---
title: "Singapore PDPA vs GDPR Comparison"
canonical_url: "https://www.sorena.io/artifacts/apac/singapore-pdpa/singapore-pdpa-vs-gdpr"
source_url: "https://www.sorena.io/artifacts/apac/singapore-pdpa/singapore-pdpa-vs-gdpr"
author: "Sorena AI"
description: "Compare Singapore PDPA and GDPR implementation work across consent, DPO accountability, processors, transfers, breach notification, DNC marketing, rights, retention, and penalties."
published_at: "2026-05-09"
updated_at: "2026-05-09"
keywords:
  - "Singapore PDPA vs GDPR"
  - "PDPA comparison"
  - "GDPR SCCs"
  - "Singapore data protection"
  - "Singapore PDPA"
  - "GDPR"
  - "Data protection"
  - "Cross-border transfers"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# Singapore PDPA vs GDPR Comparison

Compare Singapore PDPA and GDPR implementation work across consent, DPO accountability, processors, transfers, breach notification, DNC marketing, rights, retention, and penalties.

*Comparison* *Singapore* *PDPA vs GDPR*

## Singapore PDPA vs GDPR

Singapore PDPA work should not be copied into a GDPR control set without checking the role, purpose, transfer mechanism, notification clock, marketing channel, and evidence standard.

This comparison helps separate Singapore-specific PDPA duties from GDPR transfer and SCC evidence that the cited source material supports.

This page compares practical implementation differences between Singapore's Personal Data Protection Act 2012 and GDPR-linked transfer obligations that are supported by the available ASEAN/EU source material. It focuses on the work product teams actually need: purpose and consent records, DPO/accountability evidence, data intermediary or processor terms, breach escalation, DNC marketing checks, access and correction handling, retention decisions, transfer mechanisms, and penalty escalation.

## Singapore PDPA vs GDPR: implementation differences that matter

Compare the Singapore PDPA control record against GDPR-linked transfer evidence without assuming that one regime's paperwork satisfies the other.

- **Singapore PDPA**: Use the Singapore column to build PDPA-specific evidence for purposes, consent or exceptions, DPO/accountability, data intermediaries, breach notification, DNC marketing, rights, retention, transfers, and PDPC enforcement.
- **GDPR**: Treat the GDPR column only for the comparator points supported by the cited sources, especially EU SCC transfer evidence and GDPR references included in the ASEAN/EU Joint Guide.

| Dimension | Singapore PDPA | GDPR | Operational implication | Sources |
| --- | --- | --- | --- | --- |
| Scope boundary | The PDPA analysis starts with the collection, use, or disclosure purpose. Record the notified purpose, consent basis, deemed-consent route, exception, withdrawal impact, and whether a reasonable person would consider the purpose appropriate. | For EU SCC transfers, the Joint Guide notes that the data exporter must comply with the GDPR, including Article 6 legal basis, and that transferred data should be adequate, relevant, and limited to what is necessary for the transfer purpose. | Do not reduce both regimes to a single consent checkbox. Keep a Singapore purpose/consent note and, for EU transfers, a separate GDPR legal-basis and data-minimisation note tied to the SCC transfer. | [Advisory Guidelines on Key Concepts in the Personal Data Protection Act](https://www.pdpc.gov.sg/guidelines-and-consultation/2020/03/advisory-guidelines-on-key-concepts-in-the-personal-data-protection-act?ref=sorena.io) - Supports the Singapore consent, notification, purpose limitation, deemed-consent, and withdrawal framing.<br>[Joint Guide to ASEAN Model Contractual Clauses and EU Standard Contractual Clauses](https://asean.org/wp-content/uploads/3-ASEAN-Model-Contractual-Clauses-for-Cross-Border-Data-Flows_Final.pdf?ref=sorena.io) - Supports the GDPR SCC transfer references to Article 6 legal basis and Article 5(1)(c) data minimisation.<br>[Personal Data Protection Regulations 2021](https://sso.agc.gov.sg/SL/PDPA2012-S63-2021?ref=sorena.io) - Supports Singapore procedures for deemed consent by notification and legitimate interests assessments. |
| Covered actors | A Singapore data intermediary that processes personal data for another organisation under a written or evidenced contract is directly subject to protection, retention, and breach-notification duties, while the organisation remains responsible for other PDPA obligations and for transfer limitation. | For EU SCC controller-to-processor transfers, the Joint Guide describes SCC module evidence such as importer instructions, technical and organisational measures, documentation, audits, sub-processing, and supervisory-authority cooperation. | Map vendors twice: Singapore data intermediary scope and contract evidence on one side; EU SCC module, exporter/importer role, audit, documentation, and sub-processor evidence on the other. | [Guide to Managing Data Intermediaries](https://www.pdpc.gov.sg/help-and-resources/2020/09/guide-to-managing-data-intermediaries?ref=sorena.io) - Supports the Singapore DC/DI lifecycle, written contract, service management, incident escalation, monitoring, audit, and exit-management expectations.<br>[Joint Guide to ASEAN Model Contractual Clauses and EU Standard Contractual Clauses](https://asean.org/wp-content/uploads/3-ASEAN-Model-Contractual-Clauses-for-Cross-Border-Data-Flows_Final.pdf?ref=sorena.io) - Supports the EU SCC controller-to-processor comparison, including documentation, audits, authority cooperation, and processor instructions.<br>[Advisory Guidelines on Key Concepts in the Personal Data Protection Act](https://www.pdpc.gov.sg/guidelines-and-consultation/2020/03/advisory-guidelines-on-key-concepts-in-the-personal-data-protection-act?ref=sorena.io) - Supports the Singapore point that data intermediaries have limited direct PDPA obligations while the organisation remains responsible for the wider PDPA compliance set. |
| Trigger | Singapore organisations must designate one or more individuals responsible for PDPA compliance, make business contact information available, and maintain data protection policies and practices. The organisation remains responsible even when duties are delegated. | The cited sources do not include an official GDPR DPO article. For this page, do not infer GDPR DPO appointment criteria from Singapore's DPO/accountability rule; verify GDPR DPO scope separately before reusing the same owner. | A Singapore DPO appointment and contact-publication record is useful evidence for PDPA accountability, but it is not enough by itself to prove GDPR DPO compliance. | [Advisory Guidelines on Key Concepts in the Personal Data Protection Act](https://www.pdpc.gov.sg/guidelines-and-consultation/2020/03/advisory-guidelines-on-key-concepts-in-the-personal-data-protection-act?ref=sorena.io) - Supports the Singapore DPO designation, business contact, delegation, and organisational accountability statements.<br>[Joint Guide to ASEAN Model Contractual Clauses and EU Standard Contractual Clauses](https://asean.org/wp-content/uploads/3-ASEAN-Model-Contractual-Clauses-for-Cross-Border-Data-Flows_Final.pdf?ref=sorena.io) - Supports only GDPR-side SCC accountability evidence, such as documentation and supervisory-authority cooperation, not a general GDPR DPO appointment rule.<br>[Guide to Accountability under the Personal Data Protection Act](https://www.pdpc.gov.sg/help-and-resources/2019/07/guide-to-accountability-under-the-personal-data-protection-act?ref=sorena.io) - Supports treating accountability as demonstrable organisational measures rather than only a named person. |
| Core obligations | The PDPA transfer limitation rule requires overseas recipients to be protected to a comparable PDPA standard through prescribed requirements, legally enforceable obligations, specified certifications, or supported alternatives such as consent with a written summary where applicable. | For GDPR-linked transfers, the cited-source comparison is EU SCC work: parties complete transfer appendices, identify exporter/importer details, describe transferred data and purpose, specify technical and organisational measures, and document local-law assessments where required. | Do not assume ASEAN MCCs, Singapore transfer clauses, and EU SCCs are interchangeable. Each transfer packet needs the correct mechanism, parties, appendix, safeguards, and assessment record. | [Advisory Guidelines on Key Concepts in the Personal Data Protection Act](https://www.pdpc.gov.sg/guidelines-and-consultation/2020/03/advisory-guidelines-on-key-concepts-in-the-personal-data-protection-act?ref=sorena.io) - Supports the Singapore transfer limitation explanation, comparable-protection standard, contracts, binding corporate rules, specified certifications, and ASEAN MCC references.<br>[Personal Data Protection Regulations 2021](https://sso.agc.gov.sg/SL/PDPA2012-S63-2021?ref=sorena.io) - Supports the statutory transfer-regulation categories for overseas transfers.<br>[Joint Guide to ASEAN Model Contractual Clauses and EU Standard Contractual Clauses](https://asean.org/wp-content/uploads/3-ASEAN-Model-Contractual-Clauses-for-Cross-Border-Data-Flows_Final.pdf?ref=sorena.io) - Supports EU SCC transfer appendices, data exporter/importer information, purpose, technical and organisational measures, and SCC local-law assessment evidence.<br>[ASEAN Model Contractual Clauses for Cross Border Data Flows](https://asean.org/wp-content/uploads/3-ASEAN-Model-Contractual-Clauses-for-Cross-Border-Data-Flows_Final.pdf?ref=sorena.io) - Supports the point that ASEAN MCCs are voluntary contractual clauses and may be adapted or supplemented for transfer contexts. |
