How it works What We Check Pricing Articles About Free PDPA Scan →
Enforcement report

Singapore Website PDPA Health Check 2026: What 10,298 Scanned Sites and Five PDPC Decisions Show

Five Personal Data Protection Commission decisions in 2025 imposed S$455,000 in penalties over incidents affecting 1.86 million people. None of them involved an exotic attack. Here is what they found, and what we see on Singapore websites today.

By the Sitetals research team· Published 27 August 2026· Updated 27 August 2026· 14 min read· All articles

The short version

This is compliance research, not legal advice. Sitetals is an independent scanner, not a law firm and not affiliated with the Personal Data Protection Commission.

Whether a specific obligation applies to your organisation is a question of fact and law. For a decision that carries risk, take advice from a Singapore-qualified practitioner.

What we scanned, and what that sample is worth

Between 17 and 27 August 2026 we completed compliance scans of 10,298 Singapore-associated websites. Each site is counted once, using its most recent completed scan.

The sample was assembled from public web indexes: the CommonCrawl Singapore host index (5,610 sites), Majestic (711), certificate transparency logs (540), the SGX API (375) and a Singapore business-listing set (332), with 27 unattributed.

That composition matters. It is a convenience sample weighted toward domains large enough to appear in a public index. It is not a random or representative sample of Singapore businesses, and nothing here should be read as "X% of Singapore companies". It is a large, dated, reproducible read of what Singapore websites currently expose.

10,298Singapore websites scanned, 17–27 Aug 2026
62.4%showed at least one visible gap
S$455,000in penalties across five 2025 decisions
1,861,510individuals affected in those five cases

What we found on 10,298 Singapore websites

Share of all scanned sites showing each finding. A site can appear in more than one row.

Tracker code served with no consent mechanism present
42.6%
No data protection contact discoverable on the site
41.2%
Google Analytics or ad tag code served with no consent mechanism present
26.4%
No privacy policy found
23.8%
Not served over HTTPS
5.9%

Denominator is all 10,298 sites with a completed scan, not only those with findings. Sites that did not resolve, were unreachable, or were behind bot protection are excluded rather than counted as clean. Sample drawn from public web indexes and therefore weighted toward indexed domains; not a representative sample of Singapore businesses. Figures are a snapshot of our scan database taken on 27 August 2026; scanning is continuous, so the same query run later returns a larger sample. “No data protection contact discoverable on the site” means exactly that: regulation 1A of the Personal Data Protection Regulations 2021 also accepts publication on the organisation’s ACRA BizFile record, which a website scan cannot see.

The 41.2% with no published data protection contact is the one that is trivially checkable from outside. Section 11(5) of the PDPA requires an organisation to make available to the public the business contact information of at least one designated individual, and regulation 1A of the Personal Data Protection Regulations 2021 names two accepted routes: the organisation's ACRA record on BizFile, or a readily accessible part of its official website.

One honest caveat on our own number. Because BizFile is an accepted route, an organisation that has filed its designated individual with ACRA satisfies section 11(5) even with nothing on its website — and our scanner reads websites, not BizFile. So 41.2% means no data protection contact was discoverable on the site, not that those organisations are in breach. More on both routes here.

The 23.8% with no discoverable privacy policy is the more serious one. Section 20 requires that individuals be informed of the purposes for collection on or before collection. A published policy is the ordinary way a website discharges that. Where there is no policy at all and the site collects personal data — a contact form, a newsletter box, a checkout — there is a real question about how notification is being given.

The five decisions, and what each one actually found

Every figure below was taken from the published decision itself, not from a secondary summary. Citations and case numbers are given so you can check them.

OrganisationCitationDecision datePenaltyIndividualsObligation
Marina Bay Sands Pte. Ltd.[2025] SGPDPC 6
DP-2310-C1622
28 Oct 2025S$315,000665,495Protection, s.24
Air Sino-Euro Associates Travel Pte. Ltd.[2025] SGPDPC 5
DP-2312-C1857
31 Oct 2025S$47,000336,759Accountability s.11(3) and Protection s.24
Singapore Data Hub Pte Ltd[2025] SGPDPC 2
DP-2406-C2514
7 Apr 2025S$17,500698,112Protection, s.24
Goldheart Jewelry Pte. Ltd.[2025] SGPDPC 4
DP-2305-C1061
20 Jun 2025S$58,00041,379Protection, s.24
People Central Pte. Ltd.[2025] SGPDPCS 4
DP-2405-C2330
S$17,500119,765Protection, s.24
TotalS$455,0001,861,510

Marina Bay Sands — S$315,000, and the most instructive failure of the five

Between September 2022 and March 2023 the organisation migrated to a new middleware platform. The migration involved replicating the existing API configurations onto the new platform, and the organisation chose to do that replication manually. One employee was tasked with compiling an inventory of every API and its calling application ID. That inventory was then used to configure the token verification policy on the new platform.

