S$1M
Max financial penalty per violation
3 Days
To notify PDPC after a data breach
100%
Of data-collecting businesses must comply
Singapore's Personal Data Protection Act applies to every organisation that collects, uses, or discloses personal data — with no minimum size threshold. A 5-person SME carries the same legal obligations as a 500-person enterprise.
Have you appointed a Data Protection Officer (DPO)?
Do you have a documented Data Protection Policy?
Can your team respond to a breach within 3 calendar days?
Have your staff received formal PDPA awareness training?
Most Singapore SMEs aren't as prepared as they think — and that's exactly the gap Cyber Essentials is built to close.