No Singapore office, no Singapore entity, no Singapore server — and the PDPA still applies to every Singapore customer you collect data from. Eight obligations, five gaps a GDPR policy leaves open, and what to do about each.
You have no Singapore office. Your servers are in Frankfurt, your head office is in Paris or London or San Francisco, and nobody on the team has been to Singapore. You sell to Singapore customers through your website.
The PDPA applies to you. Not prospectively, not once you incorporate locally — now, on the data you are collecting today.
This is compliance research, not legal advice. Sitetals is an independent scanner, not a law firm and not affiliated with the Personal Data Protection Commission.
Whether a specific obligation applies to your organisation is a question of fact and law. For a decision that carries risk, take advice from a Singapore-qualified practitioner.
The Act binds “organisations”, and section 2(1) defines that term to include a company “whether or not — (a) formed or recognised under the law of Singapore; or (b) resident, or having an office or a place of business, in Singapore”.
If a Singapore resident fills in your contact form, buys from your store, or is tracked by your analytics while on your site, you are collecting personal data as an organisation within the meaning of the Act.
“A DPO has to be in Singapore, and we cannot appoint one.” This is simply not what the Act says, and it produces a gap that need not exist. Your existing head of privacy, general counsel or compliance lead can hold it from anywhere.
| Obligation | Provision | What it means for a foreign operator |
|---|---|---|
| Designate a responsible individual | s.11(3) | Name someone. Anywhere in the world. |
| Publish their contact | s.11(5), reg. 1A | In a readily accessible part of your official website, or in your ACRA BizFile record if you are registered in Singapore. For a foreign business with no ACRA record, that means the website. |
| Internal policies and a complaints process | s.12 | Develop and implement policies, run a complaints process, tell your staff, and make the information available on request. |
| Consent before collection | ss.13–14 | Including data collected by trackers on your Singapore-facing pages. |
| Notification of purpose | ss.18, 20 | Tell people the purposes on or before collection, in terms a reasonable person would consider appropriate. |
| Reasonable security | s.24 | Applies to your systems wherever they are, for the data you hold. |
| Overseas transfer | s.26, regs. 9–12 | Keyed to a transfer from Singapore by a “transferring organisation” to a separate “recipient” abroad (reg. 9, which excludes the transferring organisation itself). Map your flows against that definition rather than assuming either way. |
| Breach notification | ss.26B–26E | A separate notification to the PDPC, on a different clock from the GDPR's. |
| Do Not Call | Part 9, ss.38, 43 | Reaches a specified message addressed to a Singapore telephone number where the sender is in Singapore when it is sent, or the recipient is in Singapore when it is accessed (s.38). |
Any answer of “no” or “not sure” points to the corresponding item below.
Sitetals fetches your Singapore-facing pages and reports what is visible in them: whether a data protection contact is published, whether a privacy policy is reachable, and which third-party tracking scripts are present in the page as served.
It reads the pages as delivered rather than running them in a browser, so a site that assembles itself in JavaScript will show less. No sign-up, no card.
Run a free PDPA scanFree scan. Full PDF report with the PDPA references and a fix list from S$68.
If your site collects any of the following from Singapore visitors — name, personal email address, telephone number, delivery address, or an IP address or device identifier linked to an individual — the PDPA is engaged, and the eight obligations below are live.
One qualification is worth settling early rather than late: section 4(5) provides that, except where it is expressly mentioned, Parts 3 to 6A do not apply to business contact information — a person’s name, title, business telephone number, business address or business email address, where it was not provided solely for their personal purposes. A strictly business-to-business site that collects work names and work email addresses is therefore in a materially different position from a consumer site, and it is worth establishing which one you are before you build a programme for the other.
Two separate duties. Section 11(3) is the designation; section 11(5) is the publication. Regulation 1A of the Personal Data Protection Regulations 2021 names the accepted routes: your ACRA record on BizFile, or a readily accessible part of your official website. A foreign business with no ACRA record has one route, which is the website.
Practical form: a role address such as dpo@yourdomain.com, clearly
labelled, in the privacy policy and in the footer, monitored by a named person. Not
behind a login, not reachable only through a general enquiries form.
The full guide is here.
In Re Air Sino-Euro Associates Travel Pte. Ltd. [2025] SGPDPC 5 the Commission found that no individual had been designated until 15 April 2024, after the incident, and that there were no internal data protection policies.
Those Accountability findings sat alongside Protection findings, and the S$47,000 penalty was imposed for both together — it was not a fine for the missing DPO alone.
Section 26 provides that an organisation must not transfer personal data to a country or territory outside Singapore except in accordance with the prescribed requirements, and those requirements are in regulations 9 to 12.
Regulation 10(1) puts the duty on the transferring organisation — defined in regulation 9 as the organisation that transfers the data from Singapore — and requires it, before transferring, to take appropriate steps to ascertain whether, and to ensure that, the recipient is bound by legally enforceable obligations providing a standard of protection at least comparable to the protection under the Act.
Note who cannot be a recipient. Regulation 9 excludes the transferring organisation itself, and its own employees acting in the course of their employment, from the meaning of “recipient” — so data moving between your own systems has no recipient, and no instrument can be written for it.
The instrument question arises where there is a genuinely separate recipient. Regulations 11 and 12 provide three routes: a contract satisfying both limbs of regulation 11(2); binding corporate rules under regulation 11(3), where the recipient is a related entity within regulation 11(4) — that is, one company controls the other, or both are under common control; or a recipient holding a specified certification under regulation 12, which since 2 March 2026 includes the Global CBPR and Global PRP systems alongside the APEC ones.
Which of your flows has a separate recipient, and where the data sits when it moves, is the question to answer before you buy paperwork. Full detail on cross-border transfers from Singapore.
| Element | Under the GDPR | Under the PDPA | Typical gap in an EU-drafted policy |
|---|---|---|---|
| Lawful basis | Six bases, including the Art. 6(1)(f) legitimate-interests balancing test | Consent, deemed consent, and specific exceptions. A legitimate-interests exception does exist (First Schedule, Part 3) but requires an assessment before collection, with adverse effects identified and reasonable measures implemented, and excludes direct marketing | Policies that rest on Art. 6(1)(f) as an internal balancing exercise have no PDPA counterpart in that form |
| Data protection officer | Required only for certain organisations (Art. 37) | Required of every organisation (s.11(3)), with the contact published (s.11(5)) | EU policies often omit a DPO contact because the GDPR did not require one |
| Overseas transfer | Adequacy decisions, SCCs, BCRs | Legally enforceable obligations giving comparable protection; the contract must name the destination countries (reg. 11(2)) | “We use SCCs” states a mechanism, not that the two limbs of reg. 11(2) are met |
| Withdrawal | Erasure (Art. 17) and withdrawal of consent (Art. 7(3)) | Withdrawal of consent on reasonable notice (s.16), with a duty to inform the individual of the likely consequences | Erasure language does not describe the PDPA mechanism, and the consequences duty is usually absent |
| Purpose statements | Purpose limitation (Art. 5(1)(b)) | Purposes a reasonable person would consider appropriate (s.18), notified on or before collection (s.20) | Broad “legitimate business purposes” drafting is too general to serve as notification |
Comparison is directional. Policy drafting is work for a practitioner who knows both regimes. Our PDPA policy checklist sets out what the Singapore version has to contain.
Sections 13 and 14 require consent before personal data is collected, and section 20(1)(a) requires the purposes to be given on or before collection.
Analytics and advertising tags that assign a persistent identifier can collect personal data. The PDPA, though, also recognises deemed consent under section 15, and section 20(3)(a) switches off the notification duty where consent is deemed — so a Singapore-facing page that loads a tag before any banner choice is not automatically in breach in the way the equivalent page would be under the ePrivacy rules in France or Germany.
A banner tuned for CNIL expectations — equal prominence for accept and reject, blocking before consent — is closer to what the PDPA needs than a US-style notice bar. It is still not automatic compliance: what matters is whether the scripts are actually held, which is a question about your tag configuration, not your banner design. How to verify it in ten minutes.
Section 43(1) provides that a person must not send a specified message addressed to a Singapore telephone number unless, at the time of sending, they have valid confirmation that the number is not listed in the relevant register.
Under section 43(2), valid confirmation means either applying to the Commission within the prescribed duration and receiving confirmation, or obtaining that information from a checker and having no reason to believe the prescribed period has expired or the information is wrong.
Section 38 sets the reach: this Part applies to a specified message addressed to a Singapore telephone number where either the sender is present in Singapore when it is sent, or the recipient is present in Singapore when it is accessed. Sending from outside Singapore does not put you outside Part 9 — for a Singapore number the second limb will usually be met — but it is a two-limb test, not an irrelevance.
What most write-ups leave out is how much the Eighth Schedule excludes from “specified message” in the first place. Among the exclusions:
Separately from the exclusions, section 43(4) provides that a person does not contravene section 43(1) where the subscriber or user of the number gave clear and unambiguous consent to the sending of the message and that consent is evidenced in written or other form so as to be accessible for subsequent reference. Consent is an answer to the duty; it is not an answer to whether the message was a specified message in the first place.
First, a genuine transactional or ongoing-relationship message is outside the regime entirely, so the registry check is not the answer to every question.
Second, most of the exclusions turn on sole purpose — attaching a promotion to an order confirmation is what takes a message out of the exclusion and back into the duty under section 43(1).
The organisation-to-organisation exclusion at paragraph 1(1)(g) is the one that does not: it turns on the message being sent to an organisation for a purpose of the receiving organisation.
Sections 26B to 26E, not the GDPR's Article 33, govern here, and the differences are not cosmetic.
| Dimension | GDPR | PDPA |
|---|---|---|
| Deadline | 72 hours | No later than 3 calendar days |
| When the clock starts | On becoming aware of the breach | On the day you assess the breach to be notifiable (s.26D(1)) |
| The assessment itself | — | Must be conducted in a reasonable and expeditious manner once you have reason to believe a breach occurred (s.26C(2)) |
| Threshold | Risk to rights and freedoms | Significant harm to an affected individual, or significant scale (s.26B) |
| Who you tell | Your lead supervisory authority | The PDPC — separately, in addition |
| Individuals | Where high risk | Where the breach is of the significant-harm kind (s.26D(2)) — unless s.26D(5) applies, i.e. remedial action taken after assessment, or a technological measure already in place before the breach, makes significant harm unlikely |
Note the shape of the timing rule, because it is not simply a shorter 72 hours. Section 26D(1) requires notification as soon as is practicable, and in any case no later than 3 calendar days after the day you make the assessment — the assessment day itself is not counted.
What really differs from the GDPR is the starting point: assessment, not awareness. Section 26C(2) then closes the obvious gap, by requiring the assessment to be conducted in a reasonable and expeditious manner once you have reason to believe a breach has occurred. You cannot buy time by declining to assess.
Singapore enterprise buyers, distributors and channel partners run vendor due diligence, and PDPA questions are a standard part of it. A published PDPC decision naming an organisation is permanent and searchable. For most foreign operators selling into Singapore, the realistic downside is a procurement question you cannot answer well, not a penalty notice — and the fix for both is the same eight items.
Run the scan, save the result, and take a dated record of what your Singapore-facing site currently exposes into the meeting where you assign owners to these eight items.
Run a free PDPA scanFree scan. Full PDF report with the PDPA references and a fix list from S$68.
Yes, where it collects, uses or discloses personal data in Singapore. The Act attaches to the activity rather than to incorporation or physical presence, so a foreign website that collects data from Singapore residents is within scope.
No. Section 11(3) requires the designation of one or more individuals responsible for ensuring compliance and imposes no residence, citizenship or location requirement. Section 11(5) then requires their business contact information to be publicly available — for a foreign business with no ACRA record, that means a readily accessible part of your website, per regulation 1A.
No. The regimes differ on lawful basis, on who must appoint a data protection officer, on the overseas transfer test, on breach notification timing and trigger, and on how purposes must be stated. An EU-drafted policy typically needs specific additions rather than a rewrite, but the additions are not optional.
Not by virtue of being SCCs. Regulation 11(2) requires the contract to require a standard of protection at least comparable to the PDPA and to specify the countries and territories to which the data may be transferred. Assess your instrument against those two limbs, and take advice where it matters.
No later than three calendar days after the day you assess the breach to be notifiable (s.26D(1)), and as soon as practicable. The assessment itself must be conducted in a reasonable and expeditious manner once you have reason to believe a breach occurred (s.26C(2)). This is separate from, and additional to, any GDPR notification.
The Eighth Schedule excludes from “specified message” any message sent to an organisation, other than an individual acting in a personal or domestic capacity, for any purpose of the receiving organisation. Whether a given message falls within that exclusion depends on the facts, and it is not a licence for untargeted messaging to personal mobile numbers collected at events.