· Giraffe
PDPA for a Singapore Shopify store
Every Shopify order is a pile of personal data: names, emails, phone numbers, shipping addresses, and sometimes payment-related details. In Singapore, the Personal Data Protection Act 2012 (PDPA) sets the rules for how organisations collect, use, disclose and protect that information. You don't need a legal team to get the basics right, but you do need a privacy notice, a named Data Protection Officer, and a clear split between "data needed to ship the order" and "data used for marketing".
This is general information, not legal advice. What the PDPA requires depends on your facts, so check the Personal Data Protection Commission (PDPC), the Act on Singapore Statutes Online, or a lawyer before you act.
The short version
- If you run a Singapore store that takes customer details, the PDPA almost certainly applies, even if you're a one-person shop.
- Appoint a Data Protection Officer (DPO) and publish their business contact (your own email is fine for a small store).
- Order fulfilment can usually rely on deemed consent where sharing is reasonably necessary to complete the sale. Marketing needs its own consent.
- Use Shopify's Settings > Customer privacy to publish a privacy policy, and review Shopify Network Intelligence.
- For SMS marketing to Singapore numbers, check the Do Not Call (DNC) Registry or keep clear recorded consent.
- Notifiable breaches: assess quickly, then notify PDPC within three calendar days of deciding the breach is notifiable.
Does the PDPA apply to your Shopify store?
Yes, for almost every merchant reading this. The PDPA governs how organisations collect, use and disclose individuals' personal data in Singapore. Personal data is information that identifies a person on its own or with other information you hold — so a checkout name plus email and address qualifies.
PDPC materials and the Act treat organisations broadly. Sole proprietors and small e-commerce sellers are in scope. Individuals acting in a purely personal or domestic capacity are not, but selling products through a Shopify store is a business activity. If you have already registered with ACRA, that does not create a PDPA exemption — it just makes your business easier to identify.
You remain responsible for customer personal data even when tools process it for you. Shopify's Singapore Data Processing Addendum treats you as the controller for merchant customer data processed to run your store, and Shopify as a processor for those services (with separate controller roles for certain Enhanced Services). Apps, couriers and payment providers sit in the same chain: you still need a lawful basis and a privacy notice that matches reality.
Appoint a Data Protection Officer
Section 11 of the PDPA requires every organisation to designate one or more individuals responsible for ensuring compliance, usually called the Data Protection Officer. For a small Shopify store that can be you. PDPC's guidance says the role can sit with one person, be shared among staff, or be outsourced.
You must make the DPO's business contact information available to the public. Put it in your privacy policy and, ideally, in the store footer. From 1 September 2026, PDPC's regulations also treat a record on the Commission's website as a prescribed way to make that contact available, and PDPC invites organisations to register DPO details in its registry. Publishing the contact on your own site still satisfies the core duty; registration helps customers and PDPC find you.
Designating a DPO does not hand your legal duties to that person. The organisation stays responsible.
Consent for orders versus consent for marketing
The Consent Obligation is where new merchants usually overthink — or underthink — the checkout.
What you can usually do without a separate tick-box
Under sections 13 to 15 of the PDPA, you need consent (or a valid exception) before collecting, using or disclosing personal data. Deemed consent covers a lot of ordinary e-commerce:
- If a customer voluntarily gives you their details to buy something, they are generally deemed to consent to uses that are reasonable for that purpose.
- Deemed consent by contractual necessity lets you disclose data to another organisation when that is reasonably necessary to conclude or perform the contract — for example sharing a delivery address with a courier, or payment details with a gateway.
PDPC's own examples for e-commerce follow that pattern: the retailer, platform, payment provider and logistics chain can process what is reasonably necessary to fulfil the purchase. Disclosing more than you need, or using the data later for a new purpose, is a different story.
What still needs a clear marketing opt-in
Promotional emails, SMS blasts and remarketing lists are not "necessary to deliver the parcel". Do not make marketing consent a condition of buying the product — section 14 says that kind of consent is invalid if it goes beyond what is reasonable to provide the service.
In Shopify, keep fulfilment and marketing separate:
- Use the checkout options for email and SMS marketing so customers can opt in deliberately.
- Consider double opt-in for email lists if you want cleaner consent records (Settings linked from Customer privacy > Marketing settings).
- Record who opted in, when, and through which channel. If someone withdraws consent, stop using their data for that purpose and tell them the practical consequences.
Privacy policy and Settings > Customer privacy
The Notification Obligation means individuals should know why you collect their data. On a storefront, that is your privacy policy.
Shopify puts the controls under Settings > Customer privacy:
- Privacy policy. New stores get automated privacy settings by default. Review the generated text. Add your DPO contact, describe what you collect at checkout and through apps, say how long you keep order data, and explain how customers can ask for access or deletion.
- Shopify Network Intelligence. When this is on, Shopify may use your customer data together with data from other merchants for Enhanced Services (personalisation, ads, performance tools). Shopify's DPA and help docs say you must disclose this, including a link to Shopify's Consumer Privacy Policy where required. You can disable it, but some apps and features stop working.
- Cookie banner. Automated settings turn the banner on for UK/EEA visitors when those markets are active. Singapore does not have an EU-style cookie law, but PDPA still applies to personal data collected via tracking. You can enable the banner for Singapore if you want a clearer consent story for analytics and ads pixels. Shopify's banner covers Shopify tools; third-party pixels may need their own consent handling.
- Data sharing opt-out page. More important if you sell into regions that require a "do not sell/share" control. Still useful transparency if you run network-based advertising features.
Shopify's help centre is clear that automated privacy settings are not a substitute for legal advice. Read the policy like a customer would. If it mentions tools you never installed, fix it.
Marketing: email, SMS and the Do Not Call Registry
Two regimes often overlap for Singapore sellers:
- PDPA — consent and purpose limitation for using personal data in marketing.
- Do Not Call provisions in the PDPA — extra rules for specified messages sent to Singapore telephone numbers (voice, text, fax).
Before you SMS a promotional offer to a Singapore number, either check the DNC Registry and confirm the number is not listed on the relevant register, or hold clear and unambiguous consent in a form you can retrieve later (a ticked SMS marketing box at checkout with a timestamp is the usual pattern). Ongoing-relationship exemptions exist for some text messages related to an existing customer relationship, but they are narrow — do not treat every past buyer as fair game forever. Include a way to opt out.
Email marketing is mainly handled under the Spam Control Act rather than the DNC Registry. Still get PDPA consent for marketing use, include a working unsubscribe, and honour opt-outs promptly. If you also take local payments, keep marketing lists separate from the reconciliation work covered in our PayNow and GrabPay guide.
Access, correction and deletion requests
Customers can ask what personal data you hold and how you have used or disclosed it in the past year, and can ask you to correct errors. The Act says respond as soon as reasonably possible. PDPC guidance and the Personal Data Protection Regulations treat 30 calendar days as the practical checkpoint: if you need longer, tell the person within those 30 days when you will respond.
Shopify gives you admin tools for this:
- Request customer data from the customer profile (More actions) to export what Shopify holds for that customer on your store.
- Erase personal data to redact personal details such as name and address. Order economics can remain in anonymised form for your records. You have about 10 days to cancel a pending erasure. You are still responsible for telling other companies you shared the data with (apps, email tools, freelancers).
Retention is a separate duty. Section 25 says stop keeping personal data, or anonymise it, when the original purpose is over and you no longer need it for legal or business reasons. "Keep forever in case we remarket" is not a retention policy. Align backups, CSV exports and abandoned-app spreadsheets with that rule.
Sending data overseas (including to Shopify)
Section 26 of the PDPA limits transfers of personal data outside Singapore unless you ensure a comparable standard of protection. Using Shopify necessarily involves cross-border processing. Shopify's Singapore DPA states that customer personal data may be transferred and processed in countries where Shopify, affiliates or service providers are located, including Singapore and Canada, and that those transfers are made in compliance with applicable data protection laws. Shopify's help docs also note that its group and subprocessor agreements include protections aimed at Singapore's transfer rules.
Practical checklist:
- Read and keep a copy of the Shopify DPA that applies to your account.
- Check Settings > Customer privacy for the stated customer data hosting location.
- Before installing an app that syncs customer lists to another SaaS tool, skim that vendor's processing terms the same way.
- When you share addresses with carriers for fulfilment, limit the fields to what delivery needs — the same discipline covered in our Singapore shipping guide.
If something goes wrong: breach notification
A data breach under the PDPA includes unauthorised access, collection, use, disclosure, copying, modification or disposal of personal data, and loss of a device where that unauthorised access is likely.
Once you have credible grounds to believe a breach happened, you must assess whether it is notifiable. PDPC's guide expects a reasonable, documented assessment, generally within 30 calendar days. A breach is notifiable if it is likely to cause significant harm to affected individuals (including where prescribed categories of sensitive data are involved), or if it affects 500 or more individuals.
When you determine a breach is notifiable:
- Notify PDPC as soon as practicable, and no later than three calendar days after that determination (the clock starts the day after you decide).
- Notify affected individuals as soon as practicable when required, at the same time or after notifying PDPC.
- Submit through PDPC's breach notification e-service. Keep notes of containment steps — PDPC's C.A.R.E. framing (Contain, Assess, Report, Evaluate) is a workable incident checklist for a small team.
Shopify's DPA requires Shopify to notify you of confirmed personal data breaches affecting your customer personal data that it processes. That notice helps you meet your own PDPA clock; it does not replace your duty to assess and, where required, notify PDPC.
Financial stakes are real. For organisations, section 48J caps financial penalties at S$1 million, or 10% of annual turnover in Singapore if that turnover exceeds S$10 million — whichever framework applies to the case. Most early-stage stores will never see those numbers, but "we're small, so PDPA can wait" is not how the Act is written.
A practical setup order for a new Singapore store
- While you follow the usual store launch checklist, open Settings > Customer privacy and publish a privacy policy that names your DPO.
- Decide whether Shopify Network Intelligence stays on; update the policy if it does.
- Turn on separate email/SMS marketing opt-ins at checkout. Leave them unchecked by default.
- List every app that can read customers or orders. Remove ones you no longer use.
- Write a one-page breach plan: who assesses, who notifies PDPC, where the PDPC e-service bookmark lives.
- Once a year, export a sample customer record request for yourself so you know the button still works.
FAQ
Does the PDPA apply to a small Shopify store in Singapore?
Yes. The PDPA applies to organisations that collect, use or disclose personal data in Singapore, including sole proprietors and small online shops. There is no minimum staff count or revenue threshold before you need a Data Protection Officer, a privacy notice and reasonable security. Individuals acting in a purely personal or domestic capacity are outside the PDPA, but selling through a store is a business activity.
Do I need a separate marketing tick-box at checkout?
For fulfilling an order, deemed consent by contractual necessity under the PDPA usually covers sharing name, address and contact details with Shopify, payment providers and couriers when that is reasonably necessary to complete the sale. Marketing is different. Do not bundle a marketing opt-in into the purchase itself. Use Shopify's email and SMS marketing checkboxes at checkout, keep marketing consent separate, and for SMS to Singapore numbers either check the Do Not Call Registry or keep clear recorded consent.
Where do I set up a privacy policy in Shopify?
Go to Settings > Customer privacy. New stores get automated privacy settings by default, including a privacy policy template. Review that text so it matches what you actually collect, which apps you use, and whether Shopify Network Intelligence is on. Publish the policy, put your Data Protection Officer contact in it, and link to Shopify's Consumer Privacy Policy when your Shopify agreements require that disclosure.
What if customer data is leaked from my store or an app?
Assess promptly whether the breach is notifiable. Under the PDPA you generally have up to 30 calendar days to assess, then if it is notifiable you must tell the Personal Data Protection Commission as soon as practicable and no later than three calendar days after that determination. Notify affected individuals as soon as practicable when required, at the same time or after notifying the Commission. Shopify's Data Processing Addendum says Shopify will notify you of confirmed breaches of your customer personal data that it processes.
