Singapore PDPA: Your Personal Data Protection Rights Explained
Singapore's Personal Data Protection Act (PDPA) is the country's cornerstone data privacy law, giving individuals meaningful control over how organisations collect, use and disclose their personal data. Whether you're signing up for a loyalty programme at NTUC, applying for a bank account with DBS, or clicking a marketing link in your inbox, the PDPA shapes what companies can and cannot do with your information.
This guide breaks down your Singapore PDPA rights in plain English, explains the obligations organisations owe you, and shows you exactly how to enforce those rights if something goes wrong.
What Is the Singapore PDPA?
The Personal Data Protection Act 2012 (PDPA) is Singapore's baseline law governing the collection, use, disclosure and care of personal data by private-sector organisations. It is administered and enforced by the Personal Data Protection Commission (PDPC), which sits under the Infocomm Media Development Authority (IMDA).
The Act came into full force in 2014 and was significantly strengthened by the 2020 amendments, which introduced mandatory data breach notification, a data portability right, higher financial penalties, and new rules around deemed consent and legitimate interests.
Who Does the PDPA Apply To?
The PDPA applies to all private organisations that collect, use or disclose personal data in Singapore, regardless of whether the organisation itself is based in Singapore. Public agencies are governed separately by the Public Sector (Governance) Act. Key points:
- It covers Singapore citizens, permanent residents, and anyone whose personal data is processed in Singapore.
- It applies to data in both electronic and non-electronic form.
- Business contact information (such as a work email or job title) is exempt in most cases.
What Counts as Personal Data Under the PDPA?
Personal data is any data — true or false — about an individual who can be identified from that data, or from that data combined with other information the organisation has or is likely to have access to.
Common examples include:
- Full name, NRIC or FIN number, and passport number
- Home address, personal phone number, and personal email
- Photographs, CCTV footage, and voice recordings
- Bank account details, credit card numbers, and CPF information
- Health records, biometric data, and location data
- Online identifiers such as IP addresses and device IDs when linked to a person
Your Core Rights Under the Singapore PDPA
The PDPA gives you a defined set of enforceable rights over your personal data. Understanding each one is the foundation of protecting your privacy in Singapore.
1. The Right to Be Informed (Notification Obligation)
Before or at the time an organisation collects your personal data, it must inform you of the purposes for which the data will be collected, used or disclosed. Vague statements like "for business purposes" don't cut it — purposes must be specific enough for you to make an informed decision.
2. The Right to Give (and Withdraw) Consent
Organisations generally need your consent to collect, use or disclose your personal data. Consent must be freely given and cannot be a condition for providing a product or service beyond what is reasonably required. You can withdraw consent at any time with reasonable notice, and the organisation must inform you of the likely consequences of withdrawal.
3. The Right to Access Your Personal Data
You can request an organisation to provide you with:
- The personal data about you that is in its possession or under its control.
- Information about how that data has been used or disclosed within a year before the date of the request.
Organisations must respond as soon as reasonably possible, typically within 30 days, and may charge a reasonable fee to cover incremental costs.
4. The Right to Correction
If your personal data held by an organisation is inaccurate or incomplete, you can request a correction. The organisation must correct the data as soon as practicable and, unless it has a reasonable basis to disagree, send the corrected data to every other organisation it disclosed the data to in the past year.
5. The Right to Data Portability (New)
Introduced in the 2020 amendments, the data portability obligation allows you to request that an organisation transmit your data in a commonly used machine-readable format to another organisation. This right becomes fully operational as the PDPC issues sector-specific regulations.
6. The Right to Protection and Security
Organisations must make reasonable security arrangements to protect personal data in their possession from unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks. This includes technical safeguards (encryption, access controls) and organisational measures (staff training, policies).
7. The Right to Be Notified of Data Breaches
Since 1 February 2021, organisations must notify the PDPC and affected individuals of any notifiable data breach. A breach is notifiable if it:
- Results in, or is likely to result in, significant harm to affected individuals; or
- Is of a significant scale (affecting 500 or more individuals).
Notification to the PDPC must be made within 3 calendar days of assessing the breach as notifiable.
8. The Right to Opt Out of Marketing (Do Not Call Registry)
The PDPA includes Do Not Call (DNC) provisions. You can register your Singapore phone number on the DNC Registry to stop receiving marketing calls, SMS and faxes. Organisations must check the registry before sending marketing messages, unless they have your clear and unambiguous consent in written or recorded form.
Organisations' Obligations at a Glance
The PDPA sets out nine main obligations that organisations must comply with. Understanding these helps you spot when your rights are being infringed.
| Obligation | What It Means for You |
|---|---|
| Consent | Data cannot be collected, used or disclosed without your consent (with limited exceptions). |
| Purpose Limitation | Data can only be used for purposes a reasonable person would consider appropriate. |
| Notification | You must be told the purposes before collection. |
| Access & Correction | You can request access to and correction of your data. |
| Accuracy | Organisations must make reasonable efforts to keep data accurate and complete. |
| Protection | Reasonable security arrangements are mandatory. |
| Retention Limitation | Data must be deleted or anonymised when no longer needed. |
| Transfer Limitation | Overseas transfers require comparable protection standards. |
| Accountability | Organisations must appoint a Data Protection Officer (DPO) and publish contact details. |
How to Exercise Your PDPA Rights: A Step-by-Step Guide
Knowing your rights is only half the battle — knowing how to enforce them is where real privacy protection happens.
Step 1: Identify the Data Protection Officer (DPO)
Every organisation must publish the business contact information of its DPO. Look in the privacy policy on the company's website, or email the general enquiries address asking for the DPO's contact details.
Step 2: Submit a Written Request
Write to the DPO clearly stating what you want:
- Whether you are exercising your access, correction, withdrawal of consent, or data portability right.
- The specific data or purposes involved.
- Your identity and contact details, plus proof of identity if requested.
Step 3: Allow a Reasonable Response Time
Organisations should respond as soon as reasonably possible. If they need more than 30 days, they must inform you in writing of the reason and expected timeline.
Step 4: Escalate to the PDPC If Unresolved
If the organisation refuses your request, fails to respond, or mishandles your data, you can lodge a complaint with the PDPC via the online complaints portal at pdpc.gov.sg. The PDPC may investigate, mediate, or issue directions and financial penalties.
Penalties for Non-Compliance
The 2020 amendments significantly increased the financial penalties for PDPA breaches. Organisations can now be fined up to:
- S$1 million, or
- 10% of annual turnover in Singapore for organisations with turnover exceeding S$10 million — whichever is higher.
Individuals responsible for egregious mishandling of data (such as knowingly disclosing personal data without authorisation) can also face fines up to S$5,000 and/or imprisonment of up to 2 years.
Protecting Your Personal Data in Everyday Life
Beyond enforcing your rights after the fact, you can take proactive steps to minimise what organisations collect about you in the first place.
Be Selective About What You Share
Only provide the personal data that's genuinely necessary. If a retail loyalty programme asks for your NRIC number, push back — since 2019, the PDPC's NRIC Advisory prohibits organisations from collecting, using or disclosing NRIC numbers except where required by law or necessary to accurately establish identity to a high degree of fidelity.
Use Privacy-Respecting Tools for Links and Sharing
When sharing links online — whether in WhatsApp groups, on LinkedIn, or in email newsletters — the tools you use matter. A privacy-focused link shortener like Lunyb lets you share clean, trackable URLs without exposing recipients to invasive third-party trackers. If you're comparing options, our 2026 buyer's guide to URL shorteners walks through the privacy trade-offs of the major players, and our honest review of Lunyb covers how it handles user data.
Register on the Do Not Call Registry
Visit dnc.gov.sg and register your Singapore mobile number to stop unwanted marketing calls, SMS and faxes. Registration is free and takes effect within 30 days.
Review Privacy Policies Before Signing Up
Look specifically for:
- What data is collected and why
- Whether data is shared with third parties or transferred overseas
- How long data is retained
- How to withdraw consent and delete your account
Enable Strong Authentication
Use Singpass for government services, enable two-factor authentication on banking and email accounts, and use unique passwords managed by a reputable password manager. Even the strongest PDPA rights can't protect you from a compromised password.
