Singapore
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Singapore lets personal data leave the country, and we found no industry that is forced to keep data on Singaporean soil. What you must do instead is make the person receiving the data legally bound to protect it as well as Singapore law does. There is no government list of approved or banned countries and no permission to apply for. The privacy regulator is real, staffed, and publishes decisions.
Eight questions about Singapore
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Singapore's rules apply to my company?
Yes. The privacy law reaches a company that has never set foot in Singapore. It defines an organisation as any body of persons whether or not formed under Singapore law and whether or not it has an office here. There is no revenue or headcount threshold to fall below, and no in-country agent to appoint. You must name at least one person responsible for compliance and publish their contact details, but that person may sit anywhere in the world.
Section 2 defines 'organisation' to include any individual, company, association or body of persons, corporate or unincorporated, whether or not (a) formed or recognised under the law of Singapore, or (b) resident, or having an office or a place of business, in Singapore. Section 11(3) requires designation of one or more individuals responsible for compliance (in practice called the Data Protection Officer) and section 11(5) requires their business contact information to be made public; neither provision imposes a residence requirement. Carve-outs in section 4: individuals acting personally or domestically, employees acting in the course of employment, public agencies (which are covered instead by the Public Sector (Governance) Act 2018), business contact information, records over 100 years old, and individuals dead more than 10 years. Data intermediaries acting under a written contract are relieved of most obligations but not of the security and retention duties.
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Act 2012, section 2 (definition of 'organisation'), consolidated text in force from 5 December 2025
sso.agc.gov.sg
““organisation” includes any individual, company, association or body of persons, corporate or unincorporated, whether or not — (a) formed or recognised under the law of Singapore; or (b) resident, or having an office or a place of business, in Singapore”
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Act 2012, sections 4 and 11 (application of the Act; designation and publication of a responsible individual)
sso.agc.gov.sg
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Public Sector (Governance) Act 2018, sections 7 and 8 — the separate regime that covers public agencies
sso.agc.gov.sg
Link checked 18 August 2026
Can I store my users' data outside Singapore?
Yes, it can leave, and this is the unusual part: we searched banking, payments, insurance, securities, health, telecoms, government, education, gaming, mapping and defence and found no rule anywhere that forces personal data to stay in Singapore. What the law asks for is protection, not location. Before data goes abroad you must make sure the recipient is under a legal duty to protect it to a standard comparable to Singapore's.
Section 26(1) of the Personal Data Protection Act 2012 prohibits transfer 'except in accordance with requirements prescribed under this Act to ensure that organisations provide a standard of protection to personal data so transferred that is comparable to the protection under this Act'. The prescribed requirements sit in Part 3 of the Personal Data Protection Regulations 2021. There is no country list of any kind, populated or empty. Sector-by-sector position on 18 August 2026, each rated separately: - Banking and merchant banking (conditional): MAS Notice 658 and Notice 1121 govern outsourced services involving customer information. They expressly contemplate services performed overseas and set conditions rather than a ban. Note the trap: the previous rulebook (Notice 634 and the Guidelines on Outsourcing) was cancelled on 11 December 2024. - Insurance, capital markets, payments, trust companies (conditional): governed by the Guidelines on Outsourcing (Financial Institutions other than Banks), effective 11 December 2024. No localisation. - Health (conditional): the Healthcare Services Act 2020 requires records to be kept and secured but is silent on where. The Health Information Act 2026 has been passed but not commenced, and it too contains no residency requirement. - Telecoms (open): the Telecommunications Act 1999 as in force from 1 October 2025 contains no reference to keeping anything inside Singapore. - Critical information infrastructure (mirror in practice, not in law): the Cybersecurity Act 2018 applies to systems located wholly or partly in Singapore and, since 31 October 2025, also to a system located wholly outside Singapore that is owned by a person in Singapore. It regulates security, not location. - Company accounting records (mirror): the Companies Act 1967 allows records to be kept abroad but requires statements and returns to be sent to and kept in Singapore. - Mapping, gaming, education, defence: no residency rule found, checked 18 August 2026, confidence medium.
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Act 2012, section 26 (transfer of personal data outside Singapore)
sso.agc.gov.sg
“An organisation must not transfer any personal data to a country or territory outside Singapore except in accordance with requirements prescribed under this Act to ensure that organisations provide a standard of protection to personal data so transferred that is comparable to the protection under this Act.”
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Regulations 2021 (S 63/2021), Part 3, regulations 10 to 12, consolidated text in force from 2 March 2026
sso.agc.gov.sg
Link checked 18 August 2026
- Official sourceMonetary Authority of SingaporeMAS Notice 658, Management of Outsourced Relevant Services — paragraphs 6, 8 and 10 expressly address services performed overseas
mas.gov.sg
“in the case where the material ongoing outsourced relevant service is to be performed outside Singapore, the bank’s obligations to protect customer information in accordance with the laws of the place where the material ongoing outsourced relevant service is to be performed”
Link checked 18 August 2026
- Official sourceMonetary Authority of SingaporeMAS Third-Party Risk Management — confirms Notice 658, Notice 1121 and the Guidelines on Outsourcing for non-banks all took effect 11 December 2024
mas.gov.sg
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Telecommunications Act 1999, consolidated text in force from 1 October 2025 — contains no data residency requirement
sso.agc.gov.sg
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Companies Act 1967, section 199(4) — records kept abroad must be mirrored by statements and returns kept in Singapore
sso.agc.gov.sg
Link checked 18 August 2026
What do I need in place before data leaves Singapore?
There is no list of approved countries, no list of banned countries, and no form to file. You need one thing: the recipient must be under a legally enforceable duty to protect the data to a comparable standard. Most companies do this with a contract they draft themselves, because Singapore does not publish a template. Group companies can use internal group-wide rules instead, and since 2 March 2026 a recipient holding a Global Cross-Border Privacy Rules certificate also counts.
