HomeGuides › PDPA Obligations Every Singapore Business Has

PDPA Obligations Every Singapore Business Has

The PDPA has no small-business exemption. If you hold a customer list, you have obligations — including appointing someone to own them.

Every organisation in Singapore that collects, uses or discloses personal data has obligations under the Personal Data Protection Act, and there is no exemption for being small. The core duties are: collect and use personal data only with valid consent or another lawful basis, limit use to the purposes you notified, protect the data with reasonable security arrangements, appoint a Data Protection Officer and make their contact details available, keep data only as long as you need it, and notify the PDPC and affected individuals of a notifiable data breach. Financial penalties for breaching the PDPA can reach up to S$1 million, and for larger organisations up to 10% of annual turnover in Singapore — confirm the current position with the PDPC.

Where SMEs actually fail. Not on grand data strategy, but on the mundane: no named DPO, a shared spreadsheet of customers on a personal laptop, marketing to a list collected for a different purpose, and no plan for what to do in the first 48 hours after a breach. All four are fixable in an afternoon.

The obligations in plain terms

The PDPA sets out a set of related duties. In the order they usually matter to a small business:

  • Consent and notification. Before you collect personal data, tell the individual what you're collecting it for, and obtain consent — or rely on one of the lawful bases the Act provides where consent isn't required. Silence is not consent, and consent obtained for one purpose does not extend to another.
  • Purpose limitation. Use and disclose personal data only for the purposes a reasonable person would consider appropriate and that you notified. The classic failure is buying or repurposing a list for marketing it was never collected for.
  • Protection. Make reasonable security arrangements to prevent unauthorised access, collection, use, disclosure, copying, modification or disposal. "Reasonable" scales with sensitivity and volume — a clinic holding health records is held to more than a florist holding delivery addresses.
  • Accuracy, access and correction. Keep data reasonably accurate and complete where it will be used to make a decision affecting the individual, and respond to access and correction requests.
  • Retention limitation. Stop keeping personal data once the purpose has ended and there's no legal or business need. Old data you no longer use is pure downside in a breach.
  • Transfer limitation. If you send personal data overseas — including to a cloud service or an outsourced provider — you remain responsible for it being protected to a comparable standard.
  • Accountability. Have policies and practices in place, make information about them available, and be able to show what you do.

The Do Not Call provisions sit alongside these and govern marketing calls, texts and faxes to Singapore telephone numbers. Check the current requirements with the PDPC before running any telemarketing.

Appointing a Data Protection Officer

Every organisation must designate at least one individual — a Data Protection Officer — responsible for ensuring PDPA compliance, and must make that person's business contact information available. This is not optional for small businesses, and it does not require hiring anyone. In most SMEs the DPO is the owner, the operations manager or the office manager, wearing an extra hat.

What appointing a DPO should actually involve:

  1. Name someone in writing and record the appointment.
  2. Publish contact details — commonly a role-based email address on your website's privacy notice, so it survives staff turnover.
  3. Give them the authority to act, including the ability to escalate straight to the owner or board when something goes wrong.
  4. Write down what you hold. A simple inventory of what personal data you collect, where it lives, who can see it and how long you keep it is the single most useful compliance artefact for an SME.
  5. Decide the breach playbook in advance. Who assesses, who notifies, who talks to customers.

Data breach notification

The PDPA requires organisations to assess a suspected data breach and, where the breach is notifiable, to notify the PDPC and — depending on the nature of the breach — the affected individuals. Broadly, a breach is notifiable if it results in or is likely to result in significant harm to affected individuals, or is of a significant scale. The specific tests, thresholds and timeframes are set by the PDPC and do change: confirm the current requirements on the PDPC's website rather than relying on any summary, and act promptly, because assessment and notification are expected to happen quickly once a breach is discovered.

What that means operationally for a small business:

  • Detect and contain first. Stop the leak, preserve the evidence, don't wipe logs.
  • Assess whether it's notifiable against the PDPC's current criteria — and document the assessment even if you conclude it isn't.
  • Notify within the required timeframe if it is, and tell affected individuals where required.
  • Keep records. What happened, when you knew, what you decided and why.

Most SMEs discover during an incident that they don't know which vendor holds what. Sorting that out beforehand is cheaper than sorting it out at 11pm.

A practical compliance checklist

ObligationWhat a small business should haveCommon gap
Consent and notificationA privacy notice on your website and forms, stating purposesCollecting data via WhatsApp or paper forms with no notice at all
Purpose limitationMarketing lists kept separate from service-delivery dataMarketing to customers who never consented to marketing
ProtectionAccess controls, unique logins, encrypted devices, vetted vendorsShared logins and customer data on personal laptops and phones
Accountability / DPOA named DPO and published contact detailsNo DPO appointed at all
RetentionA stated retention period and periodic deletionTen years of CVs and enquiry forms nobody has opened
TransferContracts with overseas or cloud providers addressing protectionFree tools adopted by staff with no review
Breach responseA written playbook with named roles and PDPC's current criteriaImprovising during the incident

Where insurance fits — and where it doesn't

Compliance and insurance solve different halves of the same problem. Doing the PDPA work reduces the chance of an incident and the severity of the regulatory consequence. Insurance addresses the cost when one happens anyway.

Cyber insurance policies typically respond to elements of a data breach — incident response and forensics, legal costs, notification costs, and third-party claims from affected individuals — and some wordings extend to regulatory investigation costs where insurable by law. What insurance generally does not do is pay a regulatory financial penalty imposed on you; in many jurisdictions fines are uninsurable as a matter of public policy, and cover for them cannot be assumed. Check the specific wording and get confirmation in writing rather than relying on a summary.

Two practical points:

  • Insurers underwrite your controls. Multi-factor authentication, backups and staff training affect both whether you can buy cyber cover and what you pay for it. The PDPA protection obligation and the underwriting questionnaire ask for much the same things.
  • Standard property and liability policies won't help. Data breach costs sit outside a normal fire, property or public liability policy — cyber is a separate purchase.

This site is an information and referral platform, not a law firm or a broker. For a specific compliance question, take PDPA advice from a qualified professional and confirm requirements with the PDPC.

Frequently asked questions

Does the PDPA apply to small businesses in Singapore?

Yes — the PDPA applies to every organisation that collects, uses or discloses personal data in Singapore, with no exemption for small businesses or sole proprietorships. A one-person business holding a customer contact list has the same core obligations as a large company, scaled to what is reasonable for its size and the sensitivity of the data.

Do I need a Data Protection Officer for a small company?

Yes. Every organisation must designate at least one individual as its Data Protection Officer and make their business contact information available. The DPO does not have to be a new hire or a full-time role — in most SMEs it is the owner or an existing manager, and a role-based email address is the usual way to publish the contact details.

What is the penalty for breaching the PDPA?

Financial penalties under the PDPA can reach up to S$1 million, and for larger organisations up to 10% of annual turnover in Singapore. The PDPC also issues directions requiring remedial action, and enforcement decisions are published — the reputational consequence is often as significant as the sum. Confirm the current penalty framework with the PDPC.

When do I have to report a data breach in Singapore?

You must assess a suspected data breach and notify the PDPC where the breach is notifiable — broadly, where it results in or is likely to result in significant harm to affected individuals, or is of significant scale — and notify affected individuals where required. The specific criteria and timeframes are set by the PDPC and change over time, so check the current requirements on the PDPC's website and act quickly once a breach is discovered.

Does cyber insurance cover PDPA fines?

Generally you should not assume so. Cyber policies commonly cover incident response, forensics, legal costs, breach notification and third-party claims, and some wordings extend to regulatory investigation costs — but regulatory penalties themselves are frequently excluded or insurable only where the law permits. Ask for the position in writing on the specific wording before relying on it.

Do I need consent to email my existing customers?

Using personal data for marketing generally requires consent for that purpose, and consent given when someone bought from you does not automatically extend to marketing. Separate marketing consent from service-delivery data, keep a record of when and how consent was obtained, and check the Do Not Call requirements with the PDPC before calling or texting Singapore numbers.

Related cover & guides

Worried about the cost of a breach?

Tell us about your business once. We pass your enquiry to a licensed insurance professional who quotes the cover you actually need — no obligation, no spam.

Get quotes