SG Domain Registry

Legal

PDPA Policy

Personal Data Protection Act 2012 (Singapore) - Last updated: 18 September 2026

Singapore Domain Registration is committed to complying with the Personal Data Protection Act 2012 (PDPA) of Singapore. This policy explains our obligations and your rights under the PDPA.


1. What Is the PDPA?

The Personal Data Protection Act 2012 (PDPA) is Singapore's primary data protection legislation. It establishes rules governing the collection, use, disclosure, and care of personal data in Singapore. The PDPA recognises both the right of individuals to protect their personal data and the need of organisations to collect and use personal data for legitimate purposes.

2. Our Data Protection Obligations

As an organisation subject to the PDPA, we are committed to the following obligations:

  • Consent - We collect personal data only with your knowledge and consent, except where permitted by law
  • Purpose limitation - Personal data is collected only for purposes that a reasonable person would consider appropriate
  • Notification - We inform you of the purposes for which your data is collected before or at time of collection
  • Access and correction - We provide you access to your personal data and correct inaccuracies upon request
  • Accuracy - We make reasonable efforts to ensure personal data is accurate and complete
  • Protection - We implement reasonable security measures to protect your data from unauthorised access, use, or disclosure
  • Retention limitation - We cease retention of personal data when it is no longer necessary for any legal or business purpose
  • Transfer limitation - Personal data transferred outside Singapore is protected to a standard comparable to the PDPA

3. Do Not Call (DNC) Registry

We respect Singapore's Do Not Call (DNC) Registry. We will not send unsolicited telemarketing messages to Singapore telephone numbers registered in the DNC Registry without your prior consent. Transactional communications (such as order confirmations and renewal reminders) are not subject to DNC restrictions.

4. Data Breach Notification

In the event of a data breach that is notifiable under the PDPA (i.e., likely to result in significant harm to affected individuals), we will:

  • Notify the Personal Data Protection Commission (PDPC) within 3 business days of assessing that the breach is notifiable
  • Notify affected individuals as soon as reasonably practicable
  • Take immediate steps to contain and remediate the breach

5. Your Rights Under the PDPA

You have the right to:

  • Access - Request a copy of personal data we hold about you
  • Correction - Request that we correct inaccurate or incomplete personal data
  • Withdrawal of consent - Withdraw consent for non-essential data processing (note: withdrawal may affect your ability to use certain services)
  • Data portability - Request that we transmit your data to another organisation in a commonly used machine-readable format, where technically feasible

6. How to Submit a Request

To exercise your rights under the PDPA, submit a written request to our Data Protection Officer:

We will respond within 30 calendar days. We may require verification of your identity before processing your request.

7. Fees for Access Requests

We do not charge a fee for routine access or correction requests. In exceptional cases involving large volumes of data or significant administrative effort, we reserve the right to charge a reasonable fee and will notify you in advance.

8. Complaints and Escalation

If you are dissatisfied with how we handle your personal data, you may contact our Data Protection Officer at the email above. If your concerns remain unresolved, you may lodge a complaint with the Personal Data Protection Commission (PDPC) at www.pdpc.gov.sg.

9. Updates to This Policy

We review and update this PDPA Policy periodically to reflect changes in law or our data practices. The latest version is always available at this page.