· Giraffe

PDPA for a Singapore Shopify store

Information checked as of 4 October 2026

Every Shopify order is a pile of personal data: names, emails, phone numbers, shipping addresses, and sometimes payment-related details. In Singapore, the Personal Data Protection Act 2012 (PDPA) sets the rules for how organisations collect, use, disclose and protect that information. You don't need a legal team to get the basics right, but you do need a privacy notice, a named Data Protection Officer, and a clear split between "data needed to ship the order" and "data used for marketing".

This is general information, not legal advice. What the PDPA requires depends on your facts, so check the Personal Data Protection Commission (PDPC), the Act on Singapore Statutes Online, or a lawyer before you act.

The short version

Does the PDPA apply to your Shopify store?

Yes, for almost every merchant reading this. The PDPA governs how organisations collect, use and disclose individuals' personal data in Singapore. Personal data is information that identifies a person on its own or with other information you hold — so a checkout name plus email and address qualifies.

PDPC materials and the Act treat organisations broadly. Sole proprietors and small e-commerce sellers are in scope. Individuals acting in a purely personal or domestic capacity are not, but selling products through a Shopify store is a business activity. If you have already registered with ACRA, that does not create a PDPA exemption — it just makes your business easier to identify.

You remain responsible for customer personal data even when tools process it for you. Shopify's Singapore Data Processing Addendum treats you as the controller for merchant customer data processed to run your store, and Shopify as a processor for those services (with separate controller roles for certain Enhanced Services). Apps, couriers and payment providers sit in the same chain: you still need a lawful basis and a privacy notice that matches reality.

Appoint a Data Protection Officer

Section 11 of the PDPA requires every organisation to designate one or more individuals responsible for ensuring compliance, usually called the Data Protection Officer. For a small Shopify store that can be you. PDPC's guidance says the role can sit with one person, be shared among staff, or be outsourced.

You must make the DPO's business contact information available to the public. Put it in your privacy policy and, ideally, in the store footer. From 1 September 2026, PDPC's regulations also treat a record on the Commission's website as a prescribed way to make that contact available, and PDPC invites organisations to register DPO details in its registry. Publishing the contact on your own site still satisfies the core duty; registration helps customers and PDPC find you.

Designating a DPO does not hand your legal duties to that person. The organisation stays responsible.

Consent for orders versus consent for marketing

The Consent Obligation is where new merchants usually overthink — or underthink — the checkout.

What you can usually do without a separate tick-box

Under sections 13 to 15 of the PDPA, you need consent (or a valid exception) before collecting, using or disclosing personal data. Deemed consent covers a lot of ordinary e-commerce:

PDPC's own examples for e-commerce follow that pattern: the retailer, platform, payment provider and logistics chain can process what is reasonably necessary to fulfil the purchase. Disclosing more than you need, or using the data later for a new purpose, is a different story.

What still needs a clear marketing opt-in

Promotional emails, SMS blasts and remarketing lists are not "necessary to deliver the parcel". Do not make marketing consent a condition of buying the product — section 14 says that kind of consent is invalid if it goes beyond what is reasonable to provide the service.

In Shopify, keep fulfilment and marketing separate:

Privacy policy and Settings > Customer privacy

The Notification Obligation means individuals should know why you collect their data. On a storefront, that is your privacy policy.

Shopify puts the controls under Settings > Customer privacy:

Shopify's help centre is clear that automated privacy settings are not a substitute for legal advice. Read the policy like a customer would. If it mentions tools you never installed, fix it.

Marketing: email, SMS and the Do Not Call Registry

Two regimes often overlap for Singapore sellers:

Before you SMS a promotional offer to a Singapore number, either check the DNC Registry and confirm the number is not listed on the relevant register, or hold clear and unambiguous consent in a form you can retrieve later (a ticked SMS marketing box at checkout with a timestamp is the usual pattern). Ongoing-relationship exemptions exist for some text messages related to an existing customer relationship, but they are narrow — do not treat every past buyer as fair game forever. Include a way to opt out.

Email marketing is mainly handled under the Spam Control Act rather than the DNC Registry. Still get PDPA consent for marketing use, include a working unsubscribe, and honour opt-outs promptly. If you also take local payments, keep marketing lists separate from the reconciliation work covered in our PayNow and GrabPay guide.

Access, correction and deletion requests

Customers can ask what personal data you hold and how you have used or disclosed it in the past year, and can ask you to correct errors. The Act says respond as soon as reasonably possible. PDPC guidance and the Personal Data Protection Regulations treat 30 calendar days as the practical checkpoint: if you need longer, tell the person within those 30 days when you will respond.

Shopify gives you admin tools for this:

Retention is a separate duty. Section 25 says stop keeping personal data, or anonymise it, when the original purpose is over and you no longer need it for legal or business reasons. "Keep forever in case we remarket" is not a retention policy. Align backups, CSV exports and abandoned-app spreadsheets with that rule.

Sending data overseas (including to Shopify)

Section 26 of the PDPA limits transfers of personal data outside Singapore unless you ensure a comparable standard of protection. Using Shopify necessarily involves cross-border processing. Shopify's Singapore DPA states that customer personal data may be transferred and processed in countries where Shopify, affiliates or service providers are located, including Singapore and Canada, and that those transfers are made in compliance with applicable data protection laws. Shopify's help docs also note that its group and subprocessor agreements include protections aimed at Singapore's transfer rules.

Practical checklist:

If something goes wrong: breach notification

A data breach under the PDPA includes unauthorised access, collection, use, disclosure, copying, modification or disposal of personal data, and loss of a device where that unauthorised access is likely.

Once you have credible grounds to believe a breach happened, you must assess whether it is notifiable. PDPC's guide expects a reasonable, documented assessment, generally within 30 calendar days. A breach is notifiable if it is likely to cause significant harm to affected individuals (including where prescribed categories of sensitive data are involved), or if it affects 500 or more individuals.

When you determine a breach is notifiable:

Shopify's DPA requires Shopify to notify you of confirmed personal data breaches affecting your customer personal data that it processes. That notice helps you meet your own PDPA clock; it does not replace your duty to assess and, where required, notify PDPC.

Financial stakes are real. For organisations, section 48J caps financial penalties at S$1 million, or 10% of annual turnover in Singapore if that turnover exceeds S$10 million — whichever framework applies to the case. Most early-stage stores will never see those numbers, but "we're small, so PDPA can wait" is not how the Act is written.

A practical setup order for a new Singapore store

  1. While you follow the usual store launch checklist, open Settings > Customer privacy and publish a privacy policy that names your DPO.
  2. Decide whether Shopify Network Intelligence stays on; update the policy if it does.
  3. Turn on separate email/SMS marketing opt-ins at checkout. Leave them unchecked by default.
  4. List every app that can read customers or orders. Remove ones you no longer use.
  5. Write a one-page breach plan: who assesses, who notifies PDPC, where the PDPC e-service bookmark lives.
  6. Once a year, export a sample customer record request for yourself so you know the button still works.

FAQ

Does the PDPA apply to a small Shopify store in Singapore?

Yes. The PDPA applies to organisations that collect, use or disclose personal data in Singapore, including sole proprietors and small online shops. There is no minimum staff count or revenue threshold before you need a Data Protection Officer, a privacy notice and reasonable security. Individuals acting in a purely personal or domestic capacity are outside the PDPA, but selling through a store is a business activity.

Do I need a separate marketing tick-box at checkout?

For fulfilling an order, deemed consent by contractual necessity under the PDPA usually covers sharing name, address and contact details with Shopify, payment providers and couriers when that is reasonably necessary to complete the sale. Marketing is different. Do not bundle a marketing opt-in into the purchase itself. Use Shopify's email and SMS marketing checkboxes at checkout, keep marketing consent separate, and for SMS to Singapore numbers either check the Do Not Call Registry or keep clear recorded consent.

Where do I set up a privacy policy in Shopify?

Go to Settings > Customer privacy. New stores get automated privacy settings by default, including a privacy policy template. Review that text so it matches what you actually collect, which apps you use, and whether Shopify Network Intelligence is on. Publish the policy, put your Data Protection Officer contact in it, and link to Shopify's Consumer Privacy Policy when your Shopify agreements require that disclosure.

What if customer data is leaked from my store or an app?

Assess promptly whether the breach is notifiable. Under the PDPA you generally have up to 30 calendar days to assess, then if it is notifiable you must tell the Personal Data Protection Commission as soon as practicable and no later than three calendar days after that determination. Notify affected individuals as soon as practicable when required, at the same time or after notifying the Commission. Shopify's Data Processing Addendum says Shopify will notify you of confirmed breaches of your customer personal data that it processes.

Can Shopify store my Singapore customers' data overseas?

Yes, with safeguards. Shopify's Singapore Data Processing Addendum says customer personal data may be transferred and processed in countries where Shopify, affiliates or service providers operate, including Singapore and Canada, and that transfers are made in compliance with applicable data protection laws. Your Transfer Limitation Obligation under the PDPA still applies: you need a comparable standard of protection for data sent overseas, which for Shopify is typically addressed through that addendum and related transfer terms. Review Settings > Customer privacy for hosting location details, and check each app's own processing terms.


A reminder: this guide is general information, not legal advice. PDPA obligations depend on your products, apps and customer locations, so check PDPC or a professional for your situation.

If you're setting up a Singapore store, a Shopify trial is enough room to publish a privacy policy, test marketing opt-ins and walk through a sample data request before launch.

Start a Shopify trial →

References

Rules and product settings change, so check the live page before you act on anything here.

  1. Personal Data Protection Act 2012, Singapore Statutes Online. Accessed 4 Oct 2026.
  2. PDPA section 11 (Compliance with Act; DPO), Singapore Statutes Online. Accessed 4 Oct 2026.
  3. PDPA Part 4 (Consent, notification, purpose limitation), Singapore Statutes Online. Accessed 4 Oct 2026.
  4. PDPA section 21 (Access to personal data), Singapore Statutes Online. Accessed 4 Oct 2026.
  5. PDPA section 24 (Protection of personal data), Singapore Statutes Online. Accessed 4 Oct 2026.
  6. PDPA section 25 (Retention of personal data), Singapore Statutes Online. Accessed 4 Oct 2026.
  7. PDPA section 26 (Transfer of personal data outside Singapore), Singapore Statutes Online. Accessed 4 Oct 2026.
  8. PDPA section 48J (Financial penalties), Singapore Statutes Online. Accessed 4 Oct 2026.
  9. Personal Data Protection (Amendment No. 2) Regulations 2026, Singapore Statutes Online. Accessed 4 Oct 2026.
  10. Personal Data Protection Commission Singapore, PDPC. Accessed 4 Oct 2026.
  11. Accountability, PDPC. Accessed 4 Oct 2026.
  12. Kickstart Your Data Protection Journey, PDPC. Accessed 4 Oct 2026.
  13. Appoint a Data Protection Officer. It's mandatory., PDPC. Accessed 4 Oct 2026.
  14. Advisory Guidelines on Key Concepts in the PDPA, PDPC (17 May 2022). Accessed 4 Oct 2026.
  15. Draft Advisory Guidelines on Key Provisions of the PDP (Amendment) Bill, PDPC (includes e-commerce contractual necessity example). Accessed 4 Oct 2026.
  16. Guide on Managing and Notifying Data Breaches under the PDPA, PDPC (revised 15 Mar 2021). Accessed 4 Oct 2026.
  17. Required to Notify The PDPC, PDPC. Accessed 4 Oct 2026.
  18. Advisory Guidelines on the Do Not Call Provisions, PDPC (1 Feb 2021). Accessed 4 Oct 2026.
  19. Unsolicited Marketing Calls, PDPC. Accessed 4 Oct 2026.
  20. Guide to Handling Access Requests, PDPC. Accessed 4 Oct 2026.
  21. Spam Control Act 2007, Singapore Statutes Online. Accessed 4 Oct 2026.
  22. Shopify Data Processing Addendum, Shopify Singapore. Accessed 4 Oct 2026.
  23. Shopify Consumer Privacy Policy, Shopify Singapore. Accessed 4 Oct 2026.
  24. Configuring customer privacy settings, Shopify Help Center. Accessed 4 Oct 2026.
  25. Understanding customer privacy settings in your Shopify admin, Shopify Help Center. Accessed 4 Oct 2026.
  26. Processing customer data requests, Shopify Help Center. Accessed 4 Oct 2026.
  27. Onward transfers of personal data, Shopify Help Center. Accessed 4 Oct 2026.
  28. Breach of the Transfer Limitation Obligation by Shopify Commerce Singapore and Supernova, PDPC decision summary. Accessed 4 Oct 2026.