
Short answer: Any SaaS vendor that handles personal data in Singapore falls under the Personal Data Protection Act (PDPA), either as an organisation in its own right or as a data intermediary processing customer data. Everything else depends on who you sell to: MAS rules for financial buyers, CSA marks for many local buyers, and new health information rules for healthcare providers.
Related guides:
Key takeaways
- The PDPA is the baseline. It covers private organisations that collect, use or disclose personal data in Singapore, including overseas vendors that process that data for local customers.
- Breach notification has a hard clock. Notifiable breaches must reach the Personal Data Protection Commission (PDPC) no later than 3 calendar days after you assess that the breach is notifiable.
- Most other frameworks are buyer driven. The Cybersecurity Act targets critical and specially designated systems, while CSA marks, MAS expectations and health rules reach vendors through contracts and procurement.
- Your existing program carries over. A mature ISO 27001 or SOC 2 control set already covers most of the technical ground. The gaps are mostly local: breach clocks, a named data protection officer, and sector-specific evidence.
Which Singapore compliance frameworks apply to a foreign SaaS vendor?
The PDPA applies to almost every vendor with Singaporean users or customers; the rest is triggered by your customer's sector. A quick way to scope your obligations is to start from the buyer, not the regulation.
| If you sell to... | Expect to be asked about | Legal duty or buyer expectation? |
|---|---|---|
| Any Singapore business or consumer | PDPA obligations, breach handling, data transfers | Legal duty |
| Operators of critical information infrastructure | Cybersecurity Act duties passed down by contract | Legal duty for the operator, contractual for you |
| Mid-market and enterprise buyers | CSA Cyber Trust mark, ISO 27001, SOC 2 | Buyer expectation |
| SMEs and their supply chains | CSA Cyber Essentials mark | Buyer expectation |
| Banks, insurers and other MAS-regulated firms | MAS Technology Risk Management (TRM) Guidelines, outsourcing due diligence | Regulatory expectation on the customer, passed to you |
| Hospitals, clinics and other healthcare providers | Health information security and data sharing rules | Legal duty on providers, passed to you |
| Government agencies | Government ICT security policies and cloud security standards | Procurement requirement |
If your pipeline is mostly in one row, focus there first. Trying to satisfy every framework at once is how small teams stall.
What does the PDPA require from SaaS companies?
The PDPA requires organisations to collect personal data only for purposes people have been told about, protect it with reasonable security arrangements, and report serious breaches quickly. Which duties fall on you depends on your role:
- Organisation. For personal data you collect for your own purposes, such as your own customers' account contacts, employee records or marketing lists, all five areas below apply to you.
- Data intermediary. For personal data you process on a customer's behalf under a written contract, you are usually a data intermediary. The PDPA then mainly applies the protection and retention obligations to you, plus a duty to tell your customer about a breach without undue delay. Consent, purpose and transfer duties stay with your customer, though contracts often pass some of that work back to you.
Most SaaS vendors are both: an organisation for their own data and a data intermediary for the data customers load into the product. Have counsel confirm how your contracts allocate these roles. For an organisation, the work clusters into five areas.
- Consent and purpose. Collect personal data for purposes a reasonable person would consider appropriate, tell people what those purposes are, and get consent unless an exception applies.
- Protection. Make reasonable security arrangements to prevent unauthorised access, collection, use, disclosure or similar risks. In practice, PDPC enforcement decisions often focus on basics such as access control, patching and misconfigured storage.
- Retention. Stop keeping personal data once it no longer serves the purpose it was collected for.
- Transfers. When personal data leaves Singapore, make sure the recipient protects it to a standard comparable to the PDPA, usually through contractual clauses.
- Accountability. Designate at least one data protection officer (DPO), publish how people can contact them, and document your data protection policies.
Breach notification deserves its own runbook. Since the amendments took effect on 1 February 2021, a breach is notifiable when it causes, or is likely to cause, significant harm to affected individuals, or when it involves the personal data of 500 or more people. Once you assess a breach as notifiable, you must tell the PDPC as soon as practicable and no later than 3 calendar days afterwards. If you are a data intermediary processing data for a customer, your job is to tell that customer without undue delay so they can assess it.
The stakes rose in 2022. Under section 48J of the PDPA, for contraventions on or after 1 October 2022, the maximum financial penalty for an organisation whose annual turnover in Singapore exceeds S$10 million is 10% of that turnover. For every other organisation, the cap is S$1 million.
If you already run a GDPR program, much of this will feel familiar. The main adjustments are the 3-day clock, the 500-person threshold and the DPO contact details. Our guide to GDPR data breach notification requirements is a useful comparison point for your incident runbook.
Does the Cybersecurity Act apply to you?
Probably not directly, unless you operate critical information infrastructure (CII) or a designated system, but your customers may pass its duties down to you. The Cybersecurity Act 2018 regulates owners of CII in sectors such as energy, banking, healthcare, transport and government.
Parliament passed the Cybersecurity (Amendment) Bill on 7 May 2024, and its provisions are commencing in stages. As of October 2026, here is where each change stands:
- In force since 31 October 2025: updated rules for critical information infrastructure, including CII owned by third parties and CII located overseas, plus the new framework for systems of temporary cybersecurity concern, which CSA can designate for a limited period, such as during major events. See the CSA announcement.
- Not yet in force: the new categories for foundational digital infrastructure providers (such as certain cloud and data centre services) and entities of special cybersecurity interest. These await a future commencement notification, so check CSA announcements before relying on them.
For most SaaS vendors, the practical effect is contractual. If a customer is a CII operator, expect detailed security schedules, audit rights and incident reporting timelines in your agreement.
CSA Cyber Essentials vs Cyber Trust: which mark should you get?
Pick Cyber Essentials if you are a small vendor proving baseline hygiene, and Cyber Trust if you sell to larger or more digitalised organisations. The Cyber Security Agency of Singapore (CSA) launched both marks on 29 March 2022.
| Cyber Essentials | Cyber Trust | |
|---|---|---|
| Intended for | SMEs with limited IT or security resources | Larger or more digitalised organisations |
| What it proves | Baseline measures against common attacks | A risk-based program matched to your profile |
| Structure | A single baseline | Tiered levels of preparedness |
| Best fit for SaaS | Early-stage vendors selling to local SMEs | Vendors selling to enterprises or regulated buyers |
Neither mark replaces ISO 27001 or SOC 2 for global buyers. Treat them as a local trust signal that sits alongside your existing attestation. If you already hold ISO 27001, check with an accredited assessor how much of your existing evidence they can reuse before you scope a separate engagement.
What do MAS TRM expectations mean for fintech vendors?
If you sell to banks, insurers or payment firms in Singapore, your customer will assess you against the Monetary Authority of Singapore (MAS) technology risk expectations. Two instruments matter most.
- TRM Guidelines. MAS revised the Technology Risk Management Guidelines on 18 January 2021. They set expectations for board oversight, third-party risk, secure development, access management, resilience testing and cyber exercises.
- Notices on Cyber Hygiene. These make a subset of TRM requirements legally binding on regulated institutions: secure administrative accounts, timely patching, security standards for systems, network perimeter defence, malware protection, and multi-factor authentication for critical systems and systems used to access customer information.
As a vendor you are not regulated by MAS, but your customer is accountable for outsourced services. Expect a due diligence questionnaire covering these themes, contract clauses on incident notification and audit access, and requests for penetration test summaries. A well-organised third-party risk management program on your own side makes these reviews faster, because you can show how you assess your own subprocessors.
What should HealthTech vendors watch in Singapore?
Healthcare is the sector where Singapore's rules are changing fastest. According to the government's explainer, Parliament passed the Health Information Bill on 12 January 2026, and the Ministry of Health (MOH) intends it to take effect from early 2027. The details below reflect that explainer as of October 2026.
The law centres on the National Electronic Health Record (NEHR). Covered healthcare providers will have to contribute key patient data to it, meet cybersecurity and data security requirements, and notify MOH of confirmed cybersecurity incidents and data breaches in a timely manner. Access to the NEHR for employment or insurance purposes will be prohibited.
What this means for HealthTech vendors:
- Your customers will tighten vendor requirements before 2027. Clinics and hospitals preparing for the new law will look harder at the systems that store or move patient data.
- Watch MOH guidance closely. Detailed requirements will come through guidance materials and subsidiary rules, so treat any checklist published today as provisional.
- HIPAA work transfers well. If you already run a HIPAA risk assessment program for US customers, your access controls, audit logging and encryption evidence will cover much of what Singapore providers ask for.
How much of SOC 2 and ISO 27001 carries over?
Most of it. Singapore's frameworks share the same security fundamentals as the attestations you already hold, so the work is mapping and filling local gaps rather than starting over.
| Requirement area | Already covered by ISO 27001 or SOC 2? | Local gap to close |
|---|---|---|
| Access control, MFA, patching, logging | Largely yes | Map evidence to MAS Cyber Hygiene themes for financial customers |
| Incident response | Yes, as a process | Add the PDPA 3-day PDPC clock and data intermediary duties |
| Vendor management | Yes | Document cross-border transfer safeguards for personal data |
| Governance and roles | Partly | Name a DPO and publish contact details |
| Third-party certification | Yes for global buyers | Consider a CSA mark if local buyers ask for it |
Start with a short gap assessment against the PDPA, then add the sector layer your pipeline actually needs.
How SecureSlate helps
SecureSlate gives SMB, SaaS and HealthTech teams one control library that maps across frameworks such as SOC 2, ISO 27001, HIPAA and GDPR, so Singapore requirements build on work you have already done. SecureSlate has no built-in PDPA or MAS TRM framework, so you would add those duties, such as DPO designation and the 3-day breach notification runbook, through custom frameworks and controls. Read-only cloud integrations and a device agent keep evidence current. Vendor risk management tracks the vendors and subprocessors that handle your customers' data, and a trust center publishes your certifications, policies and subprocessors to buyers.
Start your free SecureSlate trial
FAQ
Does the PDPA apply to companies outside Singapore?
Yes, in many cases. The PDPA covers organisations that collect, use or disclose personal data in Singapore, whether or not they have a local office. An overseas SaaS vendor serving Singapore customers should assume it applies: as a data intermediary for data it processes on customers' behalf, and as an organisation for personal data it collects for its own purposes.
Is ISO 27001 recognised in Singapore?
Yes. ISO 27001 is widely recognised by Singapore enterprises and regulated buyers. It does not replace PDPA obligations, but it covers most of the security controls those buyers review.
What is the difference between the PDPA and GDPR breach rules?
The GDPR gives controllers 72 hours to notify a supervisory authority. The PDPA requires notification to the PDPC no later than 3 calendar days after you assess a breach as notifiable, and it sets a 500-person threshold alongside the significant harm test.
Do SaaS vendors need a CSA Cyber Trust mark?
It is not a legal requirement. It is a useful local trust signal when selling to larger Singapore organisations, especially if you lack ISO 27001 or SOC 2.
Disclaimer (legal note)
This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds