Law note · Singapore
Personal Data Protection Act, comprehensive consent-based regime
cite Act 26 of 2012 (Singapore), as amended by the Personal Data Protection (Amendment) Act 2020, Act 40 of 2020
stage IN FORCE in force since 2021-02-01
kind Comprehensive regime
binds private bodies
reviewed 2026-08-29
What it requires
- An app that collects, uses, or discloses the personal data of an individual in Singapore must obtain the individual's consent, or rely on a Part 3 or Schedule exception, and must state its purpose for the collection, use, or disclosure.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
What we found
PDPA applies a single consent-based framework to all personal data processing by organisations in Singapore: collection, use, or disclosure requires consent or a Part 3 or Schedule exception, and the Act does not distinguish controller from processor by name, instead regulating organisations directly with pass-through duties on data intermediaries.
There is no statutory sensitive-category or biometric-specific tier; every category of personal data, including a faceprint or voiceprint, is regulated under this one uniform standard.