Personal Data Protection Commission
The Personal Data Protection Commission is Singapore's statutory data protection regulator administering the Personal Data Protection Act 2012, serving all organisations operating in Singapore and Singapore residents through enforcement, advisory guidelines, mandatory e-services, and AI governance frameworks.
- Company typePrivate
- Founded2012
- HeadquartersSingapore, Singapore
- Headcount101–250
- GTM typeB2B and B2C
- OfferingServices
What Personal Data Protection Commission does
The Personal Data Protection Commission (PDPC) is Singapore's statutory data protection authority, established under the Personal Data Protection Act 2012 and operating under the Infocomm Media Development Authority (IMDA). PDPC administers and enforces the PDPA, which establishes a baseline standard for the collection, use, and disclosure of personal data by all organisations operating in Singapore, with financial penalties of up to S$1 million or 10% of annual Singapore turnover for non-compliance. The Commission's mandate covers Singapore organisations of all sizes and sectors, the Singapore public, and selected cross-border data flows, with Commissioner Denise Wong appointed in April 2026 concurrently serving as Assistant Chief Executive of IMDA's Data Innovation and Protection Group.
PDPC's operational portfolio comprises mandatory e-services (DPO Registration, Data Breach Notification Portal, DNC Registry with API access), advisory guidelines (Generative AI, AI Recommendation Systems, Children's Data, NRIC handling), practical tools (PATO, Data Protection Notice Generator, C.A.R.E. breach response framework, Self-Assessment Tool), and training products delivered through approved providers (E-Learning, Fundamentals of PDPA, Practitioner Certificate WSQ with IAPP certification). It also co-operates the PET Sandbox with IMDA and publishes enforcement decisions (387 to date) and voluntary undertakings as public regulatory precedent. PDPC holds no patents or proprietary technology assets of its own; its technical footprint lies in regulatory frameworks, guidance documentation, and government e-services.
As a Singapore government statutory board, PDPC is funded through public budget allocations rather than commercial revenue. There is no pricing model for its regulatory outputs — advisory guidelines, enforcement decisions, and e-services are free and publicly accessible. Limited fee-bearing channels include DNC Registry organisation accounts (S$32.70 one-time for Singapore-registered organisations, S$65.40 for overseas organisations) and training courses delivered by third-party providers with SSG funding support, but these are not PDPC's commercial revenue. Its growth model is defined by expanding regulatory perimeter (AI governance, NRIC enforcement), international cooperation (MOUs/MOCs with Japan, Korea, Hong Kong in 2026), and ecosystem convening (Singapore Data Festival, IAPP Asia Forum anchoring).
Personal Data Protection Commission firmographics
Firmographics- Name
- Personal Data Protection Commission
- Legal name
- Personal Data Protection Commission
- Website
- https://pdpc.gov.sg
- Company type
- Private
- Founded year
- 2012
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Short description
- The Personal Data Protection Commission is Singapore's statutory data protection regulator administering the Personal Data Protection Act 2012, serving all organisations operating in Singapore and Singapore residents through enforcement, advisory guidelines, mandatory e-services, and AI governance frameworks.
- Ownership category
- akta.pro rank
Personal Data Protection Commission industry classification
Industry- Product category
- Data Protection Regulatory Services
- NAICS
- International Affairs (92812)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Privacy Management (Consent, DSAR, RoPA) (HDADAFAH)
- akta.pro secondary industry
- Data Security & Access Governance for Data (Entitlements/Policy Enforcement) (HDAEADAH)
Keywords
Where Personal Data Protection Commission is headquartered
LocationHeadquarters
- HQ city
- Singapore
- HQ country
- Singapore
- HQ region
- Asia
Markets served
Personal Data Protection Commission business model
Business model- GTM type
- B2B and B2C
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure, Others
Distribution channels3 records
Marketing channels9 records
Personal Data Protection Commission product offering
Product offeringCore offering
PDPC is Singapore's national data protection regulator that administers and enforces the Personal Data Protection Act (PDPA) 2012. It operates the Do Not Call (DNC) Registry, mandates Data Protection Officer (DPO) registration and Data Breach Notification (within 3 calendar days), issues advisory guidelines (including on Generative AI and AI recommendation/decision systems), and publishes implementation guides such as the C.A.R.E. breach response framework, PET Sandbox with IMDA, guides on federated learning and synthetic data generation, and the PDPA Assessment Tool for Organisations (PATO). Its outputs are delivered free of charge through the pdpc.gov.sg portal and dedicated e-service portals, supplemented by fee-based DNC Registry access for organisations and approved third-party training programmes (e-learning, Fundamentals of PDPA, Practitioner Certificate WSQ with IAPP).
Product overview
The Personal Data Protection Commission (PDPC) is Singapore's data protection regulator administering the Personal Data Protection Act (PDPA). PDPC provides a comprehensive ecosystem of regulatory frameworks, digital services, and guidance products. The core offerings include the PDPA legislative framework, the Do Not Call (DNC) Registry, and mandatory services such as DPO Registration and Data Breach Notification Portal. These are supported by the C.A.R.E. Framework for breach response and the PET Sandbox for privacy-enhancing technology experimentation. PDPC's guidance portfolio includes advisory guidelines on AI governance (Generative AI and AI Recommendation Systems), implementation guides (Federated Learning, Synthetic Data Generation, ICT Systems), and practical tools (PATO assessment, Notice Generator, Self-Assessment tools). Training products range from free E-Learning to professional certification (Practitioner Certificate with IAPP). Enforcement mechanisms include published Commission Decisions and Voluntary Undertakings. Public engagement is delivered through Singapore Data Festival, Privacy Awareness Week, and sector-specific guidance for healthcare, education, real estate, and telecommunications sectors.
Differentiator
Problem solved
Functional benefit
Products and services
- Personal Data Protection Act (PDPA) Framework Singapore's baseline data protection legislation establishing 11 obligations governing the collection, use, disclosure and care of personal data by organisations; administered and enforced exclusively by PDPC.
- Do Not Call (DNC) Registry A government registry allowing individuals to register Singapore telephone numbers to opt out of specified marketing communications and enabling organisations to check numbers before sending marketing messages, with a 21-day grace period for compliance.
- Data Protection Officer (DPO) Registration Service Mandatory e-service through which Singapore organisations designate and register their Data Protection Officer with PDPC, ensuring public availability of DPO contact information and regulatory compliance under the PDPA.
- Data Breach Notification (DBN) Portal E-service portal through which organisations submit mandatory data breach notifications to PDPC within three calendar days, supported by self-assessment tools and C.A.R.E. framework guidance for breach management.
- C.A.R.E. Data Breach Response Framework A structured four-step breach response framework (Contain, Assess, Report, Evaluate) for organisations to manage and respond to personal data breaches under the PDPA, with a three-day notification deadline to PDPC.
- Advisory Guidelines on Use of Personal Data in Generative AI Advisory guidelines clarifying how PDPA obligations apply across the AI development lifecycle, including consent, web scraping, and mandatory user notifications when personal data is used to train generative AI models.
- Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems Advisory guidelines addressing data protection obligations when organisations use personal data in AI-powered recommendation engines and automated decision-making systems.
- PET Sandbox (Privacy-Enhancing Technologies Sandbox) Regulatory sandbox operated jointly with IMDA allowing organisations to experiment with privacy-enhancing technologies including federated learning and synthetic data generation, with 11 organisations facilitated across finance, healthcare, construction, transport and advertising tech sectors.
- Guide on Federated Learning Practical implementation guidance developed with GovTech Singapore enabling AI collaboration across distributed datasets while keeping personal data stored locally through federated learning approaches.
- Guide on Synthetic Data Generation Updated guidance on generating artificial datasets that mirror real data without containing personal information, supporting privacy-preserving AI development under PDPC oversight.
- Guide to Data Protection Practices for ICT Systems Updated implementation guidance with current best practices from recent data breaches and new guidance on protecting AI systems within ICT environments.
- PDPA Assessment Tool for Organisations (PATO) Self-assessment tool enabling organisations to evaluate their data protection practices against PDPA requirements and identify compliance gaps.
- Data Protection Notice Generator Online tool that generates basic privacy notices for organisations to inform stakeholders about how their personal data is collected, used and disclosed.
- Self-Assessment Tool for Data Breach Notification Online self-assessment tool that guides DPOs through questions based on legal criteria to determine whether a data breach meets notification thresholds under the PDPA.
- Data Protection Essentials (DPE) Framework Framework provided jointly with IMDA to help SMEs build a data protection programme with practical implementation guidance for PDPA compliance.
- Guide to Cross-Border Data Transfers Guidance document helping organisations comply with PDPA requirements when transferring personal data outside Singapore, including coverage of APEC Cross-Border Privacy Rules (CBPR) and Privacy Recognition for Processors (PRP) certifications.
- E-Learning on Data Protection Free online training programme of approximately 60 minutes covering the main data protection obligations under the PDPA for organisational staff and DPOs.
- Fundamentals of PDPA Course Three-day introductory course endorsed by PDPC and delivered through approved training providers, designed for new DPOs to understand their role and responsibilities under the PDPA.
- Practitioner Certificate in Personal Data Protection (Singapore) WSQ Course Intermediate three-day preparatory WSQ-aligned course for DPOs to gain practical data governance and data protection knowledge, with an optional PDPC-IAPP certification examination.
- Data Protection Trustmark National certification under Singapore Standards recognising organisations with robust data protection practices, part of Singapore's data and AI governance ecosystem.
Quantifiable outcome
- Singapore Data Festival 2026 drew 3,000 attendees, 47 partner events, and 19 regulators over 5 days, demonstrating the breadth of PDPC's influence in the data protection ecosystem.
- +3 more outcomes
Companies that use Personal Data Protection Commission
Customer profileSegments2 records
Ideal customer profiles2 records
Personal Data Protection Commission technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration1 record
AI capability3 records
Feature12 records
Personal Data Protection Commission partnerships and signals
Strategic signalPartnerships
14 partnerships are on record, tiered core and flagship.
- Japan's Personal Information Protection CommissioncorePDPC signed a Memorandum of Cooperation (MOC) with Japan's Personal Information Protection Commission to strengthen international cooperation on data protection. The MOC was announced on 20 July 2026 and is part of PDPC's broader strategy to align data protection frameworks across Asia-Pacific, facilitating cross-border data flows and sharing best practices in AI governance and privacy-enhancing technologies.
- Republic of Korea's Personal Information Protection CommissioncorePDPC signed a Memorandum of Understanding (MOU) with the Republic of Korea's Personal Information Protection Commission to enhance cross-border data protection cooperation. The MOU was announced on 16 June 2026 as part of PDPC's international cooperation efforts to align regulatory approaches with key Asia-Pacific data protection authorities.
- Hong Kong, China's Data Protection AuthoritycorePDPC signed a Memorandum of Understanding (MOU) with Hong Kong, China's data protection authority to strengthen international cooperation on personal data protection. The MOU was part of a dual signing announced on 16 June 2026 alongside the Republic of Korea MOU.
- IAPP (International Association of Privacy Professionals)flagshipPDPC collaborates with IAPP to anchor the IAPP Asia Forum within Singapore Data Festival, with Commissioner Denise Wong announcing a renewed Memorandum of Intent confirming Singapore as the home for IAPP Asia Forum for the next three years. The partnership includes AI Governance Professional training and the co-issuance of the PDPC-IAPP Practitioner Certificate for Personal Data Protection.
- Infocomm Media Development Authority (IMDA)flagshipPDPC operates under IMDA, with Commissioner Denise Wong serving concurrently as Assistant Chief Executive, Data Innovation and Protection Group (DIPG) at IMDA. IMDA and PDPC jointly launched the Guide on Federated Learning, updated Guide on Synthetic Data Generation, and operate the PET Sandbox with 11 organisations facilitated across multiple sectors.
- GovTech SingaporecorePDPC collaborated with GovTech Singapore to develop the Guide on Federated Learning, providing practical implementation guidance for practitioners. GovTech also operates the AI Guardian platform (with Litmus and Sentinel testing tools) and LionGuard 2 multilingual content moderation classifier, aligned with frameworks developed by IMDA and PDPC.
- Ant InternationalcorePDPC evaluated Ant International's proof-of-concept for PETs-enabled AI prediction model training and released Practical Guidance on data classification and handling based on this POC. Ant International completed a full PET upgrade for Alipay+ covering 1.8 billion e-wallet users, making it the first digital payment solution to fully deploy PETs in a live setting.
- NTU Singapore (Digital Trust Centre)coreAnt International is partnering with NTU Singapore's Digital Trust Centre under a Master Research Collaboration Agreement to advance research on PETs deployment for cross-border payments. PDPC's Practical Guidance was informed by this research collaboration. The National Centre for Research in Digital Trust at NTU also participates in PETs discussions at SDF.
- Cyber Security Agency of Singapore (CSA)corePDPC and CSA jointly issued an Advisory against using NRIC Numbers for Authentication (published 26 June 2025). CSA also co-authored threat advisories including Joint Threat Advisory on GhostR and Joint Technical Advisory on LockBit 3.0. Both agencies collaborate on data breach response and cybersecurity incident management.
- The Law Society of SingaporecoreThe Law Society of Singapore's Cybersecurity and Data Protection Committee co-organised multiple workshops at SDF 2026 including 'Do It Right – How to Use DPIAs as Strategic Tools' and the bi-annual Cybersecurity and Data Protection Conference 2026 featuring Commissioner Denise Wong as keynote speaker.
- Singapore Corporate Counsel Association (SCCA)coreSCCA co-organised the workshop 'Third-Party Vendor Management – Building Robust Privacy and Cybersecurity Frameworks in the Age of AI and Supply Chain Risk' at Singapore Data Festival 2026, building on last year's ASEAN e-commerce case study.
- Global Privacy AssemblyflagshipPDPC is a member of the Global Privacy Assembly, the leading global forum for data protection and privacy authorities. Commissioner Denise Wong has been instrumental in Singapore's active participation and leadership within this international body.
- Asia Pacific Privacy Authorities (APPA) ForumflagshipPDPC previously chaired the Asia Pacific Privacy Authorities Forum. Singapore's leadership in APPA has facilitated close collaboration with data protection authorities across the region, including outcomes such as enhancement of ASEAN's partnerships with the European Commission and Ibero-American Data Protection Network on the ASEAN Model Contractual Clauses.
- ASEAN Data Protection and Privacy ForumcorePDPC contributes substantively to the ASEAN Data Protection and Privacy Forum. Notable outcomes include enhancement of ASEAN's partnerships with the European Commission and Ibero-American Data Protection Network on the use of ASEAN Model Contractual Clauses to facilitate trusted data flows between ASEAN and these regions.
Scale indicators8 records
Recent moves6 records
Expansion highlights5 records
Personal Data Protection Commission competitors and assessment
Company assessmentDirect peers
- European Data Protection Board (EDPB): Independent EU body composed of national supervisory authorities that ensures consistent application of GDPR. Comparable to PDPC in its convening role across multiple data protection authorities and issuance of binding guidance.
- Information Commissioner's Office (UK ICO): The UK's independent data protection authority enforcing the UK GDPR and Data Protection Act 2018. Most directly comparable national regulator to PDPC in terms of statutory authority, enforcement track record, and advisory function.
- Office of the Privacy Commissioner (New Zealand OPC): New Zealand's independent privacy regulator. Comparable jurisdiction with shared APEC CBPR participation, similar statutory enforcement powers, and active role in global privacy forums.
- Personal Information Protection Commission (Korea PIPC): Republic of Korea's data protection authority and co-signatory to the June 2026 MOU with PDPC. Highly comparable mandate covering personal information processing, AI governance, and cross-border transfers.
- Office of the Australian Information Commissioner (OAIC): Australia's national privacy regulator under the Privacy Act 1988. Comparable to PDPC in APPA Forum participation, APEC CBPR system management, and proportionate enforcement approach.
- Office of the Privacy Commissioner of Canada: Canada's federal privacy regulator overseeing PIPEDA and the Consumer Privacy Protection Act. Comparable national data protection authority with active enforcement, AI guidance, and cross-border cooperation mandate.
- Commission Nationale de l'Informatique et des Libertés (CNIL): France's independent data protection regulator, widely regarded as one of Europe's most active DPAs. Directly comparable to PDPC in enforcement intensity, sandbox initiatives, and proactive AI/PET guidance.
- Office of the Privacy Commissioner for Personal Data (Hong Kong PCPD): Hong Kong's statutory privacy regulator. Direct peer that signed an MOU with PDPC in June 2026 and shares comparable enforcement powers, AI guidance work, and APEC CBPR participation.
- Personal Information Protection Commission (Japan PPC): Japan's national data protection authority. Direct peer that signed an MOC with PDPC in July 2026, with comparable statutory mandate under the APPI and overlapping cross-border data transfer guidance.
Others
- Infocomm Media Development Authority (IMDA): PDPC's parent Singapore statutory board. Closely related as the parent agency under which PDPC operates and jointly runs the PET Sandbox, Data Protection Essentials framework, and federated learning guidance.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks5 records
Key highlights7 records
Customer concentration
Personal Data Protection Commission social profiles
Digital presencePersonal Data Protection Commission compliance and trust
Trust signalCompliance3 records
Personal Data Protection Commission financial estimates
Financial estimateRevenue estimate
Valuation estimate
Personal Data Protection Commission leadership team
Management profileNumber of profiles
Profiles1 record
Personal Data Protection Commission funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Personal Data Protection Commission M&A and investment
M&A and investmentM&A
Investments1 record
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Personal Data Protection Commission
What does Personal Data Protection Commission do?
PDPC is Singapore's national data protection regulator that administers and enforces the Personal Data Protection Act (PDPA) 2012. It operates the Do Not Call (DNC) Registry, mandates Data Protection Officer (DPO) registration and Data Breach Notification (within 3 calendar days), issues advisory guidelines (including on Generative AI and AI recommendation/decision systems), and publishes implementation guides such as the C.A.R.E. breach response framework, PET Sandbox with IMDA, guides on federated learning and synthetic data generation, and the PDPA Assessment Tool for Organisations (PATO). Its outputs are delivered free of charge through the pdpc.gov.sg portal and dedicated e-service portals, supplemented by fee-based DNC Registry access for organisations and approved third-party training programmes (e-learning, Fundamentals of PDPA, Practitioner Certificate WSQ with IAPP).
Is Personal Data Protection Commission a public or private company?
Personal Data Protection Commission is a private company. It is classified as state government owned and is currently operating.
When was Personal Data Protection Commission founded?
Personal Data Protection Commission was founded in 2012. It employs 101 to 250 people.
Where is Personal Data Protection Commission based?
Personal Data Protection Commission is headquartered in Singapore, Singapore, in the Asia region.
Who are Personal Data Protection Commission's main competitors?
Direct peers on record are European Data Protection Board (EDPB), Information Commissioner's Office (UK ICO), Office of the Privacy Commissioner (New Zealand OPC), Personal Information Protection Commission (Korea PIPC), Office of the Australian Information Commissioner (OAIC), Office of the Privacy Commissioner of Canada, Commission Nationale de l'Informatique et des Libertés (CNIL), Office of the Privacy Commissioner for Personal Data (Hong Kong PCPD) and Personal Information Protection Commission (Japan PPC). Infocomm Media Development Authority (IMDA) is listed as an others.
Does Personal Data Protection Commission have an API?
Yes. The DNC Registry API enables organizations to programmatically check telephone numbers against the Do Not Call Registry. Organizations can connect via API for instant results when checking between 10 to 100 numbers, allowing integration with existing marketing and contact management systems. Developer documentation is at www.dnc.gov.sg/DNC_API.pdf.
What industry is Personal Data Protection Commission in?
Personal Data Protection Commission's product category is Data Protection Regulatory Services. Its primary akta.pro industry code is HDADAFAH, Privacy Management (Consent, DSAR, RoPA), with a secondary code of HDAEADAH, Data Security & Access Governance for Data (Entitlements/Policy Enforcement). Its NAICS code is 92812 and its SIC code is 7370.