facebook-pixel

Singapore PDPA: Your Personal Data Protection Rights Explained

L
Lunyb Security Team
··11 min read

Singapore's Personal Data Protection Act (PDPA) is the cornerstone of data privacy law in the Lion City. Whether you're a resident, an employee, a customer of a local business, or simply someone whose personal information has ended up in a Singapore-registered organisation's database, the PDPA gives you specific, enforceable rights over how your data is handled. Yet many people in Singapore remain unclear about what these rights actually are, how to exercise them, and what to do when an organisation refuses to cooperate.

This guide explains your PDPA rights in plain language, walks through the process of making a request or filing a complaint, and highlights recent amendments that expand your protections in 2026.

What Is the Singapore PDPA?

The Personal Data Protection Act 2012 (PDPA) is Singapore's baseline law governing the collection, use, disclosure, and care of personal data by private-sector organisations. It is administered by the Personal Data Protection Commission (PDPC), which sits within the Infocomm Media Development Authority (IMDA).

The PDPA covers any data — electronic or otherwise — from which an individual can be identified. This includes obvious identifiers like NRIC numbers, names, and phone numbers, but also less obvious data points such as IP addresses, CCTV footage, location data, and even voice recordings when combined with other information.

Who Must Comply?

The PDPA applies to all private-sector organisations that collect, use, or disclose personal data in Singapore, regardless of where the organisation is headquartered. Public agencies are governed separately under the Public Sector (Governance) Act, though the standards are broadly aligned.

Notably, the PDPA also has extraterritorial reach: an overseas company that processes the personal data of individuals in Singapore may still fall under its scope.

Your Core PDPA Rights at a Glance

The PDPA grants individuals a defined set of rights. Understanding each one is the first step to exercising meaningful control over your personal information.

RightWhat It MeansPDPA Reference
Right to Be InformedOrganisations must tell you why they are collecting your data before or at the point of collection.Notification Obligation
Right to ConsentYour data cannot be collected, used, or disclosed without your consent, subject to exceptions.Consent Obligation
Right to Withdraw ConsentYou may withdraw consent at any time with reasonable notice.Section 16
Right of AccessYou can request a copy of the personal data an organisation holds about you.Section 21
Right of CorrectionYou can ask for inaccurate or incomplete data to be corrected.Section 22
Right to Data PortabilityYou can request that your data be transmitted to another organisation in a common format.Part VIB (in force)
Right to Be Notified of BreachesOrganisations must notify you if a data breach is likely to cause significant harm.Part VIA

Right 1: The Right to Be Informed

Before an organisation collects your personal data, it must clearly tell you the purposes for which the data will be collected, used, or disclosed. This is typically done through a privacy notice or a data protection statement on a website, mobile app, or physical form.

A compliant notice should explain:

  • What data is being collected
  • Why it is being collected
  • How it will be used
  • To whom it may be disclosed
  • How to contact the organisation's Data Protection Officer (DPO)

If a notice is vague, buried in fine print, or missing entirely, the organisation is likely in breach of the Notification Obligation.

Right 2: The Right to Consent (and to Withdraw It)

Consent is the foundation of the PDPA. In most cases, an organisation cannot collect, use, or disclose your personal data unless you have consented. Consent must be given freely and can be express (a tick box) or deemed (for example, providing your email address to receive an e-receipt).

Withdrawing Consent

You have the right to withdraw consent at any time by giving reasonable notice. Once you withdraw, the organisation must stop collecting, using, or disclosing your data for the withdrawn purpose — though it may retain certain records if required by law (for example, tax or accounting obligations).

The organisation must inform you of the likely consequences of withdrawal (such as no longer being able to provide a service), but it cannot penalise you for exercising the right.

Right 3: The Right of Access

Under Section 21 of the PDPA, you can submit a written request to any organisation asking for:

  1. A copy of the personal data about you in its possession or control
  2. Information about how that data has been used or disclosed within the past year

The organisation must respond as soon as reasonably possible — typically within 30 days. If it cannot meet this timeframe, it must notify you in writing of the reason for the delay and the new expected date.

