facebook-pixel

Singapore PDPA: Your Personal Data Protection Rights Explained

L
Lunyb Security Team
··10 min read

Singapore's Personal Data Protection Act (PDPA) is the cornerstone of individual privacy in the country. Whether you are shopping online, applying for a job, or signing up for a loyalty programme, organisations must handle your personal data according to strict rules. Yet many Singapore residents are unclear about what those rules actually entitle them to. This guide explains your Singapore PDPA rights in plain English, so you can confidently exercise them.

What Is the Singapore PDPA?

The Personal Data Protection Act 2012 (PDPA) is Singapore's national data protection law that governs how private-sector organisations collect, use, disclose, and care for personal data. It is enforced by the Personal Data Protection Commission (PDPC) and applies to any organisation operating in Singapore, regardless of whether it is based locally or overseas.

The PDPA was significantly updated by the Personal Data Protection (Amendment) Act 2020, which introduced mandatory data breach notification, expanded consent frameworks, a new data portability obligation, and heavier financial penalties. As of 2026, maximum fines for serious breaches can reach up to 10% of an organisation's annual turnover in Singapore, or S$1 million, whichever is higher.

Who the PDPA Protects

The PDPA protects any individual whose personal data is held by an organisation, regardless of nationality or residency status. Personal data is defined as any data that can identify an individual, either on its own or in combination with other data an organisation is likely to have access to. This includes names, NRIC numbers, phone numbers, addresses, email accounts, biometric records, and even device identifiers.

Who the PDPA Does Not Cover

  • Government agencies (they are governed by the Public Sector (Governance) Act instead)
  • Individuals acting in a personal or domestic capacity
  • Employees acting in the course of their employment
  • Business contact information used strictly for business purposes

Your Core Rights Under the Singapore PDPA

The PDPA gives you a bundle of enforceable rights over your personal data. Understanding each one is the first step to protecting your privacy in Singapore.

1. The Right to Be Informed (Notification Obligation)

Before or at the time an organisation collects your personal data, it must tell you the purposes for which the data will be collected, used, or disclosed. If those purposes change later, you must be informed again. Vague statements like "for business purposes" are not acceptable — organisations must be specific.

2. The Right to Consent (and to Withdraw It)

Organisations generally cannot collect, use, or disclose your personal data without your consent. Consent must be freely given, informed, and specific. Silence or pre-ticked boxes do not count as valid consent. Importantly, you can withdraw your consent at any time by giving reasonable notice, and the organisation must inform you of the likely consequences before acting on your withdrawal.

3. The Right of Access

You can request a copy of the personal data an organisation holds about you, along with information about how that data has been used or disclosed in the past year. Organisations must respond as soon as reasonably possible, typically within 30 days. A reasonable fee may be charged, but it cannot be used as a barrier.

4. The Right to Correction

If your personal data is inaccurate or incomplete, you have the right to request correction. The organisation must correct the data as soon as practicable and notify other organisations to which the data was disclosed in the past year, unless you consent otherwise.

5. The Right to Data Portability (New)

Once the Data Portability Obligation is fully in force, you will have the right to request that an organisation transmit your data in a commonly used, machine-readable format to another organisation of your choice. This right will apply to specific categories of data set out in regulations, making it easier to switch between service providers such as banks, telcos, and utilities.

6. The Right to Be Notified of a Data Breach

Since 1 February 2021, organisations must notify the PDPC and affected individuals if a data breach is likely to result in significant harm to individuals or affects 500 or more people. Notification to the PDPC must be made within 3 calendar days of assessing that a notifiable breach has occurred.

7. The Right Against Unsolicited Marketing (Do Not Call)

The PDPA's Do Not Call (DNC) Provisions let you register your Singapore telephone number on the DNC Registry. Once registered, organisations must check the registry before sending you telemarketing messages, calls, or faxes, unless you have given clear and unambiguous consent in writing.

PDPA Rights at a Glance

RightWhat It MeansHow to Exercise It
NotificationKnow why your data is collectedRead privacy notices before consenting
Consent WithdrawalStop further use of your dataSubmit a written withdrawal request
AccessGet a copy of your dataWritten request; response within 30 days
CorrectionFix inaccurate dataWritten request specifying the change
Data PortabilityTransfer data to another providerWritten request once provisions apply
Breach NotificationBe told about serious breachesAutomatic — organisations must inform you
Do Not CallStop telemarketingRegister on DNC Registry (free)

Organisational Obligations You Should Know

Your rights only work because the PDPA imposes matching obligations on organisations. Knowing these obligations helps you recognise when something has gone wrong.

The Nine Main Obligations

  1. Consent Obligation — obtain valid consent before collecting data
  2. Purpose Limitation Obligation — only use data for purposes a reasonable person would consider appropriate
  3. Notification Obligation — inform individuals of collection purposes
  4. Access and Correction Obligation — respond to requests promptly
  5. Accuracy Obligation — ensure data is accurate and complete
  6. Protection Obligation — apply reasonable security safeguards
  7. Retention Limitation Obligation — stop keeping data when no longer needed
  8. Transfer Limitation Obligation — protect data sent overseas
  9. Accountability Obligation — appoint a Data Protection Officer (DPO) and publish their contact details

How to Exercise Your PDPA Rights

Enforcing your rights is usually straightforward if you follow a clear process. Here is a step-by-step guide.

