What does a PDPA compliant website mean in practice?
It means the site collects only the personal data it needs, tells people why, gets their consent, keeps that data secure and lets them reach someone responsible for it. The Personal Data Protection Act applies to the organisation, not to the website as a thing, so a PDPA compliant website in Singapore is really a website that makes your organisation's obligations easy to meet.
The PDPC's list of data protection obligations includes accountability, notification, consent, purpose limitation, accuracy, protection, retention limitation, transfer limitation, access and correction, and data breach notification. Almost every one of them touches the website in some way: the forms, the scripts, the hosting, the admin panel and the people who log into it.
This page explains how we translate those obligations into features. It is written from a developer's point of view and is not legal advice. Your lawyer or data protection officer decides what your notices say and which exceptions you rely on; we make sure the site does what those documents promise.
- Personal data covers names, phone numbers, emails, addresses, photos and similar details that identify a person.
- Business contact information, such as a work email given in a business capacity, is treated differently under the Act.
- Public agencies are outside the Act; private organisations of every size are inside it.
Each form should say, next to the submit button, what the data will be used for, and should ask for consent in a way that cannot be mistaken for anything else. That covers the Notification and Consent Obligations for most enquiry, booking and sign-up forms.
Our default pattern for a PDPA compliant website: a one-sentence purpose statement written for that specific form, a link to the full privacy notice, a required checkbox for the purpose the form exists for, and a separate optional checkbox for marketing. Neither box is ticked in advance. When the form is sent, the server stores the answers together with the exact notice text shown, the checkbox states and a time stamp.
Why store the wording? Because notices change. If someone asks what they agreed to in March, you can show them the March wording, not today's. That record also helps when you decide whether a contact may receive marketing messages later.
Keep marketing separate
Bundling marketing consent into a required checkbox makes it hard to argue that the consent was freely given. A separate, optional tick box avoids that and gives you a clean list of people who asked to hear from you.
Ask for less
Every field is data you must protect. If a callback form only needs a name and a phone number, it should not ask for date of birth or home address.
Can a Singapore website collect NRIC numbers?
Usually not. The PDPC's Advisory Guidelines on NRIC and other national identification numbers, in effect since 1 September 2019, say private organisations should collect, use or disclose NRIC numbers or copies of the NRIC only when required by law or when it is necessary to establish or verify a person's identity to a high degree of accuracy.
For a website, that rules out the old habit of using NRIC numbers as membership IDs, lucky draw entries or visitor registration. A PDPA compliant website in Singapore replaces them with a phone number, email, a partial identifier your counsel approves, or a system-generated member number.
Where full identity verification really is needed, such as some financial, healthcare or legal services, a better route is often Singpass login with Myinfo, which lets people share verified details they choose to share. Our Singpass integration guide explains how that works. If NRIC data must be stored, we encrypt it, restrict who can see it in the admin panel and log every access.
Does the PDPA require a cookie consent banner?
Not for every cookie, but for cookies that collect personal data for purposes the visitor has not asked for, such as ad targeting, consent is expected. The PDPC's Advisory Guidelines on the PDPA for Selected Topics (revised 17 May 2022) say consent is not needed for cookies that do not collect personal data, and may not be needed for activities the user has clearly requested, like keeping items in a shopping cart or staying logged in.
For targeted advertising through cookies, the same guidelines say the individual's consent is required, and that as good practice organisations should let people set cookie preferences within the website. They also note that a person's failure to manage browser settings does not by itself mean consent.
How we implement it on a PDPA compliant website: essential cookies run normally; analytics and advertising tags wait until the visitor opts in through a preference panel; the choice is stored and can be changed from a link in the footer. We test the result in the browser's developer tools to confirm nothing fires early, which is where many plugins quietly fail.
- Essential: session, security, cart, language. Load immediately.
- Analytics: page views and events. Load after opt-in, or configure without personal identifiers if your counsel agrees.
- Advertising: remarketing pixels and conversion tags. Load only after opt-in.
How do DNC Registry rules affect website sign-ups?
If you plan to send marketing calls, SMS or WhatsApp messages to Singapore numbers collected on your website, the Do Not Call provisions apply. The PDPC's guide to the DNC provisions says numbers must be checked against the registry within 21 days before sending a marketing message, unless an exception applies.
The guide describes exceptions such as clear and unambiguous consent from the person, and messages that relate solely to the subject of an ongoing relationship like a membership or subscription. It also notes that one-off transactions are not enough to create an ongoing relationship, and that business-to-business messages fall outside the DNC provisions.
On the website, that becomes a clearly worded, optional marketing checkbox that names the channels (calls, SMS, messaging apps), a stored record of that consent, and an export that flags which contacts have it. Your campaign tool can then skip or check the rest. We do not run DNC checks for you; your team or your messaging provider does that.
What should the privacy policy and DPO page on a PDPA compliant website contain?
At minimum, a clear way to reach the person responsible for data protection and an honest description of what the site collects. Under the Accountability Obligation, the PDPC expects organisations to designate a data protection officer and make that officer's business contact information available to the public.
We build two pages. The privacy notice, written or approved by your counsel, explains what data you collect, why, who you share it with, how long you keep it and how people can ask for access or correction. The data protection contact page gives the DPO's business email or a dedicated address, with a short form that routes requests to the right inbox and logs them.
Our part is making sure the notice matches reality. Before launch we list every form, script and third party on the site and share that inventory with whoever drafts the policy. A privacy notice that forgets the chat widget or the ad pixel is a common and avoidable gap.
Which security features does a PDPA compliant website need?
Reasonable security arrangements proportionate to the data you hold. The Protection Obligation does not list specific technologies, so we match the controls to the sensitivity of what your PDPA compliant website stores.
- HTTPS everywhere, with modern TLS settings and automatic certificate renewal.
- Personal data encrypted at rest in the database and in backups.
- Admin accounts with two-factor sign-in and role-based access, so a marketing intern cannot open patient records.
- Audit logs of who viewed, exported or deleted records, kept where admins cannot edit them.
- Rate limits and spam protection on forms to stop scraping and abuse.
- Dependencies and plugins kept patched, with a monthly review.
- Backups tested by actually restoring them, not just scheduled.
A brochure site that stores no form data on the server needs far less of this than a client portal. For portals and dashboards, the controls above are part of our custom software scope from US$900.
How does a website help you meet the data breach notification rules?
By making it quick to work out what happened and who was affected. The PDPC's guide to managing and notifying data breaches expects organisations to assess a suspected breach promptly, within 30 calendar days, and to notify the Commission no later than three calendar days after determining that a breach is notifiable.
A breach is notifiable if it results in, or is likely to result in, significant harm to affected individuals, or if it affects 500 or more individuals. Affected individuals must also be told as soon as practicable where required. Those clocks are short, and they start with facts your website either has or does not have.
A PDPA compliant website should therefore keep access logs, know which tables hold which kinds of personal data, and be able to list the individuals whose records sit in an affected system. We build that inventory and logging in, and write a one-page technical runbook for your team: who to call, how to lock admin access, how to pull logs. The decision to notify stays with you and your advisers.
Which third-party tools on a website create PDPA risk?
Anything that receives personal data from your pages: analytics, ad pixels, chat widgets, booking systems, form services, email marketing tools and AI chatbots. Each one is a place your visitors' data goes, and your notice should say so.
We start every rework with an inventory: which script loads on which page, what it sends and where its servers are. That also informs the Transfer Limitation Obligation, which requires personal data transferred outside Singapore to receive a standard of protection comparable to the PDPA. Many common tools process data abroad; your counsel decides what contractual protection is enough.
AI chatbots
Chat transcripts can contain names, phone numbers and health details. We configure retention limits, avoid sending more context to the AI model than needed, and document where the data is processed. See our AI chatbot guide for Singapore.
Form services
Hosted form tools are convenient but store your data on their servers. Where the data is sensitive, a form that posts to your own backend in the Singapore region keeps it under your control.
How do you make an existing website PDPA compliant?
Start with an inventory, fix the forms and scripts, then align the notice. That order matters, because a policy written before the inventory usually describes a site that does not exist.
- Step 1: list every page with a form, every stored field, and every third-party script.
- Step 2: remove fields you do not need, especially NRIC, full date of birth and home address.
- Step 3: add purpose notices, unticked consent and a separate marketing opt-in.
- Step 4: put analytics and ad tags behind a cookie preference panel.
- Step 5: move stored data behind encryption and role-based access, and switch on logging.
- Step 6: give the inventory to your counsel to update the privacy notice and DPO page.
- Step 7: set a retention period and schedule deletion of old enquiries.
For a site that also needs a new design or platform, it is often cheaper to rebuild than to patch. The website revamp guide covers that decision, and our WordPress page explains how we trim plugin sprawl.
How to choose a developer for a PDPA compliant website in Singapore
Pick someone who talks about data flows before design, and who is clear about where their job ends. A developer who claims to make you “PDPA certified” is overselling; a developer who never mentions consent is underselling.
- Do they ask what personal data each form collects and why?
- Will they show you, in the browser, that ad scripts wait for consent?
- Where will data be hosted, and in whose account?
- Who can access the admin panel, and is access logged?
- Will they give you a data inventory your lawyer can use?
- Do they say plainly that legal sign-off is yours?
Our part is the technical build and the inventory. The legal judgement belongs to your counsel, and we will not blur that line.
Working with a team in India on a PDPA compliant website
It is a fair question: can a team outside Singapore build a site that respects Singapore's data rules? Yes, provided the setup keeps your visitors' data in your accounts and gives us only the access the work requires.
In practice we build and test on staging with dummy data. Production hosting sits in your cloud account, often in the Singapore region; we receive a limited role for deployment and remove it at handover if you prefer. Where we must see live personal data to fix a bug, we agree it with you first and keep a note of the access. If your counsel treats that access as a transfer of personal data, their contractual requirements go into the written quote.
Working hours are easy: India is two and a half hours behind Singapore, so a 10 am SGT call is 7:30 am for us, and we overlap for most of your day, with WhatsApp replies seven days a week. The first two weeks usually cover the inventory, a fix list, the new forms on staging and a cookie panel you can test yourself. Quotes are in USD, invoices come from India, and payment is by Wise or bank wire.
Example: reworking a tuition centre's site for the PDPA
Picture a hypothetical enrichment centre whose enquiry form asks for the parent's NRIC, the child's full date of birth and school, and ticks “send me promotions” by default. The site also loads two advertising pixels on every page. This scenario is for illustration only.
The rework would drop the NRIC field entirely, ask for the child's level instead of full date of birth, add a purpose notice, untick and separate the marketing box, and put both pixels behind a cookie preference panel. Enquiries would move from a hosted form tool into the centre's own database in the Singapore region, with admin access limited to two staff members and every export logged.
We would hand the centre's lawyer a one-page inventory to update the privacy notice and DPO page. Timeline: about one to two weeks for a small site. Price depends on the number of forms and scripts, and appears line by line in the quote. For sites like this, see our tuition centre website guide.
PDPA compliant website needs by sector
The obligations are the same across sectors, but the data, and therefore the build, differs. Clinics hold health information, property agents collect seller phone numbers, restaurants store delivery addresses, and HR portals hold employment records.
Healthcare
Booking forms that collect symptoms or medical history need tighter access control and shorter retention. Our clinic website guide covers the healthcare advertising side as well.
Property
Seller and buyer leads plus marketing follow-up make DNC consent capture central. See our property agent website guide.
F&B and retail
Delivery addresses and order history should be kept only as long as needed, with marketing consent kept separate from checkout.
Education
Children's data calls for asking the minimum and involving parents in consent.
Related guides: clinic website design, property agent websites and restaurant website design in Singapore.
PDPA compliant website checklist before launch
Use this as a technical pre-launch list. It does not replace a legal review, but a site that passes it gives your counsel far less to fix.
- Every form has a purpose notice and a link to the privacy notice.
- Consent boxes are unticked; marketing consent is separate and optional.
- Consent wording and time stamps are stored with each submission.
- No NRIC or full ID fields unless your counsel confirms the legal basis.
- Analytics and ad scripts load only after opt-in, verified in the browser.
- Privacy notice and DPO business contact are published and linked in the footer.
- Stored data is encrypted, admin access is role-based, and access is logged.
- A retention period is set and old records are deleted on schedule.
- A breach runbook names who to call and how to pull logs.