Agent Knowledge Series

PDPA Obligations for Singapore Property Agents 2026

The Personal Data Protection Act (PDPA) imposes obligations on CEA-registered property agents when they collect, use, disclose, and retain client personal data. Violations carry financial penalties and reputational risk. This guide covers the core PDPA obligations that apply to property agents in Singapore — including the Do Not Call registry, data consent, storage limits, and data breach response.

Disclaimer (Block 1): This article is for educational purposes only and is intended to assist CEA-registered property agents in understanding regulatory frameworks. It does not constitute financial, tax, or legal advice. LEVR's calculations are indicative only. Always verify rates and eligibility with your bank, HDB, CPF Board, or a licensed financial advisor before advising clients.

What Is the PDPA and Who Does It Apply To?

The Personal Data Protection Act (PDPA) is Singapore's primary data protection legislation, administered by the Personal Data Protection Commission (PDPC). It governs the collection, use, disclosure, and retention of personal data about individuals (data subjects) by organisations and individuals conducting activities in Singapore.

CEA-registered property agents are subject to the PDPA in their professional practice. When an agent collects a client's name, NRIC number, contact details, financial information, or property preferences — whether for a buyer representation, seller listing, or rental transaction — that information is personal data and must be handled in compliance with PDPA obligations.

Core PDPA Obligations for Property Agents

The PDPA imposes nine data protection obligations on organisations and individuals collecting personal data. The most practically relevant for property agents are:

  • Consent obligation: Personal data may only be collected, used, or disclosed with the individual's knowledge and consent. Consent must be voluntary, informed, and obtained before the data is collected or used for a new purpose. Deemed consent applies where the individual voluntarily provides data in circumstances where a reasonable person would expect it to be used for a specific purpose.
  • Purpose limitation obligation: Personal data may only be collected and used for purposes that a reasonable person would consider appropriate, and which are communicated to the individual. An agent who collects a buyer's contact details for one transaction may not use those details to market unrelated services without separate consent.
  • Notification obligation: Individuals must be notified of the purposes for which their data is being collected before or at the time of collection. Agents should inform clients why their data is being collected and how it will be used.
  • Access and correction obligation: Individuals have the right to request access to their personal data held by the agent and to request corrections. Agents must respond to such requests within a reasonable timeframe.
  • Retention limitation obligation: Personal data should not be retained longer than is necessary for the business purpose for which it was collected. Agents should establish a data retention policy and securely dispose of client data once the purpose has been fulfilled.
  • Protection obligation: Reasonable security arrangements must be made to protect personal data from unauthorised access, collection, use, disclosure, or other risks. This includes securing physical documents, password-protecting digital files, and avoiding sharing client data via unsecured messaging channels.

The Do Not Call (DNC) Registry

The DNC Registry is a separate component of the PDPA that specifically governs unsolicited marketing calls and messages. Key rules for property agents:

  • Before making a telemarketing call (including calls offering property listings, rental opportunities, or agent services), the agent must check whether the recipient's number is registered on the DNC Registry
  • Sending unsolicited marketing text messages or fax messages to DNC- registered numbers is prohibited. This includes mass WhatsApp blasts, SMS campaigns, and property listing pushes to contacts who have not opted in
  • The DNC obligation applies regardless of whether the number belongs to an existing client or a new prospect — even past clients retain DNC protection once registered
  • Exceptions apply where the individual has given clear consent to receive marketing messages from the specific agent or agency, or where there is an ongoing business relationship and the message relates to goods or services in that relationship
Marketing ChannelDNC Check Required?Notes
Telemarketing call (voice)YesMust check before calling; DNC registration blocks unsolicited marketing calls
SMS / text message (marketing)YesIncluding WhatsApp if used for mass unsolicited marketing
Email marketingNo (separate rules apply)Email is governed by spam provisions, not the DNC registry; opt-out mechanism required
Personal WhatsApp (individual contact)Judgment requiredIndividual messages to known contacts are generally not unsolicited marketing; mass broadcasts to unknown contacts are

Data Breach Obligations

Singapore's PDPA includes mandatory data breach notification requirements that came into force in February 2021. Agents must be aware of the following:

  • A data breach that affects the personal data of 500 or more individuals, or that is likely to result in significant harm to the affected individuals, must be notified to the PDPC within 3 calendar days of the agent becoming aware of the breach
  • Individuals whose data is affected by a notifiable breach must also be notified as soon as practicable
  • Even below the notification threshold, the agent must document the breach, assess the impact, and take remedial action
  • Common property agent scenarios that could constitute a data breach: loss or theft of a mobile device containing client data; sending client financial information to the wrong email recipient; an unauthorised third party accessing the agent's contact database

Practical PDPA Compliance Steps for Agents

  • Use a simple data collection form or verbal notification at the start of each client relationship that specifies the purposes for which personal data is being collected
  • Obtain written or recorded consent before sharing client data with third parties (co-brokers, banks, legal firms, insurance advisors)
  • Implement a data retention schedule: determine how long you need to retain client documents after a transaction closes, and securely dispose of documents that are no longer needed
  • Check the DNC Registry before any telemarketing or unsolicited marketing message campaign
  • Store sensitive client documents (NRIC, financial statements) in password-protected folders or encrypted storage — not in open chat threads
  • If your agency has a data protection policy, follow it; if it does not, raise it with your team leader or KEO

Frequently Asked Questions

Q: Can I keep client contact details after a transaction is complete to market future listings?

A: Generally yes, provided you have the client's consent for ongoing marketing and the client has not withdrawn consent or registered on the DNC. However, you cannot indefinitely retain sensitive financial documents (NRIC, bank statements, income documents) collected for a specific transaction under the PDPA's retention limitation obligation. Marketing contacts and sensitive transaction documents should be treated differently — consult your agency's data protection policy or seek advice from a data protection officer.

Q: What are the penalties for PDPA violations by property agents?

A: The PDPC can issue financial penalties of up to S$1 million for organisations (and in some cases individuals) that breach PDPA obligations. For agents operating as sole practitioners, the penalty can be directed personally. Beyond financial penalties, the PDPC can issue directions to stop collection, processing, or disclosure of data; require remediation; and publish its enforcement decisions publicly. Reputational damage from a published enforcement action can be significant for a CEA-registered salesperson who relies on referrals and professional reputation.

Q: Does the PDPA apply to my WhatsApp conversations with clients?

A: Yes. Personal data shared via WhatsApp (including NRIC numbers, financial details, property addresses, and contact information) is subject to the PDPA in the same way as data stored in any other format. Agents should avoid asking clients to send sensitive documents via WhatsApp if the data will not be adequately secured after receipt. Using unencrypted personal WhatsApp accounts to store sensitive client financial documents creates risk if the device is lost or compromised.

Disclaimer (Block 3): LEVR's calculator outputs are estimates based on inputs provided and current regulatory parameters as known at time of publication. They are not a guarantee of borrowing capacity, stamp duty liability, or CPF eligibility. Regulatory thresholds and rates may change. Always verify with IRAS, your bank, or a licensed financial advisor before making financial decisions.

For CEA Agents

Get the 2026 ABSD Rate Guide — free

A quick-reference PDF with every ABSD rate by buyer profile. Updated for 2026 and sourced to IRAS.

Need expert guidance?

Find a verified property agent with a proven track record in your town.

Find an Agent

Run property scenarios without storing sensitive client data.

LEVR is built for CEA agents who need professional calculation tools that keep client data secure and compliant.

Essentials tier available. No credit card required.

Or find a property agent near you →