facebook-pixel

Singapore PDPA: Your Personal Data Protection Rights Explained

L
Lunyb Security Team
··10 min read

Singapore's Personal Data Protection Act (PDPA) is the cornerstone of how organisations must handle your personal information. Enacted in 2012 and significantly strengthened by the 2020 amendments, the PDPA gives every individual in Singapore a set of enforceable rights over how their data is collected, used, disclosed, and protected. Whether you're signing up for a mobile plan, applying for a bank account, or shopping online, these rights apply to you.

This guide breaks down your PDPA rights in plain English, explains the obligations placed on organisations, and shows you exactly what to do when your data is mishandled.

What Is the Singapore PDPA?

The Personal Data Protection Act 2012 is Singapore's baseline data protection law, administered by the Personal Data Protection Commission (PDPC). It governs the collection, use, and disclosure of personal data by private sector organisations, while public agencies are governed by a separate framework under the Public Sector (Governance) Act.

The PDPA defines personal data as any data about an individual who can be identified from that data, or from that data together with other information the organisation has access to. This includes obvious identifiers like your NRIC and phone number, but also things like IP addresses, photos, and behavioural data that can identify you.

Key Milestones of the PDPA

  • 2012: PDPA enacted, establishing the PDPC.
  • 2014: Main data protection obligations came into force.
  • 2020: Major amendments introduced mandatory breach notification, data portability, and higher financial penalties.
  • 2022 onwards: Penalties raised to up to 10% of annual Singapore turnover or S$1 million, whichever is higher.

Your Core Rights Under the PDPA

The PDPA gives individuals a defined set of rights that organisations must honour. Understanding these rights is the first step to controlling your digital footprint in Singapore.

1. The Right to Be Informed (Notification Obligation)

Before or at the time of collecting your personal data, organisations must tell you the purposes for which the data will be collected, used, or disclosed. Vague statements like "for business purposes" are not sufficient. The notice must be specific enough that you can make an informed decision about whether to give consent.

2. The Right to Give (and Withdraw) Consent

Consent is the foundation of the PDPA. Organisations generally cannot collect, use, or disclose your personal data without your consent, unless an exception applies (such as legal obligations or vital interests).

Equally important, you have the right to withdraw consent at any time by giving reasonable notice. Once you withdraw, the organisation must stop collecting, using, or disclosing your data for the previously consented purposes, and inform you of the likely consequences.

3. The Right of Access

You can request an organisation to provide you with:

  • Personal data about you that is in its possession or under its control.
  • Information about how that data has been used or disclosed in the past year.

Organisations must respond as soon as reasonably possible, generally within 30 days, and may charge a reasonable fee to cover the cost of retrieval.

4. The Right of Correction

If your personal data is inaccurate or incomplete, you have the right to request a correction. The organisation must correct the data as soon as practicable and send the corrected data to every other organisation to which it disclosed the data within the past year, unless you consent otherwise.

5. The Right to Data Portability (New Under 2020 Amendments)

Introduced by the 2020 amendments and being progressively implemented, the data portability obligation allows you to request that an organisation transmit your data in a commonly used machine-readable format to another organisation. This makes it easier to switch service providers without losing your information.

6. The Right to Be Notified of Data Breaches

Since February 2021, organisations must notify the PDPC and affected individuals of a data breach that:

  • Results in, or is likely to result in, significant harm to affected individuals; or
  • Is of a significant scale (involving 500 or more individuals).

Notification to the PDPC must occur within 72 hours of assessing the breach as notifiable.

7. The Right Against Unwanted Marketing (Do Not Call Registry)

The PDPA also contains the Do Not Call (DNC) provisions. Once you register your Singapore telephone number on the DNC Registry, organisations cannot send you marketing messages, calls, or faxes without clear and unambiguous consent.

The 11 Main Data Protection Obligations for Organisations

To make your rights meaningful, the PDPA imposes 11 core obligations on organisations. Knowing these helps you recognise when a company is falling short.

ObligationWhat It Means
ConsentGet valid consent before collecting, using, or disclosing personal data.
Purpose LimitationOnly use data for purposes a reasonable person would consider appropriate.
NotificationInform individuals of purposes before collection.
Access & CorrectionProvide access to data and correct inaccuracies on request.
AccuracyMake reasonable effort to ensure data is accurate and complete.
ProtectionApply reasonable security arrangements to protect personal data.
Retention LimitationCease retention once the purpose is fulfilled and legal requirements end.
Transfer LimitationOnly transfer data overseas to jurisdictions with comparable protection.
AccountabilityAppoint a Data Protection Officer (DPO) and have policies in place.
Data Breach NotificationNotify PDPC and affected individuals of notifiable breaches.
Data PortabilityTransmit data to another organisation on request (when in force).

How to Exercise Your PDPA Rights: A Step-by-Step Guide

Exercising your rights doesn't have to be intimidating. Follow this process to make sure your request is taken seriously.

  1. Identify the correct organisation. Determine which company holds your data. If you're unsure, start with the entity you originally interacted with.
  2. Find the Data Protection Officer (DPO). Every organisation must publish DPO contact details, typically on their website's privacy policy page.
  3. Submit a written request. Send an email clearly stating whether you're requesting access, correction, withdrawal of consent, or data portability. Be specific about the data involved.
  4. Provide identity verification. Organisations may reasonably ask you to verify your identity to prevent fraudulent requests.
  5. Wait for a response. Most requests should be answered within 30 days. If more time is needed, the organisation must tell you why.
  6. Escalate if necessary. If the response is inadequate or delayed without reason, you can lodge a complaint with the PDPC.

