11.3 Personal Data Protection Act (PDPA) and the Do Not Call Registry

Key Takeaways

  • The PDPA 2012 protects personal data, meaning data, whether true or not, about an individual who can be identified from that data or with other accessible information.

  • The main data protection obligations are accountability, consent, notification, purpose limitation, access and correction, accuracy, protection, retention limitation, transfer limitation and data breach notification.

  • A data breach is notifiable if it is likely to cause significant harm or affects 500 or more individuals, and the PDPC must be told within 3 calendar days of assessing it as notifiable.

  • Organisations must not collect NRIC numbers unless required by law or necessary to verify identity to a high degree of fidelity.

  • Before telemarketing, numbers must be checked against the Do Not Call Registry, and the results are valid for 21 days.

Last updated: October 2026

11.3 Personal Data Protection Act (PDPA) and the Do Not Call Registry

Quick Summary: Insurance runs on personal data, from proposal forms and medical reports to claims records. The Personal Data Protection Act 2012 (PDPA), administered by the Personal Data Protection Commission (PDPC), sets the data protection obligations that insurers and intermediaries must meet, including mandatory breach notification, and the Do Not Call (DNC) rules for marketing calls and messages. MAS's cyber hygiene and technology risk requirements are covered in Section 11.4.


The Personal Data Protection Act 2012 (PDPA) in Insurance Practice

Underwriting, policy issuance, and claims administration necessitate extensive personal data. The Personal Data Protection Act 2012 (PDPA) establishes Singapore's baseline data privacy regime, balancing an organization's need to collect, use, and disclose data with an individual's right to protect personal data.

Definition of Personal Data

Under the PDPA, personal data is defined as:

"data, whether true or not, about an individual who can be identified — (a) from that data; or (b) from that data and other information to which the organisation has or is likely to have access."

In insurance operations, personal data includes:

  • Identifiers: Legal name, NRIC/FIN numbers, passport numbers, residential addresses, contact numbers, and email addresses.
  • Underwriting & Financial Data: Bank account numbers, credit history, salary details, employment records, and vehicle registration particulars.
  • Special Category / Sensitive Data: Medical histories, diagnostic laboratory reports, attending physician statements, disability records, and claims histories.

Collection and Handling of NRIC Numbers

Under PDPC Advisory Guidelines, organizations must not collect, use, or disclose NRIC or FIN numbers unless:

  1. Required under statutory law (e.g., Insurance Act 1966, Motor Vehicles (Third-Party Risks and Compensation) Act, or MAS AML/CFT notices); or
  2. Necessary to accurately verify identity to a high degree of fidelity where misidentification poses serious risks. While insurers collect NRICs for formal policy contracts and claims payouts, intermediaries cannot demand NRIC details for generic marketing lucky draws or preliminary sales inquiries.

The Main PDPA Data Protection Obligations

Insurers, brokers and agencies must put these obligations into practice:

Accountability Obligation (Sections 11–12)

Organisations are responsible for personal data in their possession or under their control. They must appoint at least one Data Protection Officer, put in place and communicate data protection policies and practices, and have a process to receive and respond to complaints.

1. Consent Obligation (Sections 13–17)

Organisations must obtain the individual's consent before collecting, using or disclosing personal data, unless an exception applies. Consent may be express or deemed: for example, deemed by conduct when a customer submits documents for a quotation, or deemed where disclosure is necessary to perform a contract. Organisations must not make consent beyond what is reasonable a condition of providing a product. Individuals may withdraw consent on giving reasonable notice.

2. Purpose Limitation Obligation (Section 18)

Data may only be processed for purposes that a reasonable person would consider appropriate in the circumstances. Collecting medical reports to underwrite personal accident coverage is legitimate; using that data to market consumer loans without consent violates purpose limitation.

3. Notification Obligation (Section 20)

Organizations must notify individuals of data collection purposes on or before gathering the information, using clear Personal Data Protection Notices (PDPN) on proposal forms and portals.

4. Access and Correction Obligations (Sections 21–22)

Individuals have the legal right to request access to their personal data and an accounting of its disclosures over the preceding 12 months. Organizations must also correct errors or omissions promptly and forward updates to relevant third-party recipients.

5. Accuracy Obligation (Section 23)

Organizations must ensure data is accurate and complete, particularly when used to make decisions affecting the individual (e.g., premium ratings or claim repudiations) or disclosed externally.

6. Protection Obligation (Section 24)

Organizations must implement reasonable security arrangements—including encryption, firewalls, role-based access, and physical clean desk policies—to prevent unauthorized access, loss, or disclosure.

7. Retention Limitation Obligation (Section 25)

Organizations must cease retaining personal data or anonymize it once the collection purpose is exhausted and retention is no longer necessary for legal or business reasons (such as the 6-year period under the Limitation Act 1959).

8. Transfer Limitation Obligation (Section 26)

Personal data must not be transferred outside Singapore unless the overseas recipient provides a standard of protection comparable to the PDPA (e.g., via Standard Contractual Clauses or Binding Corporate Rules).

9. Data Breach Notification Obligation (Sections 26A–26E)

Introduced in the 2020 PDPA amendments, organizations must assess suspected data breaches immediately. A breach is notifiable if it:

  1. Results in, or is likely to result in, significant harm to affected individuals (e.g., compromised NRIC, medical, or financial data); OR
  2. Affects 500 or more individuals. Organizations must notify the PDPC within 3 calendar days (72 hours) of determining that a notifiable breach occurred, and notify affected individuals as soon as practicable if significant harm is likely.

The PDPA Obligations in Insurance Practice

PDPA obligationPractical example in insurance
AccountabilityAppoint a Data Protection Officer; written data policies; complaint handling
ConsentClear consent for using claims data for unrelated marketing
NotificationData protection notices on proposal forms and portals
Purpose limitationUsing medical reports only for underwriting and claims
Access and correctionLetting customers see and correct their records
AccuracyChecking claims and NCD records before applying surcharges
ProtectionEncryption, access controls, clean-desk practices
Retention limitationDeleting or anonymising data once no longer needed
Transfer limitationComparable protection when sending data overseas, for example to reinsurers or cloud hosts
Data breach notificationNotify PDPC within 3 calendar days of assessing a breach as notifiable

Enforcement

The PDPC can impose financial penalties for breaches of the data protection provisions: up to 10% of annual turnover in Singapore for organisations whose turnover exceeds S$10 million, or up to S$1 million in other cases.

The Do Not Call (DNC) Registry in Direct Marketing

To curb unsolicited commercial communications, the PDPA establishes Singapore's Do Not Call (DNC) Registry, spanning three registers: No Voice Call, No Text Message, and No Fax Message.

Operational Rules for Insurance Intermediaries:

  • Mandatory Registry Verification: Before making telemarketing calls or sending promotional SMS/messages, intermediaries must check prospective 8-digit Singapore numbers against the DNC Registry.
  • Search Result Validity: DNC search results remain valid for a maximum of 21 calendar days. Numbers contacted beyond this period must be re-verified.
  • Sender Identification: Intermediaries must clearly identify themselves, state the insurance entity represented, and provide legitimate contact numbers without masking caller ID.
  • Exemptions: Purely transactional messages (e.g., policy renewal notices, claims updates) and communications where the customer granted clear, written consent are exempt from DNC checks.
Loading diagram...
PDPA Data Lifecycle and Breach Notification
Test Your Knowledge

When is a data breach notifiable to the PDPC under the PDPA, and how quickly must the PDPC be told?

A

Only if total losses exceed S$1 million; within 30 days of the breach being discovered

B

Every incident; within 2 hours to the police

C

If significant harm is likely or 500+ people are affected; within 3 calendar days

D

Never; notification is voluntary

Test Your Knowledge

An agency plans a telemarketing campaign for home insurance. What must it do about the Do Not Call Registry?

A

Check the numbers with the DNC Registry and re-check results older than 21 days

B

Nothing, provided the numbers were bought from a reputable overseas marketing list

C

Check once, after which the result is valid indefinitely

D

Nothing, if calls are made only at weekends

Test Your Knowledge

Which PDPA obligation requires an insurer to appoint at least one Data Protection Officer and to have data protection policies?

A

The Transfer Limitation Obligation

B

The Accuracy Obligation

C

The Retention Limitation Obligation

D

The Accountability Obligation

Sections you finish are checked off in the contents.