facebook-pixel

Singapore PDPA: Your Personal Data Protection Rights Explained

L
Lunyb Security Team
··10 min read

Singapore's Personal Data Protection Act (PDPA) is the cornerstone of data privacy law in the country, giving individuals meaningful control over how organisations collect, use, and disclose their personal information. Whether you're signing up for a mobile plan, applying for a bank loan, or simply browsing an e-commerce site, the PDPA shapes what companies can (and cannot) do with your data.

This guide explains your Singapore PDPA rights in plain English, walks through how to exercise them, and shows what to do when an organisation gets it wrong.

What Is the Singapore PDPA?

The Personal Data Protection Act 2012 is Singapore's comprehensive data protection law, administered by the Personal Data Protection Commission (PDPC). It came into full force in July 2014 and was significantly amended in 2020 and 2021 to introduce mandatory breach notification, data portability, and stronger financial penalties.

The PDPA governs how private sector organisations handle personal data. Public agencies are governed separately under the Public Sector (Governance) Act, though similar principles apply. In practice, if a Singapore business holds information that can identify you, it must comply with the PDPA.

What Counts as "Personal Data"?

Personal data is any data, true or not, about an individual who can be identified from that data alone or in combination with other information the organisation has or is likely to have access to. Common examples include:

  • Full name, NRIC, FIN or passport number
  • Residential address and mobile number
  • Email address and account usernames
  • Photographs and CCTV footage
  • Medical records and financial history
  • Device identifiers, IP addresses, and location data

The Nine Main Obligations Organisations Must Follow

Before diving into your rights, it helps to understand the flip side: the obligations organisations owe you. The PDPA imposes nine core data protection obligations.

ObligationWhat It Means for You
ConsentOrganisations must obtain your consent before collecting, using, or disclosing personal data.
Purpose LimitationData can only be used for purposes a reasonable person would consider appropriate.
NotificationYou must be informed of the purposes for data collection on or before collection.
Access & CorrectionYou can request access to your data and ask for corrections.
AccuracyOrganisations must make reasonable efforts to ensure data is accurate and complete.
ProtectionReasonable security arrangements must protect data from unauthorised access.
Retention LimitationData must be deleted when no longer needed for business or legal purposes.
Transfer LimitationOverseas transfers require comparable protection standards.
AccountabilityOrganisations must appoint a Data Protection Officer (DPO) and publish contact details.

Your Core PDPA Rights as an Individual

The PDPA gives you five practical rights that you can actively exercise. Knowing them puts you in a stronger position when dealing with banks, telcos, retailers, and any other Singapore business.

1. The Right to Be Informed

Before or at the time an organisation collects your personal data, it must tell you why. Look for a privacy notice or data protection statement at signup forms, kiosks, and in-app prompts. If the purpose isn't clear, you have the right to ask.

2. The Right to Give or Withhold Consent

Consent must be meaningful. Organisations cannot force you to consent to unrelated purposes as a condition of providing a product or service. For example, a food delivery app cannot require you to share your contact list just to place an order.

3. The Right to Withdraw Consent

You can withdraw consent at any time by giving reasonable notice. The organisation must inform you of the likely consequences (e.g. account closure) but cannot penalise you for withdrawing. Once you withdraw, they must stop collecting, using, or disclosing your data for those purposes.

4. The Right to Access Your Data

You can ask an organisation for:

  1. The personal data about you they hold or have control over
  2. Information about how that data has been used or disclosed in the past year

Organisations must respond within 30 days or explain the delay. They may charge a reasonable fee but must tell you the estimated cost first.

5. The Right to Correction

If your data is inaccurate or incomplete, you can request a correction. Unless the organisation has reasonable grounds to refuse, it must correct the data and inform other organisations it previously shared the incorrect data with.

The New Data Portability Right

Introduced in the 2020 amendments, the data portability obligation lets you request that an organisation transmit your data directly to another organisation in a commonly used, machine-readable format. This is designed to reduce switching friction between service providers—for example, moving your transaction history from one bank to another.

Note that data portability provisions have specific effective dates and scope defined by the PDPC. Check the latest PDPC guidelines to confirm which categories of data are covered when you make a request.

Mandatory Data Breach Notification

Since 1 February 2021, organisations must notify both the PDPC and affected individuals when a data breach:

  • Results in, or is likely to result in, significant harm to affected individuals, or
  • Is of a significant scale (affecting 500 or more individuals)

Notification to the PDPC must happen within 3 calendar days of assessing the breach as notifiable. Affected individuals should be notified as soon as practicable. If you receive such a notice, take it seriously—change passwords, monitor accounts, and consider placing a credit alert.

The Do Not Call (DNC) Registry

Part of the PDPA also governs unsolicited telemarketing. Singapore residents can register their mobile numbers on three DNC lists:

  • No Voice Call Register
  • No Text Message Register
  • No Fax Message Register

Once registered, organisations must check the DNC Registry before sending you marketing messages unless you have an ongoing relationship with them or have given clear and unambiguous consent. Registration is free at the DNC website.

How to Exercise Your PDPA Rights: Step by Step

Exercising your rights doesn't require a lawyer. Follow this practical process.

  1. Identify the Data Protection Officer (DPO). Every organisation must publish DPO contact details, usually in the privacy policy or footer.
  2. Submit a written request. Send an email specifying whether you want access, correction, withdrawal of consent, or data portability. Be specific about what data you mean.
  3. Include verification details. Provide enough information (e.g. account number, registered email) so the organisation can confirm your identity without you oversharing.
  4. Track the 30-day window. Note the date you sent the request. Follow up if you don't hear back.
  5. Escalate to the PDPC if needed. If the organisation ignores you or refuses without valid reason, file a complaint at pdpc.gov.sg.

