facebook-pixel

Singapore PDPA: Your Personal Data Protection Rights Explained

L
Lunyb Security Team
··11 min read

Singapore's Personal Data Protection Act (PDPA) is the cornerstone of data privacy law in the Lion City. Whether you're a resident, an expat, or a business operating in Singapore, understanding your PDPA rights is essential in an era where personal data flows across apps, websites, and government services daily. This guide breaks down exactly what the PDPA protects, the rights it grants you, and how to exercise them effectively in 2026.

What Is the Singapore PDPA?

The Personal Data Protection Act 2012 (PDPA) is Singapore's primary data protection law. It governs how organisations collect, use, disclose, and protect personal data belonging to individuals in Singapore. Enforced by the Personal Data Protection Commission (PDPC), the law applies to all private sector organisations, regardless of whether they are based in Singapore or overseas, as long as they handle Singaporean personal data.

The PDPA was significantly amended in 2020 and 2021, introducing mandatory data breach notification, higher financial penalties (up to 10% of annual turnover in Singapore for large organisations), and new rights such as data portability. These updates aligned Singapore more closely with international standards like the EU's GDPR, while maintaining a distinctly Singaporean, business-friendly approach.

Who Does the PDPA Apply To?

The PDPA applies to:

  • All private sector organisations handling personal data in Singapore
  • Foreign companies that collect or process Singaporean residents' data
  • Data intermediaries processing data on behalf of other organisations

Public sector agencies are governed separately by the Public Sector (Governance) Act, though many similar principles apply.

What Counts as Personal Data Under the PDPA?

Personal data is any information, whether true or false, about an individual who can be identified from that data, or from that data combined with other information an organisation has or is likely to access. This definition is intentionally broad and covers both digital and physical records.

Examples of personal data include:

  • Full name, NRIC/FIN number, and passport details
  • Residential address and mobile number
  • Email addresses and online usernames
  • Photographs and video footage identifying an individual
  • Medical records and biometric data
  • Bank account numbers and financial information
  • Vehicle registration numbers

Special Treatment for NRIC Numbers

Since 2019, the PDPC has imposed strict rules on the collection of NRIC numbers and physical NRIC copies. Organisations can only collect your NRIC when required by law or when necessary to accurately verify identity to a high degree of fidelity. A gym membership or lucky draw entry, for example, should not require your NRIC.

Your Core PDPA Rights Explained

The PDPA grants individuals a set of enforceable rights designed to put you in control of your personal data. Here are the key rights every person in Singapore should know.

1. The Right to Be Informed (Notification Obligation)

Organisations must inform you of the purposes for which they are collecting, using, or disclosing your personal data, on or before collection. This is why you see privacy notices and consent forms. If an organisation wants to use your data for a new purpose later, they generally need to notify you and obtain fresh consent.

2. The Right to Give or Withdraw Consent

Consent is the foundation of the PDPA. Organisations typically cannot collect, use, or disclose your personal data without your consent, unless an exception applies (such as legal requirements or legitimate interests). Importantly, you have the right to withdraw consent at any time, with reasonable notice. Once you withdraw, the organisation must stop processing your data for that purpose, though they may inform you of consequences (e.g., inability to continue a service).

3. The Right of Access

You can request that an organisation provide you with:

  1. The personal data about you that it has in its possession or control
  2. Information about how that data has been used or disclosed within the past year

Organisations must respond as soon as reasonably possible, typically within 30 days. They may charge a reasonable fee to cover the cost of responding.

4. The Right of Correction

If you believe your personal data held by an organisation is inaccurate or incomplete, you have the right to request a correction. The organisation must correct the data as soon as practicable and inform other organisations to which the data was disclosed in the past year, unless you consent otherwise.

5. The Right to Data Portability (New)

Introduced through the 2020 amendments, the Data Portability Obligation allows you to request that an organisation transmit your data in a commonly used, machine-readable format to another organisation. This right makes it easier to switch service providers, for example, moving your transaction history from one bank or e-commerce platform to another. The provision is being phased in as the PDPC releases sector-specific guidelines.

6. The Right to Be Protected (Protection Obligation)

Organisations must make reasonable security arrangements to protect personal data in their possession from unauthorised access, collection, use, disclosure, copying, modification, disposal, or similar risks. This includes technical measures like encryption and access controls, as well as administrative controls like staff training.

7. The Right to Breach Notification

As of February 2021, organisations are legally required to notify both the PDPC and affected individuals of data breaches that are likely to result in significant harm or affect 500 or more individuals. Notification to the PDPC must happen within 3 calendar days of assessing the breach as notifiable.

The PDPA's Nine Main Obligations on Organisations

To better understand your rights, it helps to see them from the organisation's side. The PDPA imposes nine main obligations:

ObligationWhat It Means
ConsentMust obtain consent before collecting, using, or disclosing data
Purpose LimitationOnly use data for purposes a reasonable person would consider appropriate
NotificationInform individuals of purposes before or at the time of collection
Access and CorrectionProvide access and allow correction of personal data on request
AccuracyMake reasonable efforts to ensure data is accurate and complete
ProtectionImplement reasonable security safeguards
Retention LimitationStop retaining data when no longer necessary for business or legal purposes
Transfer LimitationOnly transfer data overseas to jurisdictions offering comparable protection
Data Breach NotificationNotify PDPC and affected individuals of significant breaches

The Do Not Call (DNC) Registry

A key component often linked to the PDPA is the Do Not Call Registry. If you register your Singapore telephone number on the DNC Registry, organisations are prohibited from sending you specified marketing messages (voice calls, SMS, or fax) unless you have given them clear and unambiguous consent to do so.

You can register your number for free at the official DNC website. Breaches can lead to fines of up to S$200,000 per offence for organisations.

How to Exercise Your PDPA Rights

Knowing your rights is only half the equation. Here's a practical step-by-step process to exercise them.

  1. Identify the organisation's Data Protection Officer (DPO). Every organisation is required to appoint a DPO and publish their contact details, often on the privacy policy page.
  2. Submit a written request. Clearly state whether you are requesting access, correction, withdrawal of consent, or data portability. Include enough information for the organisation to identify you (but avoid oversharing).
  3. Allow reasonable time. Organisations typically have 30 days to respond. If they need more time, they must inform you.
  4. Pay reasonable fees (for access requests). Fees should reflect administrative costs, not profit. Challenge unreasonable charges.
  5. Escalate to the PDPC if unresolved. If an organisation refuses or fails to comply, you can lodge a complaint with the PDPC.

Sample Access Request Template

A simple access request might read:

"Dear Data Protection Officer, Under Section 21 of the Personal Data Protection Act 2012, I request access to all personal data your organisation holds about me, along with information on how that data has been used and disclosed in the past 12 months. My details for identification are: [name, email registered with you, account/customer number]. Please acknowledge receipt and respond within 30 days."

Enforcement and Penalties

The PDPC takes enforcement seriously. Since the 2021 amendments, financial penalties can reach:

  • Up to S$1 million, or
  • 10% of an organisation's annual turnover in Singapore (if that exceeds S$10 million)

The PDPC publishes enforcement decisions publicly, which has created strong market incentives for compliance. Notable cases have involved healthcare providers, telecommunications companies, and e-commerce platforms being fined for inadequate security measures leading to data leaks.

Practical Privacy Tips Beyond the PDPA

While the PDPA gives you strong legal protections, personal responsibility still matters. Here are additional steps Singaporean residents can take:

1. Audit What You Share Online

Review the permissions you have granted to apps, especially those requesting access to contacts, location, or Singpass-linked services. Revoke what isn't necessary.

2. Use Privacy-Respecting Tools

Choose service providers that are transparent about data handling. For example, when sharing links on social media or in messaging apps, use a privacy-conscious URL shortener like Lunyb that doesn't harvest excessive click data or build advertising profiles. You can also compare options in our 2026 URL shortener buyer's guide.

3. Enable Multi-Factor Authentication

Singpass, bank accounts, and major email providers all offer MFA. Enabling it dramatically reduces the risk of unauthorised access, even if credentials leak in a breach.

4. Monitor Breach Notifications

Services like "Have I Been Pwned" let you check whether your email has appeared in known breaches. Combine this with PDPA's mandatory breach notifications for strong awareness.

5. Be Cautious with NRIC Disclosures

If an organisation asks for your NRIC and you don't see a legal basis, ask them to justify it or offer an alternative identifier. Many requests are habitual rather than lawful.

PDPA vs GDPR: Quick Comparison

Many Singaporean businesses operate internationally and must consider both frameworks. Here's how they stack up:

AspectSingapore PDPAEU GDPR
Primary RegulatorPDPCNational Data Protection Authorities
Max Penalty10% of SG turnover or S$1M4% of global turnover or €20M
Right to ErasureLimited (via consent withdrawal)Explicit "right to be forgotten"
Data PortabilityYes (being phased in)Yes
Breach NotificationWithin 3 days to PDPCWithin 72 hours to supervisory authority
Extraterritorial ScopeYes, if handling SG dataYes, if offering goods/services in EU

Recent PDPA Developments to Watch in 2026

Singapore continues to refine the PDPA to keep pace with technology:

  • Generative AI guidance: The PDPC has issued advisory guidelines on using personal data for AI training, emphasising transparency and purpose limitation.
  • Expanded data portability: Sector-specific implementation continues to roll out, starting with finance and telecommunications.
  • Children's data protections: Stronger expectations around platforms targeting minors.
  • Deepfake and biometric safeguards: Growing focus on how organisations handle biometric and voice data in authentication.

Frequently Asked Questions

Can I sue an organisation under the PDPA?

Yes. Section 48O of the PDPA gives individuals a right of private action. If you have suffered loss or damage directly as a result of a contravention of the PDPA's data protection provisions, you can commence civil proceedings in court. However, you generally must wait for the PDPC to make its finding first, unless specific exceptions apply.

Does the PDPA apply to data I share on social media?

The PDPA primarily regulates organisations, not individuals using data for personal or domestic purposes. However, if a business collects or scrapes personal data from social media for commercial use, the PDPA fully applies, including obligations around consent and purpose limitation.

How long can an organisation keep my personal data?

The Retention Limitation Obligation requires organisations to stop retaining personal data once the purpose for which it was collected is no longer served and retention is no longer necessary for legal or business purposes. There's no fixed universal period; it depends on the context. For example, tax records typically must be kept for at least five years under Singapore tax law.

What should I do if I receive a data breach notification?

Take it seriously. Change passwords for the affected account and any accounts sharing the same password, enable multi-factor authentication, monitor your bank and credit card statements, and be alert for phishing attempts referencing the breached service. Keep the notification letter in case you need to pursue compensation later.

Are small businesses exempt from the PDPA?

No. The PDPA applies to all private sector organisations in Singapore regardless of size. However, the PDPC takes a pragmatic approach, and the "reasonable" standard for security and other obligations is interpreted in context. A sole proprietor is not expected to have enterprise-grade security, but basic safeguards and sensible practices are still required.

Conclusion

Singapore's PDPA strikes a careful balance: giving individuals meaningful control over their personal data while allowing organisations to use data responsibly for legitimate purposes. By understanding your rights to be informed, consent, access, correction, portability, and breach notification, you can confidently push back when organisations overreach and make informed choices about who you trust with your information.

Data protection is a shared responsibility. The law provides the framework, regulators enforce the rules, organisations implement safeguards, and you, as an individual, exercise your rights. In 2026 and beyond, as AI, biometrics, and cross-border data flows become even more entrenched in daily life, staying informed about the PDPA is one of the most practical steps any Singapore resident can take to protect their digital identity.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles