General Privacy Notice Template for Singapore

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a General Privacy Notice?

The General Privacy Notice is a fundamental document required under Singapore's data protection framework. It should be implemented by organizations collecting personal data to ensure compliance with the Personal Data Protection Act 2012 (PDPA) and related regulations. This document provides transparency about data handling practices, helps organizations meet their legal obligations, and informs individuals about their rights regarding their personal data. It should be regularly reviewed and updated to reflect changes in data processing activities or regulatory requirements.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Singapore

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the General Privacy Notice

A General Privacy Notice is an essential legal document that organizations in Singapore must provide to individuals when collecting their personal data. Under the Personal Data Protection Act 2012 (PDPA), this notice serves as your primary tool for ensuring transparency and regulatory compliance in your data processing activities.

When do you need this document?

You must implement a General Privacy Notice whenever your organization collects, uses, or discloses personal data in Singapore. This applies to businesses operating websites that collect customer information, employers gathering employee data, healthcare providers managing patient records, and retail establishments processing customer details. The notice is required before or at the time of data collection, whether through online forms, physical applications, or direct interactions with individuals. Financial institutions, educational organizations, and e-commerce platforms particularly rely on comprehensive privacy notices to meet their extensive data processing obligations under the PDPA.

Key legal considerations

Your privacy notice must clearly explain the purposes for collecting personal data, ensuring these purposes meet the "reasonable person" test under the PDPA's Purpose Limitation Obligation. The document should detail how you obtain and manage consent, particularly for sensitive personal data or direct marketing purposes. You must include information about data retention periods, security measures, and third-party data sharing arrangements. The notice should explain individuals' rights to access, correct, and withdraw consent for their personal data. Consider including contact details for your Data Protection Officer and procedures for handling data protection complaints. Regular updates are crucial when your data processing activities change or when regulatory requirements evolve.

Legal requirements in Singapore

Under Singapore's PDPA 2012 and the Personal Data Protection Regulations 2021, your privacy notice must fulfill the Notification Obligation by informing individuals about data collection purposes before processing begins. The notice must support your Consent Obligation by clearly explaining what individuals are consenting to and how they can withdraw consent. You must address the Access and Correction Obligation by explaining how individuals can request access to their data and seek corrections. The document should demonstrate compliance with data protection safeguards and breach notification requirements. Organizations processing personal data outside Singapore must include details about cross-border transfers and adequacy determinations. The Personal Data Protection Commission expects privacy notices to be written in plain language, easily accessible, and prominently displayed on websites or provided directly to individuals during data collection.

GOVERNING LAW

Applicable law

This General Privacy Notice is drafted to comply with Singapore law. Key legislation includes:

Personal Data Protection Act 2012 (PDPA): Main privacy law in Singapore governing the collection, use, disclosure, and care of personal data

Personal Data Protection Regulations 2021: Supplementary regulations to the PDPA providing detailed requirements for compliance

Consent Obligation: PDPA requirement to obtain valid consent before collecting, using, or disclosing personal data

Purpose Limitation Obligation: PDPA requirement to collect, use or disclose personal data only for purposes that a reasonable person would consider appropriate

Notification Obligation: PDPA requirement to inform individuals of the purpose for collecting, using, or disclosing their personal data

Access and Correction Obligation: PDPA requirement to provide individuals access to their personal data and allow them to correct errors or omissions

Accuracy Obligation: PDPA requirement to make reasonable effort to ensure personal data collected is accurate and complete

Protection Obligation: PDPA requirement to implement reasonable security measures to protect personal data

Retention Limitation Obligation: PDPA requirement to cease retention of personal data when no longer necessary for legal or business purposes

Transfer Limitation Obligation: PDPA requirement to ensure adequate protection when transferring personal data outside of Singapore

Openness Obligation: PDPA requirement to implement and make information available about data protection policies and practices

APEC Cross-Border Privacy Rules: International framework for data protection that Singapore participates in, providing standards for cross-border data transfers

ASEAN Framework on Personal Data Protection: Regional framework establishing principles for harmonization of data protection laws across ASEAN member states

Spam Control Act: Singapore legislation governing unsolicited commercial electronic messages and related privacy aspects

Cybersecurity Act 2018: Singapore legislation establishing framework for protection of critical information infrastructure and cybersecurity

Banking Act: Legislation containing specific provisions for protection of financial data and banking secrecy

Healthcare Services Act: Legislation containing specific provisions for protection of medical data and patient confidentiality

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it