A Singapore business is not subject to the EU GDPR merely because its website can be viewed in Europe. The GDPR may apply when the business has an EU establishment, offers goods or services to people in the EU, or monitors their behaviour there. Singapore PDPA compliance does not automatically equal GDPR compliance. Start with territorial scope, then map processing, roles, legal bases, individual rights, transfers, contracts and governance for qualified review.

Test territorial scope before building a GDPR checklist

Article 3 of the GDPR covers processing in the context of an EU establishment and can also apply to a controller or processor outside the EU when processing relates to offering goods or services to people in the EU or monitoring their behaviour there. The European Data Protection Board and Singapore PDPC describe these triggers for non-EU organisations.

Mere website accessibility from Europe is not the whole test. Record the countries targeted, languages and currencies used, delivery or service availability, EU customer journey, advertising, behavioural tracking and any EU group presence. Obtain advice where the targeting or monitoring analysis is uncertain.

  • EU establishments or group operations connected to processing
  • Goods or services intentionally offered to people in the EU
  • Behaviour monitoring that takes place in the EU
  • Evidence supporting the scope conclusion

Keep the Singapore PDPA and EU GDPR as separate regimes

The PDPC states that PDPA compliance does not necessarily mean GDPR compliance because the regimes have different requirements. A company may need to satisfy both for the same product or data flow, but the legal analysis and evidence should not be merged into one generic privacy label.

Keep a requirement map with separate columns for the PDPA, GDPR and any sector rules. Identify overlap that can share operational controls, then preserve the distinct conditions, rights, deadlines and documentation required under each regime.

  • Applicable law and processing scope
  • Organisation's role for each data flow
  • Shared control and regime-specific evidence
  • Questions that need jurisdiction-specific advice

Map processing before selecting controls or documents

Create a processing inventory for EU-facing customers, users, employees, prospects and vendor operations. For each activity, record the personal data, individuals, purpose, system, location, recipient, retention period, security owner and transfer route.

Distinguish controller, joint-controller and processor questions rather than assigning labels from contract titles alone. Connect the inventory to actual product workflows, analytics, support, sales, hiring and infrastructure so the review reflects what the business does.

  • Individuals and personal-data categories
  • Purpose, system, owner and retention period
  • Controller or processor role requiring confirmation
  • Recipients, vendors and cross-border transfer path

Review legal bases, notices and individual rights together

For processing within GDPR scope, document the proposed legal basis and the facts supporting it. Align the purpose and basis with the privacy information shown to individuals and with the choices implemented in the product. Do not treat consent as a universal default or copy a basis from another service.

Map how the business can receive, verify, route and answer applicable requests concerning access, correction, deletion, restriction, objection or portability. Test whether the data inventory, vendors and retention controls can produce the required response rather than relying on policy wording alone.

  • Purpose and proposed legal basis by activity
  • Privacy notice and product interaction consistency
  • Request intake, identity verification and response owner
  • Exceptions or conflicts requiring qualified review

Reconcile vendors, transfers and contract roles

List each vendor and group recipient that receives EU-related personal data, where processing occurs and whether onward transfers are possible. Review the actual services, security measures, subprocessors, deletion process, incident path and audit evidence.

Separately assess GDPR transfer requirements and Singapore's PDPA Transfer Limitation Obligation. The PDPC says overseas transfers from Singapore must meet prescribed requirements for a comparable standard of protection unless an exemption applies. Do not assume one contractual clause resolves both regimes.

  • Vendor role and processing instructions
  • Hosting, support and subprocessor locations
  • Transfer mechanism and supplementary questions
  • Security, deletion, incident and audit evidence

Confirm governance appointments only after the facts are known

A Singapore organisation should already identify its PDPA accountability owner and DPO arrangements. GDPR questions about an EU representative, data protection officer, records of processing and impact assessments depend on the organisation's scope, scale, risk and processing activities.

Record the facts that drive each appointment or documentation decision. Do not publish a broad statement that every Singapore company needs an EU representative or GDPR DPO. Route uncertain conclusions to qualified counsel and retain the decision record.

  • Singapore DPO and privacy governance owner
  • EU representative analysis where relevant
  • GDPR DPO and records-of-processing questions
  • Risk and impact-assessment triggers requiring review

Build a review pack that can be tested against reality

Prepare a concise scope memorandum, processing inventory, data-flow map, vendor register, contract set, notices, request procedures, retention schedule, incident plan and evidence of implemented controls. Mark assumptions and unresolved facts instead of filling gaps with generic language.

Review the pack with the product, security, operations and legal owners who can confirm actual behaviour. Prioritise gaps that affect live EU-facing processing, then track decisions, implementation evidence and review dates.

  • Territorial-scope memorandum and evidence
  • Processing inventory and data-flow map
  • Vendor, transfer and contract register
  • Notices, rights, retention, security and incident evidence

Sources and discussion

Related resources

Prepare the next step

Use JurisLane's cross-border privacy compliance checklist to map owners and evidence across the PDPA, GDPR, vendors and transfers, then have the scope and legal conclusions reviewed for the actual business and jurisdictions.

Explore JurisLane services

Editorial note: This guide supports issue preparation and qualified review. Applicable requirements depend on the facts, entities, markets and current law.