Home/Singapore/Digital Privacy PdPA Cyber Safety Laws Guide
Digital Privacy

Singapore Digital Privacy (PDPA) & Cyber Safety Guide 2026

2026 Singapore guide to PDPA privacy, DNC rules, data-breach notification, DPO duties, individual access rights and Computer Misuse Act cyber offences.

Key Framework Criteria & Principles

PDPA Accountability and Data Protection

Core Obligations

Organisations must comply with the PDPA's data-protection obligations, including accountability, notification, consent or other permitted grounds, protection, retention, transfer, access and correction.

Mandatory DPO Appointment

DPO Required

Every organisation subject to the PDPA must designate at least one individual as its Data Protection Officer and make the business contact information available to the public.

Mandatory Data Breach Notification

3 Calendar Days

A notifiable data breach must be notified to PDPC as soon as practicable and no later than 3 calendar days after the organisation determines that the breach is notifiable.

PDPA Enforcement Penalties

S$1M / 10% Turnover

For organisations with annual turnover in Singapore exceeding S$10 million, the financial penalty ceiling for data-protection contraventions is up to S$1 million or 10% of annual turnover in Singapore, whichever is higher.

Step-by-Step Procedure

1

Identify the Applicable Framework

Determine whether the issue concerns PDPA data protection, DNC telemarketing, Computer Misuse Act offences, Cybersecurity Act requirements or multiple regimes.

2

For Organisations, Appoint a DPO

Designate at least one DPO and publish the required business contact information.

3

Implement Data Protection Controls

Maintain policies, notices, consent or other lawful processing mechanisms, access/correction processes, security controls, retention rules and cross-border transfer safeguards.

4

Assess Any Data Breach

Determine whether the breach is likely to cause significant harm or is of significant scale and therefore requires notification.

5

Notify PDPC and Individuals Where Required

If the breach is notifiable, notify PDPC as soon as practicable and no later than 3 calendar days after the determination, and notify affected individuals where required.

6

Handle Telemarketing Through DNC Rules

Check the relevant DNC registers before specified telemarketing messages unless a statutory exception or valid consent applies.

7

Escalate Suspected Cybercrime

Where there is suspected unauthorised access, hacking, malware or other criminal conduct, preserve evidence and report it to the Police where appropriate.

Core PDPA Obligations

Obligations

Obligation: Accountability
Description: Put in place policies and practices necessary to meet PDPA obligations, appoint a DPO and make relevant data-protection information available.
Obligation: Notification
Description: Notify individuals of the purposes for which personal data is intended to be collected, used or disclosed.
Obligation: Consent
Description: Generally obtain consent or rely on another legally permitted basis before collecting, using or disclosing personal data, subject to the statutory exceptions and deemed-consent frameworks.
Obligation: Purpose Limitation
Description: Collect, use or disclose personal data only for purposes a reasonable person would consider appropriate in the circumstances and in accordance with the PDPA.
Obligation: Accuracy
Description: Make reasonable efforts to ensure personal data is accurate and complete where accuracy is likely to affect a decision about the individual or be disclosed to another organisation.
Obligation: Protection
Description: Make reasonable security arrangements to protect personal data against unauthorised access, collection, use, disclosure, copying, modification or disposal.
Obligation: Retention
Description: Stop retaining personal data or remove it when retention is no longer necessary for a business or legal purpose.
Obligation: Transfer Limitation
Description: Do not transfer personal data outside Singapore unless the transfer complies with the statutory transfer-limitation requirements.
Obligation: Access and Correction
Description: Provide access to personal data and relevant use/disclosure information and correct errors or omissions where the statutory requirements are met, subject to exceptions.

Data Protection Officer Requirement

Rule

Organisations must designate at least one individual as their Data Protection Officer.

Responsibilities

  • Oversee the organisation's compliance with the PDPA.
  • Develop and implement data-protection policies and processes.
  • Handle data-access and correction requests.
  • Handle data-protection queries and complaints.
  • Assess and manage data-protection risks.
  • Liaise with PDPC where necessary.

Public Contact

The organisation must make the DPO's business contact information available to the public.

Dedicated Role

The DPO does not have to be a full-time or dedicated employee solely performing data-protection duties. Organisations may structure the role according to their circumstances.

Data-Breach Notification

Assessment

When an organisation becomes aware of a data breach, it must assess whether the breach is notifiable under the PDPA.

Notifiable When

  • The breach is likely to result in significant harm to affected individuals.
  • The breach is of significant scale, including a threshold of at least 500 affected individuals.

Notification Deadline

Once the organisation determines that a breach is notifiable, it must notify PDPC as soon as practicable and in any case no later than 3 calendar days.

Individual Notification

Affected individuals must be notified as soon as practicable, at the same time as or after notifying PDPC, where the statutory requirement to notify them is triggered.

First Day

The three-day period starts on the day after the organisation determines that the breach is notifiable.

Incident Management

  • Contain the breach and stop further unauthorised access or disclosure.
  • Assess the type and volume of personal data affected.
  • Determine whether significant harm or significant scale makes the breach notifiable.
  • Document the investigation and mitigation steps.
  • Notify PDPC within the statutory deadline where notification is required.
  • Notify affected individuals where required and provide practical steps to mitigate harm.
  • Address the security or process weakness that caused the incident.

Important

The 3-day deadline runs from the organisation's determination that the breach is notifiable, not simply from the moment the security incident first occurs.

PDPA Financial Penalties

Data Protection

For an intentional or negligent contravention of the Data Protection Provisions, PDPC may impose a financial penalty of up to S$1 million or 10% of the organisation's annual turnover in Singapore, whichever is higher, where the organisation's annual turnover in Singapore exceeds S$10 million.

Dnc

Different financial-penalty rules apply to DNC contraventions. For example, dictionary-attack and address-harvesting offences can attract higher percentage-based penalties for organisations above the relevant turnover threshold.

Not Automatic

These are statutory maximum penalties, not automatic fines imposed for every breach. PDPC considers factors such as harm, culpability and other circumstances when determining the actual enforcement outcome.

Individual Access and Correction Rights

Access

Subject to statutory exceptions, an individual can request access to personal data held or controlled by an organisation and information about how the organisation used or disclosed the data during the preceding year.

Correction

An individual can request correction of an error or omission in personal data, subject to the statutory exceptions and the organisation's obligations under the PDPA.

Exceptions

Access and correction rights are subject to exceptions under the PDPA, so organisations should assess each request rather than treating the rights as absolute.

Process

  • Send the request to the organisation or its DPO/contact point.
  • Provide sufficient information for the organisation to identify the requester and locate the relevant data.
  • The organisation assesses the request against the PDPA and applicable exceptions.
  • Where required, the organisation provides access or makes the correction and follows the applicable notification rules.

Singapore Do Not Call (DNC) Registry

Scope

The DNC provisions regulate specified telemarketing messages sent to Singapore telephone numbers.

Registers

  • No Voice Call Register
  • No Text Message Register
  • No Fax Message Register

Consumer Registration

Individuals can register Singapore telephone numbers with the DNC Registry free of charge.

Organisation Rule

Organisations generally must check the relevant DNC Register before sending specified telemarketing messages to Singapore telephone numbers unless a statutory exception applies, including where clear and unambiguous consent has been obtained.

Exceptions

  • Business-to-business marketing messages
  • Market research and surveys
  • Certain non-commercial public-agency messages
  • Certain service, delivery, warranty, recall and safety/security messages
  • Messages sent with clear and unambiguous consent in the prescribed form

Important

DNC protection does not mean every unwanted commercial or nuisance message is automatically covered. The statutory definition of a specified message and the exemptions must be checked.

Computer Misuse Act

Scope

The Computer Misuse Act is Singapore's criminal cyber-offence framework for conduct such as unauthorised access to computer material and other prohibited interference or misuse.

Examples

  • Unauthorised access to computer material
  • Unauthorised modification of computer material
  • Unauthorised use or interception of computer services or access credentials
  • Other offences created under the Act and related amendments

Penalties

Penalties depend on the specific Computer Misuse Act offence, the circumstances and any aggravating factors. The exact statutory punishment should therefore be checked against the section covering the offence instead of publishing one generic 'hacking fine'.

Civil Vs Criminal

The Computer Misuse Act is primarily a criminal statute. PDPA obligations, contractual remedies, civil claims and sector-specific cybersecurity requirements are separate legal frameworks.

Cybersecurity Act and Critical Information Infrastructure

Scope

The Cybersecurity Act 2018 establishes a regulatory framework for cybersecurity and Critical Information Infrastructure (CII) in Singapore.

Cii

Its core obligations apply to designated CII owners and other entities within the statutory scope. It should not be presented as a universal cybersecurity compliance checklist applying identically to every ordinary consumer-facing business.

Data Privacy Distinction

The Cybersecurity Act and PDPA serve different purposes. PDPA primarily governs personal-data protection, while the Cybersecurity Act addresses cyber-resilience and regulated critical information infrastructure.

What to Do if Your Personal Data Is Exposed

Steps

Contact the Organisation
Step 1

Ask the organisation or its DPO what personal data was affected, what happened and what protective measures are being taken.

Protect Accounts and Credentials
Step 2

Change affected passwords, enable multi-factor authentication and monitor financial or online accounts where appropriate.

Keep Evidence
Step 3

Retain breach notices, emails, messages, screenshots and communications with the organisation.

Consider a PDPC Complaint
Step 4

Where you believe an organisation has breached its PDPA obligations, you can submit a complaint or seek PDPC assistance through its available channels.

Report Criminal Conduct Separately
Step 5

Where the incident involves hacking, unauthorised access, malware or other suspected criminal conduct, consider making a report to the Singapore Police Force.

Required Document Checklist

•
PDPA 2012 and applicable regulations
•
DPO appointment and published contact information
•
Data protection policies and internal procedures
•
Privacy or data-protection notices
•
Consent records or documentation supporting another lawful processing basis
•
Data-breach investigation and notification records
•
DNC Registry checking records for telemarketing campaigns
•
Cybersecurity incident records where applicable

Common Mistakes & Legal Misconceptions

❌ Misconception: Saying the PDPA requires consent for every collection, use or disclosure of personal data.
✅ Statutory Fact: Consent is a principal basis, but the PDPA also contains deemed-consent frameworks and other permitted grounds or exceptions.
❌ Misconception: Saying every breach affecting 500 people must automatically be reported within 72 hours of the attack.
✅ Statutory Fact: The significant-scale threshold is 500 affected individuals, but the 3-calendar-day period begins after the organisation determines that the breach is notifiable.
❌ Misconception: Saying PDPC always imposes a S$1 million or 10% fine.
✅ Statutory Fact: That is a statutory maximum for relevant data-protection contraventions, subject to the S$10 million Singapore-turnover condition and PDPC's assessment of the case.
❌ Misconception: Saying DNC blocks every form of marketing.
✅ Statutory Fact: DNC applies to specified telemarketing messages and contains important exclusions, including B2B marketing and certain service-related messages.
❌ Misconception: Saying the PDPA gives individuals an unconditional right to all information held by an organisation.
✅ Statutory Fact: Access and correction rights are subject to statutory exceptions and procedural requirements.
❌ Misconception: Using one generic fine for Computer Misuse Act hacking offences.
✅ Statutory Fact: Penalties differ by offence and circumstances, so the relevant statutory provision should be cited for a specific offence.
❌ Misconception: Treating the Cybersecurity Act as a universal cybersecurity law for every company.
✅ Statutory Fact: Its core regulatory obligations focus on CII and other entities within its statutory scope.

Frequently Asked Questions (FAQ)

The PDPA creates a framework of obligations covering accountability, notification, consent or other permitted processing grounds, purpose limitation, accuracy, protection, retention, overseas transfers, access and correction, and data-breach notification. Organisations must also designate at least one Data Protection Officer and make the relevant business contact information available publicly.

A breach is notifiable when it is likely to result in significant harm to affected individuals or is of significant scale, including at least 500 affected individuals. Once the organisation determines that the breach is notifiable, it must notify PDPC as soon as practicable and no later than 3 calendar days.

For relevant data-protection contraventions, PDPC can impose a financial penalty of up to S$1 million or 10% of the organisation's annual turnover in Singapore, whichever is higher, where annual Singapore turnover exceeds S$10 million. The statutory ceiling is not an automatic fine; PDPC assesses the circumstances of each case.

Individuals can register Singapore telephone numbers with the DNC Registry free of charge to opt out of specified telemarketing calls, texts or faxes. Organisations generally have to check the relevant DNC register before sending specified telemarketing messages unless a statutory exception or clear and unambiguous consent applies.

Yes, subject to statutory exceptions. An individual can generally request access to personal data held or controlled by an organisation and information about how it was used or disclosed during the preceding year, and can request correction of inaccurate or incomplete personal data.

The PDPA primarily governs personal-data protection and organisational data-protection duties. The Computer Misuse Act criminalises unauthorised access and other specified computer-related conduct. The Cybersecurity Act establishes a regulatory framework focused particularly on cybersecurity and Critical Information Infrastructure and other entities within its statutory scope.
Live Expat FX Tool 0% Hidden Spread
Wise Global Expat Money Transfer

Sending funds for tuition, rent, or immigration fees? Retail banks sneak 2.5%–4% into exchange rates. Check today's real mid-market rate first.

High-Street Banks:~3.5% Hidden Markup
Wise Mid-Market:Zero Markup (Google Rate)
Compare Live Exchange Rate
⚡ Free live comparison • 50+ currencies supported

Statutory Benchmark Metrics

Primary privacy law
PDPA 2012
Privacy regulator
PDPC
DPO
Mandatory for organisations
Breach notification
Within 3 calendar days after determination
High-turnover penalty ceiling
S$1M or 10% Singapore turnover, whichever higher
Telemarketing
DNC Registry rules apply to specified messages

Official Emergency & Legal Support

Emergency Police Hotline
Dial 999
24/7 Singapore Police Force
Anti-Scam Helpline
Dial 1799
ScamShield & Banking Fraud
National Family Violence Helpline
1800-221-4444
24/7 PPO & Protection Specialist
Employment Claims (TADM)
+65 6883 5885
MOM Workplace Disputes