🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
SG · run data-protection-2026-07-29 v13-gdpri-1.0.0
content: ai_generated 30 sources retrieved model claude-sonnet-5 ·

Singapore

SG schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 59 claims · 30 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
59Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

Lead Signal

The Personal Data Protection Commission fined People Central Pte Ltd S$17,500 on 8 January 2026 for failing to implement reasonable security arrangements under the Protection Obligation. This follows an October 2025 penalty against Marina Bay Sands Pte Ltd for a negligent contravention of the same obligation, linked to a six-month window in which data went unprotected. Both decisions sit under the enhanced penalty regime in force since 1 October 2022, which permits fines of up to 10% of Singapore turnover, or S$1 million, whichever is higher, for organisations above S$10 million in turnover.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Mature, well-documented omnibus statute with a single clearly identified regulator and settled extraterritorial scope.

Primary frameworkPersonal Data Protection Act 2012 (No. 26 of 2012), as amended
Traffic-light rationale — GreenMature, well-documented omnibus statute with a single clearly identified regulator and settled extraterritorial scope.

Sub-modules (5)

Regulator And AuthorityGreen

PDPC is the statutory enforcement authority, operating under IMDA since 2016.

Claims: CLM-SG-1a2b3c4d, CLM-SG-2b3c4d5e

Act And InstrumentsGreen

Core instrument is the PDPA 2012, last comprehensively amended in November 2020 with provisions phased in through 2021-2022, alongside the Spam Control Act for the Do Not Call regime.

Claims: CLM-SG-3c4d5e6f

Material ScopeGreen

Material scope covers private-sector collection, use and disclosure of personal data; public agencies sit outside the PDPA under a separate governance statute.

Claims: CLM-SG-4d5e6f7a

Territorial ScopeGreen

Extraterritorial reach captures overseas organisations processing personal data in Singapore regardless of incorporation or residence.

Claims: CLM-SG-5e6f7a8b

Regulator Registration And FilingAmber

No general PDPC registration/filing regime exists; the principal filing-adjacent obligation is mandatory public DPO contact details.

Claims: CLM-SG-6f7a8b9c

Category narrative136 words

Singapore's omnibus regime is the Personal Data Protection Act 2012 (No. 26 of 2012, 'PDPA'), administered by the Personal Data Protection Commission (PDPC). <cite index="58-1">The PDPC is empowered to investigate and enforce the PDPA provisions.</cite> <cite index="51-18">With effect from 1 October 2016, the PDPC was subsumed into the IMDA, which is a statutory body under the Ministry of Communication and Information.</cite> <cite index="40-5">The PDPA applies only to private sector companies, as the processing of personal data by public sector bodies is governed by another law called the Public Sector Governance Act 2018.</cite> <cite index="40-3">PDPA has an extraterritorial scope similar to GDPR, and it applies to overseas organizations that collect, use, or disclose data within Singapore.</cite> <cite index="35-3">Under the PDPA, all organisations are required to appoint a DPO, whose business contact information must be made publicly available.</cite>

No periodic updates recorded against this sub-brief.

Sources and claims (6)
  1. ConfirmedPersonal Data Protection CommissionThe Personal Data Protection Commission (PDPC) is empowered to investigate and enforce the PDPA provisions.
  2. ConfirmedOneTrust DataGuidanceThe PDPC was subsumed into the Info-communications Media Development Authority (IMDA) with effect from 1 October 2016.
  3. ConfirmedOneTrust DataGuidanceThe Personal Data Protection Act 2012 (No. 26 of 2012) and the Spam Control Act 2007 were amended by Parliament in November 2020, with amendments including mandatory breach notification taking effect from 1 February 2021.
  4. ConfirmedarXivThe PDPA applies only to private sector organisations; processing of personal data by public sector agencies is governed separately under the Public Sector (Governance) Act 2018.
  5. ConfirmedarXivThe PDPA has an extraterritorial scope and applies to overseas organisations that collect, use, or disclose personal data within Singapore, regardless of place of incorporation or residence.
  6. ConfirmedOneTrust DataGuidanceAll organisations subject to the PDPA are required to appoint a Data Protection Officer (DPO) and make the DPO's business contact information publicly available.

#

Consent-based model with wide statutory exemptions rather than an enumerated GDPR Art 6-style lawful-basis list, and no distinct special-category regime.

Primary frameworkPersonal Data Protection Act 2012, as amended
Traffic-light rationale — AmberConsent-based model with wide statutory exemptions rather than an enumerated GDPR Art 6-style lawful-basis list, and no distinct special-category regime.

Sub-modules (4)

Lawful BasesAmber

Consent is the default basis, displaced by broad statutory exemption schedules functioning analogously to alternative lawful bases.

Claims: CLM-SG-7a8b9c0d

Special CategoriesAmber

No GDPR-style enumerated special category list; sensitivity is assessed contextually, with a dedicated national-ID-number regime functioning as a quasi-sensitive-identifier rule.

Claims: CLM-SG-9c0d1e2f, CLM-SG-0d1e2f3a

Pseudonymisation And AnonymisationAmber

Anonymisation is protected via criminal offences for re-identification rather than a dedicated anonymisation safe-harbour standard.

Claims: CLM-SG-1e2f3a4b

Category narrative203 words

The PDPA is consent-centric but carves out very broad exemptions. <cite index="49-14,49-15,49-16">Consent is not required under the PDPA if the data processing falls within the purview of the Section 17 exemptions, which cover collection, use and disclosure without consent in circumstances set out in the Second, Third and Fourth Schedules.</cite> <cite index="49-6">The PDPA prohibits an organization from requiring an individual to consent to the collection, use or disclosure of personal data about the individual beyond what is reasonable to provide the product or service to that individual.</cite> Unlike the GDPR, <cite index="43-18">the PDPA does not distinguish specific categories of personal data, it does deem the consent of the individual as central and necessary before commencing data processing activities.</cite> A quasi-sensitive-identifier regime exists for national identification numbers: <cite index="80-2">private sector organisations are only allowed to collect, use or disclose NRIC numbers or copies of the NRIC if the collection, use or disclosure is required by the law, or it is necessary to establish or verify an individual's identity to a high degree of accuracy.</cite> Anonymisation is addressed through offence provisions: <cite index="99-19,99-20">Part 9B of the PDPA sets out offences that hold individuals accountable for egregious mishandling of personal data, including re-identification of anonymised data.</cite>

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ConfirmedInternational Association of Privacy ProfessionalsUnder Section 13 of the PDPA, collection, use or disclosure of personal data is prohibited unless the individual gives or is deemed to have given consent, subject to broad exemptions set out in the Second, Third and Fourth Schedules.
  2. ConfirmedInternational Association of Privacy ProfessionalsThe PDPA prohibits an organisation from requiring an individual, as a condition of providing a product or service, to consent to collection, use or disclosure of personal data beyond what is reasonable, and consent may be withdrawn at any time with immediate cessation of the relevant processing.
  3. ConfirmedOneTrust DataGuidanceUnlike the GDPR, the PDPA does not create a distinct statutory category of 'special' or sensitive personal data, instead relying on consent centrality and case-by-case sensitivity assessment by the PDPC.
  4. ConfirmedPersonal Data Protection CommissionOrganisations may only collect, use or disclose NRIC numbers or copies of the NRIC (and equivalent national identification numbers) where required by law or necessary to verify identity to a high degree of accuracy.
  5. ConfirmedPersonal Data Protection CommissionPart 9B of the PDPA creates offences for knowing or reckless unauthorised disclosure or wrongful use of personal data, and for re-identification of anonymised data.

#

Access, correction and portability rights exist but there is no erasure right and no formal restriction-of-processing right analogous to GDPR Art 18.

Primary frameworkPersonal Data Protection Act 2012, as amended
Traffic-light rationale — AmberAccess, correction and portability rights exist but there is no erasure right and no formal restriction-of-processing right analogous to GDPR Art 18.

Sub-modules (5)

Access RightAmber

Statutory access right limited to a one-year lookback window, subject to exceptions.

Claims: CLM-SG-2f3a4b5c

Rectification And ErasureRed

Correction right exists; no erasure/right-to-be-forgotten equivalent.

Claims: CLM-SG-3a4b5c6d

Restriction And ObjectionAmber

No explicit restriction-of-processing right; functional equivalent is consent withdrawal.

Claims: CLM-SG-4b5c6d7e

Data PortabilityAmber

Portability Obligation limited to electronic records and to recipients with a Singapore presence.

Claims: CLM-SG-5c6d7e8f

Deadlines And Response WindowsGreen

30-day response window for access/correction; 3-calendar-day breach notification window to PDPC post-determination.

Claims: CLM-SG-6d7e8f9a, CLM-SG-7e8f9a0b

Category narrative192 words

Data subject rights are narrower than under GDPR. <cite index="49-24">Section 21 of the PDPA allows an individual to request access to personal data held by an organization and to information concerning its use or disclosure in the preceding one year.</cite> <cite index="43-13">The PDPA does not provide data subjects with the right to request the erasure or deletion of their personal data.</cite> A Data Portability Obligation exists: <cite index="36-3">upon request, organisations must transmit the individual's data in their possession or under their control to another organisation in a commonly used machine-readable format,</cite> though <cite index="37-4,37-5">the porting organisation must determine whether a receiving organisation has a presence in Singapore, limiting the obligation to receiving organisations with a Singapore presence.</cite> Response deadlines are prescribed: <cite index="52-18">if the organisation is unable to provide the personal data or make the correction requested within 30 days after receiving the request, the organisation must inform the individual, in writing, within 30 days, of the time by which it will respond.</cite> <cite index="22-21,22-23">Notification to PDPC must be made no later than three calendar days after determining the breach is notifiable, with the deadline starting from the time of that determination.</cite>

No periodic updates recorded against this sub-brief.

Sources and claims (6)
  1. ConfirmedInternational Association of Privacy ProfessionalsUnder Section 21 of the PDPA, individuals may request access to their personal data held by an organisation and information about its use or disclosure in the year preceding the request.
  2. ConfirmedInternational Association of Privacy ProfessionalsThe PDPA provides individuals a right to request correction of errors or omissions in their personal data under Section 22, but does not provide a right to request erasure or deletion of personal data.
  3. ConfirmedInternational Association of Privacy ProfessionalsIndividuals may withdraw consent for collection, use or disclosure of their personal data at any time, with reasonable notice, obliging the organisation to cease the relevant processing.
  4. ConfirmedPersonal Data Protection CommissionThe Data Portability Obligation requires organisations, upon request, to transmit an individual's data held in electronic form to another organisation with a presence in Singapore in a commonly used machine-readable format.
  5. ConfirmedPersonal Data Protection CommissionOrganisations that cannot provide requested personal data or make a correction within 30 days of a request must inform the individual in writing within 30 days of the time by which they will respond.
  6. ConfirmedPersonal Data Protection CommissionWhere a data breach is determined to be notifiable, notification to the PDPC must be made no later than three calendar days after the organisation determines the breach is notifiable.

#

Protection, breach notification, retention and DPO duties are robust and enforced, but there is no formal Records-of-Processing-Activities (ROPA) obligation equivalent to GDPR Art 30.

Primary frameworkPersonal Data Protection Act 2012, as amended
Traffic-light rationale — AmberProtection, breach notification, retention and DPO duties are robust and enforced, but there is no formal Records-of-Processing-Activities (ROPA) obligation equivalent to GDPR Art 30.

Sub-modules (7)

Accountability And DpiaAmber

Accountability is now an explicit statutory principle; DPIA-style analysis is triggered only for specific consent exceptions rather than as a general obligation.

Claims: CLM-SG-8f9a0b1c, CLM-SG-9a0b1c2d

Dpo RequirementsAmber

Mandatory DPO appointment applies to every organisation, without GDPR-style independence or qualification criteria.

Claims: CLM-SG-0b1c2d3e

Ropa RequirementsRed

No dedicated Records-of-Processing-Activities obligation was identified in the PDPA or PDPC guidance; the accountability obligation requires internal policies and practices documentation but not a formal register.

Absence provenance: not recorded. Searched: PDPC ROPA records of processing activities requirement, PDPA accountability obligation register of processing.

Joint Controller ArrangementsGreen

Controller-processor liability flows through the controller for data intermediaries; a processor exceeding instructions assumes full Data Protection Provisions liability.

Claims: CLM-SG-1c2d3e4f

Security MeasuresGreen

The Protection Obligation mandates reasonable technical and organisational security arrangements.

Claims: CLM-SG-2d3e4f5a

Breach NotificationGreen

Mandatory breach notification is triggered by significant-harm or 500+-individual thresholds, with sector-specific overlay for MAS-regulated financial institutions.

Claims: CLM-SG-3e4f5a6b, CLM-SG-4f5a6b7c

Retention And DisposalGreen

Retention Limitation Obligation requires cessation of retention once the collection purpose is no longer served.

Claims: CLM-SG-5a6b7c8d

Category narrative270 words

Accountability is explicit: <cite index="8-15">while the principle of accountability is currently implied in Sections 11 and 12 of the PDPA, the amendments include an explicit reference to the term accountability.</cite> DPIA-type analysis is required only contextually: <cite index="46-21">the PDPA requires data controllers to conduct DPIAs when seeking to collect, use or disclose personal data without express consent and are seeking to rely either on the legitimate interests exception, or deemed consent by notification.</cite> DPO appointment is universal, though: <cite index="35-4">the DPO is not required to be physically present in Singapore, but should be readily reachable from Singapore and operational during Singapore business hours,</cite> and <cite index="46-25">unlike the GDPR, the PDPA does not provide a definition of a DPO.</cite> Processor obligations flow through the controller: <cite index="35-5">the PDPA provides that an organisation will have the same obligations in respect of personal data processed on its behalf and for its purposes by a data intermediary as if the personal data were processed by the organisation itself.</cite> <cite index="56-12">The Protection Obligation under Section 24 requires organizations to make reasonable security arrangements to protect personal data in order to prevent unauthorized access, collection, use, disclosure, copying, modification, disposal or similar risks.</cite> Breach notification: <cite index="22-11">the PDPA requires organisations to notify when a breach is likely to result in significant harm to individuals or when it affects 500 or more individuals.</cite> <cite index="56-13">The Retention Limitation Obligation under Section 25 requires an organization to cease to retain documents containing personal data as soon as it is reasonable to assume that the purpose for which that personal data was collected is no longer being served by retention.</cite>

No periodic updates recorded against this sub-brief.

Sources and claims (8)
  1. ConfirmedOneTrust DataGuidanceThe accountability principle, initially implied in Sections 11 and 12 of the PDPA, was made an explicit statutory reference through the 2020 amendments.
  2. ProbableOneTrust DataGuidanceThe PDPA requires organisations to conduct a form of impact assessment when relying on the legitimate interests exception or on deemed consent by notification, though it does not impose a general DPIA obligation equivalent to GDPR Article 35.
  3. ConfirmedOneTrust DataGuidanceAlthough the DPO is not required to be physically present in Singapore, the PDPC expects the DPO to be readily reachable from Singapore and operational during Singapore business hours; the PDPA, unlike the GDPR, does not define specific independence or qualification criteria for the DPO role.
  4. ConfirmedPersonal Data Protection CommissionAn organisation has the same obligations for personal data processed on its behalf by a data intermediary as if the organisation processed the data itself, but a data intermediary that exercises its own judgement beyond the controller's instructions becomes subject to the full Data Protection Provisions for that processing.
  5. ConfirmedInternational Association of Privacy ProfessionalsThe Protection Obligation under Section 24 of the PDPA requires organisations to make reasonable security arrangements to prevent unauthorised access, collection, use, disclosure, copying, modification or disposal of personal data.
  6. ConfirmedPersonal Data Protection CommissionA data breach is notifiable to the PDPC and affected individuals if it is likely to result in significant harm to affected individuals or affects 500 or more individuals.
  7. ProbablePersonal Data Protection CommissionFinancial institutions must separately report data breaches to the Monetary Authority of Singapore where the breach has a severe and widespread impact on the institution's operations or materially affects services to customers.
  8. ConfirmedInternational Association of Privacy ProfessionalsThe Retention Limitation Obligation under Section 25 requires an organisation to cease retaining documents containing personal data, or remove the means of associating the data with an individual, as soon as the retention purpose is no longer served and retention is no longer necessary for legal or business purposes.

#

Transfer regime is mature with recognised certification schemes (APEC CBPR/PRP) and model clauses, though Singapore is not a recipient of an EU adequacy decision.

Primary frameworkPersonal Data Protection Act 2012, as amended (Transfer Limitation Obligation, s.26)
Traffic-light rationale — GreenTransfer regime is mature with recognised certification schemes (APEC CBPR/PRP) and model clauses, though Singapore is not a recipient of an EU adequacy decision.

Sub-modules (6)

Transfer MechanismsGreen

Comparable-protection standard under s.26, satisfiable via contract, consent, or recognised certification schemes.

Claims: CLM-SG-6b7c8d9e, CLM-SG-7c8d9e0f

Adequacy ReceivedRed

No confirmed record of Singapore receiving a formal adequacy-style determination from another regime (e.g., EU) was found in this pass.

Absence provenance: not recorded. Searched: Singapore EU adequacy decision GDPR, Singapore adequacy determination received.

Adequacy GrantedAmber

PDPC does not operate a GDPR-style adequacy-list mechanism; instead it relies on recognised certification (APEC CBPR/PRP) and contractual mechanisms as functional equivalents.

Absence provenance: not recorded. Searched: PDPC adequacy list granted third countries.

Sccs And BcrsGreen

ASEAN Model Contractual Clauses (tailored by PDPC) and APEC CBPR/PRP certifications function as the primary standard-clause/certification mechanisms.

Claims: CLM-SG-8d9e0f1a

Transfer Impact AssessmentAmber

No codified TIA methodology; due diligence obligation is placed on the transferring organisation.

Claims: CLM-SG-9e0f1a2b

Data LocalisationGreen

No general data localisation mandate; recent EU-SG trade agreement further constrains unjustified localisation requirements.

Claims: CLM-SG-0f1a2b3c

Category narrative206 words

<cite index="31-3,31-4">Section 26 of the PDPA limits the ability of an organization to transfer personal data outside Singapore; section 26(1) provides that an organization must not transfer any personal data outside Singapore except where it can ensure that a comparable standard of protection, as provided for under the PDPA, will be maintained.</cite> <cite index="51-25,51-26">Singapore is a participant of the APEC CBPR and PRP System, and in June 2020, the Personal Data Protection Regulations 2014 was amended to recognise the APEC CBPR and PRP system certifications for overseas transfers of personal data under the PDPA.</cite> <cite index="39-1,39-2">The PDPC has published guidance on how to tailor the ASEAN Model Contractual Clauses to meet Singapore's PDPC requirements, including sample clauses for contracts with overseas recipients holding Global/APEC CBPR/PRP certification.</cite> <cite index="34-1,34-2">The Transfer Limitation Obligation requires that an organisation ensures that personal data transferred overseas is protected to a standard comparable with the Data Protection Provisions, with the onus on the transferring organisation to undertake appropriate due diligence.</cite> No EU adequacy decision covering Singapore was located in this research pass. Data localisation is generally not mandated, and <cite index="5-7">the EU-Singapore Digital Trade Agreement entered into force on February 1, 2026, enhancing online consumer protection and prohibiting unjustified data localization requirements.</cite>

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ConfirmedInternational Association of Privacy ProfessionalsSection 26 of the PDPA prohibits an organisation from transferring personal data outside Singapore except where it can ensure a standard of protection comparable to the PDPA is maintained over the transferred data.
  2. ConfirmedOneTrust DataGuidanceSince June 2020, the Personal Data Protection Regulations recognise APEC Cross-Border Privacy Rules (CBPR) and Privacy Recognition for Processors (PRP) system certifications as a basis for compliance with the Transfer Limitation Obligation for overseas transfers.
  3. ConfirmedPersonal Data Protection CommissionThe PDPC has published guidance on tailoring the ASEAN Model Contractual Clauses (MCCs) to meet Singapore's Transfer Limitation Obligation requirements, and provides sample clauses for contracts with overseas recipients holding Global/APEC CBPR or PRP certification.
  4. ConfirmedPersonal Data Protection CommissionThe onus is on the transferring organisation to undertake appropriate due diligence and obtain assurances that an overseas recipient can maintain a standard of protection comparable to the PDPA before transferring personal data outside Singapore.
  5. ProbableOneTrust DataGuidanceThe EU-Singapore Digital Trade Agreement, which entered into force on 1 February 2026, prohibits unjustified data localisation requirements between the parties.

#

Strong financial-sector and telecom-marketing overlays; credit-scoring and insurance-specific data rules could not be confirmed with primary sourcing.

Primary frameworkPersonal Data Protection Act 2012, overlaid by MAS Notices/Guidelines (financial) and sector-specific bills (health)
Traffic-light rationale — AmberStrong financial-sector and telecom-marketing overlays; credit-scoring and insurance-specific data rules could not be confirmed with primary sourcing.

Sub-modules (7)

Financial Sector OverlayGreen

MAS overlays PDPA with outsourcing, technology-risk, and data-governance guidelines for financial institutions; co-regulation exists alongside the PDPC.

Claims: CLM-SG-1a2b3c5d, CLM-SG-2b3c5d6e

Health Sector OverlayAmber

A Health Information Bill introduces a dedicated framework for health data management; enactment/commencement status requires confirmation.

Claims: CLM-SG-3c5d6e7f

Telecoms And EprivacyGreen

DNC provisions of the PDPA function as Singapore's direct-marketing/telecom-privacy overlay; IMDA separately regulates telecom licensees.

Claims: CLM-SG-4d6e7f8a

Employment DataGreen

Employment-purpose processing requires notification under s.20(4), satisfiable via general notice channels.

Claims: CLM-SG-5e7f8a9b

Credit And ScoringRed

No PDPA-specific credit-scoring regime was located in this research pass.

Absence provenance: not recorded. Searched: Singapore PDPA credit scoring regulation, PDPC credit bureau data protection.

EducationGreen

Private education institutions may collect NRIC numbers to satisfy record-keeping regulations.

Claims: CLM-SG-6f8a9b0c

InsuranceRed

No dedicated PDPA insurance-sector overlay was confirmed; stakeholder consultation responses reference interactions between minors' consent rules and insurance contract law but do not establish a standalone regime.

Absence provenance: not recorded. Searched: Singapore PDPA insurance sector data protection overlay, MAS insurance data protection notice.

Category narrative210 words

Financial services carry a substantive MAS overlay: <cite index="91-2,91-3,91-4">the Monetary Authority of Singapore issued Guidelines on Outsourcing Risk Management on 27 July 2016, including under certain circumstances arrangements involving customer information, setting MAS expectations of institutions entering outsourcing arrangements.</cite> <cite index="94-3,94-4">MAS issued guidance on 29 May 2024 for banks and finance companies to enhance data governance and management practices, emphasizing a data governance framework and board oversight, aligning with Basel Committee principles.</cite> Health data is addressed by a dedicated bill: <cite index="95-7">the Health Information Bill establishes a framework for health data management, defining roles, data sharing protocols, and penalties for non-compliance.</cite> Telecom-adjacent marketing is governed by the PDPA's own Do Not Call regime: <cite index="81-1,81-5">the DNC provisions of the PDPA generally prohibit organisations from sending marketing messages -- voice calls, text or fax messages -- to Singapore telephone numbers listed in the DNC Registry.</cite> Employment-context notice is streamlined: <cite index="30-16">PDPC's Advisory Guidelines clarify that it may be sufficient to provide general notification to employees such as through employment contracts, employee handbooks, or notices in the company intranet.</cite> In education, <cite index="73-8,73-9">registered private education institutions are required to keep proper records of enrolled students' NRIC numbers under the Private Education Regulations.</cite> Credit-scoring and insurance-specific overlays were not confirmed in this pass.

No periodic updates recorded against this sub-brief.

Sources and claims (6)
  1. ConfirmedOneTrust DataGuidanceThe Monetary Authority of Singapore's Guidelines on Outsourcing Risk Management, issued 27 July 2016, set MAS expectations for financial institutions entering outsourcing arrangements, including those involving customer information.
  2. ConfirmedOneTrust DataGuidanceMAS issued guidance on 29 May 2024 setting supervisory expectations for banks and finance companies to establish data governance frameworks addressing data quality, risk aggregation and risk reporting, informed by Basel Committee principles.
  3. UncertainOneTrust DataGuidanceSingapore's Health Information Bill establishes a framework for health data management, defining roles, data-sharing protocols and penalties for non-compliance.
  4. ConfirmedPersonal Data Protection CommissionThe Do Not Call (DNC) provisions of the PDPA prohibit organisations from sending marketing voice calls, text messages or faxes to Singapore telephone numbers registered on the DNC Registry.
  5. ConfirmedPersonal Data Protection CommissionUnder Section 20(4) of the PDPA, an organisation collecting, using or disclosing personal data for managing or terminating an employment relationship must inform the individual of that purpose, and PDPC guidance permits general notification via employment contracts, handbooks or intranet notices.
  6. ConfirmedPersonal Data Protection CommissionRegistered private education institutions may collect NRIC numbers from enrolled students where required to keep proper records under the Private Education Regulations.

#

Direct marketing/DNC regime is mature and enforced; cookie guidance exists but was not substantively verified, and dark-pattern/cross-context-advertising concepts are absent from the PDPA framework.

Primary frameworkPersonal Data Protection Act 2012, as amended (Do Not Call provisions, Part IX)
Traffic-light rationale — AmberDirect marketing/DNC regime is mature and enforced; cookie guidance exists but was not substantively verified, and dark-pattern/cross-context-advertising concepts are absent from the PDPA framework.

Sub-modules (6)

Cookies And TrackersAmber

PDPC Advisory Guidelines on Selected Topics address cookie consent and ad-targeting questions; substantive positions were not independently verified in this pass.

Claims: CLM-SG-7a9b0c1d

Dark PatternsRed

No PDPA-specific dark-pattern prohibition was located.

Absence provenance: not recorded. Searched: Singapore PDPA dark patterns prohibition, PDPC deceptive design guidance.

Opt Out SignalsGreen

DNC Registry functions as Singapore's principal opt-out signal mechanism for telemarketing.

Claims: CLM-SG-8b0c1d2e

Clean Rooms And DcrRed

No PDPC guidance on data clean rooms or data-collaboration rooms was located.

Absence provenance: not recorded. Searched: Singapore PDPC data clean room guidance.

Cross Context AdvertisingRed

PDPA has no CPRA-style 'sale'/'share' construct for cross-context behavioural advertising.

Absence provenance: not recorded. Searched: Singapore PDPA cross-context advertising sale share concept.

Direct MarketingGreen

DNC provisions and their offence/penalty structure form the core direct-marketing consent and suppression regime.

Claims: CLM-SG-9c1d2e3f, CLM-SG-0d2e3f4a

Category narrative164 words

Direct marketing is governed by the PDPA's own DNC regime rather than a distinct ePrivacy statute. <cite index="82-3">The Do Not Call (DNC) Registry helps individuals exercise the right to opt out of unwanted specified messages by registering their Singapore phone number.</cite> <cite index="89-2">Any person or organization found guilty of sending telemarketing messages to Singapore telephone numbers without checking the DNC Registry is liable to a fine of up to US$10,000 per message sent.</cite> <cite index="81-8">Organisations do not need to check the DNC Registry if they have the recipient's clear and unambiguous consent to send marketing messages to the Singapore telephone number.</cite> Cookie-specific guidance exists within PDPC's Advisory Guidelines on Selected Topics, which include dedicated questions on <cite index="47-16,47-17">whether consent must be obtained for the use of cookies and whether organisations are allowed to use cookies for targeting of advertisements</cite>, though the substantive answers were not retrieved in this pass. No dark-pattern-specific prohibition, clean-room/data-collaboration rule, or CPRA-style cross-context 'sale'/'share' concept was identified in the PDPA.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. UncertainOneTrust DataGuidanceThe PDPC's Advisory Guidelines on the PDPA for Selected Topics address whether consent must be obtained for the use of cookies and whether cookies may be used for targeted advertising.
  2. ConfirmedPersonal Data Protection CommissionThe Do Not Call Registry allows individuals to register their Singapore telephone number to opt out of receiving unwanted marketing voice calls, text messages and faxes.
  3. ConfirmedInternational Association of Privacy ProfessionalsA person or organisation that sends telemarketing messages to a Singapore telephone number without checking the DNC Registry, absent a relevant exception, commits an offence and is liable to a fine of up to US$10,000 per message sent.
  4. ConfirmedPersonal Data Protection CommissionOrganisations do not need to check the DNC Registry before sending marketing messages where they have the recipient's clear and unambiguous consent to receive such messages at that Singapore telephone number.

#

AI governance relies on voluntary frameworks (Model AI Governance Framework, Agentic AI MGF, ISAGO, AI Verify) rather than binding statute; no dedicated biometric or genetic-data law was confirmed, and national-security carve-outs are largely undocumented in general legislation.

Primary frameworkModel AI Governance Framework (voluntary); PDPA as general personal-data backstop
Traffic-light rationale — AmberAI governance relies on voluntary frameworks (Model AI Governance Framework, Agentic AI MGF, ISAGO, AI Verify) rather than binding statute; no dedicated biometric or genetic-data law was confirmed, and national-security carve-outs are largely undocumented in general legislation.

Sub-modules (6)

Profiling RestrictionsRed

No general Art 22-style profiling restriction was located in the PDPA; profiling limits appear only in children-specific guidance.

Absence provenance: not recorded. Searched: Singapore PDPA profiling restrictions automated decision-making adults, PDPC Article 22 equivalent.

Automated Decision Making TransparencyAmber

Transparency/explainability are addressed through the voluntary Model AI Governance Framework rather than a binding ADM transparency right.

Claims: CLM-SG-2f4a5b6c

Ai Risk AssessmentsAmber

AI risk assessment tools (ISAGO, AI Verify) and the new Agentic AI Model Governance Framework are voluntary; MAS is separately consulting on binding-adjacent AI risk guidance for financial institutions.

Claims: CLM-SG-3a5b6c7d, CLM-SG-4b6c7d8e, CLM-SG-5c7d8e9f

Biometric RegimeAmber

No dedicated biometric-data statute was confirmed; biometric data is treated as personal data under the PDPA, supplemented by ad hoc device-specific guidance (e.g., smart glasses).

Claims: CLM-SG-6d8e9f0a

Genetic DataRed

No dedicated genetic-data regime was identified in this research pass.

Absence provenance: not recorded. Searched: Singapore PDPA genetic data regulation, PDPC genetic data guidance.

State Surveillance CarveoutsAmber

Public agencies sit outside the PDPA and are governed by their own internal data rules; no general public-authority surveillance statute over private-sector-held data was confirmed.

Claims: CLM-SG-7e9f0a1b, CLM-SG-8f0a1b2c

Category narrative186 words

Singapore's AI governance is predominantly voluntary/soft-law rather than binding. <cite index="68-4,68-5,68-6">The Model AI Governance Framework's 11 guiding principles include transparency, explainability, repeatability/reproducibility and safety, aiming to improve public understanding and trust in AI.</cite> <cite index="68-11,68-13">AI Verify is a testing framework/toolkit and the Implementation and Self-Assessment Guide for Organizations (ISAGO) offers practical implementation advice, though AI Verify cannot test Generative AI/LLMs and does not guarantee safety.</cite> <cite index="70-1,70-2">Singapore's Agentic AI Model Governance Framework was unveiled in January 2026, the first governance model in the world specifically addressing agentic AI.</cite> <cite index="95-1">MAS opened a consultation on AI risk management guidelines for financial institutions, covering governance, oversight, and lifecycle controls.</cite> Biometric-specific statutory regimes were not confirmed; <cite index="5-22">MDDI advises organizations on compliance with the PDPA for AI-equipped smart glasses, addressing privacy, safety and related considerations,</cite> functioning as sector guidance rather than a dedicated biometric law. On surveillance, <cite index="51-13,51-15">there is no general legislation in Singapore that specifically relates to surveillance conducted by public authorities of personal data held by private organisations, and Singapore public agencies are not subject to the PDPA's data protection provisions, having their own separate rules.</cite>

No periodic updates recorded against this sub-brief.

