Singapore and Thailand PDPA Posture
Singapore’s Personal Data Protection Act (2012, amended 2020) and Thailand’s Personal Data Protection Act B.E. 2562 (in force since 2022) share a design: a personal-data regime with a consent requirement at collection, an access-and-correction right on roughly a 30-day clock, and — in Singapore’s case — a separate Do Not Call (DNC) register that gates outbound marketing calls, SMS, and faxes to +65 numbers. Thailand runs a consent-led regime administered by the Personal Data Protection Committee (PDPC Thailand); Singapore’s regulator is the Personal Data Protection Commission (PDPC SG). Both are deemed-consent, opt-out-flavoured regimes compared with the EU’s opt-in strictness — Singapore’s PDPA since the 2020 amendment even codifies a deemed-by-business-necessity class — but that latitude is a judgement about your facts, made by your counsel, not a default Orbit assumes. PDPA places the duty on the organisation, not the platform. Orbit never mandates your Singapore or Thailand posture — it gives you the tenant-controlled consent ledger, the suppression layer, the DNC scrub chain, the DSAR pipeline with a codedpdpa jurisdiction, and the privacy register.
This page maps each PDPA obligation to the surface you already have so
a PDPC questionnaire or a Thai regulator review reads the evidence from
your own configuration.
The PDPA surface map
One row per obligation a Singapore or Thailand operator usually has to answer, mapped to the Orbit control that holds it and the deep page that documents it. This table mirrors “The GDPR surface map” on the GDPR posture guide — the same controls, read against a different statute.
Two adjacent controls round out the map:
- Quiet hours. No PDPA provision names them, but an SG or TH marketing program inherits the expectation from the carriers and the local marketing regimes — set the fallback window with the rest (Quiet hours configuration).
- Voice data residency. SG and TH transfers are assessments you run on your transfer basis; the residency pin (Voice data residency) records where recordings physically live.
Section 2 — A worked sequence for a Singapore recipient
A tenant running SMS plus voice outbound into Singapore reads as this sequence. Each step is a tenant-owned decision Orbit enforces; none is a platform mandate. Step 1 — posture. For deemed-consent or opt-out-based SG marketing, keepunknown_marketing_policy: allow_with_logging (so the send runs
and the ledger records the unbacked contact) but move
consent_default_policy: deny_on_missing where you want the stricter
line — for example on channels where you cannot show any consent basis.
The two knobs are tenant-owned — see
Consent Posture: The Unknown-Consent Policies.
Step 2 — capture consent with the basis. At acquisition, record the
grant with lawful_basis and a purpose string (PDPA’s consent duty
turns on the disclosed purpose):
source and last_synced_at fields and treat a
stale row as a risk flag, not a blocker (the fail-open caveat is
documented on DNC Scrubbing). The feed that
refreshes the per-country rules rows carries the SG register link — see
Country Rules Auto-Refresh Feeds.
Step 4 — wire withdrawal to the same suppression list. STOP
keywords, the consent API with opt_in: false, and the preference
center all land on one list. A revoked +65 contact stays suppressed
regardless of which entry point they used.
Step 5 — file a DSAR with the pdpa clock. When an SG data subject
asks for access or correction, file it under the coded jurisdiction so
the SLA tracker applies the 30-day clock automatically:
Section 3 — A worked sequence for a Thailand recipient
Thailand’s PDPA reads closer to the EU shape — express consent at collection, a rights chapter administered by the PDPC Thailand, and explicit RoPA-class records duties (s39–41). The sequence: Step 1 — posture. Express-consent markets call for the strict line: keepunknown_marketing_policy: refuse and
consent_default_policy: deny_on_missing for TH recipients, so an
unbacked contact receives no marketing.
Step 2 — capture consent with the basis. Record the grant explicitly
per channel, lawful_basis: consent, and the purpose string your TH
notice disclosed:
last_synced_at stayed fresh.
Step 4 — DSAR on the same pdpa code. TH data subjects file under
the same coded jurisdiction; the 30-day SLA clock tracks the request
with or without an SG/TH split:
Section 4 — What Orbit does NOT do
Boundary conditions, stated once and plainly:- Orbit never files with the PDPC for you. A breach notification to the Singapore PDPC (or the equivalent Thai filing) is your act — the breach register’s attestation records the judgement behind the notification, but the notification itself is yours.
- Orbit never decides whether deemed consent applies, or which basis fits. Deemed consent, business-necessity consent, legitimate interests — the legal analysis is counsel’s. The consent ledger records the basis you assert; the judgement it captures is yours.
- Orbit never scrubs your outbound against a register automatically in a way you cannot see. The DNC check answers source and freshness explicitly, fails open when a source is stale, and applies the gates you enabled. A failing scrub because the org toggle is off is a configuration fact, not a platform mandate — the strict-tenant rule applies to every control except the US federal voice window.
- Nothing on this page gates sending by itself. Consent records, the suppression layer, the DSAR pipeline, and the register are the ledger. The send-time gates that exist are the ones you turned on, and each defaults open.
- This is not legal advice. The sequence assembles Orbit’s controls; whether the assembled posture satisfies the SG or TH PDPA for your processing is a call for your counsel.
Section 5 — Related references
- Posture overview — the toggle map this page extends for SG/TH.
- Privacy Register — the Art.30-analog activity filings the PDPC stores read first.
- DNC Scrubbing: Sources, Freshness, and the Check Endpoint — the pre-flight the SG outbound sequence wires.
- Country Rules Auto-Refresh Feeds — what keeps the SG and TH country rows current.
- DSAR — the operator verb set, the coded jurisdictions
(including
pdpaat 30 days), and the proof-of-deletion certificate. - Consent Management — the lawful-basis fields the SG/TH consent records rest on.
- Consent Posture: The Unknown-Consent Policies — the two posture knobs that separate the SG opt-out line from the TH express-consent line.
- Evidence Binder — the export that reads everything above when a regulator or buyer asks for the full program.