This guide is general information, not legal advice. Refer to the PDPC's official guidelines for your situation.
Does the PDPA apply to my school?
The PDPA applies to private-sector organisations that collect, use or disclose personal data in Singapore. That includes tuition centres, enrichment centres, preschools, private education institutions and international schools. Public agencies — including government schools — are excluded from the PDPA and follow separate public-sector data rules.
The main PDPA obligations, applied to schools
| Obligation | What it means for a school or centre |
|---|---|
| Consent | Get consent from parents (or students who can consent for themselves) before collecting personal data, e.g. on the enrolment form. |
| Purpose limitation & notification | Tell parents why you collect data — enrolment, billing, emergencies, marketing — and only use it for those purposes. |
| Access & correction | Let parents request a copy of their child's data and correct errors. |
| Accuracy | Keep contact and medical details accurate, especially where decisions depend on them. |
| Protection | Use reasonable security: access controls, strong passwords, encryption, no student lists in public chat groups. |
| Retention limitation | Delete or anonymise data you no longer need, e.g. for students who left years ago. |
| Transfer limitation | If data is stored or sent overseas, ensure it gets comparable protection. |
| Data breach notification | Assess suspected breaches promptly; notify the PDPC and affected individuals where required. |
| Accountability | Appoint a Data Protection Officer, have data protection policies, and make the DPO's contact available. |
Can a tuition centre collect NRIC numbers?
Generally, no. Under the PDPC's advisory guidelines on NRIC and other national identification numbers (effective since 1 September 2019), organisations should not collect, use or disclose full NRIC numbers or retain physical NRIC cards unless required by law or necessary to accurately establish or verify an individual's identity to a high degree of fidelity. For most tuition and enrichment centres, a student's name, date of birth and parent contact are enough.
Do schools need a Data Protection Officer?
Yes. Every organisation covered by the PDPA must designate at least one person to be responsible for ensuring compliance — commonly called the Data Protection Officer (DPO) — and make their business contact information publicly available. In a small centre this is often the owner or centre manager.
What happens if there is a data breach?
A breach is notifiable if it is likely to result in significant harm to affected individuals, or affects 500 or more individuals. Once you assess that a breach is notifiable, you must notify the PDPC within 3 calendar days, and in cases of significant harm, notify affected individuals too. Examples in a school setting include a lost laptop with student records, an email sent to the wrong parent list, or a spreadsheet of contacts posted in a group chat.
What are the penalties?
The PDPC can impose financial penalties of up to S$1 million or 10% of an organisation's annual turnover in Singapore (for organisations with turnover above S$10 million), whichever is higher, as well as directions to remedy the breach.
How school management software helps with PDPA
- Role-based access — teachers see their own classes; only authorised staff see medical or financial data.
- Audit logs — a record of who viewed or changed each record.
- Consent records — store consent captured on the enrolment form, with timestamps.
- Private parent messaging — no exposing parents' numbers in group chats.
- Encryption and Singapore hosting — reduce breach risk and simplify transfer obligations.
- Data export and deletion — answer access requests and apply retention policies.
SchoolSoftware.sg includes all of these. Software supports compliance but does not replace your organisation's own policies and DPO.