In recent years, public agencies have increasingly partnered with trusted organisations outside of the public sector to reach Singaporeans effectively – these organisations include social service agencies, community partners and self-help groups such as SG Enable, the Chinese Development Assistance Council, Mendaki, Sinda, and the Eurasian Association.
Previously, these external organisations were not enabled under the Public Sector (Governance) Act (PSGA) to have data from the public sector shared with them. They had to rely on individual consent, common law public interest grounds, or sector-specific legislation to obtain information, which was time-consuming and barred these external partners from getting into contact with vulnerable individuals.
On 12 January 2026, Singapore’s Parliament passed significant amendments to the PSGA, broadening the Government’s ability to share public sector data with trusted external partners to target the above issues. These changes mark a departure from the existing framework, which previously only allowed data sharing within public sector agencies. This article explains:
- What is the Public Sector (Governance) Act (PSGA)?
- What are the amendments introduced under the PSGA Amendment Bill?
- How do the PSGA amendments interplay with the PDPA?
What is the Public Sector (Governance) Act (PSGA)?
The PSGA was first enacted in 2018, which formalised the legal framework for lawful data sharing among Singapore’s public sector agencies. Before that, there was no formal legislation establishing the legal basis for, and laying out the parameters of, intra-government data sharing. With the implementation of the PSGA, public agencies were enabled to share data safely to better serve Singaporeans.
The way data sharing among different agencies works is best explained through an example – for instance, when residents apply for financial assistance at a Social Service Office (SSO), they will not be required to submit various documents to different agencies to prove their financial status. This is because the SSO is under the government’s Ministry of Social and Family Development (MSF) and thus, their frontline officers have access to data from other government agencies to evaluate these residents’ eligibility for financial assistance.
What data can be shared?
Under the PSGA, public sector agencies may share data, provided that the data sharing falls within the seven prescribed public interest purposes. These are:
- To uphold and promote the values of the Singapore public sector
- To secure economies or efficiencies for the Singapore public sector
- To improve (directly or indirectly) the efficiency or effectiveness of policies, programme management or service planning and delivery by Singapore public sector agencies
- To ensure business continuity
- To ensure accountable and prudent stewardship of Singapore’s public sector finances and resources
- To manage risks to the financial position of the Government
- To support a whole-of-government approach in the discharge of the public sector agencies’ functions
In effect, individual consent is not strictly required for lawful data sharing among public agencies when the sharing is done pursuant to these public interest purposes.
However, if data is disclosed without authorisation or used improperly, the public officer will be subject to a maximum fine of $5,000 or a jail term of up to 2 years or both.
What are the Amendments Introduced Under the PSGA Amendment Bill?
As mentioned above, the PSGA’s data governance framework only applied to public sector agencies and not external partners – even when they had use cases that serve public sector objectives. Apart from making it cumbersome for such partners to provide services to the public, this also impedes efforts to reach out to people who need help.
For example, one external partner who previously was not allowed to access data from public agencies is SG Enable, an agency that supports disabled people and their caregivers. Naturally, SG Enable found it difficult to identify disabled people who needed help in areas such as employment and training opportunities, as they did not have the legal grounds to obtain access to relevant data. As a result, MSF could only share the addresses of people with disabilities and no other information about their disability conditions, needs or demographics, which meant that SG Enable had to obtain such information by personally making visits to persons with disabilities and their families.
Now, the PSGA has been amended to allow data to be shared with external partners that work closely with the public sector to deliver public services, such as social service agencies, community partners, and self-help groups. To ensure that data is shared securely and in an accountable manner, data can only be shared with external partners when 3 main safeguards have been met:
1. Data can only be shared for a legitimate purpose
The first safeguard is that data can only be shared with external partners for a legitimate purpose. This means that data can only be shared for the same seven public purposes that govern inter-agency sharing today.
Also, the right to share data under the PSGA does not apply to information that is confidential or privileged. For example, if a contract has been signed that says the information cannot be disclosed to other agencies, it will be confidential and cannot be shared. If the information is part of private communications between lawyers and their clients, it is legally privileged and also cannot be shared.
2. Authorisation from a Minister is needed
The second safeguard is that authorisation from a Minister is needed before data can be shared with external partners. The relevant Minister must specifically authorise each use case of data-sharing with external partners. Such authorisation must be documented and clearly state what data can be shared, which partner receives it and for what purpose it may be used.
3. Safeguards for data protection and data security
The third safeguard is that external partners must have their own safeguards for data protection and data security. Terms of Use will be imposed on external partners through contractual agreements to secure data. The Terms of Use will include requirements in line with what public sector agencies are subjected to when they share data within the public sector, such as using anti-malware software with up-to-date signatures and performing regular vulnerability assessments. Since the Terms of Use are legally binding contractual agreements, if the requirements in them are breached, the party in breach will be liable to pay damages to the other party.
How long can data be retained for by external partners?
The Terms of Use imposed on external partners should specify data retention periods and requirements to purge data. External partners will also have to provide yearly declarations of compliance with the terms of use. If the Terms of Use are not complied with, data access may be revoked.
For more sensitive data, frequent periodic audit checks will be conducted by public agencies or appointed third parties. Highly sensitive data will be reviewed monthly before any data sharing is established. An example of such highly sensitive data is health information that is used for employment and insurance purposes.
What are the penalties for external partners that breach the PSGA?
Individuals from external partners who have been convicted of having misused shared data will be subject to the same penalties as public officers under the PSGA – a maximum fine of $5,000, a jail term of up to 2 years, or both.
How do the PSGA Amendments Interplay With the PDPA?
Some of the data sharing safeguards may remind you of the regulations against private companies under the Personal Data Protection Act (PDPA).
Before the amendments, the PSGA only applied to the public sector. Now that the PSGA data sharing rules apply to not just public agencies but also external organisations, these external partners may find themselves potentially liable for breaches of both the PDPA and PSGA. Which legislation might such organisations find themselves in violation of? This will likely depend on the type of data, how the misused data was obtained (i.e. whether it was through another government agency under the PSGA), and for what purpose the data was obtained.
When a company might be liable under the PSGA but not the PDPA
The PDPA only applies to personal data (data about an individual who can be identified from that data) whereas the PSGA governs the sharing of both personal and non-personal data (such as anonymised data). If, for example, a company shares non-personal data that it obtained from another government agency under the PSGA beyond the authorised public interest purpose, the company might be liable under the PSGA, rather than the PDPA.
When a company might be liable under the PDPA but not the PSGA
Where a company obtains data through its own sources and not under the PSGA, and then misuses the data, it may be liable under the PPDA but not the PSGA. For example, if a company obtains customer information through its own website and not from another government agency, any mishandling of the data would fall under the PDPA and not the PSGA.
When a company might be liable under both the PDPA and PSGA
A company might be liable under both the PDPA and PSGA if it uses data beyond an authorised public interest purpose (a PSGA issue) while also failing to implement reasonable security measures (a PDPA issue). For example, company A was a healthcare provider that shared patients’ email addresses with a telemarketing firm. This fell outside of a public interest purpose and therefore ran afoul of the PSGA. At the same time, company A also failed to implement proper encryption on its list of patients’ email addresses and was thus found to have failed to implement reasonable security measures under the PDPA.
—
Singapore’s expansion of the PSGA represents an evolution from intra-government data sharing to a more collaborative, cross-sector model with external partners. In other words, the PSGA has extended its ambit to cover external partners who might require data from public agencies for public interest. To ensure that data is shared safely, it must first be authorised by a Minister. The data can only be shared for a legitimate purpose, and the external partner must implement safeguards before receiving such data.
For organisations that partner with the public sector, these amendments underscore the importance of understanding data governance obligations and preparing robust data protection practices. Stakeholders with complex compliance concerns may benefit from seeking legal guidance from a data privacy or regulatory lawyer.
