---
title: "Singapore PDPA Cross-Border Transfers"
canonical_url: "https://www.sorena.io/artifacts/apac/singapore-pdpa/cross-border-transfers"
source_url: "https://www.sorena.io/artifacts/apac/singapore-pdpa/cross-border-transfers"
author: "Sorena AI"
description: "Official source Singapore PDPA guidance for overseas personal data transfers, comparable protection, ASEAN MCCs, APEC certifications, vendor roles, and evidence records."
published_at: "2026-05-09"
updated_at: "2026-05-09"
keywords:
  - "Singapore PDPA cross-border transfers"
  - "Transfer Limitation Obligation"
  - "comparable protection"
  - "ASEAN MCCs"
  - "APEC CBPR"
  - "APEC PRP"
  - "Singapore PDPA"
  - "Cross-border Transfers"
  - "Transfer Limitation"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# Singapore PDPA Cross-Border Transfers

Official source Singapore PDPA guidance for overseas personal data transfers, comparable protection, ASEAN MCCs, APEC certifications, vendor roles, and evidence records.

*Artifact Guide* *Singapore* *Transfer Limitation*

## Singapore PDPA Cross-Border Transfers

Under the Singapore PDPA, an organisation should treat an overseas personal data transfer as an accountability control: identify when possession or direct control is relinquished, then evidence comparable protection for the overseas recipient.

This page helps structure transfer decisions, contracts, certification checks, vendor role records, and operating controls for Singapore PDPA transfer limitation work.

This guide focuses on the Singapore PDPA Transfer Limitation Obligation for personal data sent outside Singapore. It explains the practical evidence a team should keep before approving an overseas transfer: data flow, recipient role, comparable-protection mechanism, contract or certification support, onward-transfer handling, and review ownership.

## When does the Singapore PDPA transfer limitation rule matter?

Start with the data flow, not the vendor name. The PDPC advisory guidelines explain that section 26 limits transfers to another organisation outside Singapore where the transferring organisation relinquishes possession or direct control over personal data. The examples include transfers to a related company for centralised corporate functions and transfers to an overseas data intermediary for processing.

If the personal data remains in the Singapore organisation's possession or direct control while stored or used overseas, the analysis is different: the organisation still has direct primary obligations under the PDPA data protection provisions, including protection, access and correction, and retention policy coverage for those overseas repositories.

- Record the sender, overseas recipient, destination country or territory, system, personal data categories, transfer purpose, and whether the recipient receives the data as an organisation or as a data intermediary.
- Mark whether the Singapore organisation is relinquishing possession or direct control, or whether it continues to own, lease, operate, or directly maintain the overseas repository.
- Separate transfers to related group companies, cloud or CRM processors, analytics vendors, fulfilment partners, and one-off recipient disclosures because the evidence and contract terms may differ.
- Do not approve a transfer merely because the vendor is reputable; the record should show how the recipient will protect the transferred personal data to a standard comparable to the PDPA.

Sources for this answer:

- [PDPC Advisory Guidelines on Key Concepts in the PDPA](https://www.pdpc.gov.sg/guidelines-and-consultation/2020/03/advisory-guidelines-on-key-concepts-in-the-personal-data-protection-act?ref=sorena.io) - Grounds the transfer trigger: section 26 applies to overseas transfers where an organisation relinquishes possession or direct control, and comparable protection is the core obligation.
- [Personal Data Protection Regulations 2021](https://sso.agc.gov.sg/SL/PDPA2012-S63-2021?ref=sorena.io) - Grounds the regulatory structure for overseas transfers, including requirements for transfer, legally enforceable obligations, and specified certifications.

## What proves comparable protection for an overseas recipient?

The practical decision is whether the recipient is bound by a mechanism that gives the transferred personal data comparable protection. PDPC guidance describes legally enforceable obligations imposed by law, contract, binding corporate rules, or another legally binding instrument. It also recognises specified certifications under the APEC Cross Border Privacy Rules system and APEC Privacy Recognition for Processors system.

For recurring vendor or group transfers, build the approval record around enforceable terms or verified certification rather than informal assurances. PDPC guidance encourages reliance on legally enforceable obligations or specified certifications, especially where there is an ongoing relationship with the recipient.

