Standards & programs
What is PDPA?
Also known as Personal Data Protection Act (Singapore).
Singapore's data protection law (2012, revised 2021). QNSI evaluates 9 PDPA obligations including consent, purpose limitation, protection, retention, and breach notification.
Decision context
Why PDPA matters
Singapore's Personal Data Protection Act governs collection, use, disclosure, protection, retention and breach-related duties for personal data within its scope. Cryptography supports protection and accountability but does not determine consent, purpose, access, correction, transfer or notification obligations by itself.
How to evaluate PDPA
Identify the organization, data, purposes, jurisdictions and roles in scope with qualified legal review. Map technical evidence to the relevant obligation and retain decisions, access, deletion and incident records. Do not describe a product as PDPA compliant without deployment-specific legal and operational assessment.
Standards & programs
Standards & programs evidence boundary
Standards define algorithms, testing methods, transition expectations, or regulatory obligations; they do not automatically certify a product or deployment. Confirm the exact publication, version, scope, implementation evidence, and accountable assessment route before describing a system as compliant or validated.
FAQ
Common questions
What is PDPA?
Singapore's data protection law (2012, revised 2021). QNSI evaluates 9 PDPA obligations including consent, purpose limitation, protection, retention, and breach notification.
Why does PDPA matter?
Singapore's Personal Data Protection Act governs collection, use, disclosure, protection, retention and breach-related duties for personal data within its scope. Cryptography supports protection and accountability but does not determine consent, purpose, access, correction, transfer or notification obligations by itself.
How should PDPA be evaluated?
Identify the organization, data, purposes, jurisdictions and roles in scope with qualified legal review. Map technical evidence to the relevant obligation and retain decisions, access, deletion and incident records. Do not describe a product as PDPA compliant without deployment-specific legal and operational assessment.
What is PDPA also known as?
PDPA is also known as Personal Data Protection Act (Singapore). Singapore's data protection law (2012, revised 2021). QNSI evaluates 9 PDPA obligations including consent, purpose limitation, protection, retention, and breach notification.
More