What Is Considered Personal Data Under PDPA: A Complete Guide for Singapore Businesses

What Is Considered Personal Data Under PDPA: A Complete Guide for Singapore Businesses

The Personal Data Protection Act 2012 (PDPA) is Singapore’s comprehensive data privacy legislation, and at its core lies a deceptively simple question: what exactly counts as personal data? For businesses operating in Singapore, getting this definition wrong can lead to hefty fines, reputational damage, and regulatory action from the Personal Data Protection Commission (PDPC).

This guide breaks down what is considered personal data under the PDPA, with practical examples and compliance advice tailored to Singapore businesses.

The Legal Definition of Personal Data Under PDPA

Section 2(1) of the PDPA defines personal data as “data, whether true or not, about an individual who can be identified from that data; or from that data and other information to which the organisation has or is likely to have access.” This broad definition has two critical elements that every business must understand.

First, the data does not need to be true. Even inaccurate information about someone qualifies as personal data if it can identify them. Second, the identification test considers not just the data itself, but also other information the organisation reasonably has access to. A customer ID number might seem anonymous in isolation, but if your CRM system links it to a name and address, the PDPC treats it as personal data.

Common Examples of Personal Data in Singapore

The following types of information are clearly recognised as personal data under PDPA enforcement decisions:

Identity Information: Full name, NRIC number, FIN (Foreign Identification Number), passport number, and birth certificate number. Since the 2019 NRIC Advisory Guidelines, organisations are prohibited from collecting, using, or disclosing NRIC numbers unless required by law or necessary to accurately identify individuals.

Contact Details: Phone numbers, residential addresses, email addresses (both personal and work emails that identify an individual), and social media account handles linked to a real identity.

Financial Data: Bank account numbers, credit card details, salary information, CPF contribution records, and income tax filing details. The Marina Bay Sands data breach case showed how seriously the PDPC treats exposure of financial and personal records.

Biometric Data: Fingerprints, facial recognition templates, retina scans, voice prints, and DNA profiles. With more Singapore offices using biometric access control, this category is increasingly relevant.

Digital Identifiers: IP addresses (when linked to an identifiable user), device IDs, cookies that track individual browsing behaviour, and GPS location data from mobile applications.

Visual and Audio Records: Photographs, CCTV footage showing identifiable individuals, audio recordings of phone conversations, and video conference recordings.

Employment Records: Employee evaluations, disciplinary records, medical certificates, leave applications, and training records that identify specific staff members.

What Is NOT Considered Personal Data

Not everything falls under the PDPA’s definition. Business contact information provided by an individual solely for business purposes — such as a corporate email address, business title, and office phone number — is explicitly excluded under Section 4(5) of the PDPA. This means B2B marketing using business cards collected at industry events generally falls outside PDPA consent requirements.

Anonymised data that cannot identify any individual, even when combined with other available information, is also excluded. However, the PDPC has cautioned that poor anonymisation practices can result in data remaining personal. Simply removing names while keeping detailed demographic profiles may not be sufficient.

Aggregated statistical data — for example, “35% of employees in the manufacturing sector reported workplace injuries” — is not personal data, provided no individual can be identified from the aggregate.

The Grey Areas: When Data Becomes Personal

Many PDPC enforcement decisions have centred on situations where organisations did not realise they were handling personal data. Job application forms containing NRIC numbers left in unlocked cabinets, customer feedback forms with phone numbers stored on unencrypted USB drives, and employee records shared via unsecured email have all resulted in enforcement actions.

Metadata is another grey area. A photograph file contains EXIF data that may include GPS coordinates, device information, and timestamps. Combined with a social media post, this metadata could identify an individual even if the photo itself does not clearly show a face.

Even opinion data qualifies. If a manager writes “John performs poorly under pressure” in a performance review, that subjective opinion is personal data about John.

Obligations for Singapore Businesses

Once you have established that your organisation handles personal data, the PDPA imposes several key obligations:

Consent Obligation: You must obtain the individual’s consent before collecting, using, or disclosing their personal data, unless an exception applies (such as business improvement or legitimate interests under the 2021 amendments).

Purpose Limitation: Personal data can only be collected for purposes a reasonable person would consider appropriate, and you must inform individuals of these purposes.

Protection Obligation: Reasonable security arrangements must protect personal data from unauthorised access, modification, disclosure, or similar risks. The standard of “reasonable” depends on the sensitivity of the data and the size of your organisation.

Retention Limitation: Stop retaining personal data when it is no longer needed for the purpose it was collected, or when consent is withdrawn. Many organisations fall afoul of this by keeping customer databases indefinitely.

Data Breach Notification: Since February 2021, organisations must notify the PDPC and affected individuals of data breaches that are likely to result in significant harm, within three calendar days of assessing the breach to be notifiable.

Investing in PDPA compliance training helps your team understand these obligations in practical, day-to-day scenarios.

Recent Enforcement Trends in Singapore

The PDPC has been increasingly active. In 2025 alone, financial penalties exceeded SGD 2 million across multiple enforcement actions. Common violations include failing to implement adequate protection measures, excessive collection of NRIC numbers, and inadequate access controls on databases containing personal data.

Penalties under the amended PDPA can reach up to SGD 1 million or 10% of annual turnover for organisations with turnover exceeding SGD 10 million, whichever is higher. This significant increase from the previous SGD 1 million cap reflects the government’s seriousness about data protection.

Practical Steps to Get Your Organisation Compliant

Start with a data inventory. Map every department’s data collection touchpoints — HR forms, customer databases, vendor contracts, marketing lists, CCTV systems, and access control logs. For each touchpoint, document what personal data is collected, why, how it is stored, who has access, and when it should be deleted.

Appoint a Data Protection Officer (DPO). Under the PDPA, every organisation must designate at least one individual as DPO. This person does not need to be a dedicated hire — the role can be assigned to an existing manager, but they must have sufficient authority and resources to fulfil the function.

Review your consent mechanisms. Ensure consent is obtained before data collection, that it is specific to stated purposes, and that individuals can easily withdraw consent. Update your privacy policies to reflect actual practices, not boilerplate language copied from another organisation.

Implement technical safeguards proportionate to the sensitivity of data you handle. Encryption for data at rest and in transit, role-based access controls, regular patch management, and employee training on phishing awareness form the baseline.

Finally, prepare a data breach response plan. The 72-hour assessment window and three-day notification requirement leave no room for ad-hoc responses. Tabletop exercises help your team practice before a real incident occurs.

When in Doubt, Treat It as Personal Data

The PDPC’s guidance consistently favours a broad interpretation of personal data. If there is any reasonable possibility that data could identify an individual — directly or in combination with other information your organisation holds — treat it as personal data and apply PDPA safeguards accordingly.

This conservative approach costs little but protects your organisation from the financial and reputational consequences of a PDPC enforcement action.

Need help assessing your PDPA compliance posture? Contact Sage Shield for a free consultation — our team specialises in data protection and regulatory compliance for Singapore businesses.



Free
Consultation
Call Now WhatsApp
☍ Legal Register Platform — AI-Powered Compliance for 15 APAC Countries Try Free →