English中文
Singapore flag

Singapore

PDPA Compliance for Businesses in Singapore

Independently fact-checkedBy Recording Law Editorial Team9 min read

Independently fact-checked against primary sources (last audited July 23, 2026). · 6 primary sources cited on this page. How we verify our legal content

PDPA Compliance for Businesses in Singapore

Frequently Asked Questions

Does every business in Singapore need a Data Protection Officer?

Yes. Section 11(3) of the PDPA requires every organisation that handles personal data to designate at least one individual responsible for ensuring compliance with the Act, and the PDPC calls that person a Data Protection Officer (DPO). There is no size or turnover threshold, so the requirement applies to a one-person business as much as to a large company.

Is DPO a term used in the PDPA?

No. The Act itself does not use the phrase Data Protection Officer or the initials DPO. Section 11(3) simply requires an organisation to designate one or more individuals responsible for ensuring compliance. DPO is the label the PDPC uses for that designated individual, so a checklist that says appoint a DPO is really referring to the s 11(3) designation.

Does appointing a DPO limit my businesss liability?

No. Section 11(6) states expressly that designating an individual does not relieve the organisation of any of its obligations under the Act. Appointing a DPO is a compliance step, not a liability shield. If the organisation contravenes the PDPA, the organisation remains answerable, regardless of who its DPO is.

How quickly must a business report a data breach to the PDPC?

Under s 26D, an organisation must notify the PDPC no later than 3 calendar days after the day it assesses that the breach is a notifiable data breach. The clock runs from the organisations own assessment, not from discovery. A breach is notifiable if it affects 500 or more individuals, or is likely to cause significant harm.

What are the penalties for breaching the PDPA?

The PDPC can issue directions and financial penalties under s 48J. Since 1 October 2022, an organisation can face a penalty of up to 10 percent of its annual turnover in Singapore where that turnover exceeds S$10 million, and otherwise up to S$1 million. A separate, lower tier applies to individuals.

Updates

Independently fact-checked against the cited primary sources

The enhanced financial penalty tier under s 48J took effect, allowing a penalty of up to 10 percent of an organisations annual turnover in Singapore where that turnover exceeds S$10 million.

Sources and References

  1. Personal Data Protection Act 2012(sso.agc.gov.sg).gov
  2. Personal Data Protection Act 2012, s 11 (designation of individuals responsible for compliance; liability not shifted)(sso.agc.gov.sg).gov
  3. Personal Data Protection Commission, getting started as a Data Protection Officer(pdpc.gov.sg).gov
  4. Personal Data Protection Act 2012, s 26D (duty to notify the Commission of a notifiable data breach)(sso.agc.gov.sg).gov
  5. Personal Data Protection (Notification of Data Breaches) Regulations 2021, reg 4 (500 affected individuals is a notifiable breach)(sso.agc.gov.sg).gov
  6. Personal Data Protection Act 2012, s 48J (financial penalties for a contravention)(sso.agc.gov.sg).gov
Share: