What this record can establish
- The current statutory framework and the PDPC's official map of organisational obligations.
- That Singapore's main data-protection framework has an operative institutional and guidance history.
SG · ACT 26/2012 · source-led dossier
Personal Data Protection Act 2012
What this record can establish
What it cannot establish
Instrument and status timeline
The principal data-protection obligations entered operation on a staged implementation timetable.
SG-01 · Singapore Statutes OnlineThe current official consolidation records an amendment by Act 19 of 2025 from this date; issue-specific legal effect still needs a provision-level check.
SG-01 · Singapore Statutes OnlineThe consolidated statute and official obligations guide must be checked together for the issue under review.
SG-02 · Personal Data Protection Commission Singapore17-factor research index
Every factor remains inspectable without implying that evidence across frameworks is numerically equivalent.
How the legal architecture can be found, understood and translated into a research plan.
The statute and PDPC obligations guide offer complementary entry points, while exceptions and guidance remain issue-specific.
How much interpretation is needed before a team can identify the rule that governs its activity?
Which entities, people, data and overseas activities fall inside the framework?
Which processing grounds exist, and how does an organisation document the one it relies on?
What must a person be told, when, and in what form before data is used?
What people can understand, choose, contest and ask organisations to do.
Consent, withdrawal, access and correction are visible parts of the framework; statutory alternatives and exceptions must also be mapped.
Can a person reverse a choice through a practical, understandable route?
Which rights exist, and what must happen before a person can obtain a remedy?
How does the framework recognise age, guardianship and risks to younger people?
What transparency or recourse applies when automated processing affects a person?
How duties, safeguards, risk processes and transfer mechanisms are organised.
Accountability, protection, retention, transfer and breach duties are presented as an integrated organisational framework.
Who remains accountable when processing is delegated or shared?
Which safeguards and breach steps are specified, and when are they triggered?
When must an organisation investigate and document risk before processing?
Which transfer routes exist, and what continuing safeguards travel with the data?
Which obligations create fixed costs, and what tailoring exists for smaller organisations?
Could teams implement the rule through portable patterns without weakening legal context?
How rules are supervised, enforced, explained and tested through practice.
The PDPC publishes extensive guidance, but this dossier does not treat publication volume as a quality score.
How can people and organisations reach the institution, and what can it do?
How are sanctions linked to conduct, context and due process?
What has the framework's operation, guidance and enforcement record actually demonstrated?
TAKE TO COUNSEL / TEAMS
Operational questions, not prescriptions
Which consent rule, statutory alternative or exception governs the activity?
Which PDPC guideline supplements the statute for this sector or practice?
Has the specific amended provision relied upon actually commenced?
Official source rail
Article revision record
This register begins with the private-preview editorial rebuild. It records material content, method, interface and trust-policy changes without inventing a history that predates the available repository evidence.
DOSSIER-PDPA-20260826-01