Special Cases: Sensitive Data and Cross-Border Transfers
Sensitive Personal Data
While the PDPA doesn't formally create a separate category of "sensitive data" like the GDPR does, the PDPC's guidelines make clear that organisations must apply higher standards of protection to data such as NRIC numbers, financial details, medical records and children's data.
Cross-Border Data Transfers
If your data is transferred outside Singapore — for example, to a cloud provider based in the US or India — the organisation must ensure the recipient provides a standard of protection comparable to the PDPA. This is typically done through contractual clauses, binding corporate rules, or reliance on approved certifications.
Recent Developments and What's Next
Singapore's data protection framework continues to evolve. Recent focus areas include:
- AI and personal data: The PDPC has issued a Model AI Governance Framework and specific guidance on the use of personal data in AI systems.
- Deemed consent by notification: Organisations can rely on deemed consent for secondary purposes if they notify individuals and give them a chance to opt out.
- Legitimate interests exception: A new basis for processing data without consent where the legitimate interest outweighs any adverse effect on the individual.
- Increased enforcement: The PDPC has been publishing more enforcement decisions and imposing larger fines, signalling stricter scrutiny.
Frequently Asked Questions
Does the PDPA apply to foreign companies serving Singapore users?
Yes. The PDPA applies to any organisation that collects, uses or discloses personal data in Singapore, regardless of where the organisation is incorporated. A US-based e-commerce platform selling to Singapore consumers, for example, must comply with the PDPA in respect of those users.
Can I ask a company to delete all my personal data?
The PDPA doesn't create a standalone "right to erasure" like the GDPR's right to be forgotten. However, you can withdraw consent for the continued use of your data, and organisations must cease using it and delete or anonymise it once it's no longer needed for a legal or business purpose.
What's the difference between the PDPA and the GDPR?
Both laws protect personal data, but the GDPR is broader in scope, includes rights like erasure and objection to automated decision-making, and imposes higher penalties (up to 4% of global turnover). The PDPA is more business-friendly with exceptions like legitimate interests and deemed consent, but the 2020 amendments have brought it closer to GDPR standards.
How much can I be charged for accessing my own data?
Organisations may charge a reasonable fee to cover the incremental cost of responding to your access request, but the fee must not be used to discourage requests. If you disagree with the fee, you can complain to the PDPC.
What should I do if I suspect my personal data has been misused?
First, contact the organisation's DPO in writing and give them a reasonable chance to respond. If they don't respond adequately or you're not satisfied, file a complaint with the PDPC via pdpc.gov.sg. Keep copies of all correspondence and any evidence of misuse.
Final Thoughts
The PDPA gives Singaporeans a robust set of rights over their personal data — but those rights are only as strong as your willingness to exercise them. Understand what organisations owe you, keep an eye on how your data is being used, and don't hesitate to push back through DPO requests or PDPC complaints when something feels off.
Combined with sensible digital hygiene — minimal data sharing, strong authentication, and privacy-respecting tools for everyday tasks like link sharing — the PDPA framework offers real, practical protection in a data-driven economy.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Singapore PDPA: Your Personal Data Protection Rights Explained
Singapore's PDPA gives you powerful rights over your personal data. Learn what those rights are, how to exercise them, and what penalties organisations face for breaches in this comprehensive 2026 guide.
PIPEDA vs GDPR: Canadian Privacy Law Explained (2026 Guide)
PIPEDA and GDPR both protect personal data, but they differ sharply in consent rules, individual rights, breach timelines, and penalties. This guide explains the key differences and shows Canadian businesses how to build a compliance program that satisfies both laws in 2026.
Singapore PDPA vs GDPR: Key Differences for Businesses in 2026
Singapore's PDPA and the EU's GDPR both protect personal data, but they differ significantly in consent, penalties, breach notification, and cross-border transfers. This guide breaks down the key differences so businesses can build a unified compliance strategy.
GDPR After Brexit: What Changed for UK Businesses and Data Protection
GDPR did not disappear after Brexit—it split into two parallel regimes. This guide explains how UK GDPR differs from EU GDPR, what adequacy decisions mean for data transfers, and the practical compliance steps every British business should take in 2026.