🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
SG v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 3 failing30 sources retrieved model claude-sonnet-5 · 2026-07-29

Singapore

SG schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated update date not yet available · 10 categories · 59 claims · 39 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
59Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 13 sub-modules are flagged red.

Jurisdiction brief

Standing brief, as of 29 July 2026.

Lead Signal

The Personal Data Protection Commission fined People Central Pte Ltd S$17,500 on 8 January 2026 for failing to implement reasonable security arrangements under the Protection Obligation. This follows an October 2025 penalty against Marina Bay Sands Pte Ltd for a negligent contravention of the same obligation, linked to a six-month window in which data went unprotected. Both decisions sit under the enhanced penalty regime in force since 1 October 2022, which permits fines of up to 10% of Singapore turnover, or S$1 million, whichever is higher, for organisations above S$10 million in turnover.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Mature, well-documented omnibus statute with a single clearly identified regulator and settled extraterritorial scope.

Primary frameworkPersonal Data Protection Act 2012 (No. 26 of 2012), as amended
Traffic-light rationale — GreenMature, well-documented omnibus statute with a single clearly identified regulator and settled extraterritorial scope.

Sub-modules (5)

Regulator And AuthorityGreen

PDPC is the statutory enforcement authority, operating under IMDA since 2016.

Claims (2):

  • The Personal Data Protection Commission (PDPC) is empowered to investigate and enforce the PDPA provisions.
  • The PDPC was subsumed into the Info-communications Media Development Authority (IMDA) with effect from 1 October 2016.

Act And InstrumentsGreen

Core instrument is the PDPA 2012, last comprehensively amended in November 2020 with provisions phased in through 2021-2022, alongside the Spam Control Act for the Do Not Call regime.

Claims (1):

  • The Personal Data Protection Act 2012 (No. 26 of 2012) and the Spam Control Act 2007 were amended by Parliament in November 2020, with amendments including mandatory breach notification taking effect from 1 February 2021.

Material ScopeGreen

Material scope covers private-sector collection, use and disclosure of personal data; public agencies sit outside the PDPA under a separate governance statute.

Claims (1):

  • The PDPA applies only to private sector organisations; processing of personal data by public sector agencies is governed separately under the Public Sector (Governance) Act 2018.

Territorial ScopeGreen

Extraterritorial reach captures overseas organisations processing personal data in Singapore regardless of incorporation or residence.

Claims (1):

  • The PDPA has an extraterritorial scope and applies to overseas organisations that collect, use, or disclose personal data within Singapore, regardless of place of incorporation or residence.

Regulator Registration And FilingAmber

No general PDPC registration/filing regime exists; the principal filing-adjacent obligation is mandatory public DPO contact details.

Claims (1):

  • All organisations subject to the PDPA are required to appoint a Data Protection Officer (DPO) and make the DPO's business contact information publicly available.
Category narrative136 words

Singapore's omnibus regime is the Personal Data Protection Act 2012 (No. 26 of 2012, 'PDPA'), administered by the Personal Data Protection Commission (PDPC). <cite index="58-1">The PDPC is empowered to investigate and enforce the PDPA provisions.</cite> <cite index="51-18">With effect from 1 October 2016, the PDPC was subsumed into the IMDA, which is a statutory body under the Ministry of Communication and Information.</cite> <cite index="40-5">The PDPA applies only to private sector companies, as the processing of personal data by public sector bodies is governed by another law called the Public Sector Governance Act 2018.</cite> <cite index="40-3">PDPA has an extraterritorial scope similar to GDPR, and it applies to overseas organizations that collect, use, or disclose data within Singapore.</cite> <cite index="35-3">Under the PDPA, all organisations are required to appoint a DPO, whose business contact information must be made publicly available.</cite>

no periodic updates on record for this sub-brief

Sources and claims (6)
  1. ConfirmedPersonal Data Protection Commission — The Personal Data Protection Commission (PDPC) is empowered to investigate and enforce the PDPA provisions.observed
  2. ConfirmedOneTrust DataGuidance — The PDPC was subsumed into the Info-communications Media Development Authority (IMDA) with effect from 1 October 2016.observed
  3. ConfirmedOneTrust DataGuidance — The Personal Data Protection Act 2012 (No. 26 of 2012) and the Spam Control Act 2007 were amended by Parliament in November 2020, with amendments including mandatory breach notification taking effect from 1 February 2021.observed
  4. ConfirmedarXiv — The PDPA applies only to private sector organisations; processing of personal data by public sector agencies is governed separately under the Public Sector (Governance) Act 2018.observed
  5. ConfirmedarXiv — The PDPA has an extraterritorial scope and applies to overseas organisations that collect, use, or disclose personal data within Singapore, regardless of place of incorporation or residence.observed
  6. ConfirmedOneTrust DataGuidance — All organisations subject to the PDPA are required to appoint a Data Protection Officer (DPO) and make the DPO's business contact information publicly available.observed

#

Consent-based model with wide statutory exemptions rather than an enumerated GDPR Art 6-style lawful-basis list, and no distinct special-category regime.

Primary frameworkPersonal Data Protection Act 2012, as amended
Traffic-light rationale — AmberConsent-based model with wide statutory exemptions rather than an enumerated GDPR Art 6-style lawful-basis list, and no distinct special-category regime.

Sub-modules (4)

Lawful BasesAmber

Consent is the default basis, displaced by broad statutory exemption schedules functioning analogously to alternative lawful bases.

Claims (1):

  • Under Section 13 of the PDPA, collection, use or disclosure of personal data is prohibited unless the individual gives or is deemed to have given consent, subject to broad exemptions set out in the Second, Third and Fourth Schedules.

Special CategoriesAmber

No GDPR-style enumerated special category list; sensitivity is assessed contextually, with a dedicated national-ID-number regime functioning as a quasi-sensitive-identifier rule.

Claims (2):

  • Unlike the GDPR, the PDPA does not create a distinct statutory category of 'special' or sensitive personal data, instead relying on consent centrality and case-by-case sensitivity assessment by the PDPC.
  • Organisations may only collect, use or disclose NRIC numbers or copies of the NRIC (and equivalent national identification numbers) where required by law or necessary to verify identity to a high degree of accuracy.

Pseudonymisation And AnonymisationAmber

Anonymisation is protected via criminal offences for re-identification rather than a dedicated anonymisation safe-harbour standard.

Claims (1):

  • Part 9B of the PDPA creates offences for knowing or reckless unauthorised disclosure or wrongful use of personal data, and for re-identification of anonymised data.
Category narrative203 words

The PDPA is consent-centric but carves out very broad exemptions. <cite index="49-14,49-15,49-16">Consent is not required under the PDPA if the data processing falls within the purview of the Section 17 exemptions, which cover collection, use and disclosure without consent in circumstances set out in the Second, Third and Fourth Schedules.</cite> <cite index="49-6">The PDPA prohibits an organization from requiring an individual to consent to the collection, use or disclosure of personal data about the individual beyond what is reasonable to provide the product or service to that individual.</cite> Unlike the GDPR, <cite index="43-18">the PDPA does not distinguish specific categories of personal data, it does deem the consent of the individual as central and necessary before commencing data processing activities.</cite> A quasi-sensitive-identifier regime exists for national identification numbers: <cite index="80-2">private sector organisations are only allowed to collect, use or disclose NRIC numbers or copies of the NRIC if the collection, use or disclosure is required by the law, or it is necessary to establish or verify an individual's identity to a high degree of accuracy.</cite> Anonymisation is addressed through offence provisions: <cite index="99-19,99-20">Part 9B of the PDPA sets out offences that hold individuals accountable for egregious mishandling of personal data, including re-identification of anonymised data.</cite>

no periodic updates on record for this sub-brief

Sources and claims (5)
  1. ConfirmedInternational Association of Privacy Professionals — Under Section 13 of the PDPA, collection, use or disclosure of personal data is prohibited unless the individual gives or is deemed to have given consent, subject to broad exemptions set out in the Second, Third and Fourth Schedules.observed
  2. ConfirmedInternational Association of Privacy Professionals — The PDPA prohibits an organisation from requiring an individual, as a condition of providing a product or service, to consent to collection, use or disclosure of personal data beyond what is reasonable, and consent may be withdrawn at any time with immediate cessation of the relevant processing.observed
  3. ConfirmedOneTrust DataGuidance — Unlike the GDPR, the PDPA does not create a distinct statutory category of 'special' or sensitive personal data, instead relying on consent centrality and case-by-case sensitivity assessment by the PDPC.observed
  4. ConfirmedPersonal Data Protection Commission — Organisations may only collect, use or disclose NRIC numbers or copies of the NRIC (and equivalent national identification numbers) where required by law or necessary to verify identity to a high degree of accuracy.observed
  5. ConfirmedPersonal Data Protection Commission — Part 9B of the PDPA creates offences for knowing or reckless unauthorised disclosure or wrongful use of personal data, and for re-identification of anonymised data.observed

#

Access, correction and portability rights exist but there is no erasure right and no formal restriction-of-processing right analogous to GDPR Art 18.

Primary frameworkPersonal Data Protection Act 2012, as amended
Traffic-light rationale — AmberAccess, correction and portability rights exist but there is no erasure right and no formal restriction-of-processing right analogous to GDPR Art 18.

Sub-modules (5)

Access RightAmber

Statutory access right limited to a one-year lookback window, subject to exceptions.

Claims (1):

  • Under Section 21 of the PDPA, individuals may request access to their personal data held by an organisation and information about its use or disclosure in the year preceding the request.

Rectification And ErasureRed

Correction right exists; no erasure/right-to-be-forgotten equivalent.

Claims (1):

  • The PDPA provides individuals a right to request correction of errors or omissions in their personal data under Section 22, but does not provide a right to request erasure or deletion of personal data.

Restriction And ObjectionAmber

No explicit restriction-of-processing right; functional equivalent is consent withdrawal.

Claims (1):

  • Individuals may withdraw consent for collection, use or disclosure of their personal data at any time, with reasonable notice, obliging the organisation to cease the relevant processing.

Data PortabilityAmber

Portability Obligation limited to electronic records and to recipients with a Singapore presence.

Claims (1):

  • The Data Portability Obligation requires organisations, upon request, to transmit an individual's data held in electronic form to another organisation with a presence in Singapore in a commonly used machine-readable format.

Deadlines And Response WindowsGreen

30-day response window for access/correction; 3-calendar-day breach notification window to PDPC post-determination.

Claims (2):

  • Organisations that cannot provide requested personal data or make a correction within 30 days of a request must inform the individual in writing within 30 days of the time by which they will respond.
  • Where a data breach is determined to be notifiable, notification to the PDPC must be made no later than three calendar days after the organisation determines the breach is notifiable.
Category narrative192 words

Data subject rights are narrower than under GDPR. <cite index="49-24">Section 21 of the PDPA allows an individual to request access to personal data held by an organization and to information concerning its use or disclosure in the preceding one year.</cite> <cite index="43-13">The PDPA does not provide data subjects with the right to request the erasure or deletion of their personal data.</cite> A Data Portability Obligation exists: <cite index="36-3">upon request, organisations must transmit the individual's data in their possession or under their control to another organisation in a commonly used machine-readable format,</cite> though <cite index="37-4,37-5">the porting organisation must determine whether a receiving organisation has a presence in Singapore, limiting the obligation to receiving organisations with a Singapore presence.</cite> Response deadlines are prescribed: <cite index="52-18">if the organisation is unable to provide the personal data or make the correction requested within 30 days after receiving the request, the organisation must inform the individual, in writing, within 30 days, of the time by which it will respond.</cite> <cite index="22-21,22-23">Notification to PDPC must be made no later than three calendar days after determining the breach is notifiable, with the deadline starting from the time of that determination.</cite>

no periodic updates on record for this sub-brief

Sources and claims (6)
  1. ConfirmedInternational Association of Privacy Professionals — Under Section 21 of the PDPA, individuals may request access to their personal data held by an organisation and information about its use or disclosure in the year preceding the request.observed
  2. ConfirmedInternational Association of Privacy Professionals — The PDPA provides individuals a right to request correction of errors or omissions in their personal data under Section 22, but does not provide a right to request erasure or deletion of personal data.observed
  3. ConfirmedInternational Association of Privacy Professionals — Individuals may withdraw consent for collection, use or disclosure of their personal data at any time, with reasonable notice, obliging the organisation to cease the relevant processing.observed
  4. ConfirmedPersonal Data Protection Commission — The Data Portability Obligation requires organisations, upon request, to transmit an individual's data held in electronic form to another organisation with a presence in Singapore in a commonly used machine-readable format.observed
  5. ConfirmedPersonal Data Protection Commission — Organisations that cannot provide requested personal data or make a correction within 30 days of a request must inform the individual in writing within 30 days of the time by which they will respond.observed
  6. ConfirmedPersonal Data Protection Commission — Where a data breach is determined to be notifiable, notification to the PDPC must be made no later than three calendar days after the organisation determines the breach is notifiable.observed

#

Protection, breach notification, retention and DPO duties are robust and enforced, but there is no formal Records-of-Processing-Activities (ROPA) obligation equivalent to GDPR Art 30.

