Compliance & regulationChecklist
PDPA for clinics: a working checklist for Singapore practices
The PDPA applies to every private clinic, whatever its size. This checklist sets out what the Act, PDPC’s healthcare guidance and MOH’s record-retention rules actually ask of a practice, and where clinics most often slip.
Key takeaways
- Patients who register and consult are generally deemed to consent to the clinic using their data for their care. Marketing and other secondary uses need separate consent, or a properly assessed notification with a real chance to opt out.
- Clinics may collect NRIC numbers to identify patients accurately, but must stop using full or partial NRIC numbers to authenticate anyone by 31 December 2026.
- A breach affecting 500 or more people, or exposing certain sensitive health data alongside a name or ID number, must be reported to PDPC within 3 calendar days of deciding it is notifiable. The assessment itself should be done within 30 days.
- The PDPA sets no fixed retention period, but MOH licence conditions do: electronic patient health records must be kept for the patient’s lifetime plus 6 years.
- Appointment reminders are generally not marketing. Promotional WhatsApp or SMS messages to Singapore numbers fall under the Do Not Call rules.
The short answer: what the PDPA asks of a clinic
The Personal Data Protection Act (PDPA) applies to private clinics as to any Singapore organisation; a solo GP practice has the same obligations as a hospital group. The core is short: know why you collect each item of patient data, protect it, let patients see it, keep it only as long as required, and have a plan for when something goes wrong.
PDPC’s Advisory Guidelines for the Healthcare Sector (revised 20 September 2023) apply the Act to clinic scenarios; MOH licence conditions add record-keeping rules. The table is the one-page version.
| Area | What to have in place | Evidence to keep |
|---|---|---|
| Consent and notification | Registration form and privacy notice that state your purposes; a separate opt-in for marketing | Current form and notice; consent flags in the patient record |
| NRIC | NRIC collected to identify patients, never used to verify callers or log anyone in | Front-desk script; system login settings |
| DPO and policies | At least one named DPO with published business contact; a written data protection policy | DPO registry entry; policy; staff training log |
| Protection | Named accounts, role-based access, MFA, audit logs, vendor contracts | Account list; permission matrix; audit log exports |
| Breach response | A written plan that tracks the 30-day and 3-day clocks | Incident log; assessment records |
| Access and correction | A process to respond within 30 days | Request log; copies of replies |
| Retention and disposal | A schedule aligned with MOH retention periods; secure disposal | Retention schedule; disposal records |
| Messaging | Reminders kept apart from marketing; DNC checks where needed | Consent flags; DNC check results |
Consent, notification and NRIC numbers
Consent for care is usually deemed
A patient who registers and presents for consultation gives, in PDPC’s view, deemed consent by conduct for the purposes of that visit, covering everyone involved in their care. Agreeing to a referral covers disclosing what the referral needs; note verbal consent in the file. Deemed consent does not cover anything beyond the visit: newsletters, screening promotions, sharing data with a partner business.
For those, get express consent, or rely on deemed consent by notification only after the assessment Section 15A requires and with a genuine opt-out. Patients may withdraw consent at any time, though the clinic can keep data where another legal basis applies, such as record-keeping required by law.
- State the purposes on the registration form: care, billing, claims to insurers and government schemes, national health record contribution, reminders.
- Mark which fields are compulsory, and never make marketing consent a condition of treatment.
- Record marketing consent as its own yes-or-no, with the date, in the patient record.
NRIC: collect to identify, never to authenticate
PDPC’s NRIC guidelines, in effect since 1 September 2019, allow collecting NRIC numbers where the law requires it or where a person must be identified to a high degree of fidelity. The guidelines use a GP clinic as their example: accurate identification keeps medical records complete. Asking for NRIC at registration is fine.
The newer rule is about authentication. In February 2026 PDPC announced that private organisations must stop using full or partial NRIC numbers for authentication by 31 December 2026, with stepped-up enforcement from 1 January 2027. That ends “tell me the last four digits of your NRIC” as a way to confirm a caller before discussing results, and any login where an NRIC number acts as the password. Identify with NRIC; verify with a one-time code, Singpass, or a callback to the number on file.
DPO, policies and everyday safeguards
Every organisation must designate at least one data protection officer (DPO) and make that person’s business contact information public. In a clinic this is often the practice manager or a principal doctor, and PDPC keeps a DPO registry on its website. You also need written data protection policies, with information about them publicly available.
The Protection Obligation asks for “reasonable security arrangements”. For a clinic, that usually means:
- A named account for every staff member, removed the day they leave.
- Permissions by role: the front desk does not need full clinical notes.
- Multi-factor authentication for anyone who can open patient records.
- Audit logs showing who opened which record, reviewed periodically.
- Encrypted devices and backups; no patient lists in personal chat groups.
- Staff briefed at induction and at regular intervals.
If you are working towards the CSA Cyber Essentials mark, most of this doubles as evidence; see Cyber Essentials for clinics.
Vendors are data intermediaries
Your clinic system vendor, IT support, SMS provider and cloud storage process patient data on your behalf. Under the PDPA they are data intermediaries: they carry protection and retention obligations and must notify you of breaches they detect, but responsibility to patients stays with the clinic. The contract should cover permitted use, where data is stored (transfers outside Singapore bring in the Transfer Limitation Obligation), security, breach notification, and return or deletion at the end. Our guide to switching systems covers exit terms.
Data breaches: thresholds and timelines
Since 1 February 2021, a breach must be notified if it is likely to result in significant harm to the people affected, or involves 500 or more individuals.
Under the Notification of Data Breaches Regulations 2021, exposing a person’s name, alias or ID number together with a prescribed category is deemed significant harm. Several categories are clinical:
- Assessment, diagnosis or treatment of sexually transmitted diseases, HIV infection, schizophrenia or delusional disorder, or substance abuse and addiction.
- Treatment relating to egg or sperm donation, contraceptive operations or procedures, or abortion.
- Suicide or attempted suicide, and domestic, child or sexual abuse.
- Insurance claim details, including the health conditions described.
- An account identifier together with its password or other credential.
A leaked list of names and appointment times may avoid these categories, but 600 patients is notifiable on scale alone.
| Step | Deadline | Notes |
|---|---|---|
| Credible grounds to believe a breach happened | Start assessing straight away | Includes an alert from a vendor or a member of the public |
| Assess whether it is notifiable | Reasonably and expeditiously, within 30 calendar days | Document every step; be ready to explain any delay |
| Notify PDPC | As soon as practicable, no later than 3 calendar days after deciding it is notifiable | Day one is the day after the decision |
| Notify affected patients | As soon as practicable, at the same time as or after PDPC | Required where significant harm is likely |
| Vendor detects a breach | Must notify the clinic | Set a short deadline in the contract |
Separately, the Health Information Act, passed by Parliament on 12 January 2026, adds mandatory reporting of cybersecurity incidents and data breaches to MOH as its requirements take effect; a PDPC notification will not cover both. It also phases in compulsory NEHR contribution.
Financial penalties for breaching the data protection provisions can reach S$1 million, or 10% of annual turnover in Singapore for organisations whose turnover there exceeds S$10 million.
Access, correction and how long to keep records
Access requests
Patients may ask for their personal data and how it was used or disclosed in the past year. Respond as soon as reasonably possible; if you cannot within 30 days, say in writing within those 30 days when you will. A reasonable fee is allowed, and a medical report can stand in for photocopied handwritten notes. Verify identity first. If you refuse under an exception, keep a complete copy for at least 30 calendar days so the patient can seek a review.
Correction requests
Correct factual errors such as an old address. A diagnosis is a professional opinion that the PDPA does not require you to change; if you decline, annotate the record with the requested correction.
Retention: where the PDPA meets MOH rules
The PDPA says to stop keeping personal data once it serves no purpose and no legal or business reason remains; it sets no fixed period. For medical records, MOH’s licence conditions for all HCSA licensees (Circular 85/2022) set minimums:
| Record | Minimum retention |
|---|---|
| Computerised or electronic patient health records, including scanned paper | Lifetime plus 6 years (lifetime counts as 110 years if the date of death is unknown) |
| Paper outpatient records | 6 years from the last consultation or treatment |
| High-risk patients or cases, such as complications, pending complaints, or patients lacking mental capacity | At least 15 years from the last consultation or treatment |
| Records relevant to legal, mediation or disciplinary proceedings, begun or reasonably foreseeable | Until the proceedings end, or the normal period if longer |
Assume your records will outlive your software: the retention duty stays with the licensee when you change vendors or close. When disposal is due, destroy paper securely and purge electronic records from backups and retired devices too.
WhatsApp and SMS: reminders versus marketing
The Do Not Call (DNC) provisions apply to “specified messages”, those that offer, advertise or promote goods or services, sent to Singapore telephone numbers. PDPC’s DNC guidelines say this covers voice calls, SMS and apps such as WhatsApp that use a Singapore number.
Most clinic messaging is not marketing. PDPC’s examples: a text solely reminding a patient of an appointment, or a call to book a review of results, is unlikely to be a specified message. Messages within an ongoing relationship about its subject are excluded too: telling an asthma patient under your care about a new asthma drug is fine; promoting it to a patient you see only for migraines is not.
For anything promotional, such as a health-screening package or a new service:
- Check the DNC Registry first (results are valid for 21 days), or hold clear and unambiguous consent in written or other accessible form. Silence after an opt-out letter is not consent.
- Identify the clinic, with contact details valid for at least 30 days after sending.
- Give effect to withdrawn consent within 21 days.
- Keep reminders and marketing on separate consent flags.
- Send from the clinic’s number and a shared inbox, not staff personal phones.
Whatever messaging tool you use, check that each send is recorded against the patient and that a marketing opt-out does not block receipts or medical certificates.
Frequently asked questions
Does the PDPA apply to a small GP clinic?
Yes. The PDPA applies to private organisations in Singapore regardless of size, so a single-doctor clinic has the same obligations as a group. What changes with size is how elaborate your policies and controls need to be, not whether they are needed.
Can our clinic still ask patients for their NRIC?
Yes, for identification. PDPC’s NRIC guidelines use a GP clinic as an example of where collecting NRIC numbers is justified to keep accurate medical records. What must stop by 31 December 2026 is using full or partial NRIC numbers to authenticate people, for example to confirm a caller’s identity or as a login password.
Do WhatsApp appointment reminders need a DNC check?
Generally no. PDPC’s healthcare guidelines say a message sent solely to remind a patient of an appointment is unlikely to be a specified message. Promotional messages to Singapore numbers do need a DNC check within 21 days of sending, unless you hold clear and unambiguous consent or an exclusion such as an ongoing relationship applies.
How long must a clinic keep medical records in Singapore?
Under MOH’s licence conditions for HCSA licensees, electronic patient health records must be kept for the patient’s lifetime plus 6 years, and paper outpatient records for 6 years from the last consultation. High-risk cases need at least 15 years, and records tied to legal or disciplinary proceedings must be kept until those end.
Can a patient ask us to delete their medical records?
A patient can withdraw consent for future uses, but the PDPA lets a clinic keep data where another legal basis applies, and MOH’s retention periods are such a basis. Explain what you must keep and why, stop any optional uses such as marketing, and record the request.
When do we have to report a data breach to PDPC?
When it is likely to cause significant harm to the individuals affected, or involves 500 or more people. Assess within 30 calendar days of having credible grounds to suspect a breach, then notify PDPC no later than 3 calendar days after deciding it is notifiable.
Sources
- PDPC — Advisory Guidelines for the Healthcare Sector (revised 20 September 2023)
- PDPC — Guide on Managing and Notifying Data Breaches under the PDPA
- Personal Data Protection (Notification of Data Breaches) Regulations 2021
- PDPC — Advisory Guidelines on the PDPA for NRIC and other National Identification Numbers
- PDPC — Organisations to cease the use of NRIC numbers for authentication by 31 December 2026
- PDPC — Advisory Guidelines on the Do Not Call Provisions (revised 1 February 2021)
- MOH Circular 85/2022 — Licence Conditions on the Retention Periods of Patient Health Records
- PDPC — Advisory Guidelines on Enforcement of the Data Protection Provisions (1 October 2022)
Primary sources checked on the date above. Schemes and requirements change — always confirm against the latest official notice.
This article is general information for clinic operators, not legal, regulatory or financial advice.