Personal Data Protection Commission (PDPC) · Singapore

Personal Data Protection Act 2012 (Singapore) compliance software

Singapore's data protection law, amended in 2020 and in force in stages from 1 February 2021 — 61 obligations across accountability, consent, access and correction, care of data, breach notification and Do Not Call, with every PDPC clock tracked.

At a glance
  • RegulatorPersonal Data Protection Commission (PDPC)
  • InstrumentPDPA 2012, 2020 Revised Edition (Act 40 of 2020 amendments, in force in stages from 1 Feb 2021)
  • Structure9 domains, Parts 3-6, 6A, 6B (not in force), 9, 9A-9C; 61 assessable controls
  • Notifications3 calendar days to PDPC after breach assessment · individuals as soon as practicable · penalty regime since 1 Oct 2022
SG PDPAAvailable
Overview

What SG PDPA requires

Who it applies to

  • Any organisation collecting, using or disclosing personal data in Singapore, other than an individual acting personally, an employee acting in the course of employment, or a public agency
  • Data intermediaries processing personal data on behalf of and for another organisation, for the sections that continue to bind them (sections 24-25 and parts of Part 6A)
  • Telecommunications service providers and anyone sending marketing messages to a Singapore telephone number, under Part 9's Do Not Call regime
  • Any organisation that has appointed, or must appoint, a Data Protection Officer under section 11(3)

The Personal Data Protection Act 2012 (2020 Revised Edition) is Singapore's general data protection law, administered by the Personal Data Protection Commission (PDPC) under the Info-communications Media Development Authority. The Personal Data Protection (Amendment) Act 2020 rewrote large parts of it — deemed consent by notification, the mandatory notifiable-data-breach regime, new offences for unauthorised disclosure, improper use and re-identification, and an enhanced financial penalty — commencing in stages from 1 February 2021, with the penalty regime following on 1 October 2022. GRCLens carries 61 assessable controls across 9 domains following the Act's own Part structure.

Nine domains cover accountability (the mandatory Data Protection Officer and policy framework), consent (including the 2020 deemed-consent-by-notification mechanism and the First Schedule exceptions for legitimate interests and business improvement purposes), purpose limitation and notification, access and correction, care of personal data (accuracy, protection, retention, cross-border transfer), data breach notification, Do Not Call, and the preventive controls a Part 9B offence or a Commission direction under Part 9C implies. Part 6B (data portability) was enacted in 2020 but has not been brought into force; GRCLens carries it as a single flagged, not-yet-assessable row.

Two clocks anchor the breach domain: a reasonable-and-expeditious internal assessment (PDPC's own guide treats 30 days as the outer limit) followed by notification to the Commission no later than 3 calendar days after that assessment is made, and notification to affected individuals as soon as practicable thereafter. A financial penalty of up to 10% of Singapore annual turnover above S$10 million, or S$1 million, whichever is higher, has applied since 1 October 2022 — GRCLens quotes it in guidance rather than treating it as a control, since nobody can be 'compliant' with what the Commission may fine.

In the platform

How GRCLens supports SG PDPA

SG PDPA runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.

Every PDPC clock as an indicator

The 3-calendar-day breach notification, the reasonable-and-expeditious assessment PDPC's own guide treats as 30 days, and the Do Not Call register-check duty are tracked as key risk indicators, so a missed clock is amber before it becomes a finding.

Consent traced to a lawful basis

Every control in the Consent domain traces back to section 13's three lawful bases — consent, deemed consent, or a named exception — including the 2020 legitimate-interests and business-improvement grounds, so an assessor can see which basis a given processing activity relies on.

Breach domain built around two thresholds

Section 26B's significant-harm and 500-individual scale thresholds, the assessment duty, and the separate Commission, individual and data-intermediary notification ducks are each their own control, so 'notifiable' is a documented decision, not a guess after the fact.

Part 6B tracked without being assessed

Data portability was enacted in 2020 but never commenced; GRCLens carries the one row flagged not in force, so the catalogue does not silently score a duty that does not yet exist — and is ready to activate the moment it commences.

Questions

SG PDPA frequently asked questions

Is the Personal Data Protection Act 2012 the same as the 2020 amendments?

The 2020 Revised Edition is the current consolidated text, already incorporating the Personal Data Protection (Amendment) Act 2020's changes. Those changes themselves commenced in stages — most from 1 February 2021, the enhanced financial penalty from 1 October 2022 — so 'the PDPA' today already means the amended Act; GRCLens's 61 controls follow the current 2020 Revised Edition numbering throughout.

How fast must a data breach be reported under the PDPA?

An organisation must assess a suspected breach in a reasonable and expeditious manner — PDPC's own guide treats 30 days as the outer limit — then notify the Commission no later than 3 calendar days after making that assessment, and notify affected individuals as soon as practicable where the breach is likely to cause significant harm.

Is data portability part of the PDPA today?

No. Part 6B was enacted by the 2020 amendment Act but has not been brought into force as of September 2026, and its operative sections do not appear in the consolidated Act text on Singapore Statutes Online. GRCLens carries a single flagged row so the gap is visible rather than silently assessed.

Talk to us about SG PDPA

Security Solution Consultants provides Singapore PDPA compliance advisory alongside the platform, so you can combine tooling with hands-on expertise.