Legal obligation
Data Protection Officer appointment
Data Protection Officer appointment — legal obligation, Singapore. It binds organisations subject to the Personal Data Protection Act 2012.
- Jurisdiction
- Singapore
- Record class
- Legal obligation
- Instrument
- Reporting
- Last verified
Where this applies
This record is scoped to Singapore. Scope is part of the claim: a rule that binds one part of a country does not bind the whole of it, and this library states the scope its sources state.
Instrument
Personal Data Protection Act 2012, s. 11(3)
Who it binds
Organisations subject to the Personal Data Protection Act 2012
What it requires
PDPA s. 11(3), opened and read directly at sso.agc.gov.sg, requires an organisation to "designate one or more individuals to be responsible for ensuring that the organisation complies with this Act" — a Data Protection Officer. The Personal Data Protection Commission (PDPC) states a DPO's business contact information must be made publicly available. Appointment is a distinct legal duty from any separate PDPC notification/registration channel.
Route to the authority
Further sources cited on this page
Last verified:
Related records and requirements
- Data Protection Officer appointment threshold (Germany) — Germany's BDSG §38 requires appointing a Data Protection Officer once an organisation generally employs at least 20 people continuously engaged in automated personal-data processing — a German-specific addition on top of GDPR.
- Act Respecting the Protection of Personal Information in the Private Sector (Québec) (Canada) — Québec's law requires designating a person in charge of the protection of personal information — by default the business's highest authority, delegable in writing.
This page is for information only; it is not legal advice, and it does not establish whether this record applies to your business. Verify current status through the official source above.