You hold other people's details: names, phone numbers, NRIC numbers, addresses, salaries, medical notes, CVs, photos. The law treats those details as something you are looking after on someone else's behalf — like cash in a safe you did not buy. Three duties follow from that, and everything else is detail.
Protect the details you hold: who can see them, where they live, who else has a copy. Most real breaches are boring — a shared spreadsheet, an old staff account, a photo of an NRIC in a group chat.
If you collected a phone number to deliver an order, you cannot use it to send marketing that nobody agreed to. Purpose first, then permission.
If someone asks how you handle personal data, you can answer in one page: what you hold, why, who sees it, how long you keep it, and who is responsible. That is accountability, and a blank stare is the finding.
These are the duties the law names. Read them as one story: ask, use it for that, tell people, let them correct it, keep it accurate, protect it, delete it when done, be careful sending it abroad, and publish how you work.
| Obligation | What it means in practice |
|---|---|
| Consent | You asked, and the person agreed — or the law gives you another basis to hold the data |
| Purpose limitation | You use it for the reason you collected it, and not a convenient second reason |
| Notification | You told them why you wanted it, before or at the point you collected it |
| Access and correction | If someone asks what you hold about them, you can answer, and you fix it if it is wrong |
| Accuracy | You keep the details reasonably correct, especially if you make decisions based on them |
| Protection | Reasonable security: access controls, no shared logins, locked files, staff who know the rules |
| Retention limitation | You stop keeping data when the purpose is done and there is no other reason to hold it |
| Transfer limitation | Sending data overseas requires a comparable standard of protection |
| Openness | You publish your data protection policy and your DPO's contact details |
The mistake we see most: Naming someone is not the same as doing the job. The most common real-world failure is a DPO whose name is on the website and who has never seen the data the company holds.
The staff list, the customer list, the medical notes — all in one file on someone's desktop, opened by whoever asks.
A resigned employee's email and shared-drive access, still working months later. Cheap to fix, catastrophic to explain.
NRIC photos in WhatsApp groups, tenancy files and HR chats — the most common unsecured copy in Singapore.
A payroll bureau, a marketing agency, a cloud tool — each holding your data with no written terms about what they may do with it.
This page explains the PDPA in plain English so you can act sensibly. It is not legal advice, and it is not a substitute for reading the PDPC's own guidance or taking advice on a specific incident. We implement and document; lawyers advise on the law.
Yes. There is no turnover or headcount threshold. A two-person company that holds a customer list has the same core duties as a large one — the scale of what is reasonable differs, the duty does not.
Yes, and in most SMEs that is exactly what happens. What matters is that the person has the authority to act, the time to do it, and published contact details.
For most SMEs it is a documentation-and-register job rather than a project: policies, your data inventory, response templates, the DPO contact, staff briefing. See the published fees on our pricing page, or ask for a written quote.
The PDPC can investigate, order remedies and impose financial penalties. The practical risk for an SME is usually commercial: a client questionnaire, a tender, a vendor audit or a breach you cannot explain.
No. Business contact details can be used for their purpose — but the protection duties still apply, and the marketing rules still apply. Collect less, and write down why you hold what you hold.
Checked at the source on 20 September 2026. If a rule changes, this page changes with it.
Most companies cannot list where personal data lives. Ask us for a data inventory session — we map it with your team, and you keep the register whether or not you hire us for anything else.