Singapore's digital economy is booming, but with that growth comes strict legal responsibility. If your website, mobile app, e-commerce platform, SaaS product or digital marketplace collects any personal data from individuals in Singapore, you are legally bound by the Personal Data Protection Act 2012 (PDPA), regardless of whether your organisation is based locally or overseas.
Enforced by the Personal Data Protection Commission (PDPC), the PDPA establishes a comprehensive framework governing how personal data is collected, used, disclosed and protected by organisations. While the PDPA does not explicitly mandate a document titled "Privacy Policy," the law effectively requires one. Organisations must notify individuals of the purposes for which their data is collected and must make information about their data protection policies and practices publicly available. For any business operating online, a well-drafted, accurate privacy policy is not just best practice; it is your primary compliance instrument. Non-compliance is not costless: since 1 October 2022 the PDPC may impose a financial penalty of up to 10% of an organisation's annual turnover in Singapore where that turnover exceeds S$10 million, or S$1 million, whichever is higher.
This article breaks down exactly what your website or app needs to include to stay on the right side of Singapore law in 2026 and beyond.
Who Must Comply? The Scope of the PDPA
The PDPA applies broadly. It covers all private-sector organisations that collect, use, or disclose personal data in Singapore, regardless of whether the organisation is incorporated in Singapore or overseas. This means a foreign e-commerce store shipping to Singapore, a global SaaS platform with Singaporean users, or a local food delivery app all fall under the same regulatory umbrella.
The law applies to both electronic and non-electronic data. Narrow exemptions exist for individuals acting in a purely personal or domestic capacity, employees acting in the course of their employment, public agencies, and pure business contact information (such as a business email address and job title).
Core obligations under the PDPA
The PDPA imposes several key obligations that shape the content of your privacy policy:
- Consent Obligation[1]
You must obtain an individual's voluntary and informed consent before collecting, using or disclosing their personal data, unless deemed consent applies or a statutory exception is available. Since the 2020 amendments, consent may be deemed where an individual voluntarily provides data for an evident purpose, where collection is reasonably necessary to perform a contract with the individual, or by notification following an assessment of likely adverse effects. The First Schedule separately permits collection, use or disclosure without consent for legitimate interests and for business improvement purposes. Pre-ticked boxes, buried opt-ins, and consent bundled within general terms of service are all invalid.
- Purpose Limitation Obligation[2]
Personal data may only be collected, used or disclosed for purposes that a reasonable person would consider appropriate in the circumstances, and that have been notified to the individual. Data collected for one purpose cannot silently be repurposed for another.
- Notification Obligation[3]
On or before collection, you must inform individuals of the purposes for which their personal data will be collected, used or disclosed. This obligation is the direct legal foundation for a privacy policy. Without clear, upfront notification, no other obligation can be properly satisfied.
- Access and Correction Obligations[4]
Individuals have the right to request access to their personal data and to correct any inaccuracies. Organisations must respond within a reasonable time and cannot charge excessive fees.
- Accuracy Obligation[5]
Organisations must take reasonable steps to ensure that personal data is accurate, complete and up to date particularly where that data is likely to be used to make decisions affecting the individual, or disclosed to third parties.
- Retention Limitation Obligation[6]
Personal data must not be retained once the purpose for which it was collected is no longer being served, and retention is no longer necessary for legal or business purposes. Indefinite retention of personal data is not permissible.
- Transfer Limitation Obligation[7]
Personal data may not be transferred outside Singapore unless the receiving organisation provides a standard of protection comparable to the PDPA; for example, through contractual clauses, binding corporate rules or recognised certifications such as the Global Cross-Border Privacy Rules (CBPR) System, which succeeded the APEC arrangement in 2022 and in which Singapore participates.
- Data Breach Notification Obligation[8]
Organisations must assess suspected data breaches and, where a breach is notifiable (likely to cause significant harm to individuals and/or affects 500 or more individuals), notify the PDPC within three calendar days of determining it is notifiable and inform affected individuals as soon as practicable.
What Your Privacy Policy Must Cover
A privacy policy is not merely a necessity under the PDPA; it is the cornerstone of your Notification Obligation. Here is what it must address:
- What Personal Data You Collect and Why
Your privacy policy must clearly state the types of personal data you collect (name, email, phone number, device identifiers, browsing behaviour, etc.) and the purposes for which you collect them. This flows from the Purpose Limitation Obligation i.e. data collected for one purpose cannot silently be repurposed for another.
- Consent And How It Is Obtained and withdrawn
You must obtain consent before collecting, using, or disclosing personal data. Pre-ticked boxes and bundled consents that hide marketing opt-ins within terms of service are not valid. Consent must be freely given, specific, and informed. Organisations cannot obtain consent through deception or misleading practices. Further a mechanism for how users can withdraw consent including consequences of withdrawal.
- Data Protection Officer (DPO) Contact Details
Organisations are required to designate an individual as Data Protection Officer (who can be an existing employee and need not be a dedicated full-time role for small organisations), and mandatorily make the DPO's contact information publicly available, typically in the privacy policy.
- Retention Periods
Your privacy policy should state how long you hold different categories of personal data. Retention limitation obligations require organisations to stop retaining personal data once it no longer serves a legal purpose or business need.
- Overseas Data Transfers
If your website or app routes personal data to servers or third-party vendors outside Singapore which is almost inevitable if you use AWS, Google Analytics, Stripe, or similar cloud services, your privacy policy must address this. If you transfer data outside Singapore, common when using cloud-hosted analytics, ensure the receiving party offers comparable protection to the PDPA, or obtain the individual's informed consent for the transfer.
- Cookies and Tracking Technologies
The PDPA does not specifically regulate cookies, but if cookies or similar technologies collect personal data, consent and notification requirements apply. Strictly necessary cookies that do not process personal data are generally exempt. Singapore has no statutory prior-consent rule for cookies, and PDPC guidance accepts that consent may in some circumstances be inferred from a user's browser or device settings. A banner allowing users to accept or reject non-essential categories before such cookies are set, with scripts blocked until consent is given, is a prudent approach carried over from EU practice rather than a PDPA requirement. It is worth adopting where the same site also serves European users.
- Disclosure to third parties
Identify categories of recipients; payment processors, hosting providers, analytics tools (e.g., Google Analytics), email service providers, professional advisers, government authorities when required by law, or parties involved in business transfers. Note any overseas transfers and the safeguards used.
- Data Breach Notification
Under Part 6A of the PDPA, organisations must assess suspected data breaches and determine whether they are notifiable. A breach is generally notifiable where it is likely to result in significant harm to affected individuals and/or is of significant scale. Thus the organisation should maintain a data-breach response plan. The PDPA contains obligations to assess data breaches and notify the PDPC and affected individuals where the breach is notifiable. The Act expressly includes provisions concerning notifiable breaches, assessment and notification.
- Children’s Data
If your platform is likely to be accessed by minors, additional care is required. On 28 March 2024, the PDPC released Advisory Guidelines on the PDPA for Children's Personal Data[9], aimed at organisations offering online products or services likely to be accessed by children. The guidelines clarify that children aged 13 to 17 may provide valid consent, provided that policies on data collection, use, disclosure and withdrawal are presented in a way that the child can clearly understand, including the implications of giving or withdrawing consent. If there is doubt about the child's level of understanding, parental or guardian consent should be obtained.
- Address direct marketing and the DNC Registry
Marketing through email, SMS, telephone calls and push notifications should be addressed separately from ordinary service communications. The PDPC states that organisations generally have 21 days to ensure marketing messages are no longer sent after receiving an opt-out request. Clear and unambiguous consent may remove the need to check the DNC Registry, but the consent should be properly recorded.
Conclusion
A Singapore privacy policy should be a practical and accurate explanation of the organisation’s actual data practices, not a generic template copied from another jurisdiction. At a minimum it should identify the organisation and DPO, describe the data collected and the purposes of collection and use, explain consent and withdrawal, disclose third-party and overseas processing, set out access and correction procedures, address retention and security, and cover direct-marketing controls.
The policy should be reviewed whenever the organisation launches new features, changes analytics or advertising tools, introduces new vendors, expands overseas, begins collecting more sensitive information, or alters its marketing methods. It should be backed by internal policies, contracts, training and a breach-response plan.
Section 13 of PDPA ↑
Section 18 of PDPA ↑
Section 20 of PDPA ↑
Section 21 and 22 of PDPA ↑
Section 23 of PDPA ↑
Section 25 of PDPA ↑
Section 26 of PDPA ↑
Section 26A-26D of PDPA ↑
https://www.pdpc.gov.sg/organisations/regulations-decisions/regulatory-guidance/advisory-guidelines-on-the-pdpa-for-childrens-personal-data-in-the-digital-environment ↑