Singapore Personal Data Protection Act 2012 (PDPA) is a law that governs the collection, use and disclosure of personal data by all private organisations. The Act has come into full effect on 2nd July 2014 and has been updated recently with new amendments that takes effect on 2 November 2020. Organisations which fail to comply with PDPA may be fined up to $1 million and suffer reputation damage.

Only use or disclose personal data for the purposes defined.
Inform the individuals on the purposes for collection, use and disclosure of their personal data during collection.
Ensure that the consent has been obtained from the individuals before collecting, using or disclosure of the personal data.
Upon request, provide the personal data of the individual and information on how the individual’s personal data has been used or disclosed in the past year. Correct an individual’s personal data upon request.
Ensure that personal data is accurate and complete during collection or when making a decision which will affect the individual.
Keep personal data in your possession secure from unauthorised access, modification, disclosure, use, copying, whether in hardcopy or electronic form.
Retain personal data only for business/legal purposes and securely destroy personal data when no longer needed.
Ensure overseas external organisations provide a standard of protection comparable to the protection under the Singapore PDPA.
Designate a Data Protection Officer and publish his/her business contact information. Make available personal data protection policies and practices to public and employees, including complaint process.
Do not send marketing messages to individuals who have registered in the National DNC registry through voice, text messages or fax unless you have obtained their clear and unambiguous consent or have an on-going relationship (for text / fax).
Conduct gap assessment against the PDPA requirements
Define data protection policy and processes to kick start your compliance programme
Provide training and awareness programs to employees on organisation’s personal data protection policies and processes
Offer all-round administrative and advisory support for your data protection office
Perform compliance review and testing against PDPA’s requirements
Depending on the services, your organisation will