Law / Singapore

Personal Data Protection Act, enforcement and private right of action

Personal Data Protection Act 2012, ss.48J, 48O, as added by Act 40 of 2020

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 1 October 2022.

An enforcement supervision rule binding private bodies.

As of 2 September 2026.

What it requires

  • An app processing the personal data of an individual in Singapore must be prepared to answer to the PDPC for a Part 4 through 6B violation, facing a financial penalty of up to 10 percent of Singapore annual turnover for a serious contravention, and an individual harmed by such a violation may bring a civil claim for relief directly.

If you get it wrong

Criminal exposureNo

Private right of actionYes

Penalty structure

Section 48J(3): a financial penalty imposed on an organisation under s.48J(1)(a) (an intentional or negligent contravention of Part 3, 4, 5, 6, 6A or 6B) must not exceed 10% of the organisation's annual turnover in Singapore where that turnover exceeds S$10 million, or S$1 million in any other case. Because 10% of a S$10 million turnover is exactly S$1 million, the two branches cross over at that threshold, so the effective rule is the higher of a S$1 million fixed cap or 10% of Singapore annual turnover. Two further, narrower caps sit alongside this organisation-level rule and are not captured in the fixed_cap / turnover_pct_cap fields above, which describe only the s.48J(3) rule: s.48J(4) caps a financial penalty on a person under s.48J(1)(b)(i) (a Part 9 contravention) at S$200,000 for an individual, or S$1 million for a non-individual person; s.48J(4A) caps a financial penalty on a person under s.48J(1)(b)(ii) (a s.48B(1) dictionary-attack contravention) at S$200,000 for an individual, rising to 5% of the person's annual turnover in Singapore where that turnover exceeds S$20 million, otherwise S$1 million.

Rule
Higher of
As of
2 September 2026
Currency
SGD
Fixed cap
1,000,000
Turnover percentage cap
10

Who enforces it

Enforcement body

Personal Data Protection Commission (PDPC)

What it reaches

Obligation class

Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Personal Data Protection Commission (PDPC) is Singapore's supervisory authority. Financial penalties under s.48J, added by the 2020 amendment and commencing 1 October 2022, reach up to 10 percent of Singapore annual turnover for an organisation with turnover exceeding S$10 million (otherwise up to S$1 million), and up to S$200,000 for an individual, or up to 5 percent of turnover exceeding S$20 million.

Section 48O(1), also added by the 2020 amendment, gives a person who suffers loss or damage directly from a contravention of the Consent Obligation (Part 4), Access and Correction (Part 5), Care of Personal Data (Part 6), Notification of Data Breaches (Part 6A), or Data Portability (Part 6B) provisions a right of action for relief in civil proceedings; its own specific commencement date within the 2020 amendment was not independently isolated.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics

Read the law

official statute text, Singapore Statutes Online (SSO)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app