facebook-pixel

Singapore PDPA: Your Personal Data Protection Rights Explained

L
Lunyb Security Team
··11 min read

Singapore's Personal Data Protection Act (PDPA) is the cornerstone of how personal information is collected, used, and disclosed across the country. Whether you're a consumer wondering what a company can legally do with your data, or a business owner trying to stay compliant, understanding your PDPA rights is essential in 2026. This guide breaks down the law in plain language, explains each right you have as an individual, and shows how to exercise them effectively.

What Is the Singapore PDPA?

The Personal Data Protection Act (PDPA) is Singapore's primary data protection law, enacted in 2012 and enforced by the Personal Data Protection Commission (PDPC). It governs how private sector organisations collect, use, disclose, and safeguard personal data belonging to individuals in Singapore.

The PDPA applies to any organisation operating in Singapore, regardless of where it is headquartered, and covers personal data in both electronic and non-electronic forms. Since major amendments in 2020 and updates that continue to roll out, the law now includes mandatory data breach notification, enhanced consent frameworks, and stricter financial penalties—up to 10% of annual turnover in Singapore for large organisations.

Who the PDPA Protects

The PDPA protects any identifiable individual whose personal data is held by an organisation. Personal data includes names, NRIC numbers, phone numbers, email addresses, financial details, biometric data, and any other information that can identify a person on its own or when combined with other data.

Who the PDPA Applies To

The Act applies to all private sector organisations, including sole proprietors, partnerships, companies, associations, and charities. Public agencies are covered under separate but similar rules through the Public Sector (Governance) Act. Certain categories, such as business contact information used strictly for business purposes, are exempt from some obligations.

The Core Obligations Behind Your Rights

Before diving into individual rights, it helps to understand the nine main obligations the PDPA places on organisations. These obligations are what create your rights as a data subject.

  1. Consent Obligation — Organisations must obtain your consent before collecting, using, or disclosing your personal data.
  2. Purpose Limitation Obligation — Data can only be used for purposes a reasonable person would consider appropriate and that you were informed about.
  3. Notification Obligation — You must be told why your data is being collected before or at the time of collection.
  4. Access and Correction Obligation — You have the right to see and correct your data.
  5. Accuracy Obligation — Organisations must ensure your data is accurate and complete.
  6. Protection Obligation — Reasonable security arrangements must be in place.
  7. Retention Limitation Obligation — Data must not be kept longer than necessary.
  8. Transfer Limitation Obligation — Transferring data overseas requires comparable protection standards.
  9. Data Breach Notification Obligation — Serious breaches must be reported to the PDPC and affected individuals.

Your Personal Data Protection Rights Under the PDPA

The PDPA grants individuals in Singapore several enforceable rights over their personal data. Below is a breakdown of each one and how it works in practice.

1. The Right to Be Informed

Before an organisation collects your personal data, it must tell you the purposes for which the data will be collected, used, or disclosed. This is typically communicated through a privacy notice or data protection policy on a website, app, or physical form.

If a new purpose arises later, the organisation must notify you again and, in most cases, obtain fresh consent.

2. The Right to Give and Withdraw Consent

Consent is the foundation of PDPA compliance. Organisations must obtain your consent before collecting, using, or disclosing your data, except in limited situations covered by exceptions such as legitimate interests or legal obligations.

Equally important, you can withdraw consent at any time by giving reasonable notice. Once you withdraw, the organisation must stop collecting, using, or disclosing your data for the affected purposes—though they may retain some data if required by law.

3. The Right of Access

You have the right to request access to personal data an organisation holds about you and information about how that data has been used or disclosed in the past year. Organisations must respond within a reasonable time (typically 30 days) and may charge a small fee for retrieval costs.

There are exceptions: an organisation can refuse if disclosure would threaten someone else's safety, reveal confidential business information, or compromise an ongoing investigation.

4. The Right to Correction

If your personal data is inaccurate or incomplete, you can request that it be corrected. The organisation must correct the data as soon as practicable and inform any third parties to which the incorrect data was disclosed within the past year, unless you consent to skip this step.

