Back to Frameworks

Singapore PDPA

Singapore
12 domains
33 controls

Singapore Personal Data Protection Act (2012, as amended including 2020 Data Portability Amendment).

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (12)

Access/Correction

4 controls
Controls in the Access/Correction domain of Singapore PDPA4 controls
CodeTitle
s.21Security Measures Regarding Information Processed by Operator
s.22Notification of Security Compromises
s.22APreservation of Copies of Personal Data
s.26FData Portability Obligation

Accountability

4 controls
Controls in the Accountability domain of Singapore PDPA4 controls
CodeTitle
PDPC AG-DPbDData Protection by Design (PDPC Guidance)
s.11Consent, Justification and Objection
s.12Collection Directly from Data Subject
s.4(2)Application to Data Intermediaries

Accuracy

1 controls
Controls in the Accuracy domain of Singapore PDPA1 controls
CodeTitle
s.23Access to Personal Information

Consent

6 controls
Controls in the Consent domain of Singapore PDPA6 controls
CodeTitle
s.13Collection for Specific Purpose
s.14Retention and Restriction of Records
s.15Further Processing to be Compatible with Purpose of Collection
s.15ADeemed Consent by Notification
s.16Quality of Information
s.17Documentation

Data Breach Notification

5 controls
Controls in the Data Breach Notification domain of Singapore PDPA5 controls
CodeTitle
s.26ANotification of Data Breach (Definition)
s.26CDuty to Conduct Breach Assessment
s.26DNotification to PDPC of Data Breach
s.26D(2)Notification to Affected Individuals
s.26EData Intermediary Breach Notification

Do Not Call

3 controls
Controls in the Do Not Call domain of Singapore PDPA3 controls
CodeTitle
Part IX (s.43-48)Do Not Call Provisions - Specified Message
s.36Do Not Call Registry Maintenance
s.43AIdentifying Sender Information

Notification

1 controls
Controls in the Notification domain of Singapore PDPA1 controls
CodeTitle
s.20Information Processed by Operator or Person Acting Under Authority

Other

5 controls
Controls in the Other domain of Singapore PDPA5 controls
CodeTitle
PDPC AG-AIUse of Personal Data in AI Systems (PDPC Guidance)
s.48BProhibition Against Unauthorised Disclosure
s.48CProhibition Against Improper Use of Personal Data
s.48DProhibition Against Re-identification of Anonymised Data
s.48IFinancial Penalties (2020 Amendments)

Protection

1 controls
Controls in the Protection domain of Singapore PDPA1 controls
CodeTitle
s.24Correction of Personal Information

Purpose Limitation

1 controls
Controls in the Purpose Limitation domain of Singapore PDPA1 controls
CodeTitle
s.18Notification to Data Subject When Collecting Personal Information

Retention

1 controls
Controls in the Retention domain of Singapore PDPA1 controls
CodeTitle
s.25Manner of Access

Transfer

1 controls
Controls in the Transfer domain of Singapore PDPA1 controls
CodeTitle
s.26Transfer Limitation Obligation

Frequently Asked Questions

What is Singapore PDPA?

Singapore PDPA is a compliance framework from Singapore with 12 domains and 33 controls. Singapore Personal Data Protection Act (2012, as amended including 2020 Data Portability Amendment). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does Singapore PDPA have?

Singapore PDPA has 33 controls organised across 12 domains. The largest domains are Consent (6 controls), Data Breach Notification (5 controls), Other (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does Singapore PDPA map to?

Singapore PDPA does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I get started with Singapore PDPA compliance?

Start your Singapore PDPA compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Singapore PDPA requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 33 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.

Get Started Free →

Free forever — no credit card required