Skip to content

Stratgik — technology strategy and business systems engineering.
Delivery across the USA, UK, UAE and India.

Talk about a problem

Singapore PDPAFines up to 10% of Singapore turnover

Singapore PDPA compliance, built into your systems. Fixed fees from S$2,400.

Every organisation handling personal data in Singapore needs a Data Protection Officer, a breach process that can notify the PDPC within three days, and consent practices that stand up to scrutiny. We set it up in your website, apps and CRM, not just in a policy document.

  • Fixed fees in S$
  • Implemented in your systems, not just a policy
  • Engineers, working alongside your lawyers

What is at stake

Enforcement under the Personal Data Protection Act 2012 (PDPA)

The Personal Data Protection Commission publishes its enforcement decisions, so a breach can also become public.

  1. 10% / S$1m

    Breaches of the data protection obligations, including failure to protect personal data

  2. Directions

    PDPC can order you to stop collecting data, destroy data or fix your practices

  3. Offences

    Mishandling personal data or re-identifying anonymised data can be criminal offences for individuals

What the law asks, in plain words

Eight things to get right in Singapore

  • Data Protection Officer

    Every organisation must appoint at least one DPO and publish their business contact details.

  • Consent and notification

    Tell people why you collect their data and get consent, or rely on a documented exception such as legitimate interests after an assessment.

  • 3-day breach notification

    Assess a suspected breach within 30 days. If it is notifiable, tell the PDPC within 3 calendar days, and affected individuals where required.

  • Protection obligation

    Reasonable security arrangements to prevent unauthorised access, copying, modification or disposal.

  • Access and correction

    Give people access to their data and how it has been used, and correct errors, usually within 30 days.

  • Retention limitation

    Stop keeping personal data once the purpose is over and there is no business or legal need.

  • Transfer limitation

    Data sent overseas must be protected to a standard comparable to the PDPA, usually through contracts.

  • Do Not Call rules

    Check the DNC Registry before marketing calls, texts or faxes to Singapore numbers.

Free self-check

How ready is your organisation?

Ten questions, two minutes. Nothing is sent anywhere unless you ask for help.

0/ 100

Answer the questions to see your score

0 of 10 answered

  1. 1Have you appointed a DPO and published their contact details?
  2. 2Do you have a record of the personal data you collect and why?
  3. 3Do your forms state the purpose and collect clear consent?
  4. 4Have you documented a legitimate interests assessment where you rely on it?
  5. 5Could you assess a breach within 30 days and notify the PDPC within 3 days?
  6. 6Is personal data encrypted and access limited to those who need it?
  7. 7Can you respond to an access request within 30 days?
  8. 8Do you delete data once it is no longer needed?
  9. 9Are overseas transfers covered by contracts?
  10. 10Do you check the DNC Registry before marketing to Singapore numbers?

How we get you compliant

Four steps, done with your team

  1. 1

    Discover

    Find every copy of personal data

    Website, apps, CRM, ERP, spreadsheets, messaging tools and vendors.

  2. 2

    Decide

    Rank the gaps by risk

    Each gap scored against enforcement exposure and effort, so the serious ones get fixed first.

  3. 3

    Implement

    Fix it in your systems

    Notices, consent, request workflows, access controls, retention and vendor terms.

  4. 4

    Hand over

    Train people, rehearse a breach

    A live session for the staff who handle data and a practice run of breach reporting.

Pricing

Fixed fees. No surprises.

For organisations with one website or product and up to five systems holding personal data. Larger scope is quoted in writing before you pay anything.

Readiness Audit

Know exactly where you stand under the PDPA.

S$2,400one-time
+ GST

Report in 7 working days

Choose Readiness Audit
  • Discovery session with an engineer
  • Data map across website, apps, CRM and vendors (up to 5 systems)
  • Gap report against the 11 PDPA obligations
  • Gaps ranked by enforcement risk
  • 90-day action plan

Recommended

Compliance Setup

We put the controls into your systems.

S$7,900one-time
+ GST

Typically 3 to 5 weeks

Choose Compliance Setup
  • Everything in Readiness Audit
  • Data protection policy and notices
  • Consent capture and records on forms
  • DPO setup and published contact
  • Breach assessment and 3-day PDPC notification playbook
  • Access and correction request workflow
  • Retention schedule and overseas transfer contracts checklist
  • Live staff training session

PDPA Care

Keep compliance current as the business changes.

S$990per month
+ GST

Cancel any month

Choose PDPA Care
  • Access and correction request support
  • Quarterly review of systems and vendors
  • Breach support during Singapore business hours
  • Updates when PDPC guidance changes
  • Annual refresher training

Free readiness call

Talk to an engineer, not a salesperson

An engineer replies within one working day with a suggested approach and a fixed quote.

  1. 1
    You send the formTwo minutes. Tell us the problem, not the solution.
  2. 2
    We talk it throughA short call at a time that suits your working hours.
  3. 3
    You get a fixed quoteIn writing, in S$. Nothing is billed until you approve it.

Book your free readiness call

Interested in

See our privacy policy.

Questions

Singapore PDPA questions we get asked

Also see how Stratgik works with Singapore businesses.

Does the PDPA apply to foreign companies?

Yes. It applies to organisations that collect, use or disclose personal data in Singapore, wherever they are incorporated.

Is a Data Protection Officer mandatory for small companies?

Yes. Every organisation must designate at least one person responsible for PDPA compliance and make their business contact information available.

When must a data breach be reported?

Once you assess that a breach is notifiable, because it is likely to cause significant harm or affects 500 or more individuals, you must notify the PDPC within 3 calendar days.

How does the PDPA treat AI systems?

The PDPC’s advisory guidelines explain how personal data can be used to develop and deploy AI recommendation and decision systems, including consent, exceptions and transparency to users.

Is this legal advice?

No. Stratgik is a technology firm. We implement the processes and controls in your systems and work alongside your lawyers for legal opinions.

Are prices fixed?

Yes, for organisations with one website or app and up to five systems holding personal data. Larger scope is quoted in writing first. GST is added where applicable.

Find the gaps before a regulator does.

A readiness audit takes 7 working days and gives you a ranked, costed plan.

The Stratgik model

Strategy first. Technology that follows through.

Four stages, in order. Most businesses need them one at a time.