Personal Data Protection Act, comprehensive consent-based regime
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 February 2021.
A comprehensive regime rule binding private bodies.
As of 29 August 2026.
What it requires
- An app that collects, uses, or discloses the personal data of an individual in Singapore must obtain the individual's consent, or rely on a Part 3 or Schedule exception, and must state its purpose for the collection, use, or disclosure.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
PDPA applies a single consent-based framework to all personal data processing by organisations in Singapore: collection, use, or disclosure requires consent or a Part 3 or Schedule exception, and the Act does not distinguish controller from processor by name, instead regulating organisations directly with pass-through duties on data intermediaries.
There is no statutory sensitive-category or biometric-specific tier; every category of personal data, including a faceprint or voiceprint, is regulated under this one uniform standard.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
Read the law
official statute text, Singapore Statutes Online (SSO)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.