Singapore
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Singapore — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Singapore lets personal data leave the country, and we found no industry that is forced to keep data on Singaporean soil. What you must do instead is make the person receiving the data legally bound to protect it as well as Singapore law does. There is no government list of approved or banned countries and no permission to apply for. The privacy regulator is real, staffed, and publishes decisions.
Data governance in Singapore
The eight things that decide how you handle data about people in Singapore. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The privacy law reaches a company that has never set foot in Singapore. It defines an organisation as any body of persons whether or not formed under Singapore law and whether or not it has an office here. There is no revenue or headcount threshold to fall below, and no in-country agent to appoint. You must name at least one person responsible for compliance and publish their contact details, but that person may sit anywhere in the world.
- What you have to do here:
- Appoint a data protection officer
Section 2 defines an 'organisation' to include any individual, company, association or body of persons. It covers corporate and unincorporated bodies alike. It applies whether or not the body is formed or recognised under the law of Singapore. It applies whether or not the body lives here, or has an office or place of business here. Section 11(3) requires you to name one or more individuals responsible for compliance. Most people call that person the Data Protection Officer. Section 11(5) requires you to publish their business contact information. Neither section says that person must be based in Singapore. Section 4 sets out the exclusions. Individuals acting personally or at home. Employees acting in the course of their job. Public agencies, which are covered instead by the Public Sector (Governance) Act 2018. Business contact information. Records over 100 years old. And individuals dead more than 10 years. A supplier handling data for you under a written contract is relieved of most duties. It is not relieved of the security and retention duties.
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Act 2012, section 2 (definition of 'organisation'), consolidated text in force from 5 December 2025
sso.agc.gov.sg
““organisation” includes any individual, company, association or body of persons, corporate or unincorporated, whether or not — (a) formed or recognised under the law of Singapore; or (b) resident, or having an office or a place of business, in Singapore”
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Act 2012, sections 4 and 11 (application of the Act; designation and publication of a responsible individual)
sso.agc.gov.sg
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Public Sector (Governance) Act 2018, sections 7 and 8 — the separate regime that covers public agencies
sso.agc.gov.sg
Link checked 18 August 2026
Where the data is allowed to live
Yes, it can leave. This is the unusual part. We searched banking, payments, insurance, securities, health, telecoms, government, education, gaming, mapping and defence. We found no rule anywhere that forces personal data to stay in Singapore. What the law asks for is protection, not location. Before data goes abroad you must make sure the recipient is under a legal duty to protect it. That duty must reach a standard comparable to Singapore's.
- What you have to do here:
- Put a transfer safeguard in place
Section 26(1) of the Personal Data Protection Act 2012 bans a transfer unless you follow the requirements set under the Act. Those requirements exist to make sure data you send abroad gets protection comparable to the protection under the Act. The detailed requirements sit in Part 3 of the Personal Data Protection Regulations 2021. There is no country list of any kind, populated or empty. Industry by industry on 18 August 2026, each rated separately: - Banking and merchant banking (conditional): Monetary Authority of Singapore Notice 658 and Notice 1121 cover outsourced services involving customer information. They expressly allow the work to be done overseas. They set conditions rather than a ban. Note the trap. The previous rulebook, Notice 634 and the Guidelines on Outsourcing, was cancelled on 11 December 2024. - Insurance, capital markets, payments and trust companies (conditional): covered by the Guidelines on Outsourcing (Financial Institutions other than Banks), effective 11 December 2024. Nothing about keeping data in the country. - Health (conditional): the Healthcare Services Act 2020 requires records to be kept and secured but says nothing about where. The Health Information Act 2026 has been passed but has not started. It says nothing about where data must sit either. - Telecoms (open): the Telecommunications Act 1999, as in force from 1 October 2025, says nothing about keeping anything inside Singapore. - Critical information infrastructure (a copy stays here in reality, not by law): the Cybersecurity Act 2018 applies to systems located wholly or partly in Singapore. Since 31 October 2025 it also applies to a system located wholly outside Singapore that is owned by a person in Singapore. It governs security, not location. - Company accounting records (a copy stays here): the Companies Act 1967 allows records to be kept abroad. But statements and returns must be sent to and kept in Singapore. - Mapping, gaming, education and defence: we found no rule about where data must sit, checked 18 August 2026, with medium confidence.
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Act 2012, section 26 (transfer of personal data outside Singapore)
sso.agc.gov.sg
“An organisation must not transfer any personal data to a country or territory outside Singapore except in accordance with requirements prescribed under this Act to ensure that organisations provide a standard of protection to personal data so transferred that is comparable to the protection under this Act.”
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Regulations 2021 (S 63/2021), Part 3, regulations 10 to 12, consolidated text in force from 2 March 2026
sso.agc.gov.sg
Link checked 18 August 2026
- Official sourceMonetary Authority of SingaporeMAS Notice 658, Management of Outsourced Relevant Services — paragraphs 6, 8 and 10 expressly address services performed overseas
mas.gov.sg
“in the case where the material ongoing outsourced relevant service is to be performed outside Singapore, the bank’s obligations to protect customer information in accordance with the laws of the place where the material ongoing outsourced relevant service is to be performed”
Link checked 18 August 2026
- Official sourceMonetary Authority of SingaporeMAS Third-Party Risk Management — confirms Notice 658, Notice 1121 and the Guidelines on Outsourcing for non-banks all took effect 11 December 2024
mas.gov.sg
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Telecommunications Act 1999, consolidated text in force from 1 October 2025 — contains no data residency requirement
sso.agc.gov.sg
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Companies Act 1967, section 199(4) — records kept abroad must be mirrored by statements and returns kept in Singapore
sso.agc.gov.sg
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Singapore.
Sending data out of the country
There is no list of approved countries, no list of banned countries, and no form to file. You need one thing: the recipient must be under a legally enforceable duty to protect the data to a comparable standard. Most companies do this with a contract they draft themselves, because Singapore does not publish a template. Group companies can use internal group-wide rules instead, and since 2 March 2026 a recipient holding a Global Cross-Border Privacy Rules certificate also counts.
