Skip to content

PDPA

Singapore PDPA Data Protection Checklist

A PDPA checklist for consent, purpose limitation, DPO, data-breach notification, and PDPC expectations.

Estimated time
2–4 Months
Audience
Organizations Collecting Personal Data in Singapore
Last updated

Operational reference for Singapore PDPA. The PDPC issues guidance and enforcement; this is not legal advice.

Progress0% Completed

Progress is saved in this browser only. Nothing is sent to a server.

Phase 1: Accountability

Phase 2: Consent & Purpose

Phase 3: Protection & Retention

Phase 4: Breach & Governance

FAQ

Who enforces PDPA?+

The Personal Data Protection Commission (PDPC) of Singapore.

Is consent always required?+

PDPA is consent-based with specified exceptions (e.g., some legitimate interests after assessment).

Does GDPR paperwork suffice?+

Useful, but PDPA has its own DPO, breach, and transfer rules.

What is a data intermediary?+

A processor-like role processing on behalf of another organization.

Related field notes

The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer