pdpa-compliance7 min read13 September 2026

PDPA Deemed Consent: When You Can Collect Data Without Explicit Consent

A clear guide to PDPA deemed consent for Singapore SMEs — when you can collect data without explicit consent, the rules under PDPA 2012, and how to stay compliant.

ComplyHQ Team

PDPA Deemed Consent: When You Can Collect Data Without Explicit Consent

PDPA Deemed Consent: When You Can Collect Data Without Explicit Consent

Many Singapore SME owners believe they need a signed consent form for every scrap of personal data they touch. In reality, PDPA compliance in Singapore is more nuanced: the Personal Data Protection Act 2012 recognises deemed consent, a legal basis that lets your organisation collect, use, or disclose personal data without asking for explicit consent in certain situations. Understanding when deemed consent applies — and, just as importantly, when it does not — helps your business operate smoothly while staying on the right side of the Personal Data Protection Commission (PDPC).

TL;DR — Key Takeaways

  • Deemed consent under Section 15 of the PDPA lets you collect personal data without explicit consent when an individual voluntarily provides it for an obvious purpose.
  • The 2021 PDPA amendments added two new limbs: deemed consent by contractual necessity and deemed consent by notification.
  • Deemed consent is not a loophole — the Notification, Purpose Limitation, and Protection obligations still apply.
  • Getting it wrong can cost your organisation up to S$1 million or 10% of annual turnover in Singapore, whichever is higher.
  • When in doubt, document your reasoning — regulators reward organisations that can show their assessment.

Deemed consent is a provision under Section 15 of the PDPA 2012 that treats an individual as having consented to the collection, use, or disclosure of their personal data — even without an explicit opt-in — where they voluntarily provide the data for a purpose that is reasonably obvious. In practice, it is the legal reason your business can act on data a customer hands over during an ordinary transaction. It reduces friction while keeping the individual's expectations at the centre of Singapore data protection.

The classic example: a customer walks into your shop, orders a custom cake, and gives you their name and phone number so you can call when it is ready. You did not present a consent form, yet you may lawfully use that phone number for that purpose. The individual voluntarily provided the data, and using it to complete their own request is the obvious purpose.

Definitive statement: Deemed consent does not remove your other PDPA obligations — it only replaces the requirement for express consent. Your organisation must still notify individuals of the purpose (Section 20), limit use to that purpose (Section 18), and protect the data (Section 24).

Since the significant PDPA amendments that took effect on 1 February 2021, there are three distinct forms of deemed consent your organisation can rely on:

  1. Deemed consent by conduct (the original Section 15(1)) — the individual voluntarily provides data for a purpose that is obvious.
  2. Deemed consent by contractual necessity (Sections 15(3)–(6)) — consent flows down a chain of contracts. For example, if a customer books a hotel through a travel agent, the hotel can be deemed to have the customer's consent to receive their booking details.
  3. Deemed consent by notification (Section 15A) — you notify the individual of a new purpose, give them a reasonable opt-out period, and proceed if they do not object.

Your business can rely on PDPA deemed consent when an individual voluntarily provides personal data for a purpose that would be obvious to a reasonable person, when data must be shared to fulfil a contract the individual is party to, or when you have properly notified them of a new purpose and they have not opted out. Each pathway carries specific conditions, and the burden of proof sits with your organisation.

Here are the most common scenarios Singapore SMEs encounter:

  • Completing a transaction the customer initiated. A diner gives their mobile number to join your restaurant's waitlist. Using it to text them when the table is ready is covered. (For sector-specific detail, see our guide on PDPA for F&B and Restaurants.)
  • Delivering a service across a supply chain. An e-commerce order that passes shipping details to a logistics partner relies on deemed consent by contractual necessity. Our PDPA Compliance for E-Commerce guide walks through this in depth.
  • Introducing a related secondary purpose. You want to use existing customer contact details to send service-improvement surveys. Deemed consent by notification (Section 15A) may apply — provided you notify clearly and offer an opt-out.

The conditions you must satisfy

Deemed consent is not automatic. For deemed consent by notification, Section 15A requires your organisation to:

  • Conduct and document an assessment to identify and mitigate any adverse effect on the individual.
  • Take reasonable steps to notify the individual of the new purpose.
  • Provide a reasonable opt-out period before you begin using the data.

Definitive statement: Deemed consent by notification cannot be relied on to send direct marketing messages — the PDPC's Advisory Guidelines expressly exclude direct marketing from this pathway, and separate Do Not Call (DNC) rules apply.


Deemed consent does not apply to sensitive uses, direct marketing, or any purpose an individual would not reasonably expect — and it never overrides an individual's right to withdraw consent. Misjudging this boundary is where many Singapore SMEs run into trouble with the PDPC.

Situations where you should not rely on deemed consent:

  • Direct marketing and promotional messaging. You need express, specific consent, and you must also honour the DNC Registry for calls, texts, and faxes to Singapore numbers.
  • Sensitive personal data such as financial or health information used beyond the original obvious purpose. Professional firms handling such data — for example, accountants — face heightened expectations; see our PDPA guide for accounting firms.
  • Employee monitoring that goes beyond what staff would reasonably expect. Our Employee Monitoring and the PDPA guide explains where the line sits.
  • Selling or sharing data with third parties for unrelated purposes.

Remember that under Section 16, an individual may withdraw consent — including deemed consent — at any time by giving reasonable notice. Once they do, your organisation must stop the relevant collection, use, or disclosure.


Under the PDPA (as amended), the PDPC can impose financial penalties of up to S$1 million, or up to 10% of an organisation's annual turnover in Singapore for organisations with local turnover exceeding S$10 million — whichever is higher. These enhanced penalty caps took effect on 1 October 2022, raising the stakes for every Singapore business.

The PDPC has taken enforcement action in numerous cases involving unauthorised collection, poor security, and unsolicited marketing. Penalties frequently reach five and six figures, and directions to improve practices are common. To learn from concrete examples, read our breakdown of real PDPA enforcement cases.

Beyond fines, mishandling consent damages customer trust and can trigger mandatory breach notification. Since 1 February 2021, notifiable data breaches — those likely to result in significant harm or affecting 500 or more individuals — must be reported to the PDPC, generally within 3 calendar days of assessing that the breach is notifiable. If you ever face this scenario, our data breach response guide sets out the steps.


Before your organisation relies on deemed consent, run through a short assessment: confirm the data was voluntarily provided, verify the purpose is obvious or properly notified, document your reasoning, and make sure your other PDPA obligations are met. Treat this as a repeatable process, not a one-off.

  1. Identify the basis. Is this deemed consent by conduct, contractual necessity, or notification? Name it.
  2. Confirm voluntariness. Did the individual actively provide the data, or did you obtain it another way?
  3. Test the "obvious purpose." Would a reasonable person expect their data to be used this way?
  4. Document a notification assessment if you are relying on Section 15A, including how you mitigated adverse effects.
  5. Update your privacy notice so purposes are clearly stated (Section 20).
  6. Respect withdrawal. Ensure customers can easily withdraw consent, and that your systems act on it.
  7. Train your team. Front-line staff are your first line of compliance — see our PDPA staff training requirements guide.

For a broader view of everything your organisation needs, use our PDPA compliance checklist for Singapore SMEs. Organisations pursuing formal information security certification may also benefit from our ISO 27001 guide for SMEs.


Working out which consent basis applies — and documenting it properly — is exactly the kind of task that eats up an SME owner's week. ComplyHQ offers AI-powered compliance that handles your PDPA obligations in minutes, not weeks. The platform maps your data flows, flags where deemed consent is (and isn't) appropriate, and generates the notification assessments and privacy notices the PDPC expects to see — so your organisation has the paper trail regulators reward.

For businesses that need bespoke systems or integrations to operationalise compliance across their tech stack, our sister company Adaptels builds custom digital solutions for Singapore SMEs.

Definitive statement: The organisations that fare best under PDPA scrutiny are not those that avoid collecting data — they are the ones that can clearly explain, and evidence, the basis on which they collected it.


Key Takeaways

Deemed consent is one of the most practical tools in the PDPA, letting your business operate without drowning customers in consent forms. But it rewards precision: know which of the three limbs you are relying on, confirm the purpose is genuinely obvious or properly notified, keep marketing and sensitive data out of scope, and always honour withdrawal. Get those fundamentals right — and document them — and deemed consent becomes a source of confidence rather than risk.


Sources & References

  1. Personal Data Protection Act 2012 — Singapore Statutes Online
  2. PDPC — Advisory Guidelines on Key Concepts in the PDPA
  3. PDPC — Overview of the PDPA and the Consent Obligation
  4. PDPC — Enforcement Decisions and Undertakings
  5. PDPC — Guide on Managing and Notifying Data Breaches under the PDPA (PDF)

This article is for general information only and does not constitute legal advice. For advice specific to your organisation, consult a qualified professional.

Simplify Your Compliance

ComplyHQ's AI can assess your PDPA compliance gaps in under 15 minutes and generate the policies you need.

Try Free Assessment

Frequently Asked Questions

Do I need written consent for every piece of customer data my Singapore business collects?
No. The PDPA recognises several bases for collecting personal data, and deemed consent is one of them. When a customer voluntarily provides data for a transaction they initiated — such as giving their delivery address to complete an order — consent is deemed to be given for that specific purpose. However, you still must fulfil the Notification and Purpose Limitation obligations, so it is not a blanket exemption.
What is the difference between deemed consent and the legitimate interests exception under the PDPA?
Deemed consent (Section 15) applies when an individual voluntarily provides data for an obvious purpose, or when consent flows through a contractual chain. The legitimate interests exception (First Schedule, Part 3) lets you collect data without consent where the benefit to your organisation or the public outweighs any adverse effect on the individual — but it requires a documented assessment. Deemed consent relies on the individual's action; legitimate interests relies on your justification.
Can I rely on deemed consent to send marketing messages to my customers?
Generally no. Deemed consent by notification can be used for secondary purposes, but the PDPA and the Spam Control Act impose stricter rules on marketing. For sending marketing messages to Singapore telephone numbers you must also check the Do Not Call (DNC) Registry unless a valid exemption applies. Relying on deemed consent alone for marketing is risky, and the PDPC has penalised organisations for unsolicited marketing.
Tags:PDPASingapore complianceSMEdata protectionPDPC

Ready to get PDPA compliant?

Stop guessing about compliance. ComplyHQ uses AI to assess your gaps, generate policies, and guide you through every PDPA obligation.

Gap AssessmentPolicy GeneratorAI Compliance Chat
16 September 20267 min read

Business Contact Information Under PDPA: What You Can Use Freely

A clear guide to business contact information under Singapore's PDPA — what your business can collect, use and disclose without consent, plus the DNC traps to avoid.

Read more
14 July 20267 min read

PDPA Withdrawal of Consent: What Happens When Customers Opt Out

PDPA withdrawal of consent guide for Singapore SMEs: what to do when customers opt out, your legal timelines, obligations under the PDPA, and how to stay compliant.

Read more
11 July 20267 min read

PDPA Correction Requests: How Singapore Businesses Should Respond

Learn how to handle a PDPA correction request in Singapore: legal timelines, valid exceptions, and a step-by-step process to keep your SME compliant with the PDPC.

Read more