Personal Data Protection Regulations, 2021
The PDP Regulations provide detailed requirements for PDPA compliance including recognition of APEC Cross-Border Privacy Rules (CBPR) System and Privacy Recognition for Processors (PRP) System as approved transfer mechanisms. They establish prescribed situations where transfer obligations are satisfied and provide operational guidance for implementing PDPA requirements. Download PDF
Personal Data Protection (Amendment) Act, 2020
The Amendment Act, passed in Parliament on 2 November 2020 with most provisions effective from 1 February 2021, introduced significant updates to the PDPA including mandatory data breach notification within 3 calendar days, increased penalties up to 10% of annual turnover or SGD 1 million, deemed consent provisions, and enhanced requirements for data portability. The […]
Personal Data Protection Act (PDPA), 2012
The Personal Data Protection Act 2012 is Singapore’s principal data protection legislation that provides a baseline standard of protection for personal data. It complements sector-specific frameworks and comprises requirements governing the collection, use, disclosure and care of personal data. The Act establishes nine key obligations for organizations including consent, purpose limitation, notification, access and correction, […]