Law note · Singapore
Personal Data Protection Act, cross-border transfer
cite Personal Data Protection Act 2012, s.26
stage IN FORCE in force since 2014-07-02
kind Cross border transfer
binds private bodies
reviewed 2026-08-30
What it requires
- An app transferring the personal data of an individual in Singapore, including a faceprint, voiceprint, or other biometric identifier, to a recipient outside Singapore must ensure the recipient provides a standard of protection comparable to the PDPA, through a PDPC-prescribed mechanism, unless the PDPC has granted an exemption.
When LexLint raises it
crawls_webtrains_modelsprocesses_voiceprocesses_biometrics
What we found
Section 26(1) bars an organisation from transferring personal data to a country or territory outside Singapore except in accordance with requirements ensuring a standard of protection comparable to the PDPA; the PDPC may grant exemptions on application under s.26(2) and (3). This is a comparability-based mechanism, not a flat prohibition or a data-localization mandate; the specific instruments accepted as satisfying comparable protection sit in PDPA Regulations not read this pass.
Section 26 sits in the original 2012 Act's Part 6 (Care of Personal Data), which the Act's own consolidated text records as having commenced 2 July 2014 alongside the rest of Parts 3 to 7.