Data Privacy

Singapore PDPA vs GDPR: Key Differences

The PDPA's consent-centric model against the GDPR's six lawful bases: access rights, the absence of a special-category tier, the DNC registry, breach notification timing, and PDPC enforcement.

A Singapore organisation with a mature PDPA programme has real assets — a designated DPO, a consent architecture, a breach process, a retention policy. It also has structural gaps that only appear when the GDPR applies, because the two regimes are organised on different logic. The PDPA asks whether you have consent or fall within an exception. The GDPR asks which of six lawful bases you rely on, and then asks a second question for health and other special category data.

This page sets out the differences that generate work. It assumes the GDPR applies to your Singapore company under Art. 3(2); if that is still open, start there.

Stated plainly at the outset: Singapore holds no EU adequacy decision, verified against the European Commission’s published list on 30 July 2026. Adequacy is not equivalence, and its absence is the Commission’s formal position that Singapore law does not deliver an essentially equivalent level of protection.

Key takeaways

  • The PDPA is built on consent — actual, deemed, or displaced by an enumerated exception. The GDPR’s six lawful bases sit on equal footing, and consent is often the weakest choice.
  • The PDPA has no special-category tier. Health data is ordinary personal data under the statute. Art. 9 GDPR prohibits processing it without a second, cumulative condition.
  • The PDPA access right is narrower than Art. 15, may be charged for, and has no erasure or objection counterpart. The data portability obligation is legislated but not in force.
  • The Do Not Call Registry has no GDPR equivalent, and it binds organisations sending marketing to Singapore numbers regardless of where they sit.
  • Breach notification clocks differ in kind: the PDPA runs three days from the end of your assessment; Art. 33 runs 72 hours from awareness.

The PDPA 2012 organises its data protection provisions as a set of obligations — Consent, Purpose Limitation, Notification, Access and Correction, Accuracy, Protection, Retention Limitation, Transfer Limitation, Accountability, and Data Breach Notification. Consent under s 13 is the gateway. It can be actual, or deemed under s 15 by conduct, and the 2020 amendments added deemed consent by contractual necessity and deemed consent by notification, the latter requiring an assessment of adverse effect and a reasonable opt-out period. Where consent is unavailable, the First Schedule provides exceptions, including the legitimate interests exception — which requires a documented assessment and disclosure that the organisation is relying on it — and a business improvement exception.

It is therefore inaccurate to describe the modern PDPA as purely consent-based. But the architecture is still consent-plus-derogations rather than a menu of equivalent bases, and the derogations carry conditions that the GDPR’s bases do not.

Under the GDPR, every processing purpose needs one of the six Art. 6 bases, chosen before processing starts and disclosed in the notice. Consent is one of six and is frequently the wrong one: it must be freely given, specific, informed and unambiguous under Art. 7, it must be as easy to withdraw as to give, and withdrawal stops the processing. Where a Singapore organisation has relied on deemed consent or on a First Schedule exception, the migration work is to identify the equivalent Art. 6 basis and document the reasoning — most often legitimate interests, which requires a three-part balancing test that can be produced on request.

The practical output of that work is an Art. 30 record of processing activities with a basis recorded per purpose. This is normally the largest single item in a PDPA-to-GDPR gap closure.

No special-category tier

This is the divergence that catches Singapore’s health-tech, medtech and clinical research sector.

The PDPA’s data protection provisions apply to “personal data” without a statutory tier for sensitive data. PDPC guidance expects a higher standard of protection for data of a more sensitive nature, and the Personal Data Protection (Notification of Data Breaches) Regulations 2021 prescribe categories — including health and medical information and financial data — whose breach is deemed likely to result in significant harm. But those are calibrations of the Protection and Breach Notification obligations, not a separate lawful-processing regime.

Art. 9(1) GDPR is a prohibition. Processing health, genetic, biometric-for-identification, racial or ethnic, political, religious, trade union, sex life or sexual orientation data is forbidden unless a condition in Art. 9(2) applies, cumulatively with the Art. 6 basis. Legitimate interest is not among the Art. 9 conditions. Explicit consent under Art. 9(2)(a) is a higher standard than ordinary consent. And Art. 35(3)(b) makes a DPIA effectively mandatory for large-scale processing of this data. Our page on special categories sets out the conditions.

For a Singapore telehealth platform or clinical data centre, this is not a documentation adjustment. It is a second legal analysis that has no counterpart in the PDPA at all.

Individual rights

Right PDPA GDPR
Access s 21, subject to Fifth Schedule exceptions; a reasonable fee may be charged; PDPC guidance expects a response within 30 days or notice of the time required Art. 15; one month, extendable by two; first copy free; extends to purposes, recipients, retention, sources and safeguards
Correction s 22 Art. 16
Erasure No individual right. s 25 obliges the organisation to cease retention when the purpose ends Art. 17, exercisable by the individual
Portability Part 6B enacted, not in force as at 30 July 2026 Art. 20
Objection Withdrawal of consent under s 16; no general objection right Art. 21, including profiling
Automated decisions No equivalent Art. 22
Direct marketing DNC Registry, Part 9 Art. 21(2) absolute right to object, plus the ePrivacy consent rule

The Art. 15 gap is the one that surprises operations teams. A GDPR access request is not a copy of a record; it is a disclosure of the purposes, the recipients or categories of recipient, the retention period or the criteria for it, the source where the data was not collected from the individual, the existence of the other rights, and — because Singapore has no adequacy decision — the specific safeguards applied to international transfers. Requests arrive from anyone, at any time, free of charge, with a one-month clock.

The Do Not Call Registry

Part 9 of the PDPA established three registers — No Voice Call, No Text Message, No Fax — operational since 2 January 2014. Before sending a specified message to a Singapore telephone number, an organisation must check the relevant register and hold a valid confirmation, unless an exemption applies. The obligation binds organisations sending such messages to Singapore numbers irrespective of where the sender is located.

There is no EU analogue. European direct marketing is governed by the ePrivacy Directive’s prior-consent rule for electronic communications, transposed differently in each member state, combined with the GDPR’s absolute right to object. A Singapore organisation running outbound campaigns into both markets therefore operates two incompatible mechanics: a registry check before contact in Singapore, and a lawful basis plus a working opt-out in Europe. Neither process substitutes for the other, and a single suppression list will not implement both.

Breach notification: three days is not 72 hours

Mandatory breach notification took effect on 1 February 2021 under Part 6A of the PDPA and the Personal Data Protection (Notification of Data Breaches) Regulations 2021. A breach is notifiable if it is of significant scale — affecting 500 or more individuals — or if it results, or is likely to result, in significant harm to any affected individual. On becoming aware of a possible breach the organisation must conduct a reasonable and expeditious assessment; once it has assessed the breach as notifiable, it must notify the PDPC as soon as practicable and in any case no later than three calendar days after that assessment, and notify affected individuals as soon as practicable where significant harm arises.

Art. 33 GDPR runs differently on all three dimensions. The clock is 72 hours from becoming aware of the breach, not from completing an assessment. The threshold is whether the breach is unlikely to result in a risk to rights and freedoms — lower than “significant harm” — and there is no numeric floor equivalent to 500 individuals. Where high risk arises, Art. 34 requires communication to individuals without undue delay. Incomplete notifications are permitted in phases under Art. 33(4); waiting until the facts are settled is not.

A Singapore runbook built to the PDPA sequence will miss the GDPR deadline by design, because the PDPA’s structure explicitly permits assessment before the clock starts. The remedy is a parallel European track with its own timer.

Regulators and enforcement

Singapore has a single regulator, the PDPC, which investigates, issues directions, accepts undertakings and imposes financial penalties. Since 1 October 2022 the maximum financial penalty has been S$1 million, or 10% of the organisation’s annual turnover in Singapore where that turnover exceeds S$10 million, whichever is higher.

