Skip to main content

Singapore PDPA (PDPC SG + DNC Register)

Singapore’s Personal Data Protection Act (2012, amended 2020) is an opt-out-flavoured regime: consent may rest on deemed consent, including the deemed-by-business-necessity class the 2020 amendment codifies, and the access-and-correction right runs on a 30-day clock. What separates Singapore from every other APAC market is Part 9, the Do Not Call provisions: marketing calls, SMS, and faxes to +65 numbers must scrub against the national DNC register unless the recipient’s consent is captured in the form Part 9 accepts. The regulator is the Personal Data Protection Commission (PDPC SG), and the duty sits on the organisation sending, not on the platform it sends through. Which basis fits your processing, and whether the DNC register reaches a given campaign, is a judgement for your counsel; Orbit ships the controls that record the answer you reach. The combined Singapore and Thailand PDPA Posture page holds the cross-market obligation map; this page is the Singapore-only checklist and worked sequence. Thailand’s self-standing page is Thailand PDPA.
This page describes Orbit’s platform controls. It is not legal advice. Which PDPA obligations apply to you — deemed consent or express, whether the DNC register reaches your traffic, what basis fits a cross-border transfer — depends on your processing. Confirm with qualified counsel.

The SG checklist

Data-residency posture. Singapore imposes no bright-line localization on most private-sector processing; the 2020 amendment requires a comparable standard of protection on transfers out of Singapore, which is an assessment you run on your transfer basis. For voice, the residency pin (Voice Data Residency) records where recordings physically live, and BYOK (BYOK Customer Managed Keys) carries the localization claim where a buyer or reviewer needs it. Map the whole transfer posture per Data Residency Overview. Sender registration. The SG rows returned by GET /compliance/country-rules?channel=sms typically read recommended for alphanumeric sender IDs, the lightest registration level among the long-tail markets. File the registration through your operator or aggregator and wire its status into your compliance profile before production traffic; the row, not this page, is authoritative, and Country Compliance Requirements documents the read. Sender-format rules live on Singapore SGNIC Sender Rules. KYC document roles. Carrier-facing or aggregator-facing filings attach to the KYC identity model: corporate identity as business_doc, address evidence as address_proof, individual signers as id_proof. Orbit never files a registration on your behalf; it exposes the row and the gate and delivers once the row reports approved. Opt-in aliases. Singapore marketing follows the deemed-consent line: you may send on a disclosed, recorded basis until the recipient opts out, subject to the DNC register. English STOP aliases are the canonical APAC expectation and each reply writes a suppression entry; extend the vocabulary on the Opt-Out Keyword Alias Table where your traffic needs more. Store the consent record with lawful_basis and a purpose string per (contact, channel) pair so the deemed-consent nuance the 2020 amendment codifies is recorded, not assumed. DSAR clock. Access-and-correction requests from Singapore data subjects file under applicable_jurisdiction: "pdpa" — the 30-day clock the DSAR page applies automatically under that code. Erasure outcomes flow into suppression so a deleted +65 contact cannot silently re-enter marketing sends. DST concern. Singapore sits at a fixed UTC+8 with no DST. No statutory quiet-hours window exists; the restraint inherits from carrier practice. Set a recipient-timezone-resolved default (21:00–08:00 SG time) on Quiet-Hours Configuration and validate it with Quiet-Hours Preview. The safety property is timezone fixity, not the window itself.

Worked sequence for a Singapore recipient

Step 1 — capture consent with the basis.
Step 2 — DNC scrub before outbound. Pre-flight the list through GET /compliance/dnc/check and read the source and last_synced_at fields; treat a stale row as a risk flag, not a blocker, per the fail-open caveat on DNC Scrubbing. The feed that refreshes the SG country row carries the register link — see Country Rules Auto-Refresh Feeds. Step 3 — wire withdrawal to suppression. STOP replies, the consent API with opt_in: false, and the preference center all land on one suppression list; a revoked +65 contact stays suppressed regardless of the entry point — Opt-Out & Suppression Lists. Step 4 — file a DSAR on the pdpa clock.
Step 5 — hold the accountability records. File each SG-facing activity in the Privacy Register; record notifications to the PDPC SG in the Breach Incident Register — the notification itself is your act, the attestation records the judgement behind it. When a reviewer asks for the whole program, the Evidence Binder assembles it.