Data Protection and the PDPA in Singapore

Data protection in Singapore runs mainly on one statute, the Personal Data Protection Act 2012, supervised by the Personal Data Protection Commission. This section explains how the Act is structured, how to complain when an organisation mishandles your data, and how the separate online-falsehoods regime under POFMA fits alongside it.
This is general legal information, not legal advice. Consult a qualified advocate and solicitor about your situation.
Information last verified on 22 July 2026. This page provides general legal information about Singapore law and is not legal advice in an individual case.
What the PDPA covers
The PDPA governs the collection, use and disclosure of personal data by organisations. Personal data means data about an identifiable individual, and the Act sets out obligations that an organisation must meet whenever it handles that data.
The Act does not regulate individuals acting privately. Section 4(1)(a) provides that the data protection obligations do not apply to an individual acting in a personal or domestic capacity. It is the organisation-facing nature of the Act that defines its scope: a company, an employer or an association is bound, while a private individual handling their own personal contacts is not.
The data protection obligations
The PDPC describes the Act's requirements as a set of 11 data protection obligations, covering matters such as consent, purpose limitation, notification, access and correction, accuracy, protection, retention limitation, transfer limitation and accountability.

There is an important qualification. The eleventh obligation, the Data Portability Obligation, is listed by the PDPC but has not commenced. The PDPC states that it will take effect when the supporting Regulations are issued. A reader should not be told they can make a data portability request today, because that right is not yet in force.
Data breach notification
Since the introduction of mandatory breach notification, an organisation that suffers a data breach must assess whether it is notifiable and, if so, notify the PDPC. Under s 26D, notification to the PDPC must be made no later than 3 calendar days after the day the organisation assesses that the breach is a notifiable data breach.
The clock runs from the organisation's own assessment that the breach is notifiable, not from the date the breach was discovered. A breach is of significant scale, and therefore notifiable, if it affects 500 or more individuals, a figure fixed by reg 4 of the Personal Data Protection (Notification of Data Breaches) Regulations 2021. A breach that is likely to result in significant harm to affected individuals is also notifiable. Affected individuals must generally be notified as well, subject to the exceptions in the Act.
Penalties and enforcement
The PDPC can investigate a suspected contravention and can issue directions and financial penalties. Section 48J sets the ceiling for a financial penalty on an organisation. Since 1 October 2022, that ceiling is up to 10 percent of the organisation's annual turnover in Singapore where that turnover exceeds S$10 million, and otherwise up to S$1 million. A separate, lower tier applies to individuals.

Enforcement by the PDPC is distinct from compensation to an affected person. The PDPC's directions and penalties are regulatory. They do not put money in the hands of the individual whose data was mishandled.
Getting compensation: the private right of action
An individual who suffers loss or damage directly as a result of a contravention has a separate right of private action under s 48O. That is a civil claim in court, and the remedies can include damages, an injunction or a declaration.

There is a timing gate. Where the PDPC has made a decision on the same contravention, the private action generally cannot be brought until that decision is final, with no further right of appeal. The detailed process for raising a concern with the PDPC first is on the how to make a complaint to the PDPC guide.
POFMA sits alongside, not inside, the PDPA
Data protection is not the only online-facing law people ask about. The Protection from Online Falsehoods and Manipulation Act 2019, known as POFMA, is a separate regime that lets a Minister issue directions in response to a false statement of fact communicated in Singapore against the public interest. It is not part of the PDPA and does not deal with personal data. The mechanism, and how it differs from a defamation claim, is explained on the POFMA explained guide.
Guides in this section
- How to make a complaint to the PDPC walks through contacting the organisation first, the escalation windows, and what the PDPC can and cannot do.
- POFMA explained covers Correction Directions, Stop Communication Directions and the appeal path to the High Court.

For a shorter country-level summary written as part of the worldwide data privacy survey, see the Singapore entry in the world data privacy survey. The wider legal map is on the Singapore law overview, and the related recording rules are on the recording laws in Singapore section page.
Frequently Asked Questions
What is the PDPA in Singapore?
The Personal Data Protection Act 2012 (PDPA) is Singapore's main data protection statute. It governs how organisations collect, use and disclose personal data, and it is supervised by the Personal Data Protection Commission (PDPC). It sets out a set of data protection obligations for organisations, requires notification of certain data breaches, and provides for financial penalties and a private right of action.
How many data protection obligations are there under the PDPA?
The PDPC lists 11 data protection obligations. The eleventh, the Data Portability Obligation, is listed but has not yet come into force. The PDPC states that it will take effect when the supporting Regulations are issued, so an individual cannot make a data portability request today.
When must a data breach be reported to the PDPC?
Under s 26D of the PDPA, an organisation must notify the PDPC of a notifiable data breach no later than 3 calendar days after the day it assesses that the breach is notifiable. A breach is of significant scale, and therefore notifiable, if it affects 500 or more individuals, per reg 4 of the Notification of Data Breaches Regulations 2021, and a breach likely to cause significant harm is also notifiable.
Can the PDPC award me compensation?
No. The PDPC's role is regulatory. It can issue directions and financial penalties against an organisation, but it does not award damages to an affected individual. To seek compensation, an individual uses the separate private right of action under s 48O of the PDPA, which is a civil claim in court and generally can only be brought after any PDPC decision on the same contravention is final.
Is POFMA part of the PDPA?
No. POFMA, the Protection from Online Falsehoods and Manipulation Act 2019, is a separate statute. It lets a Minister issue directions in response to a false statement of fact communicated in Singapore against the public interest. It does not deal with personal data and is not administered by the PDPC.
Updates
The enhanced financial penalty tier under s 48J of the PDPA took effect, allowing a penalty of up to 10 percent of an organisation's annual turnover in Singapore where that turnover exceeds S$10 million.
Sources and References
- Personal Data Protection Act 2012(sso.agc.gov.sg).gov
- Personal Data Protection Commission, the data protection obligations under the PDPA(pdpc.gov.sg).gov
- Personal Data Protection Act 2012, s 4(1)(a) (no obligation on an individual acting in a personal or domestic capacity)(sso.agc.gov.sg).gov
- Personal Data Protection Act 2012, s 26D (duty to notify the Commission of a notifiable data breach)(sso.agc.gov.sg).gov
- Personal Data Protection (Notification of Data Breaches) Regulations 2021, reg 4 (prescribed number of affected individuals is 500)(sso.agc.gov.sg).gov
- Personal Data Protection Act 2012, s 48J (financial penalties for a contravention)(sso.agc.gov.sg).gov
- Personal Data Protection Act 2012, s 48O (right of private action)(sso.agc.gov.sg).gov