Law / Singapore

Singapore

privacy

Singapore's comprehensive private-sector data-protection law is the Personal Data Protection Act 2012 (No. 26 of 2012, PDPA), as substantially amended by the Personal Data Protection (Amendment) Act 2020 (Act 40 of 2020), with most provisions in force 1 February 2021 and the financial-penalty regime commencing later, 1 October 2022.

PDPA uses a single consent-based framework applied uniformly to all personal data; it has no statutory sensitive-category or biometric-specific provision, a direct full-text search for biometric returning zero hits, so a voiceprint or faceprint is regulated exactly like any other personal data, correcting the derivation seed's sensitive_biometric_restriction from true to false.

Cross-border transfer requires a standard of protection comparable to the Act under s.26, and s.48O arms a private plaintiff for a contravention of the Consent, Access and Correction, Care of Personal Data, Notification of Data Breaches, or Data Portability provisions, alongside PDPC financial penalties of up to 10 percent of Singapore annual turnover.

The exact scope of the Act's publicly-available-data consent exception is an open item: Section 2 defines the term publicly available, which strongly suggests a Schedule exception uses it to excuse consent, but the operative exception provision itself was not read this pass, so the derivation seed's publicly_available_exemption value is not carried into this document either way.

12 instruments named 5 researched in detail As of 2026-08-29

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

Personal Data Protection Act, data breach notification

cite Personal Data Protection Act 2012, Part 6A, ss.26A-26E, as added by Act 40 of 2020 stage IN FORCE in force since 2021-02-01 binds private bodies source official statute text, Singapore Statutes Online (SSO)
What it requires

Part 6A, added by the 2020 amendment, makes a data breach notifiable if it results in, or is likely to result in, significant harm to an affected individual, or is or is likely to be of significant scale; an internal-only breach is deemed not notifiable.

The organisation must notify the PDPC as soon as practicable, and in any case no later than 3 calendar days after assessing the breach is notifiable, and must also notify each affected individual, subject to exceptions where technological measures render significant harm unlikely or a law-enforcement agency or the PDPC directs otherwise.

Comprehensive regime

Personal Data Protection Act, comprehensive consent-based regime

cite Act 26 of 2012 (Singapore), as amended by the Personal Data Protection (Amendment) Act 2020, Act 40 of 2020 stage IN FORCE in force since 2021-02-01 binds private bodies source official statute text, Singapore Statutes Online (SSO)
What it requires

PDPA applies a single consent-based framework to all personal data processing by organisations in Singapore: collection, use, or disclosure requires consent or a Part 3 or Schedule exception, and the Act does not distinguish controller from processor by name, instead regulating organisations directly with pass-through duties on data intermediaries.

There is no statutory sensitive-category or biometric-specific tier; every category of personal data, including a faceprint or voiceprint, is regulated under this one uniform standard.

Cross border transfer

Personal Data Protection Act, cross-border transfer

cite Personal Data Protection Act 2012, s.26 stage IN FORCE in force since 2014-07-02 binds private bodies source official statute text, Singapore Statutes Online (SSO)
What it requires

Section 26(1) bars an organisation from transferring personal data to a country or territory outside Singapore except in accordance with requirements ensuring a standard of protection comparable to the PDPA; the PDPC may grant exemptions on application under s.26(2) and (3). This is a comparability-based mechanism, not a flat prohibition or a data-localization mandate; the specific instruments accepted as satisfying comparable protection sit in PDPA Regulations not read this pass.

Section 26 sits in the original 2012 Act's Part 6 (Care of Personal Data), which the Act's own consolidated text records as having commenced 2 July 2014 alongside the rest of Parts 3 to 7.

Data subject rights

Personal Data Protection Act, data subject rights

cite Personal Data Protection Act 2012, ss.21-22 stage IN FORCE in force since 2014-07-02 binds private bodies source official statute text, Singapore Statutes Online (SSO)
What it requires

Part 5 grants a data subject the statutory rights of access (s.21) and correction (s.22) of their personal data; the Act's own consolidated commencement note records Part 5 as having commenced 2 July 2014 with the rest of Parts 3 to 7.

A data portability right, headed Part 6B and added by the Personal Data Protection (Amendment) Act 2020, does not appear anywhere in the Act's own table of contents on Singapore Statutes Online, which lists every Part from Part 1 through Part 10 and goes directly from Part 6A to Part 7 with no Part 6B heading between them, so this document no longer asserts a Part 6B data portability right exists as a numbered Part of the Act.

This conflicts with a quoted extract elsewhere in this document (the enforcement instrument's s.48O(1) pin), which names Part 6B among the Parts whose contravention grounds a private right of action; that quote could not be independently re-verified against primary text this pass (the section body text was not reachable through the crawler's read of this URL, only the table of contents), so it is flagged here as needing re-verification rather than silently resolved either way. No distinct statutory deletion or erasure right was found in the table of contents structure surveyed.

Enforcement supervision

Personal Data Protection Act, enforcement and private right of action

cite Personal Data Protection Act 2012, ss.48J, 48O, as added by Act 40 of 2020 stage IN FORCE in force since 2022-10-01 binds private bodies source official statute text, Singapore Statutes Online (SSO)
What it requires

The Personal Data Protection Commission (PDPC) is Singapore's supervisory authority. Financial penalties under s.48J, added by the 2020 amendment and commencing 1 October 2022, reach up to 10 percent of Singapore annual turnover for an organisation with turnover exceeding S$10 million (otherwise up to S$1 million), and up to S$200,000 for an individual, or up to 5 percent of turnover exceeding S$20 million.

Section 48O(1), also added by the 2020 amendment, gives a person who suffers loss or damage directly from a contravention of the Consent Obligation (Part 4), Access and Correction (Part 5), Care of Personal Data (Part 6), Notification of Data Breaches (Part 6A), or Data Portability (Part 6B) provisions a right of action for relief in civil proceedings; its own specific commencement date within the 2020 amendment was not independently isolated this pass.

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.