Readable outline — open in a web browser (Safari/Chrome) for the interactive map.
Nine topic clusters drawn from your notes. Compliance is treated as a continuous cycle — not a one-time checklist.
Tap a branch below to start, or explore from the map.
Singapore's data-protection regime is primarily governed by the Personal Data Protection Act (PDPA), which sets a baseline standard of protection across the economy.
Its core aim is to balance individuals' right to protect their data with organisations' need to use data for legitimate, reasonable purposes. Explore the five facets below.
The PDPA balances individuals' right to protect their data against organisations' need to use data for legitimate, reasonable purposes.
Applies broadly to any individual, company, association or body (formed in Singapore or not) handling personal data. Covers electronic and physical data, whether true or false.
The bulk of the regime — the 11 Key Obligations (POPCON ExTRAS ADD) governing collection, care of data, and individual autonomy. Accountability underpins them: a proactive, risk-based approach, not a checklist.
Apply to marketing messages (voice, SMS, fax) to Singapore numbers. Organisations must check the DNC Registry before sending, identify the sender, and are barred from dictionary attacks / address-harvesting software. A registry check is valid for up to 21 days before the message is sent.
Enforced by the Personal Data Protection Commission (PDPC). Options range from advisory notices to accepting voluntary undertakings for remediation.
For egregious or high-impact breaches, the PDPC can investigate and impose financial penalties of up to S$1 million or 10% of annual turnover in Singapore, whichever is higher.
Every organisation must appoint at least one Data Protection Officer (DPO).
To demonstrate accountability, organisations are encouraged to use these frameworks & tools — tap to jump:
DPMP & DPIA each have their own full branch; PATO lives under Tools & Roles.
Handle a breach with the C.A.R.E. response model. Notification rules live under the Report step.
Act swiftly to prevent further compromise and implement mitigating actions to limit damage.
Evaluate the circumstances, the ease of identifying individuals from compromised data, and whether the breach is legally notifiable.
Fulfil the duty to notify the PDPC and, where required, affected individuals, once a breach is assessed as notifiable.
Generally met when a full name / alias / full NRIC is compromised together with sensitive data:
Even if the harm threshold is met, individual notification is not required if:
Review the overall response so recovery and future prevention strategies can be improved.
A process & tool to identify, assess and address personal-data risks based on an organisation's functions, needs and processes.
Determine if a new/changed system or process involves personal data. Check for new data collection, disclosure to new third parties, or a new/unconsented purpose.
Form the DPIA project team (PM, DPO, steering committee, departmental reps). Define scope, the risk framework & methodology, stakeholders, and timeline.
Map how data moves via a Data Inventory Map or Data Flow Diagram. Review documents, contracts, specs; consult departments / on-site inspection.
Check compliance against obligations (consent, notification, purpose limitation) using a checklist. Rate & rank risks by impact and likelihood.
Propose technical & organisational measures to treat risks. Assign action owners and set an implementation timeline.
Document into a DPIA report (DPO reviews, senior management approves). Owners execute; the DPO monitors results to ensure risks are managed.
A framework to build a robust data-protection infrastructure and demonstrate accountability. A continuous four-step cycle: Governance & Risk → Policy & Practices → Processes → Review.
Establish a governance structure with leadership to define values and identify data-protection risks.
Three core concepts in risk management, and how they connect.
In short: a threat exploits a vulnerability, which creates a risk.
Threat — something with the potential to cause harm. It can be technical (malware, spyware) or human (a disgruntled former employee, or careless staff who leave confidential documents in a coffee shop).
Vulnerability — a specific weakness, gap, or shortcoming in a system or process that a threat can exploit. Examples: an inadequate firewall, unpatched software, or weak internal policies (e.g. allowing staff to take physical documents out of the office).
Risk — the potential for loss, harm, or negative effect on an organisation or individual. Assessed by combining the likelihood of an incident with its expected impact (Risk ≈ Likelihood × Impact).
How they connect: a threat has the potential to do harm by exploiting a vulnerability (a weakness), which creates a risk (the potential for loss, compliance failure, or negative impact).
Develop data-protection policies and clearly designate roles and responsibilities.
Design SOPs that operationalise policies into daily business functions.
Regularly review and update policies & processes; conduct audits to stay current.
Mapped as a continuous lifecycle. Accountability sits at the top as the overarching principle.
An acronym checklist a company runs through whenever it collects, uses or stores personal data.
Three obligations govern how data is collected:
An organisation can rely on four valid types of consent — explore each below.
The most straightforward and safest form of consent.
The individual actively agrees to the collection, use or disclosure of their data — e.g. physically signing a form or ticking a checkbox online.
Inferred from the individual's actions rather than explicitly given. Applies when someone voluntarily provides their data, fully knowing and understanding the purpose.
Example: giving your home address to a restaurant specifically so they can deliver your food order.
Also inferred, but specifically in the context of a contract. Applies when an individual provides data to enter a contract and processing/sharing it is reasonably necessary to perform or fulfil that contract.
The organisation clearly notifies the individual of a new purpose for using their data and gives a reasonable period to opt out. If they don't opt out in time, they are deemed to have consented.
The organisation must first conduct a risk assessment to ensure the new purpose is low risk and won't negatively impact the customer.
Four obligations govern caring for data once held:
To ensure personal data transferred outside Singapore is protected to a standard comparable to the PDPA.
It protects individuals' data rights even when their data crosses international borders.
Management controls, training, and policy-driven procedures — e.g. developing and communicating clear data-protection policies to all staff.
A specific weakness or gap that can be exploited — an internal flaw in a system or process that gives threats an opening to cause harm. Safeguards exist to close these.
Replacing identifying data with artificial identifiers or aliases. It reduces the linkability of a data set while still allowing re-identification if the key is available — so it is not full anonymisation.
Removing identifying information from a dataset so the remaining data can no longer identify any particular individual. This lets an organisation securely retain and reuse what used to be personal data for other purposes — e.g. trend analysis or statistical market research — without identifying the people involved.
Anonymisation is a valid way to comply with the Retention Limitation Obligation: when data is no longer needed for business or legal purposes, the organisation must either securely destroy it or “remove the means by which the personal data can be associated with particular individuals” (i.e. anonymise it).
Techniques — textual / database data:
Physical documents: redact (black out) names, or alter precise dates and locations. Audio / video: blur faces in photos or CCTV, and electronically disguise audio.
Re-identification risk & the Motivated Intruder Test. As computing power and public data grow, anonymised data can sometimes be combined with other information to re-identify someone. To test robustness, organisations run a “Motivated Intruder Test” — checking whether a reasonably competent person, using standard investigative techniques and public resources (internet, social media), could work out an individual’s identity from the anonymised dataset.
Three industry principles used to determine risk levels and assess impact if data or systems are compromised:
Three obligations protect the individual's ongoing rights:
The obligation only applies to data categories that have been 'white-listed' by regulations.
To provide certainty, it is limited to specific white-listed data categories prescribed by regulations — not to all personal data.
The fundamental principle sitting above the whole cycle.
A risk-based approach to identifying, monitoring, and responding to personal-data risks in order to demonstrate compliance.
It is about being proactive and systematic in managing data risks — showing that the organisation takes responsibility, rather than reacting only after something goes wrong.
Appointing a Data Protection Officer (DPO) is a requirement — but the accountability for adherence to the Act rests with the organisation as a whole, not the DPO alone.
A mnemonic for the scenarios where an organisation may collect, use or disclose personal data without consent. Three groups of three: 3 P's · 3 I's · 3 E's.
Pair it with POPCON ExTRAS ADD (the 11 obligations) when revising.
Business Contact Information (BCI) is usually grouped with the P's — the PDPA data-protection rules don't apply to it.
Plus BCI — Business Contact Information (PDPA rules don't apply).
To rely on this exception, an organisation must conduct an assessment to determine whether its legitimate interests outweigh any adverse effect on the individual.
This is a balancing test and risk assessment — it ensures the organisation's interests do not unfairly harm the individual.
In short, the framework requires balancing the business need against the potential impact on individuals.
The Evaluation exception applies to activities like determining suitability for employment, promotion, or awarding scholarships.
Loyalty programs do not qualify — they usually operate under express consent and count as marketing / business activities, not 'evaluation' in the legal sense.
Self-assessment, accountability and data-mapping instruments referenced across your notes.
A digital self-assessment tool by the PDPC.
The RACI Matrix is a tool used to clearly define roles and responsibilities within an organisation's team.
Documents how data flows through a process — from collection to secure destruction.
All 63 practice questions with options, grouped by topic. Tap any card to reveal the correct answer.
Extra exam facts gathered in one place, so you don't have to hunt through each branch. Tap a topic below.
The PDPA applies to personal data in a record that has been in existence for less than 100 years.
Limited protection applies: only the Disclosure and Protection (Safeguarding) obligations, for up to 10 years after the date of death.
The objective standard throughout the PDPA: data purposes must be ones a reasonable person would consider appropriate in the circumstances.
Four purposes where data may be collected, used or disclosed without consent:
For Research / Business Improvement, all must hold:
Conduct a risk assessment so the legitimate interest outweighs adverse effects, and notify individuals you rely on it. Data may be shared within a group of companies for business improvement if they are bound by contract to safeguard it and the individuals are existing or prospective customers.
An opt-out framework: notify the individual of the purpose and give a reasonable period to opt out.
Covered: voice calls, SMS, MMS, faxes. Excluded: email and IM (e.g. Telegram) — still governed by the DP provisions.
Step 3 (Processes) implements Data Protection by Design (DPbD): consider data protection from the earliest design stage and throughout the operational lifecycle — not bolted on later.