Data Privacy Addendum Template for Singapore

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Data Privacy Addendum?

The Data Privacy Addendum is essential for organizations operating in or with Singapore that engage in personal data processing activities. It supplements existing service agreements to ensure compliance with Singapore's Personal Data Protection Act 2012 and related regulations. This document is particularly important given Singapore's strict data protection regime and significant penalties for non-compliance. The addendum details processing scope, security measures, breach notifications, and cross-border transfer mechanisms, providing a robust framework for data protection compliance.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Singapore

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Data Privacy Addendum

A Data Privacy Addendum is a crucial legal document that establishes the framework for personal data processing relationships under Singapore's Personal Data Protection Act 2012 (PDPA). When your organization engages third-party processors or acts as a processor for other companies, this addendum ensures compliance with Singapore's comprehensive data protection laws and protects both parties from regulatory penalties.

When do you need this document?

You need a Data Privacy Addendum whenever your business relationship involves processing personal data under Singapore law. This includes cloud service providers handling customer data, marketing agencies processing client databases, HR service providers managing employee information, and IT vendors accessing personal data during system maintenance. The document is essential when engaging sub-processors, establishing cross-border data transfers, or when your main service agreement lacks specific data protection clauses. Singapore's PDPA applies to organizations collecting, using, or disclosing personal data in Singapore, regardless of whether the organization is based locally or overseas.

Key legal considerations

The addendum must clearly define the roles and responsibilities of data controllers and processors under the PDPA's nine key obligations. Critical clauses include data processing purposes and scope, security safeguards meeting PDPA standards, data breach notification procedures within required timeframes, and provisions for data subject rights including access and correction requests. You must address data retention periods, secure deletion procedures, and audit rights for the controller. The document should specify liability allocation for PDPA violations and include indemnification clauses. Cross-border transfer provisions must comply with PDPA requirements and may need additional safeguards like standard contractual clauses or adequacy decisions.

Legal requirements in Singapore

Under Singapore's PDPA 2012 and the Personal Data Protection Regulations 2021, processors must implement appropriate security arrangements to protect personal data and can only process data according to controller instructions. Data breach notification to the Personal Data Protection Commission (PDPC) is mandatory within 72 hours for significant breaches, with additional notification to affected individuals required in certain circumstances. The addendum must address the PDPA's consent framework, purpose limitation principle, and notification obligations. For international transfers, you must ensure adequate protection levels in destination countries or implement appropriate safeguards. The PDPC's Advisory Guidelines provide detailed compliance requirements that should be reflected in your addendum terms. Organizations must also consider Singapore's position on GDPR compliance for European data subjects and potential applicability of sector-specific regulations.

GOVERNING LAW

Applicable law

This Data Privacy Addendum is drafted to comply with Singapore law. Key legislation includes:

Personal Data Protection Act 2012 (PDPA): Main privacy legislation in Singapore that includes Data Protection Provisions, nine main obligations for handling personal data, provisions on data breach notification, and rules on cross-border data transfers

Personal Data Protection Regulations 2021: Supplementary regulations that specify requirements for data breach notification and requirements for transfer of personal data overseas

PDPC Advisory Guidelines: Official guidelines providing specific guidance on PDPA compliance, including industry-specific guidelines and interpretation of key PDPA concepts

Singapore Privacy Shield Framework: Framework relevant for data transfers between Singapore and the United States

GDPR Considerations: European Union's General Data Protection Regulation requirements when dealing with EU data subjects

APEC Cross-Border Privacy Rules System: Regional framework for data protection and cross-border data transfers in the Asia-Pacific region

ASEAN Framework on Personal Data Protection: Regional framework establishing principles for data protection within ASEAN member states

Banking Act: Sector-specific regulations for financial institutions handling personal data

Healthcare Services Act: Sector-specific regulations for healthcare providers handling personal data

Cybersecurity Act: Legislation governing cybersecurity standards and requirements for critical information infrastructure

Data Protection Impact Assessments: Guidelines for assessing and mitigating privacy risks in data processing activities

Data Breach Management: Guidelines for handling and reporting data breaches under Singapore law

Data Intermediary Obligations: Specific requirements and responsibilities for organizations acting as data intermediaries

Data Retention Requirements: Guidelines specifying appropriate periods for retaining personal data

Security Arrangements: Guidelines on implementing appropriate security measures to protect personal data

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it