Key Framework Criteria & Principles
PDPA Accountability and Data Protection
Core ObligationsOrganisations must comply with the PDPA's data-protection obligations, including accountability, notification, consent or other permitted grounds, protection, retention, transfer, access and correction.
Mandatory DPO Appointment
DPO RequiredEvery organisation subject to the PDPA must designate at least one individual as its Data Protection Officer and make the business contact information available to the public.
Mandatory Data Breach Notification
3 Calendar DaysA notifiable data breach must be notified to PDPC as soon as practicable and no later than 3 calendar days after the organisation determines that the breach is notifiable.
PDPA Enforcement Penalties
S$1M / 10% TurnoverFor organisations with annual turnover in Singapore exceeding S$10 million, the financial penalty ceiling for data-protection contraventions is up to S$1 million or 10% of annual turnover in Singapore, whichever is higher.
Step-by-Step Procedure
Identify the Applicable Framework
Determine whether the issue concerns PDPA data protection, DNC telemarketing, Computer Misuse Act offences, Cybersecurity Act requirements or multiple regimes.
For Organisations, Appoint a DPO
Designate at least one DPO and publish the required business contact information.
Implement Data Protection Controls
Maintain policies, notices, consent or other lawful processing mechanisms, access/correction processes, security controls, retention rules and cross-border transfer safeguards.
Assess Any Data Breach
Determine whether the breach is likely to cause significant harm or is of significant scale and therefore requires notification.
Notify PDPC and Individuals Where Required
If the breach is notifiable, notify PDPC as soon as practicable and no later than 3 calendar days after the determination, and notify affected individuals where required.
Handle Telemarketing Through DNC Rules
Check the relevant DNC registers before specified telemarketing messages unless a statutory exception or valid consent applies.
Escalate Suspected Cybercrime
Where there is suspected unauthorised access, hacking, malware or other criminal conduct, preserve evidence and report it to the Police where appropriate.
Core PDPA Obligations
Obligations
Data Protection Officer Requirement
Rule
Organisations must designate at least one individual as their Data Protection Officer.
Responsibilities
- Oversee the organisation's compliance with the PDPA.
- Develop and implement data-protection policies and processes.
- Handle data-access and correction requests.
- Handle data-protection queries and complaints.
- Assess and manage data-protection risks.
- Liaise with PDPC where necessary.
Public Contact
The organisation must make the DPO's business contact information available to the public.
Dedicated Role
The DPO does not have to be a full-time or dedicated employee solely performing data-protection duties. Organisations may structure the role according to their circumstances.
Data-Breach Notification
Assessment
When an organisation becomes aware of a data breach, it must assess whether the breach is notifiable under the PDPA.
Notifiable When
- The breach is likely to result in significant harm to affected individuals.
- The breach is of significant scale, including a threshold of at least 500 affected individuals.
Notification Deadline
Once the organisation determines that a breach is notifiable, it must notify PDPC as soon as practicable and in any case no later than 3 calendar days.
Individual Notification
Affected individuals must be notified as soon as practicable, at the same time as or after notifying PDPC, where the statutory requirement to notify them is triggered.
First Day
The three-day period starts on the day after the organisation determines that the breach is notifiable.
Incident Management
- Contain the breach and stop further unauthorised access or disclosure.
- Assess the type and volume of personal data affected.
- Determine whether significant harm or significant scale makes the breach notifiable.
- Document the investigation and mitigation steps.
- Notify PDPC within the statutory deadline where notification is required.
- Notify affected individuals where required and provide practical steps to mitigate harm.
- Address the security or process weakness that caused the incident.
Important
The 3-day deadline runs from the organisation's determination that the breach is notifiable, not simply from the moment the security incident first occurs.
PDPA Financial Penalties
Data Protection
For an intentional or negligent contravention of the Data Protection Provisions, PDPC may impose a financial penalty of up to S$1 million or 10% of the organisation's annual turnover in Singapore, whichever is higher, where the organisation's annual turnover in Singapore exceeds S$10 million.
Dnc
Different financial-penalty rules apply to DNC contraventions. For example, dictionary-attack and address-harvesting offences can attract higher percentage-based penalties for organisations above the relevant turnover threshold.
Not Automatic
These are statutory maximum penalties, not automatic fines imposed for every breach. PDPC considers factors such as harm, culpability and other circumstances when determining the actual enforcement outcome.
Individual Access and Correction Rights
Access
Subject to statutory exceptions, an individual can request access to personal data held or controlled by an organisation and information about how the organisation used or disclosed the data during the preceding year.
Correction
An individual can request correction of an error or omission in personal data, subject to the statutory exceptions and the organisation's obligations under the PDPA.
Exceptions
Access and correction rights are subject to exceptions under the PDPA, so organisations should assess each request rather than treating the rights as absolute.
Process
- Send the request to the organisation or its DPO/contact point.
- Provide sufficient information for the organisation to identify the requester and locate the relevant data.
- The organisation assesses the request against the PDPA and applicable exceptions.
- Where required, the organisation provides access or makes the correction and follows the applicable notification rules.
Singapore Do Not Call (DNC) Registry
Scope
The DNC provisions regulate specified telemarketing messages sent to Singapore telephone numbers.
Registers
- No Voice Call Register
- No Text Message Register
- No Fax Message Register
Consumer Registration
Individuals can register Singapore telephone numbers with the DNC Registry free of charge.
Organisation Rule
Organisations generally must check the relevant DNC Register before sending specified telemarketing messages to Singapore telephone numbers unless a statutory exception applies, including where clear and unambiguous consent has been obtained.
Exceptions
- Business-to-business marketing messages
- Market research and surveys
- Certain non-commercial public-agency messages
- Certain service, delivery, warranty, recall and safety/security messages
- Messages sent with clear and unambiguous consent in the prescribed form
Important
DNC protection does not mean every unwanted commercial or nuisance message is automatically covered. The statutory definition of a specified message and the exemptions must be checked.
Computer Misuse Act
Scope
The Computer Misuse Act is Singapore's criminal cyber-offence framework for conduct such as unauthorised access to computer material and other prohibited interference or misuse.
Examples
- Unauthorised access to computer material
- Unauthorised modification of computer material
- Unauthorised use or interception of computer services or access credentials
- Other offences created under the Act and related amendments
Penalties
Penalties depend on the specific Computer Misuse Act offence, the circumstances and any aggravating factors. The exact statutory punishment should therefore be checked against the section covering the offence instead of publishing one generic 'hacking fine'.
Civil Vs Criminal
The Computer Misuse Act is primarily a criminal statute. PDPA obligations, contractual remedies, civil claims and sector-specific cybersecurity requirements are separate legal frameworks.
Cybersecurity Act and Critical Information Infrastructure
Scope
The Cybersecurity Act 2018 establishes a regulatory framework for cybersecurity and Critical Information Infrastructure (CII) in Singapore.
Cii
Its core obligations apply to designated CII owners and other entities within the statutory scope. It should not be presented as a universal cybersecurity compliance checklist applying identically to every ordinary consumer-facing business.
Data Privacy Distinction
The Cybersecurity Act and PDPA serve different purposes. PDPA primarily governs personal-data protection, while the Cybersecurity Act addresses cyber-resilience and regulated critical information infrastructure.
What to Do if Your Personal Data Is Exposed
Steps
Contact the Organisation
Step 1Ask the organisation or its DPO what personal data was affected, what happened and what protective measures are being taken.
Protect Accounts and Credentials
Step 2Change affected passwords, enable multi-factor authentication and monitor financial or online accounts where appropriate.
Keep Evidence
Step 3Retain breach notices, emails, messages, screenshots and communications with the organisation.
Consider a PDPC Complaint
Step 4Where you believe an organisation has breached its PDPA obligations, you can submit a complaint or seek PDPC assistance through its available channels.
Report Criminal Conduct Separately
Step 5Where the incident involves hacking, unauthorised access, malware or other suspected criminal conduct, consider making a report to the Singapore Police Force.
Required Document Checklist
Common Mistakes & Legal Misconceptions
Frequently Asked Questions (FAQ)
Official Government Sources & Statutory Verification
Wise Global Expat Money Transfer
Sending funds for tuition, rent, or immigration fees? Retail banks sneak 2.5%–4% into exchange rates. Check today's real mid-market rate first.