All Insights Personal Data Solution

PDPA Compliance for Singapore SMEs: A Practical Checklist

Nine obligations make up most of what the PDPA actually asks of a Singapore business. Few SMEs have all nine written down in one place.

Compliz Insights · Personal Data Solution · ·

The Personal Data Protection Act applies to virtually every organisation operating in Singapore that collects, uses or discloses personal data — which in practice means almost every business with customers, employees or suppliers. The obligations aren't complicated individually, but they're easy to leave half-done when there's no single checklist tying them together. This is that checklist.

1. Appoint a Data Protection Officer

Non-negotiable and often the first gap we find. See our separate guide on the DPO requirement for what the role covers and whether to keep it in-house or outsource it.

2. Have a Written Data Protection Policy

A policy covering what personal data you collect, why, how long you keep it, and who it's shared with. This isn't just an internal document — your public-facing Privacy Policy is effectively the external half of this obligation, and the two should say the same thing.

3. Get Proper Consent (or Rely on a Valid Exception)

4. Collect Only What You Need

The Purpose Limitation obligation means data collected for one purpose (say, fulfilling an order) shouldn't be reused for an unrelated purpose (say, marketing) without separate consent or a valid basis. Audit your forms and intake processes for fields collected "just in case" with no clear purpose attached.

5. Keep Data Accurate and Secure

6. Don't Keep Data Longer Than Necessary

The Retention Limitation obligation requires you to stop keeping personal data, or anonymise it, once it's no longer needed for the purpose it was collected or for a legal/business reason. A policy that keeps everything indefinitely "in case it's useful" isn't compliant, and it also expands your exposure if a breach ever occurs.

7. Have a Breach Response Process Ready

The Notification Obligation requires assessing and, where the threshold is met, notifying PDPC and affected individuals within legislated timeframes. Waiting until a breach actually happens to figure out this process out costs you the very time the law expects you to move quickly with. See our breach notification guide for the specific timelines and thresholds.

8. Honour Access and Correction Requests

Individuals can ask what personal data you hold about them and how it's been used, and can ask you to correct inaccurate data. You need a process to receive, verify and respond to these requests within a reasonable time, not an ad hoc scramble each time one arrives.

9. Check Your Vendors

If a third-party vendor processes personal data on your behalf (a payroll provider, a marketing platform, a cloud host), you remain responsible for how that data is protected. Contracts with data-processing vendors should include data protection obligations, not just service-level terms.

Not sure how many of these boxes your business actually ticks?

Compliz reviews your current data handling against the PDPA, closes the gaps, and can act as your outsourced DPO on an ongoing basis.

Request a Quote

Frequently Asked Questions

Does the PDPA apply to B2B data, not just consumers?

Yes. The PDPA covers personal data generally, including employee, client contact and vendor contact data, not just consumer data.

How is Singapore's PDPA different from Malaysia's?

Both share similar core principles, but the two Acts have different scope, thresholds and enforcement mechanisms; a business operating in both countries should check compliance separately against each.

What counts as "personal data" under the PDPA?

Any data that can identify an individual, alone or combined with other information the organisation has or is likely to have access to.

Can customers ask me to delete their data?

Customers can withdraw consent and ask you to stop using their data, though you may still be required to retain some records for legal or contractual reasons.

Is consent always required to use personal data?

No. The PDPA also allows use under exceptions like deemed consent or legitimate interests, subject to specific conditions and, in some cases, a documented assessment.