PDPA · In plain words

What PDPA is, in one page, without the fog.

You hold other people's details: names, phone numbers, NRIC numbers, addresses, salaries, medical notes, CVs, photos. The law treats those details as something you are looking after on someone else's behalf — like cash in a safe you did not buy. Three duties follow from that, and everything else is detail.

The three duties, and then the detail

Look after it

Protect the details you hold: who can see them, where they live, who else has a copy. Most real breaches are boring — a shared spreadsheet, an old staff account, a photo of an NRIC in a group chat.

Use it only for why you took it

If you collected a phone number to deliver an order, you cannot use it to send marketing that nobody agreed to. Purpose first, then permission.

Be able to explain it

If someone asks how you handle personal data, you can answer in one page: what you hold, why, who sees it, how long you keep it, and who is responsible. That is accountability, and a blank stare is the finding.

The obligations, in everyday language

These are the duties the law names. Read them as one story: ask, use it for that, tell people, let them correct it, keep it accurate, protect it, delete it when done, be careful sending it abroad, and publish how you work.

ObligationWhat it means in practice
ConsentYou asked, and the person agreed — or the law gives you another basis to hold the data
Purpose limitationYou use it for the reason you collected it, and not a convenient second reason
NotificationYou told them why you wanted it, before or at the point you collected it
Access and correctionIf someone asks what you hold about them, you can answer, and you fix it if it is wrong
AccuracyYou keep the details reasonably correct, especially if you make decisions based on them
ProtectionReasonable security: access controls, no shared logins, locked files, staff who know the rules
Retention limitationYou stop keeping data when the purpose is done and there is no other reason to hold it
Transfer limitationSending data overseas requires a comparable standard of protection
OpennessYou publish your data protection policy and your DPO's contact details

The DPO you have to name

The mistake we see most: Naming someone is not the same as doing the job. The most common real-world failure is a DPO whose name is on the website and who has never seen the data the company holds.

The three-day clock

What PDPA does not require

Where companies actually leak

Shared spreadsheets

The staff list, the customer list, the medical notes — all in one file on someone's desktop, opened by whoever asks.

Old accounts still live

A resigned employee's email and shared-drive access, still working months later. Cheap to fix, catastrophic to explain.

Photographs of IDs

NRIC photos in WhatsApp groups, tenancy files and HR chats — the most common unsecured copy in Singapore.

Vendors nobody checked

A payroll bureau, a marketing agency, a cloud tool — each holding your data with no written terms about what they may do with it.

Not legal advice

This page explains the PDPA in plain English so you can act sensibly. It is not legal advice, and it is not a substitute for reading the PDPC's own guidance or taking advice on a specific incident. We implement and document; lawyers advise on the law.

Questions we get asked

We are a small company. Does PDPA really apply to us?

Yes. There is no turnover or headcount threshold. A two-person company that holds a customer list has the same core duties as a large one — the scale of what is reasonable differs, the duty does not.

Can the same person be the DPO and the operations manager?

Yes, and in most SMEs that is exactly what happens. What matters is that the person has the authority to act, the time to do it, and published contact details.

What does a PDPA programme cost?

For most SMEs it is a documentation-and-register job rather than a project: policies, your data inventory, response templates, the DPO contact, staff briefing. See the published fees on our pricing page, or ask for a written quote.

What happens if we ignore it?

The PDPC can investigate, order remedies and impose financial penalties. The practical risk for an SME is usually commercial: a client questionnaire, a tender, a vendor audit or a breach you cannot explain.

Do we need consent for every business card we collect?

No. Business contact details can be used for their purpose — but the protection duties still apply, and the marketing rules still apply. Collect less, and write down why you hold what you hold.

Where the facts on this page come from

Checked at the source on 20 September 2026. If a rule changes, this page changes with it.

Want to know what you actually hold?

Most companies cannot list where personal data lives. Ask us for a data inventory session — we map it with your team, and you keep the register whether or not you hire us for anything else.