GDPR can apply to Singapore companies even without any EU presence. Under Article 3(2) of the regulation, a Singapore company is subject to GDPR if it offers goods or services to EU residents or monitors their behaviour, regardless of where the company is located. PDPA compliance does not satisfy GDPR. The two frameworks share overlapping principles but have different scope, different individual rights, and materially different enforcement consequences.
When GDPR Applies to a Singapore Company
GDPR Article 3(2) applies to non-EU organisations in two scenarios: offering goods or services to EU residents, and monitoring the behaviour of EU residents through tracking, profiling, or behavioural advertising.
“Offering goods or services” does not require a completed transaction. According to the European Data Protection Board’s Guidelines 3/2018 on territorial scope, what triggers Article 3(2) is the intentional targeting of EU residents, not the physical location of the company or its servers. Indicators include EU-specific marketing, EU language options, EU payment currencies, and the ability to ship to EU addresses. A Singapore e-commerce business with EU-language product pages, a Singapore SaaS business with EU-based subscribers, and a Singapore professional services firm with EU clients are all likely within GDPR scope for their EU customer data.
For a Singapore company that falls within GDPR scope, compliance is a legal obligation. Under Article 83(5) of the GDPR, the most serious breaches (including violations of data subject rights and unlawful international data transfers) carry fines of up to €20 million or 4% of global annual turnover, whichever is higher, according to GDPR Article 83.
What GDPR Requires That PDPA Does Not
PDPA and GDPR share common DNA: both require lawful collection, transparent use, individual access rights, and data breach notification. The gaps, however, are significant.
Right to data portability. Under GDPR Article 20, individuals have the right to receive their personal data in a machine-readable format and transfer it to another controller. According to DataGuidance’s GDPR v. Singapore’s PDPA comparison, the PDPA does not include a right to data portability. Unlike the GDPR’s fully operative right to data portability under Article 20, Singapore’s PDPA contains a Data Portability Obligation introduced by the 2020 amendments, but that obligation has not yet been brought into force as of 2026. A Singapore company handling EU customer data must have a process to receive, structure, and export personal data on request.
Right to erasure. GDPR Article 17 gives individuals a broad right to request deletion of their personal data, including where it is no longer necessary for its original purpose or where consent is withdrawn. The PDPA’s deletion obligation is narrower: it arises when the purpose of collection is no longer served and retention is not required for business or legal reasons, according to DataGuidance. The GDPR right is individual-initiated and broadly available. The PDPA obligation is largely company-initiated and triggered by narrower conditions.
Data Protection Impact Assessments (DPIAs). GDPR Article 35 requires a DPIA before processing that is likely to result in high risk to individuals: large-scale profiling, systematic monitoring, or processing of special categories of data such as health or biometric information. The PDPA does not mandate DPIAs. A Singapore company deploying customer profiling for EU users, or building a health-data product for EU markets, is subject to this GDPR obligation regardless of what PDPA requires.
Records of Processing Activities (RoPA). Under GDPR Article 30, organisations with 250 or more employees, or any organisation whose processing poses risk to data subjects, must maintain a comprehensive record of all processing activities. The PDPA does not impose an equivalent record-keeping obligation.
Data breach notification timeline. Under GDPR Article 33, a breach posing risk to individuals must be reported to the relevant supervisory authority within 72 hours of the organisation becoming aware of it. Under Singapore’s Personal Data Protection (Notification of Data Breaches) Regulations 2021, organisations must notify the PDPC within three calendar days of determining that a breach is notifiable. The GDPR requires notification within 72 hours of becoming aware of a reportable breach, whereas the PDPA generally requires notification within three calendar days after determining that the breach is notifiable.
Mandatory DPO appointment. GDPR Article 37 requires certain organisations to appoint a Data Protection Officer: public authorities, companies whose core activities involve large-scale systematic monitoring, and companies processing sensitive data at scale. Unlike the GDPR, which requires a DPO only in specified circumstances, the PDPA requires organisations to designate at least one Data Protection Officer and make the DPO’s business contact information publicly available. For an overview of the DPO role and when one is needed in Singapore, see What Is a Data Protection Officer (DPO) and Does Your Singapore Company Need One?.
The EU Representative Requirement
A Singapore company subject to GDPR that has no legal establishment in the EU must designate an EU representative under Article 27 of the regulation. This requirement is mandatory, not optional, for organisations with meaningful EU data processing activity.
The EU representative acts as the point of contact for EU data protection authorities and for individuals exercising their GDPR rights. According to IAPP, the representative must be established in a member state where the organisation’s EU data subjects are located. Failure to designate an EU representative is itself an infringement, carrying fines of up to €10 million or 2% of global annual turnover under GDPR Article 83(4).
The exemption applies only to processing that is “occasional,” does not involve large-scale processing of special-category data, and is unlikely to result in risk to individuals. Many Singapore companies with ongoing EU customer relationships may find it difficult to rely on this exemption, depending on the nature, frequency and scale of their processing activities. Regulators have increasingly focused on compliance with Article 27 obligations in recent years of whether overseas businesses have an Article 27 representative in place, with enforcement activity increasing as of January 2026.
Cross-Border Data Transfers: PDPA Going Out, GDPR Coming In
Cross-border data compliance operates in both directions for Singapore companies with EU exposure.
Transfers from Singapore to other countries (PDPA). Section 26 of the PDPA restricts transfer of personal data outside Singapore unless the recipient provides a standard of protection comparable to the PDPA. The most commonly used mechanism is a contractual agreement requiring the overseas recipient to protect the data to Singapore standards. The PDPC’s Guide to Cross-Border Data Transfers sets out the available mechanisms: contractual clauses, binding corporate rules, consent, and the ASEAN Model Contractual Clauses.
Transfers from the EU to Singapore (GDPR). Singapore is not on the EU’s list of countries with an adequacy decision. An EU counterpart transferring personal data to Singapore must use a legal mechanism to satisfy GDPR Article 46: Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), or an approved derogation. For Singapore companies receiving data from EU businesses, the contract governing that transfer must include GDPR-compliant data transfer clauses. This is one of the most common contractual gaps in cross-border commercial arrangements between Singapore and EU counterparties.
Practical Steps for Singapore Companies with EU Exposure
Four steps address the core GDPR obligations for a Singapore company that sells to EU customers or handles EU personal data.
1. Confirm whether GDPR applies. The test is whether the company intentionally targets EU residents, not whether EU residents occasionally discover the product. A marketing campaign aimed at EU buyers activates GDPR scope. Organic website visitors from the EU who find the product incidentally are a lower-risk scenario, though the EDPB guidelines should be applied to the specific facts.
2. Map EU data flows. Identify all EU personal data in the business: from which touchpoints it is collected, where it is stored, what it is used for, and where it is transferred. This mapping is the input to the RoPA obligation under Article 30 and the trigger for any DPIA obligation.
3. Address the GDPR gaps on top of PDPA compliance. Review existing privacy notices, consent mechanisms, deletion processes, and breach response procedures against the GDPR requirements above. PDPA compliance is a foundation, not a destination. For a structured review of current PDPA compliance, see PDPA Compliance Audit: What Singapore Businesses Should Review Every Year.
4. Put the data transfer framework in place. If the business receives personal data from EU partners, confirm that the governing contracts include Standard Contractual Clauses. If the business transfers data outside Singapore, confirm that contracts satisfy the PDPA’s transfer limitation obligation.
FAQs: GDPR and Singapore Companies
Does serving one EU customer mean GDPR applies?
Not necessarily. GDPR Article 3(2) requires that goods or services are genuinely directed at EU residents. A one-off, unsolicited inquiry from an EU resident is unlikely to trigger GDPR scope on its own. A repeat pattern of serving EU customers with EU-specific terms, pricing, or marketing activates the territorial scope. The EDPB Guidelines 3/2018 provide the analytical framework.
Can a Singapore company satisfy GDPR by updating its privacy policy?
No. A GDPR-compliant privacy notice is necessary but not sufficient. GDPR requires organisational capability: processes to respond to subject access requests within one month, systems to issue data in portable formats on request, procedures to complete DPIAs, RoPA records, a 72-hour breach reporting mechanism, and potentially an EU representative and a DPO. The notice reflects the framework. It does not substitute for it.
Is PDPA certification a basis for GDPR adequacy?
No. Singapore is not on the EU’s adequacy list, and PDPA compliance creates no GDPR exemption. For Singapore-to-EU data flows, GDPR transfer mechanisms must be in place regardless of Singapore’s domestic data protection standards.
What is the practical starting point for a Singapore company with EU customers?
A data flow mapping exercise: document every EU personal data touchpoint, the purpose, the storage location, and the transfer mechanism. From that map, the GDPR obligations become specific and addressable rather than abstract. Three Squared Nine’s data privacy compliance service supports this exercise for Singapore businesses in cross-border environments.
How does GDPR interact with other Asian privacy frameworks for companies operating across APAC?
GDPR, PDPA, China’s PIPL, Japan’s APPI, and India’s DPDPA are distinct requirements that apply in parallel where applicable. PDPA compliance provides a starting point: its principles of purpose limitation, consent, and data accuracy align broadly with other APAC regimes. GDPR is the most prescriptive. For companies with significant cross-border exposure across APAC, mapping obligations by jurisdiction is more reliable than assuming compliance with one framework transfers to others.
How Three Squared Nine Supports Cross-Border Data Compliance
Data privacy compliance for Singapore businesses with EU exposure requires practical knowledge of both the PDPA and the GDPR, and a clear analysis of the gap between them. Three Squared Nine’s data privacy compliance service covers privacy policy review, data flow mapping, contractual data transfer frameworks, and PDPA audit support for businesses operating across borders.
For a foundational overview of what the PDPA requires of Singapore businesses, see Data Privacy Compliance in Singapore: What the PDPA Requires of Businesses.
Conclusion
GDPR applies to Singapore companies that intentionally serve EU customers or monitor EU residents, regardless of where the company is based. PDPA compliance does not substitute for GDPR: the two frameworks differ on portability, erasure, DPIAs, RoPA, breach notification timelines, and DPO obligations. For Singapore companies with EU exposure, the starting point is a data flow map that identifies which GDPR obligations apply, which contracts need updating, and whether an EU representative is required.
Disclaimer: This article is provided by Three Squared Nine for general informational purposes only and reflects publicly available information as at the date of publication. It does not constitute legal, regulatory, or compliance advice, and should not be relied upon as a substitute for professional advice tailored to your specific circumstances. Three Squared Nine provides in-house compliance and legal support services for internal and business purposes. It is not a law firm, and its services do not constitute legal advice or create a solicitor-client relationship. GDPR requirements, PDPA obligations, PDPC enforcement positions, and EU supervisory authority guidance are subject to change without notice. All information should be independently verified with the Personal Data Protection Commission (PDPC) and the European Data Protection Board (EDPB) before acting upon it. Three Squared Nine accepts no liability for any loss or damage arising from reliance on the information contained in this article.





