Cookies Notice Template for Singapore

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Cookies Notice?

A Cookies Notice is essential for websites operating in Singapore to comply with the Personal Data Protection Act (PDPA) and related privacy regulations. This document informs users about how cookies and similar technologies are used to collect and process their data while browsing a website. The notice must be clear, accessible, and provide users with information about their rights and choices regarding cookie usage. It should detail the types of cookies used, their purposes, duration, and any third-party involvement. A properly drafted Cookies Notice helps organizations demonstrate compliance with Singapore's data protection requirements while building trust with users.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Singapore

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Cookies Notice

A Cookies Notice is a legal document that informs website visitors about how your website uses cookies and similar tracking technologies to collect and process their personal data. Under Singapore's Personal Data Protection Act (PDPA) 2012 and related guidelines, you must provide clear information about cookie usage and obtain appropriate consent from users when collecting their personal data through cookies.

When do you need this document?

You need a Cookies Notice if you operate a website that uses any type of cookies or tracking technologies that collect personal data from visitors. This includes e-commerce platforms, corporate websites, blogs, or any online service that tracks user behavior, stores preferences, or collects analytics data. The notice is particularly crucial if you use marketing cookies, social media plugins, or third-party analytics tools like Google Analytics. Even if your website only uses essential cookies for basic functionality, having a comprehensive notice demonstrates transparency and builds user trust. Singapore-based businesses and international companies serving Singapore users must comply with PDPA requirements regardless of where their servers are located.

Key legal considerations

Your Cookies Notice must clearly categorize different types of cookies used on your website, including necessary cookies for basic functionality, analytical cookies for performance monitoring, and marketing cookies for advertising purposes. The document should specify the duration cookies remain active, whether they are first-party or third-party cookies, and what specific data is collected. You must provide detailed information about the legal basis for processing personal data through cookies, whether it's legitimate interest, consent, or contractual necessity. The notice should include clear instructions for users to manage their cookie preferences, withdraw consent, or opt-out of non-essential cookies. Additionally, you must disclose any cross-border data transfers and ensure appropriate safeguards are in place when sharing cookie data with overseas service providers.

Legal requirements in Singapore

Under the PDPA 2012 and PDPC Guidelines Chapter 6, you must obtain informed consent before collecting personal data through non-essential cookies. The consent mechanism must be clear, specific, and allow users to make an informed choice about cookie acceptance. Your Cookies Notice must be easily accessible from every page of your website, typically through a prominent link in the footer or header. The Personal Data Protection Commission requires that cookie banners and notices use plain English and avoid legal jargon that ordinary users cannot understand. You must implement technical measures to ensure cookies are only activated after user consent is obtained, except for strictly necessary cookies required for website functionality. The notice must also comply with the PDPA's notification obligations, informing users about their rights to access, correct, or withdraw consent for their personal data collected through cookies.

GOVERNING LAW

Applicable law

This Cookies Notice is drafted to comply with Singapore law. Key legislation includes:

PDPA 2012: Singapore's Personal Data Protection Act - Primary legislation governing collection, use, and disclosure of personal data, requiring consent and transparency in data collection practices

PDPA Guidelines - Chapter 6: Guidelines on Online Activities providing specific guidance on cookies and online tracking, including requirements for informed consent

PDPC Advisory Guidelines: Guidelines by Personal Data Protection Commission covering cookie consent mechanisms and requirements for privacy notices

Privacy Commissioner Guidelines: Singapore Privacy Commissioner's guidelines covering best practices for online privacy and requirements for cross-border data transfers

Cookie Types Requirement: Legal requirement to specify and explain different types of cookies used on the website

Purpose Specification: Legal requirement to clearly state the purpose of data collection through cookies

Consent Mechanism: Requirement to implement and explain the mechanism for obtaining user consent for cookie usage

User Rights Documentation: Requirement to outline user rights regarding cookie preferences and data collection

Data Retention Policy: Requirement to specify the duration for which collected data will be retained

Cross-border Transfer Notice: Requirement to disclose any international transfer of collected data, if applicable

GDPR Consideration: Optional consideration of EU's General Data Protection Regulation if serving European users

APEC Privacy Framework: Regional privacy standard that may influence cookie notice requirements in the Asia-Pacific context

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it