Law / Singapore

Personal Data Protection Act, comprehensive consent-based regime

Act 26 of 2012 (Singapore), as amended by the Personal Data Protection (Amendment) Act 2020, Act 40 of 2020

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 1 February 2021.

A comprehensive regime rule binding private bodies.

As of 29 August 2026.

What it requires

  • An app that collects, uses, or discloses the personal data of an individual in Singapore must obtain the individual's consent, or rely on a Part 3 or Schedule exception, and must state its purpose for the collection, use, or disclosure.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

PDPA applies a single consent-based framework to all personal data processing by organisations in Singapore: collection, use, or disclosure requires consent or a Part 3 or Schedule exception, and the Act does not distinguish controller from processor by name, instead regulating organisations directly with pass-through duties on data intermediaries.

There is no statutory sensitive-category or biometric-specific tier; every category of personal data, including a faceprint or voiceprint, is regulated under this one uniform standard.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics

Read the law

official statute text, Singapore Statutes Online (SSO)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app