General Privacy Notice Template for Singapore
Generate a bespoke document
What is a General Privacy Notice?
The General Privacy Notice is a fundamental document required under Singapore's data protection framework. It should be implemented by organizations collecting personal data to ensure compliance with the Personal Data Protection Act 2012 (PDPA) and related regulations. This document provides transparency about data handling practices, helps organizations meet their legal obligations, and informs individuals about their rights regarding their personal data. It should be regularly reviewed and updated to reflect changes in data processing activities or regulatory requirements.
About the General Privacy Notice
A General Privacy Notice is an essential legal document that organizations in Singapore must provide to individuals when collecting their personal data. Under the Personal Data Protection Act 2012 (PDPA), this notice serves as your primary tool for ensuring transparency and regulatory compliance in your data processing activities.
When do you need this document?
You must implement a General Privacy Notice whenever your organization collects, uses, or discloses personal data in Singapore. This applies to businesses operating websites that collect customer information, employers gathering employee data, healthcare providers managing patient records, and retail establishments processing customer details. The notice is required before or at the time of data collection, whether through online forms, physical applications, or direct interactions with individuals. Financial institutions, educational organizations, and e-commerce platforms particularly rely on comprehensive privacy notices to meet their extensive data processing obligations under the PDPA.
Key legal considerations
Your privacy notice must clearly explain the purposes for collecting personal data, ensuring these purposes meet the "reasonable person" test under the PDPA's Purpose Limitation Obligation. The document should detail how you obtain and manage consent, particularly for sensitive personal data or direct marketing purposes. You must include information about data retention periods, security measures, and third-party data sharing arrangements. The notice should explain individuals' rights to access, correct, and withdraw consent for their personal data. Consider including contact details for your Data Protection Officer and procedures for handling data protection complaints. Regular updates are crucial when your data processing activities change or when regulatory requirements evolve.
Legal requirements in Singapore
Under Singapore's PDPA 2012 and the Personal Data Protection Regulations 2021, your privacy notice must fulfill the Notification Obligation by informing individuals about data collection purposes before processing begins. The notice must support your Consent Obligation by clearly explaining what individuals are consenting to and how they can withdraw consent. You must address the Access and Correction Obligation by explaining how individuals can request access to their data and seek corrections. The document should demonstrate compliance with data protection safeguards and breach notification requirements. Organizations processing personal data outside Singapore must include details about cross-border transfers and adequacy determinations. The Personal Data Protection Commission expects privacy notices to be written in plain language, easily accessible, and prominently displayed on websites or provided directly to individuals during data collection.
GOVERNING LAW
Applicable law
This General Privacy Notice is drafted to comply with Singapore law. Key legislation includes:
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it