AppTech System

Blog / Compliance & Security

Document Management Systems in Singapore: What the Law Requires

19 Jul 2026 · AppTech System

A Singapore office team reviewing company records and document filing practices

A document management system stores, versions and controls access to your business files. In Singapore it also carries a legal job: the Employment Act, the Income Tax Act and the PDPA each set rules on what you keep, how long you keep it, and who may read it. Most vendor pages skip that part entirely.

That legal layer is where buying decisions usually go wrong. Firms compare storage limits and search speed, then find their new system cannot show who opened a personnel file, or cannot delete one class of record while preserving another. Obligations first and features second is the safer order, so that is the order used below.

What is a document management system?

A document management system is software that holds business documents in one controlled repository rather than scattered across drives, inboxes and desks. It indexes each file so it can be searched by content and not just by filename; it tracks versions; and it records who did what to which document.

Vendors often call this an EDMS, an electronic document management system, and the label matters less than the four jobs underneath it: capture, so paper and email arrive in the same place; retrieval, so the right version surfaces instantly; control, so only entitled staff can view or edit; and disposal, so records leave when their time is up. Disposal is the job most systems treat as an afterthought, and the one Singapore law is strictest about.

A shared drive is not a document management system

A shared network drive gives you storage and very little else. It has no version history beyond whatever someone typed into a filename, no record of who opened a file, and no way to apply a retention rule to one folder without touching every other folder beside it. Cloud sync solves sharing, not governance.

The failure is rarely dramatic. It shows up as three copies of a contract with different signatures, an ex-employee’s folder nobody dares delete, and an auditor’s request that takes two days of manual searching to answer. Those are the symptoms of a business that has outgrown its spreadsheets, and the cause is identical: the tool was built to hold a file, never to enforce a rule.

What does Singapore law require you to keep?

Three authorities set duties that land directly on your document store. IRAS requires business records to be kept for at least five years from the relevant Year of Assessment. The Ministry of Manpower sets employment record duties. ACRA requires certain company registers to be maintained and kept current.

The detail matters when you configure the system. MOM requires employment records covering the latest two years for current employees, and the last two years kept for one year after someone leaves; soft copy is accepted. ACRA has required a Register of Registrable Controllers since 31 March 2017, held at your registered office or your corporate service provider, updated within seven days of a controller confirming a change. GST-registered businesses should also check how InvoiceNow e-invoicing records are archived.

The PDPA sets a ceiling, not just a floor

Retention duties tell you the minimum. The PDPA sets a maximum. Section 25, the Retention Limitation Obligation, requires an organisation to cease retaining documents containing personal data once the purpose for collecting it is no longer served and retention is no longer necessary for legal or business purposes.

The PDPC is explicit that no fixed duration is prescribed, so reasonableness is judged against the purpose of collection and any other legal duty in play. That cuts both ways. Holding a rejected applicant’s identity documents for nine years because storage is cheap is a contravention, not prudence. Deleting a payroll record at that same nine-year mark satisfies the PDPA and breaks your tax record duty. A document system has to run both clocks at once.

Does archiving a file count as ceasing to retain it?

No, and this is the trap most businesses fall into. The PDPC states that documents merely filed in a locked cabinet, warehoused, or transferred to a party under the organisation’s control are still being retained. Electronic records that are archived, or to which access has been limited, are still retained too.

So moving a folder to cold storage, revoking everyone’s permissions, or quietly renaming it discharges nothing. An organisation ceases to retain only when it, its agents and its data intermediaries no longer have access, which the guidance says happens by returning the documents, transferring them on the individual’s instructions, destroying them, or anonymising the data. Ask any vendor to demonstrate permanent deletion, including from backups and replica copies, before you sign anything.

Who should be able to open which document?

Section 24 of the PDPA, the Protection Obligation, requires reasonable security arrangements to prevent unauthorised access, collection, use, disclosure, copying, modification or disposal of personal data. In document terms that means permissions by role, not by whoever last remembered to share a link.

Reasonable is relative to what you hold. A folder of signed employment contracts, identity documents and medical certificates deserves tighter control than a marketing library, and the system should let you say so without splitting the repository. Two capabilities carry most of the weight: role-based access controls inherited from the folder structure, and an audit log that outlives the person who triggered it. Our guide to handling data securely applies to staff records as much as customer ones.

Which features actually matter?

Judge a document management system against the duties above rather than against the feature grid. Five capabilities do nearly all of the compliance work, and a product that is weak on any one of them will cost you time later, however polished the rest of the demo looks.

  • Retention scheduling: apply a rule per document class, not per folder, and trigger disposal automatically when the clock runs out.
  • Version control: one current version with full history behind it, so no filename ever ends in “final-v3”.
  • An audit trail: who viewed, edited, downloaded or deleted a document, and exactly when they did it.
  • Granular access controls: permissions by role and document type, reviewable on a single screen.
  • Content search: full-text and metadata search that reaches inside scanned files, not only native ones.

How do you build a retention schedule?

Start by listing document classes rather than folders: employment records, payroll, tax and accounting, contracts, customer records, statutory registers. For each class, write down the longest statutory duty that applies, then the business reason you might justifiably hold it beyond that point.

Where a statutory duty and the PDPA disagree, the duty generally governs while it runs, and the PDPA takes over the moment it expires. That is why every class needs a defined end date rather than an open-ended archive. Two habits help: review the schedule annually, because thresholds move, and separate the personal data inside a record from the record itself, so anonymising remains available when deleting is not. Our PDPA compliance checklist covers the wider obligations that sit around this one.

Where off-the-shelf stops being enough

Most Singapore SMEs should buy rather than build. Established document management products handle versioning, permissions and search better than a first custom attempt will, and they cost far less to maintain. Configuration beats code for any business with conventional record types and ordinary workflows.

Custom earns its place in narrower situations: when documents must be generated and filed automatically by a system you already run, when retention rules vary by client contract instead of by document type, or when a regulator expects evidence your product simply cannot produce. That is the same build-versus-buy threshold we apply everywhere, and it is a threshold rather than a default. Where it is genuinely crossed, custom software development is the route.

Sources and disclaimer: IRAS on record keeping; the Ministry of Manpower on employment records; the PDPC Advisory Guidelines on Key Concepts in the PDPA, chapters 17 and 18; and ACRA on the Register of Registrable Controllers. Retention periods, thresholds and registers are set by those authorities and change over time. This is general information and not legal advice, so verify the current position with each authority before acting.

About AppTech System. AppTech System is a Singapore custom-software team and the people behind the Automiq and BooknGo platforms, building web, mobile, AI and enterprise software for businesses in regulated industries. Talk to us.

Records outgrown the folders holding them?

See how we build document systems

All articles

Related reading