The framework
Singapore's framework rests on the Personal Data Protection Act (PDPA) 2012, with the Personal Data Protection Commission as the supervisory authority.
The posture is hybrid. Notice and purpose limitation govern collection and consent is reserved for sensitive cases, which makes first-party marketing more workable here than in strict opt-in markets.
Key instruments
Personal Data Protection Act (PDPA) 2012, amended 2020
Singapore runs the most business-calibrated regime in Asia: consent-based on paper, but with deemed consent and a legitimate-interests route that make first-party marketing manageable, plus a strict Do Not Call registry for calls and texts. The PDPC is a prolific, guidance-heavy enforcer.
Marketing and advertising
Consent is the default but the 2020 amendments added deemed consent by notification and a legitimate interests exception; the Do Not Call registry governs phone and SMS marketing. That single sentence decides most channel plans here.
Cross-border transfers
Comparable-protection standard via contracts, BCRs or certification (APEC CBPR recognized).
Enforcement and penalties
Up to 10% of annual Singapore turnover for large firms, or SGD 1M.