Jurisdiction Guides / Asia-Pacific
Singapore Privacy & Data Protection Laws
Every regime below can apply to a business handling Singapore residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Section 2(1) defines 'organisation' broadly — including entities 'whether or not formed or recognised under the law of Singapore' and 'whether or not resident, or having an office or place of business, in Singapore' — so a foreign entity with zero Singapore presence can be caught simply by collecting, using, or disclosing personal data connected to Singapore (e.g. a foreign e-commerce site marketing to and collecting data from Singapore residents). Mechanically distinct from a formal 'offering' or 'monitoring' test but functionally similar in effect. Section 4 exempts public agencies, personal/domestic-capacity individuals, employees acting in the course of employment, and business contact information. No small-business threshold; health/financial data get additional sector-regulator rules layered on top of, not instead of, the PDPA.
Children & Minors Protections · 1
Read the status line before anything else: these Guidelines are NOT legally binding. What binds is the PDPA, and the Guidelines set out how the PDPC will interpret it where the data subject is a child — defined here as anyone 18 or younger, a wider bracket than most regimes use. The most consequential position is on consent: the PDPC accepts that a child aged 13 to 17 can give valid consent themselves, provided the collection, use, disclosure and withdrawal policies are readily understandable to them and they grasp the consequences of giving and withdrawing it — so Singapore does NOT impose blanket parental consent for teenagers the way Korea, Nigeria and Kenya do. Below 13, the Guidelines look to a parent or guardian. They also address the reasonableness of processing children's data, the heightened standard of protection expected, and how breach notification applies when the affected individuals are children. Treat non-compliance as evidence of an unreasonable practice under the PDPA rather than as a standalone offence.
Cross-Border Data Transfer · 1
s. 26(1) bars transferring personal data outside Singapore unless the organisation ensures a standard of protection comparable to the PDPA's will be maintained over it. Regulation 10 makes that concrete: the recipient must be bound by legally enforceable obligations — typically contract, binding corporate rules for intra-group transfers, a certification such as APEC CBPR, or the destination's own law where it provides comparable protection. 'Comparable' is not 'identical': the test is comparable overall effect, not a mirror of the PDPA. Singapore's model is exporter accountability rather than government pre-approval, so there is no filing or adequacy list to consult — the burden is on the organisation to document why its chosen mechanism holds.
Data Security & Breach Notification · 1
A breach is notifiable if it is of significant scale — the Regulations set that at 500 or more affected individuals — or if it results, or is likely to result, in significant harm to any affected individual. Once the organisation has assessed a breach as notifiable it must notify the PDPC as soon as practicable and in any case no later than three calendar days after that assessment, and notify affected individuals as soon as practicable where the significant-harm limb is engaged. The three days run from the assessment, not from discovery, but the assessment itself must be prompt — an organisation cannot extend its own deadline by taking longer to decide. Data intermediaries must notify the organisation they act for without undue delay.
Other Asia-Pacific jurisdictions