- Ways to send data out:
- Standard contract clauses · Approved group rules · Certification scheme · Explicit consent
Regulation 10(1) of the Personal Data Protection Regulations 2021 requires you to take appropriate steps before you send data. You must check and make sure the recipient is bound by legally enforceable duties. Regulation 11 lists what counts: any law, a contract, binding corporate rules, or any other legally binding document. A qualifying contract must do two things. It must require comparable protection. And it must name the countries and territories the data may be sent to. Binding corporate rules may only be used between related companies. They must name the recipients, the destinations, and the rights and duties they create. Regulation 12 treats a recipient as compliant if it holds a specified certification. As amended by S 86/2026, with effect from 2 March 2026, this now covers four schemes for suppliers who handle data for others. Two are run by Asia-Pacific Economic Cooperation: the APEC Privacy Recognition for Processors System and the APEC Cross-Border Privacy Rules System. The other two are the Global Privacy Recognition for Processors System and the Global Cross-Border Privacy Rules System. For everyone else, the two Cross-Border Privacy Rules systems count. Regulation 10(2) lists situations where the requirement counts as met. The person consents. But that consent is invalid unless you first gave them a written summary of the protection the destination offers. You also cannot force consent as a condition of a product unless it is really necessary. Deemed consent under section 15 also counts. So does a transfer needed for a use allowed without consent. So does data in transit, and data already publicly available in Singapore. The Commission can also exempt a named organisation from the transfer requirements under section 26(2). That exemption need not be published in the Gazette. It can be revoked at any time.
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Regulations 2021, regulation 11 (legally enforceable obligations)
sso.agc.gov.sg
“legally enforceable obligations include obligations imposed on a recipient of personal data under — (a) any law; (b) any contract in accordance with paragraph (2); (c) any binding corporate rules in accordance with paragraph (3); or (d) any other legally binding instrument.”
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Regulations 2021, regulation 12 (recipients holding specified certifications), as amended by S 86/2026 with effect from 2 March 2026
sso.agc.gov.sg
“(iii) the Global Privacy Recognition for Processors System; or (iv) the Global Cross-Border Privacy Rules System”
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Act 2012, section 26(2) to (4) — the Commission's power to exempt a named organisation, unpublished and revocable at any time
sso.agc.gov.sg
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The Personal Data Protection Commission enforces the law. It is the same body as the media and telecoms regulator, wearing a different hat. It is really working. It publishes batches of decisions and settlements several times a year, most recently in 2026. Financial firms answer to the central bank as well. Anyone running critical national systems answers to the Cyber Security Agency. All three are staffed and issuing new rules.
Section 5 of the Personal Data Protection Act 2012 designates the Info-communications Media Development Authority as the Personal Data Protection Commission. So the Commission is not a separate legal body. Here is the evidence that it works in reality, not just on paper. It published batches of decisions and undertakings on 3 July 2025, 31 July 2025, 7 August 2025, 3 September 2025 and 2 October 2025. More followed on 28 October 2025, 4 December 2025, 8 January 2026, 26 February 2026 and 9 April 2026. All are listed on its own site. On 2 February 2026 it announced it will step up enforcement on misuse of national identity numbers. The Commission can issue directions under section 48I and financial penalties under section 48J. The maximum is 10 per cent of annual turnover in Singapore, where your Singapore turnover is over 10 million Singapore dollars (about 7.8 million US dollars). Otherwise the maximum is 1 million Singapore dollars (about 780,000 US dollars). That maximum has applied since 1 October 2022. Individuals can also sue directly under section 48O. The Monetary Authority of Singapore replaced its entire outsourcing rulebook on 11 December 2024. It replaced its technology risk and cyber hygiene notices on 10 May 2024. That is a sign of active supervision, not idle supervision. The Commissioner of Cybersecurity issued a new Cybersecurity Code of Practice for Critical Information Infrastructure on 29 July 2026.
Sources
- Official sourcePersonal Data Protection CommissionEnforcement Decisions — the Commission's own published decisions and voluntary undertakings
pdpc.gov.sg
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionPDPC to step up enforcement action against misuse of NRIC numbers, published 2 February 2026
pdpc.gov.sg
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Act 2012, sections 5, 48I, 48J and 48O
sso.agc.gov.sg
“in the case of a contravention on or after the date of commencement of section 24 of the Personal Data Protection (Amendment) Act 2020 by an organisation whose annual turnover in Singapore exceeds $10 million — 10% of the annual turnover in Singapore of the organisation”
Link checked 18 August 2026
- Official sourceCyber Security Agency of SingaporeCodes of Practice — Cybersecurity Code of Practice for Critical Information Infrastructure 2026, issued 29 July 2026
csa.gov.sg
Link checked 18 August 2026
How long you must keep it — and when to delete it
Both a maximum and a minimum apply. The maximum: you must stop keeping personal data once the purpose is finished and there is no legal or business reason to hold it. No fixed number of days is attached to that. The minimum: company accounting records must be kept for at least five years. Tax records must be kept for at least five years from the relevant year of assessment. Employment records must cover the latest two years, and be kept for one year past the date an employee leaves.
- What you have to do here:
- Delete data after a period · Keep data for a minimum period
The maximum. Section 25 of the Personal Data Protection Act 2012 says you must stop keeping documents that contain personal data. You can instead strip out the link to particular individuals. This applies as soon as it is reasonable to assume the purpose is no longer served. It also requires that keeping the data is no longer necessary for legal or business purposes. The minimum. Companies Act 1967 section 199(2) sets five years from the end of the financial year. The tax authority applies five years from the relevant Year of Assessment. That comes from the Income Tax Act 1947 and the Goods and Services Tax Act 1993. Penalties run to 5,000 Singapore dollars (about 3,900 US dollars) and up to six months in prison. The Ministry of Manpower requires employment records for the latest two years for current employees. For someone who leaves, the last two years of records are kept for one year afterwards. For a struck-off or wound-up company, an officer or the liquidator must keep the books for five years after dissolution. How the clash resolves. Usually it never becomes a clash, because section 25(b) itself allows you to keep data still needed for legal purposes. Where it does clash, section 4(6)(b) of the Act settles it. Other written law wins to the extent of any inconsistency. Location matters here too. Companies Act section 199(4) allows accounting records to be held abroad. But statements and returns good enough to prepare true and fair financial statements must be sent to and kept in Singapore.
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Act 2012, section 25 (retention of personal data) and section 4(6)(b)
sso.agc.gov.sg
“An organisation must cease to retain its documents containing personal data, or remove the means by which the personal data can be associated with particular individuals, as soon as it is reasonable to assume that — (a) the purpose for which that personal data was collected is no longer being served by retention of the personal data; and (b) retention is no longer necessary for legal or business purposes.”
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Companies Act 1967, section 199(2) and 199(4) — five-year retention, and mirrored statements for records kept abroad
sso.agc.gov.sg
“If accounting and other records are kept by the company at a place outside Singapore there must be sent to and kept at a place in Singapore and be at all times open to inspection by the directors such statements and returns with respect to the business dealt with in the records so kept as will enable to be prepared true and fair financial statements”
Link checked 18 August 2026
- Official sourceInland Revenue Authority of SingaporeRecord Keeping Requirements — at least five years from the relevant Year of Assessment
iras.gov.sg
“Your company must retain its records for at least 5 years from the relevant YA.”
Link checked 18 August 2026
- Official sourceMinistry of ManpowerEmployment records — how long employers must keep them
mom.gov.sg
“For current employees: Latest two years. For ex-employees: Last two years, to be kept for one year after the employee leaves employment.”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
There are at least three separate deadlines and they run at very different speeds. Privacy: once you have decided a breach is serious enough to report, you have three calendar days to tell the regulator. Finance: a bank or other supervised firm has ONE HOUR to tell the central bank about a severe incident. It then has fourteen days for a root cause report. Critical national systems: TWO HOURS by phone to the national cyber agency, then a fuller report within seventy-two hours.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Privacy deadline. Sections 26C and 26D of the Personal Data Protection Act 2012. Once you have reason to believe a breach happened, you must assess it 'in a reasonable and expeditious manner'. There is no fixed deadline for the assessment itself. The three-day clock starts only when your assessment concludes that the breach is notifiable. A breach is notifiable if it causes or is likely to cause significant harm. It is also notifiable if it is or is likely to be of significant scale. The Personal Data Protection (Notification of Data Breaches) Regulations 2021 set the significant-scale threshold at 500 affected individuals. You must tell affected individuals on or after you tell the regulator, in any reasonable manner. That applies where the significant-harm test is met. A breach kept inside one organisation is treated as not notifiable. A supplier who handles data for you must tell you without undue delay. The duty to assess then falls on you. Finance deadline. Monetary Authority of Singapore Notice FSM-N25 requires notification 'as soon as possible, but not later than 1 hour, upon the discovery of a relevant incident'. A root cause and impact analysis report follows within 14 days. Parallel notices apply to other supervised firms. The old Notices 644, 655, 644A, 655A, 1114 and 1118 were cancelled with effect from 10 May 2024. Compliance manuals that still cite them are out of date. Cyber deadline. Section 14 of the Cybersecurity Act 2018 requires notification within the prescribed period. The Cyber Security Agency states the period is 2 hours from the moment you become aware. You call the number set out in Singapore's national cybersecurity incident response plan. Supplementary details follow within 72 hours. Since 31 October 2025 the duty also covers incidents on a supplier's interconnected systems. A fourth deadline is coming for healthcare once the Health Information Act 2026 starts. It creates separate duties to report notifiable cybersecurity incidents and notifiable data breaches. The periods will be set by regulations that do not yet exist.
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Act 2012, sections 26B, 26C and 26D
sso.agc.gov.sg
“the organisation must notify the Commission as soon as is practicable, but in any case no later than 3 calendar days after the day the organisation makes that assessment.”
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection (Notification of Data Breaches) Regulations 2021 (S 64/2021), regulation 4
sso.agc.gov.sg
“For the purposes of section 26B(3)(a) of the Act, the prescribed number of affected individuals is 500.”
Link checked 18 August 2026
- Official sourceMonetary Authority of SingaporeMAS Notice FSM-N25, Notice on Technology Risk Management, issued 9 May 2024, paragraphs 7 and 8
mas.gov.sg
“A trust company must notify the Authority as soon as possible, but not later than 1 hour, upon the discovery of a relevant incident.”
Link checked 18 August 2026
- Official sourceCyber Security Agency of SingaporeForms — reporting of cybersecurity incidents in respect of critical information infrastructure
csa.gov.sg
“The owner of a provider-owned critical information infrastructure must notify the Commissioner of the occurrence of the cybersecurity incident within 2 hours from awareness of an incident”
Link checked 18 August 2026
- Official sourceMonetary Authority of SingaporeNotice 644 Technology Risk Management [Cancelled] — evidence the old MAS technology and cyber notices were withdrawn on 10 May 2024
mas.gov.sg
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things. One: an individual employee can go to prison for two years for leaking personal data, and that is separate from any fine on the company. Two: any other Singapore law beats the privacy law, so banking secrecy and similar duties override it. Three: every organisation must stop using national identity card numbers as passwords by 31 December 2026. Four: the data portability right is printed in the Act but has never been switched on. Five: the banking outsourcing rulebook everyone cites was cancelled in December 2024.
- What you have to do here:
- Let people take their data elsewhere · Extra vendor secrecy terms
- What it costs if you get it wrong:
- Criminal liability
1. Criminal, not just administrative. Sections 48D, 48E and 48F of the Personal Data Protection Act 2012 create offences for an INDIVIDUAL. It is an offence to knowingly or recklessly disclose personal data without authorisation. It is an offence to misuse it for gain or to cause harm. And it is an offence to re-identify anonymised information. The maximum is a fine of 5,000 Singapore dollars (about 3,900 US dollars), two years in prison, or both. It applies personally to employees and contractor staff, including those handling government data. Sections 7 and 8 of the Public Sector (Governance) Act 2018 create matching offences with the same maximum, for people working inside public sector agencies. 2. Other law wins. Section 4(6)(b) says other written law prevails wherever the privacy duties are inconsistent with it. So a permissive answer under the privacy law is worth nothing if a banking secrecy duty, a professional secrecy duty or a licence condition says otherwise. 3. The national identity number deadline. On 2 February 2026 the regulator announced that organisations must stop using National Registration Identity Card numbers to check who someone is by 31 December 2026. It said it will step up enforcement. Using a national identity number as a password, a default PIN or a proof of identity is the exact pattern being targeted. 4. A sleeping duty inside the statute. Part 6B of the Act is the data portability duty. It was enacted by the Personal Data Protection (Amendment) Act 2020. It is referred to throughout the in-force text, in sections 4 and 48J among others. Yet the Part itself has never been started. A naive reading of the Act will report a portability right that does not currently exist. It can be switched on by a commencement notification. 5. Stale banking guidance. Monetary Authority of Singapore Notice 634, on banking secrecy conditions for outsourcing, was cancelled with effect from 11 December 2024. The well-known Guidelines on Outsourcing, dated 2016 and revised 2018, are also marked cancelled. They were replaced by Notice 658 for banks and Notice 1121 for merchant banks. There are also separate Guidelines on Outsourcing for banks and for non-banks. All took effect on 11 December 2024. 6. One more, for consumer products. The regulator issued separate Advisory Guidelines for children's personal data in the digital environment in March 2024. Treat children's data as its own piece of work rather than assuming the general rules cover it.
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Act 2012, Part 9B, sections 48D to 48F (offences affecting personal data and anonymised information)
sso.agc.gov.sg
“the individual shall be guilty of an offence and shall be liable on conviction to a fine not exceeding $5,000 or to imprisonment for a term not exceeding 2 years or to both.”
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Act 2012, section 4(6)(b) and references to the uncommenced Part 6B in sections 4 and 48J
sso.agc.gov.sg
“the provisions of other written law prevail to the extent that any provision of Parts 3, 4, 5, 6, 6A and 6B is inconsistent with the provisions of that other written law.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionOrganisations to cease the use of NRIC numbers for authentication by 31 December 2026, published 2 February 2026
pdpc.gov.sg
Link checked 18 August 2026
- Official sourceMonetary Authority of SingaporeNotice 634 Banking Secrecy — Conditions for Outsourcing [Cancelled]
mas.gov.sg
“This Notice was cancelled with effect from 11 December 2024.”
Link checked 18 August 2026
- Official sourceMonetary Authority of SingaporeGuidelines on Outsourcing [Cancelled] — the 2016 guidelines revised 5 October 2018, now withdrawn
mas.gov.sg
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Public Sector (Governance) Act 2018, sections 7 and 8 — equivalent criminal offences for public sector data
sso.agc.gov.sg
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionAdvisory Guidelines on the PDPA for Children's Personal Data in the Digital Environment, published 27 March 2024
pdpc.gov.sg
Link checked 18 August 2026
What's changing next
Three real things are in flight. A new health law has been passed but has not started. It will add its own breach reporting deadlines for anyone handling health records. A draft law for big data centres and big cloud providers went out for public comment on 1 July 2026 and closed on 22 July 2026. It is not law yet. And every organisation must stop using national identity numbers as passwords by 31 December 2026. Separately, watch two powers the government can use with no consultation at all.
Landing within twelve months, with dates: - 31 December 2026: the deadline to stop using National Registration Identity Card numbers to check who someone is. In February 2026 the regulator said it will step up enforcement. - Health Information Act 2026 (Act No. 1 of 2026): passed by Parliament on 12 January 2026, assented to on 3 February 2026 and published on 12 February 2026. It was still listed as Uncommenced on 18 August 2026. It creates a national electronic records system that named providers must contribute to. It adds new data security and retention duties. It adds separate duties to report cybersecurity incidents and data breaches, with the periods still to be set. It also creates a health data portability right. No start date has been announced. - Digital Infrastructure Bill: a draft was published for public consultation on 1 July 2026, closing 22 July 2026. It would licence data centre facility services in data centres with a critical information technology load of 10 megawatts or more. It would also licence cloud infrastructure and platform services earning 100 million Singapore dollars or more a year from Singapore users. That is about 78 million US dollars. Software-as-a-service is excluded. It would also make related changes to the Cybersecurity Act. It is a draft, not law. - The Monetary Authority of Singapore is consulting on new guidelines covering financial institutions' use of third-party services. POWERS THE GOVERNMENT ALREADY HOLDS, which matter more than the pending bills because they need no consultation: 1. Cybersecurity Act Parts 3C and 3D. The Cybersecurity (Amendment) Act 2024 started on 31 October 2025. The definitions of 'entity of special cybersecurity interest' and 'major foundational digital infrastructure service provider' are in force TODAY. So are the clauses in section 3(2E) to (2H) that point at them. The Parts that actually impose duties on those entities are not in force. Those Parts cover cloud service providers and data centres. Section 18 currently reads as deleted. A commencement notification alone would bring cloud and data centre rules into force. Note that they would reach a provider serving Singapore from wholly outside Singapore. 2. Personal Data Protection Act Part 6B, data portability. Enacted in 2020, never started, and can be switched on the same way. 3. Section 26(2) of the Personal Data Protection Act lets the Commission exempt a named organisation from the transfer rules by unpublished written notice. It can vary or revoke that notice at any time. Not coming. On 5 May 2026 the Ministry of Digital Development and Information told Parliament it will not amend the Act for data derived by artificial intelligence. It is relying on existing law and published guidelines instead.
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Uncommenced Acts — lists the Health Information Act 2026 as uncommenced as at 18 August 2026
sso.agc.gov.sg
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Health Information Act 2026 (Act No. 1 of 2026), Acts Supplement
sso.agc.gov.sg
“The following Act was passed by Parliament on 12 January 2026 and assented to by the President on 3 February 2026”
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and InformationPublic Consultation on Digital Infrastructure Bill, 1 July 2026
mddi.gov.sg
“All submissions should reach MDDI and IMDA within 3 weeks, no later than 22 July 2026, 10am”
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Cybersecurity Act 2018, section 3(2E) to (2H) in force from 31 October 2025, with section 18 deleted and Parts 3C and 3D absent from the in-force text
sso.agc.gov.sg
Link checked 18 August 2026
- Official sourceCyber Security Agency of SingaporeCybersecurity Act — the agency's own description of Entities of Special Cybersecurity Interest and Foundational Digital Infrastructure
csa.gov.sg
“companies that provide digital infrastructure services that are foundational to our economy or way of life (such as cloud service providers and data centres) will be regulated as Foundational Digital Infrastructure (FDI)”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionOrganisations to cease the use of NRIC numbers for authentication by 31 December 2026
pdpc.gov.sg
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and InformationMDDI response to a parliamentary question on reviewing the PDPA for AI-derived data, 5 May 2026
mddi.gov.sg
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and InformationNew Digital Infrastructure Act to enhance resilience and security of digital infrastructure and services, 1 March 2024
mddi.gov.sg
Link checked 18 August 2026
What to do: Diarise 31 December 2026 — that is the date this changes.
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries6 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Cloud and outsourcing rules
Official name: MAS Notice 658 — Management of Outsourced Relevant Services · Issued 11 December 2023 under sections 47A(2), (4), (6), (7) and (12) of the Banking Act 1970. Notice 1121 is the merchant bank equivalent. · Regulator directive
The rulebook a Singapore bank must follow before customer information reaches any outside supplier. It expressly allows the service to be performed overseas, so it is not a rule about keeping data in the country. But it demands written notice of secrecy duties, deletion on exit, independent audits, and a register filed with the central bank. It replaced Notice 634 and the old Guidelines on Outsourcing on 11 December 2024.
Enforced by Monetary Authority of Singapore
How this country controls where data goes: No restriction · Accepted routes: Standard contract clauses
What you have to do
- Extra vendor secrecy termsThe bank must tell the service provider in writing about the confidentiality duties. That includes the duties that apply under the law of the place where an overseas service is performed. A standard data protection agreement is not enough.
- Written vendor contractThe outsourcing agreement must let the bank terminate on reasonable notice and must require deletion or return of customer information on termination.
- Independent auditIndependent audits of material ongoing outsourced relevant services.
- Keep records of how you use dataBanks must submit an outsourcing register to the Monetary Authority of Singapore, using its template, from 11 December 2024.
- Secure the data
Sources
- Official sourceMonetary Authority of SingaporeNotice 658 Management of Outsourced Relevant Services for Banks
mas.gov.sg
Link checked 18 August 2026
- Official sourceMonetary Authority of SingaporeMAS Notice 658, full text, section E — effective dates
mas.gov.sg
“This Notice, other than paragraphs 7.1 and 12.8, takes effect on 11 December 2024.”
Link checked 18 August 2026
- Official sourceMonetary Authority of SingaporeNotice 634 Banking Secrecy — Conditions for Outsourcing [Cancelled], cancelled with effect from 11 December 2024
mas.gov.sg
Link checked 18 August 2026
Banking rules
Official name: MAS Notices on Technology Risk Management and Cyber Hygiene (FSM-N21 to FSM-N26 family) · Issued 9 May 2024 under the Financial Services and Markets Act 2022; the earlier Notices 644, 655, 644A, 655A, 1114 and 1118 were cancelled with effect from 10 May 2024 · Regulator directive
The fastest deadline in Singapore. A supervised financial institution has one hour from discovering a severe system or security incident to tell the central bank. It then has fourteen days to file a root cause report. Note the trap. The notice numbers everyone quotes were cancelled on 10 May 2024. They were replaced by a new family issued under the Financial Services and Markets Act.
Enforced by Monetary Authority of Singapore
How this country controls where data goes: No restriction
What you have to do
- Report cyber incidents — within 1 hourTell the Monetary Authority of Singapore as soon as possible, and no later than 1 hour after discovering a severe incident. Root cause and impact analysis report within 14 days.
- Secure the data
- Hold a security certificateCyber hygiene baseline: administrative account controls, patching, security standards, network perimeter defence, malware protection and multi-factor authentication.
What it costs if you get it wrong
- Loss of your licencePersistent non-compliance with a binding MAS notice
Sources
- Official sourceMonetary Authority of SingaporeMAS Notice FSM-N25, Notice on Technology Risk Management, issued 9 May 2024
mas.gov.sg
“A trust company must submit a root cause and impact analysis report to the Authority, within 14 days or such longer period as the Authority may allow, from the discovery of the relevant incident.”
Link checked 18 August 2026
- Official sourceMonetary Authority of SingaporeNotice FSM-N25 Technology Risk Management
mas.gov.sg
Link checked 18 August 2026
- Official sourceMonetary Authority of SingaporeNotice 644 Technology Risk Management [Cancelled]
mas.gov.sg
Link checked 18 August 2026
Cyber security rules (Inserted by the Cybersecurity (Amendment) Act 2024 (Act 19 of 2024))
Official name: Cybersecurity Act 2018, Parts 3C and 3D — entities of special cybersecurity interest and major foundational digital infrastructure service providers · Inserted by the Cybersecurity (Amendment) Act 2024 (Act 19 of 2024) · Act of parliament
The power that would put cloud providers and data centres under Singapore's cyber regulator. The definitions, and the clauses saying who these Parts apply to, have been in force since 31 October 2025. But the Parts themselves have never been started, and section 18 currently reads as deleted. A single commencement notification would turn this on. It would reach a provider based entirely outside Singapore that serves Singapore users.
Enforced by Cyber Security Agency of Singapore
How this country controls where data goes: No restriction
What you have to do
- Report cyber incidentsNot yet in force. Would apply to designated cloud service providers and data centre operators, including those serving Singapore from wholly outside Singapore.
- Hold a security certificateNot yet in force. Compliance with codes of practice and standards of performance.
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Cybersecurity Act 2018, section 3(2E) to (2H) and section 2 definitions, in force from 31 October 2025; section 18 shown as deleted and Parts 3C and 3D absent from the in-force text
sso.agc.gov.sg
“Part 3D (except section 18H) applies to any major foundational digital infrastructure service provider that — (i) provides the foundational digital infrastructure service, whether from within or outside Singapore, to persons in Singapore within the meaning of section 18G”
Link checked 18 August 2026
- Official sourceCyber Security Agency of SingaporeCybersecurity Act — the agency's own description of the Foundational Digital Infrastructure category
csa.gov.sg
Link checked 18 August 2026
Health data rules
Official name: Health Information Act 2026 · Act No. 1 of 2026; passed 12 January 2026, assented 3 February 2026, published 12 February 2026 · Act of parliament
Singapore's new health data law. It forces healthcare providers to feed patient records into a national electronic records system. It adds health-specific security duties. It creates its own breach and cyber incident deadlines, separate from the general ones. It was passed in January 2026 and is still not in force. It contains no requirement to keep health data inside Singapore.
Enforced by Ministry of Health
How this country controls where data goes: No restriction
What you have to do
- Secure the dataNot yet in force. Reasonable controls and safeguards over health information.
- Delete data after a periodNot yet in force. Same purpose-based test as the general privacy law.
- Report breaches to the regulatorNot yet in force. Deadline to be prescribed by regulations that do not yet exist.
- Report cyber incidentsNot yet in force. A separate cybersecurity incident notification duty, deadline to be prescribed.
- Let people take their data elsewhereNot yet in force. Portability of health information in electronic form.
- Keep records of how you use dataNot yet in force. Mandatory contribution of health information to the national electronic records system by specified contributors.
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Health Information Act 2026 (Act No. 1 of 2026), Acts Supplement, sections 66, 67, 74 to 81 and 86 to 88
sso.agc.gov.sg
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Uncommenced Acts listing, 18 August 2026 — Health Information Act 2026 shown as uncommenced
sso.agc.gov.sg
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Healthcare Services Act 2020, section 27 — record-keeping duties for licensed healthcare providers, with no residency requirement
sso.agc.gov.sg
Link checked 18 August 2026
Government data rules (Government)
Official name: Public Sector (Governance) Act 2018 · Act 5 of 2018, 2020 Revised Edition; consolidated version in force from 1 August 2026 · Act of parliament
Government data sits outside the general privacy law and under its own rules. Public agencies share information under data sharing directions rather than consent. The people who handle it face personal criminal liability, up to two years in prison, for leaking it or for re-identifying anonymised records.
Enforced by Government Technology Agency
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Secure the data
- Allowed because the law requires itSharing between public sector agencies runs on data sharing directions rather than consent. The general privacy law does not apply to public agencies at all.
What it costs if you get it wrong
- Criminal liability: S$5,000 fine and/or 2 years' imprisonment — about $4 thousandUnauthorised disclosure or improper use of information under the control of a public sector agency (section 7)
- Criminal liability: S$5,000 fine and/or 2 years' imprisonment — about $4 thousandUnauthorised re-identification of anonymised public sector information (section 8)
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Public Sector (Governance) Act 2018, sections 7 and 8, consolidated text in force from 1 August 2026
sso.agc.gov.sg
“the individual shall be guilty of an offence and shall be liable on conviction to a fine not exceeding $5,000 or to imprisonment for a term not exceeding 2 years or to both.”
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Act 2012, section 4(1)(c) — the privacy obligations do not apply to public agencies
sso.agc.gov.sg
Link checked 18 August 2026
Cloud and outsourcing rules (Telecoms)
Official name: Digital Infrastructure Bill (draft) · Draft released for public consultation on 1 July 2026; consultation closed 22 July 2026 · Draft law
A draft law, not a law. It would licence the biggest data centres and cloud providers serving Singapore. It would require them to report outages as well as cyber incidents. It was prompted partly by a four-hour data centre outage in October 2023 that took down banking services. Public comment closed on 22 July 2026 and no bill has been introduced.
Enforced by Info-communications Media Development Authority
How this country controls where data goes: No restriction
What you have to do
- Register or notifyProposal only. A licence from the media and telecoms regulator would be needed for two things. Data centre facility services in data centres with a critical information technology load of 10 megawatts or more. And cloud infrastructure and platform services earning at least 100 million Singapore dollars a year from Singapore users. Software-as-a-service is excluded.
- Report cyber incidentsProposal only. Notification of cybersecurity incidents and service delivery disruptions.
- Secure the dataProposal only. Physical security, cybersecurity, business continuity and disaster recovery.
Sources
- Official sourceMinistry of Digital Development and InformationPublic Consultation on Digital Infrastructure Bill, 1 July 2026
mddi.gov.sg
“A Cloud Computing Service that has generated revenue from users in Singapore of ≥ S$100 million per year on average over the 3 preceding years, and falls within the categories of Infrastructure-as-a-Service (IaaS) or Platform-as-a-Service (PaaS) but not Software-as-a-Service (SaaS).”
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and InformationNew Digital Infrastructure Act to enhance resilience and security of digital infrastructure and services, 1 March 2024
mddi.gov.sg
Link checked 18 August 2026
Applies to every company6 rules
These bind you whatever business you are in, once the country's rules reach you.
Breach reporting rules
Official name: Personal Data Protection Act 2012 · Act 26 of 2012, 2020 Revised Edition; consolidated version in force from 5 December 2025 · Act of parliament
Singapore's general privacy law. It reaches foreign companies with no local presence. It requires you to name a responsible person and publish their contact details. It lets data leave the country, provided the recipient is legally bound to comparable protection. Breach notification has been live since 1 February 2021. The turnover-based penalty maximum has applied since 1 October 2022. One whole Part, on data portability, is printed in the statute but has never been switched on.
Enforced by Personal Data Protection Commission
How this country controls where data goes: No restriction · Accepted routes: Standard contract clauses, Approved group rules, Certification scheme, Explicit consent
What you have to do
- Get consent
- Tell people what you do
- Let people see their data
- Let people correct their data
- Secure the data
- Delete data after a periodNo fixed period. Stop retaining once the purpose is served and there is no legal or business reason to keep it.
- Put a transfer safeguard in placeThe recipient must be under legally enforceable duties that give comparable protection.
- Appoint a data protection officerAt least one named individual, with contact details published. No requirement to be based in Singapore.
- Report breaches to the regulator — applies at: Significant harm, or 500 or more affected individuals, within 72 hours, from 1 February 2021
- Tell affected people — from 1 February 2021
- Written vendor contractA written contract is what relieves a supplier of most duties. Without one, the supplier carries the full set.
- Let people take their data elsewherePart 6B. Enacted in 2020, never commenced. Not enforceable on 18 August 2026.
What it costs if you get it wrong
- Percentage of global turnover: 10% of annual turnover in SingaporeContravention by an organisation whose annual turnover in Singapore exceeds S$10 million, on or after 1 October 2022
- Fixed maximum fine: S$1,000,000 — about $780 thousandContravention by any other organisation
- Criminal liability: S$5,000 fine and/or 2 years' imprisonment — about $4 thousandUnauthorised disclosure, improper use, or re-identification by an individual (sections 48D to 48F)
- Claims by individualsRight of private action for a person who suffers loss or damage (section 48O)
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Act 2012, consolidated text in force from 5 December 2025
sso.agc.gov.sg
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection (Notification of Data Breaches) Regulations 2021
sso.agc.gov.sg
Link checked 18 August 2026
Government data rules
Official name: Personal Data Protection Regulations 2021, Part 3 · S 63/2021, as amended by S 86/2026; consolidated version in force from 2 March 2026 · Directly binding regulation
The mechanics of sending personal data out of Singapore. There is no destination list of any kind and no government approval. You need one of four things. A contract. Group-wide binding rules, for related companies. A recognised privacy certification. Or valid consent, given after you hand the person a written summary of how well the destination protects the data.
Enforced by Personal Data Protection Commission
How this country controls where data goes: No restriction · Accepted routes: Standard contract clauses, Approved group rules, Certification scheme, Explicit consent
What you have to do
- Put a transfer safeguard in placeA contract must both require comparable protection AND name the countries the data may go to. Singapore publishes no template; you draft your own.
- Written vendor contract
- Hold a security certificate — from 2 March 2026Global Cross-Border Privacy Rules and Global Privacy Recognition for Processors certifications became a recognised route on 2 March 2026, alongside the two APEC schemes.
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Regulations 2021 (S 63/2021), Part 3, regulations 10 to 12, in force from 2 March 2026
sso.agc.gov.sg
Link checked 18 August 2026
General data protection law
Official name: Personal Data Protection Act 2012, Part 6B (Data Portability Obligation) · Inserted by the Personal Data Protection (Amendment) Act 2020 (Act 40 of 2020) · Act of parliament
Singapore's data portability right. Parliament passed it in 2020, and the rest of the Act refers to it repeatedly. But the Part has never been started. So on 18 August 2026 nobody can demand their data be moved to a competitor. It can be switched on by a commencement notification, without further debate.
Enforced by Personal Data Protection Commission
How this country controls where data goes: No restriction
What you have to do
- Let people take their data elsewhereNot in force. No commencement date announced as at 18 August 2026.
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Act 2012 — Part 6B is referenced in sections 4(1), 4(2), 4(6), 48I and 48J but does not appear in the arrangement of sections or the body of the in-force text
sso.agc.gov.sg
Link checked 18 August 2026
Cyber security rules
Official name: Cybersecurity Act 2018 · Act 9 of 2018, 2020 Revised Edition, as amended by the Cybersecurity (Amendment) Act 2024 (Act 19 of 2024); consolidated version in force from 31 October 2025 · Act of parliament
Singapore's cyber law for systems that keep the country running. It covers energy, water, banking, healthcare, transport, infocomm, media, security services and government. Two hours to report an incident. The 2024 amendments started on 31 October 2025. But the Parts that would regulate cloud providers and data centres are still switched off.
Enforced by Cyber Security Agency of Singapore
How this country controls where data goes: No restriction
What you have to do
- Report cyber incidents — within 2 hours, from 31 October 20252 hours by phone, then supplementary details within 72 hours. Since 31 October 2025 the duty also covers incidents on a supplier's interconnected systems.
- Independent audit — 2 yearsIndependent audit at least every two years by an auditor approved by the Commissioner; report to the Commissioner within 30 days.
- Assess high-risk projects — 1 yearAnnual cybersecurity risk assessment in the prescribed form.
- Secure the dataYou must comply with the Cybersecurity Code of Practice for Critical Information Infrastructure 2026, issued 29 July 2026. The staged compliance dates are 29 July 2027 and 31 December 2027.
- Register or notifyNot yet in force. The licensing and duties for cloud providers and data centres sit in Parts 3C and 3D, which have not been started.
