Website Privacy Notice Template for Singapore

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Website Privacy Notice?

The Website Privacy Notice is a mandatory document for websites operating in Singapore that collect personal data from users. It serves to comply with Singapore's Personal Data Protection Act (PDPA) requirements for transparency in data collection and processing. This document is essential for establishing trust with users and meeting legal obligations regarding personal data protection. The notice must clearly communicate how personal data is collected, used, disclosed, and protected, while informing users of their rights under Singapore law. Organizations must ensure their Website Privacy Notice is accurate, comprehensive, and regularly updated to reflect current data handling practices and regulatory requirements.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Singapore

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Website Privacy Notice

Your Website Privacy Notice is a fundamental legal requirement under Singapore's Personal Data Protection Act (PDPA) that governs how you collect, use, and protect personal data from website visitors. This document serves as a transparent communication tool that informs users about your data handling practices while ensuring compliance with Singapore's comprehensive data protection framework.

When do you need this document?

You need a Website Privacy Notice whenever your website collects any form of personal data from users in Singapore, regardless of your organization's size or industry. This includes collecting email addresses for newsletters, user registration information, contact form submissions, analytics data, or cookies that track user behavior. E-commerce platforms, corporate websites, blogs with comment sections, and service provider portals all require this notice. The PDPA mandates that organizations must provide clear notification before or at the time of data collection, making this document essential from your website's launch date.

Key legal considerations

Your privacy notice must address several critical PDPA requirements to ensure legal compliance. You must clearly identify the types of personal data collected, specify the purposes for collection and use, and outline your data retention policies. The notice should detail how users can access, correct, or withdraw consent for their personal data, as required under the PDPA's individual rights provisions. You must also disclose any third parties who may receive personal data and explain your security measures for protecting collected information. Additionally, the notice should address cross-border data transfers if you share data with overseas entities, ensuring compliance with transfer limitation obligations under the Personal Data Protection Regulations 2021.

Legal requirements in Singapore

Singapore's PDPA establishes specific obligations for website privacy notices that you must incorporate into your document. The notice must be written in clear, accessible language that ordinary users can understand, avoiding complex legal terminology. You're required to provide contact details for data protection inquiries and specify how users can lodge complaints with your organization or the Personal Data Protection Commission (PDPC). The notice must be prominently displayed and easily accessible on your website, typically through footer links or during user registration processes. Under the PDPC Advisory Guidelines, you should regularly review and update your privacy notice to reflect changes in data processing activities, business operations, or regulatory requirements. Failure to maintain an adequate privacy notice can result in PDPC enforcement action and significant financial penalties under the PDPA.

GOVERNING LAW

Applicable law

This Website Privacy Notice is drafted to comply with Singapore law. Key legislation includes:

Personal Data Protection Act 2012 (PDPA): Main framework for data protection in Singapore that governs the collection, use, disclosure, and care of personal data

Personal Data Protection Regulations 2021: Supplementary regulations providing specific requirements for data protection and transfer limitation obligations

PDPC Advisory Guidelines on Key PDPA Concepts: Official guidelines providing interpretation and practical guidance on key concepts in the PDPA

PDPC Advisory Guidelines on Selected Topics: Specific guidelines addressing particular aspects of data protection and special scenarios

PDPC Guide to Data Protection Practices for ICT Systems: Technical guidance for implementing data protection measures in information and communications technology systems

Spam Control Act: Legislation governing electronic marketing communications and spam control measures

General Data Protection Regulation (GDPR): EU regulation relevant if the website serves European Union residents

APEC Cross-Border Privacy Rules (CBPR) System: Regional framework for data protection and cross-border data transfers in the Asia-Pacific region

ASEAN Framework on Personal Data Protection: Regional guidelines for data protection within ASEAN member states

Industry-specific PDPC Guidelines: Sector-specific guidelines issued by the Personal Data Protection Commission for different industries

Cybersecurity Act: Legislation relevant for websites handling critical information infrastructure

Banking Act: Contains banking secrecy provisions relevant for financial services websites

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it