Regulation 10(1) of the Personal Data Protection Regulations 2021 requires the transferring organisation to take appropriate steps to ascertain and ensure that the recipient is bound by legally enforceable obligations. Regulation 11 lists what counts: any law, a contract, binding corporate rules, or any other legally binding instrument. A qualifying contract must (a) require comparable protection and (b) specify the countries and territories to which the data may be transferred. Binding corporate rules may only be used between related entities and must specify the recipients, the destinations and the rights and obligations created. Regulation 12 treats a recipient as compliant if it holds a specified certification. As amended by S 86/2026 with effect from 2 March 2026 this now covers four schemes for data intermediaries — the APEC Privacy Recognition for Processors System, the APEC Cross-Border Privacy Rules System, the Global Privacy Recognition for Processors System and the Global Cross-Border Privacy Rules System — and the two Cross-Border Privacy Rules systems for everyone else. Regulation 10(2) sets out situations where the requirement is deemed satisfied: the individual consents (but consent is invalid unless they were first given a written summary of the protection the destination offers, and it cannot be forced as a condition of a product unless genuinely necessary), deemed consent under section 15, transfer necessary for a use permitted without consent, data in transit, or data already publicly available in Singapore. The Commission may also exempt a named organisation from the transfer requirements under section 26(2). Such an exemption need not be published in the Gazette and can be revoked at any time.
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Regulations 2021, regulation 11 (legally enforceable obligations)
sso.agc.gov.sg
“legally enforceable obligations include obligations imposed on a recipient of personal data under — (a) any law; (b) any contract in accordance with paragraph (2); (c) any binding corporate rules in accordance with paragraph (3); or (d) any other legally binding instrument.”
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Regulations 2021, regulation 12 (recipients holding specified certifications), as amended by S 86/2026 with effect from 2 March 2026
sso.agc.gov.sg
“(iii) the Global Privacy Recognition for Processors System; or (iv) the Global Cross-Border Privacy Rules System”
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Act 2012, section 26(2) to (4) — the Commission's power to exempt a named organisation, unpublished and revocable at any time
sso.agc.gov.sg
Link checked 18 August 2026
Who enforces the rules in Singapore, and what can they do?
The Personal Data Protection Commission, which is the same body as the media and telecoms regulator wearing a different hat. It is genuinely working: it publishes batches of decisions and settlements several times a year, with the most recent batches in 2026. Financial firms answer to the central bank as well, and anyone running critical national systems answers to the Cyber Security Agency. All three are staffed and issuing instruments.
Section 5 of the Personal Data Protection Act 2012 designates the Info-communications Media Development Authority as the Personal Data Protection Commission, so the Commission is not a separate legal body. Evidence that it is operational rather than nominal: published decision and undertaking batches dated 3 July 2025, 31 July 2025, 7 August 2025, 3 September 2025, 2 October 2025, 28 October 2025, 4 December 2025, 8 January 2026, 26 February 2026 and 9 April 2026, all listed on its own site, plus a press release on 2 February 2026 announcing it will step up enforcement on misuse of national identity numbers. The Commission may issue directions under section 48I and financial penalties under section 48J. The ceiling is 10 per cent of annual turnover in Singapore for an organisation whose Singapore turnover exceeds 10 million Singapore dollars (about 7.8 million US dollars), and 1 million Singapore dollars (about 780,000 US dollars) otherwise. That ceiling has applied since 1 October 2022. Individuals also have a direct right of action under section 48O. The Monetary Authority of Singapore replaced its entire outsourcing rulebook on 11 December 2024 and its technology risk and cyber hygiene notices on 10 May 2024 — evidence of active, not dormant, supervision. The Commissioner of Cybersecurity issued a new Cybersecurity Code of Practice for Critical Information Infrastructure on 29 July 2026.
Sources
- Official sourcePersonal Data Protection CommissionEnforcement Decisions — the Commission's own published decisions and voluntary undertakings
pdpc.gov.sg
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionPDPC to step up enforcement action against misuse of NRIC numbers, published 2 February 2026
pdpc.gov.sg
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Act 2012, sections 5, 48I, 48J and 48O
sso.agc.gov.sg
“in the case of a contravention on or after the date of commencement of section 24 of the Personal Data Protection (Amendment) Act 2020 by an organisation whose annual turnover in Singapore exceeds $10 million — 10% of the annual turnover in Singapore of the organisation”
Link checked 18 August 2026
- Official sourceCyber Security Agency of SingaporeCodes of Practice — Cybersecurity Code of Practice for Critical Information Infrastructure 2026, issued 29 July 2026
csa.gov.sg
Link checked 18 August 2026
How long do I have to keep the data?
Both directions apply. The ceiling: you must stop keeping personal data once the purpose is finished and there is no legal or business reason to hold it, and there is no fixed number of days attached to that. The floor: company accounting records must be kept for at least five years, tax records for at least five years from the relevant year of assessment, and employment records for the latest two years, kept one year past the date an employee leaves.
Ceiling: section 25 of the Personal Data Protection Act 2012 requires an organisation to cease retaining documents containing personal data, or to strip the link to particular individuals, as soon as it is reasonable to assume that the purpose is no longer served and retention is no longer necessary for legal or business purposes. Floor: Companies Act 1967 section 199(2) sets five years from the end of the financial year. The tax authority applies five years from the relevant Year of Assessment under the Income Tax Act 1947 and the Goods and Services Tax Act 1993, with penalties of up to 5,000 Singapore dollars (about 3,900 US dollars) and up to six months' imprisonment in default. The Ministry of Manpower requires employment records for the latest two years for current employees, and the last two years kept for one year after the employee leaves. For a struck-off or wound-up company, an officer or the liquidator must keep the books for five years after dissolution. How the conflict resolves: it usually does not become a conflict, because section 25(b) itself permits retention that is still necessary for legal purposes. Where it does bite, section 4(6)(b) of the Act settles it — the provisions of other written law prevail to the extent of any inconsistency. Location interacts here too: Companies Act section 199(4) permits accounting records to be held abroad but requires statements and returns sufficient to prepare true and fair financial statements to be sent to and kept in Singapore.
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Act 2012, section 25 (retention of personal data) and section 4(6)(b)
sso.agc.gov.sg
“An organisation must cease to retain its documents containing personal data, or remove the means by which the personal data can be associated with particular individuals, as soon as it is reasonable to assume that — (a) the purpose for which that personal data was collected is no longer being served by retention of the personal data; and (b) retention is no longer necessary for legal or business purposes.”
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Companies Act 1967, section 199(2) and 199(4) — five-year retention, and mirrored statements for records kept abroad
sso.agc.gov.sg
“If accounting and other records are kept by the company at a place outside Singapore there must be sent to and kept at a place in Singapore and be at all times open to inspection by the directors such statements and returns with respect to the business dealt with in the records so kept as will enable to be prepared true and fair financial statements”
Link checked 18 August 2026
- Official sourceInland Revenue Authority of SingaporeRecord Keeping Requirements — at least five years from the relevant Year of Assessment
iras.gov.sg
“Your company must retain its records for at least 5 years from the relevant YA.”
Link checked 18 August 2026
- Official sourceMinistry of ManpowerEmployment records — how long employers must keep them
mom.gov.sg
“For current employees: Latest two years. For ex-employees: Last two years, to be kept for one year after the employee leaves employment.”
Link checked 18 August 2026
What happens if there is a breach?
There are at least three separate clocks and they run at very different speeds. Privacy: once you have decided a breach is serious enough to report, you have three calendar days to tell the regulator. Finance: a bank or other supervised firm has ONE HOUR to tell the central bank about a severe incident, then fourteen days for a root cause report. Critical national systems: TWO HOURS by phone to the national cyber agency, then a fuller report within seventy-two hours.
Privacy clock. Sections 26C and 26D of the Personal Data Protection Act 2012. On having reason to believe a breach occurred you must assess it 'in a reasonable and expeditious manner'; there is no fixed deadline for the assessment itself, and the three-day clock starts only when the assessment concludes the breach is notifiable. A breach is notifiable if it causes or is likely to cause significant harm, or is or is likely to be of significant scale. The Personal Data Protection (Notification of Data Breaches) Regulations 2021 fix the significant-scale threshold at 500 affected individuals. Affected individuals must be told on or after the regulator, in any reasonable manner, where the significant-harm limb is engaged. A breach confined inside one organisation is deemed not notifiable. A supplier processing data for you must tell you without undue delay; the assessment duty then falls on you. Finance clock. MAS Notice FSM-N25 requires notification 'as soon as possible, but not later than 1 hour, upon the discovery of a relevant incident', with a root cause and impact analysis report within 14 days. Parallel notices apply across other supervised classes. The old Notices 644, 655, 644A, 655A, 1114 and 1118 were cancelled with effect from 10 May 2024, so compliance manuals citing them are out of date. Cyber clock. Section 14 of the Cybersecurity Act 2018 requires notification within the prescribed period. The Cyber Security Agency states the period is 2 hours from awareness, by calling the number in the National Cybersecurity Incident Response Framework, with supplementary details within 72 hours. Since 31 October 2025 the duty also covers incidents on a supplier's interconnected systems. A fourth clock is coming for healthcare once the Health Information Act 2026 commences: separate notifiable cybersecurity incident and notifiable data breach duties, with the periods to be set by regulations that do not yet exist.
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Act 2012, sections 26B, 26C and 26D
sso.agc.gov.sg
“the organisation must notify the Commission as soon as is practicable, but in any case no later than 3 calendar days after the day the organisation makes that assessment.”
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection (Notification of Data Breaches) Regulations 2021 (S 64/2021), regulation 4
sso.agc.gov.sg
“For the purposes of section 26B(3)(a) of the Act, the prescribed number of affected individuals is 500.”
Link checked 18 August 2026
- Official sourceMonetary Authority of SingaporeMAS Notice FSM-N25, Notice on Technology Risk Management, issued 9 May 2024, paragraphs 7 and 8
mas.gov.sg
“A trust company must notify the Authority as soon as possible, but not later than 1 hour, upon the discovery of a relevant incident.”
Link checked 18 August 2026
- Official sourceCyber Security Agency of SingaporeForms — reporting of cybersecurity incidents in respect of critical information infrastructure
csa.gov.sg
“The owner of a provider-owned critical information infrastructure must notify the Commissioner of the occurrence of the cybersecurity incident within 2 hours from awareness of an incident”
Link checked 18 August 2026
- Official sourceMonetary Authority of SingaporeNotice 644 Technology Risk Management [Cancelled] — evidence the old MAS technology and cyber notices were withdrawn on 10 May 2024
mas.gov.sg
Link checked 18 August 2026
What trips people up in Singapore?
Five things that are not in the summary. One: an individual employee can go to prison for two years for leaking personal data, and that is separate from any fine on the company. Two: any other Singapore law beats the privacy law, so banking secrecy and similar duties override it. Three: every organisation must stop using national identity card numbers as passwords by 31 December 2026. Four: the data portability right is printed in the Act but has never been switched on. Five: the banking outsourcing rulebook everyone cites was cancelled in December 2024.
