A practical PDPA checklist for marketing teams
On this page
Singapore's Personal Data Protection Act is not onerous, but the parts that catch marketing teams out are specific and easy to get wrong — particularly the Do Not Call rules and the difference between consent you have collected and consent you can evidence.
This article is a practical summary written by a marketing practitioner, not legal advice. For obligations specific to your organisation, read the Personal Data Protection Commission's own guidance, linked throughout, or take advice from a qualified adviser.
What the PDPA actually covers
Two things matter for marketing. First, the data protection provisions: how you collect, use, disclose and protect personal data, and the requirement to notify people of your purposes. Second, the Do Not Call provisions, which govern sending marketing messages to Singapore telephone numbers.
They are separate regimes with separate rules, and satisfying one does not satisfy the other. A contact who ticked a marketing consent box on your website may still be off-limits for an SMS campaign if the consent does not meet the DNC standard.
Consent: what counts and what does not
Consent under the PDPA must be a positive action. The Commission's guidance on key concepts is explicit that consent cannot be obtained through a pre-ticked box or by treating silence as agreement, and that you must not require consent to more than is reasonably necessary to provide the product or service (PDPC Advisory Guidelines on Key Concepts in the PDPA).
In practical terms, for every form on your site:
- The marketing consent checkbox is unticked by default and separate from the submit action.
- The purpose is stated in plain language next to it — what you will send, and roughly how often.
- Submitting an enquiry is possible without agreeing to marketing.
- The timestamp, form, wording shown and IP are stored with the record. Consent you cannot evidence is, in effect, consent you do not have.
The most common failure we find. A consent statement that was updated in 2024 while the stored records still reference the 2022 wording, with no version history. Store the exact text shown at the time of collection alongside each record.
The Do Not Call Registry in practice
The DNC Registry covers voice calls, text messages and faxes to Singapore telephone numbers. Before sending a specified message you must check the number against the relevant register, and a check result remains valid for a limited window — the Commission's advisory guidelines set that validity period at 21 calendar days before the message is sent (PDPC Advisory Guidelines on the Do Not Call Provisions, and the Commission's own Do Not Call FAQ).
There are two main routes around a listed number. The first is clear and unambiguous consent given in writing or another accessible form, obtained specifically for receiving marketing messages of that type. The second is one of the exclusions set out in the Act's Eighth Schedule — which is where most business-to-business communication and genuine market research sits. Both routes need to be documented before the campaign runs, not reconstructed afterwards.
Two additional obligations are frequently overlooked. A marketing message must identify the sender and provide contact details, and an SMS campaign needs a working opt-out mechanism that a recipient can actually use.
Email is different
The DNC provisions do not extend to email — but that does not make email a free channel. The general data protection provisions still apply, so you need a valid basis for using someone's email address for marketing, a stated purpose, and a working unsubscribe. Withdrawal of consent must be honoured, and honoured promptly across every list and platform, not just the one the person clicked.
In practice the operational risk with email is fragmentation: a contact unsubscribes in your ESP, and three months later a sales sequence in the CRM emails them again because the two systems never synchronised. That is the failure we see most often, and it is a systems problem rather than a policy one.
The seven checks we run
- Consent capture. Every form audited: unticked by default, purpose stated, marketing optional, wording and timestamp stored.
- Withdrawal path. A tested unsubscribe that propagates to ESP, CRM and ad platform audience lists. We actually click it.
- DNC process. A documented check within the validity window before any call or SMS campaign, with the check reference retained, or a documented exemption.
- Audience lists. Customer-match style uploads reviewed for a lawful basis, and stale lists deleted rather than left in the platform indefinitely.
- Tags and consent mode. Analytics and advertising tags respect the visitor's consent choice, verified by inspecting network requests before and after a refusal.
- Vendors and transfers. Data processing terms in place with every processor, and a record of which vendors hold personal data and where.
- Retention and access. A stated retention period per data type, access limited to people who need it, and a documented route for access and correction requests.
Who is responsible
Every organisation subject to the PDPA must appoint at least one individual responsible for ensuring compliance — the Data Protection Officer — and make their business contact information available. In smaller companies this is frequently the marketing lead by default, which works only if that person actually has the authority to stop a campaign.
For our own clients we ask who the DPO is on the first call. If nobody knows, that is the first thing we fix, before a single audience list is uploaded anywhere.
Want the checklist as a working document? We run this audit as part of onboarding for every Singapore client, and as a standalone review for teams who are not working with us. Ask us about a PDPA marketing review.
Sources: PDPC Advisory Guidelines on the Do Not Call Provisions (PDF); PDPC Advisory Guidelines on Key Concepts in the PDPA (PDF); PDPC frequently asked questions on the Do Not Call Registry. Accurate to the best of our knowledge as at March 2026.