facebook-pixel

Singapore PDPA: Your Personal Data Protection Rights Explained

L
Lunyb Security Team
··10 min read

Singapore's Personal Data Protection Act (PDPA) is the cornerstone of data privacy law in the country, giving individuals meaningful control over how organisations collect, use, and disclose their personal information. Whether you're a Singapore resident concerned about how businesses handle your data or a professional seeking to understand your obligations, knowing your PDPA rights is essential in today's digital economy.

This comprehensive guide explains your Singapore PDPA rights in plain English, walks through how to exercise them, and clarifies what to do when organisations fail to meet their obligations.

What Is the Singapore PDPA?

The Personal Data Protection Act 2012 (PDPA) is Singapore's primary data protection legislation, administered by the Personal Data Protection Commission (PDPC). It governs how private sector organisations collect, use, disclose, and care for personal data, while balancing individual privacy rights with legitimate business needs.

The PDPA was significantly amended in 2020, with updates taking effect through 2021 that strengthened individual rights, introduced mandatory data breach notification, and increased financial penalties for non-compliance. These reforms brought Singapore's framework closer in line with global standards like the EU's GDPR while retaining a distinctly practical, business-friendly approach.

Who the PDPA Applies To

The PDPA applies to all private sector organisations that collect, use, or disclose personal data in Singapore, regardless of whether they're based locally or overseas. It does not generally apply to public agencies, which are covered by separate legislation like the Public Sector (Governance) Act.

Personal data under the PDPA means any data about an individual who can be identified from that data, or from that data combined with other information the organisation has or can reasonably access.

The Nine Main Obligations Under the PDPA

Before diving into your rights, it helps to understand the corresponding obligations organisations must meet. The PDPA is built on nine key obligations:

  1. Consent Obligation — Organisations must obtain your consent before collecting, using, or disclosing your personal data.
  2. Purpose Limitation Obligation — Data can only be used for purposes you would consider appropriate.
  3. Notification Obligation — You must be informed of the purposes for data collection.
  4. Access and Correction Obligation — You have the right to access and correct your data.
  5. Accuracy Obligation — Organisations must ensure your data is accurate and complete.
  6. Protection Obligation — Reasonable security arrangements must protect your data.
  7. Retention Limitation Obligation — Data should not be kept longer than necessary.
  8. Transfer Limitation Obligation — Overseas data transfers require comparable protection.
  9. Accountability Obligation — Organisations must appoint a Data Protection Officer (DPO) and have policies in place.

Your Core Singapore PDPA Rights

The PDPA grants Singapore residents several specific rights that empower you to control your personal data. Understanding each of these rights is the first step toward exercising them effectively.

1. The Right to Be Informed

Before an organisation collects your personal data, it must inform you of the purposes for collection, use, or disclosure. This is typically achieved through privacy notices, consent forms, or terms of service. If the organisation later wants to use your data for a new purpose, it must notify you and obtain fresh consent.

2. The Right to Give and Withdraw Consent

Consent is central to the PDPA. You must give consent, either expressly or through deemed consent (such as voluntarily providing information for an obvious purpose), before your data is processed. Equally important, you have the right to withdraw consent at any time by giving reasonable notice.

Once you withdraw consent, the organisation must stop processing your data for the withdrawn purposes and inform you of the likely consequences (for example, being unable to continue receiving a service).

3. The Right to Access Your Personal Data

You can request that an organisation provide you with:

  • The personal data it holds about you
  • Information about how your data has been used or disclosed within the past year

Organisations must respond as soon as reasonably possible, generally within 30 days. If they cannot respond within that timeframe, they must inform you of the expected response time. A reasonable fee may be charged for access requests, but it cannot be excessive.

4. The Right to Correction

If your personal data is inaccurate or incomplete, you can request correction. The organisation must correct the data as soon as practicable and send the corrected data to every other organisation to which the original data was disclosed within the past year (unless you agree otherwise).

5. The Right to Data Portability (New)

Introduced in the 2020 PDPA amendments, the data portability obligation allows you to request that an organisation transmit your personal data to another organisation in a commonly used machine-readable format. This right is designed to reduce switching costs and empower consumers, though specific regulations governing implementation continue to evolve.

6. The Right to Be Notified of Data Breaches

Under the mandatory data breach notification regime, organisations must notify the PDPC of any data breach that results in significant harm or affects 500 or more individuals. Affected individuals must also be notified so they can take protective steps such as changing passwords or monitoring accounts.

7. The Right to Do Not Call (DNC) Protection

The PDPA includes the Do Not Call Registry, allowing Singapore telephone number holders to opt out of marketing calls, text messages, and faxes. Organisations must check the registry before sending marketing messages to Singapore numbers unless they have ongoing consent.

PDPA Rights Compared with GDPR

Many international businesses need to comply with both the PDPA and the EU's General Data Protection Regulation (GDPR). Here's how key rights compare:

Right Singapore PDPA EU GDPR
Right of Access Yes (with reasonable fee) Yes (first copy free)
Right to Correction/Rectification Yes Yes
Right to Erasure ("Right to be Forgotten") No standalone right; via retention limitation Yes, explicit
Right to Data Portability Yes (subject to regulations) Yes
Right to Withdraw Consent Yes Yes
Data Breach Notification Mandatory (500+ or significant harm) Mandatory (72 hours to regulator)
Maximum Financial Penalty Up to 10% of annual turnover in Singapore or S$1M Up to 4% of global turnover or €20M

How to Exercise Your PDPA Rights

Knowing your rights is only useful if you can act on them. Here's a step-by-step process for exercising your Singapore PDPA rights effectively.

  1. Identify the organisation's Data Protection Officer (DPO). Every organisation must appoint a DPO and make their contact details publicly available, usually in the privacy policy.
  2. Submit a written request. Send your access, correction, or withdrawal request in writing (email is acceptable). Clearly state what you're asking for and reference the PDPA.
  3. Provide identity verification. Organisations may request reasonable proof of identity to prevent unauthorised access to your data.
  4. Track the response timeline. Organisations should respond within 30 days. Keep records of all correspondence.
  5. Escalate if needed. If the organisation refuses or ignores your request, you can lodge a complaint with the PDPC.

Sample Access Request Language

When writing your request, keep it clear and specific. For example: "Under the Personal Data Protection Act 2012, I am requesting access to all personal data your organisation holds about me, including information about how it has been used or disclosed in the past 12 months. Please respond within 30 days."

Filing a Complaint with the PDPC

If you believe an organisation has breached your PDPA rights, the Personal Data Protection Commission provides a formal complaint process.

Steps to Lodge a Complaint

  1. Attempt resolution first. Contact the organisation's DPO to try to resolve the matter directly. The PDPC generally expects complainants to have made this effort.
  2. Gather evidence. Collect emails, screenshots, contracts, and any correspondence relevant to your complaint.
  3. Submit online. Use the PDPC's online complaint form at pdpc.gov.sg, providing detailed information about the alleged breach.
  4. Cooperate with investigations. The PDPC may request additional information or mediation between you and the organisation.

Possible Outcomes

The PDPC can issue directions requiring organisations to stop collecting, using, or disclosing data unlawfully; destroy improperly collected data; and pay financial penalties. Under the 2020 amendments, maximum penalties can reach up to 10% of an organisation's annual turnover in Singapore or S$1 million, whichever is higher.

Practical Tips to Protect Your Personal Data

Beyond exercising formal rights, everyday habits go a long way in protecting your personal information online.

Read Privacy Policies Before Consenting

It's tempting to click "I agree" without reading, but privacy policies reveal important details about how your data will be used, shared, and stored. Look specifically for third-party disclosures, retention periods, and overseas transfer clauses.

Use Privacy-Focused Tools

Choose services that respect your privacy by design. For example, when sharing links online, using a privacy-conscious URL shortener like Lunyb helps minimise unnecessary tracking and data collection compared to platforms that harvest extensive analytics on every click. For a broader comparison of link management tools with privacy considerations, see our 2026 URL shorteners buyer's guide.

Manage Consent Actively

Periodically review the organisations that hold your data. Withdraw consent from services you no longer use and request deletion where possible. This reduces your exposure if any of those organisations later suffers a breach.

Register with the Do Not Call Registry

If you're being bombarded by marketing calls or SMS, register your Singapore number with the DNC Registry. This is free and stops most legitimate marketers from contacting you.

Monitor for Data Breaches

Stay alert to breach notifications from organisations you've dealt with. When notified, change passwords immediately, enable two-factor authentication where possible, and watch for suspicious activity on your accounts.

PDPA Updates and What's Coming Next

The PDPA continues to evolve. Recent and upcoming developments include:

  • Enhanced financial penalties — Already in effect, allowing significantly larger fines for serious breaches.
  • Mandatory breach notification — In force since February 2021.
  • Data portability regulations — Detailed implementation rules are being finalised.
  • Deemed consent by notification and legitimate interests — New consent frameworks giving organisations more flexibility while maintaining safeguards.

Staying informed through PDPC advisory guidelines and updates ensures you always know your current rights and how to enforce them.

Frequently Asked Questions

Does the Singapore PDPA apply to foreign companies?

Yes. The PDPA applies to any organisation that collects, uses, or discloses personal data in Singapore, regardless of where the organisation is based. Foreign companies serving Singapore residents must comply with the same obligations as local businesses.

Can I request that a company delete all my personal data?

The PDPA does not include a standalone "right to be forgotten" like the GDPR. However, you can withdraw consent, which typically requires the organisation to stop processing your data. The Retention Limitation Obligation also requires organisations to delete data once it's no longer needed for business or legal purposes.

How long does an organisation have to respond to my access request?

Organisations must respond as soon as reasonably possible, generally within 30 days. If more time is needed, they must notify you of the expected response date within the initial 30-day period.

What if an organisation charges me an unreasonable fee for a data access request?

Fees must be reasonable and reflect actual costs of retrieval. If you believe the fee is excessive, raise the issue with the organisation's DPO first. If unresolved, you can complain to the PDPC, which can review the fee's reasonableness.

Are there penalties for organisations that ignore my PDPA rights?

Yes. Under the amended PDPA, organisations that breach their obligations can face financial penalties of up to 10% of their annual turnover in Singapore or S$1 million, whichever is higher. The PDPC can also issue directions requiring corrective action.

Final Thoughts

Singapore's PDPA gives you real, enforceable rights over your personal data. From accessing and correcting information to withdrawing consent and lodging complaints, the framework is designed to put you back in control. The key is knowing these rights exist and being willing to exercise them.

In an era where personal data is increasingly valuable and vulnerable, taking active steps to protect your privacy is no longer optional. Read privacy policies, use privacy-respecting tools, manage your consents, and don't hesitate to challenge organisations that fall short of their PDPA obligations. Your data, your rights, your choice.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles