Compliance & regulationChecklist

PDPA for clinics: a working checklist for Singapore practices

The PDPA applies to every private clinic, whatever its size. This checklist sets out what the Act, PDPC’s healthcare guidance and MOH’s record-retention rules actually ask of a practice, and where clinics most often slip.

ClinicPlus editorial teamUpdated 10 min read

Key takeaways

  • Patients who register and consult are generally deemed to consent to the clinic using their data for their care. Marketing and other secondary uses need separate consent, or a properly assessed notification with a real chance to opt out.
  • Clinics may collect NRIC numbers to identify patients accurately, but must stop using full or partial NRIC numbers to authenticate anyone by 31 December 2026.
  • A breach affecting 500 or more people, or exposing certain sensitive health data alongside a name or ID number, must be reported to PDPC within 3 calendar days of deciding it is notifiable. The assessment itself should be done within 30 days.
  • The PDPA sets no fixed retention period, but MOH licence conditions do: electronic patient health records must be kept for the patient’s lifetime plus 6 years.
  • Appointment reminders are generally not marketing. Promotional WhatsApp or SMS messages to Singapore numbers fall under the Do Not Call rules.

The short answer: what the PDPA asks of a clinic

The Personal Data Protection Act (PDPA) applies to private clinics as to any Singapore organisation; a solo GP practice has the same obligations as a hospital group. The core is short: know why you collect each item of patient data, protect it, let patients see it, keep it only as long as required, and have a plan for when something goes wrong.

PDPC’s Advisory Guidelines for the Healthcare Sector (revised 20 September 2023) apply the Act to clinic scenarios; MOH licence conditions add record-keeping rules. The table is the one-page version.

PDPA checklist for a Singapore clinic
AreaWhat to have in placeEvidence to keep
Consent and notificationRegistration form and privacy notice that state your purposes; a separate opt-in for marketingCurrent form and notice; consent flags in the patient record
NRICNRIC collected to identify patients, never used to verify callers or log anyone inFront-desk script; system login settings
DPO and policiesAt least one named DPO with published business contact; a written data protection policyDPO registry entry; policy; staff training log
ProtectionNamed accounts, role-based access, MFA, audit logs, vendor contractsAccount list; permission matrix; audit log exports
Breach responseA written plan that tracks the 30-day and 3-day clocksIncident log; assessment records
Access and correctionA process to respond within 30 daysRequest log; copies of replies
Retention and disposalA schedule aligned with MOH retention periods; secure disposalRetention schedule; disposal records
MessagingReminders kept apart from marketing; DNC checks where neededConsent flags; DNC check results

DPO, policies and everyday safeguards

Every organisation must designate at least one data protection officer (DPO) and make that person’s business contact information public. In a clinic this is often the practice manager or a principal doctor, and PDPC keeps a DPO registry on its website. You also need written data protection policies, with information about them publicly available.

The Protection Obligation asks for “reasonable security arrangements”. For a clinic, that usually means:

  • A named account for every staff member, removed the day they leave.
  • Permissions by role: the front desk does not need full clinical notes.
  • Multi-factor authentication for anyone who can open patient records.
  • Audit logs showing who opened which record, reviewed periodically.
  • Encrypted devices and backups; no patient lists in personal chat groups.
  • Staff briefed at induction and at regular intervals.

If you are working towards the CSA Cyber Essentials mark, most of this doubles as evidence; see Cyber Essentials for clinics.

Vendors are data intermediaries

Your clinic system vendor, IT support, SMS provider and cloud storage process patient data on your behalf. Under the PDPA they are data intermediaries: they carry protection and retention obligations and must notify you of breaches they detect, but responsibility to patients stays with the clinic. The contract should cover permitted use, where data is stored (transfers outside Singapore bring in the Transfer Limitation Obligation), security, breach notification, and return or deletion at the end. Our guide to switching systems covers exit terms.

Data breaches: thresholds and timelines

Since 1 February 2021, a breach must be notified if it is likely to result in significant harm to the people affected, or involves 500 or more individuals.

Under the Notification of Data Breaches Regulations 2021, exposing a person’s name, alias or ID number together with a prescribed category is deemed significant harm. Several categories are clinical:

  • Assessment, diagnosis or treatment of sexually transmitted diseases, HIV infection, schizophrenia or delusional disorder, or substance abuse and addiction.
  • Treatment relating to egg or sperm donation, contraceptive operations or procedures, or abortion.
  • Suicide or attempted suicide, and domestic, child or sexual abuse.
  • Insurance claim details, including the health conditions described.
  • An account identifier together with its password or other credential.

A leaked list of names and appointment times may avoid these categories, but 600 patients is notifiable on scale alone.

The breach clock
StepDeadlineNotes
Credible grounds to believe a breach happenedStart assessing straight awayIncludes an alert from a vendor or a member of the public
Assess whether it is notifiableReasonably and expeditiously, within 30 calendar daysDocument every step; be ready to explain any delay
Notify PDPCAs soon as practicable, no later than 3 calendar days after deciding it is notifiableDay one is the day after the decision
Notify affected patientsAs soon as practicable, at the same time as or after PDPCRequired where significant harm is likely
Vendor detects a breachMust notify the clinicSet a short deadline in the contract

Separately, the Health Information Act, passed by Parliament on 12 January 2026, adds mandatory reporting of cybersecurity incidents and data breaches to MOH as its requirements take effect; a PDPC notification will not cover both. It also phases in compulsory NEHR contribution.

Financial penalties for breaching the data protection provisions can reach S$1 million, or 10% of annual turnover in Singapore for organisations whose turnover there exceeds S$10 million.

Access, correction and how long to keep records

Access requests

Patients may ask for their personal data and how it was used or disclosed in the past year. Respond as soon as reasonably possible; if you cannot within 30 days, say in writing within those 30 days when you will. A reasonable fee is allowed, and a medical report can stand in for photocopied handwritten notes. Verify identity first. If you refuse under an exception, keep a complete copy for at least 30 calendar days so the patient can seek a review.

Correction requests

Correct factual errors such as an old address. A diagnosis is a professional opinion that the PDPA does not require you to change; if you decline, annotate the record with the requested correction.

Retention: where the PDPA meets MOH rules

The PDPA says to stop keeping personal data once it serves no purpose and no legal or business reason remains; it sets no fixed period. For medical records, MOH’s licence conditions for all HCSA licensees (Circular 85/2022) set minimums:

RecordMinimum retention
Computerised or electronic patient health records, including scanned paperLifetime plus 6 years (lifetime counts as 110 years if the date of death is unknown)
Paper outpatient records6 years from the last consultation or treatment
High-risk patients or cases, such as complications, pending complaints, or patients lacking mental capacityAt least 15 years from the last consultation or treatment
Records relevant to legal, mediation or disciplinary proceedings, begun or reasonably foreseeableUntil the proceedings end, or the normal period if longer

Assume your records will outlive your software: the retention duty stays with the licensee when you change vendors or close. When disposal is due, destroy paper securely and purge electronic records from backups and retired devices too.

WhatsApp and SMS: reminders versus marketing

The Do Not Call (DNC) provisions apply to “specified messages”, those that offer, advertise or promote goods or services, sent to Singapore telephone numbers. PDPC’s DNC guidelines say this covers voice calls, SMS and apps such as WhatsApp that use a Singapore number.

Most clinic messaging is not marketing. PDPC’s examples: a text solely reminding a patient of an appointment, or a call to book a review of results, is unlikely to be a specified message. Messages within an ongoing relationship about its subject are excluded too: telling an asthma patient under your care about a new asthma drug is fine; promoting it to a patient you see only for migraines is not.

For anything promotional, such as a health-screening package or a new service:

  • Check the DNC Registry first (results are valid for 21 days), or hold clear and unambiguous consent in written or other accessible form. Silence after an opt-out letter is not consent.
  • Identify the clinic, with contact details valid for at least 30 days after sending.
  • Give effect to withdrawn consent within 21 days.
  • Keep reminders and marketing on separate consent flags.
  • Send from the clinic’s number and a shared inbox, not staff personal phones.

Whatever messaging tool you use, check that each send is recorded against the patient and that a marketing opt-out does not block receipts or medical certificates.

Frequently asked questions

Does the PDPA apply to a small GP clinic?

Yes. The PDPA applies to private organisations in Singapore regardless of size, so a single-doctor clinic has the same obligations as a group. What changes with size is how elaborate your policies and controls need to be, not whether they are needed.

Can our clinic still ask patients for their NRIC?

Yes, for identification. PDPC’s NRIC guidelines use a GP clinic as an example of where collecting NRIC numbers is justified to keep accurate medical records. What must stop by 31 December 2026 is using full or partial NRIC numbers to authenticate people, for example to confirm a caller’s identity or as a login password.

Do WhatsApp appointment reminders need a DNC check?

Generally no. PDPC’s healthcare guidelines say a message sent solely to remind a patient of an appointment is unlikely to be a specified message. Promotional messages to Singapore numbers do need a DNC check within 21 days of sending, unless you hold clear and unambiguous consent or an exclusion such as an ongoing relationship applies.

How long must a clinic keep medical records in Singapore?

Under MOH’s licence conditions for HCSA licensees, electronic patient health records must be kept for the patient’s lifetime plus 6 years, and paper outpatient records for 6 years from the last consultation. High-risk cases need at least 15 years, and records tied to legal or disciplinary proceedings must be kept until those end.

Can a patient ask us to delete their medical records?

A patient can withdraw consent for future uses, but the PDPA lets a clinic keep data where another legal basis applies, and MOH’s retention periods are such a basis. Explain what you must keep and why, stop any optional uses such as marketing, and record the request.

When do we have to report a data breach to PDPC?

When it is likely to cause significant harm to the individuals affected, or involves 500 or more people. Assess within 30 calendar days of having credible grounds to suspect a breach, then notify PDPC no later than 3 calendar days after deciding it is notifiable.

Sources

  1. PDPC — Advisory Guidelines for the Healthcare Sector (revised 20 September 2023)
  2. PDPC — Guide on Managing and Notifying Data Breaches under the PDPA
  3. Personal Data Protection (Notification of Data Breaches) Regulations 2021
  4. PDPC — Advisory Guidelines on the PDPA for NRIC and other National Identification Numbers
  5. PDPC — Organisations to cease the use of NRIC numbers for authentication by 31 December 2026
  6. PDPC — Advisory Guidelines on the Do Not Call Provisions (revised 1 February 2021)
  7. MOH Circular 85/2022 — Licence Conditions on the Retention Periods of Patient Health Records
  8. PDPC — Advisory Guidelines on Enforcement of the Data Protection Provisions (1 October 2022)

Primary sources checked on the date above. Schemes and requirements change — always confirm against the latest official notice.

This article is general information for clinic operators, not legal, regulatory or financial advice.

Next step

See it against your own clinic day.

Thirty minutes, screen shared, using your workflow — your busiest hour, your payer mix, your claim types. We will tell you plainly if we are the wrong fit.

No slide deck. No obligation.