The Personal Data Protection Act (PDPA) Singapore – what are the requirements?

      The Personal Data Protection Act (PDPA) sets out clear minimum standards of safeguarding personal data in Singapore. It aims to bring together sector-specific legislative and regulatory frameworks relating to the financial services industry in Singapore.

      The PDPA sets out the obligations in respect of (a) collection, (b) use, (c) disclosure and (d) care of personal data in Singapore. Personal data refers to data about an individual who can be identified from that data, or from that data and other information to which the organisation has or is likely to have access, which includes customers, suppliers, and employees.

      Data protection framework

      Firms are expected to have in place an appropriate personal data protection framework that starts with corporate governance/accountability for data protection practices in the management of personal data under the firm’s possession or control, this must also include breach management, training and communications.

      We have set out below some basic elements that should be in included in a firm’s data protection framework:

      • develop a Data Protection (DP) policy
      • appoint a DPO and ensure their business contact information is available to the public
      • identify risks and gaps using the PDPA Assessment Tool for Organisations (PATO)
      • embed data protection as part of corporate governance and establish a data protection reporting structure
      • embed regular monitoring and reporting mechanisms within your Enterprise Risk Management (ERM) framework
      • establish a data breach management team
      • develop a 4-step action plan for data breach response
      • develop a complaint handling procedure
      • develop a staff training and communications plan
      • ensure all staff complete the PDPA e-Learning programme
      • carry out an annual review of data protection policies
      • conduct a table-top exercise to test the data breach response plan
      • provide one refresher training for key employees on handling personal data
      • document data assets and flows using a data inventory map.

      Data Protection Officer (DPO) requirements

      Firms are required to designate at least one individual as the DPO and although it is not mandatory under the Act to register the DPO’s details with ACRA, firms are strongly encouraged to do so.

      The PDPC site states that “Organisations are also required to ensure that at least one DPO’s business contact information is made available to the public. The business contact information may be a general telephone or email address of the organisation.”

      Although this is not a specific MAS-related rule, it is still a legal requirement and is something that can be carried out in a short space of time. We would urge firms to register the DPO’s details with ACRA if they have not already done so . You can find out if this has already been carried out by accessing your firm’s ACR record under the Data Protection Officer(s) section.

      How can Waystone Compliance Solutions help?

      The Cyber and Data Protection team at Waystone Compliance Solutions assists firms with the provision of relevant policies and procedures and employee training in relation to data protection and in addition can carry out gap analysis to identify any areas that require attention. Please reach out to your usual Waystone Compliance Solutions representative today to learn more.

       Next post
      Share

      More like this

      Preparing for MAS PS-G04 Annual Audit: How PSPs Can Get Audit-Ready

      In this article, we outline the key PS-G04 audit requirements for payment service providers in Singapore, the areas MAS expects…
      Read more

      APAC Asset Management Regulatory Review: H1 2026 Update

      Key Regulatory Developments Across Singapore and Hong Kong
      Read more

      Regulatory Updates June 2026 – APAC Region

      Stay informed with our Regulatory Update Navigate the ever-evolving regulatory landscape with our Regulatory Update. Our team of compliance experts…
      Read more

      MAS Consults on Proposed Technology Risk Management Amendments to Strengthen Financial Sector Resilience

      The Monetary Authority of Singapore (MAS) has issued a consultation paper proposing amendments to its Notices on Technology Risk Management…
      Read more

      Implications from Recent SFC Enforcement: Key Lessons for FRR and CMR Compliance

      On 1 June 2026, the Securities and Futures Commission (“SFC”) published a news release titled, “SFC reprimands and fines XHK…
      Read more

      Regulatory Updates May 2026 – APAC Region

      Stay informed with our Regulatory Update Navigate the ever-evolving regulatory landscape with our Regulatory Update. Our team of compliance experts…
      Read more

      Hong Kong SFC Circular on Account Opening Controls: Key Compliance Measures for Chinese Mainland Investor Accounts

      On 22 May 2026, the Hong Kong Securities and Futures Commission (SFC) issued an important circular titled “Expected controls for…
      Read more
      Contact us