Data Protection Atlas

Singapore

Tier 3 Comprehensive law Asia-Pacific

Principal framework: PDPA 2012 (amended 2020) (2012). Regulator: PDPC. The 2020 amendments added mandatory breach notification and expanded deemed consent; the DNC registry governs marketing calls and texts.

At a glance

Principal law
PDPA 2012 (amended 2020)
Regulator
PDPC
Breach notification
Assess promptly; notify the PDPC within 3 calendar days of a notifiable finding, and affected persons
Maximum penalty
Up to 10% of Singapore turnover or S$1m, whichever is higher
DPO required
DPO mandatory for every organisation
Digital consent age
13 for a minor’s own consent, per PDPC guidance
Extraterritorial reach
Yes — collection or use in Singapore regardless of establishment

Structure

Structural pattern
Not assessed
Sub-jurisdictions
None — no sub-national axis
ISO code
SG

A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.

Transfers and adequacy

EU member
No
EEA member
No

Instruments

Sources

No source recorded yet. This record cannot rise above Tier 3 until it has one — see depth tiers.

Never independently verified — seeded from the prototype.