PDPA Singapore
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Accountability and Governance
Per PDPA Singapore Accountability Obligation: maintain accountability + governance + DPO + training. Requirements include (a) maintain organisational accountability for personal data protection per the PDPA + Advisory Guidelines from PDPC + (b) appoint Data Protection Officer (DPO) responsible for compliance + (c) maintain Personal Data Inventory and Records of Processing Activities + (d) deliver Staff Training and Awareness programmes including role-based content + onboarding + refresher + (e) maintain documented policies + procedures + governance structures + (f) cooperate with PDPC inquiries + reviews + (g) maintain accountability framework demonstrating compliance.
- PDPA Singapore evidence for PDPASG-1
- DPO + DPIA + transfer assessment + DNC check partial
Breach Response and Enforcement
Per PDPA Singapore Data Breach Notification Obligation + Enforcement: breach response + enforcement awareness. Requirements include (a) implement Data Breach Notification Obligation - notify PDPC within 3 days of assessing breach likely to result in significant harm to affected individuals OR involves 500+ individuals + notify affected individuals where significant harm likely + (b) operate Security Incident Response Procedures including detection + triage + containment + recovery + lessons learned + (c) maintain Regulatory Reporting and Cooperation with PDPC including investigations + reviews + (d) understand Enforcement and Penalties including financial penalties + directions + undertakings + (e) maintain breach log + incident response capability + tabletop exercises + (f) integrate with broader incident management.
- PDPA Singapore evidence for PDPASG-8
- DPO + DPIA + transfer assessment + DNC check partial
High-Risk Processing
Per PDPA Singapore Advisory Guidelines + best practice: heightened safeguards for high-risk processing. Requirements include (a) implement Children's Personal Data protections requiring parental consent for processing of children's personal data per Singapore age of consent + (b) conduct Data Protection Impact Assessment (DPIA) for high-risk processing including large-scale + sensitive + systematic monitoring + new technologies + AI + (c) implement Privacy by Design and Default across systems + processes + products + (d) implement Automated Decision-Making protections including human review + explanation + objection rights where applicable + (e) maintain documented DPIA + safeguards + risk assessments + (f) integrate privacy considerations into design + procurement + change management.
- PDPA Singapore evidence for PDPASG-4
- DPO + DPIA + transfer assessment + DNC check partial
Individual Rights
Per PDPA Singapore Access + Correction + Data Portability Obligations: implement individual rights. Requirements include (a) implement Access Obligation enabling individuals to request access to their personal data and disclosure of how it has been used or disclosed + (b) implement Correction Obligation enabling individuals to request correction of errors or omissions + (c) implement Data Portability Readiness for transmitting personal data to another organisation in commonly used machine-readable format where applicable + (d) implement supporting rights including right to restrict + object to processing + automated decision-making protections + (e) maintain mechanism for receiving + verifying + responding within statutory timelines + (f) maintain records of requests + responses + and decisions.
- PDPA Singapore evidence for PDPASG-3
- DPO + DPIA + transfer assessment + DNC check partial
Lawful Processing
Per PDPA Singapore Notification + Consent + Purpose + Lawful Basis Obligations: establish lawful processing. Requirements include (a) provide Notification to individuals of purposes for which their personal data will be collected + used + disclosed + (b) obtain Consent that is fresh + specific + informed + with mechanism for withdrawal + or rely on exceptions (deemed consent + legitimate interests + other exceptions under the PDPA) + (c) apply Purpose Limitation - personal data must be collected + used + disclosed only for purposes notified to individual or permitted under the PDPA + (d) maintain Legitimate Interests assessment where relied upon as lawful basis + (e) maintain records of notifications + consent + and purpose-specific use + (f) maintain change management for purpose + consent updates.
- PDPA Singapore evidence for PDPASG-2
- DPO + DPIA + transfer assessment + DNC check partial
Lifecycle and Marketing
Per PDPA Singapore Retention Limitation + DNC Provisions + Compliance: lifecycle + marketing. Requirements include (a) implement Retention Limitation Obligation - personal data must not be retained longer than necessary for the purposes for which it was collected or for legal/business purposes + secure disposal where retention no longer justified + (b) implement Do Not Call (DNC) Provisions per PDPA - check specified message recipient against DNC Registry before sending marketing message + comply with DNC consent + (c) operate Compliance Monitoring and Auditing including periodic review + internal audit + reporting to leadership + (d) operate Complaints Handling and Resolution mechanism for individuals + (e) maintain training + awareness on marketing + retention + (f) integrate with broader lifecycle management.
- PDPA Singapore evidence for PDPASG-7
- DPO + DPIA + transfer assessment + DNC check partial
Protection and Security
Per PDPA Singapore Protection + Accuracy Obligations: protect personal data + maintain accuracy. Requirements include (a) implement Protection Obligation making reasonable security arrangements to protect personal data against unauthorised access + collection + use + disclosure + copying + modification + disposal + similar risks + (b) implement Accuracy Obligation ensuring personal data is accurate + complete where it will be used to make decisions affecting individuals + (c) implement Data Minimization collecting only what is necessary + (d) implement encryption + pseudonymisation + access control + as appropriate + (e) conduct regular Security Testing and Assessment + (f) integrate with broader information security programme + (g) maintain monitoring + improvement.
- PDPA Singapore evidence for PDPASG-5
- DPO + DPIA + transfer assessment + DNC check partial
Transfer and Processor Management
Per PDPA Singapore Transfer Limitation Obligation + Data Intermediary provisions: cross-border + processor management. Requirements include (a) implement Transfer Limitation Obligation - personal data must not be transferred outside Singapore unless requirements ensuring comparable protection are met (per Transfer Regulations) + (b) implement Cross-Border Transfer Safeguards including data transfer agreements + binding corporate rules + certifications + (c) implement Data Intermediary Oversight - principal organisation remains accountable when using a data intermediary for processing + (d) maintain Data Processing Agreements ensuring processors process only on instructions + maintain security + assist with obligations + (e) maintain inventory of cross-border data flows + recipients + safeguards + (f) implement supplier + processor + sub-processor due diligence.
- PDPA Singapore evidence for PDPASG-6
- DPO + DPIA + transfer assessment + DNC check partial
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the PDPA Singapore framework page.