What the law actually asks of a small business
If you collect customer data in Singapore, the law already applies to you. There is no headcount threshold and no revenue cutoff: a sole trader with a booking form is in scope on the same terms as a company with fifty staff.
That sounds heavier than it is. Singapore's rules come from one main place — the Personal Data Protection Act 2012, which everyone calls the PDPA — enforced by the Personal Data Protection Commission, the PDPC, at pdpc.gov.sg. Most of the obligations are decisions you make once, write down, and revisit when your business changes.
One requirement, though, is missed more than any other, and it is not the one people expect. We will start there.
Who this applies to
You are in scope if you collect, use or disclose personal data about individuals in Singapore. Personal data means the ordinary things you already hold: names, email addresses, mobile numbers, delivery addresses, order histories, booking records, support tickets.
That covers the obvious cases — an online store, a clinic with an appointment system, a tutoring business with a parent mailing list — and the less obvious ones, like a tradesperson keeping quotes in a spreadsheet or a cafe running a loyalty scheme on an iPad.
You do not need a website, and using someone else's platform does not move the responsibility: the platform is accountable for its own systems, but the customer data you gather through it is yours. Being small changes how much work each obligation involves, not whether it applies.
What the PDPA asks of you
Appoint a Data Protection Officer and publish their contact details. Every organisation must designate at least one Data Protection Officer, a DPO, and make that person's business contact information publicly available. This applies regardless of size. A one-person business still needs a DPO, and it can be the owner — you are allowed to appoint yourself. This is the single most commonly missed obligation among Singapore small businesses, and the cheapest to fix. The failure is almost never refusal; it is that nobody ever mentioned the requirement, or that a DPO was named internally but the contact details never reached the website. Both halves matter: designating someone is not enough if a customer cannot find out how to reach them.
Get consent, notify your purposes, and know the two exceptions. As a general rule you need an individual's consent to collect, use or disclose their personal data, and you must tell them the purposes you are collecting it for. That notification is the job your privacy policy does, and the common failure is inheritance — a template copied from a larger company, describing systems you do not run. Singapore recognises two alternatives to asking outright. Deemed consent covers situations where a person voluntarily provides data for an obvious purpose, such as handing over a delivery address to have a parcel delivered. Legitimate interests lets you proceed where the benefit outweighs any adverse effect on the individual, provided you have actually assessed that. Neither covers marketing to someone who never asked for it.
Be ready to handle access and correction requests, and keep data accurate. Individuals can ask what personal data you hold about them and how it has been used or disclosed, and they can ask you to correct it if it is wrong. Alongside that sits a standalone accuracy obligation: make a reasonable effort to keep data accurate and complete where you will use it to make a decision affecting the person, or pass it to another organisation. The practical work is knowing where the data lives before a request arrives, rather than hunting through three inboxes and an old booking system under time pressure.
Protect the data, and stop keeping what you no longer need. The protection obligation asks for reasonable security arrangements, without handing you a checklist: who on your team can see customer data and why, multi-factor authentication on the accounts that matter, and removing access when someone leaves. Running alongside it is retention limitation — you must cease to retain personal data once its purpose has ended and there is no legal or business reason to keep it. Old customer lists you have forgotten about are still your liability.
Treat sending data overseas as its own decision. The transfer limitation obligation means you cannot simply move personal data out of Singapore and hope for the best; you are expected to ensure the recipient is bound to a standard of protection comparable to the PDPA. For most small businesses that comes down to knowing where your email tool, CRM, helpdesk and hosting actually keep data, and being able to say so.
Know the breach clock, and read it carefully. If a breach is notifiable, you must notify the PDPC no later than 3 calendar days after the day you make the assessment that it is notifiable. The detail matters: the clock runs from your assessment, not from the moment you discovered something was wrong. You are still expected to assess promptly, but it does mean your first move is to establish the facts. A breach is notifiable if it is likely to result in significant harm to affected individuals, or if it is of significant scale, meaning 500 or more people affected. Where significant harm is likely, you must also notify those individuals as soon as practicable. Decide who makes that assessment now, while nothing is on fire.
Check the Do Not Call registry before you market. The DNC registry sits separately from the obligations above and is regularly forgotten. It governs marketing calls, texts and faxes sent to Singapore telephone numbers, and requires you to check the register before sending. Having someone's consent to hold their data is not the same as being clear to text them a promotion.
What changes by the end of 2026
One dated change is coming, and it is widely misread. Under the PDPC's advisory guidelines, organisations must stop using the NRIC number, or a partial NRIC number, for authentication by 31 December 2026.
Authentication means verifying that someone is who they claim to be. The everyday example is the support call where you ask a customer to confirm the last few characters of their NRIC before discussing their account. That has to stop, as does using an NRIC or partial NRIC as a password or the answer to a security question.
What the rule does not do is ban collecting or holding NRIC numbers. Using an NRIC for identification — establishing who a person is, rather than proving they are that person — remains permitted where it is required by law or necessary to accurately establish identity. A clinic that must record patient identity is not being told to delete anything. Take that distinction away with you; conflating the two is the most common misreading of this change.
Separately, you may see the EU-Singapore Digital Trade Agreement described as opening the gates for data flows. Be careful with that. It has been concluded and is progressing towards entry into force, but it is a trade agreement. It is not an EU adequacy decision, and it does not remove the need for a transfer safeguard under the GDPR when EU personal data comes to Singapore.
Common mistakes
The most common mistake is the DPO. Businesses assume the requirement is for larger organisations, or appoint someone quietly and never publish the contact details.
The second is misreading the breach clock — treating the 3 days as running from discovery, then either panicking or, worse, delaying the assessment to delay the clock. Assess promptly; the three days run from there.
The third is forgetting the DNC registry exists, because it sits outside the privacy policy work. The fourth is keeping data forever: exports, old spreadsheets and dormant CRM records that serve no purpose but still carry risk. The fifth is a privacy policy written at launch and never touched. Accuracy is the obligation, not the existence of the document.
Where Dxtra fits
Dxtra generates a privacy program from a questionnaire about how your business actually works: a privacy policy, a cookie notice, consent records, processing records, a public Transparency Center, and handling for data subject access requests. It covers more than 500 obligations across over 140 countries, and starts at $10 a month. It gets the paperwork built and kept current without you assembling it, and does not replace judgement about how your business really runs.
Where to start
Do the DPO first: it is the most commonly missed item and the fastest to close. Name someone — yourself is fine — and put their business contact details where a customer can find them.
Then write down every tool that touches customer data and where each stores it, because both your transfer answer and your security answer depend on that list. Read your privacy policy as a customer would and ask whether the stated purposes match reality. Decide who assesses a breach. And if you market by call or text, check the DNC step is genuinely in your process.
If you want an outside read before you begin, Dxtra's free scan reads your site's public pages in about two minutes with no signup and returns a risk band with findings mapped to named sources — it points you at what to look at first, and does not determine whether you are compliant.
This article is general information, not legal advice. Rules change; confirm anything that matters with the Personal Data Protection Commission (pdpc.gov.sg) or a qualified adviser before you rely on it.
