Personal Data Protection Act 2012 (No. 26 of 2012)
Is this legally binding?
Binding. Binding law. It applies to everyone in scope, whether or not anyone points at it.
Singapore's general data protection law governing collection, use and disclosure of personal data by organisations. The only binding, economy-wide law in Singapore's AI governance stack; amended by the Personal Data Protection (Amendment) Act 2020.
From the source
“to govern the collection, use and disclosure of personal data by organisations in a manner that recognises both the right of individuals to protect their personal data”
Long Title; s 3
Instrument record
- Short name
- PDPA
- Date
- 2012
- Version
- Not versioned
- Cluster
- core
What this connects to
16 relations. Official relations are the ones the source documents state; anything marked GAGE analysis is our reading, not an agency's.
Contains6
- InstrumentPDPC Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems (1 Mar 2024)Guidance
Advisory guidelines interpret binding PDPA obligations for AI recommendation and decision systems; they are not themselves legally binding
- SectionPart II, Legal Effect and ScopeGuidance
Guideline interprets binding PDPA provision; guideline itself is not legally binding
- ObligationData Minimisation in AI Development (Good Practice)Guidance
Guideline interprets binding PDPA provision; guideline itself is not legally binding
- ObligationAnonymisation of Datasets for AI DevelopmentGuidance
Guideline interprets binding PDPA provision; guideline itself is not legally binding
- InstrumentPDPC Advisory Guidelines on Use of Personal Data in Generative AI (final, 20 Jul 2026)Guidance
Advisory guidelines interpret binding PDPA for generative AI; not legally binding themselves
- ObligationAnonymisation Accepted as Alternative to Data MinimisationGuidance
Guideline interprets binding PDPA provision; guideline itself is not legally binding
Issued by1
- AgencyPersonal Data Protection Commission (PDPC)Binding
PDPC administers and enforces the PDPA
Applies to1
- Concept'Organisation' (s 2(1); s 4)Binding
PDPA binds 'organisations' as defined in s 2(1), subject to s 4 exclusions
Maps across to4
- External frameworkArticle 10: Data and data governanceBindingGAGE analysis, not official
PDPA data protection obligations overlap Article 10 data governance for high-risk AI training data
- External frameworkClause 8: OperationStandardGAGE analysis, not official
PDPA-compliant data handling is part of AIMS operational control of AI systems
- External frameworkFunction: MAPGuidanceGAGE analysis, not official
Data protection impact awareness supports MAP context and risk identification
- External frameworkClause 6: PlanningStandardGAGE analysis, not official
Personal-data risk assessment for AI feeds AIMS risk planning
Mapped across from4
- InstrumentModel AI Governance Framework, 2nd Edition (2020)GuidanceGAGE analysis, not official
Sector- and technology-agnostic guidance intended to complement legal requirements incl. PDPA; not a substitute
- ConceptSensitive data disclosure through agent manipulationGuidanceGAGE analysis, not official
Agent-mediated disclosure of personal data engages PDPA protection obligations
- InstrumentFederal Trade Commission Act, Section 5BindingUnited StatesGAGE analysis, not official
The general purpose binding hook in each jurisdiction: consumer protection law in the United States, data protection law in Singapore
- ConceptThe United States has no comprehensive AI statuteBindingUnited StatesGAGE analysis, not official
Neither jurisdiction governs AI through an AI statute. Both reach it through law that predates it
Verified against the official source on 2026-08-17. GAGE is not affiliated with or endorsed by any agency named here, and nothing on this page is legal advice. How this is built and checked.