Summary: Your Organisation’s 10 Main PDPA Obligations

Your organisation is required to abide by the Personal Data Protection Act (PDPA) when using, collecting or disclosing personal data.
The 10 main personal data obligations under the PDPA are:
- Consent Obligation
- Purpose Limitation Obligation
- Notification Obligation
- Access and Correction Obligation
- Accuracy Obligation
- Protection Obligation
- Retention Limitation Obligation
- Transfer Limitation Obligation
- Data Breach Notification Obligation
- Accountability Obligation
Here is a summary of each of them.
1. Consent Obligation
Your organisation may collect, use and/or disclose only the personal data of individuals who have consented to such collection, use and/or disclosure.
These individuals must also be given the option to withdraw their consent, subject to them giving reasonable notice. Upon the withdrawal of consent, your organisation must cease collecting, using and/or disclosing the personal data of these individuals.
Read more about the PDPA’s Consent Obligation in our other article.
2. Purpose Limitation Obligation
Your organisation may collect, use and/or disclose only the personal data of individuals for the purpose(s) for which consent have been given by these individuals.
These individuals should also not be required to consent to the collection, use and/or disclosure of their personal data beyond what is reasonable for the organisation to provide a particular product or service.
3. Notification Obligation
Your organisation should inform individuals of the purpose(s) for which their personal data is being collected, used and/or disclosed.
4. Access and Correction Obligation
Your organisation is obliged to provide information to individuals, upon request and as soon as reasonably possible, on:
- What personal data of theirs is in your organisation’s possession or under its control; and
- How such personal data has been used or disclosed within 1 year of the request.
Also, should an individual request that the organisation rectify any error or omission in his or her personal data, your organisation must accede to the request as soon as practicable.
5. Accuracy Obligation
Your organisation should ensure that the personal data collected by the organisation is accurate and complete.
6. Protection Obligation
Your organisation should put in place the required security measures to protect the personal data in its possession or control, including the storage media or devices on which such data is stored. This is to prevent any unauthorised access, collection, use and/or disclosure of such data.
Examples of when the protection obligation applies would be when your organisation is processing and sending personal data, or disposing of documents containing personal data.
7. Retention Limitation Obligation
Your organisation should retain the personal data for only as long as is necessary for business or legal purposes.
8. Transfer Limitation Obligation
If your organisation is transferring the personal data overseas, such as storing the data in the cloud, ensure that the country to which the data is being transferred offers a comparable level of data protection as is provided by the PDPA.
9. Data Breach Notification Obligation
If your organisation has suffered a data breach that has caused (or is likely to cause) significant harm to affected individuals, or that has affected at least 500 individuals, then it generally must inform the Personal Data Protection Commission (PDPC) and affected individuals of the breach.
10. Accountability Obligation
Your organisation should be open to sharing information about its data protection practices, policies and complaints processes upon request.
For example, your organisation’s privacy policy can state that individuals who wish to know more the organisation’s data protection policies can get in touch with its data protection officer, and also provide means of contacting that officer.
If you require legal advice on your business’ legal obligations under the PDPA, feel free to get in touch with one of our data protection lawyers.
- What is a Nominee Director, How to Appoint and Other FAQs
- Independent Directors: Who are They and What is Their Role?
- Board of Advisors: Who Are They and What Is Their Role?
- Appointing Company Directors in Singapore: Eligibility, Process etc.
- Managing Director vs CEO in Singapore: Roles and Obligations
- Guide to Directors' Remuneration in Singapore
- Directors' Duties in Singapore
- Shadow Directors: Who are They and What Duties Do They Owe to the Company?
- How to Remove a Director from a Company in Singapore
- Removal and Resignation of Company Auditor in Singapore
- Appointing a Company Secretary: Roles and Responsibilities
- Appointing an Authorised Representative for Foreign Companies in Singapore
- Process Agents in Singapore
- Share Buybacks in Singapore: Procedure, Cost and More
- How to Split Shares (or Stocks) in a Singapore Company
- 2 Ways to Remove a Singapore Company Shareholder ASAP
- What are Treasury Shares? Guide for Singapore Companies
- Guide to Paid-Up Capital in Singapore (Is $1 Enough?)
- Preparing a Register of Shareholders for a Singapore Company
- How to Issue Shares in a Singapore Private Company
- Guide to Transferring Shares in a Singapore Private Company
- Your Guide to Share Certificates in Singapore: Usage and How to Prepare
- Shareholder Rights in Singapore Private Companies
- Shareholder Roles and Obligations in Singapore Companies
- Dividend Payments Guide for Singapore Business Owners
- Share Transmission: What Happens If a Shareholder Dies in Singapore?
- How to Reduce the Share Capital of Your Singapore Company
- Buy-Sell Agreements: How to Write & Fund Them in Singapore
- Oppression of Minority Shareholders
- Is Your Business Collaboration Competition Law-Compliant?
- Explained: Registered Filing Agent for Singapore Businesses
- Transfer Pricing Obligations of Singapore Companies
- Adhering to Trading Sanctions and Restrictions in Singapore
- Cyber Hygiene Compliance Guide for Singapore Companies
- Corporate Social Responsibility For Businesses in Singapore
- Essential Regulatory Compliance Guide for Singapore Companies
- Dormant Companies and Their Filing Obligations in Singapore
- Anti-Money Laundering Regulations and Your Business: What You Need to Know
- Price-Fixing, Bid-Rigging and Other Anti-Competitive Practices to Avoid
- Legally Conducting Lucky Draws for Singapore Businesses
- Restaurant Inspection and Food Safety Rules in Singapore
- Does Your Company Need a Legal Team (In-House Counsel)?
- Acqui-Hiring of Singapore Companies: How Does It Work?
- How to Change the Name of Your Singapore Company
- Can Directors be Liable for Company Debts in Singapore?
- Company Loans to Directors/Shareholders in Singapore
- 3 Types of Insurance Every Singapore Business Needs
- Creating and Registering Charges in Singapore: Guide for Companies
- Guide to Effective Business Continuity Planning in Singapore
- Business Asset Sale & Disposal in Singapore: How Do They Work?
- Business Partnership Disputes in Singapore: How to Resolve
- How to Commence a Derivative Action on Behalf of a Company in Singapore
- Business Will: How to Pass on Your Business to Your Successors in Singapore
- Record-Keeping Requirements for Singapore Companies
- Company Constitutions in Singapore and How to Draft One
- Company Memorandum and Articles of Association
- Company Resolutions: What are They?
- Board Resolutions in Singapore
- Minutes of Company Meeting in Singapore: How to Record
- How to Set Up a Register of Controllers
- How to Set Up a Register of Nominee Directors
- Guide to Filing Financial Statements for Singapore Business Owners
- Filing Annual Returns For Your Business
- Carbon Tax in Singapore: What is the Rate and Who Must Pay?
- Laws and Penalties for GST Evasion in Singapore
- 6 Common Taxes in Singapore For Individuals & Businesses
- Singapore Corporate Tax: How to Pay, Tax Rate, Exemptions
- Start-Up Tax Exemption Guide for New Singapore Companies
- GST Registration: Requirements and Procedure in Singapore
- What is Withholding Tax and When to Pay It in Singapore
- Singapore Influencers: Here's How to Calculate Your Income Tax
- Tax Investigation of Tax-Evading Business Owners in Singapore
- Small Business Accounting Services in Singapore
- Company Audits in Singapore: Requirements and Exemptions
- Suspect a PDPA Data Breach? Here's What to Do Next
- Must You Notify PDPC About a Data Breach in Your Business?
- Data Room: Should Your Singapore Company Set Up One?
- Victim of a Data Breach? Here’s What You Can Do
- Summary: Your Organisation's 10 Main PDPA Obligations
- Essential PDPA Compliance Guide for Singapore Businesses
- PDPA Consent Requirements: How Can Your Business Comply?
- Is It Legal for Businesses to Ask for Your NRIC in Singapore?
- Here's a 7-Step Plan for Companies to Prevent Unauthorised Disclosure When Processing and Sending Personal Data
- Cloud Storage of Personal Data: Your Business’ Data Protection Obligations
- Drafting a Comprehensive Privacy Policy For Your Singapore Website
- GDPR Compliance in Singapore: Is it Required and How to Comply
- Appointing a Data Protection Officer For Your Business: All You Need to Know
- How Can Companies Dispose of Documents Containing Personal Data?
- Check the Do-Not-Call Registry Before Marketing to Singapore Phone Numbers
- How to Legally Install CCTVs for Home/Business Use in Singapore
- Is Web Scraping or Crawling Legal in Singapore?
- Legal Options If Employees Breach Confidentiality in Singapore
- Social Media Marketing: Legal Guide for Singapore Businesses
- Your Guide to E-commerce Website Terms of Service in Singapore
- Dealing with Defamation of Your Business: Can You Sue?
- Sending Email Newsletters That Comply With Singapore Law
- A legal guide to drafting a social media policy for your company
- Your Guide to a Media Release Form in Singapore
- Your Guide to an Influencer Marketing Agreement in Singapore
- Outdoor Advertising: How to Legally Display Public Ads in Singapore
- A Guide to Digital Bank Regulation in Singapore
- Applying for a Major Payment Institution Licence in Singapore
- Applying to the MAS FinTech Regulatory Sandbox
- Payment Services Act Licensing Guide for Fintech Businesses
- How to Get a Payment Service Provider Licence in Singapore
- Financial Adviser's Licence Guide for Singapore Businesses
- Capital Markets (CMS) Licence Requirements in Singapore
- How to Offer E-Wallet Services in Singapore: Licensing Guide
- Digital Payment Token Services Licence Guide in Singapore
- How to Legally Offer Crypto Services in Singapore
- How to Restore a Struck-Off Company in Singapore
- Claw-Back of Assets From Unfair Preference and Undervalued Transactions
- Should You Save or Close Your Zombie Company in Singapore?
- Voluntary Suspension of Business in Singapore: How to Handle
- Winding Up a Singapore Company: Grounds and Procedure
- Closing Your Singapore Business: What You Need to Settle
- Striking Off a Company
- Restoring a Company That was Struck Off Without You Knowing
- Dissolution of partnerships in Singapore
- What Should a Creditor Do When a Company Becomes Insolvent?
- How to File a Proof of Debt Against a Company in Liquidation
- Validation of Payments Made by Companies Being Wound Up