PDPA for Real Estate and Property Agents in Singapore: Compliance Guide
Real estate and property agents must comply with Singapore's PDPA. Learn key obligations, consent requirements, and data handling best practices for your agency.

PDPA for Real Estate and Property Agents in Singapore: Compliance Guide
I got a call from a property agency last year — mid-panic. One of their agents had been building a personal database of prospective buyers by scraping phone numbers from PropertyGuru listings. Hundreds of numbers, all contacted via WhatsApp for property recommendations. No consent obtained. No privacy notice ever given. And one of those prospective buyers had just filed a complaint with the PDPC.
The real estate industry handles some of the most sensitive personal data out there: home addresses, financial information, family details, identity numbers. If your property agency isn't actively managing PDPA compliance, you're not just risking fines — you're risking the relationships that drive your business.
The Short Version
Property agents must obtain explicit consent before collecting personal data from buyers, sellers, or tenants. The only exception is when data collection directly supports an existing contractual relationship. Penalties for non-compliance reach up to SGD 1 million — or 10% of annual local turnover for organisations with annual turnover exceeding SGD 10 million — plus potential civil claims from affected individuals.
Why the PDPA Should Be on Every Agent's Radar
The Personal Data Protection Act 2012 regulates how organisations — including real estate agencies of every size — collect, use, disclose, and protect personal data. The PDPC enforces it and has issued specific guidance relevant to property professionals.
Think about the data flowing through your agency on any given day: client names, phone numbers, home addresses, financial details, NRIC numbers, family composition. That volume of sensitive data makes property agencies a natural target for PDPC scrutiny. Since 2013, the PDPC has issued multiple enforcement actions against real estate agencies, with penalties ranging from SGD 5,000 to SGD 275,000+ for serious or repeat breaches.
There's no exemption based on business size. Sole proprietor with one listing? You're covered.
The Obligations That Matter Most for Property Agents
1. Consent: Ask Before You Collect
Before collecting personal data, you need explicit consent — voluntary, specific, and informed. Here's what that looks like in practice:
A buyer contacts your agency asking to view properties. Before adding them to your database, send a privacy notice explaining you'll use their name, email, and phone number to match them with suitable properties. If you also want to send market updates, say so and get separate consent. Then document it.
The biggest gotcha? Many agents assume that because someone inquired about a property, they've consented to everything. They haven't. Inquiry consent covers the inquiry. Marketing consent is separate.
2. Purpose Limitation: Don't Mission-Creep
You can only use personal data for the purpose you stated when you collected it. A property owner lists their apartment for sale through your agency — that doesn't mean you can add them to your "property investment opportunity" mailing list without getting fresh consent.
3. Notification: Tell People What You're Doing
You must provide a clear privacy notice at or before the point of data collection. It should cover your agency's name and contact details, the purposes for collection, whether you'll share data with third parties (banks, lawyers, valuers), how long you'll keep it, individual rights, and how to lodge a complaint.
A privacy notice isn't a nice-to-have. If you're collecting data without one, you're already in breach.
4. Protection: Secure the Data
Keep client records accurate, complete, and secure. For property agents, this means:
- Updated client records — don't keep outdated contact details in your CRM for years
- Encrypted storage and password-protected systems
- Staff access limited to those who need it
- Secure communication channels for sensitive data like NRIC numbers and financial details
- Audit logs of who accessed what
5. Retention: Delete What You Don't Need
Don't keep personal data longer than necessary:
Transaction records — 5 to 7 years (tax and legal requirements) Marketing contacts who didn't convert — 1 to 2 years Client data when consent is withdrawn — Delete promptly
If a buyer viewed a property, didn't proceed, and never consented to marketing, their contact details should go within 3 to 6 months.
The Compliance Risks That Actually Get Agencies in Trouble
Risk 1: Scraping Contact Details from Property Portals
This is more common than the industry likes to admit. An agent scrapes seller or buyer contact details from PropertyGuru, 99.co, or similar portals without consent. Those individuals never consented to your agency contacting them. That's a breach of the Consent Obligation.
The compliant approach: contact property owners through the portal's official inquiry feature, which triggers their consent. Don't harvest contact details programmatically or manually copy numbers from listings.
Risk 2: Unsolicited WhatsApp and SMS Marketing
Sending property updates to potential buyers via WhatsApp or SMS without prior consent is a violation. Marketing via personal messaging channels requires prior express consent. Every message should include clear opt-out instructions.
Risk 3: Sitting on a Decade of Old Client Data
Your database has contacts from ten years ago who never completed a transaction and never opted into marketing. The Retention Limitation Obligation says delete them. Implement a retention schedule and actually follow it.
Risk 4: Sharing Data Without Disclosure
A buyer's bank requests their personal data for a mortgage. You provide it without the buyer knowing. No privacy notice disclosed third-party sharing. The buyer had no chance to object. Your privacy notice must clearly state who you share data with and why.
Risk 5: Insecure Storage
Client spreadsheets with names, phone numbers, and NRIC numbers on an unencrypted USB drive or open shared folder. The Protection Obligation requires reasonable security measures. An unlocked spreadsheet isn't reasonable.
PDPC Enforcement: Real Cases, Real Fines
The PDPC has gone after property agencies. Examples from published enforcement decisions:
- Orchard Scotts Realty (2021): Penalised for collecting and using tenant contacts without consent. Fine: SGD 20,000.
- PropNex (2019): Breached notification and consent obligations. Fine: SGD 50,000.
- Huttons Asia (2016): Collected personal data without consent and failed to provide privacy notices. Fine: SGD 275,000.
The patterns are consistent: no privacy notices, unauthorised data sharing, failure to respond to data access requests. All preventable.
Building a Compliant Property Agency: Step by Step
Step 1: Map your data. List all personal data you collect — names, numbers, addresses, financial info, NRIC, family details. Identify where it's stored and who has access.
Step 2: Draft a privacy notice. Cover your agency's details, collection purposes, third-party categories (banks, lawyers, valuers), retention periods, individual rights, and complaint contacts. Provide this to all clients at first contact.
Step 3: Fix your consent processes. New clients get a consent checkbox in inquiry forms. Marketing contacts need explicit opt-in. Data sharing with third parties gets documented consent.
Step 4: Set retention rules. Transaction records: 5 to 7 years. Non-converted marketing contacts: 12 to 24 months. Opt-out requests: delete promptly.
Step 5: Secure your data. Encrypt sensitive files, use password-protected CRM systems, restrict staff access by role, maintain audit logs, and train your team on data handling.
Step 6: Create a breach response plan. If personal data is lost, stolen, or accessed without authorisation: assess impact, notify affected individuals, notify the PDPC if thresholds are met, and document everything. See our Data Breach Response Guide for detailed steps.
Industry-Specific Considerations
Property Managers and Strata Councils
If your agency also manages properties or serves strata councils, you hold tenant and resident data. The same PDPA obligations apply — consent, notification, accuracy, protection, and retention cover all personal data regardless of whether it's for sales, marketing, or management.
Tenant Screening
If you use third-party screening services (credit checks, background reports), you need explicit tenant consent, confirmation that the screening firm is PDPA-compliant, disclosure of the screening purpose in your privacy notice, and retention of reports only as long as necessary (typically 1 to 2 years).
Virtual Tours and Recording
If you record virtual property tours or use video calls to show properties, disclose that recording is occurring, get consent from all individuals on camera, store recordings securely, and delete after the transaction.
Why This Matters Beyond Fines
PDPA penalties (up to SGD 1 million, or 10% of annual local turnover for larger organisations) are serious, but the broader business impact is often worse:
- Client trust: Data breaches destroy relationships. Clients won't refer an agency they don't trust.
- Reputation damage: PDPC enforcement actions are public. Negative press affects market perception.
- Legal liability: Individuals can sue for damages beyond what the PDPC imposes.
- Operational disruption: Investigations and legal proceedings consume time you could spend closing deals.
On the flip side, compliant agencies build competitive advantage. When clients know you handle their data responsibly, they're more likely to refer others and come back for repeat transactions.
Next Steps
- Audit your current data handling. Do you have privacy notices? Are clients giving informed consent? Where is client data actually stored?
- Draft or update your privacy notice. Cover all data types and third-party sharing relevant to your business.
- Implement a data audit and retention schedule. Identify what you hold and delete what's no longer necessary.
- Train your team. Every agent needs to understand consent, data security, and what not to do with client data.
- Set up regular compliance reviews. Quarterly or annual audits help catch issues before they escalate.
If compliance feels overwhelming, start small: focus on consent and privacy notices this quarter, then tackle data security and retention next. Progress beats perfection.
For a more comprehensive checklist, see our PDPA Compliance Checklist for Singapore SMEs.
Sources
-
Personal Data Protection Commission (PDPC) -- Official Website -- Singapore's independent authority for data protection. Access advisory guidelines, enforcement case summaries, and complaint procedures.
-
Personal Data Protection Act 2012 -- Singapore Statutes Online -- Full text of Singapore's data protection law, including the nine obligations and penalties.
-
PDPC Advisory Guidelines on Personal Data Protection in Real Estate -- Industry-specific PDPA guidance from PDPC covering consent, notification, and data handling in property transactions.
-
PDPC Enforcement Actions and Case Summaries -- Published decisions and fines issued to real estate agencies and other organisations, showing common breach types and penalties.
-
Singapore Business Federation (SBF) -- PDPA Compliance Resources for SMEs -- Practical guides and training resources for Singapore small and medium enterprises navigating data protection obligations.
FAQ
Q: Can property agents collect buyer and seller contact details without consent?
A: No. Under the PDPA, you must obtain explicit consent before collecting personal data from buyers, sellers, or tenants — even for legitimate business purposes like property matching. The only exception is when personal data is necessary to fulfil an existing contractual obligation. Always provide a clear privacy notice.
Q: What happens if a property agent breaches the PDPA?
A: The PDPC can issue compliance orders and impose financial penalties up to SGD 1 million — or 10% of annual local turnover for organisations with annual turnover exceeding SGD 10 million — for serious breaches. Your agency's reputation also takes a hit — enforcement decisions are published publicly. Good-faith compliance efforts significantly reduce enforcement risk.
Q: How long can a real estate agency keep client data after a transaction?
A: Transaction records are typically retained for 5 to 7 years for legal and tax purposes. Marketing databases should be pruned after 12 to 24 months of inactivity or when clients opt out. Don't keep data indefinitely.
Q: Are WhatsApp and SMS compliant channels for property inquiries?
A: Yes, but only with prior express consent or an existing transaction relationship. Always include an easy way for clients to unsubscribe or withdraw consent.
Q: What data can a property agent collect from portals like PropertyGuru or 99.co?
A: Only data the property owner or developer has publicly listed for business purposes. Scraping contact details without consent may violate the PDPA. Best practice: obtain consent directly from the individual before adding them to your database.
Simplify Your Compliance
ComplyHQ's AI can assess your PDPA compliance gaps in under 15 minutes and generate the policies you need.
Try Free AssessmentFrequently Asked Questions
Can property agents collect buyer and seller contact details without consent?
What happens if a property agent breaches the PDPA?
How long can a real estate agency keep client data after a transaction?
Are WhatsApp and SMS compliant channels for property inquiries?
What data can a property agent collect from property portals like PropertyGuru or 99.co?
Ready to get PDPA compliant?
Stop guessing about compliance. ComplyHQ uses AI to assess your gaps, generate policies, and guide you through every PDPA obligation.