Law note · Singapore

Personal Data Protection Act, comprehensive consent-based regime

cite Act 26 of 2012 (Singapore), as amended by the Personal Data Protection (Amendment) Act 2020, Act 40 of 2020 stage IN FORCE in force since 2021-02-01 kind Comprehensive regime binds private bodies reviewed 2026-08-29

What it requires

  • An app that collects, uses, or discloses the personal data of an individual in Singapore must obtain the individual's consent, or rely on a Part 3 or Schedule exception, and must state its purpose for the collection, use, or disclosure.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics

What we found

PDPA applies a single consent-based framework to all personal data processing by organisations in Singapore: collection, use, or disclosure requires consent or a Part 3 or Schedule exception, and the Act does not distinguish controller from processor by name, instead regulating organisations directly with pass-through duties on data intermediaries.

There is no statutory sensitive-category or biometric-specific tier; every category of personal data, including a faceprint or voiceprint, is regulated under this one uniform standard.

← Back to the example  ·  Lint your app →