1. Criminal, not just administrative. Sections 48D, 48E and 48F of the Personal Data Protection Act 2012 make it an offence for an INDIVIDUAL to knowingly or recklessly disclose personal data without authorisation, to misuse it for gain or to cause harm, or to re-identify anonymised information. Maximum: a fine of 5,000 Singapore dollars (about 3,900 US dollars) or two years' imprisonment or both. It bites employees and contractor staff personally, including those handling government data. Sections 7 and 8 of the Public Sector (Governance) Act 2018 create mirror offences with the same maximum for people working inside public sector agencies. 2. Other law wins. Section 4(6)(b) states that the provisions of other written law prevail to the extent that the privacy obligations are inconsistent with them. So a permissive answer under the privacy law is worth nothing if a banking secrecy duty, a professional secrecy duty or a licence condition says otherwise. 3. The national identity number deadline. On 2 February 2026 the regulator announced that organisations must cease using NRIC numbers for authentication by 31 December 2026, and that it will step up enforcement. Using a national identity number as a password, a default PIN or a proof of identity is the exact pattern being targeted. 4. A dormant obligation inside the statute. Part 6B of the Act — the data portability obligation — was enacted by the Personal Data Protection (Amendment) Act 2020 and is referenced throughout the in-force text, in sections 4 and 48J among others, yet the Part itself has never been commenced. A naive reading of the Act will report a portability right that does not currently exist. It can be switched on by commencement notification. 5. Stale banking guidance. MAS Notice 634 on banking secrecy conditions for outsourcing was cancelled with effect from 11 December 2024, and the well-known Guidelines on Outsourcing dated 2016 and revised 2018 are also marked cancelled. They were replaced by Notice 658 for banks, Notice 1121 for merchant banks, and separate Guidelines on Outsourcing for banks and for non-banks, all effective 11 December 2024. 6. Bonus, for consumer products: the regulator issued separate Advisory Guidelines for children's personal data in the digital environment in March 2024. Treat children's data as a distinct workstream rather than assuming the general rules cover it.
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Act 2012, Part 9B, sections 48D to 48F (offences affecting personal data and anonymised information)
sso.agc.gov.sg
“the individual shall be guilty of an offence and shall be liable on conviction to a fine not exceeding $5,000 or to imprisonment for a term not exceeding 2 years or to both.”
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Act 2012, section 4(6)(b) and references to the uncommenced Part 6B in sections 4 and 48J
sso.agc.gov.sg
“the provisions of other written law prevail to the extent that any provision of Parts 3, 4, 5, 6, 6A and 6B is inconsistent with the provisions of that other written law.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionOrganisations to cease the use of NRIC numbers for authentication by 31 December 2026, published 2 February 2026
pdpc.gov.sg
Link checked 18 August 2026
- Official sourceMonetary Authority of SingaporeNotice 634 Banking Secrecy — Conditions for Outsourcing [Cancelled]
mas.gov.sg
“This Notice was cancelled with effect from 11 December 2024.”
Link checked 18 August 2026
- Official sourceMonetary Authority of SingaporeGuidelines on Outsourcing [Cancelled] — the 2016 guidelines revised 5 October 2018, now withdrawn
mas.gov.sg
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Public Sector (Governance) Act 2018, sections 7 and 8 — equivalent criminal offences for public sector data
sso.agc.gov.sg
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionAdvisory Guidelines on the PDPA for Children's Personal Data in the Digital Environment, published 27 March 2024
pdpc.gov.sg
Link checked 18 August 2026
What is changing soon in Singapore?
Three real things are in flight. A new health law has been passed but not started, and it will add its own breach reporting clocks for anyone handling health records. A draft law for big data centres and big cloud providers went out for public comment on 1 July 2026 and closed on 22 July 2026; it is not law yet. And every organisation must stop using national identity numbers as passwords by 31 December 2026. Separately, watch two switches the government can flip with no consultation at all.
Landing within twelve months, with dates: - 31 December 2026: deadline to stop using NRIC numbers for authentication, with the regulator having said in February 2026 that it will step up enforcement. - Health Information Act 2026 (Act No. 1 of 2026): passed by Parliament on 12 January 2026, assented to on 3 February 2026, published on 12 February 2026, and still listed as Uncommenced on 18 August 2026. It creates a national electronic records system with mandatory contribution, new data security and retention duties, separate cybersecurity incident and data breach notification duties with periods still to be prescribed, and a health data portability right. Commencement date not yet announced. - Digital Infrastructure Bill: a draft was published for public consultation on 1 July 2026, closing 22 July 2026. It would licence data centre facility services in data centres of 10 megawatts critical IT load or more, and cloud infrastructure and platform services earning 100 million Singapore dollars or more a year from users in Singapore (about 78 million US dollars). Software-as-a-service is excluded. It would also make related amendments to the Cybersecurity Act. It is a draft, not law. - MAS is consulting on new guidelines covering financial institutions' use of third-party services. DORMANT SWITCHES, which matter more than the pending bills because they need no consultation: 1. Cybersecurity Act Parts 3C and 3D. The Cybersecurity (Amendment) Act 2024 commenced on 31 October 2025. The definitions of 'entity of special cybersecurity interest' and 'major foundational digital infrastructure service provider', and the application clauses in section 3(2E) to (2H) that point at them, are all in force TODAY. The Parts that actually impose duties on those entities — including on cloud service providers and data centres — are not, and section 18 currently reads as deleted. A commencement notification alone would bring a cloud and data centre regime into force. Note it would reach a provider serving Singapore from wholly outside Singapore. 2. Personal Data Protection Act Part 6B, data portability: enacted in 2020, never commenced, switchable the same way. 3. Section 26(2) of the Personal Data Protection Act lets the Commission exempt a named organisation from the transfer rules by unpublished written notice, on conditions it can vary or revoke at any time. Not coming: on 5 May 2026 the Ministry of Digital Development and Information told Parliament it is relying on existing law and published guidelines for data derived by artificial intelligence, rather than amending the Act.
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Uncommenced Acts — lists the Health Information Act 2026 as uncommenced as at 18 August 2026
sso.agc.gov.sg
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Health Information Act 2026 (Act No. 1 of 2026), Acts Supplement
sso.agc.gov.sg
“The following Act was passed by Parliament on 12 January 2026 and assented to by the President on 3 February 2026”
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and InformationPublic Consultation on Digital Infrastructure Bill, 1 July 2026
mddi.gov.sg
“All submissions should reach MDDI and IMDA within 3 weeks, no later than 22 July 2026, 10am”
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Cybersecurity Act 2018, section 3(2E) to (2H) in force from 31 October 2025, with section 18 deleted and Parts 3C and 3D absent from the in-force text
sso.agc.gov.sg
Link checked 18 August 2026
- Official sourceCyber Security Agency of SingaporeCybersecurity Act — the agency's own description of Entities of Special Cybersecurity Interest and Foundational Digital Infrastructure
csa.gov.sg
“companies that provide digital infrastructure services that are foundational to our economy or way of life (such as cloud service providers and data centres) will be regulated as Foundational Digital Infrastructure (FDI)”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionOrganisations to cease the use of NRIC numbers for authentication by 31 December 2026
pdpc.gov.sg
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and InformationMDDI response to a parliamentary question on reviewing the PDPA for AI-derived data, 5 May 2026
mddi.gov.sg
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and InformationNew Digital Infrastructure Act to enhance resilience and security of digital infrastructure and services, 1 March 2024
mddi.gov.sg
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
6 rules here
Layer 2
Industry rules
Made by an industry regulator. These usually beat the general position.
6 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules6 rules
Personal Data Protection Act 2012
Act of parliament · Act 26 of 2012, 2020 Revised Edition; consolidated version in force from 5 December 2025
Singapore's general privacy law. Reaches foreign companies with no local presence, requires a named responsible person whose contact details are public, and permits data to leave the country provided the recipient is legally bound to comparable protection. Breach notification has been live since 1 February 2021 and the turnover-based penalty ceiling since 1 October 2022. One whole Part — data portability — is printed in the statute but has never been switched on.
Enforced by Personal Data Protection Commission
Transfer model: No restriction · Accepted routes: Standard contract clauses, Approved group rules, Certification scheme, Explicit consent
What it makes you do
- Get consent
- Tell people what you do
- Let people see their data
- Let people correct their data
- Secure the data
- Delete data after a periodNo fixed period. Stop retaining once the purpose is served and there is no legal or business reason to keep it.
- Put a transfer safeguard in placeRecipient must be under legally enforceable obligations providing comparable protection.
- Appoint a data protection officerAt least one named individual, with contact details published. No requirement to be based in Singapore.
- Report breaches to the regulator — applies at: Significant harm, or 500 or more affected individuals, within 72 hours, from 1 February 2021
- Tell affected people — from 1 February 2021
- Written vendor contractA written contract is what relieves a data intermediary of most obligations; without one the supplier carries the full set.
- Let people take their data elsewherePart 6B. Enacted in 2020, never commenced. Not enforceable on 18 August 2026.
What it costs if you get it wrong
- Percentage of global turnover: 10% of annual turnover in SingaporeContravention by an organisation whose annual turnover in Singapore exceeds S$10 million, on or after 1 October 2022
- Fixed maximum fine: S$1,000,000 — about $780 thousandContravention by any other organisation
- Criminal liability: S$5,000 fine and/or 2 years' imprisonment — about $4 thousandUnauthorised disclosure, improper use, or re-identification by an individual (sections 48D to 48F)
- Claims by individualsRight of private action for a person who suffers loss or damage (section 48O)
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Act 2012, consolidated text in force from 5 December 2025
sso.agc.gov.sg
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection (Notification of Data Breaches) Regulations 2021
sso.agc.gov.sg
Link checked 18 August 2026
Personal Data Protection Regulations 2021, Part 3
Directly binding regulation · S 63/2021, as amended by S 86/2026; consolidated version in force from 2 March 2026
The mechanics of sending personal data out of Singapore. There is no destination list of any kind and no government approval. You need a contract, group-wide binding rules for related companies, a recognised privacy certification, or valid consent preceded by a written summary of how well the destination protects the data.
Enforced by Personal Data Protection Commission
Transfer model: No restriction · Accepted routes: Standard contract clauses, Approved group rules, Certification scheme, Explicit consent
What it makes you do
- Put a transfer safeguard in placeA contract must both require comparable protection AND name the countries the data may go to. Singapore publishes no template; you draft your own.
- Written vendor contract
- Hold a security certificate — from 2 March 2026Global Cross-Border Privacy Rules and Global Privacy Recognition for Processors certifications became a recognised route on 2 March 2026, alongside the two APEC schemes.
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Regulations 2021 (S 63/2021), Part 3, regulations 10 to 12, in force from 2 March 2026
sso.agc.gov.sg
Link checked 18 August 2026
Personal Data Protection Act 2012, Part 6B (Data Portability Obligation)
Act of parliament · Inserted by the Personal Data Protection (Amendment) Act 2020 (Act 40 of 2020)
Singapore's data portability right. Parliament passed it in 2020 and the rest of the Act refers to it repeatedly, but the Part has never been commenced, so on 18 August 2026 nobody can demand their data be moved to a competitor. It can be switched on by a commencement notification without further debate.
Enforced by Personal Data Protection Commission
Transfer model: No restriction
What it makes you do
- Let people take their data elsewhereNot in force. No commencement date announced as at 18 August 2026.
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Act 2012 — Part 6B is referenced in sections 4(1), 4(2), 4(6), 48I and 48J but does not appear in the arrangement of sections or the body of the in-force text
sso.agc.gov.sg
Link checked 18 August 2026
Cybersecurity Act 2018
Act of parliament · Act 9 of 2018, 2020 Revised Edition, as amended by the Cybersecurity (Amendment) Act 2024 (Act 19 of 2024); consolidated version in force from 31 October 2025
Singapore's cyber law for systems that keep the country running, across energy, water, banking, healthcare, transport, infocomm, media, security services and government. Two hours to report an incident. The 2024 amendments commenced on 31 October 2025, but the Parts that would regulate cloud providers and data centres are still switched off.
Enforced by Cyber Security Agency of Singapore
Transfer model: No restriction
What it makes you do
- Report cyber incidents — within 2 hours, from 31 October 20252 hours by phone, then supplementary details within 72 hours. Since 31 October 2025 the duty also covers incidents on a supplier's interconnected systems.
- Independent audit — 2 yearsIndependent audit at least every two years by an auditor approved by the Commissioner; report to the Commissioner within 30 days.
- Assess high-risk projects — 1 yearAnnual cybersecurity risk assessment in the prescribed form.
- Secure the dataComply with the Cybersecurity Code of Practice for Critical Information Infrastructure 2026, issued 29 July 2026, with staged compliance dates of 29 July 2027 and 31 December 2027.
- Register or notifyNot yet in force: the licensing and duties for cloud providers and data centres sit in Parts 3C and 3D, which have not been commenced.
What it costs if you get it wrong
- Criminal liability: S$100,000 fine and/or 2 years' imprisonment — about $78 thousandFailure without reasonable excuse to report a cybersecurity incident (section 14(3))
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Cybersecurity Act 2018, sections 3, 14 and 15, consolidated text in force from 31 October 2025
sso.agc.gov.sg
“Any owner of a provider-owned critical information infrastructure who, without reasonable excuse, fails to comply with subsection (1) shall be guilty of an offence and shall be liable on conviction to a fine not exceeding $100,000 or to imprisonment for a term not exceeding 2 years or to both.”
Link checked 18 August 2026
- Official sourceCyber Security Agency of SingaporeForms — 2-hour and 72-hour incident reporting
csa.gov.sg
Link checked 18 August 2026
- Official sourceCyber Security Agency of SingaporeCybersecurity Code of Practice for Critical Information Infrastructure 2026, effective 29 July 2026
isomer-user-content.by.gov.sg
Link checked 18 August 2026
- Official sourceCyber Security Agency of SingaporeCybersecurity Act — agency overview page, last updated 16 July 2026
csa.gov.sg
Link checked 18 August 2026
Companies Act 1967, section 199
Act of parliament · 1967 Act, 2020 Revised Edition; consolidated version in force from 6 May 2026
The one genuine keep-a-copy-here rule we found in Singapore, and it is about company books rather than personal data. Accounting records may be held overseas, but enough must be mirrored back into Singapore to let the directors produce the accounts. Everything must be kept for at least five years.
Enforced by Accounting and Corporate Regulatory Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep data for a minimum period — 5 yearsFive years from the end of the financial year to which the transactions relate.
- Keep the data in the countryOnly a mirror, not a wall. The full accounting records may sit abroad, but statements and returns sufficient to prepare true and fair financial statements must be sent to and kept in Singapore, open to inspection by the directors at all times.
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Companies Act 1967, section 199(1) to (4)
sso.agc.gov.sg
“The company must retain the records referred to in subsection (1) for a period of not less than 5 years from the end of the financial year in which the transactions or operations to which those records relate are completed.”
Link checked 18 August 2026
- Official sourceInland Revenue Authority of SingaporeRecord Keeping Requirements — the tax authority's five-year rule and the penalties for non-compliance
iras.gov.sg
Link checked 18 August 2026
Advisory Guidelines on the Personal Data Protection Act for NRIC and other National Identification Numbers
Regulator guideline · Announced 2 February 2026; compliance deadline 31 December 2026
Singapore is switching off a habit that is everywhere in its economy: using the national identity card number to prove who you are. The regulator announced on 2 February 2026 that organisations must stop using these numbers for authentication by 31 December 2026, and that it will step up enforcement against misuse.
Enforced by Personal Data Protection Commission
Transfer model: No restriction
What it makes you do
- Secure the data — from 31 December 2026Stop using national identity card numbers as a means of authentication — as a password, a default PIN, or a proof that someone is who they say they are.
Sources
- Official sourcePersonal Data Protection CommissionOrganisations to cease the use of NRIC numbers for authentication by 31 December 2026, published 2 February 2026
pdpc.gov.sg
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionPDPC to step up enforcement action against misuse of NRIC numbers and issues new advisory on data protection, 2 February 2026
pdpc.gov.sg
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionAdvisory Guidelines on the PDPA for NRIC and other National Identification Numbers
pdpc.gov.sg
Link checked 18 August 2026
Industry rules6 rules
MAS Notice 658 — Management of Outsourced Relevant Services
Regulator directive · Issued 11 December 2023 under sections 47A(2), (4), (6), (7) and (12) of the Banking Act 1970. Notice 1121 is the merchant bank equivalent. · Banking
The rulebook a Singapore bank must follow before customer information reaches any outside supplier. It expressly allows the service to be performed overseas, so it is not a localisation rule, but it demands written secrecy notification, deletion on exit, independent audits and a register filed with the central bank. It replaced Notice 634 and the old Guidelines on Outsourcing on 11 December 2024.
Enforced by Monetary Authority of Singapore
Transfer model: No restriction · Accepted routes: Standard contract clauses
What it makes you do
- Extra vendor secrecy termsThe bank must notify the service provider in writing of the confidentiality duties, including the duties that apply under the law of the place where an overseas service is performed. A standard data processing agreement is not enough.
- Written vendor contractThe outsourcing agreement must let the bank terminate on reasonable notice and must require deletion or return of customer information on termination.
- Independent auditIndependent audits of material ongoing outsourced relevant services.
- Keep records of processingBanks must submit an outsourcing register to MAS using MAS's template, from 11 December 2024.
- Secure the data
Sources
- Official sourceMonetary Authority of SingaporeNotice 658 Management of Outsourced Relevant Services for Banks
mas.gov.sg
Link checked 18 August 2026
- Official sourceMonetary Authority of SingaporeMAS Notice 658, full text, section E — effective dates
mas.gov.sg
“This Notice, other than paragraphs 7.1 and 12.8, takes effect on 11 December 2024.”
