Short answer: yes, it applies to you. The Personal Data Protection Act 2012 (PDPA) covers every organisation in Singapore's private sector that collects, uses, or discloses personal data — there is no carve-out for small businesses, sole proprietorships, or family-run firms.
Does the PDPA apply to my business?
If your business holds a customer database, a mailing list, staff records, supplier contacts, or even just names and phone numbers collected through a website form, the PDPA applies to you. It governs how organisations collect, use, disclose, and protect the personal data of individuals in Singapore, and it sits alongside — not instead of — any sector-specific rules your business may already follow (for example, banking secrecy or healthcare regulations).
The Act is enforced by the Personal Data Protection Commission (PDPC), and its obligations apply regardless of company size. A five-person accounting firm or a family-run retail business has the same underlying obligations as a large enterprise — what differs is how proportionate the compliance programme needs to be.
The core obligations, at a glance
The PDPA is built around a set of data protection obligations that apply throughout the lifecycle of personal data your business touches:
- Consent and purpose limitation — you generally need an individual's informed consent before collecting, using, or disclosing their data, and you may only use it for purposes a reasonable person would consider appropriate. Narrow exceptions exist for "legitimate interests" and "business improvement purposes," such as internal analytics.
- Notification — individuals must be told why their data is being collected, typically through a privacy policy or a collection notice at the point of interaction (a sign-up form, a job application, an invoice).
- Access and correction — individuals can request a copy of the personal data you hold on them, and ask for corrections, generally within 30 days and at no charge.
- Accuracy — data used to make a decision about an individual, or disclosed to another organisation, must be reasonably accurate and complete.
- Protection — reasonable security arrangements must be in place to prevent unauthorised access, collection, use, disclosure, or disposal of personal data.
- Retention limitation — personal data cannot be kept longer than is necessary for the purpose it was collected for, or for legal or business reasons.
- Transfer limitation — if you transfer personal data outside Singapore (to an overseas payroll vendor or cloud CRM, for instance), the receiving party must provide a comparable standard of protection.
- Openness and accountability — you must be able to demonstrate compliance, which in practice means having a written data protection policy and designated personnel responsible for it.
Appointing a Data Protection Officer
Under Section 11(3) of the PDPA, every organisation must designate at least one Data Protection Officer (DPO), and their business contact information must be made publicly accessible — both on the company's own website or materials, and by registering the DPO's details with the PDPC. There is no exemption based on how little personal data the business handles.
For an SME, this does not need to be a dedicated, full-time hire. Many businesses appoint an existing staff member — someone in operations, HR, or finance — to take on the role alongside their regular duties, or engage an external compliance provider. In substance, the DPO is responsible for:
- Developing and maintaining the company's data protection policy, including consent and breach-response procedures.
- Handling access requests and data-related complaints from customers or staff.
- Assessing new systems or vendors for data protection risk before they go live.
- Training staff on basic data-handling practices.
- Keeping an eye on PDPC guidance and making sure the business's practices keep pace with it.
Mandatory data breach notification
This is the obligation with the most immediate consequences if it's missed. A data breach is notifiable to the PDPC if it meets either of two tests:
- The significant harm test — the breach is likely to cause significant harm to affected individuals, for example where a full name is exposed together with financial information, health data, or an identifier such as a passport number.
- The significant scale test — the breach affects 500 or more individuals, regardless of the type of data involved.
Once a breach is discovered, an organisation has up to 30 calendar days to assess whether it is notifiable. If it is, the PDPC must be notified within 3 calendar days of that determination, and affected individuals must be notified as soon as practicable — typically at the same time as, or shortly after, the PDPC notification. The notification to the PDPC should set out a chronology of events, the number of individuals affected, the categories of data involved, the containment and remediation steps taken, and the DPO's contact details.
What this actually looks like for an SME
Most Singapore SMEs don't need an elaborate compliance programme — they need a handful of things done properly and kept up to date:
- A short, plain-language data protection policy, published on the website, that says what data you collect and why.
- A named DPO with contact details published and registered with the PDPC.
- Consent language built into sign-up forms, job applications, and any marketing opt-ins — and a record of when consent was given.
- Basic access controls on customer and staff data (password-protected files, restricted shared drives, staff offboarding checklists).
- A simple, written breach response plan so that if something does go wrong, the 30-day assessment clock isn't the first time anyone has thought about the process.
- A retention schedule that says when old customer or applicant data gets deleted, rather than kept indefinitely "just in case."
Penalties for non-compliance
Following the 2021 amendments to the PDPA, financial penalties for a breach of the data protection obligations can reach S$1 million, or 10% of the organisation's annual turnover in Singapore, whichever is higher. For a smaller business, that turnover-linked ceiling matters as much as the headline figure — it's precisely the kind of exposure that catches founders who assumed PDPA enforcement was reserved for large enterprises.
The bottom line
The PDPA isn't a big-company problem, and for most SMEs it isn't an expensive one either — but it does need a named owner, a written policy, and a breach plan sitting in a drawer before you need it, not after. The highest-risk gap we see is not consent language on a website; it's not knowing who the DPO is, and not having a plan for the 30-day clock that starts the moment a breach is discovered.
If you're not sure whether your current data-handling practices would hold up, a short review is usually enough to find the gaps and close them. See our Advisory services to learn more about how we support SMEs on compliance matters like this.