How it works What We Check Pricing Articles About Free PDPA Scan →
Guide

PDPA Compliance for Foreign Businesses Operating in Singapore

No Singapore office, no Singapore entity, no Singapore server — and the PDPA still applies to every Singapore customer you collect data from. Eight obligations, five gaps a GDPR policy leaves open, and what to do about each.

By the Sitetals research team· Published 27 August 2026· Updated 27 August 2026· 13 min read· All articles

The short version

You have no Singapore office. Your servers are in Frankfurt, your head office is in Paris or London or San Francisco, and nobody on the team has been to Singapore. You sell to Singapore customers through your website.

The PDPA applies to you. Not prospectively, not once you incorporate locally — now, on the data you are collecting today.

This is compliance research, not legal advice. Sitetals is an independent scanner, not a law firm and not affiliated with the Personal Data Protection Commission.

Whether a specific obligation applies to your organisation is a question of fact and law. For a decision that carries risk, take advice from a Singapore-qualified practitioner.

Why the PDPA reaches you

The Act binds “organisations”, and section 2(1) defines that term to include a company “whether or not — (a) formed or recognised under the law of Singapore; or (b) resident, or having an office or a place of business, in Singapore”.

If a Singapore resident fills in your contact form, buys from your store, or is tracked by your analytics while on your site, you are collecting personal data as an organisation within the meaning of the Act.

“A DPO has to be in Singapore, and we cannot appoint one.” This is simply not what the Act says, and it produces a gap that need not exist. Your existing head of privacy, general counsel or compliance lead can hold it from anywhere.

s.11(3)designate an individual — no residence requirement
reg. 1Ano ACRA record means the website is your only route
s.26D(1)3 calendar days from assessment, not discovery
reg. 9keyed to a transfer from Singapore — and you are never your own recipient

The eight obligations, mapped

ObligationProvisionWhat it means for a foreign operator
Designate a responsible individuals.11(3)Name someone. Anywhere in the world.
Publish their contacts.11(5), reg. 1AIn a readily accessible part of your official website, or in your ACRA BizFile record if you are registered in Singapore. For a foreign business with no ACRA record, that means the website.
Internal policies and a complaints processs.12Develop and implement policies, run a complaints process, tell your staff, and make the information available on request.
Consent before collectionss.13–14Including data collected by trackers on your Singapore-facing pages.
Notification of purposess.18, 20Tell people the purposes on or before collection, in terms a reasonable person would consider appropriate.
Reasonable securitys.24Applies to your systems wherever they are, for the data you hold.
Overseas transfers.26, regs. 9–12Keyed to a transfer from Singapore by a “transferring organisation” to a separate “recipient” abroad (reg. 9, which excludes the transferring organisation itself). Map your flows against that definition rather than assuming either way.
Breach notificationss.26B–26EA separate notification to the PDPC, on a different clock from the GDPR's.
Do Not CallPart 9, ss.38, 43Reaches a specified message addressed to a Singapore telephone number where the sender is in Singapore when it is sent, or the recipient is in Singapore when it is accessed (s.38).

Eight questions to answer this week

  1. Scope. Does your site collect names, emails, phone numbers, addresses or tracked behaviour from Singapore visitors?
  2. Designation. Is a named individual — anywhere in the world — formally designated as responsible for PDPA compliance?
  3. Publication. Does that person's business contact information appear in a readily accessible part of your website?
  4. Transfer. Does your policy say that Singapore visitors' data goes overseas, name where, and state the basis?
  5. Policy origin. Was your privacy policy drafted for the GDPR? If so, assume PDPA gaps until checked.
  6. Consent. Do analytics or advertising tags load before a Singapore visitor makes a choice?
  7. Marketing. Do you send marketing messages to +65 numbers, and are they screened?
  8. Breach. Does your incident plan have a PDPC pathway distinct from your EU supervisory-authority pathway?

Any answer of “no” or “not sure” points to the corresponding item below.

Answer three of those eight questions in 60 seconds

Sitetals fetches your Singapore-facing pages and reports what is visible in them: whether a data protection contact is published, whether a privacy policy is reachable, and which third-party tracking scripts are present in the page as served.

It reads the pages as delivered rather than running them in a browser, so a site that assembles itself in JavaScript will show less. No sign-up, no card.

Run a free PDPA scan

Free scan. Full PDF report with the PDPA references and a fix list from S$68.

The eight items

1. Confirm the PDPA applies, and stop arguing about it

If your site collects any of the following from Singapore visitors — name, personal email address, telephone number, delivery address, or an IP address or device identifier linked to an individual — the PDPA is engaged, and the eight obligations below are live.

One qualification is worth settling early rather than late: section 4(5) provides that, except where it is expressly mentioned, Parts 3 to 6A do not apply to business contact information — a person’s name, title, business telephone number, business address or business email address, where it was not provided solely for their personal purposes. A strictly business-to-business site that collects work names and work email addresses is therefore in a materially different position from a consumer site, and it is worth establishing which one you are before you build a programme for the other.

2. Designate someone, and publish how to reach them

Two separate duties. Section 11(3) is the designation; section 11(5) is the publication. Regulation 1A of the Personal Data Protection Regulations 2021 names the accepted routes: your ACRA record on BizFile, or a readily accessible part of your official website. A foreign business with no ACRA record has one route, which is the website.

Practical form: a role address such as dpo@yourdomain.com, clearly labelled, in the privacy policy and in the footer, monitored by a named person. Not behind a login, not reachable only through a general enquiries form. The full guide is here.

In Re Air Sino-Euro Associates Travel Pte. Ltd. [2025] SGPDPC 5 the Commission found that no individual had been designated until 15 April 2024, after the incident, and that there were no internal data protection policies.

Those Accountability findings sat alongside Protection findings, and the S$47,000 penalty was imposed for both together — it was not a fine for the missing DPO alone.

3. Understand which way the transfer obligation points

Section 26 provides that an organisation must not transfer personal data to a country or territory outside Singapore except in accordance with the prescribed requirements, and those requirements are in regulations 9 to 12.

Regulation 10(1) puts the duty on the transferring organisation — defined in regulation 9 as the organisation that transfers the data from Singapore — and requires it, before transferring, to take appropriate steps to ascertain whether, and to ensure that, the recipient is bound by legally enforceable obligations providing a standard of protection at least comparable to the protection under the Act.

Note who cannot be a recipient. Regulation 9 excludes the transferring organisation itself, and its own employees acting in the course of their employment, from the meaning of “recipient” — so data moving between your own systems has no recipient, and no instrument can be written for it.

The instrument question arises where there is a genuinely separate recipient. Regulations 11 and 12 provide three routes: a contract satisfying both limbs of regulation 11(2); binding corporate rules under regulation 11(3), where the recipient is a related entity within regulation 11(4) — that is, one company controls the other, or both are under common control; or a recipient holding a specified certification under regulation 12, which since 2 March 2026 includes the Global CBPR and Global PRP systems alongside the APEC ones.

Which of your flows has a separate recipient, and where the data sits when it moves, is the question to answer before you buy paperwork. Full detail on cross-border transfers from Singapore.

4. Audit your GDPR policy for the five PDPA gaps

ElementUnder the GDPRUnder the PDPATypical gap in an EU-drafted policy
Lawful basisSix bases, including the Art. 6(1)(f) legitimate-interests balancing testConsent, deemed consent, and specific exceptions. A legitimate-interests exception does exist (First Schedule, Part 3) but requires an assessment before collection, with adverse effects identified and reasonable measures implemented, and excludes direct marketingPolicies that rest on Art. 6(1)(f) as an internal balancing exercise have no PDPA counterpart in that form
Data protection officerRequired only for certain organisations (Art. 37)Required of every organisation (s.11(3)), with the contact published (s.11(5))EU policies often omit a DPO contact because the GDPR did not require one
Overseas transferAdequacy decisions, SCCs, BCRsLegally enforceable obligations giving comparable protection; the contract must name the destination countries (reg. 11(2))“We use SCCs” states a mechanism, not that the two limbs of reg. 11(2) are met
WithdrawalErasure (Art. 17) and withdrawal of consent (Art. 7(3))Withdrawal of consent on reasonable notice (s.16), with a duty to inform the individual of the likely consequencesErasure language does not describe the PDPA mechanism, and the consequences duty is usually absent
Purpose statementsPurpose limitation (Art. 5(1)(b))Purposes a reasonable person would consider appropriate (s.18), notified on or before collection (s.20)Broad “legitimate business purposes” drafting is too general to serve as notification

Comparison is directional. Policy drafting is work for a practitioner who knows both regimes. Our PDPA policy checklist sets out what the Singapore version has to contain.

5. Check what fires before consent on your Singapore-facing pages

Sections 13 and 14 require consent before personal data is collected, and section 20(1)(a) requires the purposes to be given on or before collection.

Analytics and advertising tags that assign a persistent identifier can collect personal data. The PDPA, though, also recognises deemed consent under section 15, and section 20(3)(a) switches off the notification duty where consent is deemed — so a Singapore-facing page that loads a tag before any banner choice is not automatically in breach in the way the equivalent page would be under the ePrivacy rules in France or Germany.

A banner tuned for CNIL expectations — equal prominence for accept and reject, blocking before consent — is closer to what the PDPA needs than a US-style notice bar. It is still not automatic compliance: what matters is whether the scripts are actually held, which is a question about your tag configuration, not your banner design. How to verify it in ten minutes.

6. Screen Singapore numbers — and know the exclusions

Section 43(1) provides that a person must not send a specified message addressed to a Singapore telephone number unless, at the time of sending, they have valid confirmation that the number is not listed in the relevant register.

Under section 43(2), valid confirmation means either applying to the Commission within the prescribed duration and receiving confirmation, or obtaining that information from a checker and having no reason to believe the prescribed period has expired or the information is wrong.

Section 38 sets the reach: this Part applies to a specified message addressed to a Singapore telephone number where either the sender is present in Singapore when it is sent, or the recipient is present in Singapore when it is accessed. Sending from outside Singapore does not put you outside Part 9 — for a Singapore number the second limb will usually be met — but it is a two-limb test, not an irrelevance.

What most write-ups leave out is how much the Eighth Schedule excludes from “specified message” in the first place. Among the exclusions:

Separately from the exclusions, section 43(4) provides that a person does not contravene section 43(1) where the subscriber or user of the number gave clear and unambiguous consent to the sending of the message and that consent is evidenced in written or other form so as to be accessible for subsequent reference. Consent is an answer to the duty; it is not an answer to whether the message was a specified message in the first place.

Two things follow from the exclusions

First, a genuine transactional or ongoing-relationship message is outside the regime entirely, so the registry check is not the answer to every question.

Second, most of the exclusions turn on sole purpose — attaching a promotion to an order confirmation is what takes a message out of the exclusion and back into the duty under section 43(1).

The organisation-to-organisation exclusion at paragraph 1(1)(g) is the one that does not: it turns on the message being sent to an organisation for a purpose of the receiving organisation.

7. Build the Singapore breach pathway, on the right clock

Sections 26B to 26E, not the GDPR's Article 33, govern here, and the differences are not cosmetic.

DimensionGDPRPDPA
Deadline72 hoursNo later than 3 calendar days
When the clock startsOn becoming aware of the breachOn the day you assess the breach to be notifiable (s.26D(1))
The assessment itselfMust be conducted in a reasonable and expeditious manner once you have reason to believe a breach occurred (s.26C(2))
ThresholdRisk to rights and freedomsSignificant harm to an affected individual, or significant scale (s.26B)
Who you tellYour lead supervisory authorityThe PDPC — separately, in addition
IndividualsWhere high riskWhere the breach is of the significant-harm kind (s.26D(2)) — unless s.26D(5) applies, i.e. remedial action taken after assessment, or a technological measure already in place before the breach, makes significant harm unlikely

Note the shape of the timing rule, because it is not simply a shorter 72 hours. Section 26D(1) requires notification as soon as is practicable, and in any case no later than 3 calendar days after the day you make the assessment — the assessment day itself is not counted.

What really differs from the GDPR is the starting point: assessment, not awareness. Section 26C(2) then closes the obvious gap, by requiring the assessment to be conducted in a reasonable and expeditious manner once you have reason to believe a breach has occurred. You cannot buy time by declining to assess.

8. Treat Singapore as a live commercial risk

Singapore enterprise buyers, distributors and channel partners run vendor due diligence, and PDPA questions are a standard part of it. A published PDPC decision naming an organisation is permanent and searchable. For most foreign operators selling into Singapore, the realistic downside is a procurement question you cannot answer well, not a penalty notice — and the fix for both is the same eight items.

Establish a baseline before the next risk review

Run the scan, save the result, and take a dated record of what your Singapore-facing site currently exposes into the meeting where you assign owners to these eight items.

Run a free PDPA scan

Free scan. Full PDF report with the PDPA references and a fix list from S$68.

Where you should take advice rather than self-assess

Common questions

Does the PDPA apply to a company with no presence in Singapore?

Yes, where it collects, uses or discloses personal data in Singapore. The Act attaches to the activity rather than to incorporation or physical presence, so a foreign website that collects data from Singapore residents is within scope.

Does my DPO have to be based in Singapore?

No. Section 11(3) requires the designation of one or more individuals responsible for ensuring compliance and imposes no residence, citizenship or location requirement. Section 11(5) then requires their business contact information to be publicly available — for a foreign business with no ACRA record, that means a readily accessible part of your website, per regulation 1A.

Is GDPR compliance enough for the PDPA?

No. The regimes differ on lawful basis, on who must appoint a data protection officer, on the overseas transfer test, on breach notification timing and trigger, and on how purposes must be stated. An EU-drafted policy typically needs specific additions rather than a rewrite, but the additions are not optional.

Do EU Standard Contractual Clauses satisfy the PDPA transfer requirement?

Not by virtue of being SCCs. Regulation 11(2) requires the contract to require a standard of protection at least comparable to the PDPA and to specify the countries and territories to which the data may be transferred. Assess your instrument against those two limbs, and take advice where it matters.

How fast must we notify the PDPC of a breach?

No later than three calendar days after the day you assess the breach to be notifiable (s.26D(1)), and as soon as practicable. The assessment itself must be conducted in a reasonable and expeditious manner once you have reason to believe a breach occurred (s.26C(2)). This is separate from, and additional to, any GDPR notification.

Do the Do Not Call rules apply to B2B messages?

The Eighth Schedule excludes from “specified message” any message sent to an organisation, other than an individual acting in a personal or domestic capacity, for any purpose of the receiving organisation. Whether a given message falls within that exclusion depends on the facts, and it is not a licence for untargeted messaging to personal mobile numbers collected at events.

Sources

Related reading

AccountabilityAppointing and publishing a DPO under the PDPATransfersCross-border data transfers under the PDPANotificationThe PDPA privacy policy checklistConsentDo you need a cookie banner under the PDPA?
Sitetals research team. Sitetals is an independent website compliance scanner operated by QuikForge Limited. We check Singapore websites against the PDPA obligations that are visible from the outside, and publish what the aggregate results show. Every statutory reference in this article was checked against the consolidated Act on Singapore Statutes Online, and every enforcement figure against the published decision itself. Corrections: hello@sitetals.com.