PDPA data protection for psychologists in Singapore
Client records are among the most sensitive data a psychologist holds, and in Singapore that data sits squarely within the Personal Data Protection Act (PDPA). Here's what the PDPA actually requires, in plain terms, and how it applies to running a psychology practice.
What the PDPA is
The Personal Data Protection Act is Singapore's main data protection law, setting out how organisations — including private psychology and counselling practices — may collect, use and disclose personal data. The competent regulator is the Personal Data Protection Commission (PDPC), which administers the Act and issues guidance on how it applies in practice.
The legal basis for holding client data
Under the PDPA, an organisation generally needs a valid basis to collect, use or disclose someone's personal data — consent is the most common basis in a clinical setting, obtained from the client (or their legal guardian, for a minor) before or at intake, and covering what data you collect and what you'll use it for. Being specific about this at the start — rather than a vague blanket consent — is both good practice and squarely within the spirit of the Act.
Consent, in practice
- Be specific about what you're collecting and why. A generic “I consent to data processing” line does less work than a clear statement of what's collected (intake details, session notes, billing information) and what it's used for (providing treatment, invoicing, any insurer or EAP submission the client asks you to prepare).
- Record consent, don't just assume it. A dated, retained consent record is what you'd need to point to if a client ever questions how their data has been handled.
- Update consent when the purpose changes. If you start using client data for something beyond what was originally agreed — a different reporting requirement, for instance — that's a new basis to establish, not an extension of the old one.
Cross-border data transfers
The PDPA's Transfer Limitation Obligation permits transferring personal data outside Singapore where the recipient country or organisation provides a standard of protection comparable to the PDPA's own. This matters directly for any practice using software that stores data outside Singapore: it's not automatically prohibited, but it does require the destination to offer comparable protection — something to check with any software provider you use, including how and where your patients' data is actually hosted and secured.
Where Nerela's data is hosted: encrypted in transit and at rest, hosted in the European Union under the EU's GDPR — among the more comprehensive data protection frameworks globally — with automatic backups and database-level isolation per account. That's the comparable-protection standard the PDPA's transfer rules are looking for.
Other PDPA obligations worth knowing
- Data breach notification. Organisations must notify the PDPC, and in some cases affected individuals, of a data breach that meets certain notification thresholds — which makes having a secure system with a clear incident process in the first place the better strategy than working out a response after the fact.
- Retention limitation. Personal data shouldn't be kept longer than necessary for the purpose it was collected for, or for legal or business reasons — worth having an explicit retention policy for client records rather than keeping everything indefinitely by default.
- Access and correction. Individuals generally have a right to request access to, and correction of, their own personal data held by an organisation — worth being able to respond to promptly and completely.
- Data Protection Officer. Organisations are generally required to designate someone responsible for PDPA compliance and make their contact details available — in a small practice, this is typically the practitioner themselves, but it's a role worth naming explicitly rather than leaving implicit.
None of these obligations are unusual by the standards of a well-run practice — they largely describe habits (clear consent, limited retention, a responsive process for access requests) that are good practice regardless of which law is doing the asking.
Client data handled the way the PDPA expects
Encrypted, database-isolated, exportable on request — and hosted under one of the more comprehensive data protection frameworks globally.
What this means for your day-to-day practice
Practically, this comes down to a handful of habits: a clear, specific consent process at intake; records that are encrypted and kept only as long as needed; a way to export or delete a client's data if they ask; and, if you use any third-party software, confidence that wherever it stores data offers protection comparable to the PDPA's own standard. None of this needs to be complicated — it needs to be deliberate, and in place before your first client rather than added after the fact. See our full guide to starting a private practice in Singapore for how this fits alongside everything else you need to set up.
Frequently asked questions
What is the PDPA?+
The Personal Data Protection Act is Singapore's main data protection law, governing how organisations — including psychology and counselling practices — collect, use and disclose personal data. It's administered by the Personal Data Protection Commission (PDPC).
Can I use software that stores client data outside Singapore?+
Yes, under the PDPA's Transfer Limitation Obligation, provided the destination country or organisation offers a standard of data protection comparable to the PDPA's own. This is worth confirming directly with any software provider you use.
Who regulates data protection in Singapore?+
The Personal Data Protection Commission (PDPC) is the competent authority administering the PDPA.
Whatever your title, your records should be in order
Encrypted patient records, session notes and an export you control at any time — built for psychologists, with data hosted in the European Union.
14 days free, no card · No lock-in · We answer directly
Nerela is practice management software built for psychologists and clinics: scheduling and online booking, patient records and session notes, invoicing and reports — in one place, with data hosted in the European Union. You start with 14 days free, no card, and you talk directly to the people building the product.
Start on Nerela — 14 days free →