How it works What We Check Pricing For Individuals Articles About My Report Free Scan →
Singapore PDPA Compliance Scanner

Is your website PDPA compliant?

Singapore's PDPA requires a privacy policy, a DPO contact and valid consent. We check your website against these PDPA requirements. Free. Under 60 seconds.

1Choose region
2Choose country
3Enter your website

No sign-up · No card · Results in 60 seconds · No commitment

Since 1 October 2022, the PDPC can impose financial penalties of up to 10% of annual turnover in Singapore (where this exceeds S$10 million), or S$1 million, whichever is higher, for serious breaches.
Enforcement actions are published publicly on the PDPC website.
Full compliance report from S$68. Review it before they do.

Already purchased a full report? Enter your access key →

Live Data
reachable websites analysed

not compliant
Results in 60 seconds No account required CNIL, German DPAs & PDPC enforcement-aligned No-commitment scan
PDPA Singapore PDPC Advisory 2021

Compliance clarity in three steps

No plugins. No account. Paste your domain, choose your jurisdiction, and know your compliance risk in under 60 seconds.

1

Enter your domain

Paste any website address, select your region (EU or Asia-Pacific), then choose the country whose laws apply to your site. We fetch and analyse your pages directly — no plugin or code change required.

Free · No account · Any domain
2

Instant compliance audit

We run the critical checks — cookie consent, legal notices, SSL, data transfer rules and more — against CNIL, RGPD, TDDDG, DSGVO and PDPA. Results in under 60 seconds, with exact legal references for every finding.

60 seconds · 5+ checks per jurisdiction
3

Receive your detailed report

Order a detailed PDF report — professional quality, independent price. Each finding is documented with the exact law article, the affected pages, and a step-by-step fix guide your developer can action the same day.

PDF by email · From S$68 · One payment
10%
Of annual turnover in Singapore
maximum PDPA penalty
S$1M
Max PDPA fine
in Singapore
Of scanned websites
have compliance gaps
S$68
Cost of your
full compliance report

PDPA questions we are asked most

Short answers with the section of the Act they come from. Each links to the full guide.

What does Singapore's PDPA require of a website?

Three things a website shows on its face. Section 20 requires you to inform individuals of the purposes for collection on or before you collect their personal data — a published privacy policy is the ordinary way a website does that. Section 11(3) requires a designated individual responsible for compliance, and section 11(5) requires that person's business contact information to be published. Collection through trackers needs consent. The PDPA privacy policy checklist →

Do I need a data protection officer under the PDPA?

Yes. Every organisation subject to the PDPA must designate at least one individual responsible for compliance under section 11(3), and there is no small-business exemption. A second, separate duty under section 11(5) requires you to publish that person's business contact information; regulation 1A also allows it to be filed on ACRA's BizFile instead. Designation does not transfer your liability — section 11(6) says so in terms. Appointing and publishing a DPO →

Do I need a cookie banner under the PDPA?

The PDPA does not use the word “cookie”. It regulates the collection of personal data, whatever the technology is called. You need consent — given or deemed — before collection for any tracker that collects personal data, which most analytics and advertising tags do. Deemed consent under section 15 rarely stretches to third-party analytics and advertising, so in practice those need a mechanism. A banner that appears after the tags have already loaded records a click, not a consent. Cookie banners under the PDPA →

Does the PDPA apply if my business is not in Singapore?

The PDPA can apply to a business with no presence in Singapore. It follows the activity, not the incorporation: if you collect personal data in Singapore it applies, with no office, no entity and no local server required. Your data protection officer does not have to be in Singapore either — section 11(3) requires a designated individual and says nothing about residence. GDPR compliance does not carry over. PDPA for businesses outside Singapore →

Can I send personal data collected in Singapore overseas?

Yes, subject to conditions. The PDPA does not ban sending personal data overseas — section 26 permits it subject to prescribed requirements. Regulation 10(1) requires you to take appropriate steps to ascertain and ensure the recipient is bound by legally enforceable obligations providing protection at least comparable to the Act: law, a contract meeting regulation 11(2), binding corporate rules, or another legally binding instrument. There is also a certification route: as of 2 March 2026 it covers the Global CBPR and Global PRP systems as well as the APEC ones. Cross-border transfers under the PDPA →

What does the free Singapore scan check, and what are its limits?

The free scan reads the pages your server returns and reports what is externally visible: whether a privacy policy can be found, whether a data protection contact is published on the site, and whether tracker code loads with no consent mechanism present. A finding is something we could see from outside; it is not a determination that the PDPA has been contravened. Sitetals is an independent compliance research service, not a law firm, and its reports are not legal opinions. For formal legal advice, consult a qualified practitioner familiar with the PDPA.

Detailed reports from S$68.
No subscription.

Pay once for a full PDF compliance report with page-by-page findings and legal references. Plans for sites of all sizes.

See all plans →