What Happens When Organisations Break the Rules?

The 2020 amendments significantly raised the stakes for non-compliance. Financial penalties can reach the higher of S$1 million or 10% of an organisation's annual turnover in Singapore (for organisations with local turnover exceeding S$10 million). This brings Singapore's enforcement regime closer to Europe's GDPR in terms of severity.

Directors and employees can also face criminal liability for offences such as unauthorised disclosure, improper use, or re-identification of anonymised data—punishable by fines up to S$5,000 and/or up to two years' imprisonment.

Recent Enforcement Trends

The PDPC regularly publishes decisions on its website. Common breach patterns include:

  • Weak password policies leading to credential stuffing attacks
  • Misconfigured cloud storage exposing customer databases
  • Insider misuse of customer data
  • Failure to encrypt data in transit or at rest
  • Excessive collection of NRIC numbers (restricted since 2019)

Special Rules for NRIC and National Identifiers

Since 1 September 2019, organisations generally cannot collect, use, or disclose NRIC numbers or copies of NRIC cards, except when:

  • Required by law (e.g. hospitals, hotels for check-in)
  • Necessary to accurately establish or verify identity to a high degree of fidelity

If a gym, retailer, or lucky draw organiser asks for your NRIC without clear legal basis, you can decline and report the practice to the PDPC.

Protecting Your Data Beyond the PDPA

The PDPA gives you legal rights, but proactive habits matter just as much. Practical steps include:

  • Use unique, strong passwords managed by a reputable password manager
  • Enable two-factor authentication on Singpass, banking, and email accounts
  • Review app permissions on your phone quarterly
  • Check Singpass login history for unauthorised access
  • Use encrypted DNS (like DNS-over-HTTPS) to reduce network-level tracking
  • Prefer privacy-respecting browsers with tracker blocking enabled

When you share links—whether for a work project or a WhatsApp group—consider whether the destination reveals more than you'd like. A privacy-conscious link shortener such as Lunyb lets you create clean, trackable short URLs without leaking referrer data or exposing lengthy tracking parameters. You can read our honest review of Lunyb or compare it with alternatives in our 2026 URL shortener buyer's guide to see which fits your workflow.

PDPA vs GDPR: Quick Comparison

Singapore residents dealing with international services often wonder how the PDPA stacks up against Europe's GDPR.

FeatureSingapore PDPAEU GDPR
Right of accessYes, 30 daysYes, 30 days
Right to correctionYesYes
Right to erasureIndirect (via consent withdrawal & retention limits)Yes, explicit
Data portabilityYes (phased rollout)Yes
Breach notification window3 days to PDPC72 hours to supervisory authority
Max financial penaltyUp to 10% of local turnover or S$1MUp to 4% of global turnover or €20M
DPO requiredYes, all organisationsYes, in specific cases

Filing a Complaint with the PDPC

If an organisation mishandles your data or refuses to honour a valid request, escalate to the PDPC.

  1. Try to resolve directly first. The PDPC usually expects you to have contacted the organisation's DPO before escalating.
  2. Prepare documentation. Gather emails, screenshots, and dates showing what happened.
  3. Submit through the PDPC website. Use the online complaint form at pdpc.gov.sg.
  4. Cooperate with the investigation. The PDPC may request further evidence or clarification.
  5. Consider alternative dispute resolution. The PDPC may refer minor disputes to mediation before formal enforcement.

Frequently Asked Questions

Does the PDPA apply to foreign companies offering services to Singaporeans?

Yes. If a foreign organisation collects personal data from individuals in Singapore, it is generally subject to the PDPA regardless of where its servers or headquarters are located. Enforcement across borders can be complex, but the PDPC has cooperation arrangements with several overseas regulators.

Can I ask a company to delete all my data under the PDPA?

The PDPA doesn't include an explicit "right to be forgotten" like the GDPR, but you can achieve a similar outcome. Withdrawing consent forces the organisation to stop using your data, and the retention limitation obligation requires them to delete data no longer needed for business or legal purposes.

How long do organisations have to respond to my access request?

Organisations must respond as soon as reasonably possible, and no later than 30 days. If they need more time, they must inform you in writing of when to expect a response. Unreasonable delays can be reported to the PDPC.

What should I do if I receive a data breach notification?

Take it seriously. Change passwords on the affected service and any account where you reused that password. Enable two-factor authentication. Monitor your bank statements and Singpass activity. If your NRIC or financial details were exposed, consider placing fraud alerts and watch for phishing attempts referencing the breach.

Are marketing emails from companies I've bought from covered by the DNC Registry?

The DNC Registry covers voice calls, SMS, and faxes but not emails. However, general PDPA consent rules still apply to marketing emails—you must have consented, and every email should offer a clear way to unsubscribe. Companies you have an existing relationship with may send marketing messages under the "ongoing relationship" exception, but you can always opt out.

Final Thoughts

The Singapore PDPA gives you real, enforceable rights over your personal data—but those rights only matter when you use them. Bookmark your key DPO contacts, register on the DNC Registry, review app permissions regularly, and don't hesitate to escalate to the PDPC when organisations fall short. Combined with strong personal security habits, your PDPA rights form a solid foundation for privacy in an increasingly data-driven Singapore.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles