Singapore's Personal Data Protection Act 2012, administered by the Personal Data Protection Commission, governs consent, purpose limitation, protection and the transfer of personal data, alongside the national Do Not Call regime.
22 of our 22 tracked controls apply in Singapore, graded by how firmly the law requires each one.
A named person or role accountable for data protection, with published contact where required.
A living inventory of what personal data you hold, why, where it sits and where it flows.
A valid legal reason for each use of personal data, mapped per activity.
Where you rely on consent it is freely given, specific, informed, unbundled and withdrawable, with a record.
A published, current privacy notice giving the prescribed information.
Ability to find, correct and delete one person's data on request within the legal deadline.
Every export of personal data is covered by a lawful transfer mechanism.
Encryption in transit and at rest, least-privilege access, and access logging.
A written breach plan and knowledge of each market's notification clock.
DPAs with vendors handling your data, with controller/processor roles defined.
Defined, enforced retention periods and deletion, balancing storage-limitation and legal keep-periods.
Age assurance and verifiable parental consent; no behavioural tracking of children.
Explicit consent, tighter access, and often a DPIA for special-category data.
Lawful basis/consent for e-marketing and an unsubscribe route.
A DPIA/impact assessment for high-risk processing; some markets require a filed dossier.
Card data offloaded to a compliant processor; PCI-DSS scope controlled.
A published route to raise a privacy complaint; India requires a grievance officer.
Cookie/tracker consent and an accurate cookie policy where required (esp. EU/UK).
A local/EU representative where you have no establishment in a market that requires one.
Safeguards and transparency for automated decision-making and profiling.
Registration or filing with the DPA where the market requires it.
Local storage/residency requirements for certain data or sectors.
Answer a few questions and PrivMatrix shows you exactly where you stand against PDPA, then generates the policies, notices and registers that close each gap - written for Singapore.