How it works What We Check Pricing Articles About Free PDPA Scan →
Guide

Appointing and Publishing a DPO Under Singapore's PDPA

It costs nothing, takes about an hour, and on more than a third of the Singapore websites we scan we cannot find the contact at all. Two separate duties sit in section 11 — designating an individual, and publishing how to reach them.

By the Sitetals research team· Published 27 August 2026· Updated 27 August 2026· 10 min read· All articles

The short version

Of every obligation in the PDPA, this is among the cheapest to satisfy and among the most commonly unmet. It is also one of the few obligations whose outward signs anyone can check from a browser, with no special access at all: a customer, a complainant or a regulator can open your website and look.

This is compliance research, not legal advice. Sitetals is an independent scanner, not a law firm and not affiliated with the Personal Data Protection Commission.

Whether a specific obligation applies to your organisation is a question of fact and law. For a decision that carries risk, take advice from a Singapore-qualified practitioner.

What the law requires, in two parts

Section 11, PDPA 2012

“(3) An organisation must designate one or more individuals to be responsible for ensuring that the organisation complies with this Act.

(4) An individual designated under subsection (3) may delegate to another individual the responsibility conferred by that designation. (5) An organisation must make available to the public the business contact information of at least one of the individuals designated under subsection (3) or delegated under subsection (4). … (6) The designation of an individual by an organisation under subsection (3) does not relieve the organisation of any of its obligations under this Act.”

Designation (s.11(3)). You must designate one or more individuals to be responsible for ensuring that the organisation complies with the Act. An individual — a person, not a mailbox and not a department. Section 11(4) lets that person delegate the responsibility to someone else.

Publication (s.11(5)). You must make available to the public the business contact information of at least one of those designated or delegated individuals.

And the sting (s.11(6)). Designating someone does not relieve the organisation of any of its obligations under the Act. Appointing a DPO is not a transfer of risk.

Where the contact has to appear — the part most guidance omits

Section 11(5) says the business contact information must be made available to the public, without saying where. Regulation 1A of the Personal Data Protection Regulations 2021 fills that gap, and it is worth quoting because it is unusually specific.

Regulation 1A, Personal Data Protection Regulations 2021

An organisation is deemed to have satisfied section 11(5) if it makes available the business contact information of a designated individual “(a) where the organisation is registered under an applicable Act — in a record relating to the organisation that is made available on the Internet website of the Accounting and Corporate Regulatory Authority at https://www.bizfile.gov.sg; (b) in a readily accessible part of the organisation’s official website.”

Regulation 1A names two places, and publishing in either one is deemed to satisfy section 11(5):

“Readily accessible” is the operative phrase, and it is a practical standard rather than a technical one. A contact buried on an unlinked page is present but not readily accessible.

An honest caveat about our own figure

Because BizFile is an accepted route, an organisation whose designated individual is filed with ACRA can satisfy section 11(5) with nothing on its website at all.

Our scanner reads websites; it cannot read BizFile. So the 41.2% below means no data protection contact is discoverable on the website — not that those organisations are in breach.

It is still worth fixing: a customer with a question looks at your site, not at ACRA.

41.2%of 10,298 scanned SG sites publish no contact on the site
s.11(3)designate an individual — no size exemption
reg 1Awebsite or BizFile — those are the two routes
s.11(6)designation does not transfer liability

What the enforcement record actually shows

In Re Air Sino-Euro Associates Travel Pte. Ltd. [2025] SGPDPC 5 (Case DP-2312-C1857, 31 October 2025), the Commission found that the organisation had not designated any individual under section 11(3) until 15 April 2024 — after the incident that prompted the investigation. It also had no internal data protection policies. Those were Accountability findings, made alongside separate Protection findings that included a server running Windows Server 2012, no multi-factor authentication, and no contractual requirement for the IT vendor to conduct regular security reviews.

The financial penalty was S$47,000, imposed for the Accountability and Protection breaches together, on facts including unauthorised access to the personal data of 336,759 individuals, some of which the organisation accepted had been exfiltrated.

Read the causation carefully

This decision is frequently summarised as a fine for failing to appoint a DPO. It was not. The S$47,000 was imposed for the Accountability and Protection breaches together, on facts that included unauthorised access to a large volume of personal data and several technical failures.

The Accountability finding is significant because it stood on its own — not because it carried the penalty by itself.

The Commission treated the absence of a designated individual as a standalone contravention, established on the organisation's own records, requiring no technical forensics. Once an investigation is open for any reason, that finding is available immediately.

What the role actually involves in a small company

The role does involveThe role does not require
Knowing what personal data the organisation holds and whyA law degree or a certification
Owning the privacy policy and keeping it trueA full-time appointment
Receiving and routing access, correction and withdrawal requestsAn external hire — an existing employee can hold it
Being the contact point if the PDPC or an individual gets in touchTaking the organisation's obligations onto yourself — designation does not move them off the organisation (s.11(6))
Running the s.26C assessment if a breach is suspected, and the s.26D notification if it is notifiableSole responsibility — the duty can be delegated under s.11(4)
Making sure someone reviews security arrangements periodicallyDoing the security work personally

What the Commission looked for in Air Sino-Euro was not seniority. It was whether anyone had been made responsible at all.

Publishing the contact so it actually counts

Regulation 1A tells you where. It does not tell you what the entry should look like, and that is where most of the practical mistakes happen.

Use a role address, not a personal one

Publish something like dpo@yourdomain.com that reaches the designated individual. Make sure it is monitored — an address that bounces or is never read is worse than none, because it represents a contact route that does not exist.

Put it where someone looking for it would look

In practice that means the privacy policy and a footer or contact page. If your contact is reachable only three clicks deep from an unlabelled page, it is technically present and practically absent.

Label it for what it is

“Data Protection Officer”, “Data protection contact” or “PDPA enquiries” all read clearly. A general info@ address with no indication that it handles data protection matters does not tell the reader what they have found, and does not sit well beside the s.20(1)(c) expectation that a person able to answer questions about the collection can be reached.

A practical test

Open your own website in a private browser window and try to find your data protection contact in sixty seconds, without using site search.

Regulation 1A sets no time limit, and a clearly labelled section in a privacy policy linked from every page satisfies it.

But if you cannot find your own contact in a minute, neither will the customer, the complainant or the regulator who goes looking.

Do this today

  1. Name the individual15 min Decide who it is and tell them, in writing, that they are designated under section 11(3) of the PDPA. An email confirming the designation and its date is enough; the point is that a record exists showing when the designation was made. Air Sino-Euro's finding was about a date.
  2. Set up the address10 min Use a role address that reaches the designated individual — dpo@yourdomain.com if you want the label to be unmistakable, or an existing monitored address such as legal@, provided the published entry says what it is for.
  3. Publish it in two places20 min Add it to the privacy policy under a clearly labelled heading, and to the site footer or contact page.
  4. Write down what happens when mail arrives30 min One page: who reads the mailbox, how quickly, what an access or correction request triggers, and who is called if a breach is suspected. Section 12 requires organisations to develop and implement policies necessary to meet their obligations, and the absence of internal policies was a finding in Air Sino-Euro.
  5. Diarise the breach clock10 min If a breach is suspected, section 26C(2) requires a reasonable and expeditious assessment of whether it is notifiable, and section 26D(1) requires notifying the Commission as soon as is practicable, and in any case no later than 3 calendar days after the day you make that assessment. The three days are a backstop, not an allowance.
Check whether yours is findable

Sitetals looks for a data protection contact on your homepage, in your footer and in the legal pages linked from them — the same places a visitor or a complainant would look.

Run a free PDPA scan

Free scan. Full PDF report with the PDPA references and a fix list from S$68.

Common questions

Does a small company really need a DPO in Singapore?

Yes. Section 11(3) applies to every organisation subject to the PDPA, with no threshold for headcount or revenue. It can be an existing employee holding the responsibility alongside another role, and the responsibility can be delegated under section 11(4), but someone must be designated.

Can the DPO be an external consultant or the company director?

Yes to both. The Act requires an individual to be designated as responsible; it does not require them to be an employee or hold any particular seniority. What matters is that the person can actually discharge the responsibility and is reachable at the published contact.

Must the DPO be based in Singapore, or registered with the PDPC?

Neither. Section 11(3) requires an organisation to designate one or more individuals; it does not require them to be resident in Singapore, and the Act contains no requirement to register the designation with the Commission. What section 11(5) does require is that the business contact information is made available to the public.

Does appointing a DPO reduce my liability?

No. Section 11(6) states that designating an individual does not relieve the organisation of any of its obligations under the Act. The organisation remains responsible; the designation creates an internal owner, not a shield.

Where exactly must the DPO contact be published?

Regulation 1A of the Personal Data Protection Regulations 2021 names two routes: your ACRA record on BizFile, or a readily accessible part of your official website.

Can I publish a form instead of an email address?

A monitored, clearly labelled data protection contact form can work, but it is a weaker answer than a published address: it gives the sender no record of what they submitted, and it fails silently if the form breaks.

What if we designated someone years ago but never published it?

Then section 11(3) is satisfied and section 11(5) is not. Publishing the contact is a short task, and it converts a partially met obligation into a fully met one that is visible from outside.

Sources

Related reading

EnforcementWhat the 2025–2026 PDPC decisions mean for your websiteNotificationThe PDPA privacy policy checklistReportSingapore website PDPA health check 2026ConsentDo you need a cookie banner under the PDPA?ScopeDoes the PDPA reach a business with no Singapore office?
Sitetals research team. Sitetals is an independent website compliance scanner operated by QuikForge Limited. We check Singapore websites against the PDPA obligations that are visible from the outside, and publish what the aggregate results show. Every statutory reference in this article was checked against the consolidated Act on Singapore Statutes Online, and every enforcement figure against the published decision itself. Corrections: hello@sitetals.com.