Data Protection Atlas

PDPA 2012 (Singapore)

Tier 2 In force

Singapore’s consent-centred law, run by a pragmatic and prolific regulator. Eleven data protection obligations sit alongside the Do Not Call regime; the 2020 amendments added mandatory breach notification, wider deemed consent and turnover-based penalties.

Identity

Citation
Personal Data Protection Act 2012 (No. 26 of 2012), Singapore, as amended by the PDP(A) Act 2020
Jurisdiction
Singapore
Type
comprehensive

Enacted 2012; main rules 2014; 2020 amendments from Feb 2021

Amended by: Personal Data Protection (Amendment) Act 2020

← Singapore overview

Structure

What each Part or Chapter does, and the provisions worth knowing inside it. An orientation to the shape of the instrument — not a substitute for reading the official text.

Parts 3–6 — The data protection obligations

Consent, purpose limitation, notification, access and correction, accuracy, protection, retention limitation, transfer limitation and accountability — with data portability enacted but not yet in force.

  • ss 13–17 Consent and its wide exceptions — deemed consent by notification, legitimate interests, business improvement.
  • s 24 The protection obligation — reasonable security arrangements, the ground for most fines.
  • s 26 Transfer limitation — comparable protection abroad via contracts, certification or specified schemes.
Part 6A — Data breach notification

Added in 2020 after years of voluntary practice.

  • ss 26C–26E Assess suspected breaches; notify the PDPC within 3 calendar days of a notifiable finding (significant harm, or 500+ people), and affected individuals where required.
Part 9B + s 48O — Penalties and offences

The 2020 uplift with individual accountability.

  • s 48O Financial penalties to 10% of Singapore turnover or S$1m, whichever is higher.
  • ss 48D–48F Personal offences for egregious mishandling — unauthorised disclosure, improper use, re-identification.
Parts 9–10 — Do Not Call and spam control

The consumer-facing half of the Act.

  • ss 43–47 Check the DNC registry before telemarketing calls and texts; message rules align with the Spam Control Act.

Regulatory enforcement

Interactions and conflicts

Excludes the public sector — government agencies run under the separate Public Sector (Governance) Act — a structural difference from the GDPR. Stricter sectoral rules (banking secrecy, healthcare) prevail. ASEAN Model Contractual Clauses slot into s 26, and the PDPC’s published decisions are the region’s richest enforcement record.

Sources

Never independently verified — seeded from the prototype.