Microsoft is retiring SMS and voice MFA. Passkeys become the default on 1 September 2026; SMS and voice switch off on 1 February 2027. Book your free health check
IT Next Door
← All insights
Compliance · 6 min read · Updated August 2026

PDPA: what a small business in Singapore actually has to do

The obligations are lighter than most people fear and broader than most people assume. Here is the practical version.

The Personal Data Protection Act applies to essentially every private organization in Singapore, regardless of size. There is no small-business exemption. The good news is that the practical requirements are manageable, and most of them are things a well-run IT estate does anyway.

This is a plain summary, not legal advice. Where your obligations are unusual — healthcare, finance, or large volumes of sensitive data — take proper advice.

Appoint a Data Protection Officer

Every organization must designate at least one person responsible for data protection compliance, and make their business contact information available. It can be an existing employee; it does not need to be a full-time role. The contact details must be published, typically on your website.

Have a policy, and follow it

You need documented practices covering what personal data you collect, why, how it is protected, how long it is kept and who it is shared with. A privacy policy on the website is the visible part. The internal version is what matters if you are ever asked.

Protect the data

The Protection Obligation requires reasonable security arrangements. In practice, for most businesses, that means:

  • Multi-factor authentication on every account that holds or can reach personal data.
  • Access limited to the people whose role requires it, and reviewed when people change roles or leave.
  • Encryption on laptops and mobile devices, so a lost device is not a breach.
  • Patching and endpoint protection maintained rather than assumed.
  • Backups that have been tested, since availability is part of protection.
  • Staff who can recognize a phishing email, because most breaches start there.

Know your retention position

Personal data must not be kept once the purpose it was collected for has ended and there is no legal reason to retain it. Old employee records, expired candidate CVs and dormant customer databases are the usual offenders. Retention policies in Microsoft Purview can enforce this automatically rather than relying on someone remembering.

Be ready to notify

Since 2021, notification is mandatory for breaches that cause or are likely to cause significant harm to affected individuals, or that are of significant scale — the threshold set in the regulations is 500 or more individuals. The PDPC must be notified as soon as practicable, and no later than three calendar days after you assess the breach to be notifiable. Affected individuals must be told at the same time or after.

The point that catches organizations out is the assessment clock: you are expected to assess a suspected breach expeditiously, generally within 30 days. You cannot delay the notification by delaying the assessment.

Check the Do Not Call registry

If you make marketing calls or send marketing messages to Singapore numbers, you must check the DNC registry first unless you have clear and unambiguous consent in writing. This one produces a steady stream of enforcement actions against small companies.

Where IT fits

Most of the Protection Obligation is technical, and it maps onto things that are already in your Microsoft license: MFA and Conditional Access in Entra, device encryption and compliance in Intune, retention and classification in Purview, audit logging so you can answer what happened to a file. Turning those on is a large part of demonstrating you took reasonable steps.

Ask us about your setup More insights →