| Evidence record | For Singapore, assess whether the breach is notifiable because it results in significant harm or affects at least 500 individuals. Notify PDPC as soon as practicable, and no later than 3 calendar days after determining that the breach is notifiable; notify affected individuals where required. | Under EU SCC transfer clauses in the Joint Guide, the data importer must address and mitigate breach effects, notify the exporter and competent supervisory authority when risk to rights and freedoms is likely, notify data subjects in high-risk cases with the exporter, and document breach facts and remedial action. | Run separate breach clocks and content checklists: Singapore notifiability and PDPC/individual notice on one side; SCC importer/exporter, supervisory-authority, data-subject, and documentation duties on the other. | [Personal Data Protection (Notification of Data Breaches) Regulations 2021](https://sso.agc.gov.sg/SL/PDPA2012-S64-2021?ref=sorena.io) - Supports significant-harm categories, the 500-individual significant-scale threshold, and required PDPC and affected-individual notification content.<br>[Guide on Managing and Notifying Data Breaches Under the PDPA](https://www.pdpc.gov.sg/help-and-resources/2021/01/data-breach-management-guide?ref=sorena.io) - Supports Singapore breach handling steps and the mandatory data breach notification workflow.<br>[Joint Guide to ASEAN Model Contractual Clauses and EU Standard Contractual Clauses](https://asean.org/wp-content/uploads/3-ASEAN-Model-Contractual-Clauses-for-Cross-Border-Data-Flows_Final.pdf?ref=sorena.io) - Supports the GDPR SCC breach comparison for importer notification, mitigation, supervisory-authority notification, data-subject notification, and breach records.<br>[Advisory Guidelines on Key Concepts in the Personal Data Protection Act](https://www.pdpc.gov.sg/guidelines-and-consultation/2020/03/advisory-guidelines-on-key-concepts-in-the-personal-data-protection-act?ref=sorena.io) - Supports the Singapore expectation that organisations generally assess breach notifiability within 30 calendar days. |
| Timing and deadlines | Singapore has DNC-specific duties for specified messages to Singapore telephone numbers. Unless an exception or clear and unambiguous consent in evidential form applies, teams need a DNC Register check, sender analysis, message identification/contact information, and controls against dictionary attacks or address-harvesting. | The provided GDPR source support does not support a general GDPR marketing comparison. Keep GDPR direct-marketing or ePrivacy analysis out of this page unless a separate official source is added. | Treat DNC as a Singapore-specific marketing gate. Do not mark a campaign GDPR-ready, or DNC-ready, based only on the other regime's consent record. | [Advisory Guidelines on the Do Not Call Provisions](https://www.pdpc.gov.sg/guidelines-and-consultation/2020/02/advisory-guidelines-on-the-do-not-call-provisions?ref=sorena.io) - Supports DNC specified-message scope, sender responsibility, DNC checking, evidential consent, identification/contact information, and dictionary-attack rules.<br>[Do Not Call Registry Business Rules](https://www.dnc.gov.sg/org_more.html?ref=sorena.io) - Supports the practical DNC account and Registry-check workflow for organisations and individuals.<br>[Joint Guide to ASEAN Model Contractual Clauses and EU Standard Contractual Clauses](https://asean.org/wp-content/uploads/3-ASEAN-Model-Contractual-Clauses-for-Cross-Border-Data-Flows_Final.pdf?ref=sorena.io) - Used here only to document the source boundary: this guide supports transfer clauses, not a general GDPR marketing-rule comparison.<br>[Personal Data Protection Act 2012](https://sso.agc.gov.sg/Act/PDPA2012?ref=sorena.io) - Supports treating DNC duties as Singapore PDPA statutory duties rather than generic privacy-program evidence. |
| Enforcement | PDPC may issue directions and impose financial penalties. For intentional or negligent contraventions of data protection provisions, the enforcement guidance states a maximum of S$1 million or 10% of annual turnover in Singapore, whichever is higher, where annual turnover in Singapore exceeds S$10 million. DNC penalty ranges differ by contravention type. | The cited sources support GDPR SCC enforcement through supervisory-authority cooperation and SCC redress routes, but it does not include an official GDPR administrative-fine source. Do not compare headline GDPR fine caps from these cited sources. | Escalate Singapore enforcement exposure to PDPC-focused owners, and escalate EU SCC failures to the transfer owner, exporter/importer contract owner, and supervisory-authority evidence owner. | [Advisory Guidelines on Enforcement of the Data Protection Provisions](https://www.pdpc.gov.sg/Commissions-Decisions?ref=sorena.io) - Supports Singapore directions, financial penalty powers, data protection penalty range, DNC penalty ranges, and penalty-calibration factors.<br>[Joint Guide to ASEAN Model Contractual Clauses and EU Standard Contractual Clauses](https://asean.org/wp-content/uploads/3-ASEAN-Model-Contractual-Clauses-for-Cross-Border-Data-Flows_Final.pdf?ref=sorena.io) - Supports EU SCC supervisory-authority cooperation, data-subject redress, court routes, documentation, and termination consequences, but not GDPR fine caps.<br>[Personal Data Protection Act 2012](https://sso.agc.gov.sg/Act/PDPA2012?ref=sorena.io) - Supports the statutory basis for Singapore PDPA enforcement and DNC provisions. |
| Overlap and reuse | Singapore access and correction duties apply to personal data in an organisation's possession or under its control, including data held by a data intermediary. The organisation must respond as soon as reasonably possible and use the PDPA procedure for timeframe notices, refusals, fees, and preservation where relevant. | The SCC-focused GDPR cited sources support EU SCC data-subject redress and SCC enquiries, but it does not support a full GDPR data-subject-rights comparison. Verify GDPR access, rectification, and deadline rules from an official GDPR source before aligning workflows. | For shared portals, keep a Singapore access/correction runbook that includes intermediary-held data, and keep any GDPR rights workflow under a separately sourced GDPR standard. | [Advisory Guidelines on Key Concepts in the Personal Data Protection Act](https://www.pdpc.gov.sg/guidelines-and-consultation/2020/03/advisory-guidelines-on-key-concepts-in-the-personal-data-protection-act?ref=sorena.io) - Supports Singapore access and correction obligations, including data under an organisation's control and data intermediary handling.<br>[Personal Data Protection Regulations 2021](https://sso.agc.gov.sg/SL/PDPA2012-S63-2021?ref=sorena.io) - Supports Singapore access/correction request procedures, response-timeframe notices, fees, refusal handling, and preservation rules.<br>[Joint Guide to ASEAN Model Contractual Clauses and EU Standard Contractual Clauses](https://asean.org/wp-content/uploads/3-ASEAN-Model-Contractual-Clauses-for-Cross-Border-Data-Flows_Final.pdf?ref=sorena.io) - Supports only SCC data-subject redress and enquiry handling, not a complete GDPR access or rectification workflow.<br>[Advisory Guidelines on Enforcement of the Data Protection Provisions](https://www.pdpc.gov.sg/Commissions-Decisions?ref=sorena.io) - Supports the Singapore enforcement context for access/correction failures and 30-day response-timeframe escalation examples. |
| Practical decision rule | The PDPA retention limitation rule requires organisations to stop retaining documents containing personal data, or remove the means of association with individuals, once the original purpose is no longer served and retention is no longer needed for legal or business purposes. | The GDPR source support in this folder supports SCC documentation and transfer data-minimisation references, but not a full GDPR retention-rule comparison. Avoid importing GDPR storage-limitation conclusions without a separate source. | Keep a Singapore retention rationale, deletion/anonymisation action, and legal or business purpose record. Treat GDPR retention mapping as a separate verification item unless it is tied to the SCC transfer purpose and minimisation evidence. | [Advisory Guidelines on Key Concepts in the Personal Data Protection Act](https://www.pdpc.gov.sg/guidelines-and-consultation/2020/03/advisory-guidelines-on-key-concepts-in-the-personal-data-protection-act?ref=sorena.io) - Supports the Singapore retention limitation rule, retention policy practice, and cease-retention or anonymisation evidence.<br>[Joint Guide to ASEAN Model Contractual Clauses and EU Standard Contractual Clauses](https://asean.org/wp-content/uploads/3-ASEAN-Model-Contractual-Clauses-for-Cross-Border-Data-Flows_Final.pdf?ref=sorena.io) - Supports only the GDPR transfer-purpose and data-minimisation references used here, not a full GDPR retention analysis.<br>[Guide to Managing Data Intermediaries](https://www.pdpc.gov.sg/help-and-resources/2020/09/guide-to-managing-data-intermediaries?ref=sorena.io) - Supports vendor exit-management evidence, including timeframes for data intermediaries to cease retaining personal data after processing ends. |

Sources for Scope boundary - Singapore PDPA:

- [Advisory Guidelines on Key Concepts in the Personal Data Protection Act](https://www.pdpc.gov.sg/guidelines-and-consultation/2020/03/advisory-guidelines-on-key-concepts-in-the-personal-data-protection-act?ref=sorena.io) - Supports the Singapore consent, notification, purpose limitation, deemed-consent, and withdrawal framing.
  - Quote: "The Purpose Limitation Obligation"

Sources for Scope boundary - GDPR:

- [Joint Guide to ASEAN Model Contractual Clauses and EU Standard Contractual Clauses](https://asean.org/wp-content/uploads/3-ASEAN-Model-Contractual-Clauses-for-Cross-Border-Data-Flows_Final.pdf?ref=sorena.io) - Supports the GDPR SCC transfer references to Article 6 legal basis and Article 5(1)(c) data minimisation.
  - Quote: "Article 6 (legal basis)"

Sources for Scope boundary - operational implication:

- [Personal Data Protection Regulations 2021](https://sso.agc.gov.sg/SL/PDPA2012-S63-2021?ref=sorena.io) - Supports Singapore procedures for deemed consent by notification and legitimate interests assessments.
  - Quote: "Deemed consent by notification"

Sources for Covered actors - Singapore PDPA:

- [Guide to Managing Data Intermediaries](https://www.pdpc.gov.sg/help-and-resources/2020/09/guide-to-managing-data-intermediaries?ref=sorena.io) - Supports the Singapore DC/DI lifecycle, written contract, service management, incident escalation, monitoring, audit, and exit-management expectations.
  - Quote: "binding contractual agreement"

Sources for Covered actors - GDPR:

- [Joint Guide to ASEAN Model Contractual Clauses and EU Standard Contractual Clauses](https://asean.org/wp-content/uploads/3-ASEAN-Model-Contractual-Clauses-for-Cross-Border-Data-Flows_Final.pdf?ref=sorena.io) - Supports the EU SCC controller-to-processor comparison, including documentation, audits, authority cooperation, and processor instructions.
  - Quote: "controller-to-processor transfers"

Sources for Covered actors - operational implication:

- [Advisory Guidelines on Key Concepts in the Personal Data Protection Act](https://www.pdpc.gov.sg/guidelines-and-consultation/2020/03/advisory-guidelines-on-key-concepts-in-the-personal-data-protection-act?ref=sorena.io) - Supports the Singapore point that data intermediaries have limited direct PDPA obligations while the organisation remains responsible for the wider PDPA compliance set.
  - Quote: "data intermediary"

Sources for Trigger - Singapore PDPA:

- [Advisory Guidelines on Key Concepts in the Personal Data Protection Act](https://www.pdpc.gov.sg/guidelines-and-consultation/2020/03/advisory-guidelines-on-key-concepts-in-the-personal-data-protection-act?ref=sorena.io) - Supports the Singapore DPO designation, business contact, delegation, and organisational accountability statements.
  - Quote: "Appointing a Data Protection Officer"

Sources for Trigger - GDPR:

- [Joint Guide to ASEAN Model Contractual Clauses and EU Standard Contractual Clauses](https://asean.org/wp-content/uploads/3-ASEAN-Model-Contractual-Clauses-for-Cross-Border-Data-Flows_Final.pdf?ref=sorena.io) - Supports only GDPR-side SCC accountability evidence, such as documentation and supervisory-authority cooperation, not a general GDPR DPO appointment rule.
  - Quote: "demonstrate compliance with the SCCs"

Sources for Trigger - operational implication:

- [Guide to Accountability under the Personal Data Protection Act](https://www.pdpc.gov.sg/help-and-resources/2019/07/guide-to-accountability-under-the-personal-data-protection-act?ref=sorena.io) - Supports treating accountability as demonstrable organisational measures rather than only a named person.
  - Quote: "demonstrate accountability for personal data"

Sources for Core obligations - Singapore PDPA:

- [Advisory Guidelines on Key Concepts in the Personal Data Protection Act](https://www.pdpc.gov.sg/guidelines-and-consultation/2020/03/advisory-guidelines-on-key-concepts-in-the-personal-data-protection-act?ref=sorena.io) - Supports the Singapore transfer limitation explanation, comparable-protection standard, contracts, binding corporate rules, specified certifications, and ASEAN MCC references.
  - Quote: "standard of protection"
- [Personal Data Protection Regulations 2021](https://sso.agc.gov.sg/SL/PDPA2012-S63-2021?ref=sorena.io) - Supports the statutory transfer-regulation categories for overseas transfers.
  - Quote: "Transfer of personal data outside Singapore"

Sources for Core obligations - GDPR:

- [Joint Guide to ASEAN Model Contractual Clauses and EU Standard Contractual Clauses](https://asean.org/wp-content/uploads/3-ASEAN-Model-Contractual-Clauses-for-Cross-Border-Data-Flows_Final.pdf?ref=sorena.io) - Supports EU SCC transfer appendices, data exporter/importer information, purpose, technical and organisational measures, and SCC local-law assessment evidence.
  - Quote: "the Appendix should be signed"

Sources for Core obligations - operational implication:

- [ASEAN Model Contractual Clauses for Cross Border Data Flows](https://asean.org/wp-content/uploads/3-ASEAN-Model-Contractual-Clauses-for-Cross-Border-Data-Flows_Final.pdf?ref=sorena.io) - Supports the point that ASEAN MCCs are voluntary contractual clauses and may be adapted or supplemented for transfer contexts.
  - Quote: "voluntary standard"

Sources for Evidence record - Singapore PDPA:

- [Personal Data Protection (Notification of Data Breaches) Regulations 2021](https://sso.agc.gov.sg/SL/PDPA2012-S64-2021?ref=sorena.io) - Supports significant-harm categories, the 500-individual significant-scale threshold, and required PDPC and affected-individual notification content.
  - Quote: "prescribed number of affected individuals is 500"
- [Guide on Managing and Notifying Data Breaches Under the PDPA](https://www.pdpc.gov.sg/help-and-resources/2021/01/data-breach-management-guide?ref=sorena.io) - Supports Singapore breach handling steps and the mandatory data breach notification workflow.
  - Quote: "Contain, Assess, Report, Evaluate"

Sources for Evidence record - GDPR:

- [Joint Guide to ASEAN Model Contractual Clauses and EU Standard Contractual Clauses](https://asean.org/wp-content/uploads/3-ASEAN-Model-Contractual-Clauses-for-Cross-Border-Data-Flows_Final.pdf?ref=sorena.io) - Supports the GDPR SCC breach comparison for importer notification, mitigation, supervisory-authority notification, data-subject notification, and breach records.
  - Quote: "Document and record all facts"

Sources for Evidence record - operational implication:

- [Advisory Guidelines on Key Concepts in the Personal Data Protection Act](https://www.pdpc.gov.sg/guidelines-and-consultation/2020/03/advisory-guidelines-on-key-concepts-in-the-personal-data-protection-act?ref=sorena.io) - Supports the Singapore expectation that organisations generally assess breach notifiability within 30 calendar days.
  - Quote: "within 30 calendar days"

Sources for Timing and deadlines - Singapore PDPA:

- [Advisory Guidelines on the Do Not Call Provisions](https://www.pdpc.gov.sg/guidelines-and-consultation/2020/02/advisory-guidelines-on-the-do-not-call-provisions?ref=sorena.io) - Supports DNC specified-message scope, sender responsibility, DNC checking, evidential consent, identification/contact information, and dictionary-attack rules.
  - Quote: "clear and unambiguous consent"
- [Do Not Call Registry Business Rules](https://www.dnc.gov.sg/org_more.html?ref=sorena.io) - Supports the practical DNC account and Registry-check workflow for organisations and individuals.
  - Quote: "perform telephone number checks"

Sources for Timing and deadlines - GDPR:

- [Joint Guide to ASEAN Model Contractual Clauses and EU Standard Contractual Clauses](https://asean.org/wp-content/uploads/3-ASEAN-Model-Contractual-Clauses-for-Cross-Border-Data-Flows_Final.pdf?ref=sorena.io) - Used here only to document the source boundary: this guide supports transfer clauses, not a general GDPR marketing-rule comparison.
  - Quote: "cross-border data flow"

Sources for Timing and deadlines - operational implication:

- [Personal Data Protection Act 2012](https://sso.agc.gov.sg/Act/PDPA2012?ref=sorena.io) - Supports treating DNC duties as Singapore PDPA statutory duties rather than generic privacy-program evidence.
  - Quote: "Do Not Call Registry"

Sources for Enforcement - Singapore PDPA:

- [Advisory Guidelines on Enforcement of the Data Protection Provisions](https://www.pdpc.gov.sg/Commissions-Decisions?ref=sorena.io) - Supports Singapore directions, financial penalty powers, data protection penalty range, DNC penalty ranges, and penalty-calibration factors.
  - Quote: "up to S$1 million or 10%"

Sources for Enforcement - GDPR:

- [Joint Guide to ASEAN Model Contractual Clauses and EU Standard Contractual Clauses](https://asean.org/wp-content/uploads/3-ASEAN-Model-Contractual-Clauses-for-Cross-Border-Data-Flows_Final.pdf?ref=sorena.io) - Supports EU SCC supervisory-authority cooperation, data-subject redress, court routes, documentation, and termination consequences, but not GDPR fine caps.
  - Quote: "competent EU supervisory authority"

Sources for Enforcement - operational implication:

- [Personal Data Protection Act 2012](https://sso.agc.gov.sg/Act/PDPA2012?ref=sorena.io) - Supports the statutory basis for Singapore PDPA enforcement and DNC provisions.
  - Quote: "Personal Data Protection Commission"

Sources for Overlap and reuse - Singapore PDPA:

- [Advisory Guidelines on Key Concepts in the Personal Data Protection Act](https://www.pdpc.gov.sg/guidelines-and-consultation/2020/03/advisory-guidelines-on-key-concepts-in-the-personal-data-protection-act?ref=sorena.io) - Supports Singapore access and correction obligations, including data under an organisation's control and data intermediary handling.
  - Quote: "Access and Correction Obligations"
- [Personal Data Protection Regulations 2021](https://sso.agc.gov.sg/SL/PDPA2012-S63-2021?ref=sorena.io) - Supports Singapore access/correction request procedures, response-timeframe notices, fees, refusal handling, and preservation rules.
  - Quote: "Requests for access to and correction"

Sources for Overlap and reuse - GDPR:

- [Joint Guide to ASEAN Model Contractual Clauses and EU Standard Contractual Clauses](https://asean.org/wp-content/uploads/3-ASEAN-Model-Contractual-Clauses-for-Cross-Border-Data-Flows_Final.pdf?ref=sorena.io) - Supports only SCC data-subject redress and enquiry handling, not a complete GDPR access or rectification workflow.
  - Quote: "Data subjects can enforce"

Sources for Overlap and reuse - operational implication:

- [Advisory Guidelines on Enforcement of the Data Protection Provisions](https://www.pdpc.gov.sg/Commissions-Decisions?ref=sorena.io) - Supports the Singapore enforcement context for access/correction failures and 30-day response-timeframe escalation examples.
  - Quote: "access request or correction request"

Sources for Practical decision rule - Singapore PDPA:

- [Advisory Guidelines on Key Concepts in the Personal Data Protection Act](https://www.pdpc.gov.sg/guidelines-and-consultation/2020/03/advisory-guidelines-on-key-concepts-in-the-personal-data-protection-act?ref=sorena.io) - Supports the Singapore retention limitation rule, retention policy practice, and cease-retention or anonymisation evidence.
  - Quote: "Retention Limitation Obligation"

Sources for Practical decision rule - GDPR:

- [Joint Guide to ASEAN Model Contractual Clauses and EU Standard Contractual Clauses](https://asean.org/wp-content/uploads/3-ASEAN-Model-Contractual-Clauses-for-Cross-Border-Data-Flows_Final.pdf?ref=sorena.io) - Supports only the GDPR transfer-purpose and data-minimisation references used here, not a full GDPR retention analysis.
  - Quote: "limited to what is necessary"

Sources for Practical decision rule - operational implication:

- [Guide to Managing Data Intermediaries](https://www.pdpc.gov.sg/help-and-resources/2020/09/guide-to-managing-data-intermediaries?ref=sorena.io) - Supports vendor exit-management evidence, including timeframes for data intermediaries to cease retaining personal data after processing ends.
  - Quote: "cease retaining the personal data"

### How to use the comparison

- Start with the factual activity: Singapore collection/use/disclosure, overseas transfer, vendor processing, breach, marketing message, access/correction request, retention decision, or enforcement issue.
- For Singapore, attach the PDPA or PDPC source that supports the duty and name the owner who can change the notice, consent flow, contract, vendor control, DNC check, breach process, or retention rule.
- For GDPR, use this page only where the cited sources support the point, mainly SCC transfer mechanics; verify broader GDPR duties separately before saying the same evidence is sufficient.
- Close the record with one of three outcomes: Singapore-only control, GDPR/SCC-only control, or linked controls with separate supporting source references and evidence fields.

Sources for the practical decision rule:

- [Advisory Guidelines on Key Concepts in the Personal Data Protection Act](https://www.pdpc.gov.sg/guidelines-and-consultation/2020/03/advisory-guidelines-on-key-concepts-in-the-personal-data-protection-act?ref=sorena.io) - Supports using PDPA-specific records for Singapore obligations rather than generic privacy-program labels.
  - Quote: "Accountability Obligation"
- [Joint Guide to ASEAN Model Contractual Clauses and EU Standard Contractual Clauses](https://asean.org/wp-content/uploads/3-ASEAN-Model-Contractual-Clauses-for-Cross-Border-Data-Flows_Final.pdf?ref=sorena.io) - Supports using separate transfer-clause evidence for EU SCC work instead of merging it with Singapore PDPA controls.
  - Quote: "specific transfers in an Appendix"

## Where the comparison is strongest

The Singapore side is based on the PDPA, PDPC advisory guidance, the Personal Data Protection Regulations 2021, breach notification regulations, DNC guidance, data intermediary guidance, and enforcement guidance.

The GDPR side is limited to facts supported in the cited sources, especially the Joint Guide comparing ASEAN Model Contractual Clauses with EU Standard Contractual Clauses. For GDPR topics not covered by those sources, treat this page as a prompt to verify the GDPR rule from an official EU source before reusing a Singapore control.

- Use Singapore PDPA sources for consent, notification, purpose limitation, DPO/accountability, access, correction, retention, transfer limitation, breach notification, data intermediaries, DNC marketing, and PDPC enforcement.
- Use the ASEAN/EU Joint Guide for EU SCC transfer evidence, GDPR legal-basis references in SCC transfers, EU supervisory-authority references, SCC documentation, and SCC breach clauses.
- Do not treat DNC Registry checks, Singapore DPO contact publication, or Singapore breach-notification thresholds as GDPR requirements.
- Do not treat EU SCC transfer impact and supervisory-authority evidence as enough to prove all Singapore PDPA transfer, retention, DNC, or access/correction duties.

Sources for this answer:

- [Advisory Guidelines on Key Concepts in the Personal Data Protection Act](https://www.pdpc.gov.sg/guidelines-and-consultation/2020/03/advisory-guidelines-on-key-concepts-in-the-personal-data-protection-act?ref=sorena.io) - Supports the Singapore PDPA obligations used in the comparison, including consent, notification, access, correction, retention, transfer limitation, DPO/accountability, and data intermediaries.
- [Joint Guide to ASEAN Model Contractual Clauses and EU Standard Contractual Clauses](https://asean.org/wp-content/uploads/3-ASEAN-Model-Contractual-Clauses-for-Cross-Border-Data-Flows_Final.pdf?ref=sorena.io) - Supports the GDPR-side transfer comparisons that discuss EU SCCs, GDPR legal basis, supervisory authorities, SCC records, and breach clauses.

*Recommended next step*

*Placement: after the comparison*

## Map PDPA and GDPR evidence separately

This comparison helps turn a shared privacy workstream into separate Singapore PDPA controls, GDPR transfer evidence, owners, and review checkpoints.

- [Open Assessment Autopilot for Singapore PDPA](/solutions/assessment.md): Create scoped PDPA questions for consent, DPO accountability, intermediaries, transfers, breaches, DNC marketing, rights, and retention.
- [Review source evidence](/solutions/research-copilot.md): Use Research Copilot to verify which source supports each PDPA or GDPR transfer claim before controls are reused.
- [Talk through implementation](/contact.md): Review overlap, evidence gaps, and owner assignments with Sorena.

## Evidence to keep separate

A single privacy ticket can carry both regimes, but the record should show which fact proves which side. For Singapore, keep the PDPA purpose statement, consent or exception analysis, DPO/accountability record, transfer basis, DNC check or clear consent evidence, breach assessment, and access/correction response evidence.

For GDPR-linked transfers, keep the SCC appendix, data exporter/importer details, transfer purpose, technical and organisational measures, local-law assessment where the SCCs require it, supervisory-authority references, and breach documentation required by the SCC module.

- Separate the Singapore DPO and policy-publication record from GDPR DPO analysis unless a separate GDPR source has been checked.
- Separate Singapore data intermediary scope and contract evidence from EU controller-to-processor SCC module evidence.
- Separate Singapore notifiable-breach thresholds and PDPC notification content from SCC breach clauses.
- Separate DNC marketing evidence from GDPR direct-marketing or ePrivacy analysis, which is not based on these cited sources.

Sources for this answer:

- [Guide to Managing Data Intermediaries](https://www.pdpc.gov.sg/help-and-resources/2020/09/guide-to-managing-data-intermediaries?ref=sorena.io) - Supports the Singapore evidence needed for data intermediary scope, contracts, incident escalation, service management, and exit retention.
- [Personal Data Protection (Notification of Data Breaches) Regulations 2021](https://sso.agc.gov.sg/SL/PDPA2012-S64-2021?ref=sorena.io) - Supports the Singapore breach-notification threshold and content evidence referenced in this comparison.

## Primary sources

- [Personal Data Protection Act 2012](https://sso.agc.gov.sg/Act/PDPA2012?ref=sorena.io) - Supports the statutory basis for Singapore PDPA enforcement and DNC provisions.
  - Quote: "Personal Data Protection Commission"
- [Advisory Guidelines on Key Concepts in the Personal Data Protection Act](https://www.pdpc.gov.sg/guidelines-and-consultation/2020/03/advisory-guidelines-on-key-concepts-in-the-personal-data-protection-act?ref=sorena.io) - Supports using PDPA-specific records for Singapore obligations rather than generic privacy-program labels.
  - Quote: "Accountability Obligation"
- [Personal Data Protection Regulations 2021](https://sso.agc.gov.sg/SL/PDPA2012-S63-2021?ref=sorena.io) - Supports Singapore access/correction request procedures, response-timeframe notices, fees, refusal handling, and preservation rules.
  - Quote: "Requests for access to and correction"
- [Guide to Managing Data Intermediaries](https://www.pdpc.gov.sg/help-and-resources/2020/09/guide-to-managing-data-intermediaries?ref=sorena.io) - Supports vendor exit-management evidence, including timeframes for data intermediaries to cease retaining personal data after processing ends.
  - Quote: "cease retaining the personal data"
- [Guide on Managing and Notifying Data Breaches Under the PDPA](https://www.pdpc.gov.sg/help-and-resources/2021/01/data-breach-management-guide?ref=sorena.io) - Supports Singapore breach handling steps and the mandatory data breach notification workflow.
  - Quote: "Contain, Assess, Report, Evaluate"
- [Personal Data Protection (Notification of Data Breaches) Regulations 2021](https://sso.agc.gov.sg/SL/PDPA2012-S64-2021?ref=sorena.io) - Supports significant-harm categories, the 500-individual significant-scale threshold, and required PDPC and affected-individual notification content.
  - Quote: "prescribed number of affected individuals is 500"
- [Advisory Guidelines on the Do Not Call Provisions](https://www.pdpc.gov.sg/guidelines-and-consultation/2020/02/advisory-guidelines-on-the-do-not-call-provisions?ref=sorena.io) - Supports DNC specified-message scope, sender responsibility, DNC checking, evidential consent, identification/contact information, and dictionary-attack rules.
  - Quote: "clear and unambiguous consent"
- [Do Not Call Registry Business Rules](https://www.dnc.gov.sg/org_more.html?ref=sorena.io) - Supports the practical DNC account and Registry-check workflow for organisations and individuals.
  - Quote: "perform telephone number checks"
- [Advisory Guidelines on Enforcement of the Data Protection Provisions](https://www.pdpc.gov.sg/Commissions-Decisions?ref=sorena.io) - Supports the Singapore enforcement context for access/correction failures and 30-day response-timeframe escalation examples.
  - Quote: "access request or correction request"
- [Joint Guide to ASEAN Model Contractual Clauses and EU Standard Contractual Clauses](https://asean.org/wp-content/uploads/3-ASEAN-Model-Contractual-Clauses-for-Cross-Border-Data-Flows_Final.pdf?ref=sorena.io) - Supports using separate transfer-clause evidence for EU SCC work instead of merging it with Singapore PDPA controls.
  - Quote: "specific transfers in an Appendix"
- [Guide to Accountability under the Personal Data Protection Act](https://www.pdpc.gov.sg/help-and-resources/2019/07/guide-to-accountability-under-the-personal-data-protection-act?ref=sorena.io) - Supports treating accountability as demonstrable organisational measures rather than only a named person.
  - Quote: "demonstrate accountability for personal data"
- [ASEAN Model Contractual Clauses for Cross Border Data Flows](https://asean.org/wp-content/uploads/3-ASEAN-Model-Contractual-Clauses-for-Cross-Border-Data-Flows_Final.pdf?ref=sorena.io) - Supports the point that ASEAN MCCs are voluntary contractual clauses and may be adapted or supplemented for transfer contexts.
  - Quote: "voluntary standard"

## Related Topic Guides

- [Singapore PDPA Anonymisation and DPIA Records](/artifacts/apac/singapore-pdpa/anonymisation-and-dpias.md): Build Singapore PDPA anonymisation and DPIA records around PDPC guidance: release model, re-identification risk, data flows, action plans, safeguards, and monitoring.
- [Singapore PDPA anonymisation FAQ](/artifacts/apac/singapore-pdpa/faq/anonymisation.md): FAQ on anonymisation under the Singapore PDPA: de-identification, pseudonymisation, re-identification risk, when PDPA may no longer apply, and evidence records.
- [Singapore PDPA Applicability Test](/artifacts/apac/singapore-pdpa/applicability-test.md): Test whether Singapore PDPA obligations apply by checking personal data, organisation role, data intermediary status, public agency and individual boundaries, and business contact information.
- [Singapore PDPA Breach Notification Playbook](/artifacts/apac/singapore-pdpa/breach-notification-playbook.md): An official source Singapore PDPA breach-notification playbook covering assessment, notifiable-breach thresholds, PDPC and affected-individual notification steps, roles, records, and citations.
- [Singapore PDPA breach notification thresholds FAQ](/artifacts/apac/singapore-pdpa/faq/breach-thresholds.md): FAQ on Singapore PDPA notifiable data breach tests: significant harm, significant scale, 500 affected individuals, assessment timing, PDPC notices, and affected-individual notices.
- [Singapore PDPA Breach Notification Workflow](/artifacts/apac/singapore-pdpa/breach-notification-workflow.md): An official source Singapore PDPA workflow for containing a personal data breach, assessing notifiability, notifying PDPC or affected individuals, and retaining evidence.
- [Singapore PDPA Compliance Checklist](/artifacts/apac/singapore-pdpa/checklist.md): An official source Singapore PDPA checklist for scope, DPO accountability, consent, data intermediaries, breach notification, DNC checks, transfers, and evidence records.
- [Singapore PDPA Compliance Guide](/artifacts/apac/singapore-pdpa/compliance.md): Build a Singapore PDPA compliance plan covering DPO accountability, consent and notification, protection, retention, access and correction, transfers, breach notification, and DNC checks.
- [Singapore PDPA Consent and Deemed Consent Workflow](/artifacts/apac/singapore-pdpa/consent-and-deemed-consent-selection-workflow.md): Choose express consent, deemed consent by conduct, contractual necessity, notification, or the legitimate interests exception under Singapore PDPA with based ontake fields and evidence records.
- [Singapore PDPA Consent, Notification and Purpose Rules](/artifacts/apac/singapore-pdpa/consent-notification-and-purposes.md): How Singapore PDPA consent, notification, purpose limitation, deemed consent, withdrawal, and consent exceptions should be handled in product and privacy workflows.
- [Singapore PDPA Cross-Border Transfers](/artifacts/apac/singapore-pdpa/cross-border-transfers.md): Official source Singapore PDPA guidance for overseas personal data transfers, comparable protection, ASEAN MCCs, APEC certifications, vendor roles, and evidence records.
- [Singapore PDPA Data Breach Notification Thresholds](/artifacts/apac/singapore-pdpa/breach-notification-thresholds.md): Official source Singapore PDPA breach notification thresholds covering significant harm, the 500-individual significant-scale test, assessment records, and notification timing.
- [Singapore PDPA Data Intermediaries FAQ](/artifacts/apac/singapore-pdpa/faq/data-intermediaries.md): FAQ guidance on Singapore PDPA data intermediary roles, direct obligations, organisation accountability, contracts, retention, protection, and breach escalation.
- [Singapore PDPA Data Intermediary Responsibilities](/artifacts/apac/singapore-pdpa/data-intermediary-responsibilities.md): Practical Singapore PDPA guide to data intermediary role boundaries, organisation accountability, protection, retention, breach escalation, and contract evidence.
- [Singapore PDPA Deadlines and Compliance Calendar](/artifacts/apac/singapore-pdpa/deadlines-and-compliance-calendar.md): An official source Singapore PDPA compliance calendar for breach notification, DNC checks, access and correction requests, retention reviews, and DPMP maintenance.
- [Singapore PDPA Deemed Consent and Legitimate Interests](/artifacts/apac/singapore-pdpa/deemed-consent-and-legitimate-interests.md): How to apply Singapore PDPA deemed consent by conduct, contractual necessity, notification, and legitimate interests with opt-out, adverse-effect, disclosure, and assessment records.
- [Singapore PDPA Deemed Consent FAQ](/artifacts/apac/singapore-pdpa/faq/deemed-consent.md): FAQ on Singapore PDPA deemed consent by conduct, contractual necessity, notification, opt-out periods, adverse-effect assessment, withdrawal, and direct-marketing limits.
- [Singapore PDPA DNC and Marketing Messages Guide](/artifacts/apac/singapore-pdpa/dnc-and-marketing-messages.md): An official source Singapore PDPA guide to DNC checks, specified marketing messages, Singapore telephone numbers, consent evidence, opt-outs, sender duties, and excluded messages.
- [Singapore PDPA DNC checking FAQ: when to check the DNC Registry](/artifacts/apac/singapore-pdpa/faq/dnc-checking.md): FAQ guidance on Singapore PDPA DNC checking: when to check the DNC Registry, which registers apply, 8-digit numbers, 21-day result validity, consent evidence, on-behalf checks, opt-outs, and supported exclusions.
- [Singapore PDPA DNC Marketing Checks](/artifacts/apac/singapore-pdpa/dnc-marketing-checks.md): Operational checklist for Singapore PDPA DNC marketing checks: account evidence, register status, 21-day result validity, consent evidence, and campaign owner records.
- [Singapore PDPA DNC Marketing Workflow](/artifacts/apac/singapore-pdpa/dnc-marketing-workflow.md): Workflow for Singapore PDPA DNC marketing campaigns: classify specified messages, check Singapore telephone numbers, document consent, suppress opt-outs, and approve sends.
- [Singapore PDPA DPIAs: when to run and what to document](/artifacts/apac/singapore-pdpa/faq/dpias.md): FAQ-style implementation guidance on Singapore PDPA DPIAs, including when PDPC guidance recommends them, data-flow mapping, risk treatment, DPO review, and evidence records.
- [Singapore PDPA DPMP Accountability FAQ | DPO, Policies, Evidence](/artifacts/apac/singapore-pdpa/faq/dpmp-accountability.md): FAQ for implementing Singapore PDPA accountability through a DPMP: DPO designation, policies, evidence, training, monitoring, incident logs, and review records.
- [Singapore PDPA DPMP Accountability Guide](/artifacts/apac/singapore-pdpa/dpmp-accountability.md): Build a Singapore PDPA Data Protection Management Programme with DPO ownership, policies, data inventories, DPIAs, training, monitoring, breach logs, and review records.
- [Singapore PDPA FAQ: scope, DPO, consent, breaches and DNC](/artifacts/apac/singapore-pdpa/faq.md): FAQ answers for Singapore PDPA implementation, covering scope, accountability, consent, access and correction, security, retention, transfers, data intermediaries, breach notification, and DNC checks.
- [Singapore PDPA legitimate interests FAQ](/artifacts/apac/singapore-pdpa/faq/legitimate-interests.md): FAQ guidance on Singapore PDPA legitimate interests: assessment fields, adverse effects, mitigation, balancing, disclosure, records, and marketing limits.
- [Singapore PDPA NRIC Handling FAQ](/artifacts/apac/singapore-pdpa/faq/nric-handling.md): FAQ guidance on when Singapore organisations may collect, use, disclose, retain, mask, or replace NRIC and other national identification numbers under PDPC guidance.
- [Singapore PDPA NRIC Handling Rules](/artifacts/apac/singapore-pdpa/nric-handling.md): When Singapore organisations may collect, use, disclose, retain, mask, or replace NRIC numbers under PDPC guidance.
- [Singapore PDPA Penalties and Enforcement Cases](/artifacts/apac/singapore-pdpa/pdpa-penalties-and-enforcement-cases.md): How PDPC enforcement under Singapore's PDPA works: directions, voluntary undertakings, published decisions, financial penalty caps, and implementation lessons from cases.
- [Singapore PDPA Penalties and Fines](/artifacts/apac/singapore-pdpa/penalties-and-fines.md): Singapore PDPA penalty ceilings, PDPC directions, undertakings, breach notification context, and practical controls based on official PDPC and Singapore Statutes sources.
- [Singapore PDPA Privacy Policy Template](/artifacts/apac/singapore-pdpa/pdpa-privacy-policy-template.md): A Singapore PDPA privacy policy template for writing notices, DPO contact details, access and correction routes, retention, transfers, protection, withdrawal, and complaint handling without overclaiming compliance.
- [Singapore PDPA Requirements: Core Obligations](/artifacts/apac/singapore-pdpa/requirements.md): Map Singapore PDPA obligations across consent, notification, access, security, retention, transfers, accountability, breaches, DNC checks, and data intermediaries.
- [Singapore PDPA Scope, Exclusions, and Data Intermediaries](/artifacts/apac/singapore-pdpa/scope-exclusions-and-data-intermediaries.md): Classify Singapore PDPA coverage, business contact information, personal or domestic activity, employee acts, and data intermediary obligations with official source implementation records.
- [Singapore PDPA Transfer Assessment Workflow](/artifacts/apac/singapore-pdpa/transfer-assessment-workflow.md): A Singapore PDPA workflow for assessing overseas personal data transfers, comparable protection, ASEAN MCCs, APEC CBPR/PRP certifications, vendor due diligence, onward transfers, and evidence records.
- [Singapore PDPA Transfer Clauses](/artifacts/apac/singapore-pdpa/transfer-clauses.md): Draft Singapore PDPA transfer clauses for overseas vendors, affiliates, data intermediaries, onward transfers, breach support, ASEAN MCCs, and APEC CBPR or PRP evidence.
- [Singapore PDPA transfer clauses FAQ](/artifacts/apac/singapore-pdpa/faq/transfer-clauses.md): FAQ guidance on Singapore PDPA transfer clauses, comparable protection, ASEAN MCCs, APEC CBPR and PRP certifications, onward transfers, and evidence records.
- [Singapore PDPA Vendor Outsourcing and Contracts](/artifacts/apac/singapore-pdpa/vendor-outsourcing-and-contracts.md): Contract and operating checklist for Singapore PDPA vendor outsourcing: data intermediary status, written terms, security, retention, breach, transfers, sub-contracting, and exit evidence.


---

[Privacy Policy](https://www.sorena.io/privacy) | [Terms of Use](https://www.sorena.io/terms-of-use) | [DMCA](https://www.sorena.io/dmca) | [About Us](https://www.sorena.io/about-us)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/singapore-pdpa/singapore-pdpa-vs-gdpr
