Skip links

PDPA for Websites: A Clause-by-Clause Guide to Building a Compliant Singapore Website

Table of contents

1. Consent Obligation (Sections 13–17): Design your forms honestly

The PDPA requires consent before you collect, use or disclose personal data, unless an exception applies. On a website, this shows up in your form design.

Keep checkboxes unticked. Consent should be an active choice, so pre-ticked boxes undermine it.

Separate service consent from marketing consent. Someone submitting an enquiry form has consented to being contacted about their enquiry. They have not consented to your monthly newsletter. Under Section 14(2), you also cannot make consent to unnecessary data use a condition of providing your service. So “Tick to receive promotions” should be its own optional checkbox, never bundled into “I agree to the Terms.”

Rely on deemed consent where it genuinely applies. If a customer gives you their address at checkout, you can use it to deliver their order without a separate checkbox. Don’t stretch this to cover purposes the customer wouldn’t reasonably expect.

Make withdrawal easy (Section 16). Every marketing email needs a working unsubscribe link. Account holders should be able to change their communication preferences without emailing support.

2. Notification and Purpose Limitation (Sections 18 & 20): Explain at the point of collection

You must tell people why you’re collecting their data, on or before collection, and only use it for purposes a reasonable person would consider appropriate.

A privacy policy linked in the footer is necessary, but it isn’t enough on its own. Best practice is a short notice right beside the form. For example: “We’ll use your name and email to respond to your enquiry. See our Privacy Policy.” This “layered notice” approach is what the PDPC favours.

Your privacy policy should be specific: what data you collect, why, who you share it with (payment processors, CRM, email platforms), how long you keep it, and how to contact you. A generic template copied from an overseas site is a red flag.

3. Data minimisation: The best-protected data is data you never collect

Before adding any form field, ask whether you actually need it. Do you need a date of birth for a newsletter? A phone number for a whitepaper download? Every extra field adds risk under the Protection and Retention obligations. It also tends to lower form completion rates.

4. The NRIC rules: Stop collecting it, stop authenticating with it

This is where many Singapore websites are exposed right now.

Collection. Under the PDPC’s NRIC Advisory Guidelines, you generally shouldn’t ask for NRIC numbers on your website unless the law requires it or you need to verify identity to a high degree of fidelity. Lucky draws, event registrations, membership sign-ups and visitor forms usually don’t qualify. If you think you have a legitimate need, ask whether a partial identifier, a mobile number, or Singpass/Myinfo integration would do the job instead.

Authentication. Private organisations must phase out NRIC numbers for authentication by 31 December 2026, and the PDPC will step up enforcement from 1 January 2027 (PDPC announcement). In practice, audit your website and systems for the following:

  • Login IDs that are NRIC numbers, or customers looking up their account or bookings by NRIC.
  • PDF statements, invoices or reports password-protected with the customer’s NRIC or partial NRIC. This is extremely common.
  • “Verify your identity” steps that ask for the last four characters of the NRIC.

The recommended replacements include multi-factor authentication, robust password standards, tokens or biometrics (Baker McKenzie), and for higher-assurance needs, Singpass login. Developers and agencies should treat this as a priority project for Q4 2026.

5. Protection Obligation (Section 24): Technical security is a legal requirement

Section 24 requires “reasonable security arrangements.” Most PDPC enforcement decisions involve this obligation, and many come from website issues: misconfigured databases, unpatched plugins, and admin panels protected by weak passwords. On a website, “reasonable” typically means:

  • HTTPS across the whole site, not just checkout.
  • CMS, plugins and themes kept updated, with unused plugins removed. Outdated WordPress plugins are a recurring cause of breaches.
  • Multi-factor authentication on every admin account, with no shared logins.
  • Form submissions not emailed in plain text to a shared inbox, and file upload folders not publicly accessible.
  • Regular backups and vulnerability scans, scaled to the sensitivity of the data you hold.

Is your website fully compliant with Singapore’s PDPA?

Get a Free PDPA Website Audit from SWBD and identify potential compliance gaps before they become a problem.

6. Cookies, analytics and tracking pixels

The PDPA has no cookie-specific clause like the EU’s ePrivacy rules, but the PDPC’s guidance is clear. Where cookies or trackers collect personal data, the Consent and Notification obligations apply. Cookies that are strictly necessary for the site to work, like a shopping cart session, are generally covered by deemed consent. Analytics, advertising pixels and session-replay tools that profile identifiable users are harder to justify without telling people and giving them a choice.

A practical setup is a cookie banner that explains which categories of trackers you use, with a clear way to decline non-essential ones and a cookie section in your privacy policy. Also check that your form tools don’t leak entered data, such as email addresses, to ad platforms through URL parameters or “advanced matching” features.

7. Retention Limitation (Section 25): Old form submissions are a liability

Stop retaining personal data once it no longer serves its purpose. Website form plugins quietly store every submission in the database forever, often duplicating what’s already in your CRM.

Set an auto-delete period for form entries, purge abandoned carts and inactive accounts according to a written retention schedule, and clear old CSV exports from download folders.

8. Transfer Limitation (Section 26): Know where your servers are

If your website is hosted overseas, or your forms send data to a US-based CRM or email platform, you are transferring personal data out of Singapore. You need to ensure the recipient protects it to a standard comparable to the PDPA, usually through contractual clauses in your vendor’s data processing agreement or recognised certifications. Know which vendors touch your data and where they store it, and list them in your privacy policy.

Simple CTA

Contact us to check where are you currently hosting your website.

Simple CTA

9. Access and Correction (Sections 21–22): Give people a way to ask

Individuals can request access to their personal data and how it has been used, and can request corrections. Your website should make this easy: a clearly listed contact method, and ideally an account dashboard where users can view and update their own details. Respond within the timelines the PDPC expects, generally within 30 days.

A practical setup is a cookie banner that explains which categories of trackers you use, with a clear way to decline non-essential ones and a cookie section in your privacy policy. Also check that your form tools don’t leak entered data, such as email addresses, to ad platforms through URL parameters or “advanced matching” features.

10. Data Breach Notification (Part 6A): Have a plan before you need one

If your site is compromised, the clock starts once you have reason to believe a breach occurred. You have 30 days to assess it, and if it’s notifiable (likely significant harm or 500+ people affected), 3 calendar days to notify the PDPC. Your web host and developers are typically “data intermediaries” and must alert you promptly. Make sure your contracts say so, and keep server and access logs so you can actually work out what happened.

Are your website and server logs ready if a breach happens, and who will analyse them?

Let SWBD manage your logs so you're always prepared

11. Accountability (Sections 11–12): Name your DPO

Every organisation must appoint a Data Protection Officer and make that person’s business contact information publicly available. The simplest place to do that is your website’s privacy policy or contact page. A dedicated address like dpo@yourcompany.sg works well.

12. Marketing: DNC and Spam Control

If your website collects phone numbers for marketing calls, SMS or WhatsApp, you must check them against the DNC Registry (results are valid for 30 days) unless you have clear and unambiguous consent. Commercial emails need a working unsubscribe mechanism under the Spam Control Act. Capture that consent cleanly on your forms, and record when and how it was given.

This article is general guidance, not legal advice. For specific situations, refer to the PDPC’s Advisory Guidelines or consult a qualified data protection professional.

Sources

Explore
Drag