QNSI

Standards & programs

What is PDPA?

Also known as Personal Data Protection Act (Singapore).

Singapore's data protection law (2012, revised 2021). QNSI evaluates 9 PDPA obligations including consent, purpose limitation, protection, retention, and breach notification.

Decision context

Why PDPA matters

Singapore's Personal Data Protection Act governs collection, use, disclosure, protection, retention and breach-related duties for personal data within its scope. Cryptography supports protection and accountability but does not determine consent, purpose, access, correction, transfer or notification obligations by itself.

How to evaluate PDPA

Identify the organization, data, purposes, jurisdictions and roles in scope with qualified legal review. Map technical evidence to the relevant obligation and retain decisions, access, deletion and incident records. Do not describe a product as PDPA compliant without deployment-specific legal and operational assessment.

Standards & programs

Standards & programs evidence boundary

Standards define algorithms, testing methods, transition expectations, or regulatory obligations; they do not automatically certify a product or deployment. Confirm the exact publication, version, scope, implementation evidence, and accountable assessment route before describing a system as compliant or validated.

FAQ

Common questions

What is PDPA?

Singapore's data protection law (2012, revised 2021). QNSI evaluates 9 PDPA obligations including consent, purpose limitation, protection, retention, and breach notification.

Why does PDPA matter?

Singapore's Personal Data Protection Act governs collection, use, disclosure, protection, retention and breach-related duties for personal data within its scope. Cryptography supports protection and accountability but does not determine consent, purpose, access, correction, transfer or notification obligations by itself.

How should PDPA be evaluated?

Identify the organization, data, purposes, jurisdictions and roles in scope with qualified legal review. Map technical evidence to the relevant obligation and retain decisions, access, deletion and incident records. Do not describe a product as PDPA compliant without deployment-specific legal and operational assessment.

What is PDPA also known as?

PDPA is also known as Personal Data Protection Act (Singapore). Singapore's data protection law (2012, revised 2021). QNSI evaluates 9 PDPA obligations including consent, purpose limitation, protection, retention, and breach notification.

More

Keep exploring