5. The Right to Data Portability (Coming Into Force)

The 2020 amendments introduced a Data Portability Obligation, which allows individuals to request that their data be transmitted directly to another organisation in a commonly used machine-readable format. While implementation details continue to evolve, once fully enforced this right will make it easier for you to switch service providers without losing your data history.

6. The Right to Be Notified of Data Breaches

Under the Data Breach Notification Obligation, organisations must notify the PDPC and affected individuals when a breach is likely to result in significant harm or affects 500 or more individuals. Notifications must generally happen within 72 hours of assessing the breach as notifiable.

7. The Right to Protection From Unsolicited Marketing

The Do Not Call (DNC) Registry, administered under the PDPA, lets you opt out of marketing calls, text messages, and faxes from Singapore telephone numbers. Once you register, organisations must check the registry before sending marketing messages, with limited exceptions for existing customer relationships.

8. The Right to Lodge a Complaint

If you believe your PDPA rights have been violated, you can file a complaint with the PDPC. The Commission has the power to investigate, issue directions, and impose financial penalties. You may also pursue civil action in court for damages if you suffer loss as a result of a breach.

How to Exercise Your PDPA Rights: A Step-by-Step Guide

Knowing your rights is only half the battle. Here's how to actually put them into action.

  1. Identify the organisation's Data Protection Officer (DPO). Every organisation must appoint a DPO whose contact details should be publicly available, often on the company website's privacy policy page.
  2. Submit a written request. For access, correction, or withdrawal of consent, send an email or letter clearly stating what you want. Include enough detail to identify the specific data (dates, account numbers, transaction references).
  3. Wait for a response. Organisations should acknowledge within 30 days. If they cannot respond within that period, they must inform you of the reason and provide a revised timeline.
  4. Pay any reasonable fee. Access requests may involve a nominal charge. The organisation must give you an estimate before proceeding.
  5. Escalate if necessary. If the response is unsatisfactory or ignored, file a complaint with the PDPC via their official complaint form.

PDPA Rights vs Other Major Privacy Laws

How does Singapore's PDPA compare with other well-known frameworks? The table below highlights key differences.

Right / FeatureSingapore PDPAEU GDPRCalifornia CCPA/CPRA
Right to accessYesYesYes
Right to correctionYesYesYes
Right to erasure (deletion)Limited (via withdrawal)YesYes
Right to data portabilityBeing phased inYesYes
Breach notification window72 hours (if notifiable)72 hoursWithout unreasonable delay
Maximum penaltyUp to 10% of SG turnoverUp to 4% of global turnoverUp to USD 7,500 per violation
Do Not Call registryYesNo equivalentNo equivalent

Common Scenarios Where PDPA Rights Matter

Scenario 1: Marketing Spam From a Retailer

You bought something once from an online store and now receive daily promotional emails. Under the PDPA, you can withdraw consent for marketing communications. The retailer must honour your request and confirm compliance, typically within a reasonable timeframe.

Scenario 2: Inaccurate Credit Record

You notice that a financial institution has incorrect employment information on file. You can invoke the Correction Obligation and require them to update the record and inform any credit bureaus they shared the data with.

Scenario 3: Data Breach at a Service Provider

If a company you use suffers a breach affecting your data, they must notify you if the breach is likely to cause significant harm. You can then take steps such as changing passwords, monitoring accounts, or freezing credit.

Scenario 4: Requesting Your Data Before Switching Providers

Planning to move to a competitor? You can submit an access request to get a copy of your data, including transaction history and preferences, to make the switch smoother.

Practical Tips to Protect Your Personal Data in Singapore

Beyond exercising your legal rights, you can take proactive steps to reduce data exposure.