Sample Language for a PDPA Access Request

"Under section 21 of the Personal Data Protection Act 2012, I am requesting access to all personal data about me that your organisation holds, along with information about how this data has been used or disclosed in the past 12 months. Please respond within 30 days as required by the PDPA."

What Happens When Organisations Break the PDPA

The PDPC has real teeth. Following the 2022 penalty increases, organisations that breach the PDPA can face financial penalties of up to 10% of their annual turnover in Singapore, or S$1 million, whichever is higher. The PDPC also has powers to issue directions, require remedial action, and publish enforcement decisions publicly, which carries significant reputational risk.

Recent enforcement cases have targeted a range of failures, including inadequate security controls that led to breaches, excessive collection of NRIC numbers, and failure to appoint a Data Protection Officer. The PDPC regularly publishes decisions, which are valuable reading for anyone wanting to understand how the law is applied in practice.

Practical Steps to Protect Your Personal Data in Singapore

Knowing your rights is only half the equation. Practical habits reduce your exposure in the first place.

Limit What You Share

Since 1 September 2019, organisations generally cannot collect, use, or disclose NRIC numbers or make copies of NRIC cards, except where required by law or necessary to accurately establish identity to a high degree of fidelity. If a shop or website asks for your NRIC unnecessarily, push back.

Use Privacy-Focused Tools

Use encrypted messaging apps, browsers that block trackers, and privacy-respecting search engines. When sharing links online — for example on social media or in customer communications — use a shortener that respects your privacy rather than one that aggressively fingerprints clickers. If you run a business or send links frequently, services like Lunyb offer clean, privacy-conscious short links; you can read our own honest review of Lunyb or compare it against alternatives in our 2026 URL shortener buyer's guide.

Register for the Do Not Call Registry

Register your mobile and landline numbers at the DNC Registry to cut unwanted telemarketing. It takes minutes and is free.

Audit App Permissions

Review the permissions granted to mobile apps every few months. Revoke access to location, contacts, or microphone for apps that don't need it.

Use Strong, Unique Passwords

Adopt a password manager and enable two-factor authentication (2FA) on important accounts — especially banking, government (Singpass), and email.

PDPA vs GDPR: Quick Comparison

Many Singaporean organisations serve customers in the EU and must comply with both regimes. Here's how they compare at a glance.

FeatureSingapore PDPAEU GDPR
RegulatorPDPCNational Data Protection Authorities
Maximum Penalty10% of SG turnover or S$1M4% of global turnover or €20M
Consent StandardDeemed consent permitted in some casesExplicit, freely given consent required
Breach NotificationWithin 72 hours (if notifiable)Within 72 hours
Data PortabilityYes (being phased in)Yes
Right to ErasureNo explicit "right to be forgotten"Yes, Article 17
DPO RequirementMandatory for all organisationsOnly for certain organisations

Filing a Complaint with the PDPC

If an organisation fails to respond to your request or you believe your data has been mishandled, you can file a complaint with the PDPC.

  1. Try to resolve directly first. The PDPC generally expects individuals to attempt resolution with the organisation before escalating.
  2. Gather evidence. Keep copies of your original request, the organisation's response (or lack thereof), and any relevant correspondence.
  3. Submit a complaint via the PDPC website. Use the official complaint form and provide clear details of what happened and what outcome you're seeking.
  4. Cooperate with the investigation. The PDPC may request additional information or documentation.
  5. Consider alternative dispute resolution. The PDPC may refer certain complaints to mediation before formal investigation.

Frequently Asked Questions

Does the PDPA apply to individuals acting in a personal capacity?

No. The PDPA does not apply to individuals acting in a personal or domestic capacity. It also does not apply to employees acting in the course of their employment or to public agencies. However, business contact information (name, title, work phone) is largely excluded from the main obligations.

Can I ask an organisation to delete my personal data?

The PDPA does not include a standalone "right to erasure" like the GDPR. However, you can withdraw consent for the collection, use, or disclosure of your data. Combined with the retention limitation obligation, this often results in deletion when the organisation no longer has a legal basis to keep it.

How long can an organisation keep my personal data?

Only for as long as necessary to fulfil the purpose for which it was collected, or as required by law. Once the purpose is no longer served and there is no legal reason to keep it, the organisation must cease retention or anonymise the data.

What is deemed consent under the PDPA?

Deemed consent applies when you voluntarily provide personal data for a purpose and it is reasonable that you would do so. The 2020 amendments expanded this to include deemed consent by notification (for certain business purposes) and by contractual necessity, provided organisations meet strict conditions including risk assessments.

Are overseas companies subject to the PDPA?

Yes, if they collect, use, or disclose personal data in Singapore. The PDPA has extraterritorial reach when organisations process the personal data of individuals in Singapore, even if the organisation itself has no physical presence here.

Final Thoughts

The Singapore PDPA gives you meaningful control over your personal data — but only if you know how to use it. From the right to access and correct your information to the right to be notified of breaches, these protections were designed to keep pace with a digital economy that increasingly runs on data.

Take a few minutes today to review the privacy policies of the services you use most, register on the DNC Registry if you haven't already, and bookmark the PDPC website for future reference. Data protection is not a one-time task; it's an ongoing habit that pays dividends every year you spend online.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles