WhatsApp Us

Singapore · Personal Data Protection Act · Built into the site, not bolted on

PDPA compliant website for Singapore: forms, cookies and records built in from day one

A PDPA compliant website in Singapore is one where every form, cookie and marketing message has been designed around the Personal Data Protection Act before launch, not patched after a complaint. BtechWaleTech is three freelance developers in India who build new sites from US$150, and rework existing ones, with consent-ready forms, NRIC-free fields, cookie choices, a data protection contact page and logs that help if a breach ever happens. Legal sign-off stays with your counsel. More on our Singapore work.

  • New website fromUS$150, with PDPA features planned in
  • Existing site reworkQuoted per form, cookie and integration
  • Portals with access logsFrom US$900
  • HostingYour account, Singapore region available
  • Legal wordingDrafted for your counsel to approve
  • BillingUSD quotes from India, Wise or wire
  • Consent and purpose notices on forms
  • No NRIC fields by default
  • Cookie preferences for analytics and ads
  • DPO contact page
  • DNC-aware marketing opt-ins
  • Access logs and encryption
  • Not legal advice

Three freelance developers in India · WhatsApp replies 7 days a week · Singapore sites built and reworked remotely

  • 0Marketing checkboxes ticked by default
  • 3Calendar days PDPC allows to notify a notifiable breach
  • 21Days before a marketing message within which a DNC check must be made
  • 2Working days to an itemised quote

The short answer

What makes a PDPA compliant website in Singapore?

A PDPA compliant website in Singapore tells visitors why their data is collected, gets consent before collecting it, avoids NRIC numbers unless the law or identity verification requires them, lets people control non-essential cookies, publishes a data protection contact, and protects stored data. BtechWaleTech builds these features into new sites from US$150; your counsel approves the legal wording.

Handling personal data in a custom portal or back office? Read how we approach outsourced software for Singapore companies, including overseas transfer questions, or check the website design cost guide for budgets.

Last updated

PDPA compliant website in Singapore, at a glance
Who needs itAny Singapore organisation collecting personal data through a website
Form featuresPurpose notice, unticked consent, separate marketing opt-in, consent log
Identity numbersNo NRIC field unless required by law or high-accuracy verification
CookiesEssential cookies only until visitors choose analytics or ads
Contact pagesPrivacy notice plus data protection officer business contact
SecurityHTTPS, encryption at rest, role-based access, audit logs, backups
Starting priceFrom US$150 new build; reworks quoted per item

What we build and fix

PDPA website work we take on

We do the technical build. Your lawyer or DPO decides the legal wording and policies; we put them into the site exactly as approved.

Why choose us

Cookie plugin, legal template or a site built for the PDPA

Three common ways Singapore SMEs try to make a website PDPA compliant, and what each one actually covers.

Cookie plugin, legal template or a site built for the PDPA
Area Cookie banner plugin only Downloaded privacy template Build or rework with BtechWaleTech
Contact and enquiry forms Not touched Not touched Purpose notice, unticked consent, consent log
NRIC and ID fields Not touched May mention NRIC generally Removed or replaced unless your counsel confirms a need
Analytics and ad scripts Blocked only if configured correctly Described in text Loaded only after opt-in, tested in the browser
Privacy notice Link to a page you provide Generic text, may not match your site Your counsel's text, matched to what the site really collects
DPO contact Not covered Placeholder Business contact page and email routing set up
Stored data security Not covered Not covered Encryption, access roles, audit logs, backups
Breach readiness Not covered Not covered Logs and data inventory that support a fast assessment
Starting cost Plugin subscription or free Free or low From US$150 for a new site

No website build makes an organisation PDPA compliant by itself: compliance also depends on your policies, staff practices and contracts, confirmed by your own legal adviser.

Pricing

PDPA compliant website pricing

A new brochure site of up to 100 pages with consent-ready forms, a cookie preference centre and a data protection contact page starts at US$150. Larger content sites start at US$300, and online stores with privacy-minded checkout start at US$750. Portals that hold sensitive records, with role-based access and audit logs, are custom software from US$900. Reworking an existing site is quoted per form, script and integration after a technical inventory. After two months of free maintenance, care starts at US$120/mo. All prices are USD starting points, itemised in writing before any work is billed.

Starting prices in INR and USD
ServiceIndia (INR)Worldwide (USD)Typical timelineWhat is included
Static website from ₹10,000 from US$150 1 to 2 weeks Up to 100 pages, Responsive design, Contact form and enquiry setup, Basic SEO tags and sitemap
SEO website (299+ pages) from ₹20,000 from US$300 3 to 5 weeks 299+ SEO pages, Keyword and page planning, Schema, sitemap, and internal linking, Design to deployment included
Ecommerce store from ₹50,000 from US$750 4 to 8 weeks Product and category pages, Payment gateway setup, Order and inventory basics, Performance tuning
Android & iOS app from ₹40,000 from US$600 6 to 10 weeks Android and iOS app (Flutter or React Native), Login, forms and push notifications, Admin panel and API connection, Google Play and App Store publishing
Custom web app or software from ₹60,000 from US$900 6 to 12 weeks Custom features and APIs, User accounts and roles, Admin panel, Deployment and handover
AI automation from ₹40,000 from US$600 2 to 4 weeks Workflow mapping, Tool and CRM integrations, AI agent or automation build, Testing and handover
Monthly SEO from ₹10,000/mo from US$150/mo Ongoing, monthly Technical fixes, On-page and content work, Local SEO and listings, Search Console reporting
Maintenance and support from ₹8,000/mo from US$120/mo Ongoing, monthly Content updates, Bug fixes, Backups and security checks, Speed and uptime checks

All prices are starting points, quoted in INR for India and USD for international clients, not fixed quotes. Final cost depends on the number of pages, features, integrations, content, and timelines. Share your requirement and you get an itemised estimate with nothing hidden. See full pricing.

What does a PDPA compliant website mean in practice?

It means the site collects only the personal data it needs, tells people why, gets their consent, keeps that data secure and lets them reach someone responsible for it. The Personal Data Protection Act applies to the organisation, not to the website as a thing, so a PDPA compliant website in Singapore is really a website that makes your organisation's obligations easy to meet.

The PDPC's list of data protection obligations includes accountability, notification, consent, purpose limitation, accuracy, protection, retention limitation, transfer limitation, access and correction, and data breach notification. Almost every one of them touches the website in some way: the forms, the scripts, the hosting, the admin panel and the people who log into it.

This page explains how we translate those obligations into features. It is written from a developer's point of view and is not legal advice. Your lawyer or data protection officer decides what your notices say and which exceptions you rely on; we make sure the site does what those documents promise.

  • Personal data covers names, phone numbers, emails, addresses, photos and similar details that identify a person.
  • Business contact information, such as a work email given in a business capacity, is treated differently under the Act.
  • Public agencies are outside the Act; private organisations of every size are inside it.

How should forms on a PDPA compliant website ask for consent?

Each form should say, next to the submit button, what the data will be used for, and should ask for consent in a way that cannot be mistaken for anything else. That covers the Notification and Consent Obligations for most enquiry, booking and sign-up forms.

Our default pattern for a PDPA compliant website: a one-sentence purpose statement written for that specific form, a link to the full privacy notice, a required checkbox for the purpose the form exists for, and a separate optional checkbox for marketing. Neither box is ticked in advance. When the form is sent, the server stores the answers together with the exact notice text shown, the checkbox states and a time stamp.

Why store the wording? Because notices change. If someone asks what they agreed to in March, you can show them the March wording, not today's. That record also helps when you decide whether a contact may receive marketing messages later.

Keep marketing separate

Bundling marketing consent into a required checkbox makes it hard to argue that the consent was freely given. A separate, optional tick box avoids that and gives you a clean list of people who asked to hear from you.

Ask for less

Every field is data you must protect. If a callback form only needs a name and a phone number, it should not ask for date of birth or home address.

Can a Singapore website collect NRIC numbers?

Usually not. The PDPC's Advisory Guidelines on NRIC and other national identification numbers, in effect since 1 September 2019, say private organisations should collect, use or disclose NRIC numbers or copies of the NRIC only when required by law or when it is necessary to establish or verify a person's identity to a high degree of accuracy.

For a website, that rules out the old habit of using NRIC numbers as membership IDs, lucky draw entries or visitor registration. A PDPA compliant website in Singapore replaces them with a phone number, email, a partial identifier your counsel approves, or a system-generated member number.

Where full identity verification really is needed, such as some financial, healthcare or legal services, a better route is often Singpass login with Myinfo, which lets people share verified details they choose to share. Our Singpass integration guide explains how that works. If NRIC data must be stored, we encrypt it, restrict who can see it in the admin panel and log every access.

Does the PDPA require a cookie consent banner?

Not for every cookie, but for cookies that collect personal data for purposes the visitor has not asked for, such as ad targeting, consent is expected. The PDPC's Advisory Guidelines on the PDPA for Selected Topics (revised 17 May 2022) say consent is not needed for cookies that do not collect personal data, and may not be needed for activities the user has clearly requested, like keeping items in a shopping cart or staying logged in.

For targeted advertising through cookies, the same guidelines say the individual's consent is required, and that as good practice organisations should let people set cookie preferences within the website. They also note that a person's failure to manage browser settings does not by itself mean consent.

How we implement it on a PDPA compliant website: essential cookies run normally; analytics and advertising tags wait until the visitor opts in through a preference panel; the choice is stored and can be changed from a link in the footer. We test the result in the browser's developer tools to confirm nothing fires early, which is where many plugins quietly fail.

  • Essential: session, security, cart, language. Load immediately.
  • Analytics: page views and events. Load after opt-in, or configure without personal identifiers if your counsel agrees.
  • Advertising: remarketing pixels and conversion tags. Load only after opt-in.

How do DNC Registry rules affect website sign-ups?

If you plan to send marketing calls, SMS or WhatsApp messages to Singapore numbers collected on your website, the Do Not Call provisions apply. The PDPC's guide to the DNC provisions says numbers must be checked against the registry within 21 days before sending a marketing message, unless an exception applies.

The guide describes exceptions such as clear and unambiguous consent from the person, and messages that relate solely to the subject of an ongoing relationship like a membership or subscription. It also notes that one-off transactions are not enough to create an ongoing relationship, and that business-to-business messages fall outside the DNC provisions.

On the website, that becomes a clearly worded, optional marketing checkbox that names the channels (calls, SMS, messaging apps), a stored record of that consent, and an export that flags which contacts have it. Your campaign tool can then skip or check the rest. We do not run DNC checks for you; your team or your messaging provider does that.

What should the privacy policy and DPO page on a PDPA compliant website contain?

At minimum, a clear way to reach the person responsible for data protection and an honest description of what the site collects. Under the Accountability Obligation, the PDPC expects organisations to designate a data protection officer and make that officer's business contact information available to the public.

We build two pages. The privacy notice, written or approved by your counsel, explains what data you collect, why, who you share it with, how long you keep it and how people can ask for access or correction. The data protection contact page gives the DPO's business email or a dedicated address, with a short form that routes requests to the right inbox and logs them.

Our part is making sure the notice matches reality. Before launch we list every form, script and third party on the site and share that inventory with whoever drafts the policy. A privacy notice that forgets the chat widget or the ad pixel is a common and avoidable gap.

Which security features does a PDPA compliant website need?

Reasonable security arrangements proportionate to the data you hold. The Protection Obligation does not list specific technologies, so we match the controls to the sensitivity of what your PDPA compliant website stores.

  • HTTPS everywhere, with modern TLS settings and automatic certificate renewal.
  • Personal data encrypted at rest in the database and in backups.
  • Admin accounts with two-factor sign-in and role-based access, so a marketing intern cannot open patient records.
  • Audit logs of who viewed, exported or deleted records, kept where admins cannot edit them.
  • Rate limits and spam protection on forms to stop scraping and abuse.
  • Dependencies and plugins kept patched, with a monthly review.
  • Backups tested by actually restoring them, not just scheduled.

A brochure site that stores no form data on the server needs far less of this than a client portal. For portals and dashboards, the controls above are part of our custom software scope from US$900.

How does a website help you meet the data breach notification rules?

By making it quick to work out what happened and who was affected. The PDPC's guide to managing and notifying data breaches expects organisations to assess a suspected breach promptly, within 30 calendar days, and to notify the Commission no later than three calendar days after determining that a breach is notifiable.

A breach is notifiable if it results in, or is likely to result in, significant harm to affected individuals, or if it affects 500 or more individuals. Affected individuals must also be told as soon as practicable where required. Those clocks are short, and they start with facts your website either has or does not have.

A PDPA compliant website should therefore keep access logs, know which tables hold which kinds of personal data, and be able to list the individuals whose records sit in an affected system. We build that inventory and logging in, and write a one-page technical runbook for your team: who to call, how to lock admin access, how to pull logs. The decision to notify stays with you and your advisers.

Which third-party tools on a website create PDPA risk?

Anything that receives personal data from your pages: analytics, ad pixels, chat widgets, booking systems, form services, email marketing tools and AI chatbots. Each one is a place your visitors' data goes, and your notice should say so.

We start every rework with an inventory: which script loads on which page, what it sends and where its servers are. That also informs the Transfer Limitation Obligation, which requires personal data transferred outside Singapore to receive a standard of protection comparable to the PDPA. Many common tools process data abroad; your counsel decides what contractual protection is enough.

AI chatbots

Chat transcripts can contain names, phone numbers and health details. We configure retention limits, avoid sending more context to the AI model than needed, and document where the data is processed. See our AI chatbot guide for Singapore.

Form services

Hosted form tools are convenient but store your data on their servers. Where the data is sensitive, a form that posts to your own backend in the Singapore region keeps it under your control.

How do you make an existing website PDPA compliant?

Start with an inventory, fix the forms and scripts, then align the notice. That order matters, because a policy written before the inventory usually describes a site that does not exist.

  • Step 1: list every page with a form, every stored field, and every third-party script.
  • Step 2: remove fields you do not need, especially NRIC, full date of birth and home address.
  • Step 3: add purpose notices, unticked consent and a separate marketing opt-in.
  • Step 4: put analytics and ad tags behind a cookie preference panel.
  • Step 5: move stored data behind encryption and role-based access, and switch on logging.
  • Step 6: give the inventory to your counsel to update the privacy notice and DPO page.
  • Step 7: set a retention period and schedule deletion of old enquiries.

For a site that also needs a new design or platform, it is often cheaper to rebuild than to patch. The website revamp guide covers that decision, and our WordPress page explains how we trim plugin sprawl.

How to choose a developer for a PDPA compliant website in Singapore

Pick someone who talks about data flows before design, and who is clear about where their job ends. A developer who claims to make you “PDPA certified” is overselling; a developer who never mentions consent is underselling.

  • Do they ask what personal data each form collects and why?
  • Will they show you, in the browser, that ad scripts wait for consent?
  • Where will data be hosted, and in whose account?
  • Who can access the admin panel, and is access logged?
  • Will they give you a data inventory your lawyer can use?
  • Do they say plainly that legal sign-off is yours?

Our part is the technical build and the inventory. The legal judgement belongs to your counsel, and we will not blur that line.

Working with a team in India on a PDPA compliant website

It is a fair question: can a team outside Singapore build a site that respects Singapore's data rules? Yes, provided the setup keeps your visitors' data in your accounts and gives us only the access the work requires.

In practice we build and test on staging with dummy data. Production hosting sits in your cloud account, often in the Singapore region; we receive a limited role for deployment and remove it at handover if you prefer. Where we must see live personal data to fix a bug, we agree it with you first and keep a note of the access. If your counsel treats that access as a transfer of personal data, their contractual requirements go into the written quote.

Working hours are easy: India is two and a half hours behind Singapore, so a 10 am SGT call is 7:30 am for us, and we overlap for most of your day, with WhatsApp replies seven days a week. The first two weeks usually cover the inventory, a fix list, the new forms on staging and a cookie panel you can test yourself. Quotes are in USD, invoices come from India, and payment is by Wise or bank wire.

Example: reworking a tuition centre's site for the PDPA

Picture a hypothetical enrichment centre whose enquiry form asks for the parent's NRIC, the child's full date of birth and school, and ticks “send me promotions” by default. The site also loads two advertising pixels on every page. This scenario is for illustration only.

The rework would drop the NRIC field entirely, ask for the child's level instead of full date of birth, add a purpose notice, untick and separate the marketing box, and put both pixels behind a cookie preference panel. Enquiries would move from a hosted form tool into the centre's own database in the Singapore region, with admin access limited to two staff members and every export logged.

We would hand the centre's lawyer a one-page inventory to update the privacy notice and DPO page. Timeline: about one to two weeks for a small site. Price depends on the number of forms and scripts, and appears line by line in the quote. For sites like this, see our tuition centre website guide.

PDPA compliant website needs by sector

The obligations are the same across sectors, but the data, and therefore the build, differs. Clinics hold health information, property agents collect seller phone numbers, restaurants store delivery addresses, and HR portals hold employment records.

Healthcare

Booking forms that collect symptoms or medical history need tighter access control and shorter retention. Our clinic website guide covers the healthcare advertising side as well.

Property

Seller and buyer leads plus marketing follow-up make DNC consent capture central. See our property agent website guide.

F&B and retail

Delivery addresses and order history should be kept only as long as needed, with marketing consent kept separate from checkout.

Education

Children's data calls for asking the minimum and involving parents in consent.

Related guides: clinic website design, property agent websites and restaurant website design in Singapore.

PDPA compliant website checklist before launch

Use this as a technical pre-launch list. It does not replace a legal review, but a site that passes it gives your counsel far less to fix.

  • Every form has a purpose notice and a link to the privacy notice.
  • Consent boxes are unticked; marketing consent is separate and optional.
  • Consent wording and time stamps are stored with each submission.
  • No NRIC or full ID fields unless your counsel confirms the legal basis.
  • Analytics and ad scripts load only after opt-in, verified in the browser.
  • Privacy notice and DPO business contact are published and linked in the footer.
  • Stored data is encrypted, admin access is role-based, and access is logged.
  • A retention period is set and old records are deleted on schedule.
  • A breach runbook names who to call and how to pull logs.

Obligations to features

How PDPA obligations map to website features

Obligation names from the PDPC's overview. Technical support only; your counsel confirms how each applies to you.

How PDPA obligations map to website features
PDPA obligationWhat it asks, in shortWhat the website does
Notification Tell people the purposes for collectionPurpose notice beside each form
Consent Collect only with consent, unless an exception appliesUnticked checkboxes, consent log with wording and time
Purpose limitation Use data only for reasonable, notified purposesSeparate marketing opt-in; fields tied to a purpose
Protection Reasonable security arrangementsEncryption, access roles, logs, patching
Retention limitation Stop keeping data once no longer neededScheduled deletion of old submissions
Access and correction Respond to access and correction requestsRequest form routed to the DPO, searchable records
Accountability Designate a DPO and publish business contactDPO contact page and footer link
Data breach notification Assess and notify within set timelinesAudit logs, data inventory, technical runbook

Form fields

Which form fields to keep, change or remove

A starting point for discussion with your counsel. The right answer depends on your purpose.

Which form fields to keep, change or remove
FieldTypical needOur default
Name Needed for almost every enquiryKeep
Mobile number Needed for callbacks and bookingsKeep, with a separate marketing opt-in
Email Needed for confirmationsKeep
NRIC number or copy Rarely needed onlineRemove unless required by law or for high-accuracy verification
Full date of birth Often only age or level is neededReplace with age band or level
Home address Needed only for delivery or home visitsAsk only at the step that needs it
Health or financial details Sector-specificCollect only with tight access control and retention

Cookies

Based on the PDPC's Advisory Guidelines on the PDPA for Selected Topics, chapter on online activities.

How a PDPA compliant website treats each cookie type
Cookie typeExampleLoads when
Strictly necessary Session, security, load balancingImmediately
User-requested function Shopping cart, login, languageImmediately, as the user asked for it
Preference Remembered outlet or themeImmediately if no personal data; else after choice
Analytics Page views, eventsAfter opt-in, or configured without personal identifiers
Advertising Remarketing and conversion pixelsOnly after opt-in

Across Singapore

Where PDPA website work comes up most

We work remotely for organisations across Singapore. These are the business areas where data-heavy websites are common.

  • Raffles Place and the CBD

    Financial advisers, insurers and professional firms whose client portals and enquiry forms handle financial details that call for tight access control and logging.

  • Marina Bay

    Regional headquarters running Singapore-facing websites alongside global ones, where cookie behaviour and overseas data flows need to be mapped per site.

  • Novena

    Specialist clinics and medical groups near the hospital cluster whose booking forms collect health information and need short retention and restricted access.

  • one-north

    Start-ups and research-linked firms building sign-up flows and apps, where designing consent and data minimisation in early is cheaper than retrofitting.

  • Tanjong Pagar

    Tech, marketing and F&B businesses running ad campaigns, whose sites need analytics and pixels held back until visitors opt in.

  • Paya Lebar

    SMEs and service firms in the eastern business hub whose older enquiry forms often still ask for more personal data than they need.

  • Jurong Lake District

    Retail, logistics and training providers in the west collecting delivery addresses and course registrations that need clear retention rules.

  • Bishan

    Tuition and enrichment centres whose forms collect children's details, making data minimisation and parent consent a priority.

  • Tampines

    Heartland clinics, gyms and service businesses with membership sign-ups that should not rely on NRIC numbers as member IDs.

  • Changi Business Park

    Operations and back-office teams whose internal portals hold employee data and benefit from role-based access and audit logs.

  • Orchard Road

    Retail and beauty brands with loyalty programmes and marketing lists, where separate marketing consent and DNC-aware exports matter.

  • Woodlands

    Northern SMEs and logistics firms whose delivery and booking forms collect addresses and phone numbers daily.

  • Kallang and Geylang

    Event organisers and sports businesses running ticketing and registration pages that collect attendee data in bursts.

  • Ubi and Kaki Bukit

    Light-industrial firms moving customer and supplier records online, often for the first time, and wanting a clean privacy setup from the start.

How it works

How we build or rework a PDPA compliant website

  1. Data inventory

    We list every form, stored field, script and third-party tool on the planned or existing site, and where each piece of data goes, in a document your counsel can read.

  2. Quote after the inventory

    You receive an itemised USD quote for each fix or feature within about two working days. Nothing is billed until you approve it in writing.

  3. Minimise and redesign forms

    Unneeded fields go, purpose notices and unticked consent boxes arrive, and marketing opt-ins are split out and recorded with their wording.

  4. Cookie panel and scripts

    Analytics and advertising tags move behind a preference panel, and we show you in the browser that nothing loads before consent.

  5. Secure storage and logs

    Data moves to encrypted storage in your hosting account, admin roles are set up, and access and export logs are switched on.

  6. Counsel review and launch

    Your lawyer or DPO approves the notice, DPO page and consent text, we publish exactly that, and two months of free maintenance begin.

Questions

PDPA compliant website in Singapore: frequently asked questions

What is a PDPA compliant website?

It is a website designed so the organisation behind it can meet its duties under Singapore's Personal Data Protection Act: telling people why data is collected, getting consent, collecting only what is needed, protecting stored data, publishing a data protection contact and being able to respond to requests and breaches. Compliance belongs to the organisation, confirmed by its own legal adviser.

How much does a PDPA compliant website cost in Singapore?

With BtechWaleTech, a new website with consent-ready forms, a cookie preference panel and a DPO contact page starts at US$150. Online stores start at US$750, and secure portals with audit logs start at US$900. Reworking an existing site is quoted per form and script after an inventory. All are USD starting prices, itemised in writing.

Does my website need a cookie banner under the PDPA?

It depends on what your cookies do. The PDPC's guidelines say consent is not needed for cookies that do not collect personal data or for activities the user clearly requested, but consent is required for targeted advertising that uses personal data through cookies. As good practice, the PDPC suggests letting people set cookie preferences within the website.

Can my website ask for NRIC numbers?

Only in narrow cases. The PDPC's NRIC advisory guidelines, in effect since 1 September 2019, allow private organisations to collect NRIC numbers or copies only when required by law or when necessary to verify identity to a high degree of accuracy. Most websites should use a phone number, email or system-generated ID instead. Your counsel should confirm any exception.

Is Google Analytics allowed under the PDPA?

Analytics can be used, but it may collect identifiers such as cookies and IP-derived data, so it should be covered in your privacy notice and, where it collects personal data, loaded only with consent or configured to avoid personal identifiers. We set it up behind a preference panel by default and let your counsel decide on the configuration.

Do I need a privacy policy on my Singapore website?

If your website collects personal data, people need to be told the purposes, and a privacy notice is the usual way to do that. The PDPC also expects organisations to make information about their data protection policies available and publish the business contact of their data protection officer. Your lawyer should write or approve the text; we publish and link it.

Where should the DPO contact appear on the website?

In a place people can find without searching: usually a data protection contact page linked from the footer and from the privacy notice. It should give a business email or form that reaches the data protection officer. We route that form to the right inbox and log requests so access and correction requests do not get lost.

How do the DNC rules affect my website's sign-up form?

If you will send marketing calls, SMS or messaging-app messages to Singapore numbers, the PDPC's guide says numbers must be checked against the DNC Registry within 21 days before sending, unless an exception such as clear and unambiguous consent applies. A separate, clearly worded marketing checkbox with a stored consent record gives your team that evidence.

What happens if my website has a data breach?

Under the PDPA, you assess whether the breach is notifiable, which the PDPC expects within 30 calendar days. If it is likely to cause significant harm or affects 500 or more people, you notify the PDPC within three calendar days of that determination and tell affected individuals where required. Logs and a data inventory make that assessment much faster.

Can you make my existing website PDPA compliant?

We can do the technical side: an inventory of every form, script and stored field, then fixes such as removing unneeded fields, adding purpose notices and unticked consent, moving scripts behind a cookie panel and securing stored data. Your counsel then updates the privacy notice using our inventory. Whether your organisation is compliant overall is for them to confirm.

Is it safe to have a team in India build a PDPA-sensitive website?

It can be, with the right setup. We build and test with dummy data, host production in your own cloud account, often in the Singapore region, and use limited access roles you can remove. If we need to see live personal data to fix something, we agree it first. Your counsel decides whether any contractual terms are needed for that access.

Do you provide legal advice on the PDPA?

No. We are developers, not lawyers. We explain what the PDPC's published guidance says in plain terms so you can brief your adviser, and we build what they approve. Decisions about legal bases, exceptions, notice wording and whether to notify a breach belong to your organisation and its counsel.

How long does a PDPA website rework take?

For a small brochure site with a few forms and scripts, usually one to two weeks after the inventory. A larger site with many forms, an online store or a member portal can take several weeks, especially if data must move to new, secure storage. Counsel review of the notice often sets the final launch date.

Does the PDPA apply to small businesses and sole proprietors?

The PDPA applies to organisations in Singapore that collect, use or disclose personal data, and the PDPC's own guidance addresses small businesses directly. Size does not remove the obligations, though the reasonable level of security and process may differ. A small business website with one enquiry form still needs a purpose notice and consent.

Will a PDPA compliant website affect my SEO?

Not in a harmful way. Consent panels built properly do not block search engines, and privacy notices and contact pages are ordinary pages. Analytics data may be thinner if some visitors decline tracking, which is the trade-off of respecting their choice. Google Search Console, which does not rely on your site's cookies, still reports search performance.

Can my AI chatbot be PDPA compliant?

A chatbot can be set up to support your obligations: a notice before the chat starts, limits on what is stored and for how long, no unnecessary personal data sent to the AI model, and clear information on where processing happens. We configure those settings; your counsel reviews the notice and any overseas processing.

How do I pay for PDPA website work?

You receive an itemised quote in USD and invoices from India, payable by Wise or bank wire. Milestones and any extra terms your counsel asks for are written into the quote before work begins, and nothing is billed until you approve it. For the tax treatment of an overseas invoice, ask your accountant.

Who owns the data and the website after the build?

You do. The domain, hosting account, database, code and every record belong to your organisation, and you receive all logins at handover. We do not keep copies of your visitors' data. After launch you can remove our access entirely or keep a limited role for maintenance.

What does ongoing PDPA-related maintenance involve?

Keeping plugins and dependencies patched, checking that cookie behaviour still works after tag changes, running scheduled deletion of old records, reviewing access logs and testing backups. The first two months after launch are free; after that, care plans start at US$120/mo. We also update the inventory when you add a new tool.

Should my ecommerce checkout collect less data?

Usually yes. Offer guest checkout, ask for a delivery address only when items ship, avoid date of birth unless you sell age-restricted goods, and keep marketing consent as a separate unticked box. Payment details should be handled by your payment provider's secure fields rather than stored on your server.

Can a PDPA compliant website still run remarketing ads?

Yes, with consent. Advertising pixels and remarketing tags load only after a visitor opts in through the cookie preference panel. Your audiences will be smaller than with blanket tracking, but the people in them chose to be there, which matches the PDPC's view that targeted advertising through cookies needs consent.

Next step

Plan a PDPA compliant website for your Singapore business

Send your current site link or your plans, and tell us what data you collect. We reply with a technical inventory outline and an itemised USD quote in about two working days. Your counsel keeps the final say on legal wording.