Skip to content

Insight · PDPA

Your client list is personal data. Has anyone at the firm read the PDPA?

The Personal Data Protection Act covers the seminar list, the newsletter, the CRM and the spreadsheet a partner keeps on the side. Penalties run to the higher of SGD 1 million or 10 percent of annual Singapore turnover. The eight-step checklist, the business contact exemption most firms misread, and the breach patterns the PDPC fines.

Gary McRae, management consultant based in Singapore, PMC accredited and CAIG certified

By Gary McRae

Management consultant · Singapore · PMC accredited · CAIG certified

Last reviewed 11 September 2026 · 10 min read

Every firm in Singapore knows the PDPA exists. Fewer have read it, and the firm’s own business development is where the gap shows. Partners’ contacts sit in a CRM nobody consented to. The seminar list becomes the newsletter list. A coordinator pastes a client’s details into a free AI tool to draft an invitation. None of it feels like a breach. The PDPC publishes its enforcement decisions with the organisation named, and that is where it ends up.

This is a working guide for whoever runs business development in the firm, not legal advice. What the firm has to do, where the carve-outs are, and which patterns the regulator already treats as settled. The aim is a firm that can answer a client’s data questionnaire on a Tuesday afternoon without a scramble.

The two mistakes firms make

The first is treating the PDPA as a consent box. Add a tick at the bottom of the form, publish a privacy policy, done. The Act is nine separate obligations running in parallel: consent, purpose limitation, notification, access and correction, accuracy, protection, retention limitation, transfer limitation and accountability. The box covers one of the nine.

The second is misreading the B2B exemption. There is one, and it sits inside the Do Not Call Provisions only. The core Data Protection Provisions apply to any personal data the firm holds, including a general counsel’s name attached to a corporate email. “We only market to businesses” ends at the first PDPC information notice.

Inside the exemption there is a further line. What sits outside the core consent obligations is business contact information: name, title, work email, work phone, used in the person’s role. Behavioural data is different. Who opened which client alert, the CRM’s engagement score, a lookalike audience built from the client list, a model trained on how contacts respond: all of that is processing of personal data and needs consent, even when the underlying contact details are exempt. The exemption covers static identity, not what the firm infers from it.

The eight-step checklist

Eight steps. A month if the data is tidy; longer if it is not. Each one answers a question the PDPC will ask if the firm ever faces an enforcement action.

  1. 01

    Appoint a Data Protection Officer and publish their contact

    Every organisation handling personal data in Singapore must appoint a DPO. The role is statutory. Publish the contact (an email is enough) on the privacy page. In a firm of this size it is usually the practice manager, the COO or a partner. The law does not require a specialist hire. It requires a name.

  2. 02

    Map every place personal data sits

    List every system that touches it: the website forms, the CRM, the email tool, the events platform, the spreadsheets partners keep, the AI tools people use on client work. For each, record what data, why it is held, where it lives and who can see it. The map is the first thing the PDPC asks for in an enforcement action.

  3. 03

    Get clear, affirmative consent at every collection point

    No pre-ticked boxes. No bundled consents, one tickbox covering the newsletter, the seminar follow-up, the partner's call and AI personalisation. Each purpose gets its own checkbox or a clearly worded statement. Record the consent: timestamp, IP, what was shown, what was ticked.

  4. 04

    Honour the eight individual rights without friction

    Access, correction, withdrawal of consent, deletion where consent is the legal basis, purpose limitation, accuracy, transfer restriction, accountability. The PDPC expects a response within 30 days. A data request mailbox nobody monitors is a finding waiting to happen.

  5. 05

    Treat overseas transfers as a real obligation

    Most marketing tools, and most AI tools, process data outside Singapore. The PDPA requires a comparable level of protection through contract clauses or recognised certifications. Free-tier ChatGPT processing a client's emails is the textbook breach. An enterprise tier with a signed Data Processing Addendum (DPA) is acceptable.

