industry-guides7 min read8 October 2026

Directors Duties Under Singapore Companies Act

How directors' duties under the Singapore Companies Act connect to PDPA compliance. A practical guide for Singapore SME owners on data protection accountability.

ComplyHQ Team

Directors Duties Under Singapore Companies Act

Directors Duties Under Singapore Companies Act

If you sit on the board of a Singapore company, your legal responsibilities now extend well beyond financial statements and shareholder returns — they reach directly into PDPA compliance and how your organisation handles personal data. Under the Singapore Companies Act (Cap. 50), directors owe fiduciary duties and a statutory duty of care, and Singapore's data protection regime has made data governance a clear part of that responsibility. This guide breaks down how directors' duties intersect with the Personal Data Protection Act 2012 (PDPA), and what practical steps your business should take to stay on the right side of both.

TL;DR — Key Takeaways

  • Directors owe a duty of care under Section 157 of the Companies Act that now encompasses oversight of PDPA obligations.
  • The PDPA requires every organisation to appoint a Data Protection Officer (Section 11(3)), apply reasonable security (Section 24), and notify breaches (Part 6A).
  • Since October 2022, PDPC financial penalties can reach S$1 million or 10% of Singapore annual turnover, whichever is higher.
  • Boards reduce exposure through documented policies, training, breach response plans, and regular review — not one-off fixes.
  • Platforms like ComplyHQ deliver AI-powered compliance that handles your PDPA obligations in minutes, not weeks.

How Directors' Duties Connect to PDPA Compliance

Directors' duties under the Singapore Companies Act are not separate from data protection — they are the governance layer that sits above it. Section 157 of the Companies Act requires every director to "act honestly and use reasonable diligence in the discharge of the duties of his office." When your organisation collects, stores, or uses personal data, reasonable diligence now includes ensuring the company meets its PDPA obligations.

The Companies Act imposes two broad categories of duty: fiduciary duties (to act in good faith and in the best interests of the company) and the statutory duty of skill, care and diligence under Section 157. Failure to exercise reasonable care in overseeing compliance — including data protection — can expose a director to claims from the company and scrutiny from regulators.

Definitive statement: A director who ignores known data protection risks, or fails to put any reasonable governance in place, is not discharging the duty of reasonable diligence required by Section 157 of the Singapore Companies Act.

This matters because data breaches are rarely "just an IT problem." The Personal Data Protection Commission (PDPC) has repeatedly emphasised in its enforcement decisions that accountability for personal data rests with the organisation — and the organisation is steered by its board.

What the PDPA Requires: Core Obligations Directors Must Oversee

The PDPA sets out specific, enforceable obligations. Directors do not need to execute each one personally, but they are responsible for ensuring the company has resourced and implemented them. Below are the obligations that most directly intersect with board-level PDPA compliance.

Appoint a Data Protection Officer (Section 11(3))

Every organisation in Singapore must designate at least one individual as a Data Protection Officer (DPO). This is a legal requirement, not a best practice. The DPO's business contact information must be made readily available to the public, and many organisations publish it on their website footer or privacy policy.

Snippet-ready answer: Yes — appointing a DPO is mandatory under Section 11(3) of the PDPA for every organisation in Singapore, regardless of size. Even a sole proprietor or a 3-person startup must designate one.

The DPO can be an existing employee, and smaller businesses often assign the role to an operations or office manager. What directors must ensure is that the DPO is genuinely empowered — with time, authority, and access to the board — rather than a name on paper.

Apply Reasonable Security Arrangements (Section 24)

Section 24 of the PDPA, known as the Protection Obligation, requires organisations to make "reasonable security arrangements" to protect personal data in their possession or control against unauthorised access, collection, use, disclosure, or similar risks. The PDPC's Advisory Guidelines make clear that "reasonable" scales with the sensitivity and volume of data you hold.

For a typical Singapore SME, reasonable arrangements include access controls, encryption of sensitive data, secure disposal, and staff awareness. This is also where PDPA staff training requirements become directly relevant — human error remains the leading cause of breaches the PDPC investigates.

Comply With Mandatory Data Breach Notification (Part 6A)

Since 1 February 2021, data breach notification is mandatory. Under Part 6A of the PDPA, if a breach results in (or is likely to result in) significant harm to affected individuals, or affects 500 or more individuals, you must notify the PDPC within 3 calendar days of assessing it as notifiable, and notify affected individuals as soon as practicable.

Definitive statement: Under the PDPA's Data Breach Notification Obligation, a notifiable breach affecting 500 or more individuals must be reported to the PDPC within 3 calendar days of the organisation determining it is notifiable.

Directors should confirm their organisation has a written breach response plan. Our step-by-step data breach response guide walks through exactly what to do in the first 72 hours.

Director-Level PDPA Compliance: The Penalties at Stake

Understanding the financial exposure helps boards prioritise correctly. The consequences of weak PDPA compliance are no longer trivial, and they are a legitimate matter for directors exercising reasonable diligence.

Following amendments that took effect on 1 October 2022, the PDPC can impose financial penalties of up to S$1 million, or up to 10% of an organisation's annual turnover in Singapore (for organisations with local annual turnover exceeding S$10 million), whichever is higher. This brings Singapore closer to the scale of penalties seen under regimes like the EU GDPR.

Snippet-ready answer: The maximum PDPA financial penalty in Singapore is S$1 million, or 10% of Singapore annual turnover for larger organisations — whichever is higher — in force since October 2022.

Beyond the regulator's fine, directors should weigh three further costs:

  1. Reputational damage — PDPC enforcement decisions are published and frequently reported by outlets such as The Straits Times and CNA.
  2. Civil liability — Section 48O of the PDPA gives individuals a private right of action to sue for loss or damage caused by a contravention.
  3. Operational disruption — remediation, forensic investigation, and lost customer trust often exceed the fine itself.

For directors, the lesson is straightforward: treating data protection as a governance priority is materially cheaper than treating it as an afterthought.

Practical Steps: Building Board-Level Data Protection Governance

Directors fulfil their duty of care not by becoming data protection experts, but by ensuring a reasonable system exists and is reviewed. Here is a practical framework your organisation can adopt.

1. Put Accountability in Writing

Adopt a written data protection policy and a DPO reporting line to the board. The PDPC's Accountability Obligation expects organisations to develop and implement policies and practices — and to be able to demonstrate them. A good starting point is a structured PDPA compliance checklist for Singapore SMEs.

2. Map Your Data

You cannot protect what you cannot see. Maintain a data inventory recording what personal data you collect, why, where it is stored, who can access it, and how long you keep it. This directly supports Section 24 (Protection) and Section 25 (Retention Limitation).

3. Train Your People and Review Regularly

Schedule recurring staff training and an annual board-level review of your data protection posture. Industry-specific risks vary — an e-commerce business, an F&B operator, and an accounting firm each face different exposure, so tailor your controls.

4. Use Tools That Reduce the Burden

Manual compliance is slow and easy to let slip. This is where ComplyHQ helps: it delivers AI-powered compliance that handles your PDPA obligations in minutes, not weeks — generating policies, tracking your obligations, and keeping documentation audit-ready so directors can demonstrate reasonable diligence with confidence. For businesses needing bespoke systems around compliance, Adaptels builds custom digital solutions for Singapore SMEs.

Definitive statement: The most effective way for directors to discharge their Section 157 duty in relation to data is to establish documented, regularly reviewed PDPA governance — not to react only after a breach occurs.

Bringing It Together

Directors' duties under the Singapore Companies Act and your organisation's obligations under the PDPA are two sides of the same coin: both demand reasonable diligence, both are enforceable, and both protect the people your business serves. By appointing an empowered DPO, applying reasonable security, maintaining a breach response plan, and reviewing your posture regularly, your board turns PDPA compliance from a liability into a demonstrable strength. The directors who treat data governance as a core duty — not a box to tick — are the ones best protected when scrutiny comes.

Sources & References

  1. Personal Data Protection Act 2012 — Singapore Statutes Online (AGC)
  2. Companies Act 1967 (Section 157) — Singapore Statutes Online (AGC)
  3. PDPC — Guide to Managing and Notifying Data Breaches
  4. PDPC — Advisory Guidelines on Key Concepts in the PDPA
  5. ACRA — Duties and Responsibilities of Company Directors

Simplify Your Compliance

ComplyHQ's AI can assess your PDPA compliance gaps in under 15 minutes and generate the policies you need.

Try Free Assessment

Frequently Asked Questions

Are company directors personally liable for a PDPA breach in Singapore?
Directors are not automatically personally fined for a company's PDPA breach, but they carry a statutory duty of care under Section 157 of the Companies Act to ensure the company meets its legal obligations, including data protection. Where a director knowingly authorised or neglected to prevent non-compliance, the PDPC and courts can look to individual accountability. In practice, directors are expected to put reasonable data protection governance in place and oversee it.
What does the PDPA require directors to actually do?
The PDPA requires every organisation to appoint a Data Protection Officer (DPO) under Section 11(3), implement reasonable security arrangements under Section 24, and comply with the mandatory Data Breach Notification obligation under Part 6A. Directors should ensure these are resourced, documented, and reviewed. The duty is one of oversight and reasonable care, not day-to-day administration.
How much can a company be fined for PDPA non-compliance?
Since October 2022, the PDPC can impose financial penalties of up to S$1 million, or up to 10% of annual turnover in Singapore for organisations with local turnover exceeding S$10 million — whichever is higher. These penalties sit alongside reputational damage and potential civil claims. Strong board-level governance is the most effective way to reduce this exposure.
Tags:PDPASingapore complianceSMEdata protectionPDPC

Ready to get PDPA compliant?

Stop guessing about compliance. ComplyHQ uses AI to assess your gaps, generate policies, and guide you through every PDPA obligation.

Gap AssessmentPolicy GeneratorAI Compliance Chat
5 October 20267 min read

Intellectual Property Protection for Singapore SMEs

A practical guide to IP protection and PDPA compliance Singapore SMEs need — covering trade secrets, customer data, PDPC obligations and penalties.

Read more
2 October 20267 min read

Corporate Tax Filing Guide for Singapore SMEs (2026)

PDPA compliance Singapore guide for SMEs during corporate tax filing season — protect employee and customer data, avoid PDPC penalties, and file with confidence in 2026.

Read more
14 September 20267 min read

PDPA for Telcos: Customer Data and Billing Records

PDPA compliance Singapore guide for telcos: protect customer data and billing records, meet PDPC obligations, and avoid penalties. Actionable steps for SMEs.

Read more