PDPA compliance for schools and tuition centres in Singapore

What the Personal Data Protection Act requires of private education providers, in plain English.

Last updated

Quick answer

Private schools, tuition centres, enrichment centres and preschools in Singapore must comply with the Personal Data Protection Act 2012 (PDPA), enforced by the Personal Data Protection Commission (PDPC). Key duties are: obtain consent and explain purposes before collecting personal data; avoid collecting full NRIC numbers unless necessary; protect data with reasonable security; keep it only as long as needed; appoint a Data Protection Officer; and notify the PDPC within 3 calendar days of assessing that a data breach is notifiable. Public (MOE) schools are government bodies and are not covered by the PDPA.

This guide is general information, not legal advice. Refer to the PDPC's official guidelines for your situation.

Does the PDPA apply to my school?

The PDPA applies to private-sector organisations that collect, use or disclose personal data in Singapore. That includes tuition centres, enrichment centres, preschools, private education institutions and international schools. Public agencies — including government schools — are excluded from the PDPA and follow separate public-sector data rules.

The main PDPA obligations, applied to schools

ObligationWhat it means for a school or centre
ConsentGet consent from parents (or students who can consent for themselves) before collecting personal data, e.g. on the enrolment form.
Purpose limitation & notificationTell parents why you collect data — enrolment, billing, emergencies, marketing — and only use it for those purposes.
Access & correctionLet parents request a copy of their child's data and correct errors.
AccuracyKeep contact and medical details accurate, especially where decisions depend on them.
ProtectionUse reasonable security: access controls, strong passwords, encryption, no student lists in public chat groups.
Retention limitationDelete or anonymise data you no longer need, e.g. for students who left years ago.
Transfer limitationIf data is stored or sent overseas, ensure it gets comparable protection.
Data breach notificationAssess suspected breaches promptly; notify the PDPC and affected individuals where required.
AccountabilityAppoint a Data Protection Officer, have data protection policies, and make the DPO's contact available.

Can a tuition centre collect NRIC numbers?

Generally, no. Under the PDPC's advisory guidelines on NRIC and other national identification numbers (effective since 1 September 2019), organisations should not collect, use or disclose full NRIC numbers or retain physical NRIC cards unless required by law or necessary to accurately establish or verify an individual's identity to a high degree of fidelity. For most tuition and enrichment centres, a student's name, date of birth and parent contact are enough.

Do schools need a Data Protection Officer?

Yes. Every organisation covered by the PDPA must designate at least one person to be responsible for ensuring compliance — commonly called the Data Protection Officer (DPO) — and make their business contact information publicly available. In a small centre this is often the owner or centre manager.

What happens if there is a data breach?

A breach is notifiable if it is likely to result in significant harm to affected individuals, or affects 500 or more individuals. Once you assess that a breach is notifiable, you must notify the PDPC within 3 calendar days, and in cases of significant harm, notify affected individuals too. Examples in a school setting include a lost laptop with student records, an email sent to the wrong parent list, or a spreadsheet of contacts posted in a group chat.

What are the penalties?

The PDPC can impose financial penalties of up to S$1 million or 10% of an organisation's annual turnover in Singapore (for organisations with turnover above S$10 million), whichever is higher, as well as directions to remedy the breach.

How school management software helps with PDPA

SchoolSoftware.sg includes all of these. Software supports compliance but does not replace your organisation's own policies and DPO.

Frequently asked questions

Does the PDPA apply to tuition centres?

Yes. Tuition centres are private organisations that collect personal data in Singapore, so they must comply with the Personal Data Protection Act 2012.

Does the PDPA apply to MOE schools?

No. Government schools are public agencies, which are excluded from the PDPA. They follow separate public-sector data governance rules.

How quickly must a school report a data breach in Singapore?

Once an organisation assesses that a data breach is notifiable, it must notify the PDPC within 3 calendar days.

Can schools post student photos online?

Only with consent for that purpose. Collect consent for photos and marketing use separately on your enrolment form, and respect parents who opt out.

See how it works for your school

A 30-minute walkthrough set up with your own classes, fees and term calendar.

Book a free demo