Skip to main content
Talk to a human
AI Assistant

PDPA Privacy Policy Template for Singapore Businesses

A free, editable template with all 10 clauses explained: the obligation behind each one, what you need to change, and the mistake that most often makes a notice non-compliant.

No email address, no form. The download is a plain HTML file you can open, edit and paste into your website, and everything in it is explained below so you can adapt it properly rather than find-and-replacing a company name and hoping.

What a PDPA privacy policy has to cover

  1. Who you are. The organisation accountable for the data.
  2. What you collect. The actual categories of personal data.
  3. Why you collect it. Specific purposes, not general ones.
  4. How consent works. Including how it is withdrawn.
  5. Who else sees it. Third parties and any transfer out of Singapore.
  6. How long you keep it. Real periods with a reason.
  7. How to access or correct it. A channel and a timeframe.
  8. How to reach your DPO. Business contact details.
  9. What your website tracks. Cookies and analytics.
  10. How changes are communicated. With an effective date.

Privacy policy or privacy notice?

People search for both and usually mean the same thing: the public document telling individuals how you handle their personal data. The PDPA itself is written in terms of notifying individuals of the purposes for which their data is collected, used and disclosed, rather than mandating a document with a particular title. Some organisations do keep two separate things, an internal policy governing how staff handle data and an external notice for the public. If you have both, the external one is what belongs on your website, and it is what this template is.

The template, clause by clause

Ten clauses. For each one: the PDPA obligation it exists to satisfy, what you need to change, and the mistake we see most often when reviewing notices that were adapted from a template.

1

Data Controller Identity

Accountability Obligation

Names the organisation collecting the data, so an individual knows who is accountable and who to complain to.

What to change

Your registered entity name, not your trading name. If customers know you as one brand but you invoice as another, state both.

Common mistake

Using a brand name only. If the entity named in your notice is not the entity that holds the data, the notice does not identify your data controller.

2

Types of Personal Data Collected

Notification Obligation

Lists what you actually collect, broken into identifiers, contact details, financial, employment and technical data.

What to change

Delete every category you do not collect. Add anything specific to your sector. Be concrete: “customer data” is not a category.

Common mistake

Copying the full list unedited. A notice claiming you collect financial and employment data when you collect neither is inaccurate, and inaccuracy is the problem the notice exists to prevent.

3

Purposes of Collection, Use and Disclosure

Purpose Limitation Obligation

States why you collect each category, separated into primary, secondary and employment purposes.

What to change

Write the purposes you can actually justify. Each one limits what you may later do with the data.

Common mistake

Writing purposes so broad they mean nothing (“business purposes”, “improving our services”). Vague purposes do not expand what you may do, they just fail to authorise anything specific.

4

Consent

Consent Obligation

Covers how consent is obtained and, critically, how it can be withdrawn.

What to change

Describe your real mechanism: a tick box, a signed form, a verbal confirmation logged in your CRM. Withdrawal must be as easy as giving it.

Common mistake

Treating silence as consent, or bundling consent for marketing into consent for service delivery. Under the PDPA these are separate purposes and need separate consent.

5

Third-Party Disclosure and Cross-Border Transfers

Transfer Limitation Obligation

Discloses who else receives the data and what happens when it leaves Singapore.

What to change

List your actual data intermediaries by category: payment processors, cloud hosting, email platforms, outsourced payroll.

Common mistake

Forgetting that your SaaS vendors are disclosures. If your CRM is hosted overseas, you have a cross-border transfer, and you are responsible for ensuring comparable protection.

6

Data Retention Policy

Retention Limitation Obligation

States how long you keep data and what triggers deletion.

What to change

Give real periods tied to a reason, usually a legal or accounting requirement. “As long as necessary” on its own is not a retention policy.

Common mistake

Keeping everything forever by default. The obligation is to stop retaining data once the purpose is served and there is no legal need to keep it.

7

Access and Correction Rights

Access and Correction Obligation

Explains how individuals request their data or correct it, and the limited grounds for refusal.

What to change

Name the channel and the response timeframe you can actually meet.

Common mistake

Publishing a process nobody internally knows how to execute. The first access request usually exposes this.

