English中文
Singapore flag

Singapore

Data Protection and the PDPA in Singapore

By Recording Law Editorial Team7 min read
Data Protection and the PDPA in Singapore

Frequently Asked Questions

What is the PDPA in Singapore?

The Personal Data Protection Act 2012 (PDPA) is Singapore's main data protection statute. It governs how organisations collect, use and disclose personal data, and it is supervised by the Personal Data Protection Commission (PDPC). It sets out a set of data protection obligations for organisations, requires notification of certain data breaches, and provides for financial penalties and a private right of action.

How many data protection obligations are there under the PDPA?

The PDPC lists 11 data protection obligations. The eleventh, the Data Portability Obligation, is listed but has not yet come into force. The PDPC states that it will take effect when the supporting Regulations are issued, so an individual cannot make a data portability request today.

When must a data breach be reported to the PDPC?

Under s 26D of the PDPA, an organisation must notify the PDPC of a notifiable data breach no later than 3 calendar days after the day it assesses that the breach is notifiable. A breach is of significant scale, and therefore notifiable, if it affects 500 or more individuals, per reg 4 of the Notification of Data Breaches Regulations 2021, and a breach likely to cause significant harm is also notifiable.

Can the PDPC award me compensation?

No. The PDPC's role is regulatory. It can issue directions and financial penalties against an organisation, but it does not award damages to an affected individual. To seek compensation, an individual uses the separate private right of action under s 48O of the PDPA, which is a civil claim in court and generally can only be brought after any PDPC decision on the same contravention is final.

Is POFMA part of the PDPA?

No. POFMA, the Protection from Online Falsehoods and Manipulation Act 2019, is a separate statute. It lets a Minister issue directions in response to a false statement of fact communicated in Singapore against the public interest. It does not deal with personal data and is not administered by the PDPC.

Updates

The enhanced financial penalty tier under s 48J of the PDPA took effect, allowing a penalty of up to 10 percent of an organisation's annual turnover in Singapore where that turnover exceeds S$10 million.

Sources and References

  1. Personal Data Protection Act 2012(sso.agc.gov.sg).gov
  2. Personal Data Protection Commission, the data protection obligations under the PDPA(pdpc.gov.sg).gov
  3. Personal Data Protection Act 2012, s 4(1)(a) (no obligation on an individual acting in a personal or domestic capacity)(sso.agc.gov.sg).gov
  4. Personal Data Protection Act 2012, s 26D (duty to notify the Commission of a notifiable data breach)(sso.agc.gov.sg).gov
  5. Personal Data Protection (Notification of Data Breaches) Regulations 2021, reg 4 (prescribed number of affected individuals is 500)(sso.agc.gov.sg).gov
  6. Personal Data Protection Act 2012, s 48J (financial penalties for a contravention)(sso.agc.gov.sg).gov
  7. Personal Data Protection Act 2012, s 48O (right of private action)(sso.agc.gov.sg).gov
Share: