What PDPA (Singapore) actually requires
Singapore's general data protection law. The 2021 amendments added a mandatory data breach notification regime, deemed-consent provisions for some types of processing, and significantly higher financial penalties. Enforced by the Personal Data Protection Commission (PDPC).
Key requirements
- Obtain consent for collection, use and disclosure of personal data
- Notify individuals of the purposes for collection at or before collection
- Allow individuals to withdraw consent and to access and correct their data
- Implement reasonable security arrangements to protect personal data
- Appoint a Data Protection Officer and publish their business contact
- Notify the PDPC of qualifying data breaches within 3 calendar days
At a glance
Full name
Personal Data Protection Act (Singapore)
Region
Singapore
Status
In force since 2014, major update in 2021
Who it affects
Any organisation that collects, uses or discloses personal data in Singapore — including organisations based outside Singapore where the activity targets people in Singapore.
Penalties
Financial penalties up to SGD 1 million or 10% of annual turnover in Singapore (whichever is higher) for organisations with annual turnover above SGD 10 million.
How GrantCookie covers it
Compliant defaults
Opt-in by default, granular categories, and a reject button as prominent as accept — the configuration regulators expect.
Provable records
Every consent is timestamped and stored with the banner version, so you can show exactly what was agreed to.
Easy withdrawal
A persistent re-open control lets visitors change their mind at any time, exactly as the law requires.
This page is general guidance, not legal advice. Check your specific obligations with a qualified adviser.
