Comprehensive Privacy Law
Personal Data Protection Act 2012
Singapore · November 20, 2012 (Act); July 2, 2014 (Data Protection Provisions); February 1, 2021 (2020 amendments)
Verify detailsSection 2(1) defines 'organisation' broadly — including entities 'whether or not formed or recognised under the law of Singapore' and 'whether or not resident, or having an office or place of business, in Singapore' — so a foreign entity with zero Singapore presence can be caught simply by collecting, using, or disclosing personal data connected to Singapore (e.g. a foreign e-commerce site marketing to and collecting data from Singapore residents). Mechanically distinct from a formal 'offering' or 'monitoring' test but functionally similar in effect. Section 4 exempts public agencies, personal/domestic-capacity individuals, employees acting in the course of employment, and business contact information. No small-business threshold; health/financial data get additional sector-regulator rules layered on top, not instead of, the PDPA.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.