FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
51of51items
Across 10 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Singapore PDPA Deemed Consent

What must be done before relying on deemed consent by notification?

Before using deemed consent by notification, the team should write a purpose-specific assessment. PDPC's Annex B checklist says the assessment should minimally cover the purpose, the appropriateness of notification, the reasonableness of the opt-out mode and period, likely adverse effects, and the final decision outcome.

The notification should bring the intended collection, use, or disclosure, the purpose, and the opt-out method and period to the individual's attention. Direct channels such as email, SMS, push notification, portal notice, or regular customer communications are stronger when they are likely to reach the affected individuals; mass communication needs stronger justification.

  • Define the purpose, data fields, collection/use/disclosure path, objective, and whether the activity is one-off or continuous.
  • Choose a notification channel that individuals are likely to see and keep a copy of the notice, audience, send date, and contact details offered for queries.
  • Set an opt-out period that reflects the purpose, time sensitivity, communication channel, and ease of the opt-out method; consent is deemed only after the opt-out period has lapsed.
Citations
Singapore PDPA Deemed Consent

How should teams assess adverse effects and keep evidence?

For deemed consent by notification, the assessment must identify likely adverse effects, mitigation measures, and any residual adverse effects. PDPC guidance describes adverse effect broadly, including physical harm, harassment, serious alarm, distress, and decisions or predictions that may affect individuals.

If residual adverse effects remain after mitigation, the organisation should not rely on deemed consent by notification for that purpose. Keep the assessment for the whole period during which the organisation collects, uses, or discloses personal data based on that deemed-consent route.

  • Assess sensitivity of the personal data, scale and frequency of processing, vulnerable individuals, likely impact, prediction or decision logic, and safeguards.
  • Document mitigation such as data minimisation, access controls, functional separation, encryption, deletion after use, or other technical and organisational measures.
  • Retain the completed assessment, notification copy, opt-out records, decision outcome, completion date, and management endorsement where appropriate.
Citations
Singapore PDPA Deemed Consent

What happens if an individual opts out or withdraws consent later?

For deemed consent by notification, the individual must be given a reasonable way and period to opt out before the processing starts. If the individual opts out within that period, do not start the notified collection, use, or disclosure for that individual.

After the opt-out period has passed, an individual can still withdraw consent. The organisation should allow and facilitate withdrawal, explain likely consequences, cease the relevant collection, use, or disclosure, and cause its data intermediaries and agents to cease unless continued processing is required or authorised under the PDPA or another written law.

  • Make the withdrawal route clear, including the purpose or channel covered by the withdrawal.
  • Separate optional purposes from purposes necessary to provide the product or service.
  • Do not treat withdrawal as an automatic deletion request; handle retention separately under the relevant PDPA obligations.
Citations
Singapore PDPA Deemed Consent

Can deemed consent by notification be used for direct marketing?

No. PDPC guidance states that the Personal Data Protection Regulations 2021 prescribe that deemed consent by notification does not apply to sending direct marketing messages. Obtain consent that satisfies the PDPA for the marketing purpose instead of relying on silence, an opt-out notice, or a pre-checked box.

For specified marketing messages sent to Singapore telephone numbers by voice call, text, or fax, the DNC provisions also apply. The sender must check the relevant DNC Register unless it has clear and unambiguous consent in evidential form from the user or subscriber, and the message must include sender identification and contact information.

  • Do not use deemed consent by notification to justify direct marketing sends.
  • Do not treat opt-out consent as clear and unambiguous DNC consent.
  • Keep DNC check evidence or clear, unambiguous consent records separately from the deemed-consent assessment.
Citations
Singapore PDPA DNC checking FAQ: when to check the DNC Registry

When must a team check the Singapore DNC Registry before sending marketing messages?

A team should check the DNC Registry before sending a specified marketing voice call, text message, or fax to a Singapore telephone number unless it has clear and unambiguous consent in evidential form for that message to that number, or the message is outside the DNC checking duty because a supported exclusion applies.

