Subject Access Request (Singapore)
Exercise your personal data access rights under the PDPA 2012
Subject Access Request
SUBJECT ACCESS REQUEST Personal Data Protection Act 2012 (PDPA) Date: [Request Date] To: [Org Name] Attention: [Dp Officer Name] Email: [Org Email] From: [Requester Name] NRIC / FIN / Passport: [Requester N R I C] Email: [Requester Email] Phone: [Requester Phone] Address: [Requester Address]
Request
Dear Data Protection Officer, I am writing to exercise my rights under the Personal Data Protection Act 2012 (PDPA) of Singapore. I am submitting this request in my capacity as a data subject whose personal data is held by [Org Name]. Nature of Request: [Request Type] Description of Personal Data Requested: [Data Requested] Time Period: [Time Period] Correction Details (if applicable): [Correction Details] Preferred Response Format: [Preferred Format] Additional Notes: [Additional Notes]
Statutory Basis
I understand that under the PDPA 2012: 1. ACCESS RIGHT (Section 21): I am entitled to access my personal data held by your organisation and to obtain information about the ways in which my personal data has been or may have been used or disclosed in the 12 months prior to this request. 2. CORRECTION RIGHT (Section 22): I am entitled to request correction of my personal data that is inaccurate or incomplete. 3. DATA PORTABILITY (PDPA Amendment 2021): Where applicable, I am entitled to request that my personal data be transmitted to another organisation in a commonly used machine-readable format. 4. RESPONSE TIMEFRAME: I understand that your organisation must respond to this request within 30 calendar days from the date of this request, or within such extended period as allowed by the Personal Data Protection Commission (PDPC). 5. FEES: I understand that your organisation may charge a reasonable fee for providing access to my personal data. Please advise me of any applicable fee before proceeding. If you refuse any part of this request, please provide written reasons for such refusal in accordance with the PDPA. I reserve the right to lodge a complaint with the PDPC at pdpc.gov.sg if I consider the refusal to be unjustified. Please acknowledge receipt of this request by return email. Yours sincerely, [Requester Name] Date: [Request Date]
Data Subject
________________
Signature
What Is a Subject Access Request (Singapore)?
A Subject Access Request in Singapore puts on record the entitlement or interest the party seeks to protect or relinquish.
Section 21(1) of the PDPA provides that on request, an organisation must provide the individual with: (a) personal data about the individual that is in the possession or under the control of the organisation; and (b) information about the ways in which the personal data has been or may have been used or disclosed by the organisation within a year before the date of the request. The organisation must respond within 30 days of receiving the request under Regulation 4 of the Personal Data Protection Regulations 2014, though this period may be extended if the request is complex or requires consultation with third parties.
The PDPA applies to all organisations in Singapore — private companies, partnerships, sole proprietorships, associations, and bodies corporate — that collect, use, or disclose personal data. Government agencies are subject to separate data protection obligations under the Government Instruction Manual on ICT and Smart Systems Management and the Public Sector (Governance) Act 2018 (Cap. 236A), and access requests to government agencies follow different procedures administered by the respective Ministry or statutory board.
Section 21(2) lists the circumstances under which an organisation may refuse an access request. Permissible grounds for refusal include: where providing the data could threaten the safety or health of the individual or another person; where the data is subject to legal privilege; where providing the data would reveal confidential commercial information; where the data was collected for an investigation or legal proceeding and disclosure would prejudice the investigation; and where the data is subject to a statutory prohibition on disclosure. The PDPC has issued advisory guidelines on the Access Obligation explaining how organisations should assess refusal grounds.
The PDPC maintains a complaint and enforcement mechanism for individuals whose access requests are denied or inadequately responded to. Section 28 of the PDPA empowers the PDPC to investigate complaints, conduct reviews, and issue directions to organisations found in breach of the Access Obligation. The PDPC may impose financial penalties of up to S$1 million under Section 29 (or up to 10% of annual turnover in Singapore for organisations with turnover exceeding S$10 million, following the 2021 amendments). Notable enforcement decisions by the PDPC have addressed organisations that failed to respond to access requests within the 30-day deadline, provided incomplete responses, or imposed unreasonable fees.
Organisations may charge a reasonable fee for processing an access request under Section 21(4) of the PDPA. The fee must not be excessive and must reflect the actual cost of providing the information. The PDPC advisory guidelines suggest that organisations should not use fees as a deterrent to the exercise of access rights, and any fee schedule should be transparent and communicated to the requester before processing.
When Do You Need a Subject Access Request (Singapore)?
A Subject Access Request under the Personal Data Protection Act 2012 (PDPA) in Singapore is needed whenever an individual wishes to find out what personal data an organisation holds about them and how that data has been used or disclosed. Section 21 of the PDPA grants this right to all individuals — Singapore citizens, permanent residents, and foreign nationals — whose personal data is processed by organisations in Singapore.
Employees and former employees who wish to obtain copies of their personnel records, performance evaluations, disciplinary records, or medical examination results held by their employer may submit a Subject Access Request. The Ministry of Manpower (MOM) recognises that employment records constitute personal data under the PDPA, and employers must respond within 30 days. The Employment Act 1968 (Cap. 91) does not provide a separate data access right, making the PDPA the primary mechanism for employee data access.
Individuals who suspect that their personal data has been misused — for example, receiving unsolicited marketing communications, discovering unauthorised credit checks, or finding their data on websites or directories without consent — should submit a Subject Access Request to identify what data the organisation holds and how it was obtained. The request provides the factual basis for a subsequent complaint to the Personal Data Protection Commission (PDPC) if misuse is confirmed.
Patients who wish to obtain copies of their medical records from hospitals, clinics, and healthcare providers regulated by the Ministry of Health (MOH) may exercise their access rights under the PDPA. The Singapore Medical Council's (SMC) Ethical Code and Ethical Guidelines also support patient access to medical records, and healthcare providers must respond within the 30-day PDPA timeframe.
Consumers who have provided personal data to businesses — banks regulated by the Monetary Authority of Singapore (MAS), telecommunications companies regulated by IMDA, insurance companies, retailers, and online platforms — may request access to their stored personal data, transaction histories, and marketing consent records. Financial institutions must balance PDPA access obligations with banking secrecy provisions under the Banking Act (Cap. 19), and may refuse access to data protected by legal privilege or commercial confidentiality.
Individuals involved in legal disputes who need to obtain their personal data from an opposing party or third-party organisation may submit a Subject Access Request as a data-gathering mechanism complementary to formal court discovery procedures under the Rules of Court 2021 (S 914/2021). The access request provides a faster and less costly initial means of obtaining relevant personal data.
Parents or legal guardians who wish to access personal data held about their minor children — by schools under the Ministry of Education (MOE), enrichment centres, healthcare providers, or online platforms — may submit access requests on behalf of the child, subject to the PDPC's advisory guidelines on data access requests by parents and guardians.
What to Include in Your Subject Access Request (Singapore)
A Subject Access Request under the Personal Data Protection Act 2012 (PDPA) in Singapore must contain specific information to enable the organisation to identify the requester, locate the relevant personal data, and respond within the statutory timeframe. The PDPC advisory guidelines recommend a structured request format to minimise delays and support accurate responses.
The requester's identification section must state the requester's full legal name, NRIC or passport number (to verify identity and locate records), residential address, contact telephone number, and email address. The organisation may require identity verification before processing the request — the PDPC permits organisations to request reasonable proof of identity to prevent unauthorised disclosure of personal data to third parties. For requests made on behalf of another person (such as a parent requesting a child's data, or a solicitor acting for a client), the authority to make the request — such as a letter of authorisation, power of attorney, or evidence of legal guardianship — must be provided.
The organisation details section identifies the organisation to which the request is directed — by registered name, Unique Entity Number (UEN) with the Accounting and Corporate Regulatory Authority (ACRA), address, and the department or data protection officer (DPO) to whom the request should be addressed. Section 11(3) of the PDPA requires organisations to designate at least one individual as a data protection officer responsible for confirming PDPA compliance, and access requests should be directed to the DPO where possible.
The data specification section describes the personal data the requester wishes to access. While the requester is not required to identify the exact data fields, providing sufficient detail helps the organisation locate the relevant records efficiently. The PDPC recommends specifying: the type of personal data sought (e.g., contact details, transaction records, medical records, employment records, marketing consent records); the time period for which data is sought; and any specific systems, departments, or contexts in which the data was collected (e.g., data provided during a specific transaction, application, or interaction). Broad requests covering all personal data held by the organisation are permitted under Section 21(1) but may take longer to process and incur higher fees.
The usage and disclosure information request, under Section 21(1)(b), asks the organisation to provide information about how the requester's personal data has been used or disclosed within the preceding year — including the purposes of use, the categories of recipients to whom data was disclosed, and whether data was transferred outside Singapore. Cross-border data transfers are subject to the PDPA's transfer limitation obligations under Section 26, and the requester may ask specifically about overseas transfers.
The preferred response format section specifies how the requester wishes to receive the information — electronic copy (email, secure portal), physical copy (posted to the residential address), or inspection at the organisation's premises. The PDPC advisory guidelines state that organisations should provide data in a reasonable format and should not unreasonably restrict the requester's choice.
The fee acknowledgment section addresses the organisation's right to charge a reasonable fee under Section 21(4) of the PDPA. The PDPC expects organisations to communicate the fee (if any) before processing and to waive or reduce fees where the request is simple. The fee must reflect actual processing costs and must not be used to discourage access requests. Forms-legal.com provides the Subject Access Request template with all required fields for PDPA-compliant requests to Singapore organisations.
Cite this page
Reference this free template in an article, syllabus, or research note:
Forms Legal. (2026). Subject Access Request (Singapore) (Singapore) [Legal document template]. Forms Legal. https://forms-legal.com/singapore/government/declarations/subject-access-request-singapore
"Subject Access Request (Singapore) (Singapore)." Forms Legal, 2026, https://forms-legal.com/singapore/government/declarations/subject-access-request-singapore.
@misc{formslegal-subject-access-request-singapore,
author = {{Forms Legal}},
title = {Subject Access Request (Singapore) (Singapore)},
year = {2026},
howpublished = {\url{https://forms-legal.com/singapore/government/declarations/subject-access-request-singapore}},
note = {Free legal document template. Based on Government Proceedings Act (Cap. 121)}
}Also available for these jurisdictions:
Frequently Asked Questions
An organisation in Singapore must respond to a Subject Access Request within 30 days of receiving the request, as prescribed by Regulation 4 of the Personal Data Protection Regulations 2014, issued under the Personal Data Protection Act 2012 (PDPA). The 30-day period begins from the date the organisation receives a request that contains sufficient information to identify the requester and locate the relevant personal data. If the organisation requires identity verification or additional information to process the request, the 30-day period begins from the date the verification or information is received. For complex requests involving large volumes of data, consultations with third parties, or data held across multiple systems, the organisation may extend the response period — but must inform the requester of the extension and the reasons before the original 30-day deadline expires. The Personal Data Protection Commission (PDPC) has issued enforcement decisions against organisations that failed to respond within the 30-day timeframe, and persistent non-compliance may result in directions to comply and financial penalties under Section 29 of the PDPA. If the organisation refuses the request (on grounds permitted by Section 21(2)), it must notify the requester of the refusal and the reasons within the same 30-day period.
An organisation in Singapore may charge a reasonable fee for processing a Subject Access Request under Section 21(4) of the Personal Data Protection Act 2012 (PDPA). The fee must reflect the actual cost of processing the request — including staff time to locate and compile the data, costs of reproducing documents, and postage or electronic transmission costs — and must not be excessive or used as a deterrent to discourage individuals from exercising their access rights. The Personal Data Protection Commission (PDPC) advisory guidelines on the Access Obligation state that organisations should communicate the fee to the requester before processing the request, allowing the requester to decide whether to proceed, narrow the scope of the request, or withdraw. The PDPC has indicated that many routine access requests should be processed at no charge, particularly for simple requests involving readily accessible data. Organisations that charge unreasonable fees may face complaints to the PDPC, which has the power to direct the organisation to reduce or waive the fee. For comparison, some organisations publish fee schedules on their websites or in their data protection policies, providing transparency on access request costs. Healthcare providers, financial institutions regulated by the Monetary Authority of Singapore (MAS), and telecommunications companies regulated by IMDA commonly handle access requests and may have published fee structures.
An individual exercising their access right under Section 21(1) of the Personal Data Protection Act 2012 (PDPA) in Singapore can request access to all personal data about them that is in the possession or under the control of the organisation, as well as information about how that data has been used or disclosed within the preceding year. Personal data is defined broadly in Section 2 of the PDPA as data about an individual who can be identified from that data, or from that data combined with other information to which the organisation has or is likely to have access. Common categories of personal data that individuals may access include: identity information (name, NRIC, passport, date of birth, nationality), contact details (address, phone number, email), employment records (salary, performance reviews, disciplinary records, leave records), financial records (account details, transaction history, credit assessments), medical records (diagnoses, prescriptions, test results, treatment history), marketing and consent records (consent given or withdrawn for marketing communications), CCTV footage (where the individual is identifiable), and online activity data (browsing history, purchase history, app usage data). The organisation must also provide information about the purposes for which the data was used and the organisations to which it was disclosed.
A Subject Access Request under the Personal Data Protection Act 2012 (PDPA) in Singapore can be made on behalf of another person in specific circumstances recognised by the Personal Data Protection Commission (PDPC). Parents or legal guardians may submit access requests on behalf of minor children (under 18 years of age), as the PDPC recognises that minors may not have the capacity to exercise their data protection rights independently. The parent or guardian must provide evidence of their relationship — such as a birth certificate, court custody order, or legal guardianship documentation — and the organisation may verify the relationship before processing. Attorneys acting under a valid Power of Attorney (under the Powers of Attorney Act 1998, Cap. 240) may submit access requests on behalf of the donor (principal), provided the power of attorney specifically authorises the attorney to access personal data or to act on the donor's behalf in data protection matters. Solicitors acting on behalf of clients may submit access requests with a letter of authorisation signed by the client. Donees of a Lasting Power of Attorney (LPA) registered with the Office of the Public Guardian (OPG) under the Mental Capacity Act 2008 (Cap. 177A) may act on behalf of a donor who has lost mental capacity. In all cases, the organisation must satisfy itself that the person making the request is authorised to receive the data, as disclosing personal data to an unauthorised third party would itself constitute a PDPA breach.
If an organisation in Singapore refuses a Subject Access Request or fails to respond within the 30-day timeframe prescribed by the Personal Data Protection Regulations 2014, the individual has several remedies under the Personal Data Protection Act 2012 (PDPA). First, the individual should request a written explanation from the organisation stating the specific grounds for refusal under Section 21(2) of the PDPA — the organisation must identify which statutory exception applies (legal privilege, commercial confidentiality, safety concerns, investigation purposes, or statutory prohibition). Second, if the individual believes the refusal is unjustified, they may file a complaint with the Personal Data Protection Commission (PDPC) through the PDPC's online complaint portal. The PDPC investigates complaints, may conduct reviews of the organisation's data protection practices, and has the power to issue directions requiring the organisation to comply with the access request under Section 28. Third, the PDPC may impose financial penalties on organisations found in breach of the Access Obligation — up to S$1 million under Section 29, or up to 10% of annual turnover in Singapore for organisations with annual turnover exceeding S$10 million (following the 2021 amendments). Fourth, the individual may seek legal advice from a solicitor specialising in data protection law and consider commencing civil proceedings for breach of the PDPA. The PDPC publishes enforcement decisions on its website, providing guidance on how access obligation breaches have been adjudicated in previous cases.
This template is provided for informational purposes only and does not constitute legal advice. Laws vary by jurisdiction and change over time. Consult a qualified attorney for advice specific to your situation.Full disclaimer
Found an error? Let us knowRelated Documents
You may also find these documents useful:
ACRA Annual Return (Singapore)
A support document for filing a company's annual return with the Accounting and Corporate Regulatory Authority (ACRA) under the Companies Act 1967. Ensures compliance with mandatory annual filing requirements for Singapore-incorporated companies.
ACRA BizFile+ Company Incorporation Form (Singapore)
A support document for incorporating a private limited company in Singapore through ACRA's BizFile+ portal under section 17 of the Companies Act 1967. Covers company name, directors, shareholders, registered address, and share capital details.
ACRA Change of Address Filing (Singapore)
A notification filing for a change in a Singapore company's registered office address under the Companies Act 1967. Must be lodged with ACRA within 14 days of the change through BizFile+.
ACRA Change of Directors Filing (Singapore)
A notification filing for the appointment or resignation of a director in a Singapore company under the Companies Act 1967. Must be lodged with ACRA within 14 days of the change through BizFile+.
ACRA Striking Off Application Support (Singapore)
A support document for applying to strike off a defunct Singapore company from the register under section 344 of the Companies Act 1967. Covers eligibility criteria, director declarations, outstanding liabilities, and IRAS clearance requirements.