facebook-pixel

Singapore PDPA: Your Personal Data Protection Rights Explained

L
Lunyb Security Team
··11 min read

Singapore's Personal Data Protection Act (PDPA) is the cornerstone of the country's data privacy framework, governing how organisations collect, use, disclose, and safeguard personal data. Whether you're a Singapore resident, an employee sharing details with your employer, or a customer signing up for a service, the PDPA gives you specific, enforceable rights over your personal information. This guide breaks down those rights in plain English, explains how to exercise them, and outlines what organisations must do to comply.

What Is the Singapore PDPA?

The Personal Data Protection Act 2012 (PDPA) is Singapore's principal data protection law, administered by the Personal Data Protection Commission (PDPC). It sets baseline standards for how private-sector organisations must handle personal data, and was significantly strengthened by amendments that took effect from 2021 onwards, including mandatory data breach notifications and higher financial penalties.

The PDPA applies to any organisation operating in Singapore that collects, uses, or discloses personal data, regardless of whether the organisation is physically located in the country. "Personal data" refers to any information about an identifiable individual, whether true or false, and includes names, NRIC numbers, contact details, photographs, biometric data, and even opinions expressed about a person.

Who Does the PDPA Cover?

The PDPA covers:

  • Private-sector organisations of all sizes, including sole proprietorships and multinational companies.
  • Data intermediaries (third parties processing data on behalf of another organisation).
  • Personal data of individuals, whether they are Singapore citizens, permanent residents, or foreigners residing in Singapore.

Government agencies are generally governed by a separate framework — the Public Sector (Governance) Act — though many PDPA principles apply in parallel.

The Core Data Protection Obligations Organisations Must Follow

Before exploring your rights as an individual, it helps to understand the ten key obligations the PDPA places on organisations. Your rights largely mirror these obligations.

  1. Consent Obligation — Organisations must obtain your consent before collecting, using, or disclosing your personal data.
  2. Purpose Limitation Obligation — Data can only be used for purposes a reasonable person would consider appropriate and that have been notified to you.
  3. Notification Obligation — You must be told the purposes for which your data is being collected.
  4. Access and Correction Obligation — You have the right to access and correct your data.
  5. Accuracy Obligation — Organisations must ensure the data they hold is accurate and complete.
  6. Protection Obligation — Reasonable security measures must protect data from unauthorised access.
  7. Retention Limitation Obligation — Data must not be kept longer than necessary.
  8. Transfer Limitation Obligation — Overseas transfers require comparable protection standards.
  9. Accountability Obligation — Organisations must appoint a Data Protection Officer (DPO) and publish policies.
  10. Data Breach Notification Obligation — Certain breaches must be reported to the PDPC and affected individuals.

Your Key Rights Under the Singapore PDPA

The PDPA grants you several specific rights that you can actively exercise. Understanding these rights is the first step to protecting your personal information.

1. The Right to Be Informed

Before an organisation collects your personal data, it must inform you of the purposes for which the data will be collected, used, or disclosed. This is typically achieved through a privacy notice, a consent form, or a data protection policy displayed on a website. If purposes change later, the organisation must obtain fresh consent.

2. The Right to Give and Withdraw Consent

Consent is the foundation of the PDPA. Organisations cannot collect your data without it, except in limited circumstances (for example, when required by law, in emergencies, or under the "legitimate interests" exception introduced in the 2020 amendments).

Equally important: you have the right to withdraw consent at any time. Once you withdraw consent, the organisation must stop collecting, using, or disclosing your data — although they may retain it if legally required (for example, to meet tax record-keeping obligations).

3. The Right to Access Your Personal Data

You can request that an organisation tells you:

  • What personal data of yours it holds or controls.
  • How that data has been used or disclosed in the past year.

Organisations must respond within a reasonable timeframe — typically 30 days — and may charge a nominal fee to cover reasonable costs. If they cannot respond within 30 days, they must inform you and provide an expected timeline.

