PDPA ComplianceConsulting
Singapore's Personal Data Protection Act (PDPA) establishes a comprehensive framework for data protection. Crestpoint Strategic helps organizations navigate PDPA requirements with practical, implementation-focused consulting, from compliance assessments and consent management to breach notification and ongoing advisory.
We build the systems and processes for real PDPA compliance, not just documentation exercises.
What Is the PDPA?
The Personal Data Protection Act (PDPA) is Singapore's comprehensive data protection law enacted in 2012 and enforced from July 2, 2014. It establishes a baseline standard of protection for personal data in Singapore while recognizing the legitimate need for organizations to collect, use, and disclose personal data.
The PDPA is administered and enforced by the Personal Data Protection Commission (PDPC), which has the power to investigate complaints, conduct audits, issue directions, and impose financial penalties. The Act underwent significant amendments in 2020, introducing mandatory data breach notification, enhanced consent frameworks, and increased penalties.
The PDPA is built on nine main obligations: consent, purpose limitation, notification, access, correction, accuracy, protection, retention limitation, and transfer limitation. The 2020 amendments added a tenth obligation for data breach notification. Organizations must also comply with the Do Not Call (DNC) Registry provisions when conducting marketing activities.
PDPA Data Protection Obligations
The PDPA establishes nine main obligations (plus data breach notification) that govern how organizations handle personal data.
Consent Obligation
Organizations must obtain valid consent before collecting, using, or disclosing personal data, unless an exception applies under the PDPA.
Purpose Limitation Obligation
Personal data can only be collected, used, or disclosed for purposes that a reasonable person would consider appropriate and that have been notified to the individual.
Notification Obligation
Organizations must inform individuals of the purposes for which their personal data will be collected, used, or disclosed at or before the time of collection.
Access & Correction Obligation
Upon request, organizations must provide individuals access to their personal data and information about how it has been used or disclosed, and correct any errors.
Accuracy Obligation
Organizations must make reasonable efforts to ensure that personal data collected is accurate and complete, particularly if used to make decisions affecting the individual.
Protection Obligation
Organizations must implement reasonable security arrangements to protect personal data from unauthorized access, collection, use, disclosure, copying, modification, or disposal.
Retention Limitation Obligation
Organizations must cease retaining personal data, or remove the means by which it can be associated with individuals, when no longer necessary for legal or business purposes.
Transfer Limitation Obligation
Personal data can only be transferred outside Singapore if the recipient country provides comparable protection or if prescribed safeguards are implemented.
Data Breach Notification Obligation
Organizations must assess data breaches and notify PDPC and affected individuals if the breach is likely to result in significant harm or is of significant scale.
Our PDPA Compliance Services
End-to-end consulting to achieve and maintain compliance with Singapore's Personal Data Protection Act.
PDPA Compliance Assessment
Comprehensive gap analysis of your data protection practices against Singapore PDPA requirements, covering consent, purpose limitation, notification, access, correction, and data protection policies.
Consent Management Framework
Design and implementation of consent collection mechanisms compliant with PDPA's consent obligation, including deemed consent, express consent, and withdrawal of consent procedures.
Data Protection Policy Development
Creation of organization-wide data protection policies addressing collection, use, disclosure, and care of personal data in accordance with the nine main obligations under PDPA.
Data Protection Impact Assessment
Structured risk assessments for high-risk data processing activities, identifying potential privacy risks and implementing appropriate safeguards before processing begins.
Access & Correction Request Handling
Systems and workflows to handle data subject access and correction requests within the 30-day timeline mandated by PDPA, including fee structures and exception handling.
Cross-Border Transfer Compliance
Implementation of lawful overseas transfer mechanisms including contractual arrangements, binding corporate rules, and assessments ensuring recipient jurisdictions provide comparable protection.
Data Breach Management
Design of breach notification frameworks aligned with the 2020 PDPA amendments, including assessment criteria for notifiable breaches and communication protocols for PDPC and affected individuals.
DPO Appointment & Advisory
Data Protection Officer designation support, DPO training programs, and ongoing advisory services to maintain PDPA compliance and prepare for PDPC audits or investigations.
PDPA Penalties & Enforcement
Up to SGD 1 Million
Maximum financial penalty for organizations with annual turnover under SGD 10 million in Singapore.
Up to 10% of Annual Turnover
For organizations with annual turnover exceeding SGD 10 million, penalties can reach 10% of Singapore turnover.
The PDPC has issued significant penalties to organizations across sectors including telecommunications, healthcare, and financial services. Enforcement actions are published on the PDPC website.
Why Choose Crestpoint Strategic for PDPA Compliance
Practitioner-led consulting with hands-on experience building privacy-first data architectures
Deep expertise in consent management, cross-border transfers, and privacy engineering
Practical focus on implementable solutions, not just policy documentation
Experience across industries including financial services, healthcare, e-commerce, and technology
Understanding of PDPA's intersection with GDPR, CCPA, and other global privacy frameworks
Frequently Asked Questions
Common questions about Singapore's Personal Data Protection Act.
What is the PDPA?
The Personal Data Protection Act (PDPA) is Singapore's comprehensive data protection law enacted in 2012 and enforced from July 2, 2014. It governs the collection, use, disclosure, and care of personal data by organizations in Singapore. The PDPA establishes a baseline standard of protection for personal data while recognizing the need for organizations to collect, use, and disclose personal data for legitimate purposes.
Who does the PDPA apply to?
The PDPA applies to all private sector organizations in Singapore that collect, use, or disclose personal data, regardless of size. This includes companies, partnerships, sole proprietorships, and unincorporated associations. Public agencies are governed by separate regulations. The PDPA also has extraterritorial effect for organizations outside Singapore that collect, use, or disclose personal data in Singapore.
What are the penalties for PDPA non-compliance?
Under the 2020 amendments, the Personal Data Protection Commission (PDPC) can impose financial penalties of up to SGD 1 million or 10% of annual turnover in Singapore (whichever is higher) for organizations with annual turnover exceeding SGD 10 million. The PDPC can also issue directions to stop collection, require destruction of data, or mandate compliance measures.
What constitutes a notifiable data breach under PDPA?
A data breach is notifiable if it results in, or is likely to result in, significant harm to affected individuals, OR is of a significant scale (500 or more affected individuals). Organizations must notify PDPC within 3 calendar days of assessing that a breach is notifiable, and notify affected individuals as soon as practicable.
Is appointing a DPO mandatory under PDPA?
Yes. Since 2016, all organizations subject to the PDPA must designate at least one individual as Data Protection Officer (DPO). The DPO is responsible for ensuring compliance with the PDPA, handling data protection queries and complaints, and serving as the main point of contact with the PDPC. The DPO's contact information must be made publicly available.
What is the Do Not Call (DNC) Registry?
The DNC Registry is a component of the PDPA that allows Singapore telephone numbers to be registered to opt out of receiving marketing messages and calls. Organizations must check the DNC Registry before sending marketing messages to Singapore telephone numbers. Violations can result in financial penalties of up to SGD 1 million.