Bidda Sovereign Intelligence · 10,099 Verified Nodes · 39 Sovereign Pillars

Singapore Singpass and National Digital Identity Framework under the PDPA

Singpass is Singapore's National Digital Identity (NDI) platform, operated by the Government Technology Agency of Singapore (GovTech) on behalf of the…

What Singapore Singpass and National Digital Identity Framework under the PDPA requires

Singpass is Singapore's National Digital Identity (NDI) platform, operated by the Government Technology Agency of Singapore (GovTech) on behalf of the Smart Nation and Digital Government Office. Singpass provides authentication, digital signing through Sign with Singpass, attribute sharing through Myinfo, and face verification through the Singpass Face Verification service. Authentication is grounded in the Singapore National Registration Identity Card (NRIC) number issued under the National Registration Act 1965 and the Personal Data Protection Act 2012 (PDPA). The PDPA imposes data protection obligations on private-sector organisations using Singpass-derived data including consent, purpose limitation, notification, access and correction, accuracy, protection, retention limitation, transfer limitation, openness, and accountability. Singpass requires two-factor authentication for transactional access, supporting passwords plus one-time-passwords or Singpass app push notification, and offers QR-code Singpass app authentication and SMS-based one-time-password for legacy users. The Singpass face verification service uses 1:1 biometric matching against the national identity database and is governed under the PDPA Advisory Guidelines on the use of personal data for biometric authentication. Myinfo provides API-based government-verified data sharing to over 2,700 services with consent of the citizen under PDPA Section 14. The Personal Data Protection Commission (PDPC) is the supervisory authority under the PDPA with powers under Part IX to investigate breaches, issue directions, and impose financial penalties up to ten percent of annual turnover for serious contraventions.

Pillar: Data Protection & Privacy · Authority: Government Technology Agency of Singapore and Personal Data Protection Commission · Version: 1.0.0 · Last updated:

Primary source: https://sso.agc.gov.sg/Act/PDPA2012?WholeDoc=1

SHA-256 integrity: 22127c7d142a82066907c63fdfa2ca8396da8bf0cefd74d182507e34589108a8

Primary Citations — 7 traced to source

  • Personal Data Protection Act 2012 (Singapore) Section 13: An organisation shall not collect, use, or disclose personal data about an individual unless the individual gives, or is deemed to have given, his consent to the collection, use or disclosure.
  • Personal Data Protection Act 2012 Section 14: Consent must be given freely and the purpose for which personal data will be collected, used, or disclosed must be communicated.

+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.