← ALL REGULATIONS

Singapore PDPA cookie consent requirements, and the exceptions.

Under Singapore’s Personal Data Protection Act, an organisation needs consent, or a recognised exception, before it collects personal data through cookies. Consent can be deemed in some cases, and cookies that collect no personal data fall outside the Act.

Singapore PDPA at a glanceConsent, with exceptions
Applies to
Organisations that collect, use or disclose personal data in Singapore
In force
July 2014, with amendments from February 2021
Enforced by
Personal Data Protection Commission (PDPC)
Penalties
Up to 10% of annual turnover in Singapore for organisations above S$10 million, otherwise up to S$1 million
WHAT SINGAPORE PDPA REQUIRES

What the PDPA asks of a site that uses cookies.

THE RULEConsent before collecting personal dataAn organisation must get consent, or rely on an exception such as legitimate interests, before collecting personal data through cookies.
WITH KATLAIn GDPR mode, which Auto uses outside the Americas, cookies outside the functional category wait for an opt-in, which meets the consent obligation for the cookies that need it.
THE RULETell people the purposesPeople must be told the purposes of the collection on or before it happens.
WITH KATLAKatla scans the site, classifies every cookie it finds and generates the cookie policy from that list, in 13 languages.
THE RULEWithdrawalPeople can withdraw consent on reasonable notice, and must be told what withdrawing means for them.
WITH KATLAA floating settings icon, or your own "Cookie settings" link calling katla.open(), reopens the choice on any page.
THE RULEDeemed consentConsent can be deemed when a person voluntarily provides data for a purpose, or when they were notified and did not opt out in time, after the organisation has assessed the impact.
WITH KATLAKatla does not run a notify-and-wait flow. It asks for the choice directly, which is the stricter route.

Singapore PDPA questions, answered

A summary for website owners, not legal advice. Reviewed against the sources below.

Do cookies need consent in Singapore?
Only cookies that collect personal data, and even then consent can be deemed or an exception can apply. Cookies that only keep a site working usually need none.
What are the PDPA penalties?
Up to 10% of the organisation’s annual turnover in Singapore if that turnover exceeds S$10 million, otherwise up to S$1 million.
Does the PDPA apply to overseas companies?
Yes, when they collect, use or disclose personal data in Singapore.
How does Katla treat Singapore visitors?
Auto mode reads the visitor’s timezone and uses the opt-in GDPR banner outside the Americas, so Singapore visitors are asked before any non-essential cookie is set.
RELATED REGULATIONS

See what your site sets before anyone asks.

The free plan scans your site, classifies every cookie and generates the policy, without a card. The cookie checker needs no account at all.

Get started free