What it costs if you get it wrong
- Criminal liability: S$100,000 fine and/or 2 years' imprisonment — about $78 thousandFailure without reasonable excuse to report a cybersecurity incident (section 14(3))
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Cybersecurity Act 2018, sections 3, 14 and 15, consolidated text in force from 31 October 2025
sso.agc.gov.sg
“Any owner of a provider-owned critical information infrastructure who, without reasonable excuse, fails to comply with subsection (1) shall be guilty of an offence and shall be liable on conviction to a fine not exceeding $100,000 or to imprisonment for a term not exceeding 2 years or to both.”
Link checked 18 August 2026
- Official sourceCyber Security Agency of SingaporeForms — 2-hour and 72-hour incident reporting
csa.gov.sg
Link checked 18 August 2026
- Official sourceCyber Security Agency of SingaporeCybersecurity Code of Practice for Critical Information Infrastructure 2026, effective 29 July 2026
isomer-user-content.by.gov.sg
Link checked 18 August 2026
- Official sourceCyber Security Agency of SingaporeCybersecurity Act — agency overview page, last updated 16 July 2026
csa.gov.sg
Link checked 18 August 2026
Personal data needs a copy kept in the country
Official name: Companies Act 1967, section 199 · 1967 Act, 2020 Revised Edition; consolidated version in force from 6 May 2026 · Act of parliament
The one real keep-a-copy-here rule we found in Singapore. It is about company books rather than personal data. Accounting records may be held overseas. But enough must be copied back into Singapore to let the directors produce the accounts. Everything must be kept for at least five years.
Enforced by Accounting and Corporate Regulatory Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep data for a minimum period — 5 yearsFive years from the end of the financial year to which the transactions relate.
- Keep the data in the countryOnly a copy has to stay, not the whole thing. The full accounting records may sit abroad. But statements and returns good enough to prepare true and fair financial statements must be sent to and kept in Singapore. They must be open to inspection by the directors at all times.
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Companies Act 1967, section 199(1) to (4)
sso.agc.gov.sg
“The company must retain the records referred to in subsection (1) for a period of not less than 5 years from the end of the financial year in which the transactions or operations to which those records relate are completed.”
Link checked 18 August 2026
- Official sourceInland Revenue Authority of SingaporeRecord Keeping Requirements — the tax authority's five-year rule and the penalties for non-compliance
iras.gov.sg
Link checked 18 August 2026
Payment data rules
Official name: Advisory Guidelines on the Personal Data Protection Act for NRIC and other National Identification Numbers · Announced 2 February 2026; compliance deadline 31 December 2026 · Regulator guideline
Singapore is ending a habit that is everywhere in its economy: using the national identity card number to prove who you are. The regulator announced on 2 February 2026 that organisations must stop using these numbers to check identity by 31 December 2026. It said it will step up enforcement against misuse.
It is already law, so plan for it — but nobody can be penalised under it until 31 December 2026. A contract you sign may still hold you to it sooner.
Enforced by Personal Data Protection Commission
How this country controls where data goes: No restriction
What you have to do
- Secure the data — from 31 December 2026Stop using national identity card numbers to check identity. That means as a password, as a default PIN, or as proof that someone is who they say they are.
Sources
- Official sourcePersonal Data Protection CommissionOrganisations to cease the use of NRIC numbers for authentication by 31 December 2026, published 2 February 2026
pdpc.gov.sg
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionPDPC to step up enforcement action against misuse of NRIC numbers and issues new advisory on data protection, 2 February 2026
pdpc.gov.sg
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionAdvisory Guidelines on the PDPA for NRIC and other National Identification Numbers
pdpc.gov.sg
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Whether Singapore government procurement rules (Instruction Manual 8) impose where data has to be stored or classification-based hosting conditions on suppliers
We could not confirm what Instruction Manual 8 requires. It is not published as a public government document. If you supply Singapore public agencies, assume your contract sets hosting conditions and ask the agency. Do not rely on the absence of a rule in law. Checked 18 August 2026.
The exact age thresholds in the Advisory Guidelines on the PDPA for Children's Personal Data in the Digital Environment
We could not confirm the thresholds in these guidelines. The regulator's announcement page confirms they exist and were published on 27 March 2024. We could not read the body text of that page. If you handle children's data, read the guidelines yourself.
That MAS Notice FSM-N25's one-hour incident clock applies in identical terms across every class of supervised financial institution
We could not confirm that every class of licence carries the same deadline. We checked the one-hour and fourteen-day wording in the notice for licensed trust companies. We confirmed that matching notices FSM-N21, FSM-N22, FSM-N23, FSM-N24 and FSM-N26 exist for other classes, but we did not read each one. Treat one hour as your working assumption, and check it against your own licence.
That no localisation rule exists in the education, gaming, defence or mapping sectors
We found no rule requiring telecoms data to stay in Singapore. We searched the statute book and the relevant regulators and found nothing. The Telecommunications Act 1999, in force from 1 October 2025, says nothing about keeping anything inside Singapore. Checked 18 August 2026, with medium confidence.
The exact commencement date of the Health Information Act 2026
We could not confirm when this Act will start. The official statute site listed it as uncommenced on 18 August 2026, and we found no commencement notification. If you handle Singapore health records, check again each month.
Whether the Cybersecurity Act Parts 3C and 3D will be commenced before or alongside the Digital Infrastructure Bill
We could not confirm the order in which these changes will happen. The consultation paper says the Bill would change the Cybersecurity Act 2018 and the Cybersecurity (Amendment) Act 2024 to line up the definitions. No start date has been announced.
Precise current PDPA financial penalty levels actually imposed in 2025 and 2026
We could not confirm the actual fine amounts imposed in 2025 and 2026. We could not read the individual decision texts on the regulator's site. We can show that decisions are published regularly, but not what the penalties were. Read the decisions yourself if the amounts matter to you.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.