facebook-pixel

Singapore PDPA vs GDPR: Key Differences for Businesses in 2026

L
Lunyb Security Team
··11 min read

If your business operates in Singapore, sells to European customers, or simply collects personal data online, you are almost certainly subject to at least one major privacy law — and often both. Singapore's Personal Data Protection Act (PDPA) and the European Union's General Data Protection Regulation (GDPR) are two of the most influential data protection frameworks in the world, but they take noticeably different approaches to how personal data should be collected, used, and safeguarded.

This guide breaks down the PDPA vs GDPR debate for Singapore businesses, explaining where the two laws align, where they diverge, and what practical steps you should take to remain compliant with both.

What Is the Singapore PDPA?

The Personal Data Protection Act 2012 (PDPA) is Singapore's primary data protection law, enforced by the Personal Data Protection Commission (PDPC). It governs how private-sector organisations collect, use, disclose, and care for personal data. Major amendments introduced in 2020 and 2021 added mandatory data breach notification, a data portability obligation, and significantly higher financial penalties.

The PDPA is built around a set of core obligations, including consent, purpose limitation, notification, access and correction, accuracy, protection, retention limitation, transfer limitation, and accountability. It applies to any organisation collecting personal data in Singapore, regardless of whether the organisation itself is based there.

What Is the GDPR?

The General Data Protection Regulation (GDPR) took effect on 25 May 2018 and applies across all European Union and European Economic Area member states. It is enforced by national Data Protection Authorities (DPAs) and coordinated by the European Data Protection Board (EDPB).

The GDPR governs the processing of personal data of individuals located in the EU/EEA, regardless of where the processing organisation is headquartered. That extraterritorial reach means a Singapore e-commerce store shipping to Germany, or a SaaS platform with EU users, must comply with the GDPR in addition to the PDPA.

PDPA vs GDPR: Side-by-Side Comparison

Both laws share the goal of protecting individual privacy, but their scope, requirements, and penalties differ significantly. The table below highlights the most important distinctions.

Area Singapore PDPA EU GDPR
Regulator Personal Data Protection Commission (PDPC) National DPAs coordinated by the EDPB
Territorial scope Organisations collecting/using personal data in Singapore Any processor targeting or monitoring EU/EEA residents
Definition of personal data Data about an identifiable individual, true or otherwise Any information relating to an identified or identifiable natural person
Lawful basis for processing Consent-based, with limited exceptions (deemed consent, legitimate interests, business improvement) Six lawful bases including consent, contract, legal obligation, vital interests, public task, legitimate interests
Data subject rights Access, correction, withdrawal of consent, data portability (pending full activation) Access, rectification, erasure, restriction, portability, objection, rights around automated decisions
Breach notification Notify PDPC within 3 calendar days if breach is notifiable Notify DPA within 72 hours of becoming aware
DPO requirement Mandatory for all organisations Required for public authorities and large-scale processing
Maximum penalty Up to 10% of annual turnover in Singapore (for organisations earning > S$10m) or S$1 million Up to €20 million or 4% of global annual turnover, whichever is higher
Cross-border transfers Recipient must ensure comparable protection standard Requires adequacy decision, SCCs, BCRs, or specific derogations

Key Difference 1: Legal Basis and Consent

The PDPA is fundamentally a consent-centric regime. In most cases, organisations need consent — express, deemed, or deemed by notification — to collect, use, or disclose personal data. The 2020 amendments introduced two additional bases: legitimate interests and business improvement, but these still require a documented assessment.

The GDPR, by contrast, provides six lawful bases for processing, and consent is only one of them. In fact, EU regulators actively discourage over-reliance on consent when another basis (such as contractual necessity or legitimate interests) is more appropriate. This gives GDPR-compliant organisations more flexibility, but also more accountability in documenting the basis they choose.

What this means in practice

Singapore businesses expanding to the EU often make the mistake of demanding consent for every processing activity. Under GDPR, that can actually be non-compliant — for example, you should not rely on consent to process an employee's payroll data when the lawful basis is really contractual necessity.

Key Difference 2: Data Subject Rights

Both laws give individuals the right to access and correct their personal data. However, the GDPR grants a broader catalogue of rights, including:

  • Right to erasure (the "right to be forgotten")
  • Right to restriction of processing
  • Right to object to processing, including direct marketing
  • Rights related to automated decision-making and profiling

The PDPA does not include a general right to erasure. Individuals can withdraw consent, which usually leads to deletion or cessation of use, but there is no standalone "right to be forgotten" comparable to Article 17 of the GDPR. Singapore's data portability obligation was legislated in 2020 but at the time of writing has not been fully brought into force pending subsidiary regulations.

Key Difference 3: Breach Notification Timelines

Both regimes require breach notification, but the mechanics differ.

  1. Under the PDPA, an organisation must notify the PDPC as soon as practicable, and in any case no later than 3 calendar days, once it determines that a breach is notifiable (i.e. it results in significant harm to individuals or affects 500 or more people). Affected individuals must also be notified where significant harm is likely.
  2. Under the GDPR, controllers must notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach, unless it is unlikely to result in a risk to individuals. High-risk breaches also trigger notification to affected data subjects "without undue delay".

The practical difference: the GDPR's 72-hour clock starts on awareness of the breach itself, while the PDPA's 3-day clock starts on the determination that the breach is notifiable. That subtle difference gives Singapore organisations slightly more time to assess before notifying.

Key Difference 4: Cross-Border Data Transfers

The PDPA's Transfer Limitation Obligation requires organisations to ensure that overseas recipients provide a standard of protection comparable to the PDPA. This is typically achieved through contractual clauses, binding corporate rules, or by transferring to jurisdictions with equivalent laws.

The GDPR's regime is more prescriptive. Transfers outside the EU/EEA must rely on one of:

  • An adequacy decision by the European Commission (Singapore does not currently have full adequacy status, though it participates in APEC CBPR)
  • Standard Contractual Clauses (SCCs) — the 2021 modernised set
  • Binding Corporate Rules (BCRs) for intra-group transfers
  • Specific derogations, such as explicit consent or contractual necessity

Post-Schrems II, EU exporters must also conduct a Transfer Impact Assessment to evaluate whether local laws in the recipient country undermine the SCC protections. Singapore-based recipients of EU data should be prepared to answer detailed questions about government access laws and technical safeguards.

Key Difference 5: Penalties and Enforcement

Historically, the PDPA was viewed as a lighter-touch regime, with a maximum fine of S$1 million per breach. That changed on 1 October 2022, when the amended penalty framework came into force. Now, organisations with annual turnover in Singapore above S$10 million can be fined up to 10% of that turnover. For smaller organisations, the S$1 million cap still applies.

The GDPR remains the heavier hitter. Its two-tier fine structure allows for administrative fines of up to €10 million or 2% of global annual turnover for lower-tier infringements, and up to €20 million or 4% of global annual turnover for the most serious violations — whichever is higher. Multi-hundred-million-euro fines against major tech companies have made GDPR enforcement highly visible.

Key Difference 6: DPO and Accountability

The PDPA requires every organisation to appoint at least one Data Protection Officer (DPO) and publish their business contact information. The DPO's role is to ensure compliance with the PDPA and act as a liaison with the PDPC.

Under the GDPR, a DPO is only mandatory when:

  • The processing is carried out by a public authority
  • Core activities involve large-scale, regular, and systematic monitoring of individuals
  • Core activities involve large-scale processing of special category data

However, the GDPR imposes broader accountability requirements even where a DPO is not mandatory — including maintaining records of processing activities (ROPAs), conducting Data Protection Impact Assessments (DPIAs) for high-risk processing, and demonstrating compliance through documentation.

