Manage user consent online and meet PDPA compliance
Automate consent management and align your business with regulatory compliance with our no-code, easy-to-use cookie consent solution.
The #1 cookie consent solution, trusted by 1.5 Million+ websites
Check your PDPA Compliance
CookieYes will scan your website and keep you informed on the personal data your website collects through cookies.
Singapore’s Personal Data Protection Act (PDPA) is a law that governs the collection, use and disclosure of personal data by private organizations. The PDPA aims to safeguard individuals’ personal data and mandates organisations to use personal data for legitimate and reasonable purposes. The PDPA was enacted in 2012 and was amended in November 2020 via the Personal Data Protection (Amendment) Act 2020. PDPA came into effect on February 1, 2021.
PDPA Compliance Checklist for Websites
- Obtain user consent for cookies and trackers
- Record user consents to demonstrate proof
- Include an accurate, up-to-date privacy policy
- Enlist with ‘Do Not Call’ (DNC) Registry
- Limit data collection only for legitimate purposes
- Notify data breaches to DPAs and users
Comply with PDPA Singapore using CookieYes
Display cookie consent banner for visitors
PDPA requires businesses to notify users regarding the use and disclosure of personal data at the point of collection and request users for their consent.
With CookieYes you can
- Scan your website against a 100,000+ cookie database
- Display a custom cookie banner that fits your brand
- Show a consent revisit widget for users to withdraw consent
Automate consent management
Businesses should also ensure ongoing compliance with PDPA’s obligations for consent and leverage automated tools.
With CookieYes you can
- Auto-block all third-party cookies prior to user consent
- Schedule cookie scanning for continuous compliance
- Record consent logs for proof of consent during audits
Generate a compliant privacy policy
Under PDPA Singapore, businesses should notify users of the purposes for which they collect personal data and it should be easy to read and understand.
With CookieYes you can
- Use our pre-built policy template
- Generate your privacy policy in minutes
- Simply copy-paste the policy to your website
Learn more about PDPA Singapore and take the next step towards compliance
What is PDPA Singapore?
The Personal Data Protection Act is a law enacted by Singapore that intends to regulate the collection, use, and disclosure of personal data by organizations. The PDPA aims to safeguard individuals’ personal data and mandates organisations to use personal data for legitimate and reasonable purposes.
The Personal Data Protection (Amendment) Act 2020 or PDPA Amendments was passed in November 2020. The first batch of amendments came into effect on 1 February 2021. The next set of amendments came into force on 1 October 2022.
Who does PDPA apply to?
PDPA Singapore applies to any business in the private sector that handles the personal data of Singapore residents. Similar to data privacy regulations like GDPR, PDPA has extraterritorial applicability — it applies to organizations outside Singapore that collect, use or disclose the personal data of Singapore residents.
The PDPA does not apply to public sector organizations including Government ministries and departments. The public sector is governed by other laws such as the Public Sector (Governance) Act 2018.
What are consumer rights under PDPA?
Right to be informed
The right to be informed about how their personal data will be used, and to be notified if personal data is disclosed to third parties.
Right to access
The right to access personal data and to have it available in a clear and readable format, free of cost.
What is the penalty for non-compliance?
The maximum financial penalty for non-compliance includes a fine of up to SGD 10 million (approximately USD 7.4 million) or 10% of an organization’s annual turnover in Singapore, whichever is greater.
Individuals who suffer loss or damage as a result of a violation of PDPA have private rights of action and can initiate civil proceedings against organizations to seek remedies including damages, injunctions, and declarations.
FAQ on PDPA Singapore Compliance
The first batch of changes introduced by the Personal Data Protection (Amendment) Act 2020 or PDPA Amendments came into effect on 1 February 2021. The next set of amendments came into force on 1 October 2022.
The PDPA was first passed by the Parliament of Singapore in October 2012 and was implemented in three phases by July 2014.
Fast-track your PDPA compliance in minutes
Set up a cookie consent banner in 3 simple steps and automate your compliance.