facebook-pixel

Singapore PDPA: Your Personal Data Protection Rights Explained

L
Lunyb Security Team
··10 min read

Singapore's Personal Data Protection Act (PDPA) is one of Asia's most influential data protection laws, giving individuals meaningful control over how organisations collect, use, and disclose their personal data. Whether you're a Singapore resident, a foreign national living here, or a business owner navigating compliance, understanding your PDPA rights is essential in an era of constant data exchange.

This guide breaks down every right the PDPA grants you, explains how to exercise those rights, and walks through what to do when an organisation fails to comply. By the end, you'll know exactly how the PDPA protects you and how to hold companies accountable.

What Is the Singapore PDPA?

The Personal Data Protection Act 2012 (PDPA) is Singapore's primary data protection legislation, governing how private-sector organisations handle personal data. It is enforced by the Personal Data Protection Commission (PDPC), a division of the Infocomm Media Development Authority (IMDA).

The PDPA came into full effect in July 2014 and was significantly amended in 2020 to introduce mandatory breach notification, data portability, and higher financial penalties. It applies to all organisations operating in Singapore, regardless of whether they are locally incorporated, and covers any personal data that can identify a living individual.

Who Does the PDPA Cover?

The Act applies to:

  • Private-sector organisations collecting, using, or disclosing personal data in Singapore
  • Foreign companies that process personal data of individuals in Singapore
  • Data intermediaries (processors) acting on behalf of another organisation

Government agencies are governed separately under the Public Sector (Governance) Act, though similar principles apply.

The 11 Data Protection Obligations Under PDPA

Before diving into individual rights, it helps to understand the obligations organisations must meet. These form the backbone of your protections:

  1. Consent Obligation – Organisations must obtain your consent before collecting, using, or disclosing personal data.
  2. Purpose Limitation Obligation – Data can only be used for purposes a reasonable person would consider appropriate.
  3. Notification Obligation – You must be informed of the purposes for data collection.
  4. Access and Correction Obligation – You have the right to access and correct your data.
  5. Accuracy Obligation – Organisations must ensure data is accurate and complete.
  6. Protection Obligation – Reasonable security arrangements must safeguard your data.
  7. Retention Limitation Obligation – Data must be deleted when no longer needed.
  8. Transfer Limitation Obligation – Cross-border data transfers must meet PDPA standards.
  9. Data Breach Notification Obligation – Serious breaches must be reported to the PDPC and affected individuals.
  10. Accountability Obligation – Organisations must appoint a Data Protection Officer (DPO) and publish policies.
  11. Data Portability Obligation – (Once fully in force) you can request your data be transferred to another organisation.

Your Core PDPA Rights Explained

1. Right to Be Informed

Before any organisation collects your personal data, they must clearly tell you what they're collecting, why they're collecting it, and how it will be used or disclosed. This notification typically appears in privacy policies, sign-up forms, or verbal disclosures for phone-based interactions.

If a company changes the purpose of data use, they must notify you and obtain fresh consent — silence or inaction cannot be treated as agreement.

2. Right to Give and Withdraw Consent

Consent under the PDPA must be freely given, specific, and informed. Organisations cannot bundle consent with unrelated services or force you to agree as a condition of a purchase unless the data is genuinely necessary.

Equally important, you have the right to withdraw consent at any time. When you do, the organisation must stop collecting, using, or disclosing your data for the withdrawn purposes and inform you of the likely consequences (for example, they may no longer be able to deliver certain services).

3. Right to Access Your Personal Data

You can request that any organisation provide:

  • A copy of the personal data they hold about you
  • Information about how that data has been used or disclosed within the past year

Organisations must respond as soon as reasonably possible, typically within 30 days. They may charge a reasonable fee to cover the cost of retrieval but cannot use fees as a barrier to access.

4. Right to Correction

If you find that data held about you is inaccurate, incomplete, or misleading, you can request a correction. The organisation must:

  • Correct the data as soon as practicable
  • Notify other organisations to which the data was disclosed within the past year (unless you agree otherwise)

If the organisation disagrees with your correction request, they must annotate the data with your requested change so future users see both versions.

5. Right to Data Portability

Introduced in the 2020 PDPA amendments, the data portability right allows you to request that an organisation transmit your data directly to another organisation in a commonly used, machine-readable format. This right primarily benefits consumers switching between banks, telecom providers, or subscription services.

6. Right to Be Notified of Data Breaches

If an organisation experiences a data breach that is likely to result in significant harm to you, or that affects 500 or more individuals, they must notify:

  • The PDPC within 3 calendar days of assessing the breach as notifiable
  • Affected individuals as soon as practicable

Notifications must describe the breach, the data involved, potential consequences, and steps the organisation is taking to address the incident.

7. Right to Lodge a Complaint

If an organisation fails to respect your rights, you can file a complaint with the PDPC. The Commission has the power to investigate, issue directions, and impose financial penalties of up to S$1 million or 10% of annual turnover in Singapore (whichever is higher) for serious breaches.

PDPA vs GDPR: A Quick Comparison

Many Singaporeans interact with EU-based services and wonder how the PDPA measures up to the GDPR. Here's a side-by-side look:

FeatureSingapore PDPAEU GDPR
Territorial ScopeOrganisations operating in SingaporeAny organisation targeting EU residents
Maximum PenaltyS$1M or 10% of local turnover€20M or 4% of global turnover
Breach NotificationWithin 3 days to PDPCWithin 72 hours to supervisory authority
Right to ErasureLimited (via consent withdrawal)Explicit "right to be forgotten"
Data PortabilityYes (once fully in force)Yes
DPO RequirementMandatory for all organisationsOnly for certain organisations
Do Not Call RegistryYes, integrated in PDPAHandled separately (ePrivacy)

The Do Not Call (DNC) Registry

A unique feature of Singapore's PDPA is the Do Not Call Registry. Any Singapore telephone number registered on the DNC list cannot receive marketing calls, SMS, or fax messages from local organisations.

How to Register Your Number

  1. Visit the DNC Registry website (dnc.gov.sg) or call 1800-921-2828
  2. Select which channels you want to block: voice calls, text messages, or fax
  3. Verify your registration with the SMS confirmation code
  4. Registration takes effect within 30 days and remains active indefinitely

Organisations found violating the DNC provisions face fines of up to S$200,000. If you continue receiving marketing messages after registering, report the sender to the PDPC with screenshots and timestamps.

How to Exercise Your PDPA Rights

Step 1: Identify the Data Protection Officer

Every organisation subject to the PDPA must designate a DPO and publish their contact details, usually within the privacy policy. Start by locating the DPO's email address.

Step 2: Submit a Written Request

Write a clear, dated request that includes:

  • Your full name and contact information
  • Verification of identity (e.g., account number or partial NRIC)
  • The specific right you are exercising (access, correction, withdrawal, portability)
  • The data or scope involved

Step 3: Track the Response

Keep a copy of your request and any acknowledgments. Organisations should respond within 30 days. If they cannot, they must explain the delay and give a revised timeline.

Step 4: Escalate to the PDPC

If the organisation refuses, delays unreasonably, or provides an unsatisfactory response, file a complaint with the PDPC through their online portal at pdpc.gov.sg. Include all correspondence and evidence.

Practical Tips to Protect Your Personal Data Online

Legal rights only matter if you exercise them. Combine your PDPA protections with strong day-to-day habits:

  • Audit app permissions quarterly. Review which mobile apps have access to your contacts, location, and camera.
  • Use encrypted DNS services. Providers like Cloudflare (1.1.1.1) and Quad9 prevent your browsing history from being harvested by internet service providers.
  • Choose privacy-focused browsers. Brave, Firefox, and Safari offer stronger tracker blocking than default configurations.
  • Shorten and monitor shared links. When posting links publicly, use a trusted link management service like Lunyb that lets you track clicks without exposing raw destination URLs or embedding heavy trackers. Read our honest Lunyb review for a deeper look.
  • Enable two-factor authentication on every account holding personal or financial data.
  • Limit oversharing on social platforms. Birthdates, addresses, and workplace details fuel phishing attacks.

PDPA Compliance for Businesses in Singapore

If you run a business, meeting PDPA obligations is non-negotiable. Key compliance actions include:

  1. Appoint a DPO and publish their contact details on your website.
  2. Publish a clear privacy policy written in plain language.
  3. Implement data mapping to know what personal data you hold and where.
  4. Adopt security safeguards such as encryption at rest, access controls, and staff training.
  5. Prepare a breach response plan so the 3-day notification window can be met.
  6. Review vendor contracts to ensure data intermediaries meet PDPA requirements.
  7. Conduct regular audits and Data Protection Impact Assessments (DPIAs) for high-risk processing.

For businesses that rely on marketing links, using compliant tools that respect user privacy is important. Compare options in our 2026 URL shortener buyer's guide or read our detailed Rebrandly review to see how enterprise tools stack up against privacy expectations.

Recent PDPA Enforcement Trends

The PDPC has become increasingly active in publishing enforcement decisions. Recurring themes include:

  • Failure to implement adequate security controls, especially around cloud storage buckets left publicly accessible
  • Sending marketing messages to individuals on the DNC Registry
  • Overcollection of NRIC numbers where a less intrusive identifier would suffice
  • Delayed breach notifications following ransomware or phishing incidents
  • Insufficient staff training leading to accidental disclosures

Fines have escalated significantly since the 2020 amendments, with several enforcement decisions crossing the S$100,000 mark.

Frequently Asked Questions

Does the PDPA cover foreigners living in Singapore?

Yes. The PDPA protects any individual whose personal data is handled by an organisation operating in Singapore, regardless of citizenship or residency status. Tourists, expats, and short-term visitors all enjoy the same rights.

Can I request that a company delete all my data?

The PDPA does not include an explicit "right to erasure" like the GDPR. However, when you withdraw consent for the collection, use, or disclosure of your data, the organisation must stop processing it and, subject to legal retention requirements, delete it once it is no longer needed.

How long does an organisation have to respond to my access request?

Organisations should respond as soon as reasonably possible and generally within 30 days. If they need more time, they must inform you in writing of the expected response date and the reason for the delay.

What happens if a company ignores my PDPA request?

You can escalate the matter to the PDPC by filing a complaint through pdpc.gov.sg. The Commission can investigate, issue directions requiring the organisation to comply, and impose financial penalties. In serious cases, individuals may also pursue civil action for damages.

Are small businesses exempt from the PDPA?

No. Unlike some jurisdictions, the PDPA applies to organisations of all sizes. However, the PDPC often takes a proportionate approach to enforcement, and there are exemptions for personal or domestic use of data (for example, a private contact list on your phone).

Does the PDPA apply to data I share on social media?

Personal data you voluntarily publish on public social media profiles is treated differently, but organisations that scrape or repurpose that data for commercial use still need to comply with PDPA obligations, including consent for direct marketing.

Conclusion

The Singapore PDPA gives individuals a robust set of rights to control their personal data, and the PDPC has shown a growing willingness to enforce those rights against non-compliant organisations. By knowing your rights — to consent, access, correction, portability, and breach notification — and by pairing legal awareness with good digital hygiene, you can significantly reduce your exposure to data misuse.

If a company mishandles your data or ignores a valid request, don't hesitate to escalate to the PDPC. Every enforced complaint helps raise the standard of data protection across Singapore's digital economy.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles