A PDPA checklist for launching your SaaS in Singapore
Consent, retention and breach notification: the parts founders tend to forget until a client asks.
Singapore’s Personal Data Protection Act applies the moment your product collects a name, email or phone number. Most early-stage founders know this in theory. In practice, the questions usually arrive when the first enterprise customer sends a security questionnaire.
This is the checklist we run through before every launch. It isn’t legal advice, and for anything unusual you should speak to a lawyer, but it covers what most SaaS products need.
Before launch
- Appoint a Data Protection Officer and publish their business contact details. In a small company this is often a founder.
- Write a plain-English privacy notice saying what you collect, why, who you share it with and how long you keep it.
- Collect only what you use. If the sign-up form asks for date of birth, you should be able to say why.
- Get consent at the right moment, especially for marketing. Pre-ticked boxes don’t count.
- List your data processors (hosting, email, analytics, payments) and check where they store data.
In the product
- Let users see and correct their personal data without emailing you.
- Make account deletion possible, and decide what “deleted” means for backups.
- Encrypt personal data in transit and at rest; restrict who on your team can access production.
- Keep an audit log of admin access to customer records.
- Don’t put personal data in URLs, logs or analytics events.
Retention
PDPA requires you to stop keeping personal data once it no longer serves its purpose. Write down a retention period for each type of data and automate the clean-up where you can. “Forever” is not a retention period.
If something goes wrong
If a breach is likely to cause significant harm, or affects 500 or more people, you must notify the PDPC within three calendar days of assessing that it’s notifiable, and usually the affected individuals too. Write the response plan now, while it’s calm:
- Who decides whether an incident is a notifiable breach?
- Who contacts customers, and with what template?
- How do you preserve logs for investigation?
None of this is glamorous, but it turns a three-week security review into a three-day one, and that can be the difference in closing your first big customer.