Web6 min read·August 2026

PDPA and Your Singapore Business Website: What You Actually Need in 2026

30-second version

PDPA requires a privacy policy, a data collection notice on your contact form, and a way for users to request access to their data. It does not require a cookie banner for most Singapore-only businesses.

The Personal Data Protection Act has been Singapore law since 2012 and was significantly strengthened in 2020. Yet most Singapore SME websites either have no privacy policy, or have one copied from another country's legislation that doesn't reflect Singapore law. Here's what you actually need.

What the PDPA covers on your website

PDPA governs how you collect, use, disclose, and protect personal data — any data that can identify a person: names, email addresses, phone numbers, IP addresses. If your website has a contact form, newsletter signup, or booking system, PDPA applies. No minimum threshold — size of business is not a factor.

The PDPA website checklist

  • Privacy Policy page: required. Must explain what data you collect, why, who you share it with, how long you keep it, and how users can request access or deletion.
  • Collection notice on forms: before someone submits, they should see a brief notice stating what data is collected and why. A checkbox linking to your Privacy Policy is best practice.
  • Data access mechanism: individuals can request access to their data. An email address is sufficient.
  • Unsubscribe in marketing emails: required — and must be honoured within 10 days.
  • Data Protection Officer: you must designate a DPO. For small businesses, the owner qualifies.
PDPA vs GDPR

If you have EU customers, GDPR also applies — and GDPR has stricter requirements including the cookie consent banner. For a Singapore-only customer base, PDPA is your primary obligation. Cookie banners are not required under PDPA.

What must be in your Privacy Policy

  1. 01Your business name, UEN, and DPO contact
  2. 02What data you collect (name, email, phone, IP address, cookies)
  3. 03Why you collect it (enquiries, marketing, analytics)
  4. 04Who you share it with (email platforms, Google Analytics, Meta Pixel)
  5. 05How long you keep it
  6. 06How to request access or deletion

Third-party tools and PDPA

Every third-party tool processing personal data is your responsibility. Google Analytics, Meta Pixel, Mailchimp, and Calendly all process personal data. Disclose all of them in your Privacy Policy and sign each tool's Data Processing Agreement (they all have one).

Free resource

The PDPC publishes free guides and templates at pdpc.gov.sg — authoritative guidance for Singapore businesses.

Need a PDPA-compliant website?

Every site we build includes a proper Privacy Policy, PDPA-compliant forms, and correct third-party configurations. Book a free call.

Get your free growth plan
← Back to all postsGet a free growth plan