PDPA
Singapore PDPA Data Protection Checklist
A PDPA checklist for consent, purpose limitation, DPO, data-breach notification, and PDPC expectations.
- Estimated time
- 2–4 Months
- Audience
- Organizations Collecting Personal Data in Singapore
- Last updated
Operational reference for Singapore PDPA. The PDPC issues guidance and enforcement; this is not legal advice.
Progress is saved in this browser only. Nothing is sent to a server.
Phase 1: Accountability
Phase 2: Consent & Purpose
Phase 3: Protection & Retention
Phase 4: Breach & Governance
FAQ
Who enforces PDPA?+–
The Personal Data Protection Commission (PDPC) of Singapore.
Is consent always required?+–
PDPA is consent-based with specified exceptions (e.g., some legitimate interests after assessment).
Does GDPR paperwork suffice?+–
Useful, but PDPA has its own DPO, breach, and transfer rules.
What is a data intermediary?+–
A processor-like role processing on behalf of another organization.
Related field notes
The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer