All Insights Personal Data Solution

Consent, Marketing Messages, and the Do Not Call Registry: A Singapore Compliance Guide

Checking the Do Not Call Registry isn't the same as having permission to market to someone. Most businesses actually need both, not either one on its own.

Compliz Insights · Personal Data Solution · ·

Direct marketing by phone, SMS or fax sits at the intersection of two separate Personal Data Protection Act (PDPA) requirements, and treating either one as sufficient on its own is where most SMEs go wrong: checking the registry without having consent, or having consent without checking the registry.

Two Separate Checks, Not One

The PDPA's general Consent Obligation requires a lawful basis, typically consent, before using someone's phone number or other contact details for marketing. Separately, Part 9 of the PDPA establishes the Do Not Call (DNC) Registry — three registers covering no-voice-call, no-text-message and no-fax preferences — and prohibits sending marketing messages to Singapore telephone numbers listed there. Passing one check doesn't mean you've passed the other.

Who the DNC Rules Actually Cover

The DNC provisions apply to organisations that send, cause to be sent, or authorise the sending of telemarketing messages to Singapore telephone numbers, covering voice calls, text and fax messages used to offer, advertise or promote goods, services, land, or business or investment opportunities. Before running a campaign, organisations conducting telemarketing need to submit their number lists for checking against the Registry.

When You Don't Need to Check the Registry

Consent Still Applies Even Off the Registry

A number not appearing on the DNC Registry isn't itself permission to market to it. The PDPA's general Consent Obligation still requires a lawful basis for using that contact detail for marketing purposes — the two requirements run in parallel, and a clean Registry check doesn't substitute for having obtained consent in the first place. If a marketing platform or customer relationship management (CRM) vendor handles this on your behalf, the same accountability principle from our vendor management guide applies: you remain responsible even though the platform does the sending.

Handling Opt-Outs Properly

Every marketing message sent under the continuing-relationship exemption needs a working opt-out, and any opt-out request must be actioned within 10 business days, without charging a fee, requiring a reason, or imposing any other condition. Once someone has opted out, further commercial messages need fresh consent before resuming, not a pause-and-resume approach.

Running SMS, call or fax marketing campaigns?

Compliz reviews your consent records and DNC compliance process, so your marketing doesn't become your next PDPA complaint.

Request a Quote

Frequently Asked Questions

Do I need to check the DNC Registry before every marketing SMS or call?

Generally yes, unless you have the recipient's clear, unambiguous consent for that number, or the continuing-relationship exemption applies with a proper opt-out included.

What counts as a "marketing message" under the DNC rules?

Voice calls, text messages or fax messages offering, advertising or promoting goods, services, land, or business or investment opportunities.

Can I market to existing customers without checking the Registry?

Yes, under the continuing-relationship exemption, for similar or related products or services, provided each message includes a working opt-out facility.

How fast must I action an opt-out request?

Within 10 business days, with no fee charged and no reason required from the recipient.

If a number isn't on the DNC Registry, can I message it freely?

No. You still need a lawful basis, typically consent, to use that number for marketing under the PDPA's general Consent Obligation, which is separate from the DNC check.