PDPC Regulatory Corpus
Internal
Keypad or type your PIN
PDPC Corpus
KNQX knowledge base · 23 Aug 2026

The PDPC Regulatory Corpus

Enforcement decisions, regulatory guidance and topic guides published by Singapore's Personal Data Protection Commission, with corrected fine totals after a data-repair sweep of the local archive.

FACTS in normal text, each linked to its pdpc.gov.sg source. Figures are sums of the scraped corpus, not official PDPC aggregates.
KNQX · 23 Aug 2026 · Internal
Section 01

At a glance

Six numbers summarise the corpus: total documents, enforcement decisions, guidance, topic guides, and the corrected fine count and dollar total after the data-repair sweep.

Documents indexed
479
decisions, guidance, topic guides, digests
Enforcement decisions
387
all outcome types, 2013 to 2026
Regulatory guidance
42
advisory guidelines, practical guidance, PoCs
Topic guides
50
guidance-by-topic resources
Organisations fined
153
decisions carrying a financial penalty
Total fines
S$4,673,850
summed across the corpus

Enforcement decisions by year, 2016-2026

Counts use decision dates in the corpus; the earliest decisions run from 2016.

Outcomes

245 breach findings, 118 voluntary undertakings, 22 no-breach decisions and 1 discontinued case. A review-application decision (HSBC Bank, 12 May 2021) is counted separately, not as a breach.

Top 10 penalties

SingHealth's S$1,000,000 is the combined S$250,000 and S$750,000 penalties imposed on SingHealth and IHiS. K Box is now included at S$60,000 (S$50,000 + S$10,000).

Largest fines

#OrganisationPenaltyDate
1SingHealth and IHiSS$1,000,00015 Jan 2019
2Marina Bay SandsS$315,00028 Oct 2025
3Secur Solutions GroupS$120,00024 Nov 2020
4Geodis Logistics SingaporeS$120,00002 Aug 2024
5Keppel Telecommunications & TransportationS$120,00002 Aug 2024
6Ninja LogisticsS$90,00004 Nov 2019
7Tokyo Century LeasingS$82,00010 Nov 2023
8Ecommerce EnablersS$74,40016 Aug 2023
9CommeasureS$74,00011 Nov 2021
10PPLingoS$74,00021 Mar 2024
Section 02

Regulatory guidance (42)

Advisory guidelines, practical guidance and proof-of-concept confirmations published by PDPC.

GuidancePublished
Advisory Guidelines on the Personal Data Protection Act for NRIC and other National Identification Numbers31 Aug 2018
Advisory Guidelines on the PDPA for Children’s Personal Data in the Digital Environment28 Mar 2024
Applicability of Data Protection Provisions in relation to Ant International’s Proof of Concept to Enhance Customer Engagement with Privacy Preserving AI27 Mar 2026
Advisory Guidelines on the Do Not Call Provisions26 Dec 2013
Applicability of PDPA Data Protection Provisions in relation to Grab’s Proof of Concept To Automate Data Classification and Enable Data Use25 Jul 2024
Advisory Guidelines on the Personal Data Protection Act for Selected Topics24 Sep 2013
Advisory Guidelines on Key Concepts in the Personal Data Protection Act23 Sep 2013
Introduction to the Guidelines20 Oct 2023
Application of Exceptions to Consent for sharing personal data without consent with a public agency and its partners20 Jun 2023
Advisory Guidelines on Use of Personal Data in Generative AI20 Jul 2026
Advisory Guidelines on Enforcement of Data Protection Provisions20 Apr 2016
Practical Guidance on Telco Service Providers Who Merely Provides Service That Enables Specified Messages to be Sent18 Dec 2013
Advisory Guidelines for the Telecommunication Sector16 May 2014
Advisory Guidelines for the Real Estate Agency Sector16 May 2014
Data collaboration arrangement involving common data intermediary16 Mar 2021
Practical Guidance on Whether MCST May Disclose the Contact Details of Subsidiary Proprietors14 May 2018
Practical Guidance to Queries on NRIC Numbers by a Union14 Apr 2020
Practical Guidance to Queries on NRIC Numbers by an Association14 Apr 2020
Practical Guidance to Queries by Medical Research Institution14 Apr 2020
Application of the NRIC Advisory Guidelines to operational processes of a Payment Service Provider14 Apr 2020
Advisory Guidelines for the Social Service Sector11 Sep 2014
Advisory Guidelines for the Education Sector11 Sep 2014
Advisory Guidelines for the Healthcare Sector11 Sep 2014
Applicability of Consent Obligation to a data collaboration arrangement11 Oct 2019
Advisory Guidelines for Management Corporations11 Mar 2019
Practical Guidance on Whether Research Conducted for Government Agencies are for "Public Interest"10 Dec 2015
Advisory Guidelines on In-vehicle Recordings by Transport Services for Hire09 Apr 2018
Methods of communication when providing services and adequacy of IT security arrangements09 Apr 2014
Advisory Guidelines on Requiring Consent for Marketing Purposes08 May 2015
Advisory Guidelines on Application of PDPA to Election Activities08 Aug 2017
Applicability of PDPA Data Protection Provisions in relation to Singapore General Hospital’s (SGH) Proof of Concept (POC) on Secure AI Inferencing 07 Jul 2026
Applicability of PDPA Data Protection Provisions in relation to Ant International’s Proof of Concept (POC) on Privacy Preserving Risk Controls07 Jul 2026
Applicability of Data Protection Provisions in relation to Kajima’s Proof of Concept to Generate Synthetic Data07 Jul 2025
Applicability of Data Protection Provisions in relation to TikTok’s Proof of Concept to measure success of targeted advertising07 Jul 2025
Applicability of Data Protection Provisions in relation to SPH Media’s Proof of Concept to serve relevant advertisements to its customers07 Jul 2025
Applicability of PDPA's Consent Obligation in relation to transfer of personal data to Zuellig Pharma's Trusted Execution Environment07 Dec 2023
Applicability of PDPA Data Protection Provisions in relation to Meta’s Proof of Concept on Interoperable Private Attribution07 Dec 2023
Practical Guidance on Whether Randomly Generated Numbers are Personal Data06 Dec 2015
Applicability of the credit bureau exception to credit bureau operations and services04 Jul 2014
Advisory Guidelines on use of Personal Data in AI Recommendation and Decision Systems01 Mar 2024
LIA Code of Conduct for Tied Agents of Life Insurers on the Singapore Personal Data Protection Act01 Apr 2015
LIA Code of Practice for Life Insurers on the Singapore Personal Data Protection Act01 Apr 2015
Section 03

Guidance by topic (50)

The guidance-by-topic library: primers, digests, guides and tools PDPC publishes for organisations.

Topic guidePublished
E-Learning on Data Protection30 Jun 2026
Guide to Printing Processes for Organisations29 Mar 2020
Guide to Preventing Accidental Disclosure When Processing and Sending Personal Data29 Mar 2020
What You Need to Know About the PDPA29 Jan 2021
Fundamentals of the Personal Data Protection Act (2020)28 Oct 2025
Guide to Handling Access Requests28 Oct 2020
Guide to Managing Data Intermediaries27 Oct 2021
Data Protection Essentials27 Mar 2026
Harnessing Data for Impactful Business Change27 Mar 2026
Personal Data Protection Digest 202227 Mar 2023
Basic Anonymisation26 Aug 2024
A Life in Data Protection26 Aug 2022
Guide on Synthetic Data Generation24 Sep 2024
Joint Guide to ASEAN Model Contractual Clauses (MCCs) and EU Standard Contractual Clauses (SCCs)24 May 2023
Notice for Partial NRIC Number Collection24 Apr 2020
Personal Data Captured in In-vehicle Recording Devices24 Apr 2020
ASEAN Data Management Framework and Model Contractual Clauses on Cross Border Data Flows22 Jan 2021
Personal Data Protection Digest 202021 Sep 2020
Guide on Federated Learning20 Jul 2026
Guide to Data Protection Practices for ICT Systems20 Jul 2026
Guide on Personal Data Protection Considerations for Blockchain Design18 Jul 2022
E-Learning Corporate Account18 Jan 2018
Guide on the Responsible Use of Biometric Data in Security Applications17 May 2022
ASEAN MCCs & RIPD SCCs17 Jan 2025
Personal Data Protection Digest 202116 Aug 2022
Guide to Data Protection Impact Assessments15 Oct 2021
Accountability In Enforcement14 Sep 2021
Accountability14 Sep 2021
Accountability Within An Organisation14 Sep 2021
Strengthening Trust with Data Protection Essentials14 Mar 2024
Technical Guide to Advisory Guidelines on the PDPA for NRIC and Other National Identification Numbers14 Dec 2024
Guide to Developing a Data Protection Management Programme14 Aug 2023
Guide to Cross-Border Data Transfers 14 Apr 2026
Guide on Managing and Notifying Data Breaches Under the PDPA13 Sep 2021
Guide to Notification13 Sep 2021
Data Protection Obligations under the PDPA13 Sep 2021
EU GDPR11 Oct 2017
DPO Competency Framework and Training Roadmap11 Dec 2025
Practitioner Certificate in Personal Data Protection Course (Singapore) 2020 (WSQ)11 Dec 2025
Guide on the Practice of Passing Magnetic Stripes of Payment Cards Through a Reader10 Oct 2017
APEC Cross Border Privacy Rules and Privacy Recognition for Processors Systems07 Oct 2021
Accountability Within Industry07 Oct 2021
PDPA Assessment Tool for Organisations07 Nov 2022
Guide on Active Enforcement07 Nov 2022
Data Protection Trustmark07 Jul 2025
Resources04 Nov 2020
Singapore’s Approach to AI Governance03 Nov 2023
Sample Clause for Data Transfers to APEC and Global CBPR and PRP Certified Organisations02 Apr 2026
Guide on Data Protection Clauses for Agreements Relating to the Processing of Personal Data01 Feb 2021
Broad Comparison of the PDPA's Consent and Exceptions to Consent Provisions with EU GDPR's Six Legal Bases for Processing Personal Data01 Apr 2021
Section 04

Recent enforcement decisions (15)

The most recent additions to the corpus, including the S$315,000 Marina Bay Sands penalty from October 2025.

Section 05

Local archive

The corpus is scraped and stored locally, so the figures survive PDPC site reorganisation and stay reproducible.

Method: data scraped from pdpc.gov.sg on 23 Aug 2026; totals are sums of the corpus. Fine totals include multiple-entity penalties (e.g. SingHealth S$1M = S$250K + S$750K).

Archive: ~/work/pdpa-gbrain/dashboard-data.json, regenerated 23 Aug 2026.

Section 06

Sources

Everything above links to the underlying decision or guidance page. The entry points used for the scrape: