GDPR
What Is PDPA? A Guide to Personal Data Protection Acts
PDPA stands for Personal Data Protection Act. It is not one law. At least five jurisdictions have a statute by that name, each imposing different obligations, setting different deadlines, and enforced by a different regulator. If you have been told your organisation needs to be “PDPA compliant,” the first question to settle is which PDPA.
This guide covers all five: Singapore, Malaysia, Thailand, Taiwan and Sri Lanka. It sets out what each one requires, what changed recently in each, and where they diverge enough that treating them as one regime will cause problems.
Last reviewed: September 2026.
What does PDPA stand for?
Personal Data Protection Act. The name is generic enough that several legislatures have independently arrived at it, which is exactly why the acronym causes confusion.
When someone says “the PDPA” without qualification, context usually tells you which one they mean:
- In Singapore, the Personal Data Protection Act 2012, enforced by the Personal Data Protection Commission.
- In Malaysia, the Personal Data Protection Act 2010 (Act 709), enforced by the Personal Data Protection Commissioner.
- In Thailand, the Personal Data Protection Act B.E. 2562 (2019), enforced by the Personal Data Protection Committee.
- In Taiwan, the Personal Data Protection Act, moving to a dedicated Personal Data Protection Commission.
- In Sri Lanka, the Personal Data Protection Act, No. 9 of 2022, enforced by the Data Protection Authority.
Confusingly, three of these regulators abbreviate to “PDPC.” Singapore’s Commission, Thailand’s Committee and Taiwan’s new Commission share initials while being entirely separate bodies.
A sixth law is often drawn into the same conversation. The Philippines has the Data Privacy Act of 2012 (Republic Act No. 10173), enforced by the National Privacy Commission. It is a PDPA in substance but not in name.
Which countries have a PDPA?
| Jurisdiction | Statute | In force | Regulator |
|---|---|---|---|
| Singapore | Personal Data Protection Act 2012 | Main obligations from 2 July 2014 | Personal Data Protection Commission |
| Malaysia | Personal Data Protection Act 2010 (Act 709) | 2013, substantially amended during 2025 | Personal Data Protection Commissioner |
| Thailand | Personal Data Protection Act B.E. 2562 (2019) | Fully in force 1 June 2022 | Personal Data Protection Committee |
| Taiwan | Personal Data Protection Act | Amended 2023 and October 2025 | Personal Data Protection Commission (in transition) |
| Sri Lanka | Personal Data Protection Act, No. 9 of 2022 | Phased; Authority established August 2023 | Data Protection Authority |
Singapore’s PDPA
Singapore’s law is the one most people mean when they say PDPA without further qualification, partly because it is the oldest of the group in full operation and partly because its regulator publishes enforcement decisions in detail.
The 11 PDPA obligations
The framework is usually taught as a set of numbered obligations. There are eleven, though one is not yet operative:
- Consent - collect, use or disclose personal data only for purposes the individual has consented to, and allow consent to be withdrawn.
- Purpose limitation - the purposes must be ones a reasonable person would consider appropriate.
- Notification - tell individuals the purposes before collecting, using or disclosing.
- Access and correction - on request, give individuals their data and tell them how it has been used or disclosed in the past year; correct errors.
- Accuracy - make reasonable effort to ensure data is accurate and complete.
- Protection - make reasonable security arrangements.
- Retention limitation - stop retaining data once it no longer serves a business or legal purpose.
- Transfer limitation - transfer overseas only where the receiving jurisdiction offers comparable protection.
- Accountability - have policies and practices, appoint a DPO, and publish that DPO’s business contact information.
- Data breach notification - notify the PDPC, and in some cases affected individuals, when a notifiable breach occurs.
- Data portability - transfer an individual’s data to another organisation on request. Legislated but not yet in force, because the supporting regulations have not been issued.
If you are searching for “PDPA 11 obligations” and finding sources that list ten, or nine, that is because the count has grown. The original framework had nine. Breach notification was added as the tenth in 2020. Portability is the eleventh, waiting on regulations.
What the 2020 amendment changed
The Personal Data Protection (Amendment) Act 2020 was passed on 2 November 2020 and was the first full review of the law since 2012. Three changes matter operationally.
Mandatory breach notification. Since 1 February 2021, an organisation that assesses a breach as notifiable must tell the PDPC as soon as practicable, and in any event within three calendar days. This is shorter than the 72 hours most GDPR-trained teams expect, and the clock is anchored differently: it runs from the point of assessment rather than the point of awareness.
Legitimate interests. The amendment introduced a legitimate interests basis, allowing collection, use and disclosure without consent where the organisation’s legitimate interest outweighs any adverse effect on the individual and appropriate safeguards are in place. This moved Singapore meaningfully away from a purely consent-driven model.
Higher penalties. The maximum financial penalty rose from a flat SGD 1 million to the higher of SGD 1 million or 10% of the organisation’s annual turnover in Singapore, where that turnover exceeds SGD 10 million.
A note for anyone doing telemarketing
Singapore’s PDPA also governs telemarketing through the Do Not Call Registry. This sits outside the data protection obligations above and catches organisations that never think of themselves as data processors. If you send marketing messages to Singapore numbers, this part of the Act applies to you.
Malaysia’s PDPA
Act 709 was passed in 2010 and enforced from 2013. For over a decade it was the least demanding of the group. That changed in 2025.
The seven principles
The Malaysian framework is built on seven principles rather than eleven obligations: General, Notice and Choice, Disclosure, Security, Retention, Data Integrity, and Access. Breaching any of them is an offence, not merely a regulatory failing. That is a structural difference worth understanding, because Malaysian data protection law has always carried criminal exposure.
What the 2024 amendment changed
The Personal Data Protection (Amendment) Act 2024 (Act A1727) was brought into force in stages across the first half of 2025, with the headline obligations taking effect on 1 June 2025.
Terminology aligned with the GDPR. “Data user” was replaced throughout the Act with “data controller.” This is not cosmetic. It signals a deliberate move toward the vocabulary used internationally and makes the Malaysian regime easier to map onto a GDPR-based programme. The underlying analysis is much the same as under the GDPR, and I have set it out in controller or processor: your role depends on what you do.
Data protection officers became mandatory. Both controllers and processors must now appoint one or more DPOs where their processing crosses the thresholds in the Commissioner’s guidelines, and the controller must notify the Commissioner of the appointment.
Breach notification became mandatory. A controller must notify the Commissioner as soon as practicable after having reason to believe a breach has occurred, and must also notify affected data subjects where the breach causes or is likely to cause significant harm.
Processors gained direct obligations. The Act previously placed duties almost entirely on the data user. Processors now carry obligations in their own right, particularly on security.
Biometric data became sensitive personal data. Fingerprints, facial recognition templates and similar identifiers are now explicitly in the sensitive category, which raises the processing bar.
The cross-border whitelist was scrapped. Malaysia previously operated a list of approved destination countries. That has been replaced by an assessment of whether the destination has substantially similar law or otherwise ensures adequate protection.
The amendment also raised the penalty for breaching the personal data protection principles, to a fine of up to RM1 million and imprisonment of up to three years.
Thailand’s PDPA
Thailand’s PDPA B.E. 2562 was enacted in 2019 but its application was postponed twice. It came fully into force on 1 June 2022, and it is the most closely GDPR-modelled of the group.
Lawful bases. Unlike Singapore’s original consent-centric design, Thailand’s law provides a set of lawful bases resembling Article 6 of the GDPR, including contract, legal obligation, vital interests, public task and legitimate interests.
Breach notification in 72 hours. Section 37(4) requires a data controller to notify the Office of the PDPC without delay and, where feasible, within 72 hours of becoming aware of a breach, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. The detailed criteria were published in the Government Gazette on 15 December 2022. Two points catch foreign teams out: awareness is assessed at organisational level, not executive level, and the 72 hours run continuously, so a Friday discovery does not pause over the weekend.
Mandatory DPOs. Section 41 requires a DPO where the controller or processor is a public authority, where core activities involve regular monitoring of personal data on a large scale, or where core activities involve large-scale sensitive data.
Enforcement is real. In August 2024 the PDPC issued its first administrative sanction, a THB 7 million fine against a company handling the personal data of more than 100,000 individuals. The violations were failure to implement appropriate security measures, failure to notify the breach within 72 hours, and failure to appoint a DPO. That combination is instructive, because two of the three failures were procedural rather than technical. The company was penalised as much for its governance gaps as for the breach itself.
Taiwan’s PDPA
Taiwan’s Personal Data Protection Act is often overlooked in regional summaries, and it is currently in the middle of the most significant change in its history.
Taiwan’s Constitutional Court ruled in August 2022 that an independent supervisory mechanism for personal data protection was required. An amendment in May 2023 added a provision naming a Personal Data Protection Commission as the competent authority, and a preparatory office for the Commission was established in December 2023.
On 17 October 2025 the Legislative Yuan passed further amendments establishing the Commission as the supervisory authority. The package includes mandatory DPO appointment for government agencies, new breach notification and reporting obligations for non-government entities, expanded inspection powers, and a transition period for certain supervisory functions.
Until that transition completes, oversight remains distributed across sector regulators, with the Ministry of Justice maintaining the legal framework. The Act applies extraterritorially to entities outside Taiwan processing the personal data of people in Taiwan.
If your knowledge of Taiwanese data protection predates 2025, it needs refreshing.
Sri Lanka’s PDPA
Sri Lanka enacted the Personal Data Protection Act, No. 9 of 2022, becoming the first country in South Asia with comprehensive data protection legislation. It is modelled on the GDPR and applies to controllers and processors domiciled or incorporated in Sri Lanka, and to those offering goods or services to people there.
The Act came into force in phases. The provisions establishing the Data Protection Authority and the interpretation section were brought into operation in 2023, with the Authority established in August 2023. Further parts commenced on 1 December 2023. It was subsequently amended by the Personal Data Protection (Amendment) Act, No. 22 of 2025.
If you operate in South Asia, note the contrast with India: Sri Lanka legislated first and has a functioning authority, while India’s substantive obligations under the Digital Personal Data Protection Act, 2023 do not take effect until 14 May 2027.
How PDPA compares to GDPR
The five PDPAs sit at different distances from the GDPR.
Thailand and Sri Lanka are closest. If you have a GDPR programme, most of it transfers with adjustments.
Malaysia moved much closer with the 2024 amendment, but retains a criminal-offence structure the GDPR does not have, and its seven principles do not map one-to-one onto GDPR articles.
Singapore is the most distinct. It has no equivalent of the GDPR’s lawful bases (until 2020 it was almost entirely consent-driven), it uses “organisation” and “data intermediary” rather than controller and processor, and its breach notification window is three days from assessment rather than 72 hours from awareness.
Taiwan is mid-transition, and the shape of its regime will depend on how the new Commission operates.
The practical failure mode is assuming a GDPR data processing agreement satisfies all five. It generally does not, because the required contractual content differs. For the wider picture of how these regimes relate to each other, see data protection laws around the world.
PDPA and PDPL are different acronyms
It is easy to conflate PDPA with PDPL, and the two turn up in the same conversations. PDPL stands for Personal Data Protection Law and refers primarily to Saudi Arabia’s statute, with Bahrain, Oman, Jordan, the UAE and Vietnam also using the term. Those are separate laws with separate regulators. If you are working across both Southeast Asia and the Gulf, keeping the two acronyms straight is the first step in scoping the work. I have covered the PDPL family in what is PDPL.
What PDPA compliance actually requires
Across all five jurisdictions, the recurring obligations are the same handful of things:
- A named, notified data protection officer where the thresholds are met
- A record of what personal data you hold, why, and on what basis
- A breach response procedure that can produce a regulator notification inside the applicable window
- Contracts with processors that meet the specific jurisdiction’s requirements
- A documented position on any cross-border transfer
None of that is exotic. The difficulty is that the deadlines, thresholds and contractual requirements differ enough that a single template will not satisfy all five. Building a shared data governance framework and layering jurisdiction-specific controls on top tends to work better than maintaining five parallel programmes. The full regional picture, including the countries that do not use the PDPA name, is in APAC privacy laws.
Frequently asked questions
What does PDPA stand for?
Personal Data Protection Act. Singapore, Malaysia, Thailand, Taiwan and Sri Lanka each have a statute by that name.
Is PDPA the same as GDPR?
No. All five PDPAs share concepts with the GDPR, and Thailand’s and Sri Lanka’s are closely modelled on it, but the obligations, timelines and terminology differ. A GDPR compliance programme is a useful starting point rather than a substitute.
How many obligations does the Singapore PDPA have?
Eleven, though the eleventh (data portability) is not yet in force because the supporting regulations have not been issued.
Does the PDPA require a data protection officer?
Singapore requires organisations to designate one and publish their business contact information. Malaysia has required one since 1 June 2025 where processing thresholds are met. Thailand requires one under Section 41 in specified circumstances. Taiwan’s 2025 amendments make appointment mandatory for government agencies.
What is the PDPA breach notification deadline?
It differs by country. Singapore requires notification to the PDPC as soon as practicable and within three calendar days of assessing that a notifiable breach occurred. Thailand requires notification without delay and, where feasible, within 72 hours of becoming aware. Malaysia requires notification as soon as practicable after having reason to believe a breach has occurred.
Does PDPA apply to companies outside the country?
Thailand’s law has express extraterritorial reach, as does Taiwan’s. Singapore’s applies to organisations that collect, use or disclose personal data in Singapore regardless of where they are established. Malaysia’s scope was broadened by the 2024 amendment, and Sri Lanka’s reaches those offering goods or services to people there. In practice, if you are targeting customers in these markets, assume the law reaches you and check the specifics.
Which countries have a PDPA?
Singapore, Malaysia, Thailand, Taiwan and Sri Lanka. The Philippines has an equivalent law under a different name, the Data Privacy Act of 2012.
Sources
- Singapore Personal Data Protection Act 2012 and the Personal Data Protection (Amendment) Act 2020; guidance published by the Personal Data Protection Commission
- Malaysia Personal Data Protection Act 2010 (Act 709) and Personal Data Protection (Amendment) Act 2024 (Act A1727); Guideline on Data Breach Notification and Guideline on Appointment of Data Protection Officer
- Thailand Personal Data Protection Act B.E. 2562 (2019); Personal Data Protection Committee notification on breach notification criteria, Government Gazette, 15 December 2022
- Taiwan Personal Data Protection Act, as amended May 2023 and October 2025; Constitutional Court Judgment 111-Hsien-Pan-13 (2022)
- Sri Lanka Personal Data Protection Act, No. 9 of 2022, and Personal Data Protection (Amendment) Act, No. 22 of 2025; Data Protection Authority of Sri Lanka