The employee omitted one entry: the external ArtScienceMuseum calling application ID. Because the inventory drove the configuration, the token verification policy never applied to that one page. The result was a classic insecure direct object reference — member IDs were sequential numbers, so anyone with a valid access token could change the number in the request and read another member's record. The gap was open for at least six months, from March to October 2023, and the data of 665,495 loyalty programme members was exfiltrated and offered for sale.

The Commission's criticism was not that an employee made a mistake. It was that the organisation placed the burden on one employee at a single point with no process to catch the error, and that it was unreasonable to rely on that alone.

Air Sino-Euro — S$47,000, and its Accountability finding

A cyberattack led to the exfiltration of personal data belonging to 336,759 individuals, including full images of NRIC, passport and birth certificate documents for at least a hundred of them. Investigations found the server running Windows Server 2012, no contractual requirement for the IT vendor to conduct regular security reviews, and no multi-factor authentication.

The Accountability finding is the part website operators should read twice. The organisation had not designated anyone under section 11(3) until 15 April 2024 — after the incident. That is a standalone breach, independent of the technical failures.

It is worth being precise about causation here, because it is frequently misreported: the S$47,000 was imposed for the Accountability and Protection breaches together, on facts that included a large exfiltration. It is not a "S$47,000 fine for not having a DPO". The absence of a designated individual was one finding among several, and it is the one that would have been visible from outside the organisation.

Goldheart Jewelry — S$58,000, and why "the vendor handles updates" is not an answer

The organisation ran a Magento e-commerce platform managed by a vendor. CVE-2022-24086 was published, and a patch was available, in February 2022. It was still unapplied when the vulnerability was exploited roughly eleven months later, disclosing the personal data of 41,379 individuals, some of which was published online.

The Commission's starting point was S$64,000. After the organisation's representations — including a successful argument about plaintext credentials in Magento configuration files, which the Commission accepted — the penalty imposed was S$58,000. Both numbers appear in the decision; only S$58,000 is the penalty.

The directions are as instructive as the penalty: engage a third-party vendor for a targeted security audit within 60 days, rectify what it finds, and report back.

People Central — S$17,500, and the cadence question

A cloud HR platform running on AWS. A threat actor deleted databases and put the personal data of 95,000 employees of the organisation's clients at risk, along with a further 24,765 emergency contacts and children — 18,125 emergency contacts and 6,640 children, whose data included names, dates of birth and contact numbers.

The findings were unglamorous and specific: SQL injection vulnerabilities in the web application with multiple observed attempts and no web application firewall; Remote Desktop Protocol open to the internet without two-factor authentication; inbound traffic permitted from every IP address in the cloud environment; and vulnerability scanning performed only once every two years, with no network vulnerability assessments at the time of the incident.

The decision cites the CIS Critical Security Controls, under which internal and external penetration tests should be conducted at least annually and vulnerability assessments quarterly, and records the Commission's encouragement that organisations assess the need and frequency of penetration testing as part of a periodic security review.

If you take one operational cadence away from this report, take that one.

Singapore Data Hub — S$17,500, and the testing distinction

A point-of-sale and CRM vendor to small and medium enterprises. Files were exfiltrated affecting 698,112 individuals, including approximately 689,000 whose NRIC number was involved and a further group whose medical information was affected.

The finding that generalises: the organisation carried out internal acceptance testing that checked whether the application functioned. Functional testing was held not to be a substitute for security testing. If your release checklist asks "does it work?" and never asks "can it be abused?", this decision is about you.

The pattern across all five

1. The failure is almost always a cadence failure, not a knowledge failure

The problem was the interval: eleven months to apply a known patch, two years between vulnerability scans, six months with a misconfiguration undetected. Compliance failed at the frequency, not at the concept.

2. Delegating the work never delegates the responsibility

Goldheart used a vendor. Air Sino-Euro used an IT vendor with no security-review clause. Marina Bay Sands used one employee. In each case the organisation remained accountable. Section 11(6) of the PDPA is explicit that designating an individual does not relieve the organisation of its obligations, and the decisions apply the same logic to outsourcing.

3. Financial hardship is a payment-schedule argument, not a liability argument

Two of the five organisations argued they could not afford the penalty. Neither had the penalty reduced on that basis. People Central was allowed to pay S$17,500 in twelve monthly instalments. That is the shape of the concession available: how you pay, not whether you owe.

Where the enforcement record meets what we can actually see

Most of what the Commission penalised is invisible from outside. We cannot see your patch cadence, your VAPT reports, your firewall rules or your vendor contracts, and any scanner claiming otherwise is overselling. What we can see is a different layer: the one a customer, a complainant or the Commission can look at without asking anyone's permission.

The decisions say nothing about what any of these five organisations published on its own website, and we make no claim about that.

The relationship is correlative, not causal, and we are not going to dress it up as more than that. Air Sino-Euro's Accountability finding was that no individual had been designated under section 11(3) until after the incident — a designation failure, not a publication failure, and one no scanner could have seen.

The two duties sit side by side: section 11(3) is the duty to designate someone, section 11(5) the duty to make that person's business contact information available. Only the second is visible from outside, and it has been in force since 2 July 2014. A site that still shows nothing is worth a question, even though the missing contact is not itself proof of anything.

What the Sitetals scan can and cannot tell you

Sitetals fetches your homepage and the legal pages linked from it, exactly as any visitor or complainant could, and reads the HTML it is served without executing it. It reports what is visible from outside. It has no access to your servers, your contracts or your internal processes.

QuestionVisible to the scan?Why
Is a privacy policy published and reachable?YesDetected from homepage and footer links.
Is a data protection contact discoverable on the site?YesDetected in the footer, homepage and linked legal pages. A contact filed only on the ACRA BizFile record is not visible to us.
Is tracker code served with no consent mechanism present?YesRead from the page as it is served to us, before any interaction. We do not execute the page, so we report the code that was delivered, not a network request we watched fire.
Is the site served over HTTPS?YesObserved at fetch time.
Is the policy adequate for your actual processing?NoThat depends on what you collect and why. A scan cannot read your business.
Was consent validly obtained and recorded?NoConsent records are internal.
Is your patching, VAPT or access control reasonable?NoInternal processes are not website-visible.
Are your vendor contracts adequate?NoContracts are not published.

A finding is a prompt to look, not a determination that the PDPA has been contravened. Only the Commission can make that determination.

The penalty ceiling, stated correctly

This is the most commonly mangled fact in Singapore compliance writing, so here it is from the statute. Section 48J(3), mirrored by regulation 10A of the Personal Data Protection (Enforcement) Regulations 2021, sets two maximums:

Annual turnover in SingaporeMaximum financial penalty
Exceeds S$10 million10% of annual turnover in Singapore
S$10 million or belowS$1 million

The Marina Bay Sands decision calls these the High Turnover Class and the Low Turnover Class. Any organisation whose annual turnover in Singapore is S$10 million or below sits in the Low Turnover Class, where the ceiling is S$1 million. Quoting only the 10% figure to a small operator overstates their exposure, and we would rather be useful than alarming. Note also that these are maximums: the five penalties here ranged from S$17,500 to S$315,000.

Section 48J(3), PDPA 2012

“A financial penalty imposed on an organisation … must not exceed the maximum amount to be prescribed, which in no case may be more than the following: (a) … by an organisation whose annual turnover in Singapore exceeds $10 million — 10% of the annual turnover in Singapore of the organisation; (b) in any other case — $1 million.”

What to do this week

None of this constitutes legal advice and none of it is specific to your organisation. It is the housekeeping the five decisions above keep returning to, in the order we would do it.

  1. Check whether your data protection contact is actually publishedToday Open your own site in a private window and try to find a data protection contact without using site search. Section 11(5) asks for the business contact information of at least one designated individual to be available to the public.
  2. Confirm someone is actually designatedToday Publishing a mailbox is not the same as designating a person under section 11(3). Write down who it is. Air Sino-Euro's Accountability finding was that no one had been designated at all until after the breach.
  3. Look at what fires before consentThis week Load your homepage in a private window with developer tools open and watch the network requests before you touch anything. Advertising and remarketing tags need a consent choice before they run, and analytics tags do too where they collect personal data and no exception applies — a banner that appears after the tags have already fired records a click, not a consent.
  4. Write down who is responsible for patching each platform7 days For every third-party platform you run — Shopify, WooCommerce, Magento, your CRM, your HR system — name the person who checks that security updates have been applied, and how they verify it. Goldheart is the decision that says assuming the vendor did it is not enough.
  5. Book a vulnerability assessment if you have not had one in twelve months30 days The People Central decision treated a two-year scanning interval as unreasonable and noted that penetration testing should be at least annual for systems holding significant volumes of personal data.
  6. Retire anything unsupported30 days Windows Server 2012 was cited by name in the Air Sino-Euro decision. End-of-life software that processes personal data is a finding waiting to be written.
  7. Fix your release checklistOngoing Add one line: does this change introduce a way for someone to reach data they should not? Singapore Data Hub is the decision that says functional testing does not answer that question.
See what your own site exposes

Sitetals checks the same externally visible signals discussed above: whether a privacy policy is reachable, whether a data protection contact is published, whether trackers fire before a consent choice, and whether the site is served over HTTPS. No sign-up, no card.

Run a free PDPA scan

Free scan. A full PDF report with the PDPA references and a remediation checklist starts at S$68.

Common questions

Does the PDPA apply to my business if I am not registered in Singapore?

Yes, if you collect, use or disclose personal data in Singapore. The Act attaches to the activity, not to where the organisation is incorporated. An overseas e-commerce store selling to Singapore customers and collecting their names, addresses and payment details is within scope.

Is a data protection officer mandatory for a small company?

Yes. Section 11(3) requires every organisation to designate one or more individuals responsible for ensuring compliance, with no small-business exemption. It can be an existing employee doing it alongside another role, and the responsibility can be delegated under section 11(4). Section 11(5) then requires the business contact information of at least one of those individuals to be publicly available.

How quickly must a data breach be reported to the PDPC?

Section 26D(1) requires notification as soon as practicable and no later than three calendar days after the day you assess the breach to be notifiable. The clock runs from your assessment, not from the breach itself — but section 26C(2) requires that assessment to be made in a reasonable and expeditious manner, so you cannot extend the deadline by delaying it.

What is the maximum PDPA fine?

S$1 million for an organisation whose annual turnover in Singapore is S$10 million or below, and 10% of annual Singapore turnover above that threshold. The five decisions covered here ranged from S$17,500 to S$315,000.

Does the PDPA require a cookie banner?

The Act never mentions cookies. Section 13 requires consent before personal data is collected, used or disclosed, unless consent is deemed under sections 15 to 15A or an exception in the First Schedule applies — so some cookies need no banner at all, and the PDPC's Advisory Guidelines on the PDPA for Selected Topics (revised May 2024) apply deemed consent to cookies in some cases. Analytics, advertising and remarketing tags are the ones that need a real choice, and the First Schedule's legitimate-interests exception is expressly unavailable for direct marketing. A consent mechanism that blocks those tags until a choice is made is the practical way to comply; a banner that does not block anything is not. The longer answer is here.

Method and corrections

Enforcement figures were read from the published decisions. Statutory references were checked against the consolidated Personal Data Protection Act 2012 on Singapore Statutes Online, in the version in force from 5 December 2025.

Scan figures are from our own production database and are stated with the denominator so they can be judged: one row per website, its most recent completed scan, over a window in which a single version of each check was in force throughout.

The sample definition, discovery-source composition, per-check counts and scanner limits are recorded in our dated aggregate record for this report, and every figure here traces to it. We name no scanned organisation and publish no site-level result.

If you believe a figure here is wrong, tell us and we will check it and correct it: hello@sitetals.com. We intend to refresh this report after each significant enforcement batch, and at least twice a year.

Sources

Related reading

EnforcementEvery 2025–2026 PDPC decision, and what each one means for a website operatorAccountabilityAppointing and publishing a DPO under the PDPAConsentDo you need a cookie banner under the PDPA?NotificationThe PDPA privacy policy checklist
Sitetals research team. Sitetals is an independent website compliance scanner operated by QuikForge Limited. We check Singapore websites against the PDPA obligations that are visible from the outside, and publish what the aggregate results show. Every statutory reference in this article was checked against the consolidated Act on Singapore Statutes Online, and every enforcement figure against the published decision itself. Corrections: hello@sitetals.com.