Is your website PDPA compliant?
Singapore's PDPA requires a privacy policy, a DPO contact and valid consent. We check your website against these PDPA requirements. Free. Under 60 seconds.
No sign-up · No card · Results in 60 seconds · No commitment
Since 1 October 2022, the PDPC can impose financial penalties of up to 10% of annual turnover in Singapore (where this exceeds S$10 million), or S$1 million, whichever is higher, for serious breaches.
Enforcement actions are published publicly on the PDPC website.
Full compliance report from S$68. Review it before they do.
Already purchased a full report? Enter your access key →
Compliance clarity in three steps
No plugins. No account. Paste your domain, choose your jurisdiction, and know your compliance risk in under 60 seconds.
Enter your domain
Paste any website address, select your region (EU or Asia-Pacific), then choose the country whose laws apply to your site. We fetch and analyse your pages directly — no plugin or code change required.
Free · No account · Any domainInstant compliance audit
We run the critical checks — cookie consent, legal notices, SSL, data transfer rules and more — against CNIL, RGPD, TDDDG, DSGVO and PDPA. Results in under 60 seconds, with exact legal references for every finding.
60 seconds · 5+ checks per jurisdictionReceive your detailed report
Order a detailed PDF report — professional quality, independent price. Each finding is documented with the exact law article, the affected pages, and a step-by-step fix guide your developer can action the same day.
PDF by email · From S$68 · One paymentmaximum PDPA penalty
in Singapore
have compliance gaps
full compliance report
Understand the risk before it finds you.
Guides on PDPA obligations, what the PDPC expects, and what to fix first on a Singapore website.
Shopify PDPA Compliance Singapore: A Step-by-Step Guide for Merchants
Is My Website GDPR Compliant? The 12 Checks You're Probably Missing
How to Monitor GDPR Compliance Continuously: A Practical Guide
Singapore PDPA guides
Every Singapore guide we publish, in reading order.
- Shopify PDPA compliance for Singapore merchants
- WooCommerce PDPA compliance for Singapore store operators
PDPA questions we are asked most
Short answers with the section of the Act they come from. Each links to the full guide.
What does Singapore's PDPA require of a website?
Three things a website shows on its face. Section 20 requires you to inform individuals of the purposes for collection on or before you collect their personal data — a published privacy policy is the ordinary way a website does that. Section 11(3) requires a designated individual responsible for compliance, and section 11(5) requires that person's business contact information to be published. Collection through trackers needs consent. The PDPA privacy policy checklist →
Do I need a data protection officer under the PDPA?
Yes. Every organisation subject to the PDPA must designate at least one individual responsible for compliance under section 11(3), and there is no small-business exemption. A second, separate duty under section 11(5) requires you to publish that person's business contact information; regulation 1A also allows it to be filed on ACRA's BizFile instead. Designation does not transfer your liability — section 11(6) says so in terms. Appointing and publishing a DPO →
Do I need a cookie banner under the PDPA?
The PDPA does not use the word “cookie”. It regulates the collection of personal data, whatever the technology is called. You need consent — given or deemed — before collection for any tracker that collects personal data, which most analytics and advertising tags do. Deemed consent under section 15 rarely stretches to third-party analytics and advertising, so in practice those need a mechanism. A banner that appears after the tags have already loaded records a click, not a consent. Cookie banners under the PDPA →
Does the PDPA apply if my business is not in Singapore?
The PDPA can apply to a business with no presence in Singapore. It follows the activity, not the incorporation: if you collect personal data in Singapore it applies, with no office, no entity and no local server required. Your data protection officer does not have to be in Singapore either — section 11(3) requires a designated individual and says nothing about residence. GDPR compliance does not carry over. PDPA for businesses outside Singapore →
Can I send personal data collected in Singapore overseas?
Yes, subject to conditions. The PDPA does not ban sending personal data overseas — section 26 permits it subject to prescribed requirements. Regulation 10(1) requires you to take appropriate steps to ascertain and ensure the recipient is bound by legally enforceable obligations providing protection at least comparable to the Act: law, a contract meeting regulation 11(2), binding corporate rules, or another legally binding instrument. There is also a certification route: as of 2 March 2026 it covers the Global CBPR and Global PRP systems as well as the APEC ones. Cross-border transfers under the PDPA →
What does the free Singapore scan check, and what are its limits?
The free scan reads the pages your server returns and reports what is externally visible: whether a privacy policy can be found, whether a data protection contact is published on the site, and whether tracker code loads with no consent mechanism present. A finding is something we could see from outside; it is not a determination that the PDPA has been contravened. Sitetals is an independent compliance research service, not a law firm, and its reports are not legal opinions. For formal legal advice, consult a qualified practitioner familiar with the PDPA.
Detailed reports from S$68.
No subscription.
Pay once for a full PDF compliance report with page-by-page findings and legal references. Plans for sites of all sizes.
See all plans →