Doing Business In..._2026

SINGAPORE Law and Practice Contributed by: Azmul Haque, Ashley Chew, Hu Yutong and Aaron Leong, Collyer Law LLC

Core PDPA Obligations The main obligations include: • accountability; • purpose limitation; • notification; • consent or reliance on an exception; • access;

deliberate commercial infringements may also attract criminal liability. 7.5 Others Software Software is usually protected first through copyright in source code and object code. A software-relat - ed invention may also be patentable if it meets the patentability requirements and is not excluded. Databases Databases may be protected through copyright where the database structure or compilation qualifies for protection. Database content may also be protected through confidentiality, contract, access controls, technological measures and personal data or cyber - security obligations, where relevant. Trade Secrets and Confidential Information Singapore protects trade secrets principally through the law of confidence, contract and equitable rem - edies, rather than through a registration system. Pro - tection is strengthened by confidentiality agreements, employment provisions, access controls, need-to- know restrictions, information classification, audit logs and exit procedures. Other Rights Singapore also protects geographical indications, plant varieties and layout designs of integrated cir - cuits under dedicated statutory regimes. Rights-hold - ers may generally enforce these rights through civil proceedings and seek remedies such as injunctions, damages and, where available, an account of profits. Businesses may also rely on passing off to protect goodwill associated with unregistered brands.

• correction; • accuracy; • protection; • retention limitation; • transfer limitation; and • data breach notification.

Organisations must designate at least one data pro - tection officer and make the officer’s business contact information available to the public. Related Regimes The PDPA is not the only relevant regime. Sector-spe - cific or activity-specific obligations may arise under laws and regulatory rules relating to cybersecurity, financial services, healthcare, employment, telecom - munications, spam control, electronic transactions and state-sector data governance. Where another written law is inconsistent with the PDPA, the other written law prevails to the extent of the inconsistency. The PDPA can apply to organisations carrying out activities involving personal data in Singapore, even if the organisation is incorporated overseas. The analy - sis depends on the activities conducted in Singapore, local operations, service providers and data flows. Cross-Border Transfers 8.2 Geographical Scope Jurisdictional Application An organisation transferring personal data outside Sin - gapore must comply with Section 26 of the PDPA and the prescribed requirements in the Personal Data Pro - tection Regulations 2021. In broad terms, the organi - sation must take appropriate steps to ensure that the overseas recipient is bound by legally enforceable obligations providing a standard of protection com - parable to the PDPA, unless another prescribed basis applies.

8. Data Protection 8.1 Applicable Regulations General Framework

The Personal Data Protection Act 2012 (PDPA) is Singapore’s primary general data protection statute for the private sector. It governs the collection, use and disclosure of personal data by organisations, and establishes the Do Not Call Registry framework.

949 CHAMBERS.COM

Powered by