Can Shopify store my Singapore customers' data overseas?
Yes, with safeguards. Shopify's Singapore Data Processing Addendum says customer personal data may be transferred and processed in countries where Shopify, affiliates or service providers operate, including Singapore and Canada, and that transfers are made in compliance with applicable data protection laws. Your Transfer Limitation Obligation under the PDPA still applies: you need a comparable standard of protection for data sent overseas, which for Shopify is typically addressed through that addendum and related transfer terms. Review Settings > Customer privacy for hosting location details, and check each app's own processing terms.
A reminder: this guide is general information, not legal advice. PDPA obligations depend on your products, apps and customer locations, so check PDPC or a professional for your situation.
If you're setting up a Singapore store, a Shopify trial is enough room to publish a privacy policy, test marketing opt-ins and walk through a sample data request before launch.
References
Rules and product settings change, so check the live page before you act on anything here.
- Personal Data Protection Act 2012, Singapore Statutes Online. Accessed 4 Oct 2026.
- PDPA section 11 (Compliance with Act; DPO), Singapore Statutes Online. Accessed 4 Oct 2026.
- PDPA Part 4 (Consent, notification, purpose limitation), Singapore Statutes Online. Accessed 4 Oct 2026.
- PDPA section 21 (Access to personal data), Singapore Statutes Online. Accessed 4 Oct 2026.
- PDPA section 24 (Protection of personal data), Singapore Statutes Online. Accessed 4 Oct 2026.
- PDPA section 25 (Retention of personal data), Singapore Statutes Online. Accessed 4 Oct 2026.
- PDPA section 26 (Transfer of personal data outside Singapore), Singapore Statutes Online. Accessed 4 Oct 2026.
- PDPA section 48J (Financial penalties), Singapore Statutes Online. Accessed 4 Oct 2026.
- Personal Data Protection (Amendment No. 2) Regulations 2026, Singapore Statutes Online. Accessed 4 Oct 2026.
- Personal Data Protection Commission Singapore, PDPC. Accessed 4 Oct 2026.
- Accountability, PDPC. Accessed 4 Oct 2026.
- Kickstart Your Data Protection Journey, PDPC. Accessed 4 Oct 2026.
- Appoint a Data Protection Officer. It's mandatory., PDPC. Accessed 4 Oct 2026.
- Advisory Guidelines on Key Concepts in the PDPA, PDPC (17 May 2022). Accessed 4 Oct 2026.
- Draft Advisory Guidelines on Key Provisions of the PDP (Amendment) Bill, PDPC (includes e-commerce contractual necessity example). Accessed 4 Oct 2026.
- Guide on Managing and Notifying Data Breaches under the PDPA, PDPC (revised 15 Mar 2021). Accessed 4 Oct 2026.
- Required to Notify The PDPC, PDPC. Accessed 4 Oct 2026.
- Advisory Guidelines on the Do Not Call Provisions, PDPC (1 Feb 2021). Accessed 4 Oct 2026.
- Unsolicited Marketing Calls, PDPC. Accessed 4 Oct 2026.
- Guide to Handling Access Requests, PDPC. Accessed 4 Oct 2026.
- Spam Control Act 2007, Singapore Statutes Online. Accessed 4 Oct 2026.
- Shopify Data Processing Addendum, Shopify Singapore. Accessed 4 Oct 2026.
- Shopify Consumer Privacy Policy, Shopify Singapore. Accessed 4 Oct 2026.
- Configuring customer privacy settings, Shopify Help Center. Accessed 4 Oct 2026.
- Understanding customer privacy settings in your Shopify admin, Shopify Help Center. Accessed 4 Oct 2026.
- Processing customer data requests, Shopify Help Center. Accessed 4 Oct 2026.
- Onward transfers of personal data, Shopify Help Center. Accessed 4 Oct 2026.
- Breach of the Transfer Limitation Obligation by Shopify Commerce Singapore and Supernova, PDPC decision summary. Accessed 4 Oct 2026.