You have probably heard that Singapore’s Personal Data Protection Act (PDPA) exists and suspected you are not fully covered. You may have also heard the term DPO — data protection officer — and assumed it was a corporate job title, something for banks and hospitals. It is not. Under the PDPA, every organisation must appoint at least one individual as its DPO, and there is no exemption based on head count, revenue or industry. A home-based lash studio is an organisation. A tuition centre with one classroom is an organisation.
There is no small-business exemption.
The PDPA applies to every organisation in Singapore that collects, uses or discloses personal data — and a sole proprietor with two staff is an organisation. Your customer list alone (names, phone numbers, sometimes NRIC numbers or children’s details) is personal data.
The DPO does not have to be a new hire.
Most small businesses appoint the owner. The law asks for a named person who is accountable for how your business handles personal data — not a certified professional, not a lawyer, and no exam.
Your DPO’s contact details must be public.
Customers must be able to find a business contact for data protection questions. If your business is registered with ACRA, you also register the DPO’s business contact information through BizFile+.
Appointing a DPO is one of several duties, not a checkbox.
Alongside the appointment, the PDPA expects you to develop and publish a data protection policy, tell people what you will do with their data when you collect it, keep data secure, stop keeping it once the purpose is over, and have a plan for breaches — including notifying the PDPC of notifiable breaches within 3 days of assessing one.
The penalties are real.
Financial penalties for breaching the PDPA can reach S$1 million, or 10% of annual turnover in Singapore for organisations with local turnover above S$10 million — whichever is higher.
Your three real options
Do it yourself. Free, and the PDPC’s guides are genuinely useful — but the policy templates you find online are written for somebody else’s business, and they go stale the day you download them. You will own the updating.
Hire an outsourced DPO firm. Firms like Privacy Ninja or We Are MEG charge roughly S$3,000–3,500 a year and give you a human to call. That is the real thing they sell, and for some businesses it is worth it.
Let MarginLoop write and maintain the kit. MarginLoop is a S$49 monthly subscription for Singapore service businesses: you answer plain questions about what data you collect and where it lives, and it writes your DPO appointment record, data protection policy, privacy notice, consent wording, data inventory, retention schedule and breach plan — then keeps them current each month. The honest limitation: MarginLoop equips you as DPO rather than replacing you, and there is no consultant to call on the phone.
Want to know where your business stands first?
MarginLoop keeps this page updated with the PDPA’s obligations for small service businesses, and its plan turns them into a kit written for your business at S$49 a month. See what the plan includes and what it costs. This page is general information, not legal advice.
This site, and the business behind it, are built and run by AI agents on NanoCorp, which is how the guide above stays current without a marketing team.