- For a contract route, keep the executed agreement or data transfer terms, the countries and territories covered, the recipient role, the data categories, the purpose, and the comparable-protection clauses.
- For binding corporate rules, keep the applicable entities, recipient list, countries and territories, rights and obligations, and the assessment that the rules provide comparable PDPA protection.
- For APEC CBPR or APEC PRP, keep the certification type, recipient role, certification status, evidence checked, and any contractual commitment to maintain certification and notify changes.
- If relying on consent, necessity for contract performance, vital interests, national interest, data in transit, or publicly available data, record the exact condition and why a stronger enforceable mechanism or certification is not being used.

Sources for this answer:

- [PDPC Advisory Guidelines on Key Concepts in the PDPA](https://www.pdpc.gov.sg/guidelines-and-consultation/2020/03/advisory-guidelines-on-key-concepts-in-the-personal-data-protection-act?ref=sorena.io) - Grounds the available mechanisms: law, contract, binding corporate rules, legally binding instruments, specified APEC certifications, and limited circumstances where a transfer is taken to satisfy the obligation.
- [Sample Clause for Data Transfers to APEC CBPR and PRP Certified Organisations](https://www.pdpc.gov.sg/help-and-resources/2020/06/sample-clause-for-data-transfers-to-apec-cbpr-and-prp-certified-organisations?ref=sorena.io) - Grounds the evidence expected when using APEC CBPR or PRP certification, including maintaining certification and notifying status changes.

## How should contracts and ASEAN MCCs be used?

For a contractual transfer mechanism, PDPC guidance says the clauses should require the recipient to comply with a comparable standard of protection. For a data intermediary, the minimum areas highlighted in the guidelines include protection, retention limitation, and data breach notification to the organisation without undue delay. For an overseas recipient that is an organisation rather than a data intermediary, the table also includes purpose, accuracy, policies, access, correction, and data breach assessment and notification where relevant.

The ASEAN Model Contractual Clauses are a recognised template for cross-border transfers. PDPC's Singapore guidance says PDPC recognises and encourages their use to fulfil the Transfer Limitation Obligation, while noting that parties may continue using their own compliant contractual templates.

- Select the correct relationship module before drafting: controller-to-processor for a contractor or vendor processing only on behalf of the exporter, and controller-to-controller where the importer processes for its own purposes.
- Include purpose and processing instructions, security and operational measures, retention and deletion handling, breach notice routing, onward-transfer controls, inquiry handling, and the parties responsible for regulator or individual responses.
- For Singapore PDPA use of ASEAN MCCs, consider PDPC's recommended clarifications: include deceased persons where relevant to the PDPA scope, specify breach-notice timing between parties, allocate responsibility for contacting affected individuals, and do not treat the ASEAN MCC addendum as mandatory under the PDPA.
- Keep a clause map that shows which contractual terms satisfy each comparable-protection area, instead of leaving the assessment buried in the contract.

Sources for this answer:

- [PDPC Advisory Guidelines on Key Concepts in the PDPA](https://www.pdpc.gov.sg/guidelines-and-consultation/2020/03/advisory-guidelines-on-key-concepts-in-the-personal-data-protection-act?ref=sorena.io) - Grounds the minimum areas for contractual clauses for data intermediaries and non-intermediary recipient organisations.
- [Singapore Guidance for Use of ASEAN Model Contractual Clauses](https://www.pdpc.gov.sg/help-and-resources/2021/01/asean-data-management-framework-and-model-contractual-clauses-on-cross-border-data-flows/-/media/files/pdpc/pdf-files/practical-guidance-provided-by-pdpc/singapore-guidance-for-use-of-asean-mccs---010921.pdf?ref=sorena.io) - Grounds Singapore-specific PDPC guidance on using ASEAN MCCs to fulfil the Transfer Limitation Obligation and recommended PDPA clarifications.
- [ASEAN Model Contractual Clauses for Cross Border Data Flows](https://asean.org/wp-content/uploads/3-ASEAN-Model-Contractual-Clauses-for-Cross-Border-Data-Flows_Final.pdf?ref=sorena.io) - Grounds the two ASEAN MCC modules and the baseline obligations for cross-border data transfer contracts.