Link checked 18 August 2026
- Official sourceMonetary Authority of SingaporeNotice 634 Banking Secrecy — Conditions for Outsourcing [Cancelled], cancelled with effect from 11 December 2024
mas.gov.sg
Link checked 18 August 2026
MAS Notices on Technology Risk Management and Cyber Hygiene (FSM-N21 to FSM-N26 family)
Regulator directive · Issued 9 May 2024 under the Financial Services and Markets Act 2022; the earlier Notices 644, 655, 644A, 655A, 1114 and 1118 were cancelled with effect from 10 May 2024 · Finance
The fastest clock in Singapore. A supervised financial institution has one hour from discovering a severe system or security incident to tell the central bank, and fourteen days to file a root cause report. Note the trap: the notice numbers everyone quotes were cancelled on 10 May 2024 and replaced by a new family issued under the Financial Services and Markets Act.
Enforced by Monetary Authority of Singapore
Transfer model: No restriction
What it makes you do
- Report cyber incidents — within 1 hourNotify MAS as soon as possible and not later than 1 hour after discovering a severe incident. Root cause and impact analysis report within 14 days.
- Secure the data
- Hold a security certificateCyber hygiene baseline: administrative account controls, patching, security standards, network perimeter defence, malware protection and multi-factor authentication.
What it costs if you get it wrong
- Loss of your licencePersistent non-compliance with a binding MAS notice
Sources
- Official sourceMonetary Authority of SingaporeMAS Notice FSM-N25, Notice on Technology Risk Management, issued 9 May 2024
mas.gov.sg
“A trust company must submit a root cause and impact analysis report to the Authority, within 14 days or such longer period as the Authority may allow, from the discovery of the relevant incident.”
Link checked 18 August 2026
- Official sourceMonetary Authority of SingaporeNotice FSM-N25 Technology Risk Management
mas.gov.sg
Link checked 18 August 2026
- Official sourceMonetary Authority of SingaporeNotice 644 Technology Risk Management [Cancelled]
mas.gov.sg
Link checked 18 August 2026
Cybersecurity Act 2018, Parts 3C and 3D — entities of special cybersecurity interest and major foundational digital infrastructure service providers
Act of parliament · Inserted by the Cybersecurity (Amendment) Act 2024 (Act 19 of 2024)
The switch that would put cloud providers and data centres under Singapore's cyber regulator. The definitions and the clauses saying who these Parts apply to are already in force, as of 31 October 2025, but the Parts themselves have never been commenced and section 18 currently reads as deleted. A single commencement notification would turn this on, and it would reach a provider based entirely outside Singapore that serves Singapore users.
Enforced by Cyber Security Agency of Singapore
Transfer model: No restriction
What it makes you do
- Report cyber incidentsNot yet in force. Would apply to designated cloud service providers and data centre operators, including those serving Singapore from wholly outside Singapore.
- Hold a security certificateNot yet in force. Compliance with codes of practice and standards of performance.
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Cybersecurity Act 2018, section 3(2E) to (2H) and section 2 definitions, in force from 31 October 2025; section 18 shown as deleted and Parts 3C and 3D absent from the in-force text
sso.agc.gov.sg
“Part 3D (except section 18H) applies to any major foundational digital infrastructure service provider that — (i) provides the foundational digital infrastructure service, whether from within or outside Singapore, to persons in Singapore within the meaning of section 18G”
Link checked 18 August 2026
- Official sourceCyber Security Agency of SingaporeCybersecurity Act — the agency's own description of the Foundational Digital Infrastructure category
csa.gov.sg
Link checked 18 August 2026
Health Information Act 2026
Act of parliament · Act No. 1 of 2026; passed 12 January 2026, assented 3 February 2026, published 12 February 2026 · Health and social care
Singapore's new health data law. It forces healthcare providers to feed patient records into a national electronic records system, adds health-specific security duties, and creates its own breach and cyber incident clocks separate from the general ones. It was passed in January 2026 and is still not in force. Notably, it contains no requirement to keep health data inside Singapore.
Enforced by Ministry of Health
Transfer model: No restriction
What it makes you do
- Secure the dataNot yet in force. Reasonable controls and safeguards over health information.
- Delete data after a periodNot yet in force. Same purpose-based test as the general privacy law.
- Report breaches to the regulatorNot yet in force. Deadline to be prescribed by regulations that do not yet exist.
- Report cyber incidentsNot yet in force. A separate cybersecurity incident notification duty, deadline to be prescribed.
- Let people take their data elsewhereNot yet in force. Portability of health information in electronic form.
- Keep records of processingNot yet in force. Mandatory contribution of health information to the national electronic records system by specified contributors.
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Health Information Act 2026 (Act No. 1 of 2026), Acts Supplement, sections 66, 67, 74 to 81 and 86 to 88
sso.agc.gov.sg
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Uncommenced Acts listing, 18 August 2026 — Health Information Act 2026 shown as uncommenced
sso.agc.gov.sg
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Healthcare Services Act 2020, section 27 — record-keeping duties for licensed healthcare providers, with no residency requirement
sso.agc.gov.sg
Link checked 18 August 2026
Public Sector (Governance) Act 2018
Act of parliament · Act 5 of 2018, 2020 Revised Edition; consolidated version in force from 1 August 2026 · Government
Government data sits outside the general privacy law and inside its own regime. Public agencies share information under data sharing directions rather than consent, and the people who handle it face personal criminal liability, up to two years in prison, for leaking it or for re-identifying anonymised records.
Enforced by Government Technology Agency
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Secure the data
- Allowed because the law requires itSharing between public sector agencies runs on data sharing directions rather than consent. The general privacy law does not apply to public agencies at all.
What it costs if you get it wrong
- Criminal liability: S$5,000 fine and/or 2 years' imprisonment — about $4 thousandUnauthorised disclosure or improper use of information under the control of a public sector agency (section 7)
- Criminal liability: S$5,000 fine and/or 2 years' imprisonment — about $4 thousandUnauthorised re-identification of anonymised public sector information (section 8)
Sources
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Public Sector (Governance) Act 2018, sections 7 and 8, consolidated text in force from 1 August 2026
sso.agc.gov.sg
“the individual shall be guilty of an offence and shall be liable on conviction to a fine not exceeding $5,000 or to imprisonment for a term not exceeding 2 years or to both.”
