facebook-pixel

Singapore PDPA: Your Personal Data Protection Rights Explained

L
Lunyb Security Team
··10 min read

Singapore's Personal Data Protection Act (PDPA) is one of Asia's most comprehensive data privacy frameworks, giving individuals meaningful control over how organisations collect, use, and disclose their personal data. Whether you're a resident concerned about spam calls, a customer worried about how a retailer uses your loyalty data, or an employee wondering what your employer can legally do with your information, the PDPA gives you enforceable rights.

This guide breaks down your Singapore PDPA rights in plain language, explains how to exercise them, and shows you what to do when an organisation fails to comply.

What Is the Singapore PDPA?

The Personal Data Protection Act 2012 (PDPA) is Singapore's national data protection law, enforced by the Personal Data Protection Commission (PDPC). It regulates how private-sector organisations collect, use, disclose, and care for personal data belonging to individuals in Singapore.

The Act was significantly amended in 2020 and further strengthened through 2023-2025 updates, introducing mandatory data breach notification, higher financial penalties (up to 10% of annual turnover in Singapore for larger organisations), and expanded individual rights such as data portability.

Who the PDPA Covers

  • Applies to: All private-sector organisations that collect, use, or disclose personal data in Singapore, regardless of whether the organisation is based locally.
  • Protects: Any identifiable individual in Singapore, including citizens, permanent residents, work pass holders, and foreign visitors.
  • Excludes: Public agencies (governed separately under the Public Sector Governance Act) and personal or domestic data use.

What Counts as "Personal Data"

Personal data is any information about an individual who can be identified from that data, or from that data combined with other information the organisation has or is likely to have access to. Examples include:

  • Full name, NRIC or FIN number, passport number
  • Residential address, personal phone number, personal email
  • Photographs and video recordings where the person is identifiable
  • Biometric data, health records, and financial information
  • Vehicle plate numbers linked to an individual

The Nine Main Obligations Behind Your Rights

Your PDPA rights are the flip side of nine legal obligations placed on organisations. Understanding these obligations helps you recognise when your rights are being respected — or violated.

ObligationWhat It Requires
ConsentOrganisations must obtain your consent before collecting, using, or disclosing your data.
Purpose LimitationData can only be used for purposes a reasonable person would consider appropriate.
NotificationYou must be informed of the purposes before or at the time of collection.
Access & CorrectionYou can request access to your data and ask for corrections.
AccuracyOrganisations must make reasonable effort to keep your data accurate.
ProtectionReasonable security arrangements must protect your data.
Retention LimitationData must be deleted or anonymised once no longer needed.
Transfer LimitationOverseas data transfers must offer comparable protection.
AccountabilityOrganisations must appoint a Data Protection Officer (DPO) and publish policies.

Your Core PDPA Rights Explained

1. The Right to Be Informed

Before any organisation collects your personal data, it must clearly tell you what data it's collecting, why, and how it will be used. This is usually done through a privacy notice, a consent form, or a checkbox at the point of data collection.

If a bank asks for your NRIC, they must state whether it's for identity verification, credit checks, or marketing — and get separate consent for each purpose that isn't strictly necessary.

2. The Right to Give (or Withhold) Consent

Consent under the PDPA must be:

  1. Informed — you know what you're agreeing to.
  2. Voluntary — not a condition for a service unless the data is genuinely required.
  3. Specific — one consent doesn't cover unrelated future uses.

Deemed consent may apply where consent is obvious (e.g. giving your address to have goods delivered), but organisations cannot force you to consent to marketing as a condition of getting the core service.

3. The Right to Withdraw Consent

You can withdraw consent at any time by giving reasonable notice. The organisation must:

  • Inform you of the likely consequences of withdrawal (for example, service cancellation).
  • Stop using and disclosing your data for the purposes you withdrew consent for.
  • Not charge a fee for withdrawal.

4. The Right of Access

You can ask an organisation to tell you what personal data they hold about you and how it has been used or disclosed in the past year. Organisations must respond within 30 days or explain the delay. A reasonable fee may be charged, but only to cover administrative costs — not as a deterrent.

5. The Right to Correction

If you believe data held about you is inaccurate, incomplete, or misleading, you can request correction. Once corrected, the organisation must inform other organisations it had shared the data with in the past year — unless you agree otherwise.

6. The Right to Data Portability

Introduced under the 2020 amendments, the Data Portability Obligation (once fully operational under subsidiary legislation) allows you to request that your data be transmitted in a commonly used machine-readable format to another organisation of your choice. This is especially useful when switching banks, telcos, or subscription services.

7. The Right to Be Protected From Unsolicited Marketing

Under the Do Not Call (DNC) Registry — which is part of the PDPA framework — you can register your Singapore phone number to block:

  • Telemarketing calls
  • Marketing SMS and MMS
  • Marketing fax messages

Organisations must check the DNC Registry before sending marketing messages. Fines for breaching the DNC provisions have reached tens of thousands of Singapore dollars per case.

8. The Right to Be Notified of Data Breaches

Since February 2021, organisations must notify the PDPC — and in many cases, affected individuals — of data breaches that are likely to result in significant harm or that affect 500 or more individuals. Notification must generally happen within 3 calendar days of assessing the breach as notifiable.

How to Exercise Your PDPA Rights Step by Step

Step 1: Find the Organisation's Data Protection Officer

Every organisation must publish contact details for its DPO — usually on its website's privacy policy page. Look for a "Contact Us" section, a dedicated DPO email (often dpo@company.sg), or a mailing address.

Step 2: Submit a Written Request

Send a clear, written request. Include:

  1. Your full name and contact details.
  2. Enough information for them to identify your records (customer ID, account email).
  3. The specific right you're exercising (access, correction, withdrawal, portability).
  4. The date of the request.

Step 3: Wait for a Response

The organisation has 30 days to respond substantively. If they cannot meet the deadline, they must inform you in writing and provide a new date.

Step 4: Escalate to the PDPC If Necessary

If the organisation ignores you, refuses without valid reason, or mishandles your data, you can file a complaint with the PDPC via their online portal at pdpc.gov.sg. The PDPC can investigate, issue directions, and impose financial penalties.

Practical Ways to Protect Your Personal Data Day-to-Day

Rights on paper only matter if you also take practical steps to reduce your exposure. Here are habits that pair well with the PDPA framework:

Minimise What You Share

  • Never provide your full NRIC number unless legally required (Singapore has strict rules limiting NRIC collection).
  • Use separate email aliases for shopping, newsletters, and important accounts.
  • Avoid oversharing personal details on social media profiles.

Secure Your Online Footprint

  • Enable two-factor authentication on all key accounts (Singpass, banking, email).
  • Use a reputable password manager to generate unique passwords.
  • Prefer encrypted DNS services and privacy-focused browsers to reduce third-party tracking.
  • Review app permissions on your phone monthly and revoke anything unnecessary.

Be Careful With Links You Click and Share

Malicious short links are a common vector for phishing attacks targeting Singapore users, especially through WhatsApp and SMS impersonating banks or government agencies. When sharing links yourself — for business, marketing, or personal use — use a trustworthy shortening service that offers link analytics, expiry controls, and password protection so you're not exposing recipients to insecure redirects. Services like Lunyb offer these privacy-forward features without harvesting excessive personal data from your audience. For a wider look at options, see our 2026 buyer's guide to URL shorteners or our honest review of Lunyb.

PDPA vs GDPR: Quick Comparison

Many Singapore businesses ask whether complying with the EU's GDPR is enough. It's a helpful benchmark, but the two laws differ in important ways.

FeatureSingapore PDPAEU GDPR
RegulatorPDPCNational Data Protection Authorities
Max Financial Penalty10% of annual SG turnover or S$1M (whichever higher)4% of global turnover or €20M
Consent StandardConsent, deemed consent, legitimate interestsExplicit consent or other lawful bases
Breach NotificationWithin 3 days of assessing notifiabilityWithin 72 hours of awareness
Right to ErasureLimited (via consent withdrawal + retention limits)Explicit right to be forgotten
Data PortabilityIntroduced via 2020 amendmentsExplicit right
DPO RequirementMandatory for all organisationsMandatory in specific cases

Common PDPA Misconceptions

"I signed a form, so they can do anything with my data"

False. Consent is purpose-specific. A gym cannot use your registration data to sell you insurance simply because you signed a general form. Purposes must be clearly disclosed and reasonable.

"The PDPA doesn't apply to small businesses"

False. The PDPA applies to organisations of all sizes, from home-based sellers to multinationals. There are proportionality allowances, but the core obligations remain.

"Only Singapore citizens are protected"

False. The PDPA protects any individual whose personal data is collected in Singapore, regardless of nationality or immigration status.

"Business contact information is protected"

Partially false. Business contact information (name, business title, business phone/email) provided in a professional capacity is generally excluded from most PDPA obligations.

What Happens When Organisations Breach the PDPA

The PDPC regularly publishes enforcement decisions. Common outcomes include:

  • Warnings for minor or first-time infractions.
  • Directions to fix specific practices, appoint a DPO, or improve security.
  • Financial penalties ranging from a few thousand to over a million Singapore dollars.
  • Public naming in published decisions, which carries reputational damage.

Individuals who suffer loss or damage from a breach can also bring a private civil action against the organisation once PDPC enforcement is concluded.

Frequently Asked Questions

Can my employer collect my NRIC number under the PDPA?

Yes, but only where legally required (such as for CPF contributions, tax filings, or statutory checks) or where necessary to accurately establish identity to a high degree of fidelity. Employers should not photocopy NRICs unnecessarily and must protect any collected NRIC data.

How long does an organisation have to respond to my access request?

Organisations must respond within 30 days. If more time is needed, they must inform you in writing before the deadline and provide a reasonable revised timeline.

Can I sue an organisation directly under the PDPA?

Yes. Section 48O of the PDPA gives individuals the right to bring a private civil action for loss or damage suffered as a direct result of a PDPA breach, but only after the PDPC's enforcement proceedings against that organisation are complete.

Does the PDPA cover CCTV footage of me in public places?

Yes, if the footage identifies you and is collected by a private organisation. The organisation must post clear notices about CCTV recording, use the footage only for stated purposes (e.g. security), and protect it against unauthorised access.

What should I do if I receive marketing calls after joining the DNC Registry?

Note the caller's identity, phone number, date, and time. File a complaint through the PDPC's online complaint portal. Confirmed breaches can result in significant fines against the offending organisation.

Final Thoughts

The Singapore PDPA gives you real, enforceable control over your personal data — but those rights only work when you use them. Read privacy notices before ticking consent boxes, register on the DNC list, submit access requests when you're curious about what companies know about you, and don't hesitate to escalate to the PDPC if an organisation stonewalls you.

Combine those legal rights with sensible digital hygiene — strong passwords, minimal data sharing, and privacy-respecting tools — and you'll be far ahead of the average Singapore consumer when it comes to protecting your identity in an increasingly data-driven economy.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles