PDPAData PrivacySingaporeAll Industries

Singapore Personal Data Protection Act

Singapore data protection law governing collection, use, and disclosure of personal data by private organizations in Singapore.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

PDPASection 24Patching, hardening, and exposureA record of access

Protection Obligation

Organizations MUST protect personal data with reasonable security arrangements.

Continuous scanning checks each engine and version against known CVEs, missing patches, end-of-life versions, and hardening benchmarks, and extends to the network: exposed listeners, unexpected reachability, weak TLS, and drift from the documented baseline. Findings rank by exploitability and by the classification of the data at risk, so the same CVE sits differently in the queue on classified data than on a development copy — and the scan history is the evidence that the control operated continuously rather than quarterly.

PDPASection 21Answering for an individual

Access Obligation

Upon request, organizations MUST provide individuals access to their personal data and information about its use.

Discovery locates every column holding a subject's data across every connected store, and the access history for that subject is reportable in minutes rather than reconstructed from tickets. The deletion or correction itself is executed by your application or your DBA — what the platform produces is the evidence of where the data was, who touched it, and that the change happened.

PDPASection 26BDetecting it in time to notify

Data Breach Notification

Notifiable breaches MUST be reported to PDPC within 3 calendar days of assessment.

Notification clocks start when you become aware, so detection latency is the whole exposure. Behavioural baselines score each deviation as it happens and flag it in under a second, rather than surfacing it in a weekly review. Severity is decided at the collector and routed immediately, so the window between the access and someone knowing about it is measured in seconds — and the audit trail behind it already holds what was reached, by whom, and when.

PDPASection 25Retention and availability

Retention Limitation

Organizations MUST cease retention when no longer necessary for legal or business purposes.

Retention obligations are easy to state and expensive to meet, because the cost is in keeping the record queryable rather than merely stored. Audit events land in columnar storage on immutable object storage, so a multi-year window costs object-storage prices and is still searchable in seconds when an examiner asks for a sample. Each record carries a verification hash, so what you produce years later is demonstrably what was written at the time.

What PDPA covers

s. 2(1)

Data about an individual who can be identified from that data, or from that data and other information the organisation has or is likely to have access to.

In scope

  • Identifying data held by the organisation
  • Data identifying a person in combination with other information reasonably accessible to the organisation

What falls outside

Business contact information — name, title, business telephone and address — provided for business purposes, which sits outside most of the Act.

Personal Data Protection Act 2012 · as at 2026-08

How PDPA is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The Personal Data Protection Commission of Singapore.

Published maximumChargedAs at
SGD 1 millionthe fixed ceiling2026-08
10% of annual turnover in Singaporewhere Singapore turnover exceeds SGD 10 million; the higher of the two applies2026-08

The turnover-linked ceiling was introduced by the 2020 amendments and applies where annual Singapore turnover exceeds SGD 10 million. Alongside the organisational penalty, Part 9B creates personal criminal offences for individuals who mishandle personal data held by their own employer.

Maximums are ceilings set by the instrument; enforcement is discretionary and tiered.

Who is personally on the hook

Who can be charged
Any individual who knowingly or recklessly discloses, uses, or re-identifies personal data held by their organisation without authorisation
For what
knowingly or recklessly disclosing, using, or re-identifying personal data held by their own employer
Maximum
A fine of up to SGD 5,000, imprisonment for up to 2 years, or both
Brought by
Public prosecutors, on referral from the PDPC
PrisonPersonal fineNot indemnifiable

Uncapped exposure that sits outside this instrument

These come from company law rather than from PDPA, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.

Duty of oversight

Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.

Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.

Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.

This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.

In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for PDPA,
not configured for it afterwards

Policy Template

Singapore Data Protection

Monitor access to NRIC, FIN, and Singapore-specific identifiers

Report

PDPA Compliance Report

Document data protection measures and access controls

Classification

Singapore PII Patterns

Detect NRIC, FIN, Singapore phone formats, postal codes

Alert

3-Day Breach Alert

Rapid breach detection to meet 3-day notification requirement

Other Data Privacy frameworks

Walk into the PDPA audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment