PDPC Singapore — where the practical guides come from
The PDPC is Singapore’s data protection authority and an active English-language publisher of practical privacy guidance — advisory guidelines on the Act, sector guidance, and stand-alone guides that read well outside Singapore.
- Published by
- Personal Data Protection Commission, Singapore — established 2 January 2013 to administer and enforce the Personal Data Protection Act 2012 (PDPA).
- Type
- Statutory regulator; guidance publisher.
- Versions and language
- English.
- Jurisdiction
- Singapore. The PDPC also represents the Singapore Government internationally on data protection.
- Primary audience
- DPOs and compliance teams, including UK organisations with Singapore operations or processors.
- Topic tags
- PDPA · advisory guidelines · DPIA · accountability · AI · anonymisation · Do Not Call
- Availability
- Free.
Why it matters
The PDPC’s advisory guidelines are the authority’s own reading of the PDPA, and its practical guides are where it earns a place on this list: a DPIA guide with a likelihood-and-impact matrix and sample questionnaire, a guide to building a data protection management programme, advisory guidelines on the use of personal data in AI recommendation and decision systems, and a basic anonymisation guide. The PDPA is baseline legislation — sector regulators oversee their own domains alongside it — and the PDPC also runs the Do Not Call Registry.
The UK position. Singapore has no UK adequacy decision, so transfers from the UK need an Article 46 UK GDPR transfer tool; the PDPA’s own transfer-limitation obligation applies in the other direction. Concepts overlap but do not map one-to-one — the PDPA is built around consent and its exceptions rather than UK GDPR’s six lawful bases — so the guides are best used for method and structure rather than as legal analysis of UK obligations.
The PDPC’s regulator profile sits in Regulators & Authorities; Singapore’s Data Protection Trustmark (SS 714:2025) is listed in Standards & Frameworks.
