Singapore Personal Data Protection Act
Singapore data protection law governing collection, use, and disclosure of personal data by private organizations in Singapore.
What PDPA draws on
This framework pulls on all three pillars — which is why running them as three separate tools means reconciling three sets of evidence at audit time.
Compliance
Security
What your auditor cites,
and what produces the evidence
The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.
Protection Obligation
Organizations MUST protect personal data with reasonable security arrangements.
Continuous scanning checks each engine and version against known CVEs, missing patches, end-of-life versions, and hardening benchmarks, and extends to the network: exposed listeners, unexpected reachability, weak TLS, and drift from the documented baseline. Findings rank by exploitability and by the classification of the data at risk, so the same CVE sits differently in the queue on classified data than on a development copy — and the scan history is the evidence that the control operated continuously rather than quarterly.
Access Obligation
Upon request, organizations MUST provide individuals access to their personal data and information about its use.
Discovery locates every column holding a subject's data across every connected store, and the access history for that subject is reportable in minutes rather than reconstructed from tickets. The deletion or correction itself is executed by your application or your DBA — what the platform produces is the evidence of where the data was, who touched it, and that the change happened.
Data Breach Notification
Notifiable breaches MUST be reported to PDPC within 3 calendar days of assessment.
Notification clocks start when you become aware, so detection latency is the whole exposure. Behavioural baselines score each deviation as it happens and flag it in under a second, rather than surfacing it in a weekly review. Severity is decided at the collector and routed immediately, so the window between the access and someone knowing about it is measured in seconds — and the audit trail behind it already holds what was reached, by whom, and when.
Retention Limitation
Organizations MUST cease retention when no longer necessary for legal or business purposes.
Retention obligations are easy to state and expensive to meet, because the cost is in keeping the record queryable rather than merely stored. Audit events land in columnar storage on immutable object storage, so a multi-year window costs object-storage prices and is still searchable in seconds when an examiner asks for a sample. Each record carries a verification hash, so what you produce years later is demonstrably what was written at the time.
What PDPA covers
s. 2(1)
Data about an individual who can be identified from that data, or from that data and other information the organisation has or is likely to have access to.
In scope
- Identifying data held by the organisation
- Data identifying a person in combination with other information reasonably accessible to the organisation
What falls outside
Business contact information — name, title, business telephone and address — provided for business purposes, which sits outside most of the Act.
Personal Data Protection Act 2012 · as at 2026-08
How PDPA is enforced
Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The Personal Data Protection Commission of Singapore.
| Published maximum | Charged | As at |
|---|---|---|
| SGD 1 million | the fixed ceiling | 2026-08 |
| 10% of annual turnover in Singapore | where Singapore turnover exceeds SGD 10 million; the higher of the two applies | 2026-08 |
The turnover-linked ceiling was introduced by the 2020 amendments and applies where annual Singapore turnover exceeds SGD 10 million. Alongside the organisational penalty, Part 9B creates personal criminal offences for individuals who mishandle personal data held by their own employer.
Maximums are ceilings set by the instrument; enforcement is discretionary and tiered.
Who is personally on the hook
- Who can be charged
- Any individual who knowingly or recklessly discloses, uses, or re-identifies personal data held by their organisation without authorisation
- For what
- knowingly or recklessly disclosing, using, or re-identifying personal data held by their own employer
- Maximum
- A fine of up to SGD 5,000, imprisonment for up to 2 years, or both
- Brought by
- Public prosecutors, on referral from the PDPC
Uncapped exposure that sits outside this instrument
These come from company law rather than from PDPA, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.
Duty of oversight
Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.
Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.
Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.
This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.
In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).
Enforcement data reviewed August 2026. Several figures are indexed annually and move.
Built for PDPA,
not configured for it afterwards
Singapore Data Protection
Monitor access to NRIC, FIN, and Singapore-specific identifiers
PDPA Compliance Report
Document data protection measures and access controls
Singapore PII Patterns
Detect NRIC, FIN, Singapore phone formats, postal codes
3-Day Breach Alert
Rapid breach detection to meet 3-day notification requirement
Other Data Privacy frameworks
Walk into the PDPA audit knowing the answer
228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.