WorldPrivacyAtlas
Laws by country

Children & Minors Protections

PDPC Advisory Guidelines on the PDPA for Children's Personal Data in the Digital Environment

Singapore children's guidelines

Singapore · March 28, 2024

Read the status line before anything else: these Guidelines are NOT legally binding. What binds is the PDPA, and the Guidelines set out how the PDPC will interpret it where the data subject is a child — defined here as anyone 18 or younger, a wider bracket than most regimes use. The most consequential position is on consent: the PDPC accepts that a child aged 13 to 17 can give valid consent themselves, provided the collection, use, disclosure and withdrawal policies are readily understandable to them and they grasp the consequences of giving and withdrawing it — so Singapore does NOT impose blanket parental consent for teenagers the way Korea, Nigeria and Kenya do. Below 13, the Guidelines look to a parent or guardian. They also address the reasonableness of processing children's data, the heightened standard of protection expected, and how breach notification applies when the affected individuals are children. Treat non-compliance as evidence of an unreasonable practice under the PDPA rather than as a standalone offence.

Advisory Guidelines issued by the Personal Data Protection Commission, March 28, 2024, interpreting the Personal Data Protection Act 2012Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.