Pandectes GDPR Compliance - 3,000+ Verified ⭐⭐⭐⭐⭐ 5/5 Reviews Worldwide - #1 on Shopify 🏅

Singapore Personal Data Protection Act (PDPA) Compliance

Pandectes GDPR Compliance helps Shopify stores meet Singapore PDPA requirements by collecting consent for cookies, scanning and classifying cookies, and keeping consent records.

Start Free
PDPA Singapore

The #1 cookie consent app for Shopify, trusted by 185k stores

  • Nike Strength
  • Reebok
  • Ted Baker
  • Juicy Couture
  • Aje
  • Casely
  • Oracle Red Bull Racing
  • KFC
  • Flying Tiger Copenhagen
  • Sennheiser
  • Susanne Kaufmann
  • Aldo
  • Victoria Beckham
  • Scalpers
  • UGREEN

What is PDPA?

The Personal Data Protection Act 2012 (PDPA) is Singapore’s general data protection law. It governs how private sector organizations collect, use and disclose personal data, and it also set up Singapore’s Do Not Call Registry for marketing messages. The law is administered and enforced by the Personal Data Protection Commission (PDPC).

The PDPA is built around a set of data protection obligations, including:

  • Consent: Organizations may collect, use or disclose personal data only with the individual’s consent, unless an exception applies. In some situations consent can be deemed, for example when someone voluntarily provides their data for a purpose.
  • Notification: Individuals must be told the purposes for which their data is collected, used and disclosed, on or before collection.
  • Purpose limitation: Data may only be used for purposes a reasonable person would consider appropriate.
  • Access and correction: Individuals can ask for their data and how it has been used, and ask for errors to be corrected.
  • Protection and retention: Data must be protected with reasonable security arrangements and not kept longer than needed.
  • Transfer limitation: Data sent outside Singapore must receive a standard of protection comparable to the PDPA.
  • Data breach notification: Notifiable data breaches must be reported to the PDPC no later than 3 calendar days after the organization assesses them, and in many cases to the affected individuals.

Who does the PDPA apply to?

The PDPA applies to organizations that collect, use or disclose personal data in Singapore, whether or not they are formed in Singapore or have an office there. An online store based elsewhere that collects personal data from customers in Singapore can therefore be covered.

What happens if I don’t comply with the PDPA?

The PDPC can investigate complaints and data breaches, and can give directions to bring an organization into compliance. Consequences can include:

  • Financial penalties: Up to 10% of the organization’s annual turnover in Singapore for organizations whose turnover in Singapore exceeds S$10 million, or up to S$1 million in any other case.
  • Directions: Orders to stop collecting, using or disclosing data, to destroy data collected in breach of the PDPA, or to take other steps to comply.
  • Civil claims: Individuals who suffer loss or damage from a breach of certain obligations can bring a claim in court.
  • Published decisions: The PDPC publishes its enforcement decisions, which can affect your reputation.

When did the PDPA go into effect?

The PDPA was passed in 2012. Its data protection provisions came into force on July 2, 2014, after the Do Not Call provisions took effect earlier that year. Amendments made in 2020 took effect from February 1, 2021, adding mandatory data breach notification and new forms of deemed consent, and the higher financial penalties apply from October 1, 2022.

Complying with the PDPA

For a Shopify store selling to customers in Singapore, the consent and notification obligations are the most relevant to cookies and tracking. Where cookies or similar tools collect personal data, for example to build profiles for analytics or advertising, visitors should be told what is collected and why, and their consent should be obtained. Visitors can withdraw consent at any time on reasonable notice, and you must then stop the related collection and use.

Because most stores rely on providers outside Singapore, check that your platform, payment and marketing providers protect transferred data to a comparable standard, for example through contracts. You should also be able to respond to access and correction requests, and have a plan for assessing and reporting data breaches.

A Consent Management Platform (CMP) like Pandectes GDPR Compliance helps with the parts of this that happen on your storefront. It shows a cookie banner and blocks non-essential cookies until the visitor consents, automatically scans and classifies the cookies on your store, and generates a cookie declaration for your policy. It keeps consent logs as proof of consent, helps you handle data subject requests, and lets you configure banner settings by region using geolocation, so visitors from Singapore can see a banner suited to the PDPA.

The PDPC publishes detailed advisory guidelines, and how they apply depends on your store, so review your setup with legal counsel where appropriate.

Make your Shopify Store's use of cookies and online tracking compliant today

Try for free