Primary frameworkPersonal Data Protection Act 2012, as amended
Traffic-light rationale — AmberProtection, breach notification, retention and DPO duties are robust and enforced, but there is no formal Records-of-Processing-Activities (ROPA) obligation equivalent to GDPR Art 30.

Sub-modules (7)

Accountability And DpiaAmber

Accountability is now an explicit statutory principle; DPIA-style analysis is triggered only for specific consent exceptions rather than as a general obligation.

Claims (2):

  • The accountability principle, initially implied in Sections 11 and 12 of the PDPA, was made an explicit statutory reference through the 2020 amendments.
  • The PDPA requires organisations to conduct a form of impact assessment when relying on the legitimate interests exception or on deemed consent by notification, though it does not impose a general DPIA obligation equivalent to GDPR Article 35.

Dpo RequirementsAmber

Mandatory DPO appointment applies to every organisation, without GDPR-style independence or qualification criteria.

Claims (1):

  • Although the DPO is not required to be physically present in Singapore, the PDPC expects the DPO to be readily reachable from Singapore and operational during Singapore business hours; the PDPA, unlike the GDPR, does not define specific independence or qualification criteria for the DPO role.

Ropa RequirementsRed

No dedicated Records-of-Processing-Activities obligation was identified in the PDPA or PDPC guidance; the accountability obligation requires internal policies and practices documentation but not a formal register.

Absence provenance: unavailable. Searched: PDPC ROPA records of processing activities requirement, PDPA accountability obligation register of processing.

Joint Controller ArrangementsGreen

Controller-processor liability flows through the controller for data intermediaries; a processor exceeding instructions assumes full Data Protection Provisions liability.

Claims (1):

  • An organisation has the same obligations for personal data processed on its behalf by a data intermediary as if the organisation processed the data itself, but a data intermediary that exercises its own judgement beyond the controller's instructions becomes subject to the full Data Protection Provisions for that processing.

Security MeasuresGreen

The Protection Obligation mandates reasonable technical and organisational security arrangements.

Claims (1):

  • The Protection Obligation under Section 24 of the PDPA requires organisations to make reasonable security arrangements to prevent unauthorised access, collection, use, disclosure, copying, modification or disposal of personal data.

Breach NotificationGreen

Mandatory breach notification is triggered by significant-harm or 500+-individual thresholds, with sector-specific overlay for MAS-regulated financial institutions.

Claims (2):

  • A data breach is notifiable to the PDPC and affected individuals if it is likely to result in significant harm to affected individuals or affects 500 or more individuals.
  • Financial institutions must separately report data breaches to the Monetary Authority of Singapore where the breach has a severe and widespread impact on the institution's operations or materially affects services to customers.

Retention And DisposalGreen

Retention Limitation Obligation requires cessation of retention once the collection purpose is no longer served.

Claims (1):

  • The Retention Limitation Obligation under Section 25 requires an organisation to cease retaining documents containing personal data, or remove the means of associating the data with an individual, as soon as the retention purpose is no longer served and retention is no longer necessary for legal or business purposes.
Category narrative270 words

Accountability is explicit: <cite index="8-15">while the principle of accountability is currently implied in Sections 11 and 12 of the PDPA, the amendments include an explicit reference to the term accountability.</cite> DPIA-type analysis is required only contextually: <cite index="46-21">the PDPA requires data controllers to conduct DPIAs when seeking to collect, use or disclose personal data without express consent and are seeking to rely either on the legitimate interests exception, or deemed consent by notification.</cite> DPO appointment is universal, though: <cite index="35-4">the DPO is not required to be physically present in Singapore, but should be readily reachable from Singapore and operational during Singapore business hours,</cite> and <cite index="46-25">unlike the GDPR, the PDPA does not provide a definition of a DPO.</cite> Processor obligations flow through the controller: <cite index="35-5">the PDPA provides that an organisation will have the same obligations in respect of personal data processed on its behalf and for its purposes by a data intermediary as if the personal data were processed by the organisation itself.</cite> <cite index="56-12">The Protection Obligation under Section 24 requires organizations to make reasonable security arrangements to protect personal data in order to prevent unauthorized access, collection, use, disclosure, copying, modification, disposal or similar risks.</cite> Breach notification: <cite index="22-11">the PDPA requires organisations to notify when a breach is likely to result in significant harm to individuals or when it affects 500 or more individuals.</cite> <cite index="56-13">The Retention Limitation Obligation under Section 25 requires an organization to cease to retain documents containing personal data as soon as it is reasonable to assume that the purpose for which that personal data was collected is no longer being served by retention.</cite>

no periodic updates on record for this sub-brief

Sources and claims (8)
  1. ConfirmedOneTrust DataGuidance — The accountability principle, initially implied in Sections 11 and 12 of the PDPA, was made an explicit statutory reference through the 2020 amendments.observed
  2. ProbableOneTrust DataGuidance — The PDPA requires organisations to conduct a form of impact assessment when relying on the legitimate interests exception or on deemed consent by notification, though it does not impose a general DPIA obligation equivalent to GDPR Article 35.observed
  3. ConfirmedOneTrust DataGuidance — Although the DPO is not required to be physically present in Singapore, the PDPC expects the DPO to be readily reachable from Singapore and operational during Singapore business hours; the PDPA, unlike the GDPR, does not define specific independence or qualification criteria for the DPO role.observed
  4. ConfirmedPersonal Data Protection Commission — An organisation has the same obligations for personal data processed on its behalf by a data intermediary as if the organisation processed the data itself, but a data intermediary that exercises its own judgement beyond the controller's instructions becomes subject to the full Data Protection Provisions for that processing.observed
  5. ConfirmedInternational Association of Privacy Professionals — The Protection Obligation under Section 24 of the PDPA requires organisations to make reasonable security arrangements to prevent unauthorised access, collection, use, disclosure, copying, modification or disposal of personal data.observed
  6. ConfirmedPersonal Data Protection Commission — A data breach is notifiable to the PDPC and affected individuals if it is likely to result in significant harm to affected individuals or affects 500 or more individuals.observed
  7. ProbablePersonal Data Protection Commission — Financial institutions must separately report data breaches to the Monetary Authority of Singapore where the breach has a severe and widespread impact on the institution's operations or materially affects services to customers.observed
  8. ConfirmedInternational Association of Privacy Professionals — The Retention Limitation Obligation under Section 25 requires an organisation to cease retaining documents containing personal data, or remove the means of associating the data with an individual, as soon as the retention purpose is no longer served and retention is no longer necessary for legal or business purposes.observed

#

Transfer regime is mature with recognised certification schemes (APEC CBPR/PRP) and model clauses, though Singapore is not a recipient of an EU adequacy decision.

Primary frameworkPersonal Data Protection Act 2012, as amended (Transfer Limitation Obligation, s.26)
Traffic-light rationale — GreenTransfer regime is mature with recognised certification schemes (APEC CBPR/PRP) and model clauses, though Singapore is not a recipient of an EU adequacy decision.

Sub-modules (6)

Transfer MechanismsGreen

Comparable-protection standard under s.26, satisfiable via contract, consent, or recognised certification schemes.

Claims (2):

  • Section 26 of the PDPA prohibits an organisation from transferring personal data outside Singapore except where it can ensure a standard of protection comparable to the PDPA is maintained over the transferred data.
  • Since June 2020, the Personal Data Protection Regulations recognise APEC Cross-Border Privacy Rules (CBPR) and Privacy Recognition for Processors (PRP) system certifications as a basis for compliance with the Transfer Limitation Obligation for overseas transfers.

Adequacy ReceivedRed

No confirmed record of Singapore receiving a formal adequacy-style determination from another regime (e.g., EU) was found in this pass.

Absence provenance: unavailable. Searched: Singapore EU adequacy decision GDPR, Singapore adequacy determination received.

Adequacy GrantedAmber

PDPC does not operate a GDPR-style adequacy-list mechanism; instead it relies on recognised certification (APEC CBPR/PRP) and contractual mechanisms as functional equivalents.

Absence provenance: unavailable. Searched: PDPC adequacy list granted third countries.

Sccs And BcrsGreen

ASEAN Model Contractual Clauses (tailored by PDPC) and APEC CBPR/PRP certifications function as the primary standard-clause/certification mechanisms.

Claims (1):

  • The PDPC has published guidance on tailoring the ASEAN Model Contractual Clauses (MCCs) to meet Singapore's Transfer Limitation Obligation requirements, and provides sample clauses for contracts with overseas recipients holding Global/APEC CBPR or PRP certification.

Transfer Impact AssessmentAmber

No codified TIA methodology; due diligence obligation is placed on the transferring organisation.

Claims (1):

  • The onus is on the transferring organisation to undertake appropriate due diligence and obtain assurances that an overseas recipient can maintain a standard of protection comparable to the PDPA before transferring personal data outside Singapore.

Data LocalisationGreen

No general data localisation mandate; recent EU-SG trade agreement further constrains unjustified localisation requirements.

Claims (1):

  • The EU-Singapore Digital Trade Agreement, which entered into force on 1 February 2026, prohibits unjustified data localisation requirements between the parties.
Category narrative206 words

<cite index="31-3,31-4">Section 26 of the PDPA limits the ability of an organization to transfer personal data outside Singapore; section 26(1) provides that an organization must not transfer any personal data outside Singapore except where it can ensure that a comparable standard of protection, as provided for under the PDPA, will be maintained.</cite> <cite index="51-25,51-26">Singapore is a participant of the APEC CBPR and PRP System, and in June 2020, the Personal Data Protection Regulations 2014 was amended to recognise the APEC CBPR and PRP system certifications for overseas transfers of personal data under the PDPA.</cite> <cite index="39-1,39-2">The PDPC has published guidance on how to tailor the ASEAN Model Contractual Clauses to meet Singapore's PDPC requirements, including sample clauses for contracts with overseas recipients holding Global/APEC CBPR/PRP certification.</cite> <cite index="34-1,34-2">The Transfer Limitation Obligation requires that an organisation ensures that personal data transferred overseas is protected to a standard comparable with the Data Protection Provisions, with the onus on the transferring organisation to undertake appropriate due diligence.</cite> No EU adequacy decision covering Singapore was located in this research pass. Data localisation is generally not mandated, and <cite index="5-7">the EU-Singapore Digital Trade Agreement entered into force on February 1, 2026, enhancing online consumer protection and prohibiting unjustified data localization requirements.</cite>

no periodic updates on record for this sub-brief

Sources and claims (5)
  1. ConfirmedInternational Association of Privacy Professionals — Section 26 of the PDPA prohibits an organisation from transferring personal data outside Singapore except where it can ensure a standard of protection comparable to the PDPA is maintained over the transferred data.observed
  2. ConfirmedOneTrust DataGuidance — Since June 2020, the Personal Data Protection Regulations recognise APEC Cross-Border Privacy Rules (CBPR) and Privacy Recognition for Processors (PRP) system certifications as a basis for compliance with the Transfer Limitation Obligation for overseas transfers.observed
  3. ConfirmedPersonal Data Protection Commission — The PDPC has published guidance on tailoring the ASEAN Model Contractual Clauses (MCCs) to meet Singapore's Transfer Limitation Obligation requirements, and provides sample clauses for contracts with overseas recipients holding Global/APEC CBPR or PRP certification.observed
  4. ConfirmedPersonal Data Protection Commission — The onus is on the transferring organisation to undertake appropriate due diligence and obtain assurances that an overseas recipient can maintain a standard of protection comparable to the PDPA before transferring personal data outside Singapore.observed
  5. ProbableOneTrust DataGuidance — The EU-Singapore Digital Trade Agreement, which entered into force on 1 February 2026, prohibits unjustified data localisation requirements between the parties.observed

#

Strong financial-sector and telecom-marketing overlays; credit-scoring and insurance-specific data rules could not be confirmed with primary sourcing.

Primary frameworkPersonal Data Protection Act 2012, overlaid by MAS Notices/Guidelines (financial) and sector-specific bills (health)
Traffic-light rationale — AmberStrong financial-sector and telecom-marketing overlays; credit-scoring and insurance-specific data rules could not be confirmed with primary sourcing.

Sub-modules (7)

Financial Sector OverlayGreen

MAS overlays PDPA with outsourcing, technology-risk, and data-governance guidelines for financial institutions; co-regulation exists alongside the PDPC.

Claims (2):

  • The Monetary Authority of Singapore's Guidelines on Outsourcing Risk Management, issued 27 July 2016, set MAS expectations for financial institutions entering outsourcing arrangements, including those involving customer information.
  • MAS issued guidance on 29 May 2024 setting supervisory expectations for banks and finance companies to establish data governance frameworks addressing data quality, risk aggregation and risk reporting, informed by Basel Committee principles.

Health Sector OverlayAmber

A Health Information Bill introduces a dedicated framework for health data management; enactment/commencement status requires confirmation.

Claims (1):

  • Singapore's Health Information Bill establishes a framework for health data management, defining roles, data-sharing protocols and penalties for non-compliance.

Telecoms And EprivacyGreen

DNC provisions of the PDPA function as Singapore's direct-marketing/telecom-privacy overlay; IMDA separately regulates telecom licensees.

Claims (1):

  • The Do Not Call (DNC) provisions of the PDPA prohibit organisations from sending marketing voice calls, text messages or faxes to Singapore telephone numbers registered on the DNC Registry.

Employment DataGreen

Employment-purpose processing requires notification under s.20(4), satisfiable via general notice channels.

Claims (1):

  • Under Section 20(4) of the PDPA, an organisation collecting, using or disclosing personal data for managing or terminating an employment relationship must inform the individual of that purpose, and PDPC guidance permits general notification via employment contracts, handbooks or intranet notices.

Credit And ScoringRed

No PDPA-specific credit-scoring regime was located in this research pass.

Absence provenance: unavailable. Searched: Singapore PDPA credit scoring regulation, PDPC credit bureau data protection.

EducationGreen

Private education institutions may collect NRIC numbers to satisfy record-keeping regulations.

Claims (1):

  • Registered private education institutions may collect NRIC numbers from enrolled students where required to keep proper records under the Private Education Regulations.

InsuranceRed

No dedicated PDPA insurance-sector overlay was confirmed; stakeholder consultation responses reference interactions between minors' consent rules and insurance contract law but do not establish a standalone regime.

Absence provenance: unavailable. Searched: Singapore PDPA insurance sector data protection overlay, MAS insurance data protection notice.

Category narrative210 words

Financial services carry a substantive MAS overlay: <cite index="91-2,91-3,91-4">the Monetary Authority of Singapore issued Guidelines on Outsourcing Risk Management on 27 July 2016, including under certain circumstances arrangements involving customer information, setting MAS expectations of institutions entering outsourcing arrangements.</cite> <cite index="94-3,94-4">MAS issued guidance on 29 May 2024 for banks and finance companies to enhance data governance and management practices, emphasizing a data governance framework and board oversight, aligning with Basel Committee principles.</cite> Health data is addressed by a dedicated bill: <cite index="95-7">the Health Information Bill establishes a framework for health data management, defining roles, data sharing protocols, and penalties for non-compliance.</cite> Telecom-adjacent marketing is governed by the PDPA's own Do Not Call regime: <cite index="81-1,81-5">the DNC provisions of the PDPA generally prohibit organisations from sending marketing messages -- voice calls, text or fax messages -- to Singapore telephone numbers listed in the DNC Registry.</cite> Employment-context notice is streamlined: <cite index="30-16">PDPC's Advisory Guidelines clarify that it may be sufficient to provide general notification to employees such as through employment contracts, employee handbooks, or notices in the company intranet.</cite> In education, <cite index="73-8,73-9">registered private education institutions are required to keep proper records of enrolled students' NRIC numbers under the Private Education Regulations.</cite> Credit-scoring and insurance-specific overlays were not confirmed in this pass.

no periodic updates on record for this sub-brief

Sources and claims (6)
  1. ConfirmedOneTrust DataGuidance — The Monetary Authority of Singapore's Guidelines on Outsourcing Risk Management, issued 27 July 2016, set MAS expectations for financial institutions entering outsourcing arrangements, including those involving customer information.observed
  2. ConfirmedOneTrust DataGuidance — MAS issued guidance on 29 May 2024 setting supervisory expectations for banks and finance companies to establish data governance frameworks addressing data quality, risk aggregation and risk reporting, informed by Basel Committee principles.observed
  3. UncertainOneTrust DataGuidance — Singapore's Health Information Bill establishes a framework for health data management, defining roles, data-sharing protocols and penalties for non-compliance.observed
  4. ConfirmedPersonal Data Protection Commission — The Do Not Call (DNC) provisions of the PDPA prohibit organisations from sending marketing voice calls, text messages or faxes to Singapore telephone numbers registered on the DNC Registry.observed
  5. ConfirmedPersonal Data Protection Commission — Under Section 20(4) of the PDPA, an organisation collecting, using or disclosing personal data for managing or terminating an employment relationship must inform the individual of that purpose, and PDPC guidance permits general notification via employment contracts, handbooks or intranet notices.observed
  6. ConfirmedPersonal Data Protection Commission — Registered private education institutions may collect NRIC numbers from enrolled students where required to keep proper records under the Private Education Regulations.observed

#

Direct marketing/DNC regime is mature and enforced; cookie guidance exists but was not substantively verified, and dark-pattern/cross-context-advertising concepts are absent from the PDPA framework.

Primary frameworkPersonal Data Protection Act 2012, as amended (Do Not Call provisions, Part IX)
Traffic-light rationale — AmberDirect marketing/DNC regime is mature and enforced; cookie guidance exists but was not substantively verified, and dark-pattern/cross-context-advertising concepts are absent from the PDPA framework.

Sub-modules (6)

Cookies And TrackersAmber

PDPC Advisory Guidelines on Selected Topics address cookie consent and ad-targeting questions; substantive positions were not independently verified in this pass.

Claims (1):

  • The PDPC's Advisory Guidelines on the PDPA for Selected Topics address whether consent must be obtained for the use of cookies and whether cookies may be used for targeted advertising.

Dark PatternsRed

No PDPA-specific dark-pattern prohibition was located.

Absence provenance: unavailable. Searched: Singapore PDPA dark patterns prohibition, PDPC deceptive design guidance.

Opt Out SignalsGreen

DNC Registry functions as Singapore's principal opt-out signal mechanism for telemarketing.

Claims (1):

  • The Do Not Call Registry allows individuals to register their Singapore telephone number to opt out of receiving unwanted marketing voice calls, text messages and faxes.

Clean Rooms And DcrRed

No PDPC guidance on data clean rooms or data-collaboration rooms was located.

Absence provenance: unavailable. Searched: Singapore PDPC data clean room guidance.

Cross Context AdvertisingRed

PDPA has no CPRA-style 'sale'/'share' construct for cross-context behavioural advertising.

Absence provenance: unavailable. Searched: Singapore PDPA cross-context advertising sale share concept.

Direct MarketingGreen

DNC provisions and their offence/penalty structure form the core direct-marketing consent and suppression regime.

