Cross-Border Data Transfer
Personal Data Protection Act 2012 — Transfer Limitation Obligation
Singapore · July 2, 2014
s. 26(1) bars transferring personal data outside Singapore unless the organisation ensures a standard of protection comparable to the PDPA's will be maintained over it. Regulation 10 makes that concrete: the recipient must be bound by legally enforceable obligations — typically contract, binding corporate rules for intra-group transfers, a certification such as APEC CBPR, or the destination's own law where it provides comparable protection. 'Comparable' is not 'identical': the test is comparable overall effect, not a mirror of the PDPA. Singapore's model is exporter accountability rather than government pre-approval, so there is no filing or adequacy list to consult — the burden is on the organisation to document why its chosen mechanism holds.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.