Fees and Refusals

Organisations may charge a reasonable fee for access requests to cover administrative costs, but the fee cannot be excessive. There are limited grounds on which an organisation can refuse, such as when disclosure would reveal personal data about another individual, threaten someone's safety, or compromise an ongoing investigation.

Right 4: The Right of Correction

If you discover that an organisation holds inaccurate, incomplete, misleading, or out-of-date personal data about you, you can request a correction under Section 22. The organisation must:

  • Correct the data as soon as practicable
  • Send the corrected data to every other organisation to which the original data was disclosed within the past year (unless you agree otherwise)

If the organisation disagrees with your correction request, it must annotate the data with the correction that was requested but not made. This ensures your version of the truth is at least on record.

Right 5: The Right to Data Portability

Introduced through the 2020 PDPA amendments and progressively brought into force, the Data Portability Obligation allows you to request that an organisation transmit your data — in a commonly used machine-readable format — directly to another organisation of your choice.

This right is particularly powerful when switching service providers such as telcos, banks, insurers, or digital platforms. It reduces switching costs and gives you real leverage in a competitive market.

What Data Is Portable?

Portable data generally includes data you have provided to the organisation and data generated through your use of its service. It does not usually include derived data (such as internal credit scores or profiling outputs).

Right 6: The Right to Be Notified of Data Breaches

Since 1 February 2021, the mandatory Data Breach Notification obligation requires organisations to notify both the PDPC and affected individuals when a breach:

  • Results in, or is likely to result in, significant harm to affected individuals, OR
  • Is of a significant scale (500 or more individuals affected)

Notification to the PDPC must occur within 3 calendar days of the organisation assessing that a notifiable breach has occurred. Individuals must be notified as soon as practicable so they can take protective steps — such as changing passwords, monitoring bank accounts, or freezing credit.

The Do Not Call Registry: A Related Right

Part IX of the PDPA established the Do Not Call (DNC) Registry, which lets Singapore telephone numbers opt out of marketing calls, texts, and faxes. You can register your number for free at the DNC website, and organisations must check the registry before sending marketing messages.

Breaches of DNC rules carry significant fines, and enforcement has become notably more active in recent years.

How to Exercise Your PDPA Rights: A Step-by-Step Process

  1. Identify the organisation's DPO. Every organisation must appoint a Data Protection Officer whose contact details should be publicly available (typically in the privacy policy).
  2. Submit a written request. Email is acceptable. Clearly state the right you are exercising (access, correction, withdrawal, or portability) and provide enough information to identify yourself.
  3. Wait for a response. The organisation should acknowledge receipt promptly and substantively respond within 30 days.
  4. Pay any reasonable fee if requested for access requests.
  5. Escalate if unsatisfied. If the organisation refuses, delays unreasonably, or provides an inadequate response, you can lodge a complaint with the PDPC.

Filing a Complaint with the PDPC

The PDPC accepts complaints through its online portal at pdpc.gov.sg. Before filing, you are generally expected to have raised the issue with the organisation directly and given it a reasonable opportunity to resolve the matter.

What Happens After You Complain?

The PDPC may investigate, mediate between you and the organisation, or refer the matter to the Data Protection Appeal Committee. Penalties for breaches can be severe: under the amended PDPA, financial penalties can reach up to 10% of an organisation's annual turnover in Singapore (for organisations with turnover exceeding S$10 million) or S$1 million, whichever is higher.

