Growth Marketing Glossary

Personal Data Protection Act (PDPA)

pee dee pee aynoun

A shared name, several laws. Personal Data Protection Act (PDPA) is the title used by several national privacy laws — Singapore's, Thailand's, Malaysia's — so the country always has to be specified.

personal data in a countrya PDPA governslawful handling
Schematic — a national data law constraining personal-data handling
Term
Personal Data Protection Act (PDPA)
Is
Name shared by several national privacy laws
Examples
Singapore (2012), Thailand (2022), Malaysia
Note
Always specify the country

Parts of speech & senses

personal data protection act · noun
  1. Personal Data Protection Act (PDPA) is the name shared by several countries' data-protection laws, most notably Singapore's (2012) and Thailand's (in force from June 2022). "Which PDPA — Singapore's or Thailand's — applies here?"

What a PDPA is

A Personal Data Protection Act (PDPA) is a national data-protection law — but the key thing to understand is that PDPA is not one law. It is a name used by several different countries for their own data-protection statutes, so the term is ambiguous unless the country is named. The most prominent is Singapore's Personal Data Protection Act, first enacted in 2012, which governs how organizations collect, use, and disclose personal data in Singapore and is overseen by the Personal Data Protection Commission. Thailand also has a Personal Data Protection Act, often compared to the EU's GDPR, which came into full force in June 2022. Malaysia has its own Personal Data Protection Act as well. Each of these PDPAs is a distinct law with its own rules, regulator, scope, and timeline. Because of this, the honest way to use the term is always to specify which country's PDPA you mean.

This shared name matters because confusing one country's PDPA with another's leads to real compliance mistakes. Singapore's PDPA and Thailand's PDPA address the same broad goal — protecting personal data — but they are separate laws with different definitions, consent rules, transfer requirements, and penalties, enforced by different authorities. A company operating across Southeast Asia cannot treat compliance with one as compliance with the others. For marketers and operators, the practical point is that entering a market with a PDPA means identifying that specific country's act and its requirements, not assuming a generic regional standard. The PDPA family reflects a broader wave of national privacy laws across Asia, many of them GDPR-influenced, but each remains its own statute.

Which PDPA — Singapore, Thailand, Malaysia

The clearest way to handle the PDPA name is to anchor it to a country. Singapore's PDPA, enacted in 2012, is the best known and one of the earlier comprehensive privacy laws in the region; it has been amended over time, including stronger penalties, and is enforced by the Personal Data Protection Commission. Thailand's PDPA is newer and more GDPR-like in flavor; after delays it came into full force in June 2022, with its own regulator and subordinate regulations still developing. Malaysia's Personal Data Protection Act predates both in some respects and has been subject to amendment as well. These are genuinely different laws that happen to share a name — and other jurisdictions use similar titles too — so the country is not an optional detail but the thing that determines which rules apply.

The distinction matters because each PDPA sets its own requirements for consent, notice, data transfers, breach handling, and penalties, and each is enforced by its own authority. A program built for Singapore's PDPA does not automatically satisfy Thailand's, and vice versa, even though both share principles familiar from the GDPR. The right approach is to identify exactly which country's PDPA governs the data in question and map your practices against that specific law. Broad privacy hygiene — a lawful or consented basis for processing, transparency, security, honoring data rights — travels across all of them, but the governing detail is always national. Treating PDPA as a single regional standard is the mistake to avoid.

Working within a PDPA

Working within a PDPA well starts with naming the country — Singapore, Thailand, Malaysia, or another — because that determines which law and regulator apply. From there it means building compliance around that specific act's requirements: the basis for collecting and using personal data, the notice and consent rules, the handling of data transfers, breach obligations, and the rights the law gives people. For a business operating across several Southeast Asian markets, it means treating each country's PDPA as a separate compliance obligation rather than a single regional one, and designing consent and data handling for each audience against the law that actually governs it. Shared privacy hygiene provides a common foundation, but the specific PDPA sets the binding rules.

The failures are treating PDPA as one law and assuming compliance with one country's act covers another, failing to identify which PDPA governs a given data flow, and overlooking the differences in consent, transfer, and breach rules between the Singapore, Thailand, and Malaysia versions. The discipline is to specify the country first, map your practices against that particular PDPA and its regulator, and treat each national act as its own obligation — relying on shared GDPR-style hygiene as a base while respecting that the governing requirements, timelines, and penalties differ from one PDPA to the next.

Worked example. A retailer expands across Southeast Asia and builds its privacy program around Singapore's Personal Data Protection Act, assuming one program covers the region. Entering Thailand, it discovers Thailand's PDPA — in full force since June 2022 and more GDPR-like — has its own consent, transfer, and breach rules and its own regulator. The team treats each country's PDPA as a separate obligation, mapping its practices against the specific act that governs each market. The lesson: PDPA is a name shared by several distinct national laws, so the country must be specified, and compliance with one country's PDPA does not satisfy another's. (Illustrative; RGM analysis.)
Failure modes to watch. Treating PDPA as one law and assuming compliance with one country's act covers another; failing to identify which PDPA governs a given data flow; and overlooking the differences in consent, transfer, and breach rules between the Singapore, Thailand, and Malaysia versions.

Synonyms & antonyms

Synonyms

PDPASingapore PDPAThailand PDPA

Antonyms

GDPRunregulated data use

Origin & history

Personal Data Protection Act (PDPA) — a name shared by several national data-protection laws, most notably Singapore's (2012) and Thailand's (in force 2022), so the country must always be specified.

Etymology: source.

Usage trends

Search interest for this term over the last five years:

View interest-over-time on Google Trends →

Common questions

What is the PDPA?
Personal Data Protection Act — a name shared by several countries' data-protection laws, most notably Singapore's (enacted 2012) and Thailand's (in full force from June 2022), with Malaysia and others also using the title. The country must always be specified.
Is there only one PDPA?
No. Several countries call their data-protection law a Personal Data Protection Act, and each is a distinct statute with its own rules, regulator, and timeline. Compliance with one country's PDPA does not automatically satisfy another's.
Which PDPA is best known?
Singapore's Personal Data Protection Act, enacted in 2012 and enforced by the Personal Data Protection Commission, is the most prominent, though Thailand's GDPR-like PDPA (in force from June 2022) is also widely referenced.

Resources & people to follow

Curated, non-competitor resources verified per term.

Related training

Disciplines

Areas of marketing where personal data protection act (pdpa) is a core concern:

Sources

  1. trendsGoogle Trends — "pdpa"