Singapore Data Removal Guide (2026)
Singapore residents are protected under the Personal Data Protection Act 2012 (PDPA), granting individuals enforceable rights to withdraw consent, access records, correct inaccuracies, and stop unsolicited telemarketing.
Research status: published guide pending fresh official-source re-verification.
This page is educational orientation, not legal advice. The legal fields below are a research snapshot; eligibility, exemptions, deadlines, penalty rules and broker routes can change. Verify the current statute and regulator guidance before relying on a right or filing a complaint.
At a glance
- Governing law
- PDPA
- Response deadline
- 30 calendar days (or provide notice of extension timeline)
- Regulator
- Personal Data Protection Commission (PDPC)
- Private right of action
- Yes: right of private action in civil court under Section 48O PDPA after PDPC decision
Personal Data Protection Act 2012 (PDPA)
The PDPA establishes a baseline standard of data protection for private-sector organizations in Singapore across 11 key obligations (including Consent, Purpose Limitation, Access & Correction, Retention Limitation, and Data Breach Notification). Enforced by the PDPC, financial penalties can reach up to 10% of annual local turnover.
What rights do Singapore residents have?
- โRight to withdraw consent for collection, use, or disclosure of personal data (Section 16)
- โRight to access personal data and information on past-year disclosures (Section 21)
- โRight to correct errors or omissions in personal data (Section 22)
- โRight to data portability across participating service providers
- โRight to register on the national Do Not Call (DNC) Registry
- โRight to lodge complaints with the Personal Data Protection Commission (PDPC)
Who holds your data in Singapore?
In Singapore, data brokers and marketing aggregators frequently scrape corporate directorship details from the Accounting and Corporate Regulatory Authority (ACRA BizFile), real estate property portals, professional networking sites, and consumer rewards programs. Global B2B sales databases actively trade executive contact information.
Public-record sources brokers scrape
- ACRA (Accounting and Corporate Regulatory Authority) company filings and business registry
- Commercial telephone directories and consumer marketing lists
- Real estate transaction disclosures and property listings
- Global B2B contact intelligence and talent recruitment databases
How to remove your data in Singapore
- 1Submit Section 16 withdrawal of consent notices to corporate data brokers and direct marketing organizations.
- 2Register your Singapore telephone number on the national Do Not Call (DNC) Registry at dnc.gov.sg.
- 3Request data deletion from commercial directories and marketing list resellers.
- 4File a formal complaint with the PDPC if an organization fails to honor your withdrawal of consent within 30 days.
Ready to remove
Review 1009 US/global broker workflows for $9
Much of Singapore residents' data is held by US-based people-search brokers. OfflistMe drafts a legally structured deletion email for each one, sent from your own inbox, no account, no ID upload. Pair it with the Singapore-specific steps above.
Request Removal NowWhat if a company ignores your request?
File a complaint with the Personal Data Protection Commission (PDPC). The maximum penalty in Singapore is Up to SGD $1 million or 10% of annual turnover in Singapore for large organizations, and you may have a private right of action (Yes: right of private action in civil court under Section 48O PDPA after PDPC decision).
File a complaint with the Personal Data Protection Commission (PDPC) โFAQ: Singapore data removal
What is the Do Not Call (DNC) Registry in Singapore?+
The DNC Registry allows individuals to register their Singapore phone numbers to opt out of receiving unsolicited telemarketing messages and phone calls from organizations under the PDPA.
What happens when you withdraw consent under Section 16 of Singapore's PDPA?+
Upon receiving notice of consent withdrawal, an organization must inform you of the likely consequences, cease collecting, using, or disclosing your personal data, and delete or anonymize the data in its possession unless required by law.