## What vendor role and operating evidence should be retained?

The recipient role matters because Singapore PDPA obligations differ for organisations and data intermediaries. PDPC explains that a data intermediary processes personal data on behalf of another organisation, while an organisation controls the purposes and means of processing. The transfer record should therefore state whether the overseas recipient is acting only on instructions or is receiving the data for its own purposes.

Operational evidence should be usable during vendor review, audit, incident response, and renewal. PDPC accountability guidance supports governance and risk assessment, policies and practices, operational processes, and regular review; apply those same disciplines to the transfer register.

- Maintain a transfer register with recipient role, destination, purpose, data categories, transfer mechanism, contract reference, certification evidence, onward-transfer rules, and review owner.
- For data intermediaries, keep processing instructions, sub-processor or onward-transfer approval rules, protection controls, retention/deletion terms, and breach notification routing back to the organisation.
- For recipient organisations, keep evidence for purpose limitation, accuracy, protection, retention, policies, access, correction, and breach handling where those areas are part of the comparable-protection assessment.
- Review transfer evidence when a vendor changes hosting location, sub-processors, certification status, data categories, role, product purpose, breach process, or contract terms.

Sources for this answer:

- [The Distinction between Organisations and Data Intermediaries and Why It Matters](https://www.pdpc.gov.sg/the-distinction-between-organisations-and-data-intermediaries-and-why-it-matters?ref=sorena.io) - Grounds the organisation versus data intermediary distinction used to decide which transfer contract and evidence controls apply.
- [Accountability Within An Organisation](https://www.pdpc.gov.sg/help-and-resources/2021/09/accountability/accountability-within-an-organisation?ref=sorena.io) - Grounds the governance, policies, processes, and review structure used for transfer evidence management.
- [ASEAN Data Management Framework](https://asean.org/wp-content/uploads/2021/08/ASEAN-Data-Management-Framework.pdf?ref=sorena.io) - Supports operational transfer controls through data inventory, categorisation, safeguards, monitoring, and continuous improvement for data at rest and in transit.

*Recommended next step*

*Placement: after the transfer implementation guidance*

## Turn Singapore PDPA transfer reviews into evidence-backed approvals

Use Sorena to map overseas data flows, classify recipient roles, collect transfer mechanism evidence, and review vendor controls before approving Singapore PDPA cross-border transfers.

- [Open Assessment Autopilot for Singapore PDPA](/solutions/assessment.md): Convert overseas transfer questions into assigned evidence requests, contract checks, and approval records.
- [Review Singapore PDPA source evidence](/solutions/research-copilot.md): Use Research Copilot to answer follow-up transfer questions with cited PDPA and PDPC source material.
- [Talk through implementation](/contact.md): Review transfer scope, vendor roles, comparable-protection evidence, and next implementation actions with Sorena.

