All Insights Personal Data Solution

How Long Can You Keep Personal Data? The PDPA's Retention Limitation Obligation

The Personal Data Protection Act (PDPA) sets no fixed number of years for keeping personal data. That's the part most retention policies get wrong: waiting for a deadline that was never going to arrive.

Compliz Insights · Personal Data Solution · ·

Our PDPA compliance checklist covers nine PDPA obligations, and the Retention Limitation Obligation gets only a short section there. It deserves more than that, because "just keep everything, it might be useful later" is one of the most common gaps we find when reviewing a business's actual data handling, and it's the one that quietly makes every other gap worse.

What Section 25 Actually Requires

Section 25 of the PDPA requires an organisation to stop retaining personal data, or anonymise it, once it's reasonable to assume the purpose for collecting it has been served and retention is no longer necessary for a legal or business reason. There's no Personal Data Protection Commission (PDPC)-prescribed number of years attached to this — the obligation is purpose-based, not calendar-based.

No PDPA Deadline Doesn't Mean No Deadline

This is the part that trips businesses up in both directions. Some assume "no fixed period" means they can keep data indefinitely, which the obligation doesn't allow. Others assume the PDPA gives them a specific number to work to, which it also doesn't. What actually sets the clock is whichever other law applies to that particular data.

A concrete example: the Inland Revenue Authority of Singapore (IRAS) requires businesses to keep accounting records and supporting documents for five years, counted from the end of the financial year the relevant transactions relate to, not from the transaction date itself — and that period extends further if a tax dispute is still open. Employment records, contractual documents and industry-specific regulatory records each carry their own retention logic. The PDPA's role isn't to set these numbers; it's to stop you from keeping data past the point any of them still applies.

Building a Retention Schedule That Actually Works

Secure Disposal, Not Just Deletion

Moving a file to a recycle bin or deactivating an account isn't disposal if the data is still recoverable. For physical records, that means shredding rather than bin disposal. For digital records, it means the deletion actually removes the data from primary storage and backups on a defined schedule, not just from the interface a staff member sees. If a vendor holds the data on your behalf — see our guide on managing third-party data processors — their contract should specify what "delete on request" actually means technically, not just state the phrase.

Why This Matters Beyond the Obligation Itself

Keeping data longer than necessary is a standalone PDPA breach, independent of whether that data is ever mishandled. It also expands the blast radius of any future incident: data that should have been disposed of two years ago is still data a breach can expose today. A tight retention practice is one of the few controls that reduces both your compliance exposure and your actual risk at the same time.

Not sure what your business is required to keep, and for how long?

Compliz reviews your current data holdings against the PDPA and any applicable sector rules, and builds a retention schedule your team can actually follow.

Request a Quote

Frequently Asked Questions

Does the PDPA set a default retention period for personal data?

No. Section 25 is purpose-based: stop retaining data once the purpose it was collected for is served and no legal or business reason requires keeping it longer. There's no fixed number of years set by the PDPA itself.

How long must I keep accounting records in Singapore?

IRAS requires businesses to retain accounting records and supporting documents for five years from the relevant Year of Assessment, longer if a tax dispute involving those records is still unresolved.

Is deleting a file enough, or do I need to do more?

Deletion needs to actually remove the data, including from backups, not just from the folder a staff member can see. For physical documents, that means secure shredding rather than ordinary disposal.

What if my industry regulator sets a different retention requirement?

Follow whichever requirement runs longer. Sector regulators can and do set their own retention rules on top of general PDPA and tax requirements.

Does anonymised data still count as personal data under the PDPA?

No. Data that has been genuinely anonymised, so it can no longer identify an individual, falls outside the PDPA's scope, which makes anonymisation a valid alternative to outright deletion in some cases.