Recent Amendments You Should Know About

Singapore's PDPA has evolved significantly since 2020, and further refinements continue into 2026. Key developments include:

  • Higher financial penalties aligned with global standards
  • Mandatory data breach notification with strict timelines
  • Enhanced framework for deemed consent by contractual necessity and legitimate interests
  • New offences for egregious mishandling of personal data by individuals, including unauthorised disclosure and re-identification of anonymised data
  • Expanded exceptions for business improvement allowing limited use of data without consent for legitimate operational needs

Practical Steps to Protect Your Personal Data

Knowing your rights is one half of the equation; proactively protecting your data is the other. Here are practical measures every Singapore resident should consider:

  1. Register on the DNC Registry to reduce unsolicited marketing.
  2. Read privacy notices before consenting — even a quick scan of the purposes section reveals a lot.
  3. Use strong, unique passwords and enable two-factor authentication where offered.
  4. Be selective with your NRIC. Under PDPC guidelines, organisations generally cannot collect, use, or disclose NRIC numbers unless required by law or necessary to accurately establish identity to a high degree of fidelity.
  5. Shorten and mask links you share publicly. When posting links on social media or in newsletters, consider using a privacy-conscious link management service such as Lunyb to avoid exposing tracking parameters or identifying URL structures. You can read our honest review of Lunyb for more on how it stacks up.
  6. Review app permissions regularly on your smartphone and revoke access for apps you no longer use.
  7. Encrypt sensitive files before uploading them to cloud storage.

PDPA vs GDPR: A Quick Comparison

Many Singapore organisations also handle EU data and must therefore navigate both regimes. Here's how the two frameworks compare on key rights:

FeatureSingapore PDPAEU GDPR
Right of AccessYes (30 days)Yes (1 month)
Right of CorrectionYesYes (Rectification)
Right to ErasureLimited (via withdrawal of consent)Yes (Right to be Forgotten)
Right to Data PortabilityYesYes
Right to Object to Automated DecisionsNot explicitYes
Breach Notification Window3 days to PDPC72 hours to DPA
Max Fines10% of SG turnover or S$1m4% of global turnover or €20m

Common Misconceptions About PDPA Rights

"The PDPA gives me a right to be forgotten."

Not exactly. Unlike the GDPR, the PDPA does not include a standalone right to erasure. However, you can achieve a similar outcome by withdrawing consent, after which the organisation must cease using your data and, in many cases, delete it.

"I can demand my data for free."

Organisations may charge a reasonable fee for access requests. They cannot, however, charge for correction requests or breach notifications.

"The PDPA doesn't apply to overseas companies."

It does, if they collect or process personal data of individuals in Singapore. Extraterritorial enforcement is challenging but increasingly pursued.

Frequently Asked Questions

How long does an organisation have to respond to a PDPA access request?

Organisations must respond as soon as reasonably possible, generally within 30 days. If they need more time, they must inform you in writing of the reason and provide a revised timeline.

Can I sue an organisation directly for a PDPA breach?

Yes. Section 48O of the PDPA gives individuals a private right of action to seek relief in civil proceedings if they suffer loss or damage directly as a result of a contravention. You typically need to first pursue enforcement through the PDPC.

Does the PDPA cover data collected before 2013?

Yes, the PDPA applies to personal data regardless of when it was collected. However, organisations are only required to obtain fresh consent for new purposes introduced after the PDPA came into force.

Can my employer collect my NRIC number?

Employers may collect NRIC numbers where necessary to comply with legal requirements (such as CPF contributions or tax filings). For most other purposes, alternative identifiers should be used.

What should I do if I receive a data breach notification?

Take it seriously. Change any relevant passwords immediately, enable two-factor authentication, monitor your financial accounts for unusual activity, and consider requesting a credit report. If the breach involves identity documents, alert the relevant authorities and, where appropriate, banks and government agencies.

Conclusion

Singapore's PDPA gives you real, enforceable rights over your personal data — but these rights only matter if you know how to use them. From requesting access to your data and correcting inaccuracies to withdrawing consent and porting your information to a new provider, the PDPA framework empowers individuals to hold organisations accountable.

Combine your legal rights with strong personal privacy habits — careful sharing, strong authentication, and privacy-conscious tools — and you'll be well-positioned to protect your digital identity in 2026 and beyond. For more on privacy-friendly online tools, see our 2026 URL shortener buyer's guide.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles