The obligations come from the Personal Data Protection Act 2012 on Singapore Statutes Online, as reshaped by the 2020 amendments. Consent remains the anchor: you collect personal data with the individual's consent, or under deemed consent where someone volunteers their details for an obvious purpose, and you seek fresh consent before using data for a purpose nobody was told about. Individuals may withdraw consent at any time, ask for access to their data and require corrections; where you cannot answer an access request within thirty days, you must tell the requester in writing when you will.
Alongside consent sit the quieter duties: keeping data accurate before it feeds a decision, protecting it with reasonable security arrangements, retaining it no longer than the purpose requires, and sending it overseas only where the recipient is legally bound to a comparable standard of protection. The 2020 reform added a mandatory breach regime: where a breach is likely to cause significant harm or reaches a significant scale, the organisation must notify the Personal Data Protection Commission within three calendar days of determining that the breach is notifiable.
Two further rules matter for charities specifically. The Do Not Call provisions catch calls and text messages to Singapore numbers only where the message carries a marketing element; under the PDPC's guidance, a pure appeal for donations generally sits outside the regime, but a ticketed gala or a merchandise drive brings it straight back in. And the Act requires every organisation, whatever its size, to designate at least one Data Protection Officer whose business contact information is made available to the public.