{
 "jurisdiction_id": "SG",
 "jurisdiction": "Singapore",
 "url": "https://dataprotection.gi/jurisdictions/singapore/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 59,
  "sub_modules": 57,
  "source_register": 30
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/singapore/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Mature, well-documented omnibus statute with a single clearly identified regulator and settled extraterritorial scope.",
   "claims": [
    {
     "statement": "The Personal Data Protection Commission (PDPC) is empowered to investigate and enforce the PDPA provisions.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Personal Data Protection Commission",
     "source_url": "https://www.pdpc.gov.sg/about/the-legislation/pdpa-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPC was subsumed into the Info-communications Media Development Authority (IMDA) with effect from 1 October 2016.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/singapore_-_third_country_assessment_guidance_note_dataguidance.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Personal Data Protection Act 2012 (No. 26 of 2012) and the Spam Control Act 2007 were amended by Parliament in November 2020, with amendments including mandatory breach notification taking effect from 1 February 2021.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/singapore-amendments-pdpa-thoughtful-and-tailored",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPA applies only to private sector organisations; processing of personal data by public sector agencies is governed separately under the Public Sector (Governance) Act 2018.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "arXiv",
     "source_url": "https://arxiv.org/pdf/2310.01006",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPA has an extraterritorial scope and applies to overseas organisations that collect, use, or disclose personal data within Singapore, regardless of place of incorporation or residence.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "arXiv",
     "source_url": "https://arxiv.org/pdf/2310.01006",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "All organisations subject to the PDPA are required to appoint a Data Protection Officer (DPO) and make the DPO's business contact information publicly available.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_singapore_2022_july_update.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/singapore/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Consent-based model with wide statutory exemptions rather than an enumerated GDPR Art 6-style lawful-basis list, and no distinct special-category regime.",
   "claims": [
    {
     "statement": "Under Section 13 of the PDPA, collection, use or disclosure of personal data is prohibited unless the individual gives or is deemed to have given consent, subject to broad exemptions set out in the Second, Third and Fourth Schedules.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/gdpr-matchup-singapores-personal-data-protection-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPA prohibits an organisation from requiring an individual, as a condition of providing a product or service, to consent to collection, use or disclosure of personal data beyond what is reasonable, and consent may be withdrawn at any time with immediate cessation of the relevant processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/gdpr-matchup-singapores-personal-data-protection-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Unlike the GDPR, the PDPA does not create a distinct statutory category of 'special' or sensitive personal data, instead relying on consent centrality and case-by-case sensitivity assessment by the PDPC.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_singapore_2022_july_update.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Organisations may only collect, use or disclose NRIC numbers or copies of the NRIC (and equivalent national identification numbers) where required by law or necessary to verify identity to a high degree of accuracy.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Personal Data Protection Commission",
     "source_url": "https://www.pdpc.gov.sg/-/media/files/pdpc/pdf-files/advisory-guidelines/advisory-guidelines-for-nric-numbers---310818.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Part 9B of the PDPA creates offences for knowing or reckless unauthorised disclosure or wrongful use of personal data, and for re-identification of anonymised data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Personal Data Protection Commission",
     "source_url": "https://www.pdpc.gov.sg/-/media/files/pdpc/pdf-files/advisory-guidelines/ag-on-key-concepts/advisory-guidelines-on-key-concepts-in-the-pdpa-17-may-2022.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/singapore/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Access, correction and portability rights exist but there is no erasure right and no formal restriction-of-processing right analogous to GDPR Art 18.",
   "claims": [
    {
     "statement": "Under Section 21 of the PDPA, individuals may request access to their personal data held by an organisation and information about its use or disclosure in the year preceding the request.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/gdpr-matchup-singapores-personal-data-protection-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPA provides individuals a right to request correction of errors or omissions in their personal data under Section 22, but does not provide a right to request erasure or deletion of personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/gdpr-matchup-singapores-personal-data-protection-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Individuals may withdraw consent for collection, use or disclosure of their personal data at any time, with reasonable notice, obliging the organisation to cease the relevant processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/the-personal-data-protection-framework-in-singapore",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Data Portability Obligation requires organisations, upon request, to transmit an individual's data held in electronic form to another organisation with a presence in Singapore in a commonly used machine-readable format.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Personal Data Protection Commission",
     "source_url": "https://www.pdpc.gov.sg/-/media/Files/PDPC/PDF-Files/Legislation-and-Guidelines/Response-to-Feedback-for-3rd-Public-Consultation-on-Data-Portability-Innovation-200120.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Organisations that cannot provide requested personal data or make a correction within 30 days of a request must inform the individual in writing within 30 days of the time by which they will respond.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Personal Data Protection Commission",
     "source_url": "https://www.pdpc.gov.sg/-/media/Files/PDPC/PDF-Files/Advisory-Guidelines/Advisory-Guidelines-on-Enforcement-of-DP-Provisions_1oct2022.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Where a data breach is determined to be notifiable, notification to the PDPC must be made no later than three calendar days after the organisation determines the breach is notifiable.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Personal Data Protection Commission",
     "source_url": "https://www.pdpc.gov.sg/report-data-breach",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/singapore/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Protection, breach notification, retention and DPO duties are robust and enforced, but there is no formal Records-of-Processing-Activities (ROPA) obligation equivalent to GDPR Art 30.",
   "claims": [
    {
     "statement": "The accountability principle, initially implied in Sections 11 and 12 of the PDPA, was made an explicit statutory reference through the 2020 amendments.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/singapore-amendments-pdpa-thoughtful-and-tailored",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPA requires organisations to conduct a form of impact assessment when relying on the legitimate interests exception or on deemed consent by notification, though it does not impose a general DPIA obligation equivalent to GDPR Article 35.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_singapore_2022_july_update.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Although the DPO is not required to be physically present in Singapore, the PDPC expects the DPO to be readily reachable from Singapore and operational during Singapore business hours; the PDPA, unlike the GDPR, does not define specific independence or qualification criteria for the DPO role.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_singapore_2022_july_update.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "An organisation has the same obligations for personal data processed on its behalf by a data intermediary as if the organisation processed the data itself, but a data intermediary that exercises its own judgement beyond the controller's instructions becomes subject to the full Data Protection Provisions for that processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Personal Data Protection Commission",
     "source_url": "https://www.pdpc.gov.sg/-/media/files/pdpc/pdf-files/advisory-guidelines/ag-on-key-concepts/advisory-guidelines-on-key-concepts-in-the-pdpa-17-may-2022.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Protection Obligation under Section 24 of the PDPA requires organisations to make reasonable security arrangements to prevent unauthorised access, collection, use, disclosure, copying, modification or disposal of personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/the-personal-data-protection-framework-in-singapore",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A data breach is notifiable to the PDPC and affected individuals if it is likely to result in significant harm to affected individuals or affects 500 or more individuals.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Personal Data Protection Commission",
     "source_url": "https://www.pdpc.gov.sg/report-data-breach",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Financial institutions must separately report data breaches to the Monetary Authority of Singapore where the breach has a severe and widespread impact on the institution's operations or materially affects services to customers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Personal Data Protection Commission",
     "source_url": "https://www.pdpc.gov.sg/-/media/files/pdpc/pdf-files/resource-for-organisation/2018-personal-data-protection-digest.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Retention Limitation Obligation under Section 25 requires an organisation to cease retaining documents containing personal data, or remove the means of associating the data with an individual, as soon as the retention purpose is no longer served and retention is no longer necessary for legal or business purposes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/the-personal-data-protection-framework-in-singapore",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "green",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/singapore/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Transfer regime is mature with recognised certification schemes (APEC CBPR/PRP) and model clauses, though Singapore is not a recipient of an EU adequacy decision.",
   "claims": [
    {
     "statement": "Section 26 of the PDPA prohibits an organisation from transferring personal data outside Singapore except where it can ensure a standard of protection comparable to the PDPA is maintained over the transferred data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/the-personal-data-protection-framework-in-singapore",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Since June 2020, the Personal Data Protection Regulations recognise APEC Cross-Border Privacy Rules (CBPR) and Privacy Recognition for Processors (PRP) system certifications as a basis for compliance with the Transfer Limitation Obligation for overseas transfers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/singapore_-_third_country_assessment_guidance_note_dataguidance.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPC has published guidance on tailoring the ASEAN Model Contractual Clauses (MCCs) to meet Singapore's Transfer Limitation Obligation requirements, and provides sample clauses for contracts with overseas recipients holding Global/APEC CBPR or PRP certification.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Personal Data Protection Commission",
     "source_url": "https://www.pdpc.gov.sg/organisations/resources/guidance-by-topic/guide-to-cross-border-data-transfers",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The onus is on the transferring organisation to undertake appropriate due diligence and obtain assurances that an overseas recipient can maintain a standard of protection comparable to the PDPA before transferring personal data outside Singapore.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Personal Data Protection Commission",
     "source_url": "https://www.pdpc.gov.sg/-/media/files/pdpc/pdf-files/advisory-guidelines/ag-on-key-concepts/advisory-guidelines-on-key-concepts-in-the-pdpa-17-may-2022.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EU-Singapore Digital Trade Agreement, which entered into force on 1 February 2026, prohibits unjustified data localisation requirements between the parties.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/singapore",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/singapore/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Strong financial-sector and telecom-marketing overlays; credit-scoring and insurance-specific data rules could not be confirmed with primary sourcing.",
   "claims": [
    {
     "statement": "The Monetary Authority of Singapore's Guidelines on Outsourcing Risk Management, issued 27 July 2016, set MAS expectations for financial institutions entering outsourcing arrangements, including those involving customer information.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/singapore-mas-issues-guidelines-outsourcing-risk",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "MAS issued guidance on 29 May 2024 setting supervisory expectations for banks and finance companies to establish data governance frameworks addressing data quality, risk aggregation and risk reporting, informed by Basel Committee principles.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/singapore-mas-publishes-guidance-data-governance-and",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Singapore's Health Information Bill establishes a framework for health data management, defining roles, data-sharing protocols and penalties for non-compliance.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/singapore",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Do Not Call (DNC) provisions of the PDPA prohibit organisations from sending marketing voice calls, text messages or faxes to Singapore telephone numbers registered on the DNC Registry.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Personal Data Protection Commission",
     "source_url": "https://www.pdpc.gov.sg/overview-of-pdpa/do-not-call-registry/business-owner/do-not-call-registry-and-your-business",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under Section 20(4) of the PDPA, an organisation collecting, using or disclosing personal data for managing or terminating an employment relationship must inform the individual of that purpose, and PDPC guidance permits general notification via employment contracts, handbooks or intranet notices.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Personal Data Protection Commission",
     "source_url": "https://www.pdpc.gov.sg/-/media/Files/PDPC/PDF-Files/Responses-Received-As-At-31-Aug-2023/Prudential-Assurance-Company-Singapore.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Registered private education institutions may collect NRIC numbers from enrolled students where required to keep proper records under the Private Education Regulations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Personal Data Protection Commission",
     "source_url": "https://www.pdpc.gov.sg/-/media/files/pdpc/pdf-files/advisory-guidelines/advisory-guidelines-for-nric-numbers---310818.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/singapore/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Direct marketing/DNC regime is mature and enforced; cookie guidance exists but was not substantively verified, and dark-pattern/cross-context-advertising concepts are absent from the PDPA framework.",
   "claims": [
    {
     "statement": "The PDPC's Advisory Guidelines on the PDPA for Selected Topics address whether consent must be obtained for the use of cookies and whether cookies may be used for targeted advertising.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_singapore_2022_july_update.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Do Not Call Registry allows individuals to register their Singapore telephone number to opt out of receiving unwanted marketing voice calls, text messages and faxes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Personal Data Protection Commission",
     "source_url": "https://www.pdpc.gov.sg/overview-of-pdpa/do-not-call-registry/business-owner/do-not-call-registry-and-your-business",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A person or organisation that sends telemarketing messages to a Singapore telephone number without checking the DNC Registry, absent a relevant exception, commits an offence and is liable to a fine of up to US$10,000 per message sent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/the-personal-data-protection-framework-in-singapore",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Organisations do not need to check the DNC Registry before sending marketing messages where they have the recipient's clear and unambiguous consent to receive such messages at that Singapore telephone number.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Personal Data Protection Commission",
     "source_url": "https://www.pdpc.gov.sg/overview-of-pdpa/do-not-call-registry/business-owner/do-not-call-registry-and-your-business",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/singapore/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "AI governance relies on voluntary frameworks (Model AI Governance Framework, Agentic AI MGF, ISAGO, AI Verify) rather than binding statute; no dedicated biometric or genetic-data law was confirmed, and national-security carve-outs are largely undocumented in general legislation.",
   "claims": [
    {
     "statement": "Singapore's Model AI Governance Framework, a voluntary framework rather than binding law, promotes principles of transparency and explainability for AI systems' decision-making processes.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Personal Data Protection Commission",
     "source_url": "https://www.pdpc.gov.sg/help-and-resources/2020/01/model-ai-governance-framework",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PDPC and IMDA's Model AI Governance Framework is supported by the voluntary Implementation and Self-Assessment Guide for Organisations (ISAGO) and the AI Verify testing toolkit, which help organisations assess AI systems against the Framework's principles.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Personal Data Protection Commission",
     "source_url": "https://www.pdpc.gov.sg/help-and-resources/2020/01/model-ai-governance-framework",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In January 2026, Singapore unveiled a Model AI Governance Framework for Agentic AI, the first governance model specifically addressing agentic AI systems, emphasising human oversight and accountability for agentic AI risks.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "arXiv",