Do the check at campaign execution time, not only when a lead is first collected. PDPC guidance says the check is tied to sending the specified message, and DNC Registry results are valid for 21 days from receipt. If the campaign will continue after that window, recheck before continuing telemarketing activity.

Treat third-party lead lists the same way: the sender still needs either usable consent evidence for that sender and number, or a current DNC result showing the number is not listed in the relevant register.

  • For voice campaigns, check the No Voice Call Register unless clear and unambiguous consent or a supported exclusion applies.
  • For SMS, MMS, and other text campaigns sent to Singapore telephone numbers, check the No Text Message Register unless clear and unambiguous consent or a supported exclusion applies.
  • For fax campaigns, check the No Fax Message Register unless clear and unambiguous consent or a supported exclusion applies.
  • Record the result receipt date because the 21-day validity window runs from receipt of results, not from list upload or campaign planning.
Citations
Singapore PDPA DNC checking FAQ: when to check the DNC Registry

Which DNC registers and telephone-number format should campaign systems use?

Route the campaign channel to the matching register: No Voice Call Register for phone calls, No Text Message Register for texts including SMS and MMS, and No Fax Message Register for faxes. PDPC's business-rules page also says submitted numbers are checked against all three registers, so store the per-register status instead of reducing the result to a single allowed or blocked flag.

For system validation, the DNC checking interface accepts only 8-digit numbers starting with 3, 6, 8, or 9. Reject, normalize, or manually review other formats before upload so rejected numbers are not mistaken for cleared numbers.

For small checks, PDPC describes Small Number Lookup for up to 10 telephone numbers with immediate results. For larger lists, PDPC describes Bulk Filtering using a CSV file with a single column of 8-digit telephone numbers, with results available within 24 hours.

  • Store the original campaign channel, the submitted 8-digit number, the DNC result for each register, and any rejected-number reason.
  • Do not treat a rejected or invalid-format number as approved for sending.
  • Use the result receipt timestamp to calculate the end of the 21-day validity window for that campaign run.
Citations
Singapore PDPA DNC checking FAQ: when to check the DNC Registry

What consent evidence can replace a DNC check for a Singapore telephone number?

Consent can replace a DNC check only when it is clear, unambiguous, tied to the Singapore telephone number and message channel, and evidenced in written or other retrievable form. A broad marketing-purpose clause or a customer's failure to opt out is weak support if it does not clearly say that specified messages will be sent to the number.

Keep the evidence for as long as the organisation intends to rely on that consent for sending specified messages. For electronic consent, PDPC guidance points to retaining the individual's choice, the date and time of the choice, the webpage or form shown at the time, and the clauses or terms accepted.

If a user withdraws consent, stop relying on that consent for the scope of the withdrawal after the prescribed period and use a DNC check or another valid basis before sending further specified messages.

  • Keep the consent statement, channel scope, number captured, positive action, timestamp, and source system.
  • For third-party leads, keep evidence showing the individual consented to this sender sending specified messages to that number, or run the DNC check before sending.
  • Do not infer clear and unambiguous consent from silence, pre-ticked assumptions, or generic marketing wording.
Citations
Singapore PDPA DNC checking FAQ: when to check the DNC Registry

How should teams handle on-behalf checks, vendors, and third-party checkers?

If an account holder checks the DNC Registry on behalf of another organisation, PDPC's business-rules page says the organisation names should be indicated during account creation and can be amended later. For bulk filtering, retain the On Behalf List output because it records the organisations on whose behalf the check was conducted at submission time.

Do not assume outsourcing removes sender responsibility. PDPC guidance treats the person who actually sends, causes, or authorises the specified message as a sender. A brand, marketing agency, and call centre can all fall within the sender analysis depending on the arrangement.

For third-party DNC checkers, keep the checker output, date received, expiry date, and accuracy assurances. PDPC's business page notes that it does not endorse third-party checkers and says liability is on third-party checkers for DNC infringements resulting from erroneous information.

  • Contractually require vendors to use the correct campaign channel, DNC register result, and 21-day validity window.
  • Keep the on-behalf declaration and output with the campaign approval record.
  • Escalate any campaign where the brand, agency, and call centre disagree about who authorised the message or which entity's consent evidence is being relied on.
Citations
Singapore PDPA DNC checking FAQ: when to check the DNC Registry

How should opt-outs and excluded messages affect DNC checking?

Opt-outs must be handled separately from DNC checking. PDPC's business page says organisations must provide opt-out information using the same medium and have 21 days after receiving an opt-out request to ensure marketing messages are no longer sent to the individual's telephone number.

A later DNC result should not override an opt-out or withdrawal record. If a person has withdrawn consent or opted out for the relevant sender, number, and channel, suppress the number for that scope even if a register check would otherwise allow sending.

Excluded messages should be used narrowly. Official source examples include service or reminder messages for services bought by the individual, market survey or research messages, charitable or religious causes, and B2B messages sent to an organisation for the receiving organisation's purposes. The DNC advisory also warns that if a message mixes an excluded purpose with a non-excluded marketing purpose, it can still be a specified message requiring DNC compliance.

A successful DNC check only addresses the register-checking duty. A covered message must still meet the DNC sender-identification and contact-information rules, voice calls must not conceal calling-line identity, and the organisation must separately comply with the PDPA data protection provisions for using the telephone number.

  • Keep opt-out source, timestamp, channel, number, sender, and scope so suppression rules match the request.
  • Classify service, survey, charitable, religious, and B2B messages before campaign launch, and reclassify if promotional copy is added.
  • For ongoing-relationship text or fax exemptions, verify the supported conditions before relying on them, including whether the recipient has withdrawn consent, opted out, or otherwise indicated no consent.
  • Before sending, verify the sender name, contact route, and calling-line identity controls as well as the DNC result.
Citations
Singapore PDPA DPIAs: when to run and what to document

Are DPIAs mandatory under the Singapore PDPA?

PDPC guidance does not frame a DPIA as a standalone statutory obligation where failing to run one is automatically a PDPA breach. The guidance says organisations may use DPIAs, Data Protection by Design, and Data Protection Management Programmes to demonstrate accountability in appropriate circumstances.

That distinction matters for implementation. The practical question is whether the project creates personal data handling risks that should be identified, assessed, treated, approved, and monitored before launch or major change. A missing DPIA can still matter if the organisation fails to recognise and address risks that affect other PDPA obligations, such as protection of personal data.

PDPC's DPIA guide is general, non-exhaustive guidance. It says organisations should adapt the method to their sector, business, and operational circumstances, and that following the guide does not by itself establish PDPA compliance.

  • Do not describe DPIAs as a universal PDPA filing requirement unless a separate sector, contract, customer, or internal policy requires one.
  • Do run a DPIA where the project needs a defensible record of personal data risks, controls, risk owners, and approvals.
  • Use the DPIA to show how privacy-by-design controls were considered before the system, process, product, or service was implemented.
  • Check separate sector rules, contractual commitments, and internal approval policies because they may make an assessment mandatory even though the PDPA does not impose a universal DPIA filing duty.
Citations
Singapore PDPA DPIAs: when to run and what to document

When should a team conduct or refresh a Singapore PDPA DPIA?

PDPC guidance points to DPIAs when a new system or process handles personal data, when an existing system or process is substantially redesigned, when the organisation starts collecting new types of personal data, or when organisational changes affect the department handling personal data.

A DPIA should also be revisited when the risk picture changes. Examples supported by PDPC guidance include changes to the project purpose or context, the types of personal data collected, how processing is conducted, new security vulnerabilities, or broader legislative or environmental changes.

  • Trigger the DPIA intake before design is finalised, because retrofitting controls after implementation can increase cost and effort.
  • Run one DPIA for similar projects only when their purpose, scope, and context are similar enough for the same assessment to be meaningful.
  • Refresh the DPIA when new data touchpoints, vendors, purposes, technologies, or processing steps change the personal data risk assessment.
Citations
Singapore PDPA DPIAs: when to run and what to document

What should the DPIA cover for personal data and data flows?

The DPIA should start with the concrete system or process. Record the project description, the scope of the assessment, the parties involved, and the methodology for rating risks. Then identify the personal data handled, why it is collected, who can access it, where and how it is stored, how it is used, who it is disclosed or transferred to, how long it is retained, and how it is disposed.

For product and engineering teams, the useful output is a data-flow record that follows the personal data lifecycle from collection through storage, use, disclosure, transfer, archival, and disposal. That record should be specific enough for the DPO, security, legal, operations, and vendor owners to challenge inaccurate assumptions.

  • Map collection points, notice and consent touchpoints, compulsory and optional fields, and the purpose for each type of personal data.
  • Map internal users, access levels, databases, files, manual handling, vendor disclosures, overseas transfers, retention periods, and disposal methods.
  • Attach project plans, contracts, functional specifications, security assessments, screenshots, workflow diagrams, and vendor documents used to verify the data flow.
Citations
Data Flow Illustration

Supports using lifecycle stages such as collection, storage, use, disclosure, transfer, archival, and disposal when documenting data flows.

Singapore PDPA DPIAs: when to run and what to document

How should teams assess and treat risks in a Singapore PDPA DPIA?

After the data flow is mapped, assess the project against PDPA requirements and data protection best practices. PDPC's sample questions cover consent, notification, purpose limitation, accuracy, access and correction, protection, third-party disclosure, overseas transfer, retention, disposal, breach response, and accountability.

The action plan should translate each risk into treatment work. For each gap, record the recommended control, owner, implementation timeline, monitoring plan, and any justification for accepting, prioritising, or sequencing the risk treatment. PDPC guidance recognises that the treatment approach depends on the risk assessment and the organisation's operational, resource, legal, and regulatory circumstances.

  • Use likelihood and impact criteria that fit the organisation, and document why the selected risk rating is appropriate.
  • Treat high-priority risks with concrete controls such as consent withdrawal processes, access controls, encryption, security review, vendor contract terms, retention schedules, or staff training.
  • Do not leave a DPIA at issue discovery; assign action owners and implementation timelines, then monitor whether the actions actually address the risk.
Citations
Singapore PDPA DPIAs: when to run and what to document

Who should review a Singapore PDPA DPIA and what evidence should be kept?

PDPC guidance says an effective DPIA should involve relevant stakeholders, and the DPIA lead should ideally be the project manager or the organisation's Data Protection Officer. The DPO advises throughout the process, helps define and apply the risk assessment framework, reviews the DPIA report before management submission, and assists with review when personal data risks change.

Keep a DPIA report and action-plan evidence pack. The report should explain the scope, planning, findings, proposed action plan, and approach for treating risks. The evidence pack should include the data-flow map, risk ratings, questionnaire responses, source documents, DPO review, management approval, action-owner tickets, vendor or contract updates, control evidence, monitoring results, and later review notes.

  • Assign a DPIA lead, DPO reviewer, management approver, and action owners for legal, security, product, operations, vendor, and customer-facing changes.
  • Record DPO comments and management approval before implementation where the DPIA produces a material action plan.
  • Update the record when risk changes, not only on a fixed review date.
Citations
Singapore PDPA DPMP Accountability

What does Singapore PDPA accountability require in a DPMP?

A privacy notice alone does not meet the Accountability Obligation. The PDPA requires an organisation to designate one or more individuals responsible for PDPA compliance, develop and implement the policies and practices needed to meet its obligations, and make information about those policies and practices available on request. PDPC guidance recommends staff training, monitoring, and review as ways to put those duties into operation.

A practical DPMP turns the legal duties and supporting governance measures into records: the DPO appointment, policy owner and approver, data inventory or flow diagram, risk register, training plan, incident log, management reporting cycle, and review triggers.

  • Name the DPO or DPO team, their reporting line, and the senior management owner who can remove blockers.
  • Keep internal policies for staff and operational teams, plus external-facing information that individuals can use to understand practices and complaints handling.
  • Maintain evidence that policies were approved, communicated, implemented, monitored, and reviewed.
Citations
Page 2 of 4