Skip to the content
Global Data RulesData governance rules, country by country

Singapore

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Yes, with paperworkWork: MediumEnforcement: Active

Singapore lets personal data leave the country, and we found no industry that is forced to keep data on Singaporean soil. What you must do instead is make the person receiving the data legally bound to protect it as well as Singapore law does. There is no government list of approved or banned countries and no permission to apply for. The privacy regulator is real, staffed, and publishes decisions.

Eight questions about Singapore

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Singapore's rules apply to my company?

Yes. The privacy law reaches a company that has never set foot in Singapore. It defines an organisation as any body of persons whether or not formed under Singapore law and whether or not it has an office here. There is no revenue or headcount threshold to fall below, and no in-country agent to appoint. You must name at least one person responsible for compliance and publish their contact details, but that person may sit anywhere in the world.

High confidenceNational rulesAppoint a data protection officerControllerProcessor

Can I store my users' data outside Singapore?

Yes, it can leave, and this is the unusual part: we searched banking, payments, insurance, securities, health, telecoms, government, education, gaming, mapping and defence and found no rule anywhere that forces personal data to stay in Singapore. What the law asks for is protection, not location. Before data goes abroad you must make sure the recipient is under a legal duty to protect it to a standard comparable to Singapore's.

High confidenceYes, with paperworkNo restrictionPut a transfer safeguard in place

What do I need in place before data leaves Singapore?

There is no list of approved countries, no list of banned countries, and no form to file. You need one thing: the recipient must be under a legally enforceable duty to protect the data to a comparable standard. Most companies do this with a contract they draft themselves, because Singapore does not publish a template. Group companies can use internal group-wide rules instead, and since 2 March 2026 a recipient holding a Global Cross-Border Privacy Rules certificate also counts.

High confidenceNo restrictionStandard contract clausesApproved group rulesCertification schemeExplicit consent

Who enforces the rules in Singapore, and what can they do?

The Personal Data Protection Commission, which is the same body as the media and telecoms regulator wearing a different hat. It is genuinely working: it publishes batches of decisions and settlements several times a year, with the most recent batches in 2026. Financial firms answer to the central bank as well, and anyone running critical national systems answers to the Cyber Security Agency. All three are staffed and issuing instruments.

High confidenceActiveRegulator

How long do I have to keep the data?

Both directions apply. The ceiling: you must stop keeping personal data once the purpose is finished and there is no legal or business reason to hold it, and there is no fixed number of days attached to that. The floor: company accounting records must be kept for at least five years, tax records for at least five years from the relevant year of assessment, and employment records for the latest two years, kept one year past the date an employee leaves.

High confidenceDelete data after a periodKeep data for a minimum periodKeep the data in the country

What happens if there is a breach?

There are at least three separate clocks and they run at very different speeds. Privacy: once you have decided a breach is serious enough to report, you have three calendar days to tell the regulator. Finance: a bank or other supervised firm has ONE HOUR to tell the central bank about a severe incident, then fourteen days for a root cause report. Critical national systems: TWO HOURS by phone to the national cyber agency, then a fuller report within seventy-two hours.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Singapore?

Five things that are not in the summary. One: an individual employee can go to prison for two years for leaking personal data, and that is separate from any fine on the company. Two: any other Singapore law beats the privacy law, so banking secrecy and similar duties override it. Three: every organisation must stop using national identity card numbers as passwords by 31 December 2026. Four: the data portability right is printed in the Act but has never been switched on. Five: the banking outsourcing rulebook everyone cites was cancelled in December 2024.

High confidenceCriminal liabilityPassed, not yet fully in forceLet people take their data elsewhereExtra vendor secrecy terms

What is changing soon in Singapore?

Three real things are in flight. A new health law has been passed but not started, and it will add its own breach reporting clocks for anyone handling health records. A draft law for big data centres and big cloud providers went out for public comment on 1 July 2026 and closed on 22 July 2026; it is not law yet. And every organisation must stop using national identity numbers as passwords by 31 December 2026. Separately, watch two switches the government can flip with no consultation at all.

High confidenceProposedPassed, not yet fully in forcePartly in force

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    6 rules here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    6 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules6 rules

Personal Data Protection Act 2012

Act of parliament · Act 26 of 2012, 2020 Revised Edition; consolidated version in force from 5 December 2025

Partly in forceYes, with paperwork

Singapore's general privacy law. Reaches foreign companies with no local presence, requires a named responsible person whose contact details are public, and permits data to leave the country provided the recipient is legally bound to comparable protection. Breach notification has been live since 1 February 2021 and the turnover-based penalty ceiling since 1 October 2022. One whole Part — data portability — is printed in the statute but has never been switched on.

In force since 2 July 2014

Enforced by Personal Data Protection Commission

Transfer model: No restriction · Accepted routes: Standard contract clauses, Approved group rules, Certification scheme, Explicit consent

High confidence

Personal Data Protection Regulations 2021, Part 3

Directly binding regulation · S 63/2021, as amended by S 86/2026; consolidated version in force from 2 March 2026

In forceYes, with paperwork

The mechanics of sending personal data out of Singapore. There is no destination list of any kind and no government approval. You need a contract, group-wide binding rules for related companies, a recognised privacy certification, or valid consent preceded by a written summary of how well the destination protects the data.

In force since 1 February 2021

Enforced by Personal Data Protection Commission

Transfer model: No restriction · Accepted routes: Standard contract clauses, Approved group rules, Certification scheme, Explicit consent

High confidence

Personal Data Protection Act 2012, Part 6B (Data Portability Obligation)

Act of parliament · Inserted by the Personal Data Protection (Amendment) Act 2020 (Act 40 of 2020)

Passed, not yet fully in forceYes — store it anywhere

Singapore's data portability right. Parliament passed it in 2020 and the rest of the Act refers to it repeatedly, but the Part has never been commenced, so on 18 August 2026 nobody can demand their data be moved to a competitor. It can be switched on by a commencement notification without further debate.

Enforced by Personal Data Protection Commission

Transfer model: No restriction

High confidence

Industry rules6 rules

MAS Notice 658 — Management of Outsourced Relevant Services

Regulator directive · Issued 11 December 2023 under sections 47A(2), (4), (6), (7) and (12) of the Banking Act 1970. Notice 1121 is the merchant bank equivalent. · Banking

In forceYes, with paperwork

The rulebook a Singapore bank must follow before customer information reaches any outside supplier. It expressly allows the service to be performed overseas, so it is not a localisation rule, but it demands written secrecy notification, deletion on exit, independent audits and a register filed with the central bank. It replaced Notice 634 and the old Guidelines on Outsourcing on 11 December 2024.

In force since 11 December 2024

Enforced by Monetary Authority of Singapore

Transfer model: No restriction · Accepted routes: Standard contract clauses

High confidence

MAS Notices on Technology Risk Management and Cyber Hygiene (FSM-N21 to FSM-N26 family)

Regulator directive · Issued 9 May 2024 under the Financial Services and Markets Act 2022; the earlier Notices 644, 655, 644A, 655A, 1114 and 1118 were cancelled with effect from 10 May 2024 · Finance

In forceYes — store it anywhere

The fastest clock in Singapore. A supervised financial institution has one hour from discovering a severe system or security incident to tell the central bank, and fourteen days to file a root cause report. Note the trap: the notice numbers everyone quotes were cancelled on 10 May 2024 and replaced by a new family issued under the Financial Services and Markets Act.

In force since 10 May 2024

Enforced by Monetary Authority of Singapore

Transfer model: No restriction

High confidence

Cybersecurity Act 2018, Parts 3C and 3D — entities of special cybersecurity interest and major foundational digital infrastructure service providers

Act of parliament · Inserted by the Cybersecurity (Amendment) Act 2024 (Act 19 of 2024)

Passed, not yet fully in forceYes, with paperwork

The switch that would put cloud providers and data centres under Singapore's cyber regulator. The definitions and the clauses saying who these Parts apply to are already in force, as of 31 October 2025, but the Parts themselves have never been commenced and section 18 currently reads as deleted. A single commencement notification would turn this on, and it would reach a provider based entirely outside Singapore that serves Singapore users.

Enforced by Cyber Security Agency of Singapore

Transfer model: No restriction

High confidence

Who you would hear from

  • The general privacy law, the Do Not Call registry, and data breach notification

    Fully operational. Legally the same body as the media and telecoms regulator, which is designated as the Commission by section 5 of the Act. Publishes decisions and voluntary undertakings in batches several times a year; batches dated 8 January 2026, 26 February 2026 and 9 April 2026 are on its own site. Announced on 2 February 2026 that it would step up enforcement on misuse of national identity numbers.

  • IMDA

    Telecoms and media regulation; also the legal identity of the privacy Commission; proposed licensor for data centres and cloud under the draft Digital Infrastructure Bill

  • Banking, payments, insurance, capital markets, trust companies

    Highly active. Replaced its entire outsourcing rulebook with effect from 11 December 2024 and its technology risk and cyber hygiene notices with effect from 10 May 2024. Currently consulting on new third-party risk management guidelines.

  • Commissioner of Cybersecurity

    Critical information infrastructure, systems of temporary cybersecurity concern, cybersecurity service provider licensing

    Operational. Issued a new Cybersecurity Code of Practice for Critical Information Infrastructure on 29 July 2026. Does not yet regulate cloud providers or data centres because the relevant Parts of the Act are uncommenced.

  • Policy and legislation for digital, data and online safety

  • Licensed healthcare services and, once commenced, the national health information regime

    Operational for healthcare licensing. The Health Information Act 2026 regime it will administer is not yet in force.

  • Company accounting records and retention under the Companies Act

  • Tax record retention

  • Employment records retention

  • Government systems and public sector data handling

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • Whether Singapore government procurement rules (Instruction Manual 8) impose data residency or classification-based hosting conditions on suppliers

    Instruction Manual 8 is not published as a public government document and we could not open an official text. Suppliers to Singapore public agencies should assume contractual hosting conditions exist and ask the agency, rather than relying on the absence of a statutory rule. Checked 18 August 2026.

  • The exact age thresholds in the Advisory Guidelines on the PDPA for Children's Personal Data in the Digital Environment

    The regulator's announcement page confirms the guidelines exist and were published on 27 March 2024, but the page renders its body text with JavaScript and we could not extract the thresholds from an official source in this run.

  • That MAS Notice FSM-N25's one-hour incident clock applies in identical terms across every class of supervised financial institution

    We verified the one-hour and fourteen-day wording in the notice applying to licensed trust companies, and confirmed that parallel notices FSM-N21, FSM-N22, FSM-N23, FSM-N24 and FSM-N26 exist for other classes, but we did not open each one. Treat one hour as the working assumption and confirm against your own class of licence.

  • That no localisation rule exists in the education, gaming, defence or mapping sectors

    This is a negative. We searched the statute book and the relevant regulators and found nothing, and the Telecommunications Act 1999 in force from 1 October 2025 contains no reference to keeping anything inside Singapore. No rule found, checked 18 August 2026, confidence medium.

  • The exact commencement date of the Health Information Act 2026

    The Act is listed as uncommenced on the official statute site as at 18 August 2026 and no commencement notification was located. Anyone handling Singapore health records should re-check monthly.

  • Whether the Cybersecurity Act Parts 3C and 3D will be commenced before or alongside the Digital Infrastructure Bill

    The consultation paper says the Bill would make related amendments to the Cybersecurity Act 2018 and the Cybersecurity (Amendment) Act 2024 to align the definitions, which suggests sequencing is still open. No commencement date has been announced.

  • Precise current PDPA financial penalty levels actually imposed in 2025 and 2026

    The regulator's decisions list is rendered with JavaScript and individual decision texts could not be extracted in this run. We can evidence that decisions are being published regularly, but not the amounts.

30-day cadence. Three separate instruments are mid-commencement (the Health Information Act 2026, Cybersecurity Act Parts 3C and 3D, and PDPA Part 6B), a bill is between consultation and introduction, and a hard compliance deadline falls on 31 December 2026. Any of the commencements can happen by notification with no consultation, so a longer interval risks this record asserting that cloud providers are unregulated after that has ceased to be true.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.