facebook-pixel

Singapore PDPA: Your Personal Data Protection Rights Explained

L
Lunyb Security Team
··11 min read

The Personal Data Protection Act (PDPA) is Singapore's cornerstone data protection law, giving individuals control over how organisations collect, use, and disclose their personal information. Whether you are signing up for a loyalty programme, applying for a bank loan, or receiving marketing calls, the PDPA governs what organisations can — and cannot — do with your data. This guide explains your Singapore PDPA rights in plain English, how to exercise them, and what to do when something goes wrong.

What Is the Singapore PDPA?

The Personal Data Protection Act 2012 (PDPA) is Singapore's main data protection legislation. It establishes a baseline standard for how private-sector organisations handle personal data, and it is enforced by the Personal Data Protection Commission (PDPC), part of the Infocomm Media Development Authority (IMDA).

The PDPA was significantly updated in 2020 and 2021 to introduce mandatory data breach notification, higher financial penalties, and new rights such as data portability. It applies to any organisation operating in Singapore that collects, uses, or discloses personal data, regardless of where the organisation is headquartered. Public agencies are instead governed by the Public Sector (Governance) Act, so the PDPA primarily protects you when you deal with businesses.

What Counts as "Personal Data" Under the PDPA?

Personal data is any data — whether true or false — about an individual who can be identified from that data, or from that data combined with other information the organisation has access to. Examples include:

  • Full name, NRIC/FIN number, and passport number
  • Residential address, email, and mobile number
  • Photographs and CCTV footage identifying you
  • Medical records, financial information, and employment history
  • Online identifiers such as IP addresses when linked to an identifiable person

Business contact information (your work email, title, and office number used strictly for business purposes) is treated separately and has lighter obligations.

The Core Data Protection Obligations

Before exploring your rights, it helps to understand the obligations the PDPA places on organisations. These nine obligations form the framework that your rights sit within.

ObligationWhat It Means in Practice
ConsentOrganisations must obtain your consent before collecting, using, or disclosing your personal data.
Purpose LimitationData can only be used for purposes a reasonable person would consider appropriate.
NotificationYou must be informed of the purposes for data collection on or before collection.
Access and CorrectionYou can request access to your data and correct inaccuracies.
AccuracyOrganisations must make reasonable efforts to ensure your data is accurate and complete.
ProtectionReasonable security arrangements must be in place to prevent unauthorised access.
Retention LimitationData must be destroyed when no longer needed for business or legal reasons.
Transfer LimitationOverseas transfers must offer protection comparable to the PDPA.
Data Breach NotificationSignificant breaches must be reported to the PDPC and affected individuals.

Your Key Rights Under the Singapore PDPA

The PDPA grants you several practical rights you can exercise directly with organisations holding your personal data. Here is what each right means and how to use it.

1. The Right to Be Informed

Before any organisation collects your personal data, it must tell you what it intends to collect and why. This is usually done through a data protection notice, privacy policy, or consent form. If you cannot find this information, you are entitled to ask the organisation to provide it in writing.

2. The Right to Give (and Withdraw) Consent

Consent must be voluntary, informed, and specific. Importantly, you can withdraw consent at any time by giving reasonable notice to the organisation. Once you withdraw, the organisation must stop collecting, using, or disclosing your data for the stated purpose, although they can keep it if required by law.

There are limited exceptions — called the "legitimate interests" and "business improvement" exceptions — where organisations can process your data without consent, provided they conduct a documented assessment and the processing is not likely to cause you adverse effects.

3. The Right of Access

You can ask an organisation to tell you what personal data they hold about you and how it has been used or disclosed in the past year. The organisation must respond as soon as reasonably possible — generally within 30 days — and may charge a reasonable fee to cover the cost of retrieval.

If the organisation cannot meet the 30-day deadline, it must tell you in writing when the request will be fulfilled.

4. The Right of Correction

If any of your personal data is inaccurate or incomplete, you can request a correction. Unless the organisation has reasonable grounds to refuse, it must correct the data and notify any other organisations it previously disclosed the data to within the past year.

5. The Right to Data Portability (New Under 2020 Amendments)

The data portability obligation allows you to request that an organisation transmit your data in a commonly used, machine-readable format to another organisation. This is particularly relevant for banking, telecommunications, and digital services where switching providers used to mean losing your history. (Note: the specific commencement details for the portability obligation are set by regulations issued by the PDPC.)

6. The Right to Opt Out of Marketing Messages

The PDPA's Do Not Call (DNC) Registry lets you block telemarketing calls, text messages, and faxes to your Singapore phone number. Register your number via the PDPC's website or SMS, and organisations must check the registry before sending marketing messages.

For email marketing, Singapore's Spam Control Act requires senders to provide an unsubscribe facility and honour your opt-out within 10 business days.

7. The Right to Be Notified of a Data Breach

Since 1 February 2021, organisations must notify the PDPC of any data breach that is likely to result in significant harm to you, or that affects 500 or more individuals. If you are among the affected individuals in a significant-harm breach, the organisation must also notify you directly so you can take protective action.

How to Exercise Your PDPA Rights: A Step-by-Step Guide

Knowing your rights is only half the battle — exercising them effectively requires a clear process. Follow these steps when you want to make an access, correction, or withdrawal request.

  1. Identify the organisation's Data Protection Officer (DPO). Every organisation in Singapore must appoint a DPO and publish their business contact details. Check the organisation's website, usually in the privacy policy or contact page.
  2. Submit your request in writing. Use email where possible so you have a timestamped record. State clearly whether you are making an access, correction, withdrawal, or portability request.
  3. Provide enough information to verify your identity. Organisations are allowed — and expected — to confirm who you are before releasing data, to prevent unauthorised disclosure.
  4. Keep track of the deadline. Access and correction requests should typically be responded to within 30 days. If more time is needed, the organisation must tell you in writing.
  5. Escalate if ignored. If the organisation fails to respond or you are unhappy with the outcome, you can lodge a complaint with the PDPC.

What Happens When Organisations Break the Rules?

The PDPC has significant enforcement powers. Following the 2020 amendments, the maximum financial penalty for a data breach is the higher of S$1 million or 10% of an organisation's annual turnover in Singapore (for organisations with annual turnover exceeding S$10 million).

Beyond fines, the PDPC can issue directions requiring organisations to stop certain activities, destroy improperly collected data, or implement remedial measures. In serious cases involving reckless or intentional misuse of personal data by employees, individuals can face criminal penalties including fines of up to S$5,000 and imprisonment of up to 2 years.

Notable PDPC Enforcement Themes

Reviewing published enforcement decisions reveals the issues that trigger the most penalties:

  • Weak IT security: Unpatched systems, missing encryption, and poor password practices leading to breaches.
  • Excessive data collection: Collecting full NRIC numbers when verification would suffice.
  • Vendor failures: Organisations held accountable when third-party processors mishandle data on their behalf.
  • Inadequate consent: Pre-ticked boxes, bundled consent, or marketing use beyond what was disclosed.

Practical Tips to Protect Your Personal Data Day-to-Day

While the PDPA gives you legal rights, prevention is always easier than remediation. Here are practical habits that complement your legal protections.

Be Selective About What You Share

Not every form that asks for your NRIC actually needs it. Since 1 September 2019, organisations are generally prohibited from collecting, using, or disclosing NRIC numbers (or copies of the NRIC) except where required by law or necessary to accurately establish an individual's identity. If asked unnecessarily, politely decline and refer to PDPC's NRIC guidelines.

Secure Your Online Footprint

Your personal data is only as safe as the weakest service holding it. Use strong, unique passwords with a reputable password manager, enable two-factor authentication wherever available, and prefer services that use encrypted DNS and modern browser protections. When sharing links — especially on social media or in messaging apps — consider using a privacy-respecting link management tool like Lunyb to avoid leaking tracking parameters or exposing original URLs with sensitive query strings. You can read our honest Lunyb review for a deeper look at how it compares to other options in our 2026 buyer's guide.

Monitor and Audit Your Data Regularly

Every six to twelve months, pick a service you use heavily — your bank, a major e-commerce platform, your telco — and submit a short access request. This keeps organisations accountable and helps you understand your actual data exposure.

Register with the Do Not Call Registry

If you have not already, add your Singapore mobile number to all three DNC lists (voice calls, text messages, and fax). It takes under five minutes and dramatically reduces unsolicited marketing.

PDPA vs GDPR: A Quick Comparison

If you have dealt with European data protection, you may wonder how Singapore's PDPA compares to the EU's General Data Protection Regulation (GDPR). Both aim to protect individuals, but they differ in scope and strictness.

FeatureSingapore PDPAEU GDPR
Primary RegulatorPDPCNational Data Protection Authorities
Maximum FineHigher of S$1M or 10% of SG turnoverHigher of €20M or 4% of global turnover
Consent ModelConsent-based with exceptions (legitimate interests, business improvement)Six lawful bases, including consent and legitimate interests
Right to ErasureNot a standalone right; achieved via consent withdrawal and retention limitationExplicit "right to be forgotten"
Data PortabilityYes (per PDPC regulations)Yes
Breach Notification ThresholdSignificant harm, or 500+ individuals affectedRisk to rights and freedoms of individuals

Frequently Asked Questions

Can I sue an organisation directly for a PDPA breach?

Yes. Since the 2020 amendments, individuals have a statutory right of private action under section 48O of the PDPA. If you suffer loss or damage from a PDPA contravention, you can sue in civil court — but only after the PDPC has made a decision on the matter and all appeals are exhausted or the time to appeal has passed.

How long should an organisation keep my personal data?

The PDPA does not set a fixed period. Organisations must cease retention as soon as it is reasonable to assume the data is no longer needed for the original purpose and no longer required for legal or business reasons. If you have closed an account, you can ask the organisation about its retention schedule.

Does the PDPA cover data collected before 2 July 2014?

Yes, with transitional provisions. The main data protection rules apply to personal data regardless of when it was collected, but consent obtained before the PDPA came into force is generally deemed valid for the original purposes it was collected for.

What if an overseas company handles my data?

The PDPA applies to any organisation that collects, uses, or discloses personal data in Singapore, regardless of whether the organisation is physically based here. Additionally, Singapore-based organisations that transfer your data overseas must ensure the receiving party provides a comparable standard of protection, usually through contractual safeguards.

Can my employer collect my personal data without consent?

Employers can collect, use, and disclose personal data about employees without consent in certain situations — for example, for managing the employment relationship, evaluating a job applicant, or ensuring workplace safety — provided the purpose is reasonable and employees are notified. However, consent is still generally required for purposes outside the employment relationship, such as marketing.

Final Thoughts

The Singapore PDPA is a practical, enforceable framework that puts real power in the hands of individuals. The key is to actually use these rights: ask organisations what they hold about you, correct inaccuracies when you find them, withdraw consent when a service no longer serves you, and escalate to the PDPC when organisations fall short. Combined with sensible digital habits — strong authentication, careful sharing, and privacy-aware tools — the PDPA gives Singapore residents one of the clearest paths in Asia-Pacific to meaningful control over their personal data.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles