Jurisdiction Guide
Singapore Privacy & Data Protection Laws
Every regime below can apply to a business handling Singapore residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Section 2(1) defines 'organisation' broadly — including entities 'whether or not formed or recognised under the law of Singapore' and 'whether or not resident, or having an office or place of business, in Singapore' — so a foreign entity with zero Singapore presence can be caught simply by collecting, using, or disclosing personal data connected to Singapore (e.g. a foreign e-commerce site marketing to and collecting data from Singapore residents). Mechanically distinct from a formal 'offering' or 'monitoring' test but functionally similar in effect. Section 4 exempts public agencies, personal/domestic-capacity individuals, employees acting in the course of employment, and business contact information. No small-business threshold; health/financial data get additional sector-regulator rules layered on top, not instead of, the PDPA.