The History of Indian Privacy — APAC Comparative

    Singapore PDPA vs India DPDPA: Same Roots, Diverging Reach

    Singapore's PDPA is a pragmatic economic enabler — designed for a city-state with global trade ambitions. India's DPDPA is a rights-anchored response to the needs of a billion+ digital citizens. Both matter if you operate across both markets. Written by Yuvaraj S., Founder, truConsent.

    Context

    Why Singapore Matters for Indian Businesses

    Singapore is the most common offshore hub for Indian tech companies. Thousands of Indian startups and enterprises maintain Singapore holding companies, regional headquarters, or treasury vehicles there. For many, data flows between Indian operations and Singapore entities are routine — and largely unexamined from a privacy compliance perspective. That is about to change.

    The MAS (Monetary Authority of Singapore) combined with the PDPA creates a dual compliance framework for fintech — one of the most common intersections for Indian companies with regional ambitions. If you're building a payment product, a lending platform, or a wealth management tool with presence in both countries, you're navigating four regulatory frameworks simultaneously: MAS TRM, PDPA, RBI data localisation, and DPDPA. Understanding each law's structure — and how they interact — is foundational to operating in both markets without creating structural liability.

    Singapore's PDPA was enacted in 2012, substantially amended in 2020, and represents one of the most mature and actively enforced APAC privacy frameworks. It has a track record, an institutional regulator with real teeth, and a growing body of enforcement decisions. For Indian businesses trying to understand where DPDPA enforcement will likely go, the PDPC's history is probably the most relevant regional reference point.

    Side-by-Side Comparison

    PDPA vs DPDPA: The Comparison

    Ten dimensions where Singapore and India diverge — or unexpectedly align. Each row has direct operational implications for businesses in both markets.

    DimensionSingapore PDPAIndia DPDPA
    Foundational PhilosophyBalances individual rights with business enablement. Designed to position Singapore as a trusted global data hub.Rights-first. Built on Article 21 (constitutional right to privacy). Business interests subordinate to individual data protection.
    RegulatorPersonal Data Protection Commission (PDPC) — mature, experienced, both educator and enforcer. Operates under IMDA.Data Protection Board of India (DPBI) — newly established, adjudicatory initially. Expected to evolve in scope and posture.
    Legal Grounds for ProcessingConsent + deemed consent (implied consent through contextual use) + legitimate interests + business necessity exceptions.

    Singapore is significantly more flexible on non-consent processing grounds. India is more restrictive.

    Consent + "certain legitimate uses" — a narrower, defined list covering state functions, employment, and medical emergencies.
    Consent ModelStandard consent flows. Notification + opt-out permissible in some cases. 2020 amendment formalized consent refresh requirements.Explicit, informed, unconditional consent. Managed through a licensed Consent Manager. Withdrawal must be as easy as consent.
    Data PortabilityIntroduced in the 2020 amendment. Users can request their data be sent directly to another organisation in a common machine-readable format.

    Singapore is ahead of India on this specific right.

    Not currently included in the 2023 Act. Likely to be added in future Rules or amendments.
    Sensitive DataNo separate 'sensitive' category — all personal data treated uniformly. Health data has sector-specific guidance under Healthcare Instructions.Also no explicit sensitive categories (unlike GDPR). A gap both laws share that may be addressed in future amendments.
    PenaltiesUp to SGD 1M OR 10% of annual local turnover (whichever is higher, post-2020 amendment). Proportionate to company size.

    Singapore's revenue-linked model is more proportionate for large companies. India's fixed slabs may be disproportionately high for SMEs.

    Up to ₹250 crore (~$30M) per breach instance. Fixed slabs, not revenue-linked.
    Consent Manager EquivalentNo formal equivalent. CMPs are software tools, not regulated legal entities.Licensed Consent Manager — registered with DPBI, legally accountable under the Act.
    Cross-Border TransfersWhitelist of countries with adequate protection. Contractual protections required for all others.Negative list of prohibited countries (pending Rules). Transfer restrictions apply by exclusion rather than inclusion.
    Enforcement PostureActive — PDPC initiates investigations, publishes advisory guidelines, issues financial penalties, and names companies publicly.Adjudicatory — DPBI responds to complaints. Proactive enforcement capacity expected to develop over time.

    Enforcement Track Record

    Singapore PDPA Enforcement Snapshot

    The PDPC has been enforcing since 2016. These cases illustrate the regulator's posture: active, public, and proportionate — but not lenient on systemic failures.