  6. 06

    Plan for the 72-hour breach notification window

    Notifiable breaches (significant harm, or 500 or more affected individuals) must be reported to the PDPC within 72 hours of discovery. Affected individuals must also be told unless an exception applies. Write the playbook now: who calls whom, who drafts the notice, who pulls the logs. Discovering this on the day is too late.

  7. 07

    Treat the DNC Registry and the Spam Control Act as separate obligations

    Both sit alongside the PDPA. The Do Not Call Registry mostly covers calls, texts and faxes to consumers in Singapore; the Spam Control Act covers electronic messages with a Singapore link. Both require an unsubscribe mechanism and carry 30-day grace periods. Business-to-business communication has carve-outs, and they are narrower than most firms assume.

  8. 08

    Stop collecting NRIC by 31 December 2026

    The PDPC's NRIC guidance ends general use of NRIC numbers for identification or authentication by the end of 2026. Seminar registrations, gated downloads and mailing list forms cannot ask for one. Replace it with email plus a verification code, or a reference number the firm issues. Audit the forms now. The deadline is hard.

The breach patterns the PDPC fines

  1. Pre-ticked consent boxes. Or one box covering five uses. The PDPC has been clear since 2017: consent must be specific and affirmative. The newer guidance on AI personalisation makes this stricter, not looser.
  2. Repurposed data. A client-service contact moved onto the marketing list without fresh consent. A pitch contact dropped into a nurture sequence. Common, and one of the highest-frequency findings.
  3. Purchased or scraped lists. A vendor’s database cannot transfer consent. The list may legally exist; it does not give the firm the right to market to it.
  4. Overseas transfers without protection. Data flowing to a US-only vendor with no DPA, or to a tool processing in a region the contract does not cover. Free-tier AI tools sit squarely here.
  5. Slow or absent breach response. The 72-hour clock starts on discovery. Firms that investigate first and notify second tend to find the window has closed by the time the matter reaches a partner.
  6. Unhonoured opt-outs. Withdrawal of consent must be processed within a reasonable time (10 days for marketing in practice; 30 under the Spam Control Act). Automation that keeps sending after an unsubscribe is a finding the PDPC takes seriously.

The PDPA does not sit alone

Three other regimes run alongside it for a firm’s marketing, and a fourth if the firm is a law practice.

  • Spam Control Act. Unsolicited electronic messages with a Singapore link: email, SMS, MMS. Requires an unsubscribe mechanism and clear sender identification, whether or not the PDPA’s DNC carve-outs apply.
  • Do Not Call Registry. PDPA Parts 9 and 9A. Mostly consumer phone, text and fax. The B2B carve-out lives here, not in the wider Act.
  • IMDA AI governance frameworks. Voluntary today, increasingly the reference point in enforcement. The Model AI Governance Framework (2024) and the Agentic AI Framework (2026) both meet the PDPA the moment AI touches personal data. Covered in the AI governance essay.
  • Legal Profession (Publicity) Rules. For law practices. They prohibit touting and unverifiable claims, and they are a separate check before any outbound.

The checklist above is sequenced so the PDPA work also covers most of the Spam Control Act and most of the IMDA frameworks. That is the design.

When this stops being a business development problem

Two thresholds change the conversation.

  • The firm handles health, financial or NRIC-equivalent data. Then this is no longer a checklist for the commercial side. It is a privacy programme with a dedicated DPO, external counsel and probably an external assessment. Sectoral rules (MAS, MOH) sit on top of the PDPA.
  • The firm markets across borders at scale. GDPR, US state law, ASEAN data protection rules and Korean PIPA all interact. A firm running campaigns across the region needs a transfer impact assessment, not a PDPA checklist.

If neither applies, the eight steps are enough. Implement in a month, check quarterly, refresh annually.

Frequently asked questions

Does the PDPA apply to B2B marketing in Singapore?

Largely yes, with two layers of nuance. The Do Not Call Provisions (Parts 9 and 9A) generally exclude messages to businesses. Business contact information, a person's work name, title, email and phone used in their role, sits outside the core consent obligations. But behavioural data drawn from those contacts (email click tracking, lead scoring, lookalike profiling, AI personalisation) is processing of personal data and needs consent. And the rest of the Data Protection Provisions (Parts 3 to 6A), covering security, accuracy, retention, transfer and accountability, apply regardless. 'We only market to businesses, so the PDPA does not apply' is a common breach pattern.

Can the firm send cold email to corporate addresses without consent?

Deemed consent applies to business contact information used for purposes related to the recipient's role. Personalised, business-relevant outreach to a corporate email generally qualifies. Personal email addresses do not. Purchased lists do not; a vendor cannot transfer consent. Honour unsubscribes within 10 days. The PDPC's Advisory Guidelines on Requiring Consent for Marketing are the document to cite if the practice is ever challenged.

What are the actual penalties for a PDPA breach?

The maximum financial penalty is the higher of SGD 1 million or 10 percent of annual Singapore turnover. The 10 percent rule applies to organisations with Singapore turnover above SGD 10 million; below that, SGD 1 million is the cap. Egregious cases attract criminal fines and director liability. The PDPC also publishes its enforcement decisions with the organisation named, so in a small market the reputational cost compounds the financial one.

Does the firm need to notify the PDPC about every data breach?

No. Only notifiable breaches: those that cause significant harm to affected individuals, or affect 500 or more people. The threshold has applied since the 2020 amendments. The window is 72 hours from discovery. Most breaches on the marketing side (a misaddressed email, a misconfigured form) will not meet the threshold, and should still be logged internally.

Is using ChatGPT for client communication a PDPA breach?

It depends on the tier and the data. Free ChatGPT: yes, almost always, because OpenAI may train on the data and processing happens outside Singapore without a Data Processing Addendum. ChatGPT Enterprise or Team with a signed DPA and Asia data residency: acceptable, with explicit consent for any AI-based personalisation. The problem is the account configuration, not the tool.

How does the NRIC change affect the firm’s forms?

From 31 December 2026 the firm cannot collect or use NRIC numbers for general identification or authentication. Seminar registrations, gated downloads, event sign-ups and mailing list forms must drop the field. Replace it with email plus a verification code or a reference number the firm issues. Where a regulator requires strong identity verification (financial services, for example), use Singpass or a recognised eKYC vendor.

Sources

This article is general information for the people who run business development in a Singapore firm, not legal advice. For named enforcement actions, sectoral rules (MAS, MOH) or cross-border transfers, consult a Singapore-qualified data protection lawyer.

About the author

Gary McRae is a management consultant in Singapore. MCR.AE is management consultancy for how a professional services partnership wins work: business development, marketing, and who runs both, for firms of 6 to 60 fee earners. He ran digital and marketing technology inside a global law firm, as Associate Director of Marketing: the website, the CRM, the systems the firm paid for, under partner governance, with fee earners as internal clients. 12+ years in Singapore. PMC accredited (SBACC), CAIG certified (NTU).

Find him on LinkedIn.

Put the checklist inside the Review.

The Review looks at how your firm wins work and what its people do with personal data and AI along the way. Four weeks. Written, evidenced, ends in a recommendation. If the firm’s exposure is the only thing that needs fixing, it says so.

Related reading

  • Marketing a Professional Services Firm. Partner, manager, director or consultant. The Singapore cost of each, and the four signals that say the firm needs senior ownership now.
  • Law Firm Business Development. Who actually buys, three channels and no more, PDPA-clean outbound or none, credibility before volume. Five stages in order.
  • AI Governance Framework. Your people use AI on client work. Has anyone written down how? IMDA, PDPC, ASAS, eight risks, a one-page policy.
  • MarTech Audit Framework. Half of what the firm pays for marketing software goes to tools nobody uses. A five-step audit one person runs in a week.
  • The Enterprise Development Grant. EDG closes 29 September 2026. What it funds until then, the seven-step application, and what is published about EDGE.

Work with this thinking