StructureClerk

Singapore: data protection and AI governance

Personal Data Protection Act (PDPA), in force since 2014-07-02. Supervisory authority: PDPC.

SGPriority jurisdiction, re-verified every cycleVerified on

Other languagesFrançaisEspañolالعربية中文

Data protection

Instrument
Personal Data Protection Act (PDPA)
In force since
2014-07-02
Authority
PDPC
Penalties
1M SGD ou 10% CA
Key obligations
  • Consentement
  • Notification violations
  • DPO recommandé

Key obligations and penalties are quoted from the record as the source states them; they are not translated.

What the engine decides here

These three attributes are what an agent decision depends on in this jurisdiction. They are modelled, sourced and dated.

Transfer regime
Restricted

Moving data out is restricted: it requires a recognised destination, or an explicit mechanism when the destination is not one.

Localisation mandate
Not modelled
Automated decision rights
Not modelled
Verified on
2026-08-14

Three decisions, computed just now

Same actions, this jurisdiction's context. These answers come out of the engine as the page renders, from the same function the API calls.

  • Read an internal contract

    Low-risk operation

    Allow
  • Send a customer record to US_FED

    The transfer requires a mechanism

    Approve
  • Decide on a job application

    Decision reserved for a human

    Deny

Advisory decisions. StructureClerk decides; your infrastructure enforces.

AI governance

Framework
Model AI Governance Framework
Status
guidance
Key points
  • Gouvernance interne
  • Transparence
  • Explicabilité

Do your agents operate in Singapore?

The authority API makes these attributes executable: an ALLOW, APPROVE, DENY or ESCALATE decision before the agent acts, with signed evidence any third party can verify.

Other jurisdictions: Asia-Pacific