PDPA-Compliant Software: What Singapore SMEs Need to Know (2026)
By GDI Solutions · Updated 2026-08-12 · 8 min read
If your software collects personal data in Singapore, it falls under the Personal Data Protection Act (PDPA). There are eleven Data Protection Obligations (ten in force; Data Portability not yet). The ones that shape software design most are Protection, Consent, Notification, Retention Limitation, and Access & Correction — plus a strict data-breach notification regime and a mandatory Data Protection Officer.
This is a practical summary, not legal advice. Verify specifics against the PDPC's own guidance for your situation.
The eleven PDPA obligations
- Consent — collect/use/disclose only with consent; allow withdrawal.
- Purpose Limitation — only for purposes a reasonable person would find appropriate.
- Notification — tell individuals why you're collecting their data.
- Access & Correction — let people access and correct their data on request.
- Accuracy — keep data accurate, especially if it drives decisions.
- Protection — make reasonable security arrangements against unauthorised access.
- Retention Limitation — stop keeping data you no longer need.
- Transfer Limitation — send data overseas only with comparable protection.
- Data Breach Notification — report qualifying breaches (see below).
- Accountability — appoint a DPO and publish data-protection policies.
- Data Portability — not yet in force (awaiting regulations).
Breach notification: the numbers that matter
- Notifiable if: likely significant harm, or 500+ individuals affected (significant scale).
- Assess whether a breach is notifiable within 30 calendar days of credible grounds.
- Notify the PDPC no later than 3 calendar days after determining it's notifiable.
- Notify affected individuals at the same time as, or after, the PDPC.
Penalties
Since 1 October 2022, the maximum financial penalty is the higher of S$1 million or up to 10% of annual Singapore turnover(the 10% cap applies above S$10m turnover). This is a real board-level risk, not a formality.
What this means when we build for you
PDPA compliance is easiest when it's designed in, not bolted on. When GDI Solutions builds custom software, we bake in consent capture, purpose-scoped data collection, retention controls, access/ correction flows, encryption and access logging, and — where data is sensitive — an architecture that keeps it in Singapore or on your own infrastructure. We can also help you appoint and publish a DPO contact. It's the difference between a system that's compliant by design and one that's a breach waiting to happen.
Frequently asked questions
What are the PDPA obligations for software in Singapore?
Singapore's PDPA sets out eleven Data Protection Obligations: Consent, Purpose Limitation, Notification, Access & Correction, Accuracy, Protection, Retention Limitation, Transfer Limitation, Data Breach Notification, Accountability, and Data Portability. Ten are in force; Data Portability is not yet in force pending regulations. Software that collects personal data must be designed around the Protection, Consent, Retention and Access obligations in particular.
When must a data breach be reported under the PDPA?
A breach must be notified to the PDPC if it is likely to cause significant harm, or if it affects 500 or more individuals (significant scale). You must assess whether a breach is notifiable within 30 calendar days of having credible grounds, and once you determine it is notifiable, notify the PDPC no later than 3 calendar days after. Affected individuals must be notified at the same time or after the PDPC.
What are the penalties for breaching the PDPA?
Since 1 October 2022, the maximum financial penalty is the higher of S$1 million, or up to 10% of the organisation's annual turnover in Singapore — the 10%-of-turnover cap applies to organisations with annual Singapore turnover above S$10 million. Below that, the cap is S$1 million.
Does my company need a Data Protection Officer (DPO)?
Yes. Appointing at least one DPO is mandatory for every organisation in Singapore regardless of size (section 11(3) PDPA), and you must make at least one DPO's business contact information publicly available (section 11(5)). The DPO can be an existing employee or outsourced.
Want a fixed quote for your project?
Tell us what you need built. We reply with a clear scope, timeline and fixed price — usually within one business day.
Start a project →