Sources and claims (7)
  1. ConfirmedPersonal Data Protection CommissionSingapore's Model AI Governance Framework, a voluntary framework rather than binding law, promotes principles of transparency and explainability for AI systems' decision-making processes.
  2. ConfirmedPersonal Data Protection CommissionPDPC and IMDA's Model AI Governance Framework is supported by the voluntary Implementation and Self-Assessment Guide for Organisations (ISAGO) and the AI Verify testing toolkit, which help organisations assess AI systems against the Framework's principles.
  3. ProbablearXivIn January 2026, Singapore unveiled a Model AI Governance Framework for Agentic AI, the first governance model specifically addressing agentic AI systems, emphasising human oversight and accountability for agentic AI risks.
  4. ProbableOneTrust DataGuidanceMAS opened a consultation on AI risk management guidelines for financial institutions covering governance, oversight and lifecycle controls.
  5. ProbableOneTrust DataGuidanceSingapore's media regulator (MDDI) has issued guidance advising organisations on PDPA compliance obligations for AI-equipped smart glasses, addressing privacy and safety considerations, rather than through a dedicated biometric-specific statute.
  6. ConfirmedOneTrust DataGuidanceSingapore public sector agencies are not subject to the PDPA's data protection provisions, being instead governed by their own public-sector data protection rules.
  7. ProbableOneTrust DataGuidanceThere is no general legislation in Singapore specifically governing surveillance by public authorities of personal data held by private organisations, beyond specific statutory powers to access and seize data.

#

Children's protections rest on PDPC advisory guidelines rather than statutory age-of-consent provisions, and dependent-adult protections are addressed only incidentally in breach-notification guidance.

Primary frameworkPDPC Advisory Guidelines on the PDPA for Children's Personal Data in the Digital Environment (non-statutory)
Traffic-light rationale — AmberChildren's protections rest on PDPC advisory guidelines rather than statutory age-of-consent provisions, and dependent-adult protections are addressed only incidentally in breach-notification guidance.

Sub-modules (5)

Age VerificationAmber

No statutory age of consent; PDPC applies a 13-years-old practical threshold via guidance.

Claims: CLM-SG-9a1b2c3d

Minor Profiling BansAmber

Data-minimisation guidance limits children's profile visibility by default rather than imposing an outright profiling ban.

Claims: CLM-SG-1c3d4e5f

Education SettingsAmber

Education-context organisations may prefer parental consent even for 13-17 year-olds as a matter of prudence.

Claims: CLM-SG-2d4e5f6a

Dependent AdultsRed

Vulnerable-adult protection is addressed only within breach-notification guidance (adoption/vulnerable-individual cases), not as a standalone statutory regime.

Claims: CLM-SG-3e5f6a7b

Category narrative228 words

Protections for minors are guidance-based rather than statutory. <cite index="43-2">The PDPA does not define 'child' nor 'children'.</cite> <cite index="49-10">Unlike the GDPR, the PDPA does not stipulate a minimum age of consent, choosing to leave it to other general rules of law to determine the question of capacity;</cite> however, <cite index="41-1">the PDPC considers that a child between 13 and 17 may give valid consent when policies on collection, use, disclosure and withdrawal are readily understandable by them.</cite> <cite index="41-12">Where the child is below 13 years of age, the organisation must obtain consent from the child's parent or guardian.</cite> <cite index="41-6">Where an organisation has reason to believe that a child does not have sufficient understanding of the nature and consequences of giving consent, the organisation should obtain consent from the child's parent or guardian.</cite> <cite index="41-14,41-15">Organisations should adopt data minimisation policies to limit the collection and sharing of children's personal data, including ensuring that children's account information is not made public and searchable by default.</cite> <cite index="41-9">An organisation in an education setting may assess that it is more prudent to obtain consent from a parent of a 13-year-old rather than to directly seek the consent of a 13-year-old.</cite> On vulnerable adults, <cite index="21-12">where a data breach involves information related to adoption matters or the identification of vulnerable individuals, organisations should first notify the Commission for guidance on notifying affected individuals.</cite>

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ConfirmedInternational Association of Privacy ProfessionalsThe PDPA does not define 'child' or stipulate a statutory minimum age of consent; the PDPC applies a practical rule of thumb that a minor aged 13 or above typically has sufficient understanding to consent on their own behalf.
  2. ConfirmedPersonal Data Protection CommissionWhere a child is below 13 years of age, or where an organisation has reason to believe a child lacks sufficient understanding of the nature and consequences of consent, the organisation must obtain consent from the child's parent or guardian.
  3. ConfirmedPersonal Data Protection CommissionPDPC guidance directs organisations handling children's personal data to adopt data minimisation policies, including ensuring that children's account information is not made public and searchable by default.
  4. ConfirmedPersonal Data Protection CommissionIn an education setting, an organisation may consider it more prudent to obtain parental consent for a 13-year-old rather than seeking the child's consent directly.
  5. ConfirmedPersonal Data Protection CommissionWhere a data breach involves information related to adoption matters or the identification of vulnerable individuals, organisations should first notify the PDPC for guidance before notifying affected individuals.

#

Active, escalating enforcement (higher penalty caps, regular published decisions) with a functioning private right of action, though regulator funding/capacity data and collective-redress mechanisms were not confirmed.

Primary frameworkPersonal Data Protection Act 2012, as amended (Enforcement provisions, Part IX-X; s.48O private right of action)
Traffic-light rationale — GreenActive, escalating enforcement (higher penalty caps, regular published decisions) with a functioning private right of action, though regulator funding/capacity data and collective-redress mechanisms were not confirmed.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

Maximum penalty of 10% of Singapore annual turnover (for organisations exceeding S$10m turnover) or S$1m, whichever is higher, backed by document-production and examination powers.

Claims: CLM-SG-4f6a7b8c, CLM-SG-5a7b8c9d

Enforcement Activity IndexGreen

Recent published decisions (Marina Bay Sands, October 2025; People Central, January 2026) evidence sustained enforcement activity.

Claims: CLM-SG-6b8c9d0e, CLM-SG-7c9d0e1f

Regulator Funding And CapacityRed

No specific budget or headcount data for the PDPC was located in this research pass.

Absence provenance: not recorded. Searched: PDPC budget headcount annual report, IMDA PDPC staffing data protection.

Collective Redress And Class ActionsRed

No PDPA-specific class-action or collective-redress mechanism was confirmed in this research pass.

Absence provenance: not recorded. Searched: Singapore PDPA class action collective redress data protection, representative proceedings PDPA.

Private Right Of ActionGreen

Section 48O provides a private right of civil action, contingent on finality of any related PDPC decision.

Claims: CLM-SG-8d0e1f2a

Recent Developments 180DAmber

Notable near-term developments include a scheduled 2027 NRIC-misuse enforcement escalation, the EU-Singapore Digital Trade Agreement entering into force, and ongoing MAS AI risk-management consultation.

Claims: CLM-SG-9e1f2a3b, CLM-SG-1a3b4c5d

Category narrative233 words

Financial penalties were substantially increased in 2022: <cite index="20-2">the financial penalty cap which may be imposed on organisations for breaches under the PDPA has increased from the previously fixed S$1 million, to 10% of the organisation's annual turnover in Singapore for organisations with annual local turnover exceeding S$10 million, whichever is higher,</cite> with the change <cite index="1-1">taking effect on 1 October 2022.</cite> Investigative powers are broad: <cite index="52-23">the Commission's powers include the power to require production of documents and information, and the power to require the attendance of persons, and to orally examine them.</cite> Recent enforcement activity includes a financial penalty against Marina Bay Sands: <cite index="12-3,12-4">MBS failed to discover and correct an omission for six months, leaving patrons' personal data unprotected, in negligent contravention of the Protection Obligation,</cite> and, more recently, <cite index="19-1">a financial penalty of $17,500 was imposed and directions were issued to People Central Pte Ltd for failing to put in place reasonable security arrangements, on 8 January 2026.</cite> Private redress exists: <cite index="51-5,51-6">individuals who have suffered loss or damage directly as a result of a contravention under Section 48O of the PDPA may commence civil proceedings in the courts, with the right of private action arising only after the PDPC's decision on the contravention becomes final.</cite> Recent developments include an NRIC-misuse enforcement escalation: <cite index="5-3">PDPC will enforce stricter measures against NRIC misuse by private organizations starting January 1, 2027.</cite>

No periodic updates recorded against this sub-brief.

Sources and claims (7)
  1. ConfirmedPersonal Data Protection CommissionSince amendments effective 1 October 2022, the maximum financial penalty for PDPA breaches by organisations with annual turnover in Singapore exceeding S$10 million is 10% of their annual turnover in Singapore, or S$1 million, whichever is higher.
  2. ConfirmedPersonal Data Protection CommissionThe PDPC has powers to require production of documents and information and to require the attendance of persons for oral examination in the course of its investigations.
  3. ConfirmedPersonal Data Protection CommissionIn October 2025, the PDPC imposed a financial penalty and directions on Marina Bay Sands Pte Ltd for a negligent contravention of the Protection Obligation arising from a data migration exercise that left patrons' personal data unprotected for six months.
  4. ConfirmedPersonal Data Protection CommissionOn 8 January 2026, the PDPC imposed a financial penalty of S$17,500 and directions on People Central Pte Ltd for failing to put in place reasonable security arrangements to protect personal data.
  5. ConfirmedOneTrust DataGuidanceUnder Section 48O of the PDPA, individuals who suffer loss or damage directly as a result of a contravention may commence civil proceedings against the organisation, with the right of private action arising after any PDPC decision on the matter becomes final.
  6. ProbableOneTrust DataGuidanceThe PDPC will enforce stricter measures against NRIC misuse by private organisations starting 1 January 2027.
  7. ProbableOneTrust DataGuidanceMAS opened a consultation on AI risk management guidelines for financial institutions covering governance, oversight and lifecycle controls, indicating forthcoming sector-specific AI risk guidance.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Singapore
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 59 claim(s), 30 source(s) in the cumulative register.