PrivacyCache
enactedSGEffective July 2, 2014

Personal Data Protection Act 2012 (PDPA)

Complete compliance guide for companies with <200 employees. Everything you need to know about PDPA requirements, deadlines, and penalties.

DSAR Deadline

30 calendar days

+ 30 days extension

Max Penalty

SGD 1,000,000/violation

Up to SGD $1 million or 10% of annual turnover (whichever is higher) for organizations, following 2021 amendments. The PDPC can also issue directions to stop collection/use/disclosure. Individuals face fines up to SGD $5,000 for egregious mishandling.

Threshold

No threshold

Est. Cost

$5,000 – $18,000

6-14 weeks

Mid-Market Compliance Guide

Singapore's PDPA applies to all private organizations in Singapore, with no revenue or size threshold. The 2021 amendments increased maximum fines to 10% of turnover, added mandatory breach notification, and introduced data portability. The PDPC is actively enforcing and publishes all enforcement decisions online.

Key Requirements

  • Obtain consent before collecting, using, or disclosing personal data
  • Allow individuals to withdraw consent at any time
  • Protect personal data with reasonable security arrangements
  • Mandatory Data Breach Notification to PDPC and affected individuals
  • Comply with the Do Not Call Registry (DNCR)
  • Appoint a Data Protection Officer
Enforced by: Personal Data Protection Commission (PDPC)Official site

Consumer Rights

Right of Access to Personal Data
Right to Correction
Right to Withdraw Consent
Right to Data Portability (2021 amendment)
Right to Complain to PDPC

Business Obligations

Exemptions

  • Personal or domestic data use
  • Business contact information for business purposes
  • Public agencies (governed by separate rules)
  • Employee data for employment purposes (partial exemption)

Related Privacy Laws

Recommended Compliance Tools

Browse all compliance tools

Get a mid-market compliance checklist for PDPA

We'll send you a practical, step-by-step checklist tailored for companies with <200 employees. No spam, unsubscribe anytime.

See how DPAs enforce PDPA in practice

Real fines, real violations, real lessons. Browse our enforcement database to understand what gets penalized under PDPA.

Disclaimer: This is general information, not legal advice. Consult a qualified attorney for your specific situation. Laws and regulations may change. Last reviewed: 3/27/2026.

Read the official text of PDPA