Practical Compliance Checklist for Singapore Businesses

If your organisation is subject to both frameworks, aligning to the stricter requirement is usually the most efficient path. Here is a starter checklist:

  1. Map your data flows. Know what personal data you collect, why, where it is stored, and who it is shared with.
  2. Appoint a DPO and publish their contact details — this satisfies both PDPA and, where required, GDPR.
  3. Document your lawful bases. Under GDPR, record the basis for each processing activity. Under PDPA, document consent or legitimate interests assessments.
  4. Update privacy notices. Ensure they explain purposes, retention periods, third-party recipients, cross-border transfers, and data subject rights in plain language.
  5. Implement a breach response plan. Include the 72-hour GDPR clock and the 3-day PDPA clock.
  6. Review vendor contracts. Add data processing terms, SCCs where relevant, and PDPA-compliant transfer clauses.
  7. Train your staff. Most breaches are caused by human error — phishing, misdirected emails, lost devices.
  8. Secure your links and communications. When sharing sensitive content externally, use tools that let you set expiry dates, password-protect, and monitor click activity. A privacy-focused link shortener such as Lunyb can help you control and audit how shared URLs are accessed.

Common Compliance Mistakes to Avoid

Even mature organisations trip over the same handful of issues. Watch out for:

  • Bundled consent. Asking users to agree to marketing, analytics, and account creation in a single checkbox fails both PDPA and GDPR.
  • Ignoring the GDPR because you're "based in Singapore". If you target EU users — even by accepting EUR payments or shipping to the EU — GDPR likely applies.
  • Overlooking employee data. HR records are personal data too, and processing them requires the same care as customer data.
  • Weak vendor oversight. You remain accountable for data your processors handle on your behalf.
  • Indefinite retention. Both laws require that data not be kept longer than necessary. Document your retention schedule.

Where the Two Regimes Are Converging

Despite the differences, both frameworks are moving in the same broad direction: stronger accountability, higher penalties, mandatory breach notification, and clearer individual rights. Singapore's 2020 amendments deliberately narrowed the gap with GDPR by introducing data portability, mandatory notification, and turnover-based fines.

For businesses, the practical takeaway is that building a single, well-documented privacy programme aligned to the higher of the two standards is more efficient than maintaining two parallel compliance regimes. If you want a broader look at how privacy considerations affect the tools you use every day, our guide to the best URL shorteners in 2026 and our honest review of Lunyb both touch on how link-management platforms handle user data.

Frequently Asked Questions

Does the GDPR apply to Singapore companies?

Yes, if your Singapore company offers goods or services to individuals in the EU/EEA, or monitors their behaviour (for example through analytics or targeted advertising), the GDPR applies to that processing regardless of where your business is registered.

Is Singapore's PDPA considered "adequate" under the GDPR?

No, Singapore does not currently have a full adequacy decision from the European Commission. Transfers of personal data from the EU to Singapore therefore require an appropriate transfer mechanism such as Standard Contractual Clauses, along with a Transfer Impact Assessment.

What is the biggest fine under the PDPA so far?

Prior to the 2022 penalty increase, the largest PDPA fines were in the hundreds of thousands of Singapore dollars, most notably in the SingHealth/IHiS breach. With the new 10% of local turnover cap, future maximum fines against large organisations could reach tens of millions of dollars.

Do I need separate privacy policies for PDPA and GDPR?

Not necessarily. Most organisations maintain a single, unified privacy policy that meets the higher of the two standards (usually GDPR) and includes a jurisdiction-specific annex clarifying PDPA-specific rights and the DPO's contact details.

How quickly must I respond to a data access request?

Under the GDPR, controllers must respond to a data subject access request within one month (extendable by two months for complex requests). The PDPA does not specify a fixed timeline but requires organisations to respond "as soon as reasonably possible", with 30 days being widely regarded as a reasonable benchmark.

Final Thoughts

Singapore's PDPA and the EU's GDPR share the same underlying goals — transparency, accountability, and respect for individual privacy — but they differ in scope, lawful bases, individual rights, timelines, and penalties. For most Singapore businesses today, the safer strategy is to design one privacy programme benchmarked to the higher standard and adapt at the margins for local nuances.

Treat privacy compliance not as a one-off legal project, but as an ongoing operational discipline. The organisations that thrive under both regimes are the ones that build data protection into their culture, their contracts, and the everyday tools their teams use.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles