Quick verdict
The “governance person” in a Singapore company is the Data Protection Officer. Section 11(3) of the Personal Data Protection Act 2012 says an organisation must designate one or more individuals to be responsible for ensuring the organisation complies with the Act. Section 11(5) says you must make at least one of those people’s business contact information available to the public. Section 11(6) says naming them does not take liability off the organisation.
That is not an AI Act. It is older, binding, and already the named role for anything that puts personal data into ChatGPT, a vendor copilot, or a model that ranks a customer or a candidate. If you are selling an AI accountability tool in Singapore, this is who you contact. Their email is often on the privacy policy.
Best for: Singapore operators, AU/SG groups, and anyone running outbound to the person who actually owns PDPA. Honest limit: the law requires a designated individual, not always a full-time exclusive hire. We are not a PDPC adviser of record and we do not replace the organisation’s liability.
Last updated: 31 August 2026.
Who is the PDPA person in a Singapore company?
The Data Protection Officer. Every organisation that is subject to the PDPA must have at least one. There is no staff-count or turnover threshold the way Australia’s Privacy Act has a small-business line. Sole proprietors and non-profits are in the PDPC starter kit’s “appoint a DPO” list. Public agencies sit under a different part of the regime; the companies we mean here are private organisations that collect or use personal data in Singapore.
What the law actually requires (not the brochure version)
| Section | Duty | What people get wrong |
|---|---|---|
| 11(3) | Designate one or more individuals responsible for PDPA compliance | Thinking only “big companies” need a DPO |
| 11(4) | That person may delegate operational work | Delegation does not delete the designation |
| 11(5) | Publish business contact information of at least one designated or delegated person | Hiding the DPO behind a general “contact us” with no data-protection path. PDPC has fined organisations that failed to make a DPO reachable |
| 11(6) | The organisation stays liable | Treating an outsourced DPO-as-a-service as a transfer of legal risk |
PDPC’s starter kit is explicit on the employment question: the DPO can be a dedicated role or an additional function. They may or may not be an employee. They may or may not sit in Singapore, but they must be readily accessible from Singapore. Ideal shape: someone with a line to management. Operational work can sit with a small team or an outsourced provider. Someone in senior management should still own the relationship.
There is no mandatory DPO certificate. PDPC encourages training against its DPO Competency Framework. Registration of the DPO with PDPC is encouraged, not a substitute for publishing the contact. As of late 2024 the BizFile+ DPO path changed; PDPC points organisations at its current registration form. Publish the contact on the site either way.
What that person already has to do
PDPC’s Data Protection Management Programme guide lists the job in plain language. A DPO is expected to:
- Put data-protection policies and processes in place so the organisation can comply with the PDPA
- Build a data-protection culture and tell staff what the rules are
- Handle access and correction requests
- Manage queries and complaints about personal data
- Alert management when personal-data risk shows up
- Liaise with PDPC when needed
The 2020/2021 amendments added a data-breach notification duty. The DPO typically owns the Data Breach Management Plan: decide if a breach is notifiable, tell PDPC and affected individuals inside the statutory clocks. Access and correction requests have their own clocks (commonly treated as 30 days unless a refusal ground applies).
Underneath that sit the organisation’s PDPA obligations, which the DPO has to make operable: consent, purpose limitation, notification, access and correction, accuracy, protection, retention limitation, transfer limitation, accountability, and breach notification. Do Not Call rules sit alongside for marketing numbers.
Financial penalties for serious breaches can reach the higher of S$1 million or 10% of annual turnover in Singapore. Appointing a DPO is not a shield. It is how the organisation shows it even tried.
Why AI landed on this person’s desk
Singapore still has no AI Act. Personal data in a prompt, a fine-tune, a retrieval index, a vendor log or a ranking model is still personal data. The DPO is already the named owner of that problem.
Two PDPC instruments made that explicit:
- Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems (1 March 2024). Consent, notification, business-improvement and research exceptions, transparency about recommendations and decisions, DPIAs recommended where the processing is significant.
- Advisory Guidelines on the Use of Personal Data in Generative AI (final 20 July 2026). How personal data may be used to develop generative models, who in the supply chain stays accountable, and how individual requests should be handled. The organisation cannot contract PDPA away to the model vendor.
IMDA’s Model Frameworks (including the 2026 agentic framework) stay voluntary. They still ask for the same artefacts a DPO needs: owners, risk bounds, human accountability, logs. Framework map: Singapore AI governance 2026.
Unique insight from Power Days in Singapore: the DPO often already has a privacy policy and a vendor list. They do not have a row for “Salesforce enabled AI summaries in a release note” or “HR pastes CVs into ChatGPT.” Until those rows exist, they cannot answer an access request that asks “what did you put about me into a model,” and they cannot tell management the risk. The job became an inventory job.
How to find this person (they are supposed to be findable)
Section 11(5) is a gift to anyone doing honest outreach. Look at:
- The organisation’s privacy policy — DPO email or a
dpo@/dataprotection@alias - The website footer or “personal data” page
- Consent forms and employee handbooks
- PDPC’s DPO registration, where the organisation filed it
If you cannot find a contact, that is itself a PDPA gap. Do not cold-email the CEO with “AI Act 2027.” Write the DPO: you already have the legal duty; here is the register for the AI that is already using personal data.
What the DPO needs on their desk — and what the tool holds
A living evidence system does not replace counsel and does not certify the organisation. It holds the working file the DPO is already supposed to maintain, including the AI rows they usually lack.
| DPO job | What the accountability layer keeps |
|---|---|
| Know what personal data you have, and where it goes | Inventory of tools, models, APIs and embedded SaaS AI; data in; destination; training opt-in; residency |
| Consent, purpose, notification | Purpose on each row; whether the privacy notice actually mentions that use |
| Access and correction | Which systems hold a person’s data, including prompts and logs, so a request is not a scavenger hunt |
| Protection and transfers | Vendor, subprocessors, DPA, region. The organisation stays accountable for the GenAI vendor |
| Accuracy when data is used to decide something about a person | Decision flag + human override. Matches PDPC’s AI recommendation/decision guidelines and, in Australia, the Dec 2026 ADM text |
| Retention | What the vendor keeps, what you keep, a review date |
| Breach plan | Which AI systems could leak personal data; who to call; what logs exist |
| Alert management; liaise with PDPC | Risk tier, owner, exportable evidence pack — not a workshop deck from last year |
| DPIA / significant AI processing | The same row, with a deeper risk note, instead of a second spreadsheet |
Field list we actually fill: AI inventory (same hunt; PDPA flags instead of APP 1). A Power Hour stands the system up. A Power Day puts the DPO, IT and the function leads in one room and leaves a living register. What the day produces.
Two-question filter, Singapore edition: are you using AI? Does the DPO have a register they can evidence? Yes and no — that is the call.
FAQ
Must the DPO be a full-time dedicated employee? No. The Act requires a designated individual. PDPC allows an additional function, a small team, or an outsourced DPO. Someone in management should still own it. A company that has grown past “the office manager is also DPO” and now has shadow AI usually needs more time than a title on a business card.
Does appointing a DPO make us PDPA-compliant? No. It is one mandatory step. The organisation remains liable for consent, protection, transfers, breaches and the rest.
Is the DPO also the AI governance owner? Often in practice, because AI now processes personal data. IMDA still wants a named accountable person for AI systems. If that is a different executive, the DPO still needs the personal-data rows. One register, two names on the row.
We are an Australian company with a Singapore office. If you collect or use personal data in Singapore, PDPA applies to that handling. Publish a DPO contact that works from Singapore. Keep one evidence layer with a Singapore export. Comparison: EU vs AU vs SG.
Will a Power Day make the DPO “compliant”? No. It gives them the living file the job requires. Legal opinions and PDPC engagement stay with them and their counsel.
Related: Singapore AI governance 2026 · AI inventory · Power Day · Prove it · Contact the team that will sit with your DPO
