Skip to content

Singapore PDPA

In force Singapore · In force Jul 2, 2014 · no upcoming deadlines

Deadlines

DateWhat happens
Jul 2, 2014PDPA data protection obligations take effect12.2 years ago
Feb 1, 20212020 amendments largely in force5.6 years ago
Oct 1, 2022Higher financial penalty cap applies4 years ago

Summaries for reference, not legal advice. Check the official text.

What it does

Singapore's baseline private-sector data protection law covering consent, purpose limitation, notification, access and correction, protection, retention, transfer limitation, and the Do Not Call registry. The 2020 amendments added mandatory breach notification, expanded deemed consent and legitimate-interests exceptions, and raised fines.

Who it applies to
All private-sector organizations collecting, using or disclosing personal data in Singapore (public agencies excluded). Breach notification: notify PDPC within 3 calendar days of assessing a breach as notifiable (significant harm, or affecting 500+ individuals).
Penalties
Financial penalties up to 10% of annual Singapore turnover for organizations with turnover above SGD 10 million, otherwise up to SGD 1 million (since 1 Oct 2022). Criminal offences for individuals who mishandle personal data.
Enforced by
Personal Data Protection Commission (PDPC)
Official name
Personal Data Protection Act 2012 (Singapore)
Citation
Act 26 of 2012; amended by Personal Data Protection (Amendment) Act 2020
Topics
privacy, breach-notification
Verified 2026-09-22 sso.agc.gov.sg
Research notes

Dates and thresholds come from established knowledge; the PDPC overview page did not list them and sso.agc.gov.sg blocked automated fetch. The data portability obligation has been legislated but not yet brought into force. No 2025-2026 PDPA amendment was found.

Related

Questions about Singapore PDPA
What are the Singapore PDPA compliance deadlines?
Jul 2, 2014: PDPA data protection obligations take effect. Feb 1, 2021: 2020 amendments largely in force. Oct 1, 2022: Higher financial penalty cap applies.
When does Singapore PDPA take effect?
Singapore PDPA took effect on Jul 2, 2014.
Who does Singapore PDPA apply to?
All private-sector organizations collecting, using or disclosing personal data in Singapore (public agencies excluded). Breach notification: notify PDPC within 3 calendar days of assessing a breach as notifiable (significant harm, or affecting 500+ individuals).
What are the penalties under Singapore PDPA?
Financial penalties up to 10% of annual Singapore turnover for organizations with turnover above SGD 10 million, otherwise up to SGD 1 million (since 1 Oct 2022). Criminal offences for individuals who mishandle personal data.

When the rules change: new data, privacy and AI laws and deadlines, the next morning.