When a private company in Singapore mishandles your personal data, the Personal Data Protection Act gives you somewhere to go: the Personal Data Protection Commission, and ultimately a court.
When a ministry does the same thing, neither route is open. The Act's data protection obligations do not bind government agencies at all, and a separate regime with a different purpose takes their place.
What section 4 says
Section 4 of the Act carries the exclusion, in these words.
"Parts 3, 4, 5, 6, 6A and 6B do not impose any obligation on — (a) any individual acting in a personal or domestic capacity; (b) any employee acting in the course of his or her employment with an organisation; (c) any public agency; or (d) any other organisations or personal data, or classes of organisations or personal data, prescribed for the purposes of this provision."
The Commission calls those six Parts the Data Protection Provisions. They hold the duties on accountability, consent and purpose, access and correction, looking after the data, and breach notification.
Two subsections further down, the same section deals with records over a hundred years old and most data about people long dead, and there it says "This Act does not apply". For public agencies the drafter chose narrower words, removing the obligations in six named Parts and leaving the rest of the Act in place.
Who counts as a public agency
The definition in section 2 has three limbs:
"public agency" includes — (a) the Government, including any ministry, department, agency, or organ of State; (b) any tribunal appointed under any written law; or (c) any statutory body specified under subsection (2)
The third limb is the one that surprises people. A statutory board is not a public agency just because it is a statutory board. Subsection (2) lets the Minister specify statutory bodies by notification in the Gazette, and only the ones specified are covered. A statutory body that has never been gazetted is, for the purposes of this Act, an ordinary organisation with the full set of obligations.
The parts of the Act that still reach government
Because the exclusion names six Parts rather than the whole Act, the others still apply. The Do Not Call provisions in Part 9 are not excluded; the Act's own schedule exempts messages a public agency sends to promote a programme "which is not for a commercial purpose", an exemption that would be unnecessary if Part 9 did not reach public agencies at all.
Part 9B, the criminal offences, is explicit. Its offence of unauthorised disclosure covers personal data "in the possession or under the control of an organisation or a public agency". Public servants themselves are then routed to a different statute, so the same act is not punished twice.
What governs government data instead
The Ministry of Digital Development and Information states the division plainly: data management in the public sector "is governed by the Public Sector (Governance) Act ('PSGA') and the Government Instruction Manual on Infocomm Technology & Smart Systems Management … The Personal Data Protection Act ('PDPA') applies to the private sector."
The Public Sector (Governance) Act 2018 is criminal and personal. It makes it an offence for a public official to disclose data without authority, to misuse it for gain or to cause harm, and to re-identify anonymised data, and it extends the misuse offence to contractors and their employees. Each carries a fine of up to $5,000, imprisonment of up to two years, or both.
The instruction manual is internal government policy rather than legislation. Extracts are published, but it is not on Singapore Statutes Online and it gives an individual nothing to enforce.
Where the difference shows up for you
Against a private organisation, section 48O gives a person a direct route to court:
"A person who suffers loss or damage directly as a result of a contravention — (a) by an organisation of any provision of Part 4, 5, 6, 6A or 6B … has a right of action for relief in civil proceedings in a court."
The court can grant an injunction, a declaration or damages. A public agency cannot contravene those Parts, because they impose no obligation on it, so that route does not exist against one.
The Commission's own complaints page reflects this. For a concern about a government agency it does not offer its own process; it points you to the agency's Quality Service Manager and to the Government Data Incident Reporting Platform.
The two regimes also aim at different people. A private-sector breach usually ends with directions or a financial penalty against the company, while the public-sector law prosecutes the officer who misused the data. Of the two, only the private-sector route includes a claim you can bring yourself.
The vendor exemption that no longer exists
If you supply services to the government, this is the part most likely to be out of date in your own compliance notes.
Until 1 February 2021, section 4 also excluded "an organisation in the course of acting on behalf of a public agency". The Personal Data Protection (Amendment) Act 2020 deleted that limb. A government contract no longer takes a vendor outside the Act. The Commission's advisory guidelines now say that organisations providing services to public agencies "may either have obligations under the PDPA as data controllers or as data intermediaries".
A vendor acting as a data intermediary for an agency carries a reduced set of duties, but not an empty one: it must still protect the data and cease retaining it, and a separate section added in the same amendment requires it to notify the agency "without undue delay" if it has reason to believe a breach has occurred.
Limits on the exemption
Government data is still regulated, by a law that carries prison terms and reaches contractors. And the exemption is narrower than a name suggests: a statutory board is only a public agency if the Gazette says so, and a private company doing government work sits fully inside the Act.
What to do with it
Before complaining, work out who holds the data. A private company answers to the Commission and, under section 48O, to a court. A ministry, department or gazetted statutory board is reached through the agency itself and the government's incident reporting platform, and the likely outcome there is discipline or prosecution rather than compensation.
Vendors have a simpler task: find the date on the data protection policy. A policy written before February 2021 that treats government work as outside the Act relies on a provision that no longer exists.
Where this comes from
The statutory text is from the Personal Data Protection Act 2012 on Singapore Statutes Online, current version as at 16 September 2026, sections 2, 4, 26E, 48D and 48O and the Eighth Schedule; the repealed limb was read from the historical versions on the same site. Section 4 has been amended once, by Act 40 of 2020 with effect from 1 February 2021, and was carried into the 2020 Revised Edition; later amending Acts did not touch it. The penalties are from the Public Sector (Governance) Act 2018, sections 7 and 8. The division of responsibility is quoted from the Ministry of Digital Development and Information; the vendor statement is from the Commission's Advisory Guidelines on Key Concepts, revised 1 October 2021; the complaint routing is from the Commission's complaints page, read the same day.
The Commission's 164-page advisory guidelines mention public agencies fourteen times and data intermediaries sixty-seven times, and never use the old phrase "on behalf of a public agency" — consistent with the statute's repeal of that limb.