industry-guides8 min read6 June 2026

PDPA for E-Commerce: Handling Customer Data in Singapore Online Shops

Complete guide to PDPA compliance for Singapore e-commerce businesses. Learn how to handle customer data, consent requirements, and avoid PDPC penalties.

ComplyHQ Team

PDPA for E-Commerce: Handling Customer Data in Singapore Online Shops

PDPA for E-Commerce: What Singapore Online Shops Get Wrong

Last year, a Shopee seller I know got a PDPC complaint. A customer had unsubscribed from marketing emails three times, but the emails kept coming. Turns out the seller was using two different email tools — Mailchimp for campaigns and Shopify's built-in email for abandoned cart flows. Unsubscribing from one didn't affect the other. Nobody had checked. The PDPC didn't care that it was accidental.

Here's the reality: Singapore's PDPA treats your e-commerce business the same as any other organisation. You need explicit consent before collecting customer data, proper security safeguards, and the ability to respond to data breaches within days — not weeks. Between 2020 and 2025, the PDPC issued 40+ enforcement actions against Singapore SMEs, with penalties averaging SGD 35,000 to SGD 150,000. Your online shop is not too small to be noticed.


Why This Applies to You

If your Singapore e-commerce shop collects names, email addresses, phone numbers, payment details, delivery addresses, or browsing history, you're handling personal data under the PDPA 2012. This applies whether you're running a Shopify store, a custom-built website, selling on Lazada or Shopee, or doing social commerce through Instagram.

Non-compliance exposes you to:

  • Civil fines up to SGD 1 million (PDPA Section 27)
  • Criminal prosecution for wilful breaches (PDPA Section 34)
  • Reputational damage through publicly published PDPC enforcement notices
  • Customer lawsuits for damages from unauthorised data use
  • Platform removal — Shopee, Lazada, and others suspend sellers for PDPA violations

The good news? Most violations are preventable with clear policies, proper consent workflows, and basic security measures.


The Five Core Obligations for Your Online Shop

You need permission in clear language before collecting any personal data. Silence, pre-ticked boxes, or "by using this site you agree" banners don't count.

What this means in practice:

  • Email collection: Add a checkbox at checkout: "I consent to [Shop Name] storing my email address to process my order and send order updates." Unchecked by default.
  • Marketing lists: Separate from purchase consent. A different checkbox: "I consent to receive marketing emails about new products and promotions." Never auto-enrol customers in newsletters.
  • Cookies and tracking: Disclose what you're using (Google Analytics, Facebook Pixel, Shopify analytics) and get consent before firing the tracking code.
  • Payment data: Your payment gateway (Stripe, PayPal) handles the heavy lifting. Your consent statement references their processing.

Document everything. What consent was requested, when it was given, how it was obtained, what the person consented to. Most e-commerce platforms log checkbox data automatically — export and archive it monthly.


2. Tell People What You're Doing With Their Data (Section 18)

Your privacy policy is a legal requirement. Not a marketing afterthought, not a copied template from a random website. It must clearly state what data you collect, why, who you share it with, how long you keep it, and how people can access or correct their information.

What your policy should cover:

Customer names, emails, phones — For order processing and delivery. Retained for 3 years after purchase. Shared with delivery courier and payment processor.

Payment card details — Not stored by you (processor handles this). Shared with payment processor only.

Browsing history, IP addresses — For analytics and fraud prevention. Retained for 12 months. Shared with Google Analytics, your platform.

Marketing emails — For promotional communications. Retained until unsubscribed. Shared with your email service provider.

Purchase history — For customer service and recommendations. Retained for 5 years. Your team only.

Your privacy policy needs to be visible (footer link on every page, before checkout), written in plain language, mobile-friendly, and updated at least annually.


3. Actually Secure the Data (Section 24)

The PDPC expects reasonable security proportional to your data sensitivity and business size.

Non-negotiable for every e-commerce shop:

  • HTTPS (SSL/TLS) on your entire site. If you're on Shopify, WooCommerce, or Wix, this is automatic. Verify it.
  • Encrypted databases. Most hosted platforms handle this — confirm with your provider.
  • Strong passwords (12+ characters) and two-factor authentication on all admin accounts.
  • Weekly backups with tested recovery procedures.
  • Automatic software and plugin updates.
  • An incident response plan documented before you need it.

What not to do:

  • Don't store full credit card numbers (that's your payment processor's job)
  • Don't keep customer data in unencrypted spreadsheets on shared drives
  • Don't share customer lists with third parties without consent
  • Don't email customer data without encryption

For managed platforms (Shopify, WooCommerce.com), most of this is built in. For custom-built sites, verify HTTPS, database encryption, and automatic backups with your developer.


4. Let Customers Access and Correct Their Data (Section 20)

People have the right to request a copy of their data and correct inaccuracies. You must respond within 30 days.

Set up a simple process:

  • Include a contact email in your privacy policy for data requests
  • Create a basic request form (even a standard email template works)
  • Train your team to respond promptly
  • Document each request and response

Most e-commerce platforms have built-in "customer data export" features. Use them.


5. Have a Plan for When Things Go Wrong (Section 26D)

If customer data is lost, stolen, or exposed, you must report significant breaches to the PDPC and notify affected customers.

What counts as a breach: Hacked database, lost device with customer data, accidental disclosure (email to wrong recipient), ransomware, insider theft.

Your response plan (document this now, not during a crisis):

  1. Assess the risk within 24 hours
  2. Report to PDPC if significant (email privacy@pdpc.gov.sg)
  3. Notify affected individuals within 30 days
  4. Document everything — the breach, investigation, notifications, remediation

The Four Mistakes That Actually Get E-Commerce Shops Fined

Mistake 1: Auto-Enrolling Customers in Marketing

The PDPC has fined online retailers for sending marketing emails to customers who only gave purchase consent. Marketing consent must be explicit and separate. Pre-ticked boxes don't count. An unchecked "Subscribe to our newsletter" checkbox with an unsubscribe link in every email is what you need.

Mistake 2: Storing Credit Card Numbers

Just don't. Your payment processor (Stripe, PayPal, Shopify Payments) handles this securely. If you're somehow storing card numbers in your own database, stop immediately.

Mistake 3: Sharing Customer Data Without Disclosure

Selling or sharing your customer email list with a marketing agency without consent? That's a fine waiting to happen. List every third party in your privacy policy. Get explicit consent for each disclosure. Use data processing agreements with vendors.

Mistake 4: Keeping Data Forever "Just in Case"

Document retention periods by data type and stick to them. Set calendar reminders to delete old data. Keep a deletion log.


The 30-Day Compliance Plan

Week 1:

Week 2:

  • Add consent checkboxes to your checkout form
  • Test that they log correctly
  • Update privacy policy links in footer and checkout

Week 3:

  • Configure analytics consent (Google Analytics, Facebook Pixel)
  • Document your data retention schedule
  • Create a one-page breach response plan

Week 4:

  • Train your team (20 minutes) on PDPA basics and data handling
  • Set calendar reminders for monthly data deletion
  • Schedule an annual compliance review

If you want to shortcut this, ComplyHQ can audit your shop, generate a compliant privacy policy, and handle your PDPA obligations in minutes — giving you more time for what actually grows your business.


Real PDPC Cases: What Happened to Shops Like Yours

Delivery platform fined SGD 220,000 — Shared customer contacts with restaurants without consent. Lesson: disclose all third parties and get separate consent.

Fashion retailer fined SGD 75,000 — Sent marketing emails without explicit consent, forced to delete entire email list. Lesson: separate marketing consent from purchase consent.

E-grocery platform fined SGD 150,000 — Database hacked, failed to notify customers within 30 days. Lesson: have a breach response plan ready before you need it.

Beauty brand fined SGD 40,000 — Kept customer data indefinitely with no deletion schedule. Lesson: document and enforce retention policies.

These cases are publicly available on the PDPC Enforcement Cases page.


Quick Answers to Common Questions

"I'm a small Lazada/Shopee seller — does PDPA apply to me?" Yes. You collect customer data (email, delivery address) and are responsible for PDPA compliance. The marketplace is also a data controller, but that doesn't reduce your obligations.

"Can I use customer data for things beyond order fulfilment?" Only with explicit consent and disclosure in your privacy policy. Each new purpose requires new consent.

"I outsource my website to a developer — who's responsible?" You are. The developer is the data processor; you're the data controller. You need a Data Processing Agreement in writing.

"How do I get PDPA compliance verified?" The PDPC doesn't issue certificates. You can self-audit using PDPC guidelines, hire a consultant (SGD 3,000-10,000), or pursue ISO 27001 certification as a complementary standard.


What You Must Do (The Non-Negotiables)

  1. Obtain written consent before collecting any personal data (PDPA Section 13)
  2. Publish a privacy policy disclosing all collection, use, retention, and disclosure (PDPA Section 18)
  3. Implement security measures proportional to your data sensitivity (PDPA Section 24)
  4. Respond to data requests within 30 days (PDPA Section 20)
  5. Report data breaches to the PDPC and affected individuals without unreasonable delay (PDPA Section 26D)
  6. Document everything: consent records, policies, procedures, breach responses

Resources

Not sure where to start? Run through the PDPA Compliance Checklist for Singapore SMEs for a step-by-step audit. Or if a breach happens, follow the Data Breach Response Guide for immediate action steps.

Sources

  1. PDPC — Personal Data Protection Commission
  2. Personal Data Protection Act 2012
  3. CSA — Cyber Security Agency of Singapore

Simplify Your Compliance

ComplyHQ's AI can assess your PDPA compliance gaps in under 15 minutes and generate the policies you need.

Try Free Assessment

Frequently Asked Questions

Can I collect customer email addresses without consent?
No. Under PDPA Section 13, you must obtain explicit consent before collecting personal data, including email addresses. The only exception is collection for legitimate business purposes where the individual has reasonable notice. For marketing emails, consent is mandatory. Document all consent in writing and retain records for at least one year.
What happens if I get fined for PDPA violations?
PDPC penalties reach up to SGD 1 million for first-time offences or SGD 2 million for repeat violations. The PDPC has issued fines averaging SGD 30,000–SGD 220,000 to Singapore businesses for mishandling customer data. Fines increase significantly for large-scale breaches or intentional non-compliance.
How long can I keep customer purchase records?
Under PDPA Section 19, you must not retain personal data longer than necessary for your stated business purposes. For e-commerce, this typically means 3–5 years for purchase history, 2 years for marketing records, and until contractual obligations end. Document your retention policy in writing and delete data proactively.
Do I need a privacy policy for my online shop?
Yes. PDPA Section 18 requires you to notify individuals of personal data collection, usage, and disclosure. Your privacy policy must be clearly visible (usually in the footer), explain what data you collect, how you use it, who you share it with, and how long you keep it. Review and update annually.
What should I do if my e-commerce site gets hacked?
You must report significant data breaches to the PDPC without unreasonable delay, and notify affected customers if there is significant risk of harm. Document your incident response plan before a breach occurs. Implement encryption, multi-factor authentication, and regular security audits to prevent breaches. ComplyHQ can help you build a data breach response plan that meets PDPC expectations.
Tags:PDPASingapore complianceSMEe-commercedata protectionPDPCcustomer data

Ready to get PDPA compliant?

Stop guessing about compliance. ComplyHQ uses AI to assess your gaps, generate policies, and guide you through every PDPA obligation.

Gap AssessmentPolicy GeneratorAI Compliance Chat
15 July 20267 min read

PDPA for Law Firms: Client Privilege and Data Protection

A practical guide to PDPA compliance in Singapore for law firms — reconciling legal professional privilege with data protection duties, breach rules, and PDPC penalties.

Read more
12 July 20267 min read

PDPA for Accounting Firms: Client Financial Data

PDPA compliance Singapore guide for accounting firms handling client financial data. Learn PDPC obligations, penalties, and practical steps to protect sensitive records.

Read more
9 July 20267 min read

PDPA for Event Companies: Attendee Data Rules

PDPA compliance for Singapore event companies: how to collect, use, and protect attendee data under the PDPA — consent, retention, breach rules, and penalties.

Read more