## Primary sources

- [PDPC Advisory Guidelines on Key Concepts in the PDPA](https://www.pdpc.gov.sg/guidelines-and-consultation/2020/03/advisory-guidelines-on-key-concepts-in-the-personal-data-protection-act?ref=sorena.io) - Primary official source for the Transfer Limitation Obligation, comparable protection, transfer mechanisms, certification use, contractual clause scope, and data-in-transit treatment.
  - Quote: "Transfer Limitation Obligation"
- [Personal Data Protection Regulations 2021](https://sso.agc.gov.sg/SL/PDPA2012-S63-2021?ref=sorena.io) - Primary regulation source support for transfer requirements, legally enforceable obligations, and specified certifications under the PDPA regulations.
  - Quote: "TRANSFER OF PERSONAL DATA OUTSIDE SINGAPORE"
- [Singapore Guidance for Use of ASEAN Model Contractual Clauses](https://www.pdpc.gov.sg/help-and-resources/2021/01/asean-data-management-framework-and-model-contractual-clauses-on-cross-border-data-flows/-/media/files/pdpc/pdf-files/practical-guidance-provided-by-pdpc/singapore-guidance-for-use-of-asean-mccs---010921.pdf?ref=sorena.io) - Grounds Singapore-specific use of ASEAN MCCs to fulfil the Transfer Limitation Obligation and recommended PDPA clarifications.
  - Quote: "fulfil the Transfer Limitation Obligation"
- [ASEAN Model Contractual Clauses for Cross Border Data Flows](https://asean.org/wp-content/uploads/3-ASEAN-Model-Contractual-Clauses-for-Cross-Border-Data-Flows_Final.pdf?ref=sorena.io) - Grounds the ASEAN MCC transfer modules, baseline clauses, due diligence, onward-transfer handling, and breach notification structure.
  - Quote: "contractual terms and conditions"
- [Sample Clause for Data Transfers to APEC CBPR and PRP Certified Organisations](https://www.pdpc.gov.sg/help-and-resources/2020/06/sample-clause-for-data-transfers-to-apec-cbpr-and-prp-certified-organisations?ref=sorena.io) - Grounds the APEC CBPR and PRP sample clause for comparable protection and certification-status maintenance.
  - Quote: "legally enforceable set of obligations"
- [The Distinction between Organisations and Data Intermediaries and Why It Matters](https://www.pdpc.gov.sg/the-distinction-between-organisations-and-data-intermediaries-and-why-it-matters?ref=sorena.io) - Grounds the role distinction used to classify overseas recipients and decide whether data intermediary or organisation controls apply.
  - Quote: "on behalf of another organisation"
- [Accountability Within An Organisation](https://www.pdpc.gov.sg/help-and-resources/2021/09/accountability/accountability-within-an-organisation?ref=sorena.io) - Grounds operational evidence management through governance, policies, processes, and regular review.
  - Quote: "4 Steps of Accountability"
- [ASEAN Data Management Framework](https://asean.org/wp-content/uploads/2021/08/ASEAN-Data-Management-Framework.pdf?ref=sorena.io) - Grounds data inventory, categorisation, safeguards, monitoring, and continuous improvement for operational transfer controls.
  - Quote: "data at rest as well as data in transit"

## Related Topic Guides

- [Singapore PDPA Anonymisation and DPIA Records](/artifacts/apac/singapore-pdpa/anonymisation-and-dpias.md): Build Singapore PDPA anonymisation and DPIA records around PDPC guidance: release model, re-identification risk, data flows, action plans, safeguards, and monitoring.
- [Singapore PDPA anonymisation FAQ](/artifacts/apac/singapore-pdpa/faq/anonymisation.md): FAQ on anonymisation under the Singapore PDPA: de-identification, pseudonymisation, re-identification risk, when PDPA may no longer apply, and evidence records.
- [Singapore PDPA Applicability Test](/artifacts/apac/singapore-pdpa/applicability-test.md): Test whether Singapore PDPA obligations apply by checking personal data, organisation role, data intermediary status, public agency and individual boundaries, and business contact information.
- [Singapore PDPA Breach Notification Playbook](/artifacts/apac/singapore-pdpa/breach-notification-playbook.md): An official source Singapore PDPA breach-notification playbook covering assessment, notifiable-breach thresholds, PDPC and affected-individual notification steps, roles, records, and citations.
- [Singapore PDPA breach notification thresholds FAQ](/artifacts/apac/singapore-pdpa/faq/breach-thresholds.md): FAQ on Singapore PDPA notifiable data breach tests: significant harm, significant scale, 500 affected individuals, assessment timing, PDPC notices, and affected-individual notices.
- [Singapore PDPA Breach Notification Workflow](/artifacts/apac/singapore-pdpa/breach-notification-workflow.md): An official source Singapore PDPA workflow for containing a personal data breach, assessing notifiability, notifying PDPC or affected individuals, and retaining evidence.
- [Singapore PDPA Compliance Checklist](/artifacts/apac/singapore-pdpa/checklist.md): An official source Singapore PDPA checklist for scope, DPO accountability, consent, data intermediaries, breach notification, DNC checks, transfers, and evidence records.
- [Singapore PDPA Compliance Guide](/artifacts/apac/singapore-pdpa/compliance.md): Build a Singapore PDPA compliance plan covering DPO accountability, consent and notification, protection, retention, access and correction, transfers, breach notification, and DNC checks.
- [Singapore PDPA Consent and Deemed Consent Workflow](/artifacts/apac/singapore-pdpa/consent-and-deemed-consent-selection-workflow.md): Choose express consent, deemed consent by conduct, contractual necessity, notification, or the legitimate interests exception under Singapore PDPA with based ontake fields and evidence records.
- [Singapore PDPA Consent, Notification and Purpose Rules](/artifacts/apac/singapore-pdpa/consent-notification-and-purposes.md): How Singapore PDPA consent, notification, purpose limitation, deemed consent, withdrawal, and consent exceptions should be handled in product and privacy workflows.
- [Singapore PDPA Data Breach Notification Thresholds](/artifacts/apac/singapore-pdpa/breach-notification-thresholds.md): Official source Singapore PDPA breach notification thresholds covering significant harm, the 500-individual significant-scale test, assessment records, and notification timing.
- [Singapore PDPA Data Intermediaries FAQ](/artifacts/apac/singapore-pdpa/faq/data-intermediaries.md): FAQ guidance on Singapore PDPA data intermediary roles, direct obligations, organisation accountability, contracts, retention, protection, and breach escalation.
- [Singapore PDPA Data Intermediary Responsibilities](/artifacts/apac/singapore-pdpa/data-intermediary-responsibilities.md): Practical Singapore PDPA guide to data intermediary role boundaries, organisation accountability, protection, retention, breach escalation, and contract evidence.
- [Singapore PDPA Deadlines and Compliance Calendar](/artifacts/apac/singapore-pdpa/deadlines-and-compliance-calendar.md): An official source Singapore PDPA compliance calendar for breach notification, DNC checks, access and correction requests, retention reviews, and DPMP maintenance.
- [Singapore PDPA Deemed Consent and Legitimate Interests](/artifacts/apac/singapore-pdpa/deemed-consent-and-legitimate-interests.md): How to apply Singapore PDPA deemed consent by conduct, contractual necessity, notification, and legitimate interests with opt-out, adverse-effect, disclosure, and assessment records.
- [Singapore PDPA Deemed Consent FAQ](/artifacts/apac/singapore-pdpa/faq/deemed-consent.md): FAQ on Singapore PDPA deemed consent by conduct, contractual necessity, notification, opt-out periods, adverse-effect assessment, withdrawal, and direct-marketing limits.
- [Singapore PDPA DNC and Marketing Messages Guide](/artifacts/apac/singapore-pdpa/dnc-and-marketing-messages.md): An official source Singapore PDPA guide to DNC checks, specified marketing messages, Singapore telephone numbers, consent evidence, opt-outs, sender duties, and excluded messages.
- [Singapore PDPA DNC checking FAQ: when to check the DNC Registry](/artifacts/apac/singapore-pdpa/faq/dnc-checking.md): FAQ guidance on Singapore PDPA DNC checking: when to check the DNC Registry, which registers apply, 8-digit numbers, 21-day result validity, consent evidence, on-behalf checks, opt-outs, and supported exclusions.
- [Singapore PDPA DNC Marketing Checks](/artifacts/apac/singapore-pdpa/dnc-marketing-checks.md): Operational checklist for Singapore PDPA DNC marketing checks: account evidence, register status, 21-day result validity, consent evidence, and campaign owner records.
- [Singapore PDPA DNC Marketing Workflow](/artifacts/apac/singapore-pdpa/dnc-marketing-workflow.md): Workflow for Singapore PDPA DNC marketing campaigns: classify specified messages, check Singapore telephone numbers, document consent, suppress opt-outs, and approve sends.
- [Singapore PDPA DPIAs: when to run and what to document](/artifacts/apac/singapore-pdpa/faq/dpias.md): FAQ-style implementation guidance on Singapore PDPA DPIAs, including when PDPC guidance recommends them, data-flow mapping, risk treatment, DPO review, and evidence records.
- [Singapore PDPA DPMP Accountability FAQ | DPO, Policies, Evidence](/artifacts/apac/singapore-pdpa/faq/dpmp-accountability.md): FAQ for implementing Singapore PDPA accountability through a DPMP: DPO designation, policies, evidence, training, monitoring, incident logs, and review records.
- [Singapore PDPA DPMP Accountability Guide](/artifacts/apac/singapore-pdpa/dpmp-accountability.md): Build a Singapore PDPA Data Protection Management Programme with DPO ownership, policies, data inventories, DPIAs, training, monitoring, breach logs, and review records.
- [Singapore PDPA FAQ: scope, DPO, consent, breaches and DNC](/artifacts/apac/singapore-pdpa/faq.md): FAQ answers for Singapore PDPA implementation, covering scope, accountability, consent, access and correction, security, retention, transfers, data intermediaries, breach notification, and DNC checks.
- [Singapore PDPA legitimate interests FAQ](/artifacts/apac/singapore-pdpa/faq/legitimate-interests.md): FAQ guidance on Singapore PDPA legitimate interests: assessment fields, adverse effects, mitigation, balancing, disclosure, records, and marketing limits.
- [Singapore PDPA NRIC Handling FAQ](/artifacts/apac/singapore-pdpa/faq/nric-handling.md): FAQ guidance on when Singapore organisations may collect, use, disclose, retain, mask, or replace NRIC and other national identification numbers under PDPC guidance.
- [Singapore PDPA NRIC Handling Rules](/artifacts/apac/singapore-pdpa/nric-handling.md): When Singapore organisations may collect, use, disclose, retain, mask, or replace NRIC numbers under PDPC guidance.
- [Singapore PDPA Penalties and Enforcement Cases](/artifacts/apac/singapore-pdpa/pdpa-penalties-and-enforcement-cases.md): How PDPC enforcement under Singapore's PDPA works: directions, voluntary undertakings, published decisions, financial penalty caps, and implementation lessons from cases.
- [Singapore PDPA Penalties and Fines](/artifacts/apac/singapore-pdpa/penalties-and-fines.md): Singapore PDPA penalty ceilings, PDPC directions, undertakings, breach notification context, and practical controls based on official PDPC and Singapore Statutes sources.
- [Singapore PDPA Privacy Policy Template](/artifacts/apac/singapore-pdpa/pdpa-privacy-policy-template.md): A Singapore PDPA privacy policy template for writing notices, DPO contact details, access and correction routes, retention, transfers, protection, withdrawal, and complaint handling without overclaiming compliance.
- [Singapore PDPA Requirements: Core Obligations](/artifacts/apac/singapore-pdpa/requirements.md): Map Singapore PDPA obligations across consent, notification, access, security, retention, transfers, accountability, breaches, DNC checks, and data intermediaries.
- [Singapore PDPA Scope, Exclusions, and Data Intermediaries](/artifacts/apac/singapore-pdpa/scope-exclusions-and-data-intermediaries.md): Classify Singapore PDPA coverage, business contact information, personal or domestic activity, employee acts, and data intermediary obligations with official source implementation records.
- [Singapore PDPA Transfer Assessment Workflow](/artifacts/apac/singapore-pdpa/transfer-assessment-workflow.md): A Singapore PDPA workflow for assessing overseas personal data transfers, comparable protection, ASEAN MCCs, APEC CBPR/PRP certifications, vendor due diligence, onward transfers, and evidence records.
- [Singapore PDPA Transfer Clauses](/artifacts/apac/singapore-pdpa/transfer-clauses.md): Draft Singapore PDPA transfer clauses for overseas vendors, affiliates, data intermediaries, onward transfers, breach support, ASEAN MCCs, and APEC CBPR or PRP evidence.
- [Singapore PDPA transfer clauses FAQ](/artifacts/apac/singapore-pdpa/faq/transfer-clauses.md): FAQ guidance on Singapore PDPA transfer clauses, comparable protection, ASEAN MCCs, APEC CBPR and PRP certifications, onward transfers, and evidence records.
- [Singapore PDPA Vendor Outsourcing and Contracts](/artifacts/apac/singapore-pdpa/vendor-outsourcing-and-contracts.md): Contract and operating checklist for Singapore PDPA vendor outsourcing: data intermediary status, written terms, security, retention, breach, transfers, sub-contracting, and exit evidence.
- [Singapore PDPA vs GDPR Comparison](/artifacts/apac/singapore-pdpa/singapore-pdpa-vs-gdpr.md): Compare Singapore PDPA and GDPR implementation work across consent, DPO accountability, processors, transfers, breach notification, DNC marketing, rights, retention, and penalties.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/singapore-pdpa/cross-border-transfers.md
