PDPA Compliance for Businesses in Singapore

Any organisation in Singapore that collects, uses or discloses personal data has duties under the Personal Data Protection Act 2012, and those duties do not wait until a business reaches a certain size. This guide sets out the practical compliance steps for a business, starting with the one requirement people most often get wrong: appointing the person responsible for data protection.
This is general legal information, not legal advice. Consult a qualified advocate and solicitor about your situation.
Information last verified on 23 July 2026. This page provides general legal information about Singapore law and is not legal advice in an individual case.
The PDPA applies to every organisation
The PDPA binds organisations, not private individuals, but it draws no line based on size, revenue or number of staff. A sole proprietor collecting customer contacts and a multinational both fall within it. If your business handles personal data about identifiable individuals, whether customers, members or job applicants, the Act applies to you.
That is a common surprise for small businesses. There is no small-business exemption from the core data protection obligations, and there is no threshold below which the requirement to appoint a responsible individual falls away.
Step one: designate a responsible individual (the DPO)
The foundational compliance step is in s 11(3): an organisation must designate one or more individuals to be responsible for ensuring that the organisation complies with the Act. This is the requirement everyone refers to as appointing a Data Protection Officer.

It is worth being precise, because it affects how you read the law. The phrase Data Protection Officer, and the initials DPO, do not appear in the Act. DPO is the label the PDPC uses for the individual an organisation must designate under s 11(3). So when a compliance checklist tells you to appoint a DPO, the underlying legal duty is the s 11(3) designation. The PDPC confirms that every organisation in Singapore that handles personal data must appoint at least one such individual.
The designated individual may delegate the responsibility to another person (s 11(4)), but the duty to designate someone remains.
Make the contact information public
Appointing the individual is not enough on its own. Under s 11(5), the organisation must make available to the public the business contact information of at least one of the designated individuals, so that a member of the public knows who to reach about the organisations handling of personal data.
You can satisfy this by publishing the contact details, for example on your website or privacy policy. The PDPC also states that registering your DPO with the PDPC automatically fulfils both the appointment and the public-contact requirements, which is a convenient route for a small organisation.
A DPO is not a liability shield
One misconception is worth correcting directly. Appointing a DPO does not move legal responsibility off the business and onto that person. Section 11(6) says in terms that the designation of an individual does not relieve the organisation of any of its obligations under the Act.
In other words, appointing a DPO is a compliance step, not a way to outsource liability. If the organisation contravenes the Act, the organisation itself remains answerable, regardless of who its DPO is or what that person did or did not do.
The obligations you are complying with
The PDPC frames the Acts requirements as 11 data protection obligations. They cover consent, notification of purpose, purpose limitation, access and correction, accuracy, protection (security), retention limitation, transfer limitation, accountability, and, more recently, data portability.

One qualification matters for planning. The eleventh obligation, data portability, is listed by the PDPC but has not commenced. It takes effect only when the supporting regulations are issued, so a business cannot yet receive or be required to act on a formal data portability request. The other obligations are live and enforceable now.
A working compliance posture typically means: obtaining valid consent or relying on another lawful basis, telling people why you collect their data, limiting use to those purposes, keeping data accurate, securing it with reasonable arrangements, not keeping it longer than needed, and being able to respond to access and correction requests. Section 12 separately requires an organisation to develop and implement internal policies and practices to meet these obligations.
Breach notification
If your organisation suffers a data breach, you must assess whether it is notifiable and, if it is, notify the PDPC. Under s 26D, notification must be made no later than 3 calendar days after the day the organisation assesses that the breach is a notifiable data breach.
Read that timing carefully. The 3-day clock runs from your own assessment that the breach is notifiable, not from the moment you discovered the breach. A breach is of significant scale, and therefore notifiable, if it affects 500 or more individuals, a figure fixed by reg 4 of the Personal Data Protection (Notification of Data Breaches) Regulations 2021. A breach likely to cause significant harm to affected individuals is also notifiable. Affected individuals generally have to be notified as well, subject to the exceptions in the Act. The detailed mechanics are on the data breach notification guide.
Penalties for getting it wrong
The PDPC can investigate a suspected contravention and issue directions and financial penalties. Section 48J sets the ceiling. Since 1 October 2022, an organisations financial penalty can be up to 10 percent of its annual turnover in Singapore where that turnover exceeds S$10 million, and otherwise up to S$1 million. A separate, lower tier applies to individuals.
A failure to designate a responsible individual, or to meet any other Part 3 obligation, sits within the conduct the PDPC can act on. The practical takeaway for a business is that compliance is cheaper than a penalty, and the first, low-cost step is simply to designate your responsible individual and publish their contact details.
Where to go next
For how the Act is structured overall, including how an affected individual complains and the private right of action for damages, see the data protection and the PDPA section page. For the step-by-step breach process, thresholds and timelines, see the data breach notification guide.

Frequently Asked Questions
Does every business in Singapore need a Data Protection Officer?
Yes. Section 11(3) of the PDPA requires every organisation that handles personal data to designate at least one individual responsible for ensuring compliance with the Act, and the PDPC calls that person a Data Protection Officer (DPO). There is no size or turnover threshold, so the requirement applies to a one-person business as much as to a large company.
Is DPO a term used in the PDPA?
No. The Act itself does not use the phrase Data Protection Officer or the initials DPO. Section 11(3) simply requires an organisation to designate one or more individuals responsible for ensuring compliance. DPO is the label the PDPC uses for that designated individual, so a checklist that says appoint a DPO is really referring to the s 11(3) designation.
Does appointing a DPO limit my businesss liability?
No. Section 11(6) states expressly that designating an individual does not relieve the organisation of any of its obligations under the Act. Appointing a DPO is a compliance step, not a liability shield. If the organisation contravenes the PDPA, the organisation remains answerable, regardless of who its DPO is.
How quickly must a business report a data breach to the PDPC?
Under s 26D, an organisation must notify the PDPC no later than 3 calendar days after the day it assesses that the breach is a notifiable data breach. The clock runs from the organisations own assessment, not from discovery. A breach is notifiable if it affects 500 or more individuals, or is likely to cause significant harm.
What are the penalties for breaching the PDPA?
The PDPC can issue directions and financial penalties under s 48J. Since 1 October 2022, an organisation can face a penalty of up to 10 percent of its annual turnover in Singapore where that turnover exceeds S$10 million, and otherwise up to S$1 million. A separate, lower tier applies to individuals.
Updates
The enhanced financial penalty tier under s 48J took effect, allowing a penalty of up to 10 percent of an organisations annual turnover in Singapore where that turnover exceeds S$10 million.
Sources and References
- Personal Data Protection Act 2012(sso.agc.gov.sg).gov
- Personal Data Protection Act 2012, s 11 (designation of individuals responsible for compliance; liability not shifted)(sso.agc.gov.sg).gov
- Personal Data Protection Commission, getting started as a Data Protection Officer(pdpc.gov.sg).gov
- Personal Data Protection Act 2012, s 26D (duty to notify the Commission of a notifiable data breach)(sso.agc.gov.sg).gov
- Personal Data Protection (Notification of Data Breaches) Regulations 2021, reg 4 (500 affected individuals is a notifiable breach)(sso.agc.gov.sg).gov
- Personal Data Protection Act 2012, s 48J (financial penalties for a contravention)(sso.agc.gov.sg).gov