facebook-pixel

Singapore PDPA: Your Personal Data Protection Rights Explained

L
Lunyb Security Team
··11 min read

Singapore's Personal Data Protection Act (PDPA) is the country's cornerstone privacy law, giving every individual meaningful control over how organisations collect, use, and disclose their personal data. Whether you're signing up for a rewards app, applying for a job, or clicking a shortened link, the PDPA sets clear boundaries on what companies can and cannot do with your information.

This guide breaks down your Singapore PDPA rights in plain English, explains how the law has evolved since its major 2020 amendments, and shows you exactly how to enforce these rights when an organisation oversteps.

What Is the Singapore PDPA?

The Personal Data Protection Act 2012 (PDPA) is Singapore's baseline law governing the collection, use, disclosure, and care of personal data by private-sector organisations. It is enforced by the Personal Data Protection Commission (PDPC), a unit under the Infocomm Media Development Authority (IMDA).

The PDPA applies to any organisation operating in Singapore, regardless of where the organisation is headquartered, whenever it handles personal data of individuals in Singapore. Public agencies are governed by a separate framework (the Public Sector Governance Act), but most private companies, non-profits, and even sole proprietors fall under the PDPA.

Key 2020 Amendments You Should Know

Major amendments passed in November 2020 and rolled out through 2021–2022 significantly strengthened the PDPA. The most important changes include:

  • Mandatory data breach notification for breaches likely to cause significant harm or affecting 500 or more individuals.
  • Higher financial penalties: up to 10% of annual turnover in Singapore (for organisations earning more than S$10 million) or S$1 million, whichever is higher.
  • A new data portability obligation allowing individuals to request their data be transferred to another organisation.
  • Expanded consent frameworks, including deemed consent by notification and legitimate interests exceptions.
  • Enhanced protection against unsolicited commercial messages under the Do Not Call (DNC) provisions.

Your Core PDPA Rights as an Individual

The PDPA grants individuals a set of enforceable rights over their personal data. Understanding each one is the first step to protecting yourself.

1. The Right to Be Informed (Notification Obligation)

Before or at the time of collecting your personal data, an organisation must inform you of the purposes for collection, use, or disclosure. This is why you see privacy notices during sign-ups. If purposes change later, you must be re-notified.

2. The Right to Consent (and to Withdraw It)

Organisations generally cannot collect, use, or disclose your personal data without your consent. You also have the right to withdraw consent at any time by giving reasonable notice. Once withdrawn, the organisation must stop using your data for the withdrawn purposes, though they may retain it if legally required.

3. The Right of Access

You can request a copy of the personal data an organisation holds about you, along with information on how that data has been used or disclosed in the past year. Organisations must respond as soon as reasonably possible, typically within 30 days, and may charge a reasonable fee.

4. The Right to Correction

If your data is inaccurate or incomplete, you can require the organisation to correct it. Corrected data must also be sent to other organisations that received the incorrect data in the past year, unless you agree otherwise.

5. The Right to Data Portability (New)

Introduced in the 2020 amendments, this right lets you request that your data held by one organisation be transmitted in a commonly used machine-readable format to another organisation. Note: the portability obligation applies only once operationalised through regulations, and specific data categories are covered.

6. The Right to Protection

Organisations must make reasonable security arrangements to protect personal data in their possession or control against unauthorised access, collection, use, disclosure, copying, modification, disposal, or similar risks.

7. The Right to Data Breach Notification

If a notifiable data breach occurs, the organisation must notify both the PDPC and affected individuals without unreasonable delay, and within 3 calendar days of assessing the breach as notifiable.

8. The Right to Opt Out of Marketing (Do Not Call Registry)

You can register your Singapore telephone number on the DNC Registry to block unsolicited telemarketing calls, texts, and faxes. Organisations must check the registry before sending marketing messages unless you have given clear and unambiguous consent.

PDPA Rights at a Glance

RightWhat It MeansResponse Time
AccessGet a copy of your data and its usage historyUsually within 30 days
CorrectionFix inaccurate or incomplete dataAs soon as practicable
Withdraw ConsentStop further use of your dataWithin a reasonable period
Data PortabilityTransfer data to another organisationPer PDPC regulations
Breach NotificationBe told if your data is compromisedWithin 3 days of assessment
DNC Opt-OutBlock telemarketingEffective within 30 days

Organisations' Obligations Under the PDPA

The PDPA imposes nine main data protection obligations on organisations. Knowing these helps you recognise when a company is falling short.

  1. Consent Obligation – Collect only with valid consent (or a recognised exception).
  2. Purpose Limitation – Use data only for purposes a reasonable person would consider appropriate.
  3. Notification – Inform individuals of purposes.
  4. Access and Correction – Provide access and correct data upon request.
  5. Accuracy – Ensure data is accurate and complete.
  6. Protection – Implement reasonable security measures.
  7. Retention Limitation – Stop retaining data once no longer needed.
  8. Transfer Limitation – Ensure comparable protection when transferring data overseas.
  9. Accountability – Appoint a Data Protection Officer (DPO) and publish their contact details.

Every organisation in Singapore that collects personal data must appoint at least one DPO. If you cannot find their contact details on a company's website, that itself is a red flag and a breach of the Accountability Obligation.

How to Exercise Your PDPA Rights: Step-by-Step

Step 1: Identify the Organisation's Data Protection Officer

Look for a "Privacy Policy" or "Data Protection" page on the company's website. The DPO's email is often listed there, e.g., dpo@company.com.sg.

Step 2: Submit a Written Request

Send a clear, written request (email is fine) specifying which right you're exercising. For example:

  • "I am requesting access to all personal data your organisation holds about me under Section 21 of the PDPA."
  • "I hereby withdraw my consent for the use of my personal data for marketing purposes."

Include your full name, contact details, and any account or reference numbers.

Step 3: Wait for the Response

Organisations should respond as soon as reasonably possible. If they need more than 30 days, they must tell you why and give an estimated timeline.

Step 4: Escalate If Necessary

If the organisation refuses, ignores you, or provides an inadequate response, you can file a complaint with the PDPC through their online portal at pdpc.gov.sg.

Step 5: Seek Compensation via Private Right of Action

The PDPA allows individuals who suffer loss or damage due to a contravention to bring civil proceedings against the organisation in court, once the PDPC has made a decision on the matter.

Penalties for Non-Compliance

The financial consequences for organisations that ignore PDPA obligations are significant. Under the enhanced framework:

  • Organisations with annual turnover in Singapore exceeding S$10 million face fines of up to 10% of their local annual turnover.
  • Smaller organisations face fines of up to S$1 million per breach.
  • Individuals convicted under DNC or unauthorised disclosure offences may face fines up to S$5,000 to S$10,000 and, in serious cases, imprisonment.

The PDPC publishes enforcement decisions publicly, so you can research an organisation's compliance track record before trusting them with your data.

PDPA and Everyday Digital Life in Singapore

Shortened Links and Tracking

Every time you click a shortened URL, some data may be logged — commonly your IP address, referrer, device type, and timestamp. Under the PDPA, if this data can identify you (directly or in combination with other data), it counts as personal data and must be handled accordingly.

Reputable link management services publish clear privacy notices and let you review their data practices. For example, we cover how Lunyb handles data transparently in our honest Lunyb review, and compare privacy practices across major providers in our 2026 URL shortener buyer's guide. If you manage links for a Singapore-based business, choosing a shortener with PDPA-aware data handling matters as much as choosing one with good analytics — see our Rebrandly review for a comparison point.

Cookies and Web Tracking

The PDPC has clarified that cookies capturing personal data require consent. Most Singapore websites now display cookie banners, though not all comply meaningfully. You have the right to reject non-essential cookies.

Cross-Border Data Transfers

When a Singapore-based service sends your data overseas (for cloud storage, analytics, or processing), it must ensure the receiving jurisdiction offers protection comparable to the PDPA. Standard contractual clauses and binding corporate rules are common mechanisms.

Special Categories: Employees, Minors, and Sensitive Data

Employee Data

Employers can collect employee data for managing employment relationships without explicit consent, but only for reasonable purposes and with proper notification. Employees still retain access and correction rights.

Data of Minors

The PDPA does not set a fixed age of consent, but the PDPC's guidelines suggest that individuals aged 13 and above generally have sufficient understanding to consent. For younger children, parental consent is expected.

Sensitive Personal Data

Unlike some other frameworks, the PDPA does not formally define a "sensitive" category. However, the PDPC expects organisations to apply higher standards of protection to data such as NRIC numbers, financial details, medical records, and biometric information.

The NRIC Rule You Should Know

Since 1 September 2019, organisations in Singapore are generally prohibited from collecting, using, or disclosing NRIC numbers (or copies of NRIC cards) except where required by law or necessary to accurately verify identity to a high degree of fidelity. If a shop or website asks for your NRIC for a lucky draw or Wi-Fi access, that's very likely a PDPA violation you can report.

Practical Tips to Protect Your Data

  1. Read privacy notices before signing up, even if only skimming for what data is collected and for what purpose.
  2. Use unique passwords and enable two-factor authentication wherever available.
  3. Register on the DNC Registry at dnc.gov.sg to stop telemarketing.
  4. Regularly review app permissions on your phone and revoke unnecessary access.
  5. Withdraw consent from services you no longer use, then request data deletion.
  6. Avoid giving your NRIC unless legally required.
  7. Use encrypted DNS and privacy-focused browsers to reduce passive tracking at the network level.
  8. Check enforcement decisions on the PDPC website before trusting a new service with sensitive data.

Filing a Complaint with the PDPC

If an organisation has violated your rights, follow this process:

  1. Contact the organisation first — the PDPC generally expects you to have tried to resolve the issue directly.
  2. Gather evidence — emails, screenshots, dates, and any responses received.
  3. Submit a complaint via the PDPC's online complaint form at pdpc.gov.sg.
  4. Cooperate with investigations — the PDPC may request further information.
  5. Consider mediation — the PDPC often refers disputes to its Data Protection Dispute Resolution scheme.

Frequently Asked Questions

Does the PDPA apply to foreign companies?

Yes. The PDPA applies to any organisation collecting, using, or disclosing personal data of individuals in Singapore, regardless of whether the organisation is physically located here. A US-based e-commerce site serving Singapore customers, for example, must comply.

Can I request deletion of my data under the PDPA?

The PDPA does not include a standalone "right to erasure" like the EU GDPR. However, you can withdraw consent, and organisations must cease retaining personal data once the purpose for collection is no longer served and retention is not legally required. In practice, this often achieves the same outcome.

How long can an organisation keep my data?

Only as long as it is necessary for the stated business or legal purposes. The Retention Limitation Obligation requires organisations to anonymise or dispose of personal data once it is no longer needed. There is no fixed maximum period — it depends on the purpose.

What counts as a notifiable data breach?

A data breach is notifiable if it (a) results in, or is likely to result in, significant harm to affected individuals, or (b) is of a significant scale, meaning it affects 500 or more individuals. Organisations must notify the PDPC within 3 calendar days of assessing the breach as notifiable.

Can I sue an organisation for a PDPA breach?

Yes. Once the PDPC has made a decision on a matter and any appeals have concluded, you can bring civil proceedings for loss or damage suffered as a result of the contravention. Remedies include damages, injunctions, and declarations.

Final Thoughts

The Singapore PDPA gives you genuine, enforceable rights over your personal data — but those rights only work when you use them. Knowing when to ask for access, when to withdraw consent, and when to escalate to the PDPC turns a piece of legislation into a real shield around your digital life.

As Singapore continues to strengthen its data protection regime, expect more granular obligations around AI-driven data processing, biometric information, and cross-border transfers. Staying informed is the best long-term protection you can give yourself.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles