facebook-pixel

Singapore PDPA: Your Personal Data Protection Rights Explained

L
Lunyb Security Team
··10 min read

Singapore's Personal Data Protection Act (PDPA) is the cornerstone of data privacy law in the Lion City, giving every individual meaningful control over how organisations collect, use, and disclose their personal data. Whether you're a Singapore resident concerned about how your information is handled or a business trying to stay compliant, understanding your Singapore PDPA rights is essential in 2026.

This guide breaks down the PDPA in plain English, explains each of your rights, and shows you exactly how to exercise them when an organisation mishandles your data.

What Is the Singapore PDPA?

The Personal Data Protection Act 2012 (PDPA) is Singapore's primary data protection law, enforced by the Personal Data Protection Commission (PDPC). It governs how private-sector organisations collect, use, disclose, and safeguard personal data belonging to individuals in Singapore.

The PDPA came into full effect in July 2014 and has been amended several times, most notably in 2020 to introduce mandatory data breach notification, expanded consent frameworks, and increased financial penalties. As of 2026, organisations can face fines of up to 10% of annual turnover in Singapore or S$1 million, whichever is higher, for serious breaches.

Who the PDPA Applies To

  • All private-sector organisations operating in Singapore, regardless of size or where they are headquartered
  • Data intermediaries that process personal data on behalf of another organisation
  • Overseas organisations that collect, use, or disclose personal data in Singapore

Public agencies are governed separately by the Public Sector (Governance) Act, not the PDPA.

What Counts as Personal Data Under PDPA?

Personal data is any data, true or false, about an individual who can be identified from that data alone or in combination with other information the organisation has or is likely to have access to.

Examples include:

  • Full name, NRIC or FIN number, passport number
  • Residential address, mobile number, personal email
  • Photographs, CCTV footage, voice recordings
  • Biometric data such as fingerprints and facial scans
  • Financial information, credit card numbers, bank details
  • Medical records and health information
  • Employment history and educational qualifications

Business contact information (name, business title, business phone, business email) used strictly for business purposes is generally excluded from most PDPA obligations.

Your Core Rights Under the Singapore PDPA

The PDPA grants you several enforceable rights over your personal data. Here are the most important ones every Singapore resident should know.

1. The Right to Be Informed (Notification Obligation)

Before or at the time an organisation collects your personal data, it must inform you of the purposes for which your data will be collected, used, or disclosed. This is why you see privacy notices at sign-up forms, on websites, and in mobile app onboarding screens.

If an organisation later wants to use your data for a new purpose, it must notify you and, in most cases, obtain fresh consent.

2. The Right to Consent (and Withdraw It)

Organisations generally need your consent to collect, use, or disclose your personal data. Consent must be:

  1. Informed – you must understand what you're consenting to
  2. Voluntary – not obtained through deceptive or coercive practices
  3. Specific – tied to clearly stated purposes

You can withdraw consent at any time by giving reasonable notice. Once you withdraw, the organisation must stop collecting, using, or disclosing your data – though they may retain it if legally required (for example, financial records under tax law).

3. The Right of Access

You can request a copy of the personal data an organisation holds about you, along with information on how that data has been used or disclosed within the past year. Organisations must generally respond within 30 days and may charge a reasonable fee.

4. The Right of Correction

If you find that personal data held about you is inaccurate, incomplete, misleading, or out of date, you can request that the organisation correct it. Once corrected, they must also notify other organisations they previously shared that data with (unless you agree otherwise).

5. The Right to Data Portability

Introduced in the 2020 amendments and progressively rolled out, the data portability obligation lets you request that an organisation transmit your data in a commonly used machine-readable format to another organisation. This makes it easier to switch service providers without losing your history.

6. The Right to Be Notified of Data Breaches

Since February 2021, organisations must notify the PDPC and affected individuals of data breaches that are likely to result in significant harm or involve 500 or more individuals. Notification to the PDPC must happen within 3 calendar days of assessing that a notifiable breach occurred.

The Nine Data Protection Obligations at a Glance

The PDPA imposes nine main obligations on organisations. Understanding them helps you recognise when your rights may have been violated.

Obligation What It Means
Consent Must obtain valid consent before collecting, using, or disclosing personal data
Purpose Limitation Data can only be used for purposes a reasonable person would consider appropriate
Notification Must inform individuals of collection purposes
Access & Correction Must provide access and correct data on request
Accuracy Must make reasonable effort to keep data accurate and complete
Protection Must implement reasonable security arrangements
Retention Limitation Must stop retaining data once purpose is fulfilled
Transfer Limitation Overseas transfers must offer comparable protection to PDPA
Data Breach Notification Must notify PDPC and affected individuals of notifiable breaches

How to Exercise Your PDPA Rights

Exercising your rights under the PDPA is more straightforward than many people realise. Follow this simple process to make an access, correction, or withdrawal request.

Step 1: Identify the Data Protection Officer (DPO)

Every organisation in Singapore is required to appoint a Data Protection Officer. Their contact details should be available on the organisation's website (usually in the privacy policy) or by contacting customer service.

Step 2: Submit a Written Request

Send your request in writing (email is acceptable). Be specific about what you want:

  • For access: state clearly that you're requesting a copy of your personal data under section 21 of the PDPA
  • For correction: identify the specific data that is inaccurate and provide the correct information
  • For withdrawal: state that you're withdrawing consent and specify which purposes

Step 3: Wait Up to 30 Days

Organisations must respond within 30 days. If they need more time, they must inform you in writing with a reasonable estimated date. Access requests may involve a modest fee, but organisations must give a written estimate first.

Step 4: Escalate to the PDPC If Necessary

If the organisation refuses your request without valid grounds, ignores you, or handles your data improperly, you can file a complaint with the PDPC at pdpc.gov.sg. The PDPC can investigate, mediate, and issue directions or financial penalties.

Common PDPA Exceptions to Be Aware Of

Your rights are strong but not absolute. Organisations can legally decline certain requests when:

  • Disclosure would reveal personal data about another individual
  • The data is subject to legal privilege
  • Providing access could threaten someone's safety or health
  • The request is frivolous, vexatious, or would require disproportionate effort
  • The data is used solely for domestic or personal purposes
  • The data relates to journalistic, artistic, or literary purposes

Do Not Call (DNC) Registry: A Related Right

The PDPA also established Singapore's Do Not Call Registry, which lets you opt out of unsolicited marketing messages sent to your local phone number. You can register your Singapore number for free at dnc.gov.sg, covering three separate lists: voice calls, text messages, and fax messages.

Once registered, organisations must check the DNC Registry before sending marketing messages, unless they have your clear and unambiguous consent in writing.

Practical Tips for Protecting Your Personal Data in Singapore

Knowing your rights is only half the battle. Here are proactive steps to reduce your exposure in the first place.

1. Minimise What You Share

When signing up for services, ask yourself whether every field is truly necessary. Skip optional fields and never share your NRIC number unless legally required (the PDPC has strict guidelines against unnecessary NRIC collection).

2. Read Privacy Policies (At Least Skim Them)

Look for the sections on data sharing, retention periods, and overseas transfers. If a policy is vague or reserves broad rights to share your data, think twice.

3. Use Privacy-Respecting Tools

Choose services that limit data collection by design. For example, when sharing links publicly, consider using a privacy-focused link shortener like Lunyb that doesn't require accounts for basic use and avoids invasive tracking. You can read our honest review of Lunyb or compare it against alternatives in our 2026 URL shortener buyer's guide.

4. Enable Two-Factor Authentication

Even the best privacy law won't protect you if your account gets compromised. Enable 2FA on every service that offers it, especially your Singpass, email, and banking accounts.

5. Review App Permissions Regularly

Mobile apps often request more permissions than they need. Audit them every few months and revoke anything unnecessary.

PDPA vs GDPR: Quick Comparison

Singapore's PDPA is often compared to the EU's General Data Protection Regulation. Here's how they differ.

Feature Singapore PDPA EU GDPR
Maximum Fine 10% of Singapore turnover or S$1M 4% of global turnover or €20M
Consent Standard Deemed consent allowed in some cases Explicit consent required
Breach Notification 3 days to PDPC 72 hours to supervisory authority
Right to Erasure Limited (via consent withdrawal) Explicit "right to be forgotten"
Data Portability Being rolled out progressively Fully in force
DPO Requirement Mandatory for all organisations Mandatory only in specific cases

What to Do If Your PDPA Rights Are Violated

If you believe an organisation has mishandled your personal data, follow these escalation steps:

  1. Contact the DPO first – give the organisation a reasonable chance to address your concern
  2. Document everything – keep copies of emails, screenshots, and dates
  3. File a complaint with the PDPC – use the online complaint form at pdpc.gov.sg
  4. Consider civil action – since 2022, individuals can pursue private civil claims for loss or damage caused by PDPA breaches

Recent enforcement actions have shown the PDPC is willing to impose substantial fines. Major penalties against companies in the healthcare, e-commerce, and telecom sectors demonstrate that the regulator takes systemic failures seriously.

Frequently Asked Questions

Does the PDPA apply to foreign companies serving Singapore customers?

Yes. If a company collects, uses, or discloses personal data in Singapore – even if it is headquartered overseas – the PDPA applies. This includes global platforms serving Singapore users.

Can my employer collect my NRIC number?

Employers can collect NRIC numbers where required by law (for CPF contributions, tax reporting, etc.) or where necessary to accurately identify individuals for high-risk activities. Routine collection of NRIC for non-essential purposes like membership sign-ups is prohibited under the PDPC's NRIC advisory guidelines.

How long can organisations keep my personal data?

The Retention Limitation Obligation requires organisations to stop retaining personal data as soon as it is no longer necessary for the original purpose or for legal or business reasons. There's no fixed timeline – it depends on the context, though tax and employment records typically have statutory minimum retention periods.

Is my WhatsApp or Telegram data protected under PDPA?

Personal communications between individuals for private purposes are generally excluded. However, if a business uses WhatsApp or Telegram to communicate with customers, the personal data collected through those conversations is subject to the PDPA.

Can I sue a company directly for a PDPA breach?

Yes. Since October 2022, individuals who suffer loss or damage from a breach of the PDPA's data protection provisions can bring a private right of action in Singapore's civil courts, in addition to any action taken by the PDPC.

Final Thoughts

The Singapore PDPA gives you real, enforceable rights over your personal data – but those rights only matter if you know how to use them. Take a few minutes today to review the privacy policies of services you rely on most, exercise your access rights where you're curious, and register your number on the DNC Registry if you haven't already.

Combined with sensible personal habits – minimising data sharing, using privacy-respecting tools, and enabling strong authentication – the PDPA provides a solid foundation for taking back control of your digital life in Singapore.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles