Directors Duties Under Singapore Companies Act
How directors' duties under the Singapore Companies Act connect to PDPA compliance. A practical guide for Singapore SME owners on data protection accountability.

Directors Duties Under Singapore Companies Act
If you sit on the board of a Singapore company, your legal responsibilities now extend well beyond financial statements and shareholder returns — they reach directly into PDPA compliance and how your organisation handles personal data. Under the Singapore Companies Act (Cap. 50), directors owe fiduciary duties and a statutory duty of care, and Singapore's data protection regime has made data governance a clear part of that responsibility. This guide breaks down how directors' duties intersect with the Personal Data Protection Act 2012 (PDPA), and what practical steps your business should take to stay on the right side of both.
TL;DR — Key Takeaways
- Directors owe a duty of care under Section 157 of the Companies Act that now encompasses oversight of PDPA obligations.
- The PDPA requires every organisation to appoint a Data Protection Officer (Section 11(3)), apply reasonable security (Section 24), and notify breaches (Part 6A).
- Since October 2022, PDPC financial penalties can reach S$1 million or 10% of Singapore annual turnover, whichever is higher.
- Boards reduce exposure through documented policies, training, breach response plans, and regular review — not one-off fixes.
- Platforms like ComplyHQ deliver AI-powered compliance that handles your PDPA obligations in minutes, not weeks.
How Directors' Duties Connect to PDPA Compliance
Directors' duties under the Singapore Companies Act are not separate from data protection — they are the governance layer that sits above it. Section 157 of the Companies Act requires every director to "act honestly and use reasonable diligence in the discharge of the duties of his office." When your organisation collects, stores, or uses personal data, reasonable diligence now includes ensuring the company meets its PDPA obligations.
The Companies Act imposes two broad categories of duty: fiduciary duties (to act in good faith and in the best interests of the company) and the statutory duty of skill, care and diligence under Section 157. Failure to exercise reasonable care in overseeing compliance — including data protection — can expose a director to claims from the company and scrutiny from regulators.
Definitive statement: A director who ignores known data protection risks, or fails to put any reasonable governance in place, is not discharging the duty of reasonable diligence required by Section 157 of the Singapore Companies Act.
This matters because data breaches are rarely "just an IT problem." The Personal Data Protection Commission (PDPC) has repeatedly emphasised in its enforcement decisions that accountability for personal data rests with the organisation — and the organisation is steered by its board.
What the PDPA Requires: Core Obligations Directors Must Oversee
The PDPA sets out specific, enforceable obligations. Directors do not need to execute each one personally, but they are responsible for ensuring the company has resourced and implemented them. Below are the obligations that most directly intersect with board-level PDPA compliance.
Appoint a Data Protection Officer (Section 11(3))
Every organisation in Singapore must designate at least one individual as a Data Protection Officer (DPO). This is a legal requirement, not a best practice. The DPO's business contact information must be made readily available to the public, and many organisations publish it on their website footer or privacy policy.
Snippet-ready answer: Yes — appointing a DPO is mandatory under Section 11(3) of the PDPA for every organisation in Singapore, regardless of size. Even a sole proprietor or a 3-person startup must designate one.
The DPO can be an existing employee, and smaller businesses often assign the role to an operations or office manager. What directors must ensure is that the DPO is genuinely empowered — with time, authority, and access to the board — rather than a name on paper.
Apply Reasonable Security Arrangements (Section 24)
Section 24 of the PDPA, known as the Protection Obligation, requires organisations to make "reasonable security arrangements" to protect personal data in their possession or control against unauthorised access, collection, use, disclosure, or similar risks. The PDPC's Advisory Guidelines make clear that "reasonable" scales with the sensitivity and volume of data you hold.
For a typical Singapore SME, reasonable arrangements include access controls, encryption of sensitive data, secure disposal, and staff awareness. This is also where PDPA staff training requirements become directly relevant — human error remains the leading cause of breaches the PDPC investigates.
Comply With Mandatory Data Breach Notification (Part 6A)
Since 1 February 2021, data breach notification is mandatory. Under Part 6A of the PDPA, if a breach results in (or is likely to result in) significant harm to affected individuals, or affects 500 or more individuals, you must notify the PDPC within 3 calendar days of assessing it as notifiable, and notify affected individuals as soon as practicable.
Definitive statement: Under the PDPA's Data Breach Notification Obligation, a notifiable breach affecting 500 or more individuals must be reported to the PDPC within 3 calendar days of the organisation determining it is notifiable.
Directors should confirm their organisation has a written breach response plan. Our step-by-step data breach response guide walks through exactly what to do in the first 72 hours.
Director-Level PDPA Compliance: The Penalties at Stake
Understanding the financial exposure helps boards prioritise correctly. The consequences of weak PDPA compliance are no longer trivial, and they are a legitimate matter for directors exercising reasonable diligence.
Following amendments that took effect on 1 October 2022, the PDPC can impose financial penalties of up to S$1 million, or up to 10% of an organisation's annual turnover in Singapore (for organisations with local annual turnover exceeding S$10 million), whichever is higher. This brings Singapore closer to the scale of penalties seen under regimes like the EU GDPR.
Snippet-ready answer: The maximum PDPA financial penalty in Singapore is S$1 million, or 10% of Singapore annual turnover for larger organisations — whichever is higher — in force since October 2022.
Beyond the regulator's fine, directors should weigh three further costs:
- Reputational damage — PDPC enforcement decisions are published and frequently reported by outlets such as The Straits Times and CNA.
- Civil liability — Section 48O of the PDPA gives individuals a private right of action to sue for loss or damage caused by a contravention.
- Operational disruption — remediation, forensic investigation, and lost customer trust often exceed the fine itself.
For directors, the lesson is straightforward: treating data protection as a governance priority is materially cheaper than treating it as an afterthought.
Practical Steps: Building Board-Level Data Protection Governance
Directors fulfil their duty of care not by becoming data protection experts, but by ensuring a reasonable system exists and is reviewed. Here is a practical framework your organisation can adopt.
1. Put Accountability in Writing
Adopt a written data protection policy and a DPO reporting line to the board. The PDPC's Accountability Obligation expects organisations to develop and implement policies and practices — and to be able to demonstrate them. A good starting point is a structured PDPA compliance checklist for Singapore SMEs.
2. Map Your Data
You cannot protect what you cannot see. Maintain a data inventory recording what personal data you collect, why, where it is stored, who can access it, and how long you keep it. This directly supports Section 24 (Protection) and Section 25 (Retention Limitation).
3. Train Your People and Review Regularly
Schedule recurring staff training and an annual board-level review of your data protection posture. Industry-specific risks vary — an e-commerce business, an F&B operator, and an accounting firm each face different exposure, so tailor your controls.
4. Use Tools That Reduce the Burden
Manual compliance is slow and easy to let slip. This is where ComplyHQ helps: it delivers AI-powered compliance that handles your PDPA obligations in minutes, not weeks — generating policies, tracking your obligations, and keeping documentation audit-ready so directors can demonstrate reasonable diligence with confidence. For businesses needing bespoke systems around compliance, Adaptels builds custom digital solutions for Singapore SMEs.
Definitive statement: The most effective way for directors to discharge their Section 157 duty in relation to data is to establish documented, regularly reviewed PDPA governance — not to react only after a breach occurs.
Bringing It Together
Directors' duties under the Singapore Companies Act and your organisation's obligations under the PDPA are two sides of the same coin: both demand reasonable diligence, both are enforceable, and both protect the people your business serves. By appointing an empowered DPO, applying reasonable security, maintaining a breach response plan, and reviewing your posture regularly, your board turns PDPA compliance from a liability into a demonstrable strength. The directors who treat data governance as a core duty — not a box to tick — are the ones best protected when scrutiny comes.
Sources & References
Simplify Your Compliance
ComplyHQ's AI can assess your PDPA compliance gaps in under 15 minutes and generate the policies you need.
Try Free AssessmentFrequently Asked Questions
Are company directors personally liable for a PDPA breach in Singapore?
What does the PDPA require directors to actually do?
How much can a company be fined for PDPA non-compliance?
Ready to get PDPA compliant?
Stop guessing about compliance. ComplyHQ uses AI to assess your gaps, generate policies, and guide you through every PDPA obligation.