Singapore’s Personal Data Protection Act applies to every organisation that handles personal data — with no minimum size or revenue threshold. An SME with five employees collecting customer contact details has the same legal obligations as a listed company. The PDPC can impose penalties of up to S$1 million or 10% of annual Singapore turnover (whichever is higher for organisations with annual Singapore turnover above S$10 million) for intentional or negligent breaches, under Section 48J of the PDPA. In October 2025, Marina Bay Sands was fined S$315,000 after personal data belonging to 665,495 patrons was exposed and sold on the dark web, according to the PDPC. The risk is not theoretical. For SMEs, the path to compliance is practical and achievable, but it requires deliberate implementation across nine defined obligations.
The 9 PDPA Obligations Singapore SMEs Must Meet
The Personal Data Protection Act imposes nine data protection obligations on all organisations that collect, use, or disclose personal data in Singapore, according to the Personal Data Protection Commission. These are not guidelines. They are legal requirements.
1. Consent Obligation. Collect, use, or disclose personal data only with the individual’s consent for specified, disclosed purposes.
2. Purpose Limitation. Use data only for the purposes for which consent was obtained. You cannot expand use without new consent.
3. Notification and Openness. Be transparent about how personal data is handled. Every organisation must appoint a Data Protection Officer and make the DPO’s contact details publicly accessible, on the company website for example.
4. Access and Correction. Individuals have the right to access their personal data held by your organisation and to correct inaccuracies. Responses must be provided within a reasonable timeframe, typically interpreted as within 30 days.
5. Accuracy. Personal data must be accurate and complete, particularly when it is used for decisions affecting individuals.
6. Protection. Implement reasonable security arrangements to prevent unauthorised access, collection, use, disclosure, copying, modification, disposal, or similar risks. This covers physical, technical, and organisational measures.
7. Retention Limitation. Retain personal data only for as long as it is necessary for the purpose it was collected, or as required by law. Delete or anonymise data when retention is no longer needed.
8. Transfer Limitation. Transfer personal data internationally only to countries with comparable data protection standards, or under arrangements that provide equivalent protection.
9. Data Breach Notification. Assess every data breach. Notify the PDPC and affected individuals if the breach meets the notification thresholds: either the breach is likely to cause significant harm to affected individuals, or it involves the personal data of 500 or more individuals, according to the Personal Data Protection (Notification of Data Breaches) Regulations 2021. Notification must be made within 3 calendar days of completing the breach assessment.
Step-by-Step: How to Implement PDPA Compliance
Step 1: Appoint Your Data Protection Officer
Appointing a DPO is mandatory. Every organisation must have at least one individual responsible for ensuring PDPA compliance, according to the PDPC.
The DPO does not need to be a data protection lawyer, but they must have practical knowledge of Singapore’s data protection laws and the ability to assess and manage data-related risks. For SMEs, this is often an existing employee who takes on the DPO role alongside other responsibilities. Their contact details must be published in a place individuals can find, typically the company website.
The PDPC has published a DPO Competency Framework and Training Roadmap to clarify the required competencies and support organisations in training data protection staff, according to the PDPC.
Step 2: Map Your Personal Data
You cannot protect data you cannot find. Create a personal data inventory covering:
- What personal data you collect (names, email addresses, NRIC numbers, financial information, health data)
- Where it is stored (servers, cloud platforms, third-party tools, physical files)
- How it flows through your systems (from collection through processing to deletion)
- Who has access to it internally and externally
- Whether any data is transferred to vendors or processors outside Singapore
Data mapping is the foundation of every other compliance step. Without it, you are working blind.
Step 3: Review and Fix Your Consent Framework
For each category of personal data you collect, document the purpose and confirm you have an appropriate basis for collection. For most SMEs, this means reviewing:
- Website contact forms and newsletter sign-ups
- Customer account registration processes
- Employee data collection at onboarding
- Data collected by third-party integrations (payment processors, CRMs, analytics tools)
Consent must be for a specific purpose, given voluntarily, and informed. Pre-ticked boxes do not constitute valid consent.
Important upcoming change: From 31 December 2026, private organisations must cease using NRIC numbers as a form of authentication, including as passwords, login IDs, or default credentials. The PDPC announced this requirement on 2 February 2026, with stepped-up enforcement including directions and financial penalties taking effect from 1 January 2027, according to the PDPC. If your current processes use NRIC for authentication, begin the transition before that deadline.
Step 4: Implement Security Controls
The Protection Obligation requires reasonable security arrangements. For an SME, this means:
- Encryption for sensitive personal data in storage and in transit
- Access controls: only staff who need personal data for their specific role should have access to it
- Password management policies
- Regular security reviews of third-party tools that process personal data
- A documented process for managing vendor access to customer data
The Marina Bay Sands case is instructive. The fine of S$315,000 arose from a failure to implement a second-layer security check on an API configuration during a software migration exercise. A single employee’s manual oversight was not caught for six months. The root cause was not malice but inadequate organisational controls. According to the PDPC, the breach exposed 665,495 patrons’ personal data, which was subsequently sold on the dark web.
Step 5: Establish a Retention and Deletion Schedule
Document retention periods for each category of personal data and build a process to enforce them. Common retention requirements in Singapore:
- Employment records: at least 5 years after employment ends (Employment Act)
- Tax and accounting records: at least 5 years (Income Tax Act)
- Customer personal data: delete or anonymise when it is no longer necessary for the business purpose
The simplest implementation is a data retention schedule reviewed annually, with a named person responsible for triggering deletion processes when retention periods expire.
Step 6: Build a Data Breach Response Plan
A data breach response plan is not optional. It is a regulatory requirement for the breach notification obligation to work in practice. The plan should cover:
- How to identify and classify a breach (what counts as a breach, who reports it internally, and to whom)
- How to assess whether a breach meets the notification thresholds
- How to notify the PDPC within 3 calendar days of completing the assessment
- How to notify affected individuals where required
- How to document the incident and the response
Test the plan at least once a year. A plan that has never been run through is not a plan but a document.
Step 7: Train Your Staff
Personal data breaches in Singapore are most often caused by human error: misconfigured systems, phishing attacks on staff, data sent to the wrong recipient. Staff training is both a regulatory expectation and a practical risk control.
At minimum, all staff who handle personal data should understand:
- What personal data your organisation collects and why
- How to handle requests from individuals to access or correct their data
- What to do if they suspect a data breach has occurred
- The consequences of mishandling personal data
Three Squared Nine’s data privacy compliance service covers staff training, data mapping, governance framework design, and incident response planning, structured as an ongoing programme rather than a one-off exercise.
Common PDPA Mistakes SMEs Make
Using NRIC numbers as passwords or verification codes. This is both a security risk and, from 1 January 2027, subject to stepped-up PDPC enforcement including financial penalties.
Retaining customer data indefinitely. Many SMEs have customer records going back years with no deletion process. The retention obligation applies to all of this data.
Sharing customer data with vendors without data processing agreements. If you send customer data to a third-party email platform, CRM, or payment processor, that vendor processes personal data on your behalf. A data processing agreement is required.
No written consent for marketing. Sending marketing communications to contacts who provided their details for a different purpose (such as to receive a quote) is a consent violation.
Not publishing DPO contact details. This is the most common technical breach found by the PDPC during investigations.
What the PDPC Looks for in Enforcement
PDPC enforcement actions increasingly focus on systemic operational gaps rather than isolated incidents. In May 2024, the PDPC published three enforcement decisions on 23 May 2024, with financial penalties totalling S$102,000 imposed on two organisations: PPLingo (S$74,000) for accountability and protection failures, and Horizon Fast Ferry (S$28,000) for protection failures. A third organisation, Cortina Watch, received directions without a financial penalty. In January 2026, People Central Pte Ltd was ordered to pay S$17,500 for breaching the protection obligation, one of four enforcement decisions published by the PDPC at the start of 2026, signalling a continuing focus on operational security gaps.
The factors that drive enforcement outcomes are:
- Whether the organisation had a functioning compliance programme at the time of the breach
- Whether it responded promptly and disclosed voluntarily
- The scale of the breach and harm caused to individuals
- Whether remediation steps were taken immediately
Organisations with documented, implemented compliance programmes (even if imperfect) consistently receive better outcomes than those that had no programme in place.
Three Squared Nine’s compliance audit service assesses the current state of PDPA implementation and identifies gaps before the PDPC does. More context on Singapore’s broader data protection framework is available in our data privacy compliance guide.
FAQs: PDPA Compliance for Singapore SMEs
Does PDPA apply to my SME if we only collect basic contact information?
Yes. The PDPA applies to any organisation that collects, uses, or discloses personal data in Singapore. Names, email addresses, and phone numbers are personal data. There is no minimum data volume or business size threshold.
What is the penalty for a PDPA breach?
For intentional or negligent breaches: up to S$1 million for organisations with annual Singapore turnover below S$10 million, or up to 10% of annual Singapore turnover for organisations above that threshold (whichever is higher than S$1 million), under Section 48J of the PDPA. Penalties are not automatic; PDPC investigates and considers mitigating factors including the organisation’s compliance programme and response.
Do we need to hire a dedicated Data Protection Officer?
No. The DPO role can be given to an existing employee alongside other responsibilities. The requirement is that the person has sufficient knowledge of Singapore data protection law to fulfil the role effectively, and that their contact details are publicly accessible.
When must we notify PDPC of a data breach?
When a breach is likely to cause significant harm to affected individuals, or when it involves personal data of 500 or more individuals. Notification must be made within 3 calendar days of completing the breach assessment, not within 3 days of the breach occurring.
What is the most common PDPA compliance gap for SMEs?
The absence of a documented data retention and deletion process. Most SMEs collect personal data but have no process for deciding when to delete it. This is both a legal gap under the retention limitation obligation and a practical risk: data that is retained indefinitely grows as a liability over time.
Conclusion
PDPA compliance for Singapore SMEs is achievable when it is built as a practical programme rather than treated as a documentation exercise. The nine obligations are defined, the implementation steps are concrete, and the cost of a well-run programme is a fraction of the cost of a PDPC investigation, and far less than the reputational damage of a publicly disclosed breach.
Disclaimer: This article is provided by Three Squared Nine for general informational purposes only and reflects publicly available information as at the date of publication. It does not constitute legal, regulatory, or compliance advice, and should not be relied upon as a substitute for professional advice tailored to your specific circumstances. Three Squared Nine provides in-house compliance and legal support services for internal and business purposes. It is not a law firm, and its services do not constitute legal advice or create a solicitor-client relationship. The PDPA’s obligations, PDPC enforcement positions, advisory guidelines, and penalty structures are subject to change without notice. All information should be independently verified with the Personal Data Protection Commission (PDPC) before acting upon it. Three Squared Nine accepts no liability for any loss or damage arising from reliance on the information contained in this article.





