Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

// request.cf · coarse context

A page that knows where it met you.

Only coarse request metadata is shown. This demo does not display or persist visitor IP addresses.

Country
US
Cloudflare location
CMH
Connection
HTTP/2
Language
Not provided

Ray ID: a2353afac8aa3524

Jump to content

// Workers AI · dad joke modeWhy was the Personal Data Protection Act 2012 a wallflower? It was private.

From Wikipedia, the free encyclopedia
Personal Data Protection Act 2012
Parliament of Singapore
  • An Act to govern the collection, use and disclosure of personal data by organisations, and to establish the Do Not Call Register and to provide for its administration, and for matters connected therewith, and to make related and consequential amendments to various other Acts.
CitationNo. 26 of 2012
Passed byParliament of Singapore
Passed15 October 2012
Assented to20 November 2012
Legislative history
Bill titlePersonal Data Protection Bill
Introduced byAssoc Prof Dr Yaacob Ibrahim
Status: In force

The Personal Data Protection Act 2012 ("PDPA") sets out the law on data protection in Singapore. The PDPA regulates the processing of personal data in the private sector.[1]

Overview

[edit]

The PDPA establishes a general data protection regime, originally comprising nine data protection obligations which are imposed on organisations: the Consent Obligation, the Purpose Limitation Obligation, the Notification Obligation, the Access and Correction Obligation, the Accuracy Obligation, the Protection Obligation, the Retention Limitation Obligation, the Transfer Limitation Obligation and the Openness Obligation (now referred to as the Accountability Obligation).[2]

Major amendments to the PDPA were proposed and passed in 2020.[3][4] Among other changes, a tenth data protection obligation was added, namely, the Data Breach Notification Obligation.[5]

The PDPA also governs telemarketing in Singapore. It establishes the Do Not Call Registers, on which telephone numbers may be registered. There are three Do Not Call Registers: (i) the No Fax Message Register; (ii) the No Text Message Register; and (iii) the No Voice Call Register. Generally, if a telephone number is listed on a Do Not Call Register (e.g. the No Text Message Register), then it is not permitted to send a marketing message of the relevant kind to that telephone number.[6] Businesses typically use compliance checklists to ensure these registers are screened before telemarketing campaigns.[7]

Personal Data Protection Commission

[edit]

The PDPA establishes the Personal Data Protection Commission (PDPC) as the regulatory authority governing data protection in Singapore. The PDPC enforces the PDPA and publishes advisory guidelines on the interpretation of the PDPA.[8] To date, the PDPC has enforced the PDPA against a number of organisations.[9][10][11] Notable enforcement cases include SingHealth, which was implicated in the 2018 SingHealth data breach.[12]

In July 2026, the PDPC issued advisory guidelines requiring organizations that seek consent to use personal data for training or fine-tuning generative artificial intelligence models to provide AI-specific notifications. The notifications are intended to explain the purpose of the data use, the types of personal data involved and how the data will be used. The requirement does not apply when organisations use anonymised data.[13][14]

Management

[edit]
Commissioner
Date Commissioner Remarks
1 January 2017 - 20 June 2020 Tan Kiat How
20 June 2020 - 1 April 2026 Lew Chuen Hong [15][16]
1 April 2026 - Present Denise Wong [17]

References

[edit]
  1. "Parliament: Public agencies not governed by PDPA because of fundamental differences in how they operate". The Straits Times.
  2. Wong, Benjamin (2017). "Data privacy law in Singapore: the Personal Data Protection Act 2012". International Data Privacy Law. 7 (4): 287–302. doi:10.1093/idpl/ipx016.
  3. "On protecting data while enabling innovation: 6 highlights from MPs' rigorous debate on PDPA amendments". The Straits Times.
  4. "Parliament: Proposed changes to PDPA include stiffer fines for data breaches, mandatory notification when they occur". The Straits Times.
  5. Personal Data Protection (Amendment) Act 2020. Singapore. 2 November 2020.
  6. "Do Not Call Registry: An easy guide for consumers". The Straits Times.
  7. Say, Jeremiah (2026-03-05). "PDPA Compliance Checklist". arkshield.sg. Retrieved 2026-03-24.
  8. "About Us". Personal Data Protection Commission. Retrieved 6 April 2021.
  9. "CDP and two other organisations fined for data privacy breach". The Straits Times.
  10. "Courts fined $9,000 for second data breach in two years". The Straits Times.
  11. "Grab fined $10k over fourth data privacy breach in two years". The Straits Times.
  12. "Singapore health system hit by 'most serious breach of personal data' in cyberattack; PM Lee's data targeted". CNA. Archived from the original on 2018-07-26. Retrieved 2021-04-06.
  13. Lee, Li Ying (20 July 2026). "AI-specific notifications mandatory for firms using personal data to train AI models: PDPC". The Straits Times. Retrieved 20 July 2026.
  14. "PDPC Issues Guidance for Organisations on Responsible Use of Personal Data in Generative AI". Personal Data Protection Commission. 20 July 2026. Retrieved 20 July 2026.
  15. "New Chief Executive appointed to Infocomm Media Development Authority". www.mddi.gov.sg. Retrieved 2024-12-15.
  16. Frater, Patrick (2020-06-15). "Lew Chuen Hong Appointed Chief Executive at Singapore's IMDA". Variety. Retrieved 2024-12-15.
  17. "Ms Denise Wong Appointed as Commissioner of Singapore's Personal Data Protection Commission (PDPC)". Infocomm Media Development Authority. Retrieved 2026-04-05.
[edit]