     "source_url": "https://arxiv.org/pdf/2607.07612",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "MAS opened a consultation on AI risk management guidelines for financial institutions covering governance, oversight and lifecycle controls.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/singapore",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Singapore's media regulator (MDDI) has issued guidance advising organisations on PDPA compliance obligations for AI-equipped smart glasses, addressing privacy and safety considerations, rather than through a dedicated biometric-specific statute.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/singapore",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Singapore public sector agencies are not subject to the PDPA's data protection provisions, being instead governed by their own public-sector data protection rules.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/singapore_-_third_country_assessment_guidance_note_dataguidance.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "There is no general legislation in Singapore specifically governing surveillance by public authorities of personal data held by private organisations, beyond specific statutory powers to access and seize data.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/singapore_-_third_country_assessment_guidance_note_dataguidance.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/singapore/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Children's protections rest on PDPC advisory guidelines rather than statutory age-of-consent provisions, and dependent-adult protections are addressed only incidentally in breach-notification guidance.",
   "claims": [
    {
     "statement": "The PDPA does not define 'child' or stipulate a statutory minimum age of consent; the PDPC applies a practical rule of thumb that a minor aged 13 or above typically has sufficient understanding to consent on their own behalf.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/gdpr-matchup-singapores-personal-data-protection-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Where a child is below 13 years of age, or where an organisation has reason to believe a child lacks sufficient understanding of the nature and consequences of consent, the organisation must obtain consent from the child's parent or guardian.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Personal Data Protection Commission",
     "source_url": "https://www.pdpc.gov.sg/-/media/files/pdpc/pdf-files/advisory-guidelines/advisory-guidelines-on-the-pdpa-for-children's-personal-data-in-the-digital-environment_mar24.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PDPC guidance directs organisations handling children's personal data to adopt data minimisation policies, including ensuring that children's account information is not made public and searchable by default.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Personal Data Protection Commission",
     "source_url": "https://www.pdpc.gov.sg/-/media/files/pdpc/pdf-files/advisory-guidelines/advisory-guidelines-on-the-pdpa-for-children's-personal-data-in-the-digital-environment_mar24.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In an education setting, an organisation may consider it more prudent to obtain parental consent for a 13-year-old rather than seeking the child's consent directly.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Personal Data Protection Commission",
     "source_url": "https://www.pdpc.gov.sg/-/media/files/pdpc/pdf-files/advisory-guidelines/advisory-guidelines-on-the-pdpa-for-children's-personal-data-in-the-digital-environment_mar24.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Where a data breach involves information related to adoption matters or the identification of vulnerable individuals, organisations should first notify the PDPC for guidance before notifying affected individuals.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Personal Data Protection Commission",
     "source_url": "https://www.pdpc.gov.sg/-/media/files/pdpc/pdf-files/other-guides/guide-on-managing-and-notifying-data-breaches-under-the-pdpa-15-mar-2021.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/singapore/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Active, escalating enforcement (higher penalty caps, regular published decisions) with a functioning private right of action, though regulator funding/capacity data and collective-redress mechanisms were not confirmed.",
   "claims": [
    {
     "statement": "Since amendments effective 1 October 2022, the maximum financial penalty for PDPA breaches by organisations with annual turnover in Singapore exceeding S$10 million is 10% of their annual turnover in Singapore, or S$1 million, whichever is higher.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Personal Data Protection Commission",
     "source_url": "https://www.pdpc.gov.sg/news-and-events/announcements/2022/09/amendments-to-enforcement-under-the-personal-data-protection-act-in-updated-advisory-guidelines-and-guide",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPC has powers to require production of documents and information and to require the attendance of persons for oral examination in the course of its investigations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Personal Data Protection Commission",
     "source_url": "https://www.pdpc.gov.sg/-/media/Files/PDPC/PDF-Files/Advisory-Guidelines/Advisory-Guidelines-on-Enforcement-of-DP-Provisions_1oct2022.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In October 2025, the PDPC imposed a financial penalty and directions on Marina Bay Sands Pte Ltd for a negligent contravention of the Protection Obligation arising from a data migration exercise that left patrons' personal data unprotected for six months.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Personal Data Protection Commission",
     "source_url": "https://www.pdpc.gov.sg/all-commissions-decisions/2025/10/breach-of-the-protection-obligation-by-marina-bay-sands-pte-ltd",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 8 January 2026, the PDPC imposed a financial penalty of S$17,500 and directions on People Central Pte Ltd for failing to put in place reasonable security arrangements to protect personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Personal Data Protection Commission",
     "source_url": "https://www.pdpc.gov.sg/all-commissions-decisions/2026/01/breach-of-the-protection-obligation-by-people-central-pte-ltd",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under Section 48O of the PDPA, individuals who suffer loss or damage directly as a result of a contravention may commence civil proceedings against the organisation, with the right of private action arising after any PDPC decision on the matter becomes final.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/singapore_-_third_country_assessment_guidance_note_dataguidance.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PDPC will enforce stricter measures against NRIC misuse by private organisations starting 1 January 2027.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/singapore",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "MAS opened a consultation on AI risk management guidelines for financial institutions covering governance, oversight and lifecycle controls, indicating forthcoming sector-specific AI risk guidance.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/singapore",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}