    2018

    SGD 750,000 + SGD 250,000

    SingHealth + IHiS

    1.5 million patient records stolen in a cyberattack. The largest PDPA fine at the time. Both the healthcare provider and its IT operator were fined separately — establishing that technology partners share liability.

    2020

    SGD 10,000

    GrabCar

    Driver personal data leaked due to an insecure system update. A small fine — but notable because it arose from a negligent software deployment, not a targeted attack.

    2019

    Financial penalty issued

    My Digital Lock

    Unsecured web forms led to unauthorised access to customer data. Demonstrated that even SMEs face enforcement action under PDPA.

    2024

    SGD 20,000

    Consumers Association of Singapore

    Fined for failing to implement adequate data protection measures — a reminder that non-profit organisations are not exempt from PDPA obligations.

    2021

    Proportionate financial penalty

    ShopBack

    Fined for a data breach affecting customer account details. Penalty was proportionate to the company's size and the scope of the impact.

    2021

    Financial penalty issued

    Autobahn Motors

    Fined for inadequate data protection measures after a breach exposed customer data stored in a publicly accessible folder.

    Practical Guidance

    For Businesses Operating in Both Markets

    Operating in both Singapore and India isn't just about having two privacy policies. It requires architectural decisions that satisfy both regimes simultaneously.

    01

    Default to India's stricter consent standard

    Singapore's deemed consent provisions are considerably broader than DPDPA's legitimate uses. If you operate in both markets, default to DPDPA's explicit consent requirement across the board — it satisfies both laws simultaneously and simplifies your compliance architecture.

    02

    Build data portability now, even if India doesn't require it yet

    Your Singapore users have a right to data portability under PDPA 2020. Your India users do not — yet. Build portability into your data architecture now. When DPDPA amendments add portability (and they likely will), you won't need to retrofit.

    03

    Map your regulatory stack before you map your data

    If you're a fintech operating in both markets, you're effectively managing four frameworks: MAS TRM guidelines + Singapore PDPA + RBI data localisation + India DPDPA. Consent management is only one layer. Before building a compliance programme, map the full regulatory stack for your specific business model.

    04

    Understand both cross-border transfer mechanisms

    If you're moving data from Singapore to India: check Singapore's whitelist status for India (currently included). If you're moving data from India to Singapore: await DPDPA's negative list once Rules are notified, and structure your transfers accordingly. Document your transfer basis for both directions.

    Trajectory

    Where Both Laws Are Headed

    Singapore is refining its balance. The 2020 amendment added portability, tightened breach notification timelines, and increased maximum penalties to revenue-linked caps. A further review of PDPA is underway, with particular attention to algorithmic decision-making and the boundaries of deemed consent in AI-powered contexts. The PDPC's recent guidance on AI governance suggests that Singapore is preparing its privacy framework for an era of automated processing.

    India is building its foundation. The DPDPA Rules will be the critical document — they'll define Significant Data Fiduciaries, establish the negative list for cross-border transfers, operationalize the DPBI, and set out the technical and organisational standards for consent management. Until the Rules are notified, the full scope of India's framework remains incomplete. But the statutory obligations are already live — and compliance cannot wait for the Rules.

    The convergence point is clear: both laws are moving toward more explicit consent requirements, broader data subject rights, and stronger enforcement. The PDPC has proven that a smaller regulator can act decisively and publicly. The DPBI will take time to develop that institutional muscle — but the trajectory is set. Businesses that build adaptable consent infrastructure now — infrastructure that works within India's strict explicit-consent model and Singapore's broader framework simultaneously — will absorb both countries' future amendments more easily than those who treat compliance as a one-time checkbox exercise.

    The Structural Insight

    Singapore's PDPA was built to enable trade. India's DPDPA was built to protect rights. These different starting points produce genuinely different laws — but they are converging. The businesses that will thrive across APAC's evolving privacy landscape are those that build consent infrastructure sophisticated enough to satisfy the stricter standard, not those that optimise for minimum compliance in each jurisdiction separately.

    India's Licensed Consent Manager

    truConsent is not a CMP. Not a cookie banner.

    India is the only country where a Consent Manager is a licensed intermediary accountable to a regulator. truConsent is built specifically for DPDPA 2023 — consent lifecycle, data principal rights, breach management, and more.