When can an organisation rely on legitimate interests under the Singapore PDPA?
An organisation may rely on the Singapore PDPA legitimate interests exception to collect, use, or disclose personal data without consent only where the identified legitimate interests of the organisation or another person outweigh any adverse effect on the individual.
Treat the exception as a documented justification, not as a default replacement for consent. The assessment should identify the purpose, the personal data involved, how the data will be collected, used, or disclosed, whether the activity is one-off or continuous, who benefits, and why the interest is legitimate in the circumstances.
- Start by confirming that personal data is being collected, used, or disclosed and that no more specific written-law basis or consent exception better fits the facts.
- Describe the legitimate interest and direct benefits, including who benefits and what negative impact may arise if the activity cannot be carried out.
- Do not use the general legitimate interests exception for a purpose of sending marketing messages.
Shows legitimate interests as an exception to consent and states that the general exception applies to collection, use, and disclosure subject to assessment and marketing-message limits.
Supports the core rule that identified legitimate interests must outweigh adverse effects on individuals and that organisations should document the assessment.