The Personal Data Protection Act (PDPA) Singapore – what are the requirements?

      The Personal Data Protection Act (PDPA) sets out clear minimum standards of safeguarding personal data in Singapore. It aims to bring together sector-specific legislative and regulatory frameworks relating to the financial services industry in Singapore.

      The PDPA sets out the obligations in respect of (a) collection, (b) use, (c) disclosure and (d) care of personal data in Singapore. Personal data refers to data about an individual who can be identified from that data, or from that data and other information to which the organisation has or is likely to have access, which includes customers, suppliers, and employees.

      Data protection framework

      Firms are expected to have in place an appropriate personal data protection framework that starts with corporate governance/accountability for data protection practices in the management of personal data under the firm’s possession or control, this must also include breach management, training and communications.

      We have set out below some basic elements that should be in included in a firm’s data protection framework:

      • develop a Data Protection (DP) policy
      • appoint a DPO and ensure their business contact information is available to the public
      • identify risks and gaps using the PDPA Assessment Tool for Organisations (PATO)
      • embed data protection as part of corporate governance and establish a data protection reporting structure
      • embed regular monitoring and reporting mechanisms within your Enterprise Risk Management (ERM) framework
      • establish a data breach management team
      • develop a 4-step action plan for data breach response
      • develop a complaint handling procedure
      • develop a staff training and communications plan
      • ensure all staff complete the PDPA e-Learning programme
      • carry out an annual review of data protection policies
      • conduct a table-top exercise to test the data breach response plan
      • provide one refresher training for key employees on handling personal data
      • document data assets and flows using a data inventory map.

      Data Protection Officer (DPO) requirements

      Firms are required to designate at least one individual as the DPO and although it is not mandatory under the Act to register the DPO’s details with ACRA, firms are strongly encouraged to do so.

      The PDPC site states that “Organisations are also required to ensure that at least one DPO’s business contact information is made available to the public. The business contact information may be a general telephone or email address of the organisation.”

      Although this is not a specific MAS-related rule, it is still a legal requirement and is something that can be carried out in a short space of time. We would urge firms to register the DPO’s details with ACRA if they have not already done so . You can find out if this has already been carried out by accessing your firm’s ACR record under the Data Protection Officer(s) section.

      How can Waystone Compliance Solutions help?

      The Cyber and Data Protection team at Waystone Compliance Solutions assists firms with the provision of relevant policies and procedures and employee training in relation to data protection and in addition can carry out gap analysis to identify any areas that require attention. Please reach out to your usual Waystone Compliance Solutions representative today to learn more.

       Next post
      Share

      More like this

      Compliance Readiness 2026: SFC Checklist and Key Priorities for Fund Managers

      As 2025 comes to a close, Licensed Corporations (“LCs”) with Type 9 licenses in Hong Kong face a pivotal transition…
      Read more

      Compliance Readiness 2026: MAS Checklist and Key Priorities for Fund Managers

      As 2025 draws to a close, Licensed Fund Management Companies (LFMCs) in Singapore face a critical transition into 2026. Beyond…
      Read more

      CPT Deadline 2025 – Complete Your Hours Online with Waystone

      Stay ahead of regulatory requirements and protect your firm’s license. All licensed entities, representatives, and Responsible Officers (ROs) must complete…
      Read more

      Hong Kong’s Digital Asset Regulatory Landscape: The Current State, What’s Next and How to Prepare

      Hong Kong has established itself as a leading global hub for virtual assets and fintech innovation, due to the bold…
      Read more

      Regulatory Updates October 2025 – APAC Region

      Stay informed with our Regulatory Update Navigate the ever-evolving regulatory landscape with our Regulatory Update. Our team of compliance experts…
      Read more

      MAS Consultation on Measures to Enhance Investor Recourse Avenues in Market Misconduct Cases

      On 24 October 2025, the Monetary Authority of Singapore (“MAS”) issued a consultation paper proposing recommendations aimed at enhancing investor…
      Read more

      Singapore Corporate Tax Filing Deadline for 2025

      As the financial year rolls on, companies in Singapore should take note of an important compliance milestone fast approaching: the…
      Read more
      Contact us