facebook-pixel

Singapore PDPA: Your Personal Data Protection Rights Explained

L
Lunyb Security Team
··10 min read

Singapore's Personal Data Protection Act (PDPA) is the cornerstone of the country's data protection framework, giving individuals meaningful control over how organisations collect, use, and disclose their personal information. Whether you're a Singapore resident wanting to protect your privacy or a business trying to stay compliant, understanding your PDPA rights is essential in 2026.

This guide breaks down the PDPA in plain English, explains each of your rights as a data subject, and outlines what organisations must do to respect those rights. We'll also cover recent amendments, enforcement trends, and practical steps you can take if your data is mishandled.

What Is the Singapore PDPA?

The Personal Data Protection Act 2012 (PDPA) is Singapore's primary data protection law, administered by the Personal Data Protection Commission (PDPC). It governs how private sector organisations handle personal data and grants individuals specific rights over their information.

The PDPA came into full effect in July 2014 and has since been amended several times, most notably in 2020, to introduce mandatory data breach notification, expanded consent frameworks, and higher financial penalties. As of 2026, maximum fines can reach up to 10% of an organisation's annual turnover in Singapore or S$1 million, whichever is higher.

Who Does the PDPA Apply To?

The PDPA applies to all private sector organisations that collect, use, or disclose personal data in Singapore, regardless of whether the organisation itself is based in Singapore. It does not apply to:

  • Public agencies (which are governed by the Public Sector Governance Act)
  • Individuals acting in a personal or domestic capacity
  • Employees acting in the course of their employment
  • Business contact information used strictly for business purposes

What Counts as Personal Data?

Personal data is any data about an individual who can be identified from that data, or from that data combined with other information the organisation has or is likely to have access to. Examples include:

  • Full name, NRIC number, and passport number
  • Home address, phone number, and email address
  • Photographs, voice recordings, and biometric data
  • Financial records, health records, and employment history
  • IP addresses and device identifiers when linked to an identifiable person

Your Core Rights Under the Singapore PDPA

The PDPA gives you five foundational rights over your personal data. These rights form the basis of every complaint, request, or dispute you might have with an organisation handling your information.

1. The Right to Be Informed

Before or at the time an organisation collects your personal data, it must inform you of the purposes for which the data will be collected, used, or disclosed. This is known as the Notification Obligation. In practice, this is why you see privacy notices and consent checkboxes on websites, apps, and paper forms.

2. The Right to Give and Withdraw Consent

Organisations generally need your consent to collect, use, or disclose your personal data. Consent must be freely given, and you have the right to withdraw it at any time by giving reasonable notice. Once you withdraw consent, the organisation must stop processing your data for the withdrawn purposes and inform you of the likely consequences.

Note that the 2020 amendments introduced additional legal bases beyond consent, including "legitimate interests" and "business improvement" purposes, but these come with strict conditions and assessments.

3. The Right of Access

You have the right to request access to personal data an organisation holds about you, as well as information on how that data has been used or disclosed within the past year. Organisations must respond as soon as reasonably possible, typically within 30 days, and may charge a reasonable fee for compliance.

4. The Right of Correction

If your personal data is inaccurate or incomplete, you can request that the organisation correct it. Once corrected, the organisation must send the amended data to every other organisation it disclosed the data to in the past year, unless you consent otherwise.

5. The Right to Data Portability (Coming Into Force)

The 2020 amendments introduced a Data Portability Obligation, allowing you to request that your data be transmitted directly to another organisation in a commonly used machine-readable format. Implementation details continue to roll out through subsidiary legislation, and organisations should monitor PDPC guidance closely.

Organisation Obligations Under the PDPA

Your rights only matter if organisations meet their corresponding obligations. The PDPA imposes nine main obligations on organisations that handle personal data.

ObligationWhat It Requires
ConsentObtain valid consent before collecting, using, or disclosing personal data
Purpose LimitationOnly use data for purposes a reasonable person would consider appropriate
NotificationInform individuals of collection purposes before or at the time of collection
Access and CorrectionProvide access and allow correction upon valid request
AccuracyMake reasonable effort to ensure data is accurate and complete
ProtectionImplement reasonable security arrangements to protect data
Retention LimitationCease retention when purpose is no longer served and retention is no longer necessary
Transfer LimitationEnsure comparable protection when transferring data overseas
AccountabilityAppoint a Data Protection Officer and develop policies

Mandatory Data Breach Notification

Since February 2021, organisations must notify both the PDPC and affected individuals of any notifiable data breach. A data breach is considered notifiable if it results in significant harm to affected individuals or affects 500 or more individuals.

Notification Timelines

  1. Assess the breach: Once aware, organisations have up to 30 days to assess whether the breach is notifiable.
  2. Notify the PDPC: Notification must occur as soon as practicable, and no later than 3 calendar days after determining the breach is notifiable.
  3. Notify affected individuals: Communication to affected individuals must happen at the same time or shortly after PDPC notification, unless a valid exception applies.

Failure to comply with breach notification obligations can result in significant financial penalties and reputational damage.

The Do Not Call (DNC) Registry

The PDPA also governs unsolicited marketing communications through the Do Not Call Registry. Singapore residents can register their Singapore telephone numbers on three separate registries:

  • No Voice Call Register — blocks marketing phone calls
  • No Text Message Register — blocks marketing SMS and MMS
  • No Fax Message Register — blocks marketing faxes

Organisations must check the DNC Registry before sending marketing messages to Singapore numbers unless they have clear and unambiguous consent from the recipient in writing. Registration is free and can be done through the PDPC's DNC portal.

How to Exercise Your PDPA Rights

Exercising your rights is straightforward, but following the correct process improves your chances of a timely and satisfactory response.

Step 1: Identify the Data Protection Officer

Every organisation subject to the PDPA must appoint a Data Protection Officer (DPO) and publish their contact details, usually within a privacy policy on the company website.

Step 2: Submit a Written Request

Submit your access, correction, or withdrawal request in writing, ideally by email so you have a record. Include:

  • Your full name and contact details
  • Sufficient identification information to verify your identity
  • A clear description of the data you want to access, correct, or stop being processed
  • Your preferred format for the response

Step 3: Await Response

The organisation should acknowledge receipt promptly and respond substantively within 30 days. If they need more time, they must inform you and provide an estimated response date.

Step 4: Escalate to the PDPC If Necessary

If the organisation refuses your request without valid grounds, delays unreasonably, or handles your complaint poorly, you can file a complaint with the PDPC through their online complaints portal. The PDPC can investigate, issue directions, and impose penalties.

Practical Privacy Tips for Singapore Residents

Beyond invoking your PDPA rights, there are practical steps you can take to reduce data exposure in the first place.

Minimise What You Share

Only provide personal data that is genuinely necessary for a transaction. Question forms that ask for your NRIC number, and remember that from 2019 organisations are generally prohibited from collecting or using full NRIC numbers except in limited circumstances.

Use Privacy-Preserving Tools

When sharing links on social media, messaging apps, or emails, consider using a privacy-focused URL shortener like Lunyb that doesn't harvest excessive tracking data from your recipients. You can read our honest review of Lunyb to learn more, or compare options in our 2026 URL shortener buyer's guide.

Review App Permissions Regularly

Mobile apps often collect far more data than they need. Periodically review the permissions granted to apps on your phone and revoke access to location, contacts, microphone, or camera when it isn't essential.

Enable Encrypted DNS and Browser Privacy Features

Use browsers that block trackers by default and enable encrypted DNS (DNS over HTTPS or DNS over TLS) to prevent your internet service provider from easily profiling your browsing activity.

PDPA vs GDPR: Quick Comparison

Many Singapore businesses also serve customers in the EU and must comply with both the PDPA and the General Data Protection Regulation (GDPR). Here's a quick comparison of the two frameworks.

FeatureSingapore PDPAEU GDPR
RegulatorPDPCNational DPAs
Maximum FineUp to 10% of Singapore turnover or S$1MUp to 4% of global turnover or €20M
Consent StandardDeemed consent permitted in some casesExplicit consent generally required
Breach NotificationWithin 3 days after assessmentWithin 72 hours of awareness
Data PortabilityBeing rolled outEstablished right
DPO RequirementMandatory for all organisationsMandatory in specific circumstances

Enforcement Trends and Recent PDPC Decisions

The PDPC has become increasingly active in enforcement, with published decisions serving as important guidance for organisations. Common causes of financial penalties include:

  • Inadequate security arrangements leading to unauthorised access
  • Failure to obtain proper consent before disclosing data to third parties
  • Excessive collection of NRIC numbers and copies of NRICs
  • Delayed or absent breach notifications
  • Poor vendor management leading to third-party breaches

Organisations should regularly review PDPC enforcement decisions on the PDPC website to understand evolving expectations and refine their compliance programmes accordingly.

Frequently Asked Questions

Can I sue an organisation directly for a PDPA breach?

Yes. The PDPA provides a private right of action, allowing individuals who suffer loss or damage due to a contravention to bring civil proceedings directly against the organisation. However, most disputes are first channelled through the PDPC's complaint and mediation processes.

Does the PDPA apply to foreign companies that serve Singapore customers?

Yes. The PDPA applies to any organisation that collects, uses, or discloses personal data in Singapore, regardless of where the organisation is based. Foreign companies serving Singapore customers online generally fall within scope.

How long do organisations have to respond to an access request?

Organisations must respond as soon as reasonably possible. If they cannot respond within 30 days, they must inform you of the delay and provide an estimated timeline. Unreasonable delays can be reported to the PDPC.

Can an organisation refuse my access request?

Yes, in limited circumstances. Common valid grounds include requests that would reveal personal data about another individual, would compromise safety or investigations, or would breach legal privilege. The organisation must inform you of the refusal and the reasons.

Do I need to pay to make an access request?

Organisations are permitted to charge a reasonable fee to cover the cost of responding to an access request. The fee cannot be used as a barrier to prevent legitimate access, and the organisation should provide an estimate before proceeding.

Final Thoughts

Singapore's PDPA has matured into a robust framework that balances individual privacy rights with commercial realities. As enforcement intensifies and penalties rise, both individuals and organisations benefit from understanding the law in detail. Individuals gain meaningful control over their data, while organisations that embrace PDPA principles build trust and reduce the risk of costly regulatory action.

Take time to understand your rights, exercise them when appropriate, and adopt privacy-preserving habits in your daily digital life. When in doubt, consult the PDPC's official guides or seek advice from a qualified data protection professional.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles