PDPA Compliance Checklist for Singapore Businesses in 2026

PDPA Compliance Checklist for Singapore Businesses in 2026

The Personal Data Protection Act (PDPA) is Singapore’s primary data protection law, governing how organisations collect, use, disclose, and store personal data. With enforcement action by the Personal Data Protection Commission (PDPC) continuing in 2026 and financial penalties for breaches remaining significant, having a clear PDPA compliance checklist is essential for every Singapore business. Organisations handling sensitive data should also consider ISO 27001 certification as a complementary framework for information security management — regardless of size or industry. Organisations looking to further demonstrate their cybersecurity commitment may also pursue Cyber Trust certification in Singapore, a nationally recognised cyber security mark.

Frequently Asked Questions on PDPA Compliance

Q: Who does the PDPA apply to?

The PDPA applies to all private sector organisations operating in Singapore that collect, use, or disclose personal data. This includes businesses of all sizes — from sole proprietorships and SMEs to large corporations. Public agencies are governed by separate public sector data protection laws, but private sector companies working with public agencies must still comply with the PDPA in their own data handling activities. If your organisation collects so much as a customer’s name and email address, PDPA obligations apply.

Q: What personal data does the PDPA cover?

The PDPA covers any data — whether true or false — about an individual who can be identified from that data, or from that data and other information to which the organisation has or is likely to have access. This includes names, identification numbers (NRIC, passport), contact details, financial information, medical records, biometric data, and even combinations of data points that together identify an individual. In 2026, the PDPC has also emphasised that inferred data and data derived from analytics can constitute personal data if it relates to an identifiable individual.

Q: What are the key obligations under the PDPA?

The PDPA imposes nine main data protection obligations on organisations: Consent, Purpose Limitation, Notification, Access and Correction, Accuracy, Protection, Retention Limitation, Transfer Limitation, and Openness. The 2021 amendments added a Mandatory Data Breach Notification obligation, requiring organisations to notify the PDPC (and affected individuals in certain cases) within three calendar days of becoming aware of a significant data breach.

Q: Does my business need to appoint a Data Protection Officer?

Yes. Since 2021, all organisations subject to the PDPA are required to appoint at least one Data Protection Officer (DPO). The DPO does not need to be a full-time dedicated role — in smaller organisations, the responsibility is often assigned to an existing staff member. However, the DPO must have sufficient authority, resources, and knowledge to fulfil their responsibilities, which include ensuring PDPA compliance, handling data protection queries, managing data breach responses, and liaising with the PDPC where necessary. The DPO’s business contact details must be made publicly available.

Q: What should be in our data protection policies?

At minimum, your organisation should have a Data Protection Policy covering how you collect, use, disclose, and retain personal data, and how individuals can exercise their access and correction rights. You should also have an internal Data Breach Response Plan detailing how to detect, assess, contain, and report a data breach within the mandatory three-day notification window. Additional policies covering data retention schedules, third-party vendor management, and employee data handling are strongly recommended. All policies should be reviewed and updated regularly — at least annually, or after any significant change to your data processing activities.

Q: How should we handle consent for data collection?

Under the PDPA, consent must be obtained before or at the time of personal data collection, and individuals must be notified of the purposes for which their data will be used. Consent must be given voluntarily, and cannot be obtained through deceptive or misleading means. The 2021 amendments introduced a “deemed consent by contractual necessity” and “legitimate interests” basis, providing some flexibility for situations where consent is impractical — but these bases are narrow and should be applied carefully with legal guidance.

Q: What technical measures are required for data protection?

The PDPA’s Protection Obligation requires organisations to implement reasonable security arrangements to protect personal data from unauthorised access, collection, use, disclosure, copying, modification, disposal, or similar risks. While the PDPA does not prescribe specific technical controls, the PDPC’s advisory guidelines indicate that reasonable measures include access controls, encryption of sensitive data, regular vulnerability assessments and penetration testing, staff training, and incident response capabilities. Organisations that have suffered data breaches are frequently found to have lacked basic technical safeguards.

Q: What happens if we experience a data breach?

If your organisation suffers a data breach, you must assess whether it is a “notifiable” breach under the PDPA. A breach is notifiable if it is likely to cause significant harm to affected individuals, or if it involves personal data of 500 or more individuals. If notifiable, you must inform the PDPC within three calendar days of becoming aware of the breach, and notify affected individuals if significant harm is likely. Failure to notify within the required timeframe is itself an offence. Financial penalties for PDPA breaches can reach S$1 million for most organisations, or 10% of annual turnover for organisations with annual turnover exceeding S$10 million.

Q: How should we manage third-party vendors who handle our customer data?

Under the PDPA, your organisation remains responsible for personal data even when it is processed by third-party vendors — data intermediaries in PDPA terminology. You must contractually require your data intermediaries to protect the personal data they handle on your behalf, and conduct due diligence to ensure they have adequate data protection practices. This includes reviewing vendor data protection policies, conducting periodic audits or assessments, and ensuring contracts clearly define data handling obligations, retention periods, and breach notification requirements.

Your PDPA Compliance Checklist at a Glance

Use this checklist as a starting point for assessing your organisation’s PDPA readiness:

  • Appoint a Data Protection Officer (DPO) and publish their contact details
  • Map all personal data collected, stored, and processed by your organisation
  • Review and update consent collection processes and privacy notices
  • Implement a documented Data Protection Policy accessible to staff and customers
  • Establish a Data Breach Response Plan with clear roles and a three-day notification workflow
  • Conduct regular staff training on data protection obligations
  • Implement technical security measures — access controls, encryption, vulnerability assessments
  • Review and update contracts with third-party vendors handling personal data
  • Set and enforce data retention schedules — delete or anonymise data no longer needed
  • Conduct periodic internal PDPA compliance reviews, at minimum annually

Still Have Questions?

PDPA compliance can be complex, particularly for organisations handling sensitive personal data or operating across multiple business units. Our consultants can conduct a PDPA gap assessment, help you build your compliance framework, and support your team with practical training.

For organisations also looking to strengthen technical cybersecurity controls as part of their PDPA compliance programme, explore our penetration testing and vulnerability assessment services. Businesses eligible for government funding may also find the Enterprise Development Grant (EDG) useful for funding data protection consultancy and technology projects.

Need Help with PDPA Compliance?

Contact Sage Shield Safety Consultants for expert PDPA gap assessments, policy development, DPO support, and staff training tailored to your business.

Contact Us

Related Articles

Related Articles

Need ISO 27001 certification in Singapore certification for information security? We provide complete ISMS implementation consultancy.

ISO 27001 consultant →



Free
Consultation
Call Now WhatsApp
☍ Legal Register Platform — AI-Powered Compliance for 15 APAC Countries Try Free →