Journal/Compliance

A PDPA checklist for launching your SaaS in Singapore

Consent, retention and breach notification: the parts founders tend to forget until a client asks.

Singapore’s Personal Data Protection Act applies the moment your product collects a name, email or phone number. Most early-stage founders know this in theory. In practice, the questions usually arrive when the first enterprise customer sends a security questionnaire.

This is the checklist we run through before every launch. It isn’t legal advice, and for anything unusual you should speak to a lawyer, but it covers what most SaaS products need.

Before launch

  • Appoint a Data Protection Officer and publish their business contact details. In a small company this is often a founder.
  • Write a plain-English privacy notice saying what you collect, why, who you share it with and how long you keep it.
  • Collect only what you use. If the sign-up form asks for date of birth, you should be able to say why.
  • Get consent at the right moment, especially for marketing. Pre-ticked boxes don’t count.
  • List your data processors (hosting, email, analytics, payments) and check where they store data.

In the product

  • Let users see and correct their personal data without emailing you.
  • Make account deletion possible, and decide what “deleted” means for backups.
  • Encrypt personal data in transit and at rest; restrict who on your team can access production.
  • Keep an audit log of admin access to customer records.
  • Don’t put personal data in URLs, logs or analytics events.

Retention

PDPA requires you to stop keeping personal data once it no longer serves its purpose. Write down a retention period for each type of data and automate the clean-up where you can. “Forever” is not a retention period.

If something goes wrong

If a breach is likely to cause significant harm, or affects 500 or more people, you must notify the PDPC within three calendar days of assessing that it’s notifiable, and usually the affected individuals too. Write the response plan now, while it’s calm:

  1. Who decides whether an incident is a notifiable breach?
  2. Who contacts customers, and with what template?
  3. How do you preserve logs for investigation?
Using AI features?Check whether your AI provider stores prompts, for how long, and in which country. Business tiers of most providers let you opt out of training and limit retention. Put this in your privacy notice.

None of this is glamorous, but it turns a three-week security review into a three-day one, and that can be the difference in closing your first big customer.

ComplianceSampan Labs Journal
All articles
Written by Priya Menon

Delivery Lead. Keeps projects on time and clients informed. Writes the weekly demo notes everyone actually reads.

Have an idea?
Let's ship it.

Tell us what you're building. A real person replies within one business day, Singapore time.