoint a DPO and make their contact details publicly available, usually on the company website or in the privacy policy.
  2. Submit your request in writing. Email is generally accepted. Clearly state what you want (access, correction, withdrawal, portability) and provide enough information to verify your identity.
  3. Wait for the response. Organisations should acknowledge receipt promptly and respond within 30 days. Access requests may involve a reasonable fee.
  4. Escalate if necessary. If the organisation refuses, ignores you, or provides an inadequate response, you can lodge a complaint with the PDPC.
  5. File a complaint with the PDPC. Use the online complaint form at pdpc.gov.sg. Include copies of your original request and any responses.

PDPA vs Other Regional Privacy Laws

Singapore's PDPA sits within a growing patchwork of Asia-Pacific privacy laws. Here's how it compares to a few major frameworks:

FeatureSingapore PDPAEU GDPRHong Kong PDPOAustralia Privacy Act
Right to accessYesYesYesYes
Right to erasureLimited (via consent withdrawal)Yes (right to be forgotten)No explicit rightLimited
Data portabilityYes (being phased in)YesNoSector-specific
Breach notificationYes (within 3 days)Yes (within 72 hours)VoluntaryYes (as soon as practicable)
Maximum fineUp to S$1M or 10% of annual turnover€20M or 4% of global turnoverHK$1MA$50M+ (updated 2022)
Do Not Call registryYesNo (opt-in consent instead)No (separate rules)Yes

Enforcement and Penalties Under the PDPA

The 2020 amendments significantly increased the financial penalties for PDPA breaches. As of 1 October 2022, the PDPC can impose fines of up to S$1 million, or 10% of an organisation's annual turnover in Singapore (whichever is higher) for organisations with turnover exceeding S$10 million.

Beyond fines, the PDPC can also issue directions to stop collecting, using, or disclosing data, order the destruction of unlawfully collected data, and require organisations to publish their enforcement decisions. Individuals can also bring private civil actions for damages if they suffer loss due to a PDPA breach.

Notable Enforcement Cases

Recent enforcement highlights include large fines against major consumer platforms and telcos for inadequate data protection controls, particularly around credential stuffing attacks, insecure APIs, and third-party vendor breaches. The PDPC regularly publishes its decisions online, and reading them is one of the best ways to understand how the law is applied in practice.

Practical Tips to Protect Your Personal Data in Singapore

Legal rights only get you so far — proactive habits matter too. Here are practical steps every Singaporean can take:

  • Register on the DNC Registry. Visit dnc.gov.sg and register your mobile number for all three lists (calls, SMS, fax).
  • Read privacy notices before consenting. Look specifically for third-party sharing clauses and marketing opt-ins.
  • Use privacy-focused tools for link sharing. When you shorten or share URLs, choose services that don't harvest excessive analytics on the people clicking. Lunyb, for example, offers link shortening with a privacy-conscious approach — useful when you want a clean short link without exposing recipients to heavy tracking.
  • Enable two-factor authentication. Even the best PDPA compliance can't protect an account with a weak password.
  • Check what data services hold on you. Send annual data access requests to your most-used platforms. It's an eye-opening exercise.
  • Use encrypted DNS and privacy-respecting browsers. Network-level protections like DNS over HTTPS reduce how much of your browsing metadata is exposed.

For Businesses: Staying PDPA Compliant

If you operate a business in Singapore, PDPA compliance is not optional. At minimum you should appoint and publish a DPO, maintain a written data protection policy, implement reasonable security arrangements, keep records of consent, have a breach response plan, and train staff on data handling.

For marketing teams that rely on shortened links for campaigns, choosing tools that align with your data protection posture matters. If you're evaluating shortening platforms, our guides on the best URL shorteners reviewed and compared and our Rebrandly review for 2026 break down what each platform collects and how they handle data. You may also find our honest review of Lunyb useful when comparing options.

What's Next for the PDPA?

The PDPC continues to refine the framework, with ongoing work on the Data Portability Obligation's operational scope, updated advisory guidelines for AI systems handling personal data, and stronger cross-border data transfer rules aligned with the ASEAN Model Contractual Clauses. Expect continued convergence with global standards like GDPR, particularly around automated decision-making and profiling.

For individuals, the trajectory is clear: more rights, faster breach notifications, and stronger enforcement. For organisations, the message is equally clear: treat data protection as a core business function, not an afterthought.

Frequently Asked Questions

How long does an organisation have to respond to a PDPA access request?

Organisations must respond as soon as reasonably possible, and generally within 30 days of receiving the request. If they cannot meet the deadline, they must inform you in writing of when they will be able to respond. Unreasonable delays can be reported to the PDPC.

Can I request deletion of my personal data under the Singapore PDPA?

The PDPA does not include an explicit "right to be forgotten" like the GDPR. However, you can achieve a similar outcome by withdrawing consent — after which the organisation must stop using your data and, in most cases, cease retention unless required by law. You can also request correction if data is inaccurate.

What counts as personal data under the PDPA?

Personal data means data about an individual who can be identified from that data, or from that data combined with other information the organisation has or is likely to have access to. This includes obvious identifiers like your name and NRIC, but also things like IP addresses, device identifiers, and biometric data when linked to an identifiable person.

How do I file a PDPA complaint with the PDPC?

First, try to resolve the issue directly with the organisation's Data Protection Officer. If that fails, visit pdpc.gov.sg and submit a complaint through the online form. Include copies of your original request, the organisation's response (if any), and any supporting documents. The PDPC will typically ask for evidence that you attempted to resolve the matter first.

Does the PDPA apply to overseas companies serving Singapore customers?

Yes. The PDPA applies to any organisation that collects, uses, or discloses personal data in Singapore, regardless of whether the organisation itself is based here. Overseas companies with Singapore users must comply, and the PDPC has taken enforcement action against foreign entities in the past.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles