It costs nothing, takes about an hour, and on more than a third of the Singapore websites we scan we cannot find the contact at all. Two separate duties sit in section 11 — designating an individual, and publishing how to reach them.
Of every obligation in the PDPA, this is among the cheapest to satisfy and among the most commonly unmet. It is also one of the few obligations whose outward signs anyone can check from a browser, with no special access at all: a customer, a complainant or a regulator can open your website and look.
This is compliance research, not legal advice. Sitetals is an independent scanner, not a law firm and not affiliated with the Personal Data Protection Commission.
Whether a specific obligation applies to your organisation is a question of fact and law. For a decision that carries risk, take advice from a Singapore-qualified practitioner.
“(3) An organisation must designate one or more individuals to be responsible for ensuring that the organisation complies with this Act.
(4) An individual designated under subsection (3) may delegate to another individual the responsibility conferred by that designation. (5) An organisation must make available to the public the business contact information of at least one of the individuals designated under subsection (3) or delegated under subsection (4). … (6) The designation of an individual by an organisation under subsection (3) does not relieve the organisation of any of its obligations under this Act.”
Designation (s.11(3)). You must designate one or more individuals to be responsible for ensuring that the organisation complies with the Act. An individual — a person, not a mailbox and not a department. Section 11(4) lets that person delegate the responsibility to someone else.
Publication (s.11(5)). You must make available to the public the business contact information of at least one of those designated or delegated individuals.
And the sting (s.11(6)). Designating someone does not relieve the organisation of any of its obligations under the Act. Appointing a DPO is not a transfer of risk.
Section 11(5) says the business contact information must be made available to the public, without saying where. Regulation 1A of the Personal Data Protection Regulations 2021 fills that gap, and it is worth quoting because it is unusually specific.
An organisation is deemed to have satisfied section 11(5) if it makes available the business contact information of a designated individual “(a) where the organisation is registered under an applicable Act — in a record relating to the organisation that is made available on the Internet website of the Accounting and Corporate Regulatory Authority at https://www.bizfile.gov.sg; (b) in a readily accessible part of the organisation’s official website.”
Regulation 1A names two places, and publishing in either one is deemed to satisfy section 11(5):
“Readily accessible” is the operative phrase, and it is a practical standard rather than a technical one. A contact buried on an unlinked page is present but not readily accessible.
Because BizFile is an accepted route, an organisation whose designated individual is filed with ACRA can satisfy section 11(5) with nothing on its website at all.
Our scanner reads websites; it cannot read BizFile. So the 41.2% below means no data protection contact is discoverable on the website — not that those organisations are in breach.
It is still worth fixing: a customer with a question looks at your site, not at ACRA.
In Re Air Sino-Euro Associates Travel Pte. Ltd. [2025] SGPDPC 5 (Case DP-2312-C1857, 31 October 2025), the Commission found that the organisation had not designated any individual under section 11(3) until 15 April 2024 — after the incident that prompted the investigation. It also had no internal data protection policies. Those were Accountability findings, made alongside separate Protection findings that included a server running Windows Server 2012, no multi-factor authentication, and no contractual requirement for the IT vendor to conduct regular security reviews.
The financial penalty was S$47,000, imposed for the Accountability and Protection breaches together, on facts including unauthorised access to the personal data of 336,759 individuals, some of which the organisation accepted had been exfiltrated.
This decision is frequently summarised as a fine for failing to appoint a DPO. It was not. The S$47,000 was imposed for the Accountability and Protection breaches together, on facts that included unauthorised access to a large volume of personal data and several technical failures.
The Accountability finding is significant because it stood on its own — not because it carried the penalty by itself.
The Commission treated the absence of a designated individual as a standalone contravention, established on the organisation's own records, requiring no technical forensics. Once an investigation is open for any reason, that finding is available immediately.
| The role does involve | The role does not require |
|---|---|
| Knowing what personal data the organisation holds and why | A law degree or a certification |
| Owning the privacy policy and keeping it true | A full-time appointment |
| Receiving and routing access, correction and withdrawal requests | An external hire — an existing employee can hold it |
| Being the contact point if the PDPC or an individual gets in touch | Taking the organisation's obligations onto yourself — designation does not move them off the organisation (s.11(6)) |
| Running the s.26C assessment if a breach is suspected, and the s.26D notification if it is notifiable | Sole responsibility — the duty can be delegated under s.11(4) |
| Making sure someone reviews security arrangements periodically | Doing the security work personally |
What the Commission looked for in Air Sino-Euro was not seniority. It was whether anyone had been made responsible at all.
Regulation 1A tells you where. It does not tell you what the entry should look like, and that is where most of the practical mistakes happen.
Publish something like dpo@yourdomain.com that reaches the designated
individual. Make sure it is monitored — an address that
bounces or is never read is worse than none, because it represents a contact route that
does not exist.
In practice that means the privacy policy and a footer or contact page. If your contact is reachable only three clicks deep from an unlabelled page, it is technically present and practically absent.
“Data Protection Officer”, “Data protection contact” or
“PDPA enquiries” all read clearly. A general
info@ address with no indication that it handles data protection matters
does not tell the reader what they have found, and does not sit well beside the s.20(1)(c)
expectation that a person able to answer questions about the collection can be reached.
Open your own website in a private browser window and try to find your data protection contact in sixty seconds, without using site search.
Regulation 1A sets no time limit, and a clearly labelled section in a privacy policy linked from every page satisfies it.
But if you cannot find your own contact in a minute, neither will the customer, the complainant or the regulator who goes looking.
dpo@yourdomain.com
if you want the label to be unmistakable, or an existing monitored address such as
legal@, provided the published entry says what it is for.Sitetals looks for a data protection contact on your homepage, in your footer and in the legal pages linked from them — the same places a visitor or a complainant would look.
Run a free PDPA scanFree scan. Full PDF report with the PDPA references and a fix list from S$68.
Yes. Section 11(3) applies to every organisation subject to the PDPA, with no threshold for headcount or revenue. It can be an existing employee holding the responsibility alongside another role, and the responsibility can be delegated under section 11(4), but someone must be designated.
Yes to both. The Act requires an individual to be designated as responsible; it does not require them to be an employee or hold any particular seniority. What matters is that the person can actually discharge the responsibility and is reachable at the published contact.
Neither. Section 11(3) requires an organisation to designate one or more individuals; it does not require them to be resident in Singapore, and the Act contains no requirement to register the designation with the Commission. What section 11(5) does require is that the business contact information is made available to the public.
No. Section 11(6) states that designating an individual does not relieve the organisation of any of its obligations under the Act. The organisation remains responsible; the designation creates an internal owner, not a shield.
Regulation 1A of the Personal Data Protection Regulations 2021 names two routes: your ACRA record on BizFile, or a readily accessible part of your official website.
A monitored, clearly labelled data protection contact form can work, but it is a weaker answer than a published address: it gives the sender no record of what they submitted, and it fails silently if the form breaks.
Then section 11(3) is satisfied and section 11(5) is not. Publishing the contact is a short task, and it converts a partially met obligation into a fully met one that is visible from outside.