4. The Right to Correct Your Personal Data

If you find that an organisation holds inaccurate or incomplete data about you, you can request a correction. The organisation must correct the data as soon as practicable and send the corrected data to every other organisation to which it has disclosed the original data within a year, unless you consent otherwise.

5. The Right to Data Portability (New Under 2020 Amendments)

The 2020 PDPA amendments introduced a data portability obligation, allowing you to request that your data be transmitted to another organisation in a commonly used, machine-readable format. This is particularly useful when switching between service providers, such as banks, telecommunications carriers, or online platforms. Implementation regulations are still being progressively rolled out, so check the PDPC website for the most current guidance.

6. The Right to Be Notified of Data Breaches

Since 1 February 2021, organisations must notify the PDPC and affected individuals of data breaches that:

  • Result in, or are likely to result in, significant harm to affected individuals, or
  • Affect 500 or more individuals.

Notification to the PDPC must occur within 72 hours of assessing that a notifiable breach has occurred. This gives you the opportunity to take protective steps such as changing passwords, monitoring bank accounts, or freezing credit checks.

7. The Right to Opt Out of Marketing Messages (Do Not Call Registry)

The PDPA's Do Not Call (DNC) provisions let you register your Singapore telephone number on the DNC Registry to stop receiving unsolicited telemarketing calls, texts, and faxes. Organisations must check the DNC Registry before sending marketing messages and honour your preferences.

How to Exercise Your PDPA Rights: A Step-by-Step Process

Knowing your rights is one thing — exercising them effectively is another. Here's a practical process for making a request under the PDPA.

  1. Identify the organisation's Data Protection Officer (DPO). Every organisation must appoint a DPO and publish their contact details, usually on the company website's privacy policy or contact page.
  2. Submit a written request. Send an email or letter clearly stating your request — for access, correction, withdrawal of consent, or data portability. Include enough details for the organisation to verify your identity.
  3. Verify your identity. Be prepared to provide identity verification. Organisations must be certain they are releasing data to the correct person.
  4. Wait for a response. The standard response window is 30 days. If more time is needed, the organisation must let you know.
  5. Review and follow up. If the response is incomplete or unsatisfactory, follow up in writing. Keep records of all correspondence.
  6. Escalate to the PDPC if needed. If the organisation refuses your request or fails to comply, you can lodge a complaint with the Personal Data Protection Commission via the PDPC website.

PDPA vs. Other Major Data Protection Laws

Singapore's PDPA shares principles with other global data protection regimes but has its own distinct approach. The table below compares key features.

FeatureSingapore PDPAEU GDPRUK Data Protection Act 2018
Consent standardDeemed and express consent both recognisedExplicit, unambiguous consent requiredExplicit, unambiguous consent required
Right of accessYes, typically within 30 daysYes, within 30 daysYes, within 30 days
Data portabilityYes (progressively rolled out)YesYes
Breach notification72 hours from assessment72 hours from awareness72 hours from awareness
Max financial penaltyUp to 10% of annual Singapore turnover (or S$1M, whichever is higher)Up to 4% of global turnover or €20MUp to 4% of global turnover or £17.5M
Do Not Call regimeYes, statutoryNot built into GDPRSeparate PECR regulations

Penalties for Non-Compliance

The PDPA's enforcement powers were significantly strengthened in 2022. Organisations that fail to comply can face:

  • Financial penalties of up to 10% of annual turnover in Singapore for organisations with annual turnover exceeding S$10 million, or S$1 million — whichever is higher.
  • Directions from the PDPC, such as ordering the organisation to stop collecting or using data, destroy improperly collected data, or provide access/correction.
  • Reputational damage from published enforcement decisions on the PDPC website.
  • Civil actions — individuals who suffer loss or damage due to a PDPA contravention can sue the organisation directly.

Practical Tips to Protect Your Personal Data in Singapore

While the PDPA gives you strong rights, personal vigilance is equally important. Here are some practical steps you can take.

Be Selective About What You Share

When signing up for services, ask whether all requested fields are truly necessary. Under the PDPA, organisations should only collect data they genuinely need for the stated purpose. Avoid sharing your NRIC number unless legally required — the PDPC has issued specific guidance restricting NRIC collection.

Read Privacy Notices Carefully

It's tempting to click "I agree" without reading, but privacy notices tell you exactly how your data will be used. Look for details on data sharing with third parties, overseas transfers, and retention periods.

Use Privacy-Enhancing Tools

Consider tools that reduce the amount of personal data you expose online. Encrypted DNS services, private browsers with tracker blocking, and disposable email addresses can all help limit unnecessary data collection. When sharing links — for example, in emails or on social media — a trusted URL shortener like Lunyb can help you avoid exposing tracking parameters or long URLs that reveal personal identifiers. For a deeper look at how Lunyb approaches privacy, see our honest review of Lunyb.

Register on the Do Not Call Registry

If you're tired of unsolicited marketing calls and texts, register your Singapore number on the DNC Registry at dnc.gov.sg. Registration is free and covers voice calls, SMS, and fax.

Monitor Data Breach Announcements

Keep an eye on news reports and official notifications about data breaches. If a service you use is breached, change your password immediately, enable two-factor authentication, and consider what other accounts might share those credentials.

Special Considerations for Businesses

If you run a business in Singapore, PDPA compliance is not optional. At a minimum you should:

  • Appoint a Data Protection Officer and publish their contact details.
  • Develop and publish a privacy policy in clear, accessible language.
  • Map your data flows — know what data you collect, why, where it's stored, and who has access.
  • Implement reasonable security safeguards, including encryption, access controls, and regular audits.
  • Train your staff on PDPA obligations and incident response.
  • Establish a data breach response plan aligned with the 72-hour notification requirement.

Marketing teams in particular should be careful with link tracking and analytics. If you're evaluating link management platforms for your marketing operations, our 2026 buyer's guide to URL shorteners and Rebrandly review can help you choose a solution that aligns with your data protection obligations.

Frequently Asked Questions

Does the PDPA apply to businesses located outside Singapore?

Yes. The PDPA applies to any organisation — regardless of where it is physically based — that collects, uses, or discloses personal data in Singapore. Overseas e-commerce sites, cloud providers, and marketing platforms serving Singapore customers must comply with PDPA requirements.

Can I sue an organisation directly for a PDPA breach?

Yes. Under section 48O of the PDPA, individuals who suffer loss or damage as a direct result of a contravention may bring a private civil action against the organisation. However, this right typically requires the PDPC to have first made a finding of breach or for the organisation to have admitted liability.

How long does an organisation have to respond to my access request?

Organisations should respond as soon as reasonably possible, generally within 30 days. If they cannot meet this deadline, they must notify you in writing and provide an estimated response timeframe. Unreasonable delays can be reported to the PDPC.

What should I do if I believe my personal data has been misused?

First, contact the organisation's Data Protection Officer in writing and give them a reasonable opportunity to respond. If the issue isn't resolved satisfactorily, you can submit a complaint to the PDPC through their online portal. Include all supporting evidence, correspondence, and a clear description of the alleged breach.

Are there any exemptions to the consent requirement?

Yes. The PDPA allows collection, use, or disclosure without consent in specific circumstances — including where required by law, in emergencies to protect life or health, for investigations, for publicly available data, and under the "legitimate interests" exception where the benefits outweigh any adverse effects on the individual. Organisations relying on these exceptions must still meet other PDPA obligations like protection and retention limitation.

Conclusion

The Singapore PDPA gives you meaningful, enforceable rights over your personal data — from the right to know what's being collected, to the right to correct inaccuracies, withdraw consent, receive breach notifications, and take your data with you when switching providers. Combined with stronger penalties and mandatory breach reporting introduced in recent years, the framework has become one of Asia's most robust data protection regimes.

As an individual, understanding these rights transforms you from a passive subject of data collection into an active participant in your own privacy. As a business, respecting these rights is not just a legal requirement — it's a foundation for building trust with your customers. Whether you're safeguarding personal information or handling data on behalf of others, taking the PDPA seriously is one of the smartest investments you can make in the digital economy.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles