PDPA 2012 (Singapore)
Tier 2 In forceSingapore’s consent-centred law, run by a pragmatic and prolific regulator. Eleven data protection obligations sit alongside the Do Not Call regime; the 2020 amendments added mandatory breach notification, wider deemed consent and turnover-based penalties.
Identity
- Citation
- Personal Data Protection Act 2012 (No. 26 of 2012), Singapore, as amended by the PDP(A) Act 2020
- Jurisdiction
- Singapore
- Type
- comprehensive
Enacted 2012; main rules 2014; 2020 amendments from Feb 2021
Amended by: Personal Data Protection (Amendment) Act 2020
Structure
What each Part or Chapter does, and the provisions worth knowing inside it. An orientation to the shape of the instrument — not a substitute for reading the official text.
Parts 3–6 — The data protection obligations
Consent, purpose limitation, notification, access and correction, accuracy, protection, retention limitation, transfer limitation and accountability — with data portability enacted but not yet in force.
- ss 13–17 Consent and its wide exceptions — deemed consent by notification, legitimate interests, business improvement.
- s 24 The protection obligation — reasonable security arrangements, the ground for most fines.
- s 26 Transfer limitation — comparable protection abroad via contracts, certification or specified schemes.
Part 6A — Data breach notification
Added in 2020 after years of voluntary practice.
- ss 26C–26E Assess suspected breaches; notify the PDPC within 3 calendar days of a notifiable finding (significant harm, or 500+ people), and affected individuals where required.
Part 9B + s 48O — Penalties and offences
The 2020 uplift with individual accountability.
- s 48O Financial penalties to 10% of Singapore turnover or S$1m, whichever is higher.
- ss 48D–48F Personal offences for egregious mishandling — unauthorised disclosure, improper use, re-identification.
Parts 9–10 — Do Not Call and spam control
The consumer-facing half of the Act.
- ss 43–47 Check the DNC registry before telemarketing calls and texts; message rules align with the Spam Control Act.
Regulatory enforcement
Interactions and conflicts
Excludes the public sector — government agencies run under the separate Public Sector (Governance) Act — a structural difference from the GDPR. Stricter sectoral rules (banking secrecy, healthcare) prevail. ASEAN Model Contractual Clauses slot into s 26, and the PDPC’s published decisions are the region’s richest enforcement record.
Sources
- Primary Singapore Statutes Online — PDPA
- Regulator PDPC — regulator
Never independently verified — seeded from the prototype.