LexVibe
Singapore
In force since 2 July 2014

PDPA compliance for a portfolio site

Personal Data Protection Act 2012 (Singapore). This page applies it to one kind of product (portfolio site), so you get the obligations that are actually yours instead of a summary of the whole statute.

Does it apply to you?

Organisations collecting personal data in Singapore.

What a portfolio site typically processes

  • contact form submissions
  • basic web analytics
  • embedded third-party content such as fonts, maps or video

Each of these is processing you have to disclose. Adding an SDK later adds to this list — which is why a policy written once goes stale.

Documents you need

The intersection of what PDPA requires and what a portfolio site actually does:

  • Privacy policy

Rights you must honour

PDPA gives people in Singapore the right to:

  • Access a copy of their data
  • Correct inaccurate data
  • Withdraw consent at any time
  • Receive their data in a portable format

Cookies and trackers

Trackers may load by default, but the visitor needs a working way to opt out, and you must honour it.

See what your site is actually missing

Paste your URL. We fetch the live page, detect the trackers, payments and AI calls that really ship to visitors, and tell you which documents and consent you need. No signup.

No signup · result in seconds

Primary sources

  • s. 13Consent required before collecting, using or disclosing data
  • s. 20Notify the individual of the purpose
  • s. 21Right of access
  • s. 26DNotify the Commission and affected individuals of a breach

Everything we track about PDPA

PDPA for other kinds of product

Other frameworks for a portfolio site

This page is an engineering summary of publicly available regulatory requirements, generated from LexVibe's framework registry — not legal advice. Every framework links to its official text so you can check it yourself. For decisions about your own compliance posture, consult the primary sources and a lawyer qualified in the relevant jurisdiction.