The PDPC publishes its decisions, which makes Singapore enforcement unusually legible. Two illustrate the range. In January 2019, following the July 2018 cyberattack on SingHealth’s patient database, the PDPC imposed S$750,000 on Integrated Health Information Systems and S$250,000 on SingHealth — S$1 million in total, and at the time the largest penalties it had issued. In a decision dated 28 October 2025 the PDPC found Marina Bay Sands in breach of the Protection Obligation and imposed a financial penalty of S$315,000 following the exfiltration of the personal data of roughly 665,000 patrons.

The EU has one authority per member state, coordinated through the EDPB’s consistency mechanism. Singapore companies commonly assume the Art. 56 one-stop-shop will give them a single European counterpart; it will not, because the one-stop-shop requires a main establishment in the Union. Any supervisory authority in whose territory affected data subjects are located may act against a controller in scope under Art. 3(2). Penalties run to the two bands of Art. 83: EUR 10 million or 2%, and EUR 20 million or 4%, of worldwide annual turnover.

One point runs the other way. Section 11(3) of the PDPA requires every organisation to designate at least one individual as a data protection officer and to make that person’s business contact information publicly available. The GDPR requires a DPO only where Art. 37 conditions are met, but where one is required, Arts. 38 and 39 give the role statutory independence, protection from dismissal for performing its tasks, and a defined task list. Singapore’s requirement is broader; the GDPR’s is deeper.

Transfers

Section 26 and the Personal Data Protection Regulations 2021 impose a Transfer Limitation Obligation: data may leave Singapore only if the recipient is bound by legally enforceable obligations providing a standard of protection comparable to the PDPA. This governs data flowing out of Singapore and has no bearing on data flowing in from the EEA, which is governed entirely by Chapter V of the GDPR. Because Singapore has no adequacy decision, that means Standard Contractual Clauses and a transfer impact assessment — set out in our page on Singapore–EU data transfers, which also addresses why the EU–Singapore Digital Trade Agreement does not change the position.

FAQ

If we comply with the PDPA, how much GDPR work remains?

Typically four things: an Art. 6 basis documented per purpose, an Art. 9(2) condition wherever health or other special category data is involved, an operational rights process running to a one-month clock at no charge, and a transfer file. Security, retention and breach handling largely carry across, with the breach timing rebuilt.

Is the PDPA’s legitimate interests exception the same as Art. 6(1)(f)?

No. They point in a similar direction but the conditions differ, and the PDPA version requires disclosure that you are relying on it. Under the GDPR you document a three-part balancing test and remain exposed to an Art. 21 objection. Reproduce the analysis in GDPR terms rather than cross-referencing the Singapore assessment.

Does having a PDPA DPO satisfy the GDPR?

Only if that person meets the Art. 37–39 requirements — expert knowledge, no conflict of interest, direct reporting to the highest management level, and protection from dismissal for performing the role. Many PDPA DPO appointments are held by an operations or IT manager whose other duties would create a conflict under Art. 38(6).

Which regime is stricter?

The wrong question to plan against. The PDPA is broader on DPO designation and imposes a marketing registry the EU does not have. The GDPR is materially stricter on lawful bases, special category data, individual rights, breach timing and transfers. Both apply, and neither discharges the other. The same conclusion holds for Australia, as set out in our comparison of the Privacy Act 1988 and the GDPR.

What tooling handles both?

One inventory producing two register views. Two systems drift. Our buying guide for GDPR compliance software for Singapore companies covers the dual-register requirement.

Legiscope automates this for you

Stop doing compliance manually. Legiscope's AI handles ROPA creation, DPA audits, and gap analysis — in minutes, not weeks.

Start free trial
TD
Written by
Fondateur de Legiscope et expert RGPD

Docteur en droit de l'Université Panthéon-Assas (Paris II), 23 ans d'expérience en droit du numérique et conformité RGPD. Ancien conseiller de l'administration du Premier ministre sur la mise en œuvre du RGPD. Thiébaut est le fondateur de Legiscope, plateforme de conformité RGPD automatisée par l'IA.

View full author profile →