Business Contact Information Under PDPA: What You Can Use Freely
A clear guide to business contact information under Singapore's PDPA — what your business can collect, use and disclose without consent, plus the DNC traps to avoid.

Business Contact Information Under PDPA: What You Can Use Freely
Business contact information is one of the most misunderstood concepts in Singapore's Personal Data Protection Act (PDPA) — and getting it right can save your organisation from unnecessary consent workflows while keeping you compliant. In short: information such as a person's name, job title, business email and business phone number, when collected in a business context, is largely exempt from the core data protection obligations. This guide explains exactly what your business can use freely, where the exemption ends, and the Do Not Call traps that still catch many Singapore SMEs.
TL;DR — Key Takeaways
- Business contact information (BCI) is defined in section 2(1) of the PDPA and is exempt from the Data Protection Provisions (Parts 3 to 6A) under section 4(5).
- You do not need consent to collect, use or disclose BCI — name cards, work emails and business phone numbers are fair game for legitimate business use.
- The exemption applies only when the information was not provided solely for the individual's personal purposes.
- The Do Not Call (DNC) provisions in Part 9 still apply to telemarketing sent to Singapore phone numbers — even business ones.
- Penalties for PDPA breaches can reach up to S$1 million or 10% of annual turnover in Singapore, whichever is higher.
What Is Business Contact Information Under the PDPA?
Business contact information is data an individual provides in a business or professional capacity — not for personal reasons. Section 2(1) of the PDPA defines it as an individual's name, position name or title, business telephone number, business address, business email address or business fax number, and any other similar information, that is not provided by the individual solely for his or her personal purposes.
The definition is deliberately broad but hinges on one test: purpose of provision. When a supplier hands you a name card at a trade show, or a client emails you from their corporate address, that information is business contact information. When someone gives you their personal mobile number to receive family photos, it is personal data.
Definitive statement your business can rely on: If contact details were shared in a professional context to facilitate business dealings, they qualify as business contact information and sit outside the PDPA's consent, notification and purpose limitation obligations.
Common examples of business contact information include:
- A name card collected at a networking event or conference
- A supplier's contact details on a quotation or invoice
- A LinkedIn profile listing a work email and job title
- A "Contact Us" enquiry sent from a corporate email address
- An employee's work desk phone number listed in a company directory
Why Business Contact Information Is Exempt From Consent
The reason business contact information sits outside most PDPA obligations is deliberate: commerce would grind to a halt if every B2B email required documented consent. Section 4(5) of the PDPA states that Parts 3, 4, 5, 6 and 6A do not impose any obligation on an organisation in respect of business contact information. In plain terms, the consent, purpose limitation, notification, access and correction, and data breach notification obligations do not apply to BCI.
Here is what that means in practice for your organisation:
| Obligation (PDPA Part) | Applies to business contact information? |
|---|---|
| Consent Obligation (Part 4) | ❌ No |
| Purpose Limitation (Part 4) | ❌ No |
| Notification Obligation (Part 4) | ❌ No |
| Access & Correction (Part 5) | ❌ No |
| Data Breach Notification (Part 6A) | ❌ No |
A quote-ready fact: Because of section 4(5), your business can add a name card to your CRM, forward a colleague's work email to a partner, or build a B2B prospect list from corporate directories — all without obtaining consent under the PDPA.
That said, the exemption is not a licence to ignore good data governance. The PDPC's Advisory Guidelines on Key Concepts in the PDPA make clear that the exemption is scoped narrowly to the information itself, not to any personal data that happens to travel alongside it. If you also hold a contact's personal home address or personal mobile, those elements remain personal data.
Where the Business Contact Information Exemption Ends
The single biggest mistake Singapore SMEs make is assuming that "B2B means no rules". The exemption is narrower than it looks, and three limits deserve close attention.
1. The "solely for personal purposes" test
The exemption evaporates the moment information was provided solely for personal purposes. If a self-employed hawker gives you their mobile number to receive a personal delivery, that number is personal data even though the person runs a business. The question is always why the individual shared it, not what the individual does for a living.
2. Marketing calls and messages still trigger the Do Not Call rules
Here is the trap. The Data Protection Provisions do not apply to business contact information — but the Do Not Call (DNC) provisions in Part 9 of the PDPA are separate. Before sending a marketing (telemarketing) message or making a marketing voice call to a Singapore telephone number, your business must check the number against the DNC Registry, unless an exemption applies (such as an ongoing relationship exemption with clear opt-out). This obligation applies to Singapore phone numbers regardless of whether the number is "business" or "personal".
Definitive statement: The business contact information exemption covers the data protection rules, but it does not exempt your marketing calls or texts to Singapore phone numbers from the DNC Registry checking requirement.
3. Personal data mixed in with business data
If your database links a work email to a person's dietary preferences, health information, or home address, only the business contact information elements are exempt. The rest is personal data subject to full PDPA obligations, including the Protection Obligation to secure it with reasonable security arrangements.
Practical Steps: Using Business Contact Information Compliantly
Snippet summary: To use business contact information safely, classify your data correctly, keep B2B and B2C databases separate where possible, and layer DNC screening on top of your marketing workflows. These three habits keep your organisation on the right side of both the PDPA and the DNC rules.
Follow these actionable steps:
- Classify at the point of collection. Tag whether contact details were provided in a business or personal capacity. A simple field in your CRM ("source: business / personal") prevents costly misjudgements later.
- Separate marketing lists from contact records. Just because you can store business contact information without consent does not mean you can market to it freely. Maintain a distinct, DNC-screened list for outbound telemarketing.
- Screen Singapore numbers against the DNC Registry. Subscribe to the DNC checking service and log every check. Keep records for at least the period the PDPC recommends to demonstrate due diligence.
- Secure everything anyway. Even exempt data lives in systems that also hold personal data. Apply reasonable security arrangements — access controls, encryption, and staff awareness — across the board.
- Train your team. Front-line staff who collect name cards and enquiries need to understand the distinction. See our guide on PDPA staff training requirements for building a data protection culture.
This is precisely the kind of classification and screening that trips up busy SME owners. ComplyHQ offers AI-powered compliance that handles your PDPA obligations in minutes, not weeks — mapping which data is exempt, flagging DNC risks, and generating the policies the PDPC expects to see. If your compliance stack needs custom integration work, the team at Adaptels builds tailored digital solutions for Singapore SMEs.
What Happens If You Get It Wrong?
Snippet summary: Misclassifying personal data as business contact information — or ignoring the DNC rules — can expose your organisation to significant financial penalties. Since October 2022, the PDPC can impose penalties of up to S$1 million, or 10% of an organisation's annual turnover in Singapore (whichever is higher) for turnover above S$10 million.
The PDPC has consistently taken enforcement action where organisations treated personal data too loosely. Marketing messages sent to numbers on the DNC Registry, and failures to protect databases, have both attracted financial penalties and directions. The lesson for your organisation: the business contact information exemption is a genuine convenience, but overreaching it converts a compliant workflow into an enforcement risk.
To understand how these rules play out in real disputes, review our breakdown of PDPA penalties and enforcement cases. And if you are still building your foundations, the PDPA compliance checklist for Singapore SMEs walks through every obligation step by step. Businesses handling large volumes of enquiries — such as e-commerce operators — should pay particular attention to keeping business and personal data streams distinct.
Key Takeaways for Your Organisation
- Business contact information collected in a business context is exempt from the PDPA's consent, notification and other Data Protection Provisions under section 4(5).
- The exemption fails if information was provided solely for personal purposes — always assess the reason for provision.
- Do Not Call rules are separate — screen Singapore phone numbers before any marketing outreach.
- Secure all data and train staff, because exempt data rarely lives in isolation.
- When the classification gets complex, automate it rather than guessing.
Getting business contact information right lets your organisation move faster in B2B dealings while staying firmly compliant — the best of both worlds when you understand exactly where the line sits.
Sources & References
Simplify Your Compliance
ComplyHQ's AI can assess your PDPA compliance gaps in under 15 minutes and generate the policies you need.
Try Free AssessmentFrequently Asked Questions
Do I need consent to email someone using their work email address?
Is a name card (business card) covered by PDPA consent rules?
Does the business contact information exemption cover personal mobile numbers?
Ready to get PDPA compliant?
Stop guessing about compliance. ComplyHQ uses AI to assess your gaps, generate policies, and guide you through every PDPA obligation.