Link checked 18 August 2026
- Official sourceAttorney-General's Chambers of Singapore (Singapore Statutes Online)Personal Data Protection Act 2012, section 4(1)(c) — the privacy obligations do not apply to public agencies
sso.agc.gov.sg
Link checked 18 August 2026
Digital Infrastructure Bill (draft)
Draft law · Draft released for public consultation on 1 July 2026; consultation closed 22 July 2026 · Telecoms
A draft law, not a law. It would licence the biggest data centres and cloud providers serving Singapore and require them to report outages as well as cyber incidents, prompted partly by a four-hour data centre outage in October 2023 that took down banking services. Public comment closed on 22 July 2026 and no bill has been introduced.
Enforced by Info-communications Media Development Authority
Transfer model: No restriction
What it makes you do
- Register or notifyProposal only. A licence from the media and telecoms regulator for data centre facility services in data centres of 10 megawatts critical IT load or more, and for cloud infrastructure and platform services earning at least S$100 million a year from Singapore users. Software-as-a-service is excluded.
- Report cyber incidentsProposal only. Notification of cybersecurity incidents and service delivery disruptions.
- Secure the dataProposal only. Physical security, cybersecurity, business continuity and disaster recovery.
Sources
- Official sourceMinistry of Digital Development and InformationPublic Consultation on Digital Infrastructure Bill, 1 July 2026
mddi.gov.sg
“A Cloud Computing Service that has generated revenue from users in Singapore of ≥ S$100 million per year on average over the 3 preceding years, and falls within the categories of Infrastructure-as-a-Service (IaaS) or Platform-as-a-Service (PaaS) but not Software-as-a-Service (SaaS).”
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and InformationNew Digital Infrastructure Act to enhance resilience and security of digital infrastructure and services, 1 March 2024
mddi.gov.sg
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
Whether Singapore government procurement rules (Instruction Manual 8) impose data residency or classification-based hosting conditions on suppliers
Instruction Manual 8 is not published as a public government document and we could not open an official text. Suppliers to Singapore public agencies should assume contractual hosting conditions exist and ask the agency, rather than relying on the absence of a statutory rule. Checked 18 August 2026.
The exact age thresholds in the Advisory Guidelines on the PDPA for Children's Personal Data in the Digital Environment
The regulator's announcement page confirms the guidelines exist and were published on 27 March 2024, but the page renders its body text with JavaScript and we could not extract the thresholds from an official source in this run.
That MAS Notice FSM-N25's one-hour incident clock applies in identical terms across every class of supervised financial institution
We verified the one-hour and fourteen-day wording in the notice applying to licensed trust companies, and confirmed that parallel notices FSM-N21, FSM-N22, FSM-N23, FSM-N24 and FSM-N26 exist for other classes, but we did not open each one. Treat one hour as the working assumption and confirm against your own class of licence.
That no localisation rule exists in the education, gaming, defence or mapping sectors
This is a negative. We searched the statute book and the relevant regulators and found nothing, and the Telecommunications Act 1999 in force from 1 October 2025 contains no reference to keeping anything inside Singapore. No rule found, checked 18 August 2026, confidence medium.
The exact commencement date of the Health Information Act 2026
The Act is listed as uncommenced on the official statute site as at 18 August 2026 and no commencement notification was located. Anyone handling Singapore health records should re-check monthly.
Whether the Cybersecurity Act Parts 3C and 3D will be commenced before or alongside the Digital Infrastructure Bill
The consultation paper says the Bill would make related amendments to the Cybersecurity Act 2018 and the Cybersecurity (Amendment) Act 2024 to align the definitions, which suggests sequencing is still open. No commencement date has been announced.
Precise current PDPA financial penalty levels actually imposed in 2025 and 2026
The regulator's decisions list is rendered with JavaScript and individual decision texts could not be extracted in this run. We can evidence that decisions are being published regularly, but not the amounts.
30-day cadence. Three separate instruments are mid-commencement (the Health Information Act 2026, Cybersecurity Act Parts 3C and 3D, and PDPA Part 6B), a bill is between consultation and introduction, and a hard compliance deadline falls on 31 December 2026. Any of the commencements can happen by notification with no consultation, so a longer interval risks this record asserting that cloud providers are unregulated after that has ceased to be true.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.
Compare with
- Singapore versus Argentina
- Singapore versus Armenia
- Singapore versus Australia
- Singapore versus Austria
- Singapore versus Azerbaijan
- Singapore versus Brazil
- Singapore versus Bulgaria
- Singapore versus Cambodia
- Singapore versus Canada
- Singapore versus China
- Singapore versus Croatia
- Singapore versus Cyprus
- Singapore versus Estonia
- Singapore versus France
- Singapore versus Georgia
- Singapore versus Germany
- Singapore versus Greece
- Singapore versus Hong Kong SAR
- Singapore versus Hungary
- Singapore versus Iceland
- Singapore versus India
- Singapore versus Indonesia
- Singapore versus Ireland
- Singapore versus Israel
- Singapore versus Italy
- Singapore versus Japan
- Singapore versus Latvia
- Singapore versus Lithuania
- Singapore versus Luxembourg
- Singapore versus Malta
- Singapore versus Mexico
- Singapore versus Mongolia
- Singapore versus Nepal
- Singapore versus Netherlands
- Singapore versus Poland
- Singapore versus Russia
- Singapore versus Saudi Arabia
- Singapore versus Serbia
- Singapore versus Slovakia
- Singapore versus Slovenia
- Singapore versus South Korea
- Singapore versus Spain
- Singapore versus Sri Lanka
- Singapore versus Sweden
- Singapore versus Switzerland
- Singapore versus Taiwan
- Singapore versus Thailand
- Singapore versus Turkey
- Singapore versus Ukraine
- Singapore versus United Arab Emirates
- Singapore versus United Kingdom
- Singapore versus United States
- Singapore versus Uzbekistan