8

Data Protection Officer Contact

Accountability Obligation

Provides the DPO’s business contact details so individuals can reach whoever is accountable.

What to change

A real, monitored channel. A role-based address (dpo@) survives staff changes better than a personal one.

Common mistake

Leaving the placeholder in. This is the single most common failure we see, and it is also the clause that requires you to have actually appointed someone.

9

Cookies and Tracking Technologies

Consent Obligation

Separates strictly necessary cookies from analytics and marketing cookies, and explains how to manage them.

What to change

Match it to what your site actually runs. If you have GA4 and a pixel, say so.

Common mistake

Describing a cookie banner you have not implemented. The notice and the website have to agree.

10

Updates to This Notice

Notification Obligation

Sets out how changes are communicated and from when they apply.

What to change

State how you will notify material changes and keep the effective date current.

Common mistake

An undated notice. Without a date, nobody can tell which version applied when the data was collected.

How to adapt it in an afternoon

  1. List what you actually collect before you open the template. Walk through every form, every system and every integration. Most organisations find at least one category they had forgotten, usually inside a tool someone signed up for independently.
  2. Delete before you add. Strike out every category and purpose that does not apply. A shorter accurate notice beats a longer aspirational one.
  3. Fill in the DPO clause last, and only if it is true. If you have not appointed anyone, that is the real gap, and the notice cannot paper over it.
  4. Check the notice against the website. If the notice describes a cookie banner or a preferences centre you have not built, either build it or remove the claim.
  5. Date it and publish it where people can find it. Footer on every page, plus a link at the point of collection on any form.

What this template does not do

  • It is not legal advice, and it is not a substitute for advice on your specific situation.
  • It does not cover sector-specific requirements. Financial services, healthcare and education carry obligations beyond the PDPA.
  • It does not make you compliant. It describes practices; it does not create them.
  • Left inaccurate, it works against you. A notice describing consent records or retention schedules you do not keep is a written record of the gap, which is worse than a shorter notice that is true.

Need help implementing this correctly?

The template is the easy part. The clauses it contains commit you to having consent records, retention schedules, an access-request process and a named DPO. If publishing it would mean describing things you do not yet have in place, that is the work worth doing next.

Common questions

Is this PDPA privacy policy template really free?

Yes. The template downloads without an email address or a form. Every clause is also explained in full on this page, so you can adapt it without downloading anything.

What is the difference between a privacy policy and a privacy notice?

In Singapore practice they are used interchangeably for the public-facing document that tells individuals how you handle their personal data. The PDPA itself talks about notifying individuals of purposes rather than about a document with a particular name. Internally, some organisations distinguish a privacy policy (how staff must handle data) from a privacy notice (what the public is told). If you keep both, the public one is what belongs on your website.

Does using this template make my business PDPA compliant?

No, and any template that claims otherwise is overselling. A privacy notice is one visible piece of compliance. It does not appoint a Data Protection Officer, does not create the consent records or retention schedules it describes, and does not secure your systems. It also becomes a liability if it describes practices you do not actually follow, because it is then a written record of the gap.

Do I need a Data Protection Officer to use this template?

The template has a clause for DPO contact details because the PDPA requires every organisation to appoint at least one person responsible for data protection and to make their business contact information available. There is no small-business exemption. You can appoint someone internally or outsource the role.

Where should the privacy policy live on my website?

Somewhere reachable from every page, which in practice means the footer, and linked from any form that collects personal data at the point of collection. A notice nobody can find before submitting a form has not notified anyone.

How often should I update it?

Whenever what you actually do changes: a new payment processor, a new CRM, a new marketing channel, a new category of data. Review it at least annually even if nothing obvious has changed, because integrations tend to accumulate quietly.

Related reading

Disclaimer: This template and guide are provided for general information only and do not constitute legal advice. The Personal Data Protection Act and the PDPC’s advisory guidelines are the authoritative sources for your obligations, and requirements change. For your specific situation, seek qualified advice.

Not sure whether your notice holds up?

We review privacy notices against what an organisation actually does, and tell you where the two do not match.

Schedule Consultation