  • Read privacy notices carefully. Before signing up, understand what data is collected and for what purposes.
  • Use privacy-friendly tools. Encrypted DNS, private browsers, and secure messaging apps limit how much data third parties can harvest. For safer link sharing, a privacy-conscious URL shortener like Lunyb lets you share links without exposing full destination URLs or tracking parameters.
  • Register on the Do Not Call Registry. A free, quick way to reduce unwanted marketing calls and texts.
  • Use unique passwords and two-factor authentication. Even the strongest privacy law cannot protect data that is stolen through account takeovers.
  • Audit app permissions regularly. Mobile apps often request more data than they need. Revoke unnecessary permissions.
  • Be cautious with public Wi-Fi. Avoid entering sensitive information over unsecured networks.

For businesses handling links and campaign data, tools like Lunyb or established platforms reviewed in our 2026 URL shortener buyer's guide can help you maintain PDPA-aligned data handling practices while still tracking what matters.

What Businesses Should Do to Respect PDPA Rights

If you run a business in Singapore, respecting PDPA rights is not optional—it is a legal duty backed by significant penalties.

  1. Appoint a Data Protection Officer. Every organisation must have one, and their contact must be publicly available.
  2. Publish a clear privacy policy. Explain what data you collect, why, how long you keep it, and how individuals can exercise their rights.
  3. Implement consent management. Track when and how consent was obtained, and provide easy withdrawal mechanisms.
  4. Train your staff. Human error causes most breaches. Regular training on PDPA obligations is essential.
  5. Have an incident response plan. Be ready to assess and report breaches within the 72-hour window.
  6. Review vendor contracts. Any third party processing data on your behalf must offer equivalent protection.

Pros and Cons of the Singapore PDPA Framework

Pros

  • Clear, principle-based obligations that are easier to interpret than more prescriptive regimes.
  • The Do Not Call Registry offers strong, tangible protection against telemarketing.
  • Recent amendments align Singapore closer to global standards like the GDPR.
  • Financial penalties are meaningful enough to drive compliance.
  • The PDPC actively publishes guidance, decisions, and educational materials.

Cons

  • No explicit "right to erasure" as robust as under the GDPR.
  • Data portability implementation has been slower than anticipated.
  • Enforcement, while improving, still lags behind the volume of breaches reported.
  • Small businesses often struggle with the resources needed for full compliance.

Frequently Asked Questions

What is the maximum penalty for a PDPA violation in Singapore?

Since October 2022, organisations with annual turnover in Singapore exceeding SGD 10 million can face fines of up to 10% of their annual Singapore turnover. Smaller organisations face a maximum fine of SGD 1 million. Individuals responsible for offences can also face personal penalties.

Can I request deletion of my personal data under the PDPA?

The PDPA does not include a standalone "right to erasure" like the GDPR. However, you can withdraw consent, which effectively requires organisations to stop using your data. They must also delete data that is no longer needed for the purpose it was collected, under the Retention Limitation Obligation.

How long does an organisation have to respond to an access request?

Organisations are expected to respond as soon as reasonably possible, typically within 30 days. If more time is needed, they must inform you of the delay and provide a revised timeline. Unreasonable delays can be grounds for a PDPC complaint.

Does the PDPA apply to overseas companies serving Singapore customers?

Yes. The PDPA applies to any organisation that collects, uses, or discloses personal data in Singapore, regardless of where the organisation is based. Overseas companies serving Singapore customers must comply with the same obligations as local businesses.

Where do I file a PDPA complaint?

Complaints can be filed directly with the Personal Data Protection Commission (PDPC) through their official website. You should first try to resolve the issue with the organisation's Data Protection Officer, as the PDPC generally expects individuals to attempt direct resolution before escalating.

Final Thoughts

Singapore's PDPA gives individuals meaningful control over their personal data, backed by a regulator willing to enforce the rules. Whether you're concerned about marketing spam, worried about a data breach, or simply want to understand what companies can do with your information, knowing your PDPA rights is the first line of defence. Combine those legal rights with practical privacy habits—strong passwords, careful app permissions, and privacy-respecting tools—and you'll be well-positioned to protect your data in an increasingly connected Singapore.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles