Law note · Singapore

Personal Data Protection Act, cross-border transfer

cite Personal Data Protection Act 2012, s.26 stage IN FORCE in force since 2014-07-02 kind Cross border transfer binds private bodies reviewed 2026-08-30

What it requires

  • An app transferring the personal data of an individual in Singapore, including a faceprint, voiceprint, or other biometric identifier, to a recipient outside Singapore must ensure the recipient provides a standard of protection comparable to the PDPA, through a PDPC-prescribed mechanism, unless the PDPC has granted an exemption.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_voice
  • processes_biometrics

What we found

Section 26(1) bars an organisation from transferring personal data to a country or territory outside Singapore except in accordance with requirements ensuring a standard of protection comparable to the PDPA; the PDPC may grant exemptions on application under s.26(2) and (3). This is a comparability-based mechanism, not a flat prohibition or a data-localization mandate; the specific instruments accepted as satisfying comparable protection sit in PDPA Regulations not read this pass.

Section 26 sits in the original 2012 Act's Part 6 (Care of Personal Data), which the Act's own consolidated text records as having commenced 2 July 2014 alongside the rest of Parts 3 to 7.

← Back to the example  ·  Lint your app →