Singapore PDPA (PDPC SG + DNC Register)
Singapore’s Personal Data Protection Act (2012, amended 2020) is an
opt-out-flavoured regime: consent may rest on deemed consent, including
the deemed-by-business-necessity class the 2020 amendment codifies, and
the access-and-correction right runs on a 30-day clock. What separates
Singapore from every other APAC market is Part 9, the Do Not Call
provisions: marketing calls, SMS, and faxes to +65 numbers must scrub
against the national DNC register unless the recipient’s consent is
captured in the form Part 9 accepts. The regulator is the Personal
Data Protection Commission (PDPC SG), and the duty sits on the
organisation sending, not on the platform it sends through. Which basis fits your processing, and
whether the DNC register reaches a given campaign, is a judgement for
your counsel; Orbit ships the controls that record the answer you
reach. The combined
Singapore and Thailand PDPA Posture
page holds the cross-market obligation map; this page is the
Singapore-only checklist and worked sequence. Thailand’s self-standing
page is Thailand PDPA.
This page describes Orbit’s platform controls. It is not legal
advice. Which PDPA obligations apply to you — deemed consent or
express, whether the DNC register reaches your traffic, what basis
fits a cross-border transfer — depends on your processing. Confirm
with qualified counsel.
The SG checklist
Data-residency posture.
Singapore imposes no bright-line localization on most private-sector
processing; the 2020 amendment requires a comparable standard of
protection on transfers out of Singapore, which is an assessment you
run on your transfer basis. For voice, the residency pin
(Voice Data Residency) records
where recordings physically live, and BYOK
(BYOK Customer Managed Keys)
carries the localization claim where a buyer or reviewer needs it.
Map the whole transfer posture per
Data Residency Overview.
Sender registration.
The SG rows returned by
GET /compliance/country-rules?channel=sms typically read
recommended for alphanumeric sender IDs, the lightest registration
level among the long-tail markets. File the registration through your
operator or aggregator and wire its status into your compliance
profile before production traffic; the row, not this page, is
authoritative, and
Country Compliance Requirements
documents the read. Sender-format rules live on
Singapore SGNIC Sender Rules.
KYC document roles.
Carrier-facing or aggregator-facing filings attach to the
KYC identity model: corporate
identity as business_doc, address evidence as address_proof,
individual signers as id_proof. Orbit never files a registration on
your behalf; it exposes the row and the gate and delivers once the row
reports approved.
Opt-in aliases.
Singapore marketing follows the deemed-consent line: you may send on a
disclosed, recorded basis until the recipient opts out, subject to
the DNC register. English STOP aliases are the canonical APAC
expectation and each reply writes a suppression entry; extend the
vocabulary on the
Opt-Out Keyword Alias Table
where your traffic needs more. Store the consent record with
lawful_basis and a purpose string per (contact, channel) pair so
the deemed-consent nuance the 2020 amendment codifies is recorded, not
assumed.
DSAR clock.
Access-and-correction requests from Singapore data subjects file
under applicable_jurisdiction: "pdpa" — the 30-day clock the
DSAR page applies automatically under that code.
Erasure outcomes flow into suppression so a deleted +65 contact
cannot silently re-enter marketing sends.
DST concern.
Singapore sits at a fixed UTC+8 with no DST. No statutory quiet-hours
window exists; the restraint inherits from carrier practice. Set a
recipient-timezone-resolved default (21:00–08:00 SG time) on
Quiet-Hours Configuration and
validate it with
Quiet-Hours Preview. The safety
property is timezone fixity, not the window itself.
Worked sequence for a Singapore recipient
Step 1 — capture consent with the basis.
Step 2 — DNC scrub before outbound. Pre-flight the list through
GET /compliance/dnc/check and read the source and last_synced_at
fields; treat a stale row as a risk flag, not a blocker, per the
fail-open caveat on DNC Scrubbing. The feed
that refreshes the SG country row carries the register link — see
Country Rules Auto-Refresh Feeds.
Step 3 — wire withdrawal to suppression. STOP replies, the
consent API with opt_in: false, and the preference center all land
on one suppression list; a revoked +65 contact stays suppressed
regardless of the entry point —
Opt-Out & Suppression Lists.
Step 4 — file a DSAR on the pdpa clock.
Step 5 — hold the accountability records. File each SG-facing
activity in the Privacy Register;
record notifications to the PDPC SG in the
Breach Incident Register —
the notification itself is your act, the attestation records the
judgement behind it. When a reviewer asks for the whole program, the
Evidence Binder assembles it.