Home/Singapore/Digital Privacy PdPA Cyber Safety Laws Guide
Digital Privacy

Singapore Digital Privacy (PDPA) & Cyber Safety Guide 2026

Complete guide to digital privacy under the Personal Data Protection Act (PDPA) & Computer Misuse Act. Explains DNC registry, data breaches, & cyber safety.

Overview & Statutory Background

Digital privacy and online security in Singapore are enforced through the Personal Data Protection Act (PDPA 2012), administered by the Personal Data Protection Commission (PDPC), and the Computer Misuse Act (CMA). The PDPA establishes data protection obligations governing the collection, use, disclosure, and security of personal data by organizations. It enforces the Do Not Call (DNC) Registry, prohibiting unsolicited telemarketing messages. Under the 2020 PDPA amendments, mandatory data breach notification is required, and financial penalties for data breaches can reach up to 10% of an organization's annual turnover in Singapore or S$1 Million. Use this guide to understand Singapore privacy laws.

Key Pass Highlights & Statutory Criteria

Privacy Statute
PDPA 2012 (Cap. 26)
Verified
Regulatory Body
PDPC (Data Protection Commission)
Verified
Max Breach Fine
10% Turnover or S$1M Fine
Verified
Telemarketing Registry
Do Not Call (DNC) Registry
Verified

Evaluation Criteria & Points Breakdown

PDPA Data Protection Principles & Consent

Consent & Notification

Organisations generally need consent or another permitted statutory basis (such as deemed consent or legitimate interests) under the PDPA to collect, use, or disclose personal data.

Mandatory Data Breach Notification to PDPC

Breach Notification

Notifiable data breaches that cause significant harm or affect 500+ individuals must be notified to PDPC as soon as practicable and no later than 3 calendar days.

Maximum Financial Penalties for Data Breaches

Max Penalty Cap

Financial penalty up to 10% of annual turnover in Singapore for organizations with annual local turnover exceeding S$10 million, or S$1 million, whichever is higher.

Computer Misuse Act (CMA) Offence Provisions

CMA Cybercrime Laws

CMA criminalizes unauthorized access (hacking), modification, interception, or misuse of computer systems and data in Singapore.

Mandatory Eligibility Requirements

Applies to all private sector organizations operating or handling personal data in Singapore.
Individuals can register their Singapore mobile numbers on the DNC Registry free of charge.
Organizations must appoint a Data Protection Officer (DPO) and publish DPO contact details.
Individuals have the statutory right to access and correct their personal data.

Step-by-Step Application & Issuance Process

1

DNC Registry Mobile Number Registration

Individual registers phone number on official DNC registry (dnc.gov.sg) via Singpass.

2

Submitting Data Access or Correction Request

Submit written request to organization's Data Protection Officer (DPO) for personal data records.

3

Filing Complaint with PDPC for Privacy Violation

File online complaint with PDPC for spam messages, unauthorized data disclosure, or breach.

4

PDPC Investigation & Enforcement Order

PDPC investigates, issues remediation directions, and levies financial penalties on offending company.

5

Police Cybercrime Report under Computer Misuse Act

Report unauthorized account hacking, malware, or online scam to Singapore Police Force Cybercrime Command.

Required Document Checklist

Personal Data Protection Act 2012 (Cap. 26A)
Computer Misuse Act (Cap. 50A)
PDPC Mandatory Data Breach Notification Form
Do Not Call (DNC) Registry Check Portal Logs
Cybersecurity Act 2018 Critical Information Infrastructure Rules

Frequently Asked Questions (FAQ)

The Personal Data Protection Act (PDPA 2012) is Singapore's primary data privacy law governing the collection, use, disclosure, and protection of personal data by organizations, enforced by the PDPC.

The DNC Registry allows individuals to block unsolicited telemarketing calls, SMS messages, and faxes to their Singapore telephone numbers.

Under the PDPA, financial penalties for data breaches can reach up to S$1 Million or 10% of an organization's annual turnover in Singapore.

You should contact the organization's Data Protection Officer (DPO) and file a complaint with the Personal Data Protection Commission (PDPC).

Yes. Under PDPA amendments, organizations must notify PDPC within 72 hours and inform affected individuals if the breach poses significant harm.

Unauthorized computer access carries fines up to S$5,000 and up to 2 years imprisonment for a first offense.

Statutory Benchmark Metrics

Privacy Statute
PDPA 2012 (Cap. 26)
Regulatory Body
PDPC (Data Protection Commission)
Max Breach Fine
10% Turnover or S$1M Fine
Telemarketing Registry
Do Not Call (DNC) Registry
⭐ Low-Fee Money Transfer Real Exchange Rate
Wise Global Expat Money Transfer

Send money across 50+ currencies with real mid-market exchange rates and zero hidden bank markup fees.

Transfer Money with Wise
🛡️ Guaranteed Mid-Market Rate
⭐ MOM & ICA VERIFIED🔒 256-Bit Encrypted

MOM & ICA Document Security

Safeguard Employment Pass submissions, PR applications, passport scans, and COMPASS salary verifications directly on official portals.

Access Official MOM Portal
✔ Official Government Portal Verification