Claims (2):

  • A person or organisation that sends telemarketing messages to a Singapore telephone number without checking the DNC Registry, absent a relevant exception, commits an offence and is liable to a fine of up to US$10,000 per message sent.
  • Organisations do not need to check the DNC Registry before sending marketing messages where they have the recipient's clear and unambiguous consent to receive such messages at that Singapore telephone number.
Category narrative164 words

Direct marketing is governed by the PDPA's own DNC regime rather than a distinct ePrivacy statute. <cite index="82-3">The Do Not Call (DNC) Registry helps individuals exercise the right to opt out of unwanted specified messages by registering their Singapore phone number.</cite> <cite index="89-2">Any person or organization found guilty of sending telemarketing messages to Singapore telephone numbers without checking the DNC Registry is liable to a fine of up to US$10,000 per message sent.</cite> <cite index="81-8">Organisations do not need to check the DNC Registry if they have the recipient's clear and unambiguous consent to send marketing messages to the Singapore telephone number.</cite> Cookie-specific guidance exists within PDPC's Advisory Guidelines on Selected Topics, which include dedicated questions on <cite index="47-16,47-17">whether consent must be obtained for the use of cookies and whether organisations are allowed to use cookies for targeting of advertisements</cite>, though the substantive answers were not retrieved in this pass. No dark-pattern-specific prohibition, clean-room/data-collaboration rule, or CPRA-style cross-context 'sale'/'share' concept was identified in the PDPA.

no periodic updates on record for this sub-brief

Sources and claims (4)
  1. UncertainOneTrust DataGuidance — The PDPC's Advisory Guidelines on the PDPA for Selected Topics address whether consent must be obtained for the use of cookies and whether cookies may be used for targeted advertising.observed
  2. ConfirmedPersonal Data Protection Commission — The Do Not Call Registry allows individuals to register their Singapore telephone number to opt out of receiving unwanted marketing voice calls, text messages and faxes.observed
  3. ConfirmedInternational Association of Privacy Professionals — A person or organisation that sends telemarketing messages to a Singapore telephone number without checking the DNC Registry, absent a relevant exception, commits an offence and is liable to a fine of up to US$10,000 per message sent.observed
  4. ConfirmedPersonal Data Protection Commission — Organisations do not need to check the DNC Registry before sending marketing messages where they have the recipient's clear and unambiguous consent to receive such messages at that Singapore telephone number.observed

#

AI governance relies on voluntary frameworks (Model AI Governance Framework, Agentic AI MGF, ISAGO, AI Verify) rather than binding statute; no dedicated biometric or genetic-data law was confirmed, and national-security carve-outs are largely undocumented in general legislation.

Primary frameworkModel AI Governance Framework (voluntary); PDPA as general personal-data backstop
Traffic-light rationale — AmberAI governance relies on voluntary frameworks (Model AI Governance Framework, Agentic AI MGF, ISAGO, AI Verify) rather than binding statute; no dedicated biometric or genetic-data law was confirmed, and national-security carve-outs are largely undocumented in general legislation.

Sub-modules (6)

Profiling RestrictionsRed

No general Art 22-style profiling restriction was located in the PDPA; profiling limits appear only in children-specific guidance.

Absence provenance: unavailable. Searched: Singapore PDPA profiling restrictions automated decision-making adults, PDPC Article 22 equivalent.

Automated Decision Making TransparencyAmber

Transparency/explainability are addressed through the voluntary Model AI Governance Framework rather than a binding ADM transparency right.

Claims (1):

  • Singapore's Model AI Governance Framework, a voluntary framework rather than binding law, promotes principles of transparency and explainability for AI systems' decision-making processes.

Ai Risk AssessmentsAmber

AI risk assessment tools (ISAGO, AI Verify) and the new Agentic AI Model Governance Framework are voluntary; MAS is separately consulting on binding-adjacent AI risk guidance for financial institutions.

Claims (3):

  • PDPC and IMDA's Model AI Governance Framework is supported by the voluntary Implementation and Self-Assessment Guide for Organisations (ISAGO) and the AI Verify testing toolkit, which help organisations assess AI systems against the Framework's principles.
  • In January 2026, Singapore unveiled a Model AI Governance Framework for Agentic AI, the first governance model specifically addressing agentic AI systems, emphasising human oversight and accountability for agentic AI risks.
  • MAS opened a consultation on AI risk management guidelines for financial institutions covering governance, oversight and lifecycle controls.

Biometric RegimeAmber

No dedicated biometric-data statute was confirmed; biometric data is treated as personal data under the PDPA, supplemented by ad hoc device-specific guidance (e.g., smart glasses).

Claims (1):

  • Singapore's media regulator (MDDI) has issued guidance advising organisations on PDPA compliance obligations for AI-equipped smart glasses, addressing privacy and safety considerations, rather than through a dedicated biometric-specific statute.

Genetic DataRed

No dedicated genetic-data regime was identified in this research pass.

Absence provenance: unavailable. Searched: Singapore PDPA genetic data regulation, PDPC genetic data guidance.

State Surveillance CarveoutsAmber

Public agencies sit outside the PDPA and are governed by their own internal data rules; no general public-authority surveillance statute over private-sector-held data was confirmed.

Claims (2):

  • Singapore public sector agencies are not subject to the PDPA's data protection provisions, being instead governed by their own public-sector data protection rules.
  • There is no general legislation in Singapore specifically governing surveillance by public authorities of personal data held by private organisations, beyond specific statutory powers to access and seize data.
Category narrative186 words

Singapore's AI governance is predominantly voluntary/soft-law rather than binding. <cite index="68-4,68-5,68-6">The Model AI Governance Framework's 11 guiding principles include transparency, explainability, repeatability/reproducibility and safety, aiming to improve public understanding and trust in AI.</cite> <cite index="68-11,68-13">AI Verify is a testing framework/toolkit and the Implementation and Self-Assessment Guide for Organizations (ISAGO) offers practical implementation advice, though AI Verify cannot test Generative AI/LLMs and does not guarantee safety.</cite> <cite index="70-1,70-2">Singapore's Agentic AI Model Governance Framework was unveiled in January 2026, the first governance model in the world specifically addressing agentic AI.</cite> <cite index="95-1">MAS opened a consultation on AI risk management guidelines for financial institutions, covering governance, oversight, and lifecycle controls.</cite> Biometric-specific statutory regimes were not confirmed; <cite index="5-22">MDDI advises organizations on compliance with the PDPA for AI-equipped smart glasses, addressing privacy, safety and related considerations,</cite> functioning as sector guidance rather than a dedicated biometric law. On surveillance, <cite index="51-13,51-15">there is no general legislation in Singapore that specifically relates to surveillance conducted by public authorities of personal data held by private organisations, and Singapore public agencies are not subject to the PDPA's data protection provisions, having their own separate rules.</cite>

no periodic updates on record for this sub-brief

Sources and claims (7)
  1. ConfirmedPersonal Data Protection Commission — Singapore's Model AI Governance Framework, a voluntary framework rather than binding law, promotes principles of transparency and explainability for AI systems' decision-making processes.observed
  2. ConfirmedPersonal Data Protection Commission — PDPC and IMDA's Model AI Governance Framework is supported by the voluntary Implementation and Self-Assessment Guide for Organisations (ISAGO) and the AI Verify testing toolkit, which help organisations assess AI systems against the Framework's principles.observed
  3. ProbablearXiv — In January 2026, Singapore unveiled a Model AI Governance Framework for Agentic AI, the first governance model specifically addressing agentic AI systems, emphasising human oversight and accountability for agentic AI risks.observed
  4. ProbableOneTrust DataGuidance — MAS opened a consultation on AI risk management guidelines for financial institutions covering governance, oversight and lifecycle controls.observed
  5. ProbableOneTrust DataGuidance — Singapore's media regulator (MDDI) has issued guidance advising organisations on PDPA compliance obligations for AI-equipped smart glasses, addressing privacy and safety considerations, rather than through a dedicated biometric-specific statute.observed
  6. ConfirmedOneTrust DataGuidance — Singapore public sector agencies are not subject to the PDPA's data protection provisions, being instead governed by their own public-sector data protection rules.observed
  7. ProbableOneTrust DataGuidance — There is no general legislation in Singapore specifically governing surveillance by public authorities of personal data held by private organisations, beyond specific statutory powers to access and seize data.observed

#

Children's protections rest on PDPC advisory guidelines rather than statutory age-of-consent provisions, and dependent-adult protections are addressed only incidentally in breach-notification guidance.

Primary frameworkPDPC Advisory Guidelines on the PDPA for Children's Personal Data in the Digital Environment (non-statutory)
Traffic-light rationale — AmberChildren's protections rest on PDPC advisory guidelines rather than statutory age-of-consent provisions, and dependent-adult protections are addressed only incidentally in breach-notification guidance.

Sub-modules (5)

Age VerificationAmber

No statutory age of consent; PDPC applies a 13-years-old practical threshold via guidance.

Claims (1):

  • The PDPA does not define 'child' or stipulate a statutory minimum age of consent; the PDPC applies a practical rule of thumb that a minor aged 13 or above typically has sufficient understanding to consent on their own behalf.

Minor Profiling BansAmber

Data-minimisation guidance limits children's profile visibility by default rather than imposing an outright profiling ban.

Claims (1):

  • PDPC guidance directs organisations handling children's personal data to adopt data minimisation policies, including ensuring that children's account information is not made public and searchable by default.

Education SettingsAmber

Education-context organisations may prefer parental consent even for 13-17 year-olds as a matter of prudence.

Claims (1):

  • In an education setting, an organisation may consider it more prudent to obtain parental consent for a 13-year-old rather than seeking the child's consent directly.

Dependent AdultsRed

Vulnerable-adult protection is addressed only within breach-notification guidance (adoption/vulnerable-individual cases), not as a standalone statutory regime.

Claims (1):

  • Where a data breach involves information related to adoption matters or the identification of vulnerable individuals, organisations should first notify the PDPC for guidance before notifying affected individuals.
Category narrative228 words

Protections for minors are guidance-based rather than statutory. <cite index="43-2">The PDPA does not define 'child' nor 'children'.</cite> <cite index="49-10">Unlike the GDPR, the PDPA does not stipulate a minimum age of consent, choosing to leave it to other general rules of law to determine the question of capacity;</cite> however, <cite index="41-1">the PDPC considers that a child between 13 and 17 may give valid consent when policies on collection, use, disclosure and withdrawal are readily understandable by them.</cite> <cite index="41-12">Where the child is below 13 years of age, the organisation must obtain consent from the child's parent or guardian.</cite> <cite index="41-6">Where an organisation has reason to believe that a child does not have sufficient understanding of the nature and consequences of giving consent, the organisation should obtain consent from the child's parent or guardian.</cite> <cite index="41-14,41-15">Organisations should adopt data minimisation policies to limit the collection and sharing of children's personal data, including ensuring that children's account information is not made public and searchable by default.</cite> <cite index="41-9">An organisation in an education setting may assess that it is more prudent to obtain consent from a parent of a 13-year-old rather than to directly seek the consent of a 13-year-old.</cite> On vulnerable adults, <cite index="21-12">where a data breach involves information related to adoption matters or the identification of vulnerable individuals, organisations should first notify the Commission for guidance on notifying affected individuals.</cite>

no periodic updates on record for this sub-brief

Sources and claims (5)
  1. ConfirmedInternational Association of Privacy Professionals — The PDPA does not define 'child' or stipulate a statutory minimum age of consent; the PDPC applies a practical rule of thumb that a minor aged 13 or above typically has sufficient understanding to consent on their own behalf.observed
  2. ConfirmedPersonal Data Protection Commission — Where a child is below 13 years of age, or where an organisation has reason to believe a child lacks sufficient understanding of the nature and consequences of consent, the organisation must obtain consent from the child's parent or guardian.observed
  3. ConfirmedPersonal Data Protection Commission — PDPC guidance directs organisations handling children's personal data to adopt data minimisation policies, including ensuring that children's account information is not made public and searchable by default.observed
  4. ConfirmedPersonal Data Protection Commission — In an education setting, an organisation may consider it more prudent to obtain parental consent for a 13-year-old rather than seeking the child's consent directly.observed
  5. ConfirmedPersonal Data Protection Commission — Where a data breach involves information related to adoption matters or the identification of vulnerable individuals, organisations should first notify the PDPC for guidance before notifying affected individuals.observed

#

Active, escalating enforcement (higher penalty caps, regular published decisions) with a functioning private right of action, though regulator funding/capacity data and collective-redress mechanisms were not confirmed.

Primary frameworkPersonal Data Protection Act 2012, as amended (Enforcement provisions, Part IX-X; s.48O private right of action)
Traffic-light rationale — GreenActive, escalating enforcement (higher penalty caps, regular published decisions) with a functioning private right of action, though regulator funding/capacity data and collective-redress mechanisms were not confirmed.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

Maximum penalty of 10% of Singapore annual turnover (for organisations exceeding S$10m turnover) or S$1m, whichever is higher, backed by document-production and examination powers.

Claims (2):

  • Since amendments effective 1 October 2022, the maximum financial penalty for PDPA breaches by organisations with annual turnover in Singapore exceeding S$10 million is 10% of their annual turnover in Singapore, or S$1 million, whichever is higher.
  • The PDPC has powers to require production of documents and information and to require the attendance of persons for oral examination in the course of its investigations.

Enforcement Activity IndexGreen

Recent published decisions (Marina Bay Sands, October 2025; People Central, January 2026) evidence sustained enforcement activity.

Claims (2):

  • In October 2025, the PDPC imposed a financial penalty and directions on Marina Bay Sands Pte Ltd for a negligent contravention of the Protection Obligation arising from a data migration exercise that left patrons' personal data unprotected for six months.
  • On 8 January 2026, the PDPC imposed a financial penalty of S$17,500 and directions on People Central Pte Ltd for failing to put in place reasonable security arrangements to protect personal data.

Regulator Funding And CapacityRed

No specific budget or headcount data for the PDPC was located in this research pass.

Absence provenance: unavailable. Searched: PDPC budget headcount annual report, IMDA PDPC staffing data protection.

Collective Redress And Class ActionsRed

No PDPA-specific class-action or collective-redress mechanism was confirmed in this research pass.

Absence provenance: unavailable. Searched: Singapore PDPA class action collective redress data protection, representative proceedings PDPA.

Private Right Of ActionGreen

Section 48O provides a private right of civil action, contingent on finality of any related PDPC decision.

Claims (1):

  • Under Section 48O of the PDPA, individuals who suffer loss or damage directly as a result of a contravention may commence civil proceedings against the organisation, with the right of private action arising after any PDPC decision on the matter becomes final.

Recent Developments 180DAmber

Notable near-term developments include a scheduled 2027 NRIC-misuse enforcement escalation, the EU-Singapore Digital Trade Agreement entering into force, and ongoing MAS AI risk-management consultation.

Claims (2):

  • The PDPC will enforce stricter measures against NRIC misuse by private organisations starting 1 January 2027.
  • MAS opened a consultation on AI risk management guidelines for financial institutions covering governance, oversight and lifecycle controls, indicating forthcoming sector-specific AI risk guidance.
Category narrative233 words

Financial penalties were substantially increased in 2022: <cite index="20-2">the financial penalty cap which may be imposed on organisations for breaches under the PDPA has increased from the previously fixed S$1 million, to 10% of the organisation's annual turnover in Singapore for organisations with annual local turnover exceeding S$10 million, whichever is higher,</cite> with the change <cite index="1-1">taking effect on 1 October 2022.</cite> Investigative powers are broad: <cite index="52-23">the Commission's powers include the power to require production of documents and information, and the power to require the attendance of persons, and to orally examine them.</cite> Recent enforcement activity includes a financial penalty against Marina Bay Sands: <cite index="12-3,12-4">MBS failed to discover and correct an omission for six months, leaving patrons' personal data unprotected, in negligent contravention of the Protection Obligation,</cite> and, more recently, <cite index="19-1">a financial penalty of $17,500 was imposed and directions were issued to People Central Pte Ltd for failing to put in place reasonable security arrangements, on 8 January 2026.</cite> Private redress exists: <cite index="51-5,51-6">individuals who have suffered loss or damage directly as a result of a contravention under Section 48O of the PDPA may commence civil proceedings in the courts, with the right of private action arising only after the PDPC's decision on the contravention becomes final.</cite> Recent developments include an NRIC-misuse enforcement escalation: <cite index="5-3">PDPC will enforce stricter measures against NRIC misuse by private organizations starting January 1, 2027.</cite>

no periodic updates on record for this sub-brief

Sources and claims (7)
  1. ConfirmedPersonal Data Protection Commission — Since amendments effective 1 October 2022, the maximum financial penalty for PDPA breaches by organisations with annual turnover in Singapore exceeding S$10 million is 10% of their annual turnover in Singapore, or S$1 million, whichever is higher.observed
  2. ConfirmedPersonal Data Protection Commission — The PDPC has powers to require production of documents and information and to require the attendance of persons for oral examination in the course of its investigations.observed
  3. ConfirmedPersonal Data Protection Commission — In October 2025, the PDPC imposed a financial penalty and directions on Marina Bay Sands Pte Ltd for a negligent contravention of the Protection Obligation arising from a data migration exercise that left patrons' personal data unprotected for six months.observed
  4. ConfirmedPersonal Data Protection Commission — On 8 January 2026, the PDPC imposed a financial penalty of S$17,500 and directions on People Central Pte Ltd for failing to put in place reasonable security arrangements to protect personal data.observed
  5. ConfirmedOneTrust DataGuidance — Under Section 48O of the PDPA, individuals who suffer loss or damage directly as a result of a contravention may commence civil proceedings against the organisation, with the right of private action arising after any PDPC decision on the matter becomes final.observed
  6. ProbableOneTrust DataGuidance — The PDPC will enforce stricter measures against NRIC misuse by private organisations starting 1 January 2027.observed
  7. ProbableOneTrust DataGuidance — MAS opened a consultation on AI risk management guidelines for financial institutions covering governance, oversight and lifecycle controls, indicating forthcoming sector-specific AI risk guidance.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

Blocking. 3 failing check(s).

schema_validpass
min_architecture_patterns0
min_red_flags0
min_controls0
worked_examples_count0
decision_tree_nodes0
counterparty_diligence_questions0
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
board_briefing_presentFAIL
every_practical_object_has_source_idFAIL
source_tier_integrity_okpass
jurisdiction_source_floor_metFAIL
tier_a_b_national_primary_pct0.0
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Singapore
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 59 claim(s) (59 category placement(s)), 39 source(s) in the cumulative register.

Audit trail

Machine checkChallenged on 29 Sep 2026: nothing tested (no claim on this page was eligible for an automated test). An automated, adversarial test run by a second model; no person has assessed the result.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacyadequacy granted
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacysccs and bcrs
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redresscollective redress and class actions

Self-audit

Strong T1/T2 (primary PDPC statute pages, official advisory guidelines, and published enforcement decisions) coverage was achieved for regulator_and_framework, data_subject_rights, controller_processor_duties, cross_border_and_adequacy, children_and_vulnerable_groups, and enforcement_and_redress. sectoral_watch (financial sub-module) and algorithmic_biometric_and_surveillance_governance relied more heavily on T3/T4 secondary trackers (DataGuidance, IAPP, arXiv) because MAS notices and AI-framework commentary were not directly retrieved from mas.gov.sg or pdpc.gov.sg primary PDF text in this pass. adtech_and_commercial_privacy's cookies_and_trackers sub-module rests on table-of-contents headings only (PDPC Advisory Guidelines on Selected Topics), not verified substantive text. credit_and_scoring, insurance, dark_patterns, clean_rooms_and_dcr, cross_context_advertising, genetic_data, profiling_restrictions (adult), ropa_requirements, regulator_funding_and_capacity, and collective_redress_and_class_actions carry explicit absent_field_provenance as no qualifying primary or secondary evidence was located.

Unresolved questions (6):

  • What is the current legislative/commencement status of the Health Information Bill referenced in secondary trackers (enacted vs. still a bill)?
  • What is the substantive PDPC position (not just guideline headings) on cookie consent and ad-targeting under the Advisory Guidelines on Selected Topics?
  • Does Singapore's PDPA framework have a formal Records-of-Processing-Activities (ROPA) requirement analogous to GDPR Art 30, or is this fully absent by design?
  • Are there PDPC-published figures on regulator funding, headcount, or case backlog to assess enforcement capacity?
  • Is there a confirmed collective-redress or representative-action mechanism specific to PDPA claims, distinct from general Singapore civil procedure?
  • Has Singapore received or been the subject of any formal adequacy-style determination from the EU or other jurisdictions?

Escalate to primary-source review: yes