SINGAPORE, 6 AUG 2026 — On 5 August the Personal Data Protection Commission published two enforcement actions. One concerns a tuition company, the other a design studio. Both are voluntary undertakings, and neither contains a finding that the organisation broke the law.
That is no longer unusual; it is the ordinary case. In the twenty-four months to 6 August the Commission published 70 enforcement outcomes, and 58 of them were undertakings. The last Commission's Decision — the instrument that makes findings, applies the law to facts and can carry a financial penalty — was published on 7 May.
What we counted
Every enforcement outcome the Commission publishes gets its own page, and every page carries a publication date and a label saying whether it is a Commission's Decision or a Voluntary Undertaking. The regulator's sitemap lists 387 of them. We fetched all 387 and recorded the date and the label on each.
This measures publication, not conduct. A decision published in January may concern an incident from years earlier, and the Commission does not publish an outcome the moment it reaches one. The count describes the public record as it stands — the only version of the regulator's reasoning available to outsiders.
| Year | Decisions | Undertakings | Total | Undertaking share |
|---|---|---|---|---|
| 2016 | 22 | 0 | 22 | 0% |
| 2017 | 19 | 0 | 19 | 0% |
| 2018 | 29 | 0 | 29 | 0% |
| 2019 | 51 | 0 | 51 | 0% |
| 2020 | 47 | 3 | 50 | 6% |
| 2021 | 29 | 11 | 40 | 28% |
| 2022 | 29 | 9 | 38 | 24% |
| 2023 | 17 | 10 | 27 | 37% |
| 2024 | 16 | 44 | 60 | 73% |
| 2025 | 4 | 24 | 28 | 86% |
| 2026 to 6 Aug | 6 | 17 | 23 | 74% |
RECATOOLS count of all 387 enforcement pages listed in the PDPC sitemap, each fetched for its published date and instrument type. Shares are ours. 2026 is a partial year and the 2020 figure covers only the period after 10 September, when the first undertaking was published.
The two instruments are not variants of each other
A Commission's Decision is the end of an investigation. The Commission's own Guide on Active Enforcement lists what a breach finding can produce: no breach, a warning, directions, financial penalties, or directions and financial penalties together. The decision states what happened, which obligation was engaged and why the Commission concluded what it did.
A voluntary undertaking is a different mechanism, introduced under section 48L when the Personal Data Protection (Amendment) Act 2020 came into force on 1 February 2021. An organisation asks for it early, before an investigation runs its course, and offers a remediation plan. The Commission may accept if it judges that the undertaking achieves, in the Guide's words, a similar or better enforcement outcome more effectively and efficiently than a full investigation.
The published undertakings are not empty. A signed undertaking records that the Commission has reason to believe the organisation has not complied with the Act, summarises the facts in one schedule and sets out the remediation steps in another. But the Guide is explicit about what it is not: the organisation's execution of an undertaking does not amount to an admission of breach of the PDPA. Reason to believe is not a finding, and a remediation plan is not an analysis of where the legal line falls.
The change came in two steps, not one
Undertakings did not displace decisions gradually. The first three were published on a single day, 10 September 2020, and for three years afterwards they ran at roughly ten a year against seventeen to twenty-nine decisions.
Then two things happened in sequence. In 2024 undertakings more than quadrupled, from 10 to 44, while decisions barely moved. In 2025 decisions collapsed, from 16 to 4. The first change added a new instrument at volume; the second removed the old one.
The four decisions published in 2025 are the entire reasoned output of that year: Ezynetic in July, a finding of no breach against the Institute of Mental Health in the same month, a management corporation in August, and Marina Bay Sands in October. Six have followed in 2026, four of them on a single day in January.
The ceiling went up as the instrument that carries it receded
The same amendment that created undertakings also raised the maximum financial penalty. From 1 October 2022, an organisation with annual Singapore turnover above S$10 million faces a cap of the higher of 10 per cent of that turnover or S$1 million, against a flat S$1 million before.
Financial penalties are imposed through decisions. There is no penalty attached to an undertaking; that is much of the point of one. The instrument that carries the heavier sanction began to thin out over the same period, from 29 decisions in 2022 to 17 the following year, 16 the year after, then 4.
These are not necessarily connected, and nothing in the record says they are. But an enforcement ceiling is only as real as the instrument that reaches it.
The reading that is fair to the regulator
The obvious interpretation is that Singapore has gone quiet on privacy enforcement, but the Commission's own criteria cut the other way.
The Guide says the Commission is unlikely to accept an undertaking where the organisation refutes responsibility, where it is a repeat incident with similar causes, where the remediation plan does not explain how compliance will be achieved, where the organisation wants more time to produce that plan, or where the breach is wilful or egregious. An undertaking is available to organisations that can demonstrate accountable policies already in place, with certification under the Data Protection Trustmark given as an example.
Read against that list, a corpus dominated by undertakings is a corpus of cases the regulator judged to be non-wilful, non-repeated, admitted and already being fixed. That is a defensible allocation of a regulator's finite investigative capacity, and it is faster for the affected individuals, whose remediation begins immediately rather than after an investigation concludes.
Nor did enforcement volume fall. Counting both instruments together, 2024 produced 60 published outcomes, the highest total in the corpus. The change was in composition.
What goes missing is the guidance
The cost lands on everyone who is not party to the case.
A compliance officer works out what the Act requires largely by reading what the regulator has found. A decision that a particular access control was inadequate, or that a particular retention period was too long, tells every other organisation running the same arrangement where it stands. Undertakings do not do that work. They record that something went wrong and that the organisation agreed to fix it, without settling whether the original arrangement broke the law.
That matters most in the areas where the law is least settled, which is where guidance is worth most. The Commission has spent the past two years consulting on the use of personal data in generative AI systems and in AI recommendation and decision systems, publishing responses to the generative AI consultation on 20 July. A body of reasoned decisions would be most useful for exactly these questions, which are arriving just as that instrument has become scarce.
What to watch
Three things would clarify the pattern.
First, will decisions resume? The Commission publishes on a roughly monthly cadence — seven publication dates so far in 2026 — so a return to reasoned output would show up quickly. Already, 2026 has produced more decisions than all of 2025.
The second is whether any published undertaking is escalated. The Guide provides that where an organisation fails to comply with an undertaking's terms, the Commission may issue directions or resume a full investigation. No such escalation appears in the published record.
The third is whether the first enforcement action touching an AI system arrives as a decision or as an undertaking. On the current ratio it will be an undertaking, and the question that everyone in the region wants answered — where the line actually falls — will not be in it.