Step 1: Find the Organisation's Data Protection Officer

Every organisation subject to the PDPA must designate a DPO and publish their business contact details. Look for the DPO's email in the company's privacy policy, usually linked in the website footer.

Step 2: Submit a Written Request

Send a clear, written request specifying:

  • Which right you are exercising (access, correction, withdrawal, etc.)
  • The personal data or account concerned
  • Proof of identity, if requested
  • Your preferred format for the response

Step 3: Track the Response Timeline

Organisations must respond as soon as reasonably possible. For access requests, this is usually within 30 days. If more time is needed, they must inform you in writing with an estimated date.

Step 4: Escalate to the PDPC If Necessary

If an organisation refuses your request without valid reason, ignores you, or handles your complaint poorly, you can lodge a complaint with the PDPC via the pdpc.gov.sg website. Alternatively, mediation is available through the PDPC's Data Protection Dispute Resolution scheme.

Practical Ways to Protect Your Personal Data in Singapore

Beyond exercising legal rights after the fact, prevention is always better. Here are practical steps to reduce your data exposure day to day.

Minimise What You Share

Do not hand over your NRIC number unless it is legally required. Under PDPA guidelines, organisations generally cannot collect, use, or disclose your NRIC number except where required by law or necessary to accurately establish or verify your identity to a high degree of fidelity.

Use Privacy-Preserving Tools

Consider encrypted messaging apps, private browsers with tracker blocking, and encrypted DNS services to reduce how much of your online activity is quietly logged. When sharing links, use a trustworthy shortener that respects privacy — for example, Lunyb lets you shorten and manage links without invasive tracking, which is helpful when posting on social media or in emails where you do not want third-party analytics harvesting click data. You can read our honest review of Lunyb for a deeper look, or compare options in our 2026 buyer's guide.

Register on the Do Not Call Registry

It takes two minutes at dnc.gov.sg and is free. You can register your Singapore mobile or landline against three types of marketing: voice calls, text messages, and faxes.

Read Privacy Notices Before Signing Up

Focus on three things: what data is collected, how long it is retained, and whether it is shared with third parties overseas. If the notice is silent or vague on any of these, that is a red flag.

Common PDPA Misconceptions

"The PDPA Doesn't Apply to Small Businesses"

False. The PDPA applies to any organisation collecting personal data in Singapore, regardless of size. A sole proprietor collecting customer emails is subject to the same core obligations as a multinational bank.

"Consent Once Given Cannot Be Withdrawn"

False. Consent can be withdrawn at any time with reasonable notice. The organisation must then stop using your data for the affected purposes, although they may retain it if legally required.

"Business Contact Information Is Fully Protected"

Partially false. Business contact information (like a work email used purely for work) is largely excluded from the PDPA's data protection provisions, though the DNC rules still apply to marketing calls.

"Overseas Companies Are Not Covered"

False. If an overseas organisation collects personal data from individuals in Singapore, it must comply with the PDPA. The PDPC has taken enforcement action against foreign entities before.

Penalties for Non-Compliance

Since October 2022, financial penalties for PDPA breaches have increased significantly. The PDPC can now impose fines of up to 10% of an organisation's annual turnover in Singapore (for organisations with turnover exceeding S$10 million) or S$1 million, whichever is higher. Individuals who mishandle data — for instance, employees who leak customer information — can face criminal penalties, including fines of up to S$5,000 and imprisonment.

Frequently Asked Questions

How long does an organisation have to respond to my PDPA access request?

Organisations must respond as soon as reasonably possible. In practice, the PDPC expects a response within 30 days. If more time is required, the organisation must inform you in writing and give an estimated response date.

Can I sue an organisation directly under the PDPA?

Yes. Section 48O of the PDPA gives individuals a private right of action. If you have suffered loss or damage as a result of a contravention, you can pursue civil proceedings — typically after the PDPC has completed its investigation and made a decision.

Does the PDPA cover data stored overseas?

Yes. The Transfer Limitation Obligation requires organisations transferring personal data outside Singapore to ensure the receiving jurisdiction provides a standard of protection comparable to the PDPA. This is usually done through contractual clauses or binding corporate rules.

What should I do if I receive marketing messages despite being on the DNC Registry?

Take a screenshot or record the details (sender, date, time, content) and file a complaint at pdpc.gov.sg. Organisations that violate the DNC provisions can be fined up to S$200,000 for repeated or serious offences.

Do I need to pay to make a PDPA request?

Correction and consent withdrawal requests are free. Access requests may attract a reasonable fee to cover the organisation's administrative costs, but the fee cannot be used to discourage requests. The organisation must provide a written estimate of the fee before proceeding.

Final Thoughts

The Singapore PDPA gives you meaningful, enforceable rights over your personal data — but those rights only work when you know how to use them. Take a few minutes to register on the DNC Registry, review the privacy notices of the services you use most, and bookmark the PDPC website for future reference. If you suspect an organisation is mishandling your data, do not hesitate to raise it with their DPO first, and escalate to the PDPC if the response is unsatisfactory. Your data belongs to you; the PDPA simply makes sure everyone else remembers that too.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles