AppTech System

Blog / Compliance & Security

PDPA Compliance Checklist for Singapore SMEs (2026)

13 Jun 2026 · AppTech System

Singapore business team reviewing data protection practices

Singapore’s Personal Data Protection Act (PDPA) applies to almost every private-sector business that handles personal data — and “we’re a small company” is not an exemption. Enforcement has stepped up: in 2025 the PDPC fined firms from travel agencies to a Marina Bay integrated resort, and a hard new deadline now looms — businesses must stop using NRIC numbers for authentication by 31 December 2026. This guide walks through every obligation, the breach-notification rule most SMEs miss, what non-compliance actually costs, and a 10-point checklist you can act on. Run our free PDPA Readiness Check to see where you stand in under a minute.

Key takeaways

  • The PDPA applies to almost all SMEs; there is no small-business exemption, and a Data Protection Officer is mandatory.
  • A notifiable breach must reach the PDPC within 3 calendar days — the rule SMEs most often miss.
  • Penalties can reach 10 per cent of Singapore turnover or S$1 million, whichever is higher (in force since 1 Oct 2022).
  • Stop using NRIC numbers for authentication by 31 December 2026; enforcement begins 1 January 2027.

What does the PDPA actually require?

The PDPA, in force since 2012, is built on a set of data-protection obligations — not just “get consent”. The Personal Data Protection (Amendment) Act 2020 added the Data Breach Notification obligation; a Data Portability obligation is legislated but not yet in operation. The PDPC sets out the practical duties below.

Obligation What it means in plain English
Consent Collect, use or disclose personal data only with consent, and let people withdraw it.
Purpose Limitation Use data only for purposes a reasonable person would consider appropriate, and that you stated.
Notification Tell individuals the purposes before or at the point you collect their data.
Access & Correction Let individuals access the data you hold and correct it within a reasonable time.
Accuracy Make a reasonable effort to keep personal data accurate and complete.
Protection (Security) Apply reasonable security: access controls, encryption, logging, staff training.
Retention Limitation Stop retaining data once the purpose ends and there is no legal need to keep it.
Transfer Limitation Ensure overseas transfers get a comparable standard of protection.
Data Breach Notification Assess breaches and notify the PDPC and affected individuals when notifiable.
Accountability Appoint a DPO, publish your data-protection policy, and be able to show compliance.

Summarised from the PDPC’s Data Protection Obligations framework; the Data Portability obligation is enacted but not yet in operation. Refer to the PDPC for the authoritative wording.

Two obligations catch SMEs out. Accountability makes appointing a Data Protection Officer mandatory, not optional. And the Protection obligation flows through to your vendors: if a SaaS tool or contractor processes data on your behalf, you stay liable. Our guide on handling customer data securely covers the practical security side.

What is the Data Breach Notification obligation?

The Data Breach Notification obligation requires you to notify the PDPC of a notifiable breach as soon as practicable, and no later than 3 calendar days after you determine it is notifiable (PDPC). This is the single obligation SMEs most often miss — and the three-day clock is short.

A breach is notifiable when it is likely to result in significant harm to affected individuals, or it affects 500 or more individuals. You must assess a suspected breach without unreasonable delay, and where the threshold is met you must also notify the affected individuals. The thresholds and timelines come from the Notification of Data Breaches Regulations 2021 and the PDPC’s breach guide.

Here is what trips people up. The three days do not start at the breach: they start when you determine it is notifiable. So a clinic that learns of a ransomware incident on a Friday cannot sit on it over the weekend; the duty to assess begins immediately. In our experience, the SMEs that cope are the ones with a written breach playbook prepared in advance — who assesses, who notifies, and what gets logged — rather than improvising mid-incident.

Which 2024–2026 PDPA changes must you act on?

The biggest near-term change is the NRIC-for-authentication ban: private organisations must cease using full or partial NRIC numbers for authentication by 31 December 2026, with the PDPC stepping up enforcement, including directions and penalties, from 1 January 2027 (PDPC, Jan 2026).

What does “authentication” mean here? Using an NRIC number, or the last few digits, as a password or to verify identity — a still-common pattern for member logins, collection counters and visitor sign-ins. It is not a ban on ever recording an NRIC where the law permits. The compliant fix is to authenticate another way: Singpass for identity, or Myinfo to pull verified particulars without storing the NRIC as a secret. Our guides on Singpass and Myinfo integration and KYC for Singapore businesses cover the alternatives.

Two other shifts matter. The PDPC issued Advisory Guidelines on Children’s Personal Data in March 2024, raising expectations for any service likely used by minors. And the higher penalty regime (below) has been in force since 2022, so it is not a future risk — it applies to decisions issued today.

What does it cost to get PDPA wrong?

Since 1 October 2022, the PDPC can impose a financial penalty of up to 10 per cent of an organisation’s annual turnover in Singapore where that turnover exceeds S$10 million, or S$1 million, whichever is higher (PDPC, 2022). For SMEs the headline cap matters less than the steady stream of mid-five-figure fines.

Recent enforcement decisions show the realistic range for SME-scale breaches:

Organisation Penalty What happened
Ezynetic S$17,500 Ransomware exfiltrated data of 190,589 individuals (Protection Obligation).
Air Sino-Euro Associates Travel S$47,000 Breach affected 336,759 individuals (Accountability and Protection Obligations).
Marina Bay Sands Financial penalty Penalised for a data breach under the Protection Obligation (Oct 2025).

Sources: PDPC enforcement decisions — Ezynetic (Jul 2025), Air Sino-Euro (Oct 2025), and the Marina Bay Sands press release (Oct 2025).

The pattern is worth noting: most penalties follow a security failure, not a paperwork slip. Ransomware and account compromise feature heavily, which tracks with the wider threat picture — Singapore’s CSA reported ransomware cases up 21 per cent and infected infrastructure rising from 70,200 to 117,300 in 2024. Beyond the fine sits the cost that does not appear in a decision: customer trust, which is far slower to rebuild.

The 10-point PDPA compliance checklist

This is the practical centrepiece. Work through these ten points and you will have covered the obligations the PDPC actually enforces against SMEs. None of them requires a large budget; most require a decision and a process. Score yourself honestly, then close the gaps in priority order.

  1. Appoint a Data Protection Officer (DPO). Name someone responsible and publish their business contact — a mandatory baseline many SMEs skip.
  2. Obtain and record consent. Collect personal data with consent for a clear, stated purpose, and keep a record of it.
  3. Publish a data-protection notice. A privacy policy explaining what you collect, why, and how people reach your DPO.
  4. Map what data you hold. Maintain a simple inventory — you can’t protect what you haven’t mapped.
  5. Limit retention. Keep personal data only as long as needed, then dispose of it securely.
  6. Honour access & correction. Have a process for individuals to access and correct their data within reasonable time.
  7. Write a breach-response plan. Be ready to assess and notify the PDPC and affected individuals within 3 days.
  8. Sign data-protection terms with vendors. Third parties that process data for you must be bound by written terms — you stay accountable.
  9. Apply reasonable security. Encryption, role-based access and logging on every system holding personal data.
  10. Stop NRIC-based authentication. Move logins and identity checks off the NRIC before the 31 December 2026 deadline.

Want your score against this list in under a minute? Run our free PDPA Readiness Check. It flags the gaps that most often lead to enforcement, so you can fix the riskiest ones first.

Where do SMEs go wrong most often?

Across the enforcement decisions and our own client work, the same handful of gaps recur — and most are organisational, not technical. The PDPC’s SME cases routinely cite a missing or under-resourced DPO and weak security arrangements rather than exotic failures. Here are the patterns we see most:

  • No DPO appointed, or it’s “everyone’s job”, which means no one’s.
  • Using the NRIC as a login or password — now on a hard deadline to stop.
  • Customer data scattered across spreadsheets, WhatsApp and personal inboxes.
  • No retention policy — data kept “just in case”, forever.
  • No breach playbook, so the 3-day clock is lost to confusion.
  • Vendors and data intermediaries handling data with no written data-protection terms.

The last one deserves emphasis. Many SMEs assume that handing data to a vendor hands over the liability too. It doesn’t. The PDPC publishes model data-protection clauses for exactly this reason, and our website security checklist covers the technical controls that back the contractual ones up.

How does software make compliance the default?

Compliance is far easier when it’s built into your systems rather than managed by hand. The PDPC and IMDA’s Data Protection Essentials (DPE) programme gives SMEs a light-touch baseline, and implementing it may be treated as a mitigating factor if a breach occurs (PDPC). Good software bakes those controls in.

Well-built systems handle the obligations you’d otherwise track in spreadsheets. They capture and log consent at the point of collection, enforce role-based access so staff see only what they need, encrypt data at rest and in transit, keep audit trails for breach assessment, and automate retention and disposal on a schedule. For identity, they verify through Singpass or Myinfo instead of capturing and storing NRIC numbers. This is how our Automiq platform governs customer data and KYC — so the AI and workflows on top run on compliant information, not a liability.

When should you build custom instead of buying off the shelf?

For most SMEs, the right move is to configure a reputable off-the-shelf tool and adopt the DPE baseline — you shouldn’t build what you can buy. Custom software earns its keep only in specific cases: when no product fits your cross-system workflow, or compliance lives in the gaps between tools. That’s where governance has to be designed in.

The cases where a custom build wins are narrow but real: unusual data flows that span booking, operations and finance with no single product to cover them; deep integration needs where consent, access logs and retention must stay consistent across several systems; or a move off NRIC-based identity that touches legacy software a vendor won’t change. That’s the work we do — see our software development services and, where data-protection tooling qualifies for funding, our PSG vs EDG guide on which grant fits an off-the-shelf tool versus a custom build.

Disclaimer: This checklist is general guidance and awareness only — not legal advice or a compliance audit. The PDPA, the Data Breach Notification obligation, penalty levels and the NRIC-authentication rules are governed by the Personal Data Protection Commission (PDPC) and are subject to change. For authoritative requirements, refer to the PDPC or a qualified legal adviser. AppTech System builds software with PDPA-aligned practices but does not provide legal services.

About AppTech System — AppTech System is a Singapore custom-software team and the people behind the Automiq and BooknGo platforms, building web, mobile, AI and enterprise software for businesses in regulated industries. Talk to us.

See where your PDPA gaps are — free, in under a minute.

Run the PDPA Check

All articles