Skip to the content
Global Data RulesData governance rules, country by country

Singapore

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Singapore — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: MediumEnforcement: Active

Singapore lets personal data leave the country, and we found no industry that is forced to keep data on Singaporean soil. What you must do instead is make the person receiving the data legally bound to protect it as well as Singapore law does. There is no government list of approved or banned countries and no permission to apply for. The privacy regulator is real, staffed, and publishes decisions.

Data governance in Singapore

The eight things that decide how you handle data about people in Singapore. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The privacy law reaches a company that has never set foot in Singapore. It defines an organisation as any body of persons whether or not formed under Singapore law and whether or not it has an office here. There is no revenue or headcount threshold to fall below, and no in-country agent to appoint. You must name at least one person responsible for compliance and publish their contact details, but that person may sit anywhere in the world.

What you have to do here:
Appoint a data protection officer

Where the data is allowed to live

Yes, it can leave. This is the unusual part. We searched banking, payments, insurance, securities, health, telecoms, government, education, gaming, mapping and defence. We found no rule anywhere that forces personal data to stay in Singapore. What the law asks for is protection, not location. Before data goes abroad you must make sure the recipient is under a legal duty to protect it. That duty must reach a standard comparable to Singapore's.

What you have to do here:
Put a transfer safeguard in place

What to do: Get the paperwork for one of the routes below signed before any data leaves Singapore.

Sending data out of the country

There is no list of approved countries, no list of banned countries, and no form to file. You need one thing: the recipient must be under a legally enforceable duty to protect the data to a comparable standard. Most companies do this with a contract they draft themselves, because Singapore does not publish a template. Group companies can use internal group-wide rules instead, and since 2 March 2026 a recipient holding a Global Cross-Border Privacy Rules certificate also counts.

Ways to send data out:
Standard contract clauses · Approved group rules · Certification scheme · Explicit consent

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Personal Data Protection Commission enforces the law. It is the same body as the media and telecoms regulator, wearing a different hat. It is really working. It publishes batches of decisions and settlements several times a year, most recently in 2026. Financial firms answer to the central bank as well. Anyone running critical national systems answers to the Cyber Security Agency. All three are staffed and issuing new rules.

How long you must keep it — and when to delete it

Both a maximum and a minimum apply. The maximum: you must stop keeping personal data once the purpose is finished and there is no legal or business reason to hold it. No fixed number of days is attached to that. The minimum: company accounting records must be kept for at least five years. Tax records must be kept for at least five years from the relevant year of assessment. Employment records must cover the latest two years, and be kept for one year past the date an employee leaves.

What you have to do here:
Delete data after a period · Keep data for a minimum period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

There are at least three separate deadlines and they run at very different speeds. Privacy: once you have decided a breach is serious enough to report, you have three calendar days to tell the regulator. Finance: a bank or other supervised firm has ONE HOUR to tell the central bank about a severe incident. It then has fourteen days for a root cause report. Critical national systems: TWO HOURS by phone to the national cyber agency, then a fuller report within seventy-two hours.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things. One: an individual employee can go to prison for two years for leaking personal data, and that is separate from any fine on the company. Two: any other Singapore law beats the privacy law, so banking secrecy and similar duties override it. Three: every organisation must stop using national identity card numbers as passwords by 31 December 2026. Four: the data portability right is printed in the Act but has never been switched on. Five: the banking outsourcing rulebook everyone cites was cancelled in December 2024.

What you have to do here:
Let people take their data elsewhere · Extra vendor secrecy terms
What it costs if you get it wrong:
Criminal liability

What's changing next

Three real things are in flight. A new health law has been passed but has not started. It will add its own breach reporting deadlines for anyone handling health records. A draft law for big data centres and big cloud providers went out for public comment on 1 July 2026 and closed on 22 July 2026. It is not law yet. And every organisation must stop using national identity numbers as passwords by 31 December 2026. Separately, watch two powers the government can use with no consultation at all.

What to do: Diarise 31 December 2026 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries6 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

Cloud and outsourcing rules

Official name: MAS Notice 658 — Management of Outsourced Relevant Services · Issued 11 December 2023 under sections 47A(2), (4), (6), (7) and (12) of the Banking Act 1970. Notice 1121 is the merchant bank equivalent. · Regulator directive

In forceYes, with paperwork

The rulebook a Singapore bank must follow before customer information reaches any outside supplier. It expressly allows the service to be performed overseas, so it is not a rule about keeping data in the country. But it demands written notice of secrecy duties, deletion on exit, independent audits, and a register filed with the central bank. It replaced Notice 634 and the old Guidelines on Outsourcing on 11 December 2024.

In force since 11 December 2024

Enforced by Monetary Authority of Singapore

How this country controls where data goes: No restriction · Accepted routes: Standard contract clauses

Finance

Banking rules

Official name: MAS Notices on Technology Risk Management and Cyber Hygiene (FSM-N21 to FSM-N26 family) · Issued 9 May 2024 under the Financial Services and Markets Act 2022; the earlier Notices 644, 655, 644A, 655A, 1114 and 1118 were cancelled with effect from 10 May 2024 · Regulator directive

In forceYes — store it anywhere

The fastest deadline in Singapore. A supervised financial institution has one hour from discovering a severe system or security incident to tell the central bank. It then has fourteen days to file a root cause report. Note the trap. The notice numbers everyone quotes were cancelled on 10 May 2024. They were replaced by a new family issued under the Financial Services and Markets Act.

In force since 10 May 2024

Enforced by Monetary Authority of Singapore

How this country controls where data goes: No restriction

Cyber security rules (Inserted by the Cybersecurity (Amendment) Act 2024 (Act 19 of 2024))

Official name: Cybersecurity Act 2018, Parts 3C and 3D — entities of special cybersecurity interest and major foundational digital infrastructure service providers · Inserted by the Cybersecurity (Amendment) Act 2024 (Act 19 of 2024) · Act of parliament

Passed, not yet fully in forceYes, with paperwork

The power that would put cloud providers and data centres under Singapore's cyber regulator. The definitions, and the clauses saying who these Parts apply to, have been in force since 31 October 2025. But the Parts themselves have never been started, and section 18 currently reads as deleted. A single commencement notification would turn this on. It would reach a provider based entirely outside Singapore that serves Singapore users.

Enforced by Cyber Security Agency of Singapore

How this country controls where data goes: No restriction

Applies to every company6 rules

These bind you whatever business you are in, once the country's rules reach you.

Breach reporting rules

Official name: Personal Data Protection Act 2012 · Act 26 of 2012, 2020 Revised Edition; consolidated version in force from 5 December 2025 · Act of parliament

Partly in forceYes, with paperwork

Singapore's general privacy law. It reaches foreign companies with no local presence. It requires you to name a responsible person and publish their contact details. It lets data leave the country, provided the recipient is legally bound to comparable protection. Breach notification has been live since 1 February 2021. The turnover-based penalty maximum has applied since 1 October 2022. One whole Part, on data portability, is printed in the statute but has never been switched on.

In force since 2 July 2014

Enforced by Personal Data Protection Commission

How this country controls where data goes: No restriction · Accepted routes: Standard contract clauses, Approved group rules, Certification scheme, Explicit consent

Government data rules

Official name: Personal Data Protection Regulations 2021, Part 3 · S 63/2021, as amended by S 86/2026; consolidated version in force from 2 March 2026 · Directly binding regulation

In forceYes, with paperwork

The mechanics of sending personal data out of Singapore. There is no destination list of any kind and no government approval. You need one of four things. A contract. Group-wide binding rules, for related companies. A recognised privacy certification. Or valid consent, given after you hand the person a written summary of how well the destination protects the data.

In force since 1 February 2021

Enforced by Personal Data Protection Commission

How this country controls where data goes: No restriction · Accepted routes: Standard contract clauses, Approved group rules, Certification scheme, Explicit consent

General data protection law

Official name: Personal Data Protection Act 2012, Part 6B (Data Portability Obligation) · Inserted by the Personal Data Protection (Amendment) Act 2020 (Act 40 of 2020) · Act of parliament

Passed, not yet fully in forceYes — store it anywhere

Singapore's data portability right. Parliament passed it in 2020, and the rest of the Act refers to it repeatedly. But the Part has never been started. So on 18 August 2026 nobody can demand their data be moved to a competitor. It can be switched on by a commencement notification, without further debate.

Enforced by Personal Data Protection Commission

How this country controls where data goes: No restriction

Who you would hear from

  • The general privacy law, the Do Not Call registry, and data breach notification

    Fully working. It is legally the same body as the media and telecoms regulator, which section 5 of the Act designates as the Commission. It publishes decisions and voluntary undertakings in batches several times a year. Batches dated 8 January 2026, 26 February 2026 and 9 April 2026 are on its own site. On 2 February 2026 it announced it would step up enforcement on misuse of national identity numbers.

  • IMDA

    Telecoms and media regulation; also the legal identity of the privacy Commission; proposed licensor for data centres and cloud under the draft Digital Infrastructure Bill

  • Banking, payments, insurance, capital markets, trust companies

    Highly active. Replaced its entire outsourcing rulebook with effect from 11 December 2024 and its technology risk and cyber hygiene notices with effect from 10 May 2024. Currently consulting on new third-party risk management guidelines.

  • Commissioner of Cybersecurity

    Critical information infrastructure, systems of temporary cybersecurity concern, cybersecurity service provider licensing

    Operational. It issued a new Cybersecurity Code of Practice for Critical Information Infrastructure on 29 July 2026. It does not yet regulate cloud providers or data centres, because the relevant Parts of the Act have not started.

  • Policy and legislation for digital, data and online safety

  • Licensed healthcare services and, once commenced, the national health information regime

    Operational for healthcare licensing. The Health Information Act 2026 rules it will administer are not yet in force.

  • Company accounting records and retention under the Companies Act

  • Tax record retention

  • Employment records retention

  • Government systems and public sector data handling

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Whether Singapore government procurement rules (Instruction Manual 8) impose where data has to be stored or classification-based hosting conditions on suppliers

    We could not confirm what Instruction Manual 8 requires. It is not published as a public government document. If you supply Singapore public agencies, assume your contract sets hosting conditions and ask the agency. Do not rely on the absence of a rule in law. Checked 18 August 2026.

  • The exact age thresholds in the Advisory Guidelines on the PDPA for Children's Personal Data in the Digital Environment

    We could not confirm the thresholds in these guidelines. The regulator's announcement page confirms they exist and were published on 27 March 2024. We could not read the body text of that page. If you handle children's data, read the guidelines yourself.

  • That MAS Notice FSM-N25's one-hour incident clock applies in identical terms across every class of supervised financial institution

    We could not confirm that every class of licence carries the same deadline. We checked the one-hour and fourteen-day wording in the notice for licensed trust companies. We confirmed that matching notices FSM-N21, FSM-N22, FSM-N23, FSM-N24 and FSM-N26 exist for other classes, but we did not read each one. Treat one hour as your working assumption, and check it against your own licence.

  • That no localisation rule exists in the education, gaming, defence or mapping sectors

    We found no rule requiring telecoms data to stay in Singapore. We searched the statute book and the relevant regulators and found nothing. The Telecommunications Act 1999, in force from 1 October 2025, says nothing about keeping anything inside Singapore. Checked 18 August 2026, with medium confidence.

  • The exact commencement date of the Health Information Act 2026

    We could not confirm when this Act will start. The official statute site listed it as uncommenced on 18 August 2026, and we found no commencement notification. If you handle Singapore health records, check again each month.

  • Whether the Cybersecurity Act Parts 3C and 3D will be commenced before or alongside the Digital Infrastructure Bill

    We could not confirm the order in which these changes will happen. The consultation paper says the Bill would change the Cybersecurity Act 2018 and the Cybersecurity (Amendment) Act 2024 to line up the definitions. No start date has been announced.

  • Precise current PDPA financial penalty levels actually imposed in 2025 and 2026

    We could not confirm the actual fine amounts imposed in 2025 and 2026. We could not read the individual decision texts on the regulator's site. We can show that decisions are published regularly, but not what the penalties were. Read the decisions yourself if the amounts matter to you.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.