pdpa-compliance7 min read16 September 2026

Business Contact Information Under PDPA: What You Can Use Freely

A clear guide to business contact information under Singapore's PDPA — what your business can collect, use and disclose without consent, plus the DNC traps to avoid.

ComplyHQ Team

Business Contact Information Under PDPA: What You Can Use Freely

Business Contact Information Under PDPA: What You Can Use Freely

Business contact information is one of the most misunderstood concepts in Singapore's Personal Data Protection Act (PDPA) — and getting it right can save your organisation from unnecessary consent workflows while keeping you compliant. In short: information such as a person's name, job title, business email and business phone number, when collected in a business context, is largely exempt from the core data protection obligations. This guide explains exactly what your business can use freely, where the exemption ends, and the Do Not Call traps that still catch many Singapore SMEs.

TL;DR — Key Takeaways

  • Business contact information (BCI) is defined in section 2(1) of the PDPA and is exempt from the Data Protection Provisions (Parts 3 to 6A) under section 4(5).
  • You do not need consent to collect, use or disclose BCI — name cards, work emails and business phone numbers are fair game for legitimate business use.
  • The exemption applies only when the information was not provided solely for the individual's personal purposes.
  • The Do Not Call (DNC) provisions in Part 9 still apply to telemarketing sent to Singapore phone numbers — even business ones.
  • Penalties for PDPA breaches can reach up to S$1 million or 10% of annual turnover in Singapore, whichever is higher.

What Is Business Contact Information Under the PDPA?

Business contact information is data an individual provides in a business or professional capacity — not for personal reasons. Section 2(1) of the PDPA defines it as an individual's name, position name or title, business telephone number, business address, business email address or business fax number, and any other similar information, that is not provided by the individual solely for his or her personal purposes.

The definition is deliberately broad but hinges on one test: purpose of provision. When a supplier hands you a name card at a trade show, or a client emails you from their corporate address, that information is business contact information. When someone gives you their personal mobile number to receive family photos, it is personal data.

Definitive statement your business can rely on: If contact details were shared in a professional context to facilitate business dealings, they qualify as business contact information and sit outside the PDPA's consent, notification and purpose limitation obligations.

Common examples of business contact information include:

  • A name card collected at a networking event or conference
  • A supplier's contact details on a quotation or invoice
  • A LinkedIn profile listing a work email and job title
  • A "Contact Us" enquiry sent from a corporate email address
  • An employee's work desk phone number listed in a company directory

The reason business contact information sits outside most PDPA obligations is deliberate: commerce would grind to a halt if every B2B email required documented consent. Section 4(5) of the PDPA states that Parts 3, 4, 5, 6 and 6A do not impose any obligation on an organisation in respect of business contact information. In plain terms, the consent, purpose limitation, notification, access and correction, and data breach notification obligations do not apply to BCI.

Here is what that means in practice for your organisation:

Obligation (PDPA Part)Applies to business contact information?
Consent Obligation (Part 4)❌ No
Purpose Limitation (Part 4)❌ No
Notification Obligation (Part 4)❌ No
Access & Correction (Part 5)❌ No
Data Breach Notification (Part 6A)❌ No

A quote-ready fact: Because of section 4(5), your business can add a name card to your CRM, forward a colleague's work email to a partner, or build a B2B prospect list from corporate directories — all without obtaining consent under the PDPA.

That said, the exemption is not a licence to ignore good data governance. The PDPC's Advisory Guidelines on Key Concepts in the PDPA make clear that the exemption is scoped narrowly to the information itself, not to any personal data that happens to travel alongside it. If you also hold a contact's personal home address or personal mobile, those elements remain personal data.


Where the Business Contact Information Exemption Ends

The single biggest mistake Singapore SMEs make is assuming that "B2B means no rules". The exemption is narrower than it looks, and three limits deserve close attention.

1. The "solely for personal purposes" test

The exemption evaporates the moment information was provided solely for personal purposes. If a self-employed hawker gives you their mobile number to receive a personal delivery, that number is personal data even though the person runs a business. The question is always why the individual shared it, not what the individual does for a living.

2. Marketing calls and messages still trigger the Do Not Call rules

Here is the trap. The Data Protection Provisions do not apply to business contact information — but the Do Not Call (DNC) provisions in Part 9 of the PDPA are separate. Before sending a marketing (telemarketing) message or making a marketing voice call to a Singapore telephone number, your business must check the number against the DNC Registry, unless an exemption applies (such as an ongoing relationship exemption with clear opt-out). This obligation applies to Singapore phone numbers regardless of whether the number is "business" or "personal".

Definitive statement: The business contact information exemption covers the data protection rules, but it does not exempt your marketing calls or texts to Singapore phone numbers from the DNC Registry checking requirement.

3. Personal data mixed in with business data

If your database links a work email to a person's dietary preferences, health information, or home address, only the business contact information elements are exempt. The rest is personal data subject to full PDPA obligations, including the Protection Obligation to secure it with reasonable security arrangements.


Practical Steps: Using Business Contact Information Compliantly

Snippet summary: To use business contact information safely, classify your data correctly, keep B2B and B2C databases separate where possible, and layer DNC screening on top of your marketing workflows. These three habits keep your organisation on the right side of both the PDPA and the DNC rules.

Follow these actionable steps:

  1. Classify at the point of collection. Tag whether contact details were provided in a business or personal capacity. A simple field in your CRM ("source: business / personal") prevents costly misjudgements later.
  2. Separate marketing lists from contact records. Just because you can store business contact information without consent does not mean you can market to it freely. Maintain a distinct, DNC-screened list for outbound telemarketing.
  3. Screen Singapore numbers against the DNC Registry. Subscribe to the DNC checking service and log every check. Keep records for at least the period the PDPC recommends to demonstrate due diligence.
  4. Secure everything anyway. Even exempt data lives in systems that also hold personal data. Apply reasonable security arrangements — access controls, encryption, and staff awareness — across the board.
  5. Train your team. Front-line staff who collect name cards and enquiries need to understand the distinction. See our guide on PDPA staff training requirements for building a data protection culture.

This is precisely the kind of classification and screening that trips up busy SME owners. ComplyHQ offers AI-powered compliance that handles your PDPA obligations in minutes, not weeks — mapping which data is exempt, flagging DNC risks, and generating the policies the PDPC expects to see. If your compliance stack needs custom integration work, the team at Adaptels builds tailored digital solutions for Singapore SMEs.


What Happens If You Get It Wrong?

Snippet summary: Misclassifying personal data as business contact information — or ignoring the DNC rules — can expose your organisation to significant financial penalties. Since October 2022, the PDPC can impose penalties of up to S$1 million, or 10% of an organisation's annual turnover in Singapore (whichever is higher) for turnover above S$10 million.

The PDPC has consistently taken enforcement action where organisations treated personal data too loosely. Marketing messages sent to numbers on the DNC Registry, and failures to protect databases, have both attracted financial penalties and directions. The lesson for your organisation: the business contact information exemption is a genuine convenience, but overreaching it converts a compliant workflow into an enforcement risk.

To understand how these rules play out in real disputes, review our breakdown of PDPA penalties and enforcement cases. And if you are still building your foundations, the PDPA compliance checklist for Singapore SMEs walks through every obligation step by step. Businesses handling large volumes of enquiries — such as e-commerce operators — should pay particular attention to keeping business and personal data streams distinct.


Key Takeaways for Your Organisation

  • Business contact information collected in a business context is exempt from the PDPA's consent, notification and other Data Protection Provisions under section 4(5).
  • The exemption fails if information was provided solely for personal purposes — always assess the reason for provision.
  • Do Not Call rules are separate — screen Singapore phone numbers before any marketing outreach.
  • Secure all data and train staff, because exempt data rarely lives in isolation.
  • When the classification gets complex, automate it rather than guessing.

Getting business contact information right lets your organisation move faster in B2B dealings while staying firmly compliant — the best of both worlds when you understand exactly where the line sits.


Sources & References

  1. PDPC — Personal Data Protection Act Overview
  2. Singapore Statutes Online — Personal Data Protection Act 2012
  3. PDPC — Advisory Guidelines on Key Concepts in the PDPA
  4. PDPC — Do Not Call Registry
  5. PDPC — Enforcement Decisions and Financial Penalties

Simplify Your Compliance

ComplyHQ's AI can assess your PDPA compliance gaps in under 15 minutes and generate the policies you need.

Try Free Assessment

Frequently Asked Questions

Do I need consent to email someone using their work email address?
No. Under the PDPA, business contact information is exempt from the Data Protection Provisions, so you do not need consent to collect, use or disclose a work email address collected in a business context. However, if you are sending marketing messages to a Singapore telephone number, the Do Not Call (DNC) provisions in Part 9 still apply and you must check the DNC Registry unless an exemption applies.
Is a name card (business card) covered by PDPA consent rules?
Generally no. Information on a business card — name, job title, company, business phone and business email — is business contact information and falls outside the consent, notification and purpose limitation obligations. You can add that contact to your CRM and follow up on the business matter without separate consent, provided the information was not given solely for personal purposes.
Does the business contact information exemption cover personal mobile numbers?
Only if the number was provided in a business capacity, not solely for personal purposes. If an employee gives you their personal mobile purely for personal reasons, it is personal data and full PDPA obligations apply. When in doubt, treat the information as personal data and obtain consent.
Tags:PDPASingapore complianceSMEdata protectionPDPC

Ready to get PDPA compliant?

Stop guessing about compliance. ComplyHQ uses AI to assess your gaps, generate policies, and guide you through every PDPA obligation.

Gap AssessmentPolicy GeneratorAI Compliance Chat
14 July 20267 min read

PDPA Withdrawal of Consent: What Happens When Customers Opt Out

PDPA withdrawal of consent guide for Singapore SMEs: what to do when customers opt out, your legal timelines, obligations under the PDPA, and how to stay compliant.

Read more
11 July 20267 min read

PDPA Correction Requests: How Singapore Businesses Should Respond

Learn how to handle a PDPA correction request in Singapore: legal timelines, valid exceptions, and a step-by-step process to keep your SME compliant with the PDPC.

Read more
8 July 20267 min read

Handling PDPA Access Requests in Singapore: 30-Day Response Guide

Master PDPA access requests in Singapore with our 30-day response guide. Step-by-step process, deadlines, exceptions & penalties for SMEs under the PDPA 2012.

Read more