Personal Data Protection Act, cross-border transfer
Personal Data Protection Act 2012, s.26
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 2 July 2014.
A cross border transfer rule binding private bodies.
As of 30 August 2026.
What it requires
- An app transferring the personal data of an individual in Singapore, including a faceprint, voiceprint, or other biometric identifier, to a recipient outside Singapore must ensure the recipient provides a standard of protection comparable to the PDPA, through a PDPC-prescribed mechanism, unless the PDPC has granted an exemption.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 26(1) bars an organisation from transferring personal data to a country or territory outside Singapore except in accordance with requirements ensuring a standard of protection comparable to the PDPA; the PDPC may grant exemptions on application under s.26(2) and (3). This is a comparability-based mechanism, not a flat prohibition or a data-localization mandate; the specific instruments accepted as satisfying comparable protection sit in PDPA Regulations not read.
Section 26 sits in the original 2012 Act's Part 6 (Care of Personal Data), which the Act's own consolidated text records as having commenced 2 July 2014 alongside the rest of Parts 3 to 7.
When LexLint raises it
crawls_webtrains_modelsprocesses_voiceprocesses_biometrics
Read the law
official statute text, Singapore Statutes Online (SSO)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.