Here is the pattern we see on most Singapore SME websites, and it is almost exactly backwards.
The site has a cookie banner — usually a copied EU-style one, with categories nobody configured. It has a privacy policy that mentions the GDPR. It has a “Terms of Service” page nobody has read since it was pasted in. And it does not publish a contact for the person responsible for personal data, does not show the company’s registration number anywhere, and quotes prices in a way that would earn a fine if the business is GST-registered.
The thing everyone installs is not required by Singapore law. Several of the things nobody installs are. That inversion happens because there is no single “website law” in Singapore to look up — the duties that actually bite come from four different regulators, none of which publishes a webmaster’s checklist. This guide assembles that checklist from the statutes and the regulators’ own guidance, separates it from the folklore, and ends with a footer you can copy.
It is a companion to our web design in Singapore guide, which covers the commercial side of building a site. This is general information, not legal advice.
There is no “website law”. There are four regulators.
Four bodies impose duties that land on a business website. They do not coordinate, and none of them frames its rules as being about websites, which is why the requirements are easy to miss.
| Regulator | Instrument | What it requires on the site |
|---|---|---|
| ACRA | Companies Act 1967, s144 | The company’s name, and its registration number, on business letters, invoices, official notices and publications |
| PDPC | Personal Data Protection Act 2012, ss 11 and 12 | A designated data protection officer whose business contact information is made available to the public, and published policies and practices |
| IRAS | GST price display rules | GST-inclusive prices on all public price displays, websites and advertisements included |
| CCCS | Guidelines on Price Transparency (CPFTA), in force 1 Nov 2020 | No drip pricing, no unsubstantiated discount or comparison claims |
ACRA: your company name, and a number most sites omit
Section 144 of the Companies Act 1967 is short, and it draws a distinction almost nobody notices.
Section 144(1) requires the name of a company to appear in legible romanised letters on its seal and on “all business letters, statements of account, invoices, official notices, publications, bills of exchange, promissory notes, indorsements, cheques, orders, receipts and letters of credit” issued by or on behalf of the company.
Section 144(1A) requires the registration number — in practice the UEN — to appear in a legible form on a shorter list: “all business letters, statements of account, invoices, official notices and publications”. The cheques, receipts, orders and negotiable instruments are absent from the second list.
So the accurate version of the folklore is: your company name has to go on receipts and cheques; the UEN does not. Both have to go on business letters, invoices, official notices and publications. Section 144(1B) makes default an offence by the company, and s144(2) creates a separate personal offence for an officer who issues a business letter, statement of account, invoice, official notice or publication without the name on it.
Is a website a “publication”? The Act does not define the term, and this is the one place in this guide where the honest answer is that it has not been definitively settled for a corporate website. The pragmatic response is that the cost of compliance is a single line of footer text, and the cost of being wrong is an offence, so the argument is not worth having. Put the full registered name and the UEN in the footer, and put both in your email signature and on every invoice and quotation, where the obligation is not arguable at all.
Three practical notes. The name must be the registered name, not the trading name — if you trade as “Acme” and are registered as “Acme Ventures Pte. Ltd.”, the footer needs the latter. Sole proprietorships and partnerships are registered under the Business Names Registration Act 2014 rather than the Companies Act, so the s144 wording does not apply to them, though the same footer line remains good practice and is often expected by payment providers. And a site that sells anything should treat its order confirmation email as an invoice, because that is what it functionally is.
PDPC: the requirement almost every Singapore site fails
This is the one that inverts the usual checklist, and it is black-letter statute rather than guidance.
Section 11(3) of the PDPA requires an organisation to designate one or more individuals responsible for ensuring it complies with the Act — the data protection officer. Section 11(5) then requires the organisation to “make available to the public the business contact information of at least one of the individuals designated”. Section 11(6) adds that designating someone “does not relieve the organisation of any of its obligations” — the DPO is a point of contact, not a liability shield.
Two details matter for how you satisfy it.
First, it is business contact information, not a named individual. A role-based address such as dpo@yourcompany.sg with a Singapore telephone number is sufficient, and is better practice than a personal name that goes stale when someone resigns. What it must be is reachable: a monitored inbox, answerable during Singapore business hours.
Second, section 11(5A) creates a deeming provision: an organisation is taken to have satisfied s11(5) if it makes the business contact information available “in any prescribed manner”. That is the statutory hook for the PDPC’s filing channel via ACRA’s BizFile portal, which organisations were asked to use by 30 September 2024. Two honest qualifications about that deadline, because it is widely misreported: the PDPC indicated that missing it would not itself attract a penalty, and BizFile is not the only way to comply. The underlying s11(5) duty to make the contact available to the public is what actually bites, and publishing it on your website satisfies it directly.
Alongside that sits the Openness Obligation in section 12: develop and implement policies and practices necessary to meet your PDPA obligations, and make information about them available on request. In practice that is your privacy policy — and it should describe what your site actually does, which for most Singapore SMEs means naming the analytics and advertising tags in use. We cover what those tags mean for consent in PDPA and marketing tracking in Singapore, and the same discipline applies to any identifier you collect on a form — including the one covered in the NRIC rules.
IRAS: the price display rule with a $5,000 fine
If your business is GST-registered, IRAS requires that all price displays to the public are GST-inclusive — price tags, price lists, advertisements, publicity brochures and websites are all named. Prices quoted verbally or in writing must be GST-inclusive too, because the public is entitled to know the final price upfront. Failure to comply can attract a fine of up to $5,000, and IRAS has publicised prosecutions.
Three specifics catch e-commerce sites in particular.
- If you show both prices, the GST-inclusive one must be displayed at least as prominently. A large “$100” with a small “+GST” underneath is the exact pattern the rule addresses.
- Do not advertise “no GST” or “GST absorbed”. IRAS’s position is that a GST-registered business intending to give a discount equal to the GST amount should not advertise that there is no GST, because GST is still included in the post-discount price and must still be accounted for. Advertise the equivalent discount instead.
- The exception is narrow. Hotels and F&B establishments that impose a service charge are not required to display GST-inclusive prices. If you are not one of those, the exception does not help you.
The failure mode is almost never the product page — it is the pricing table on a service page, the PDF rate card linked from the footer, and the ad copy, all of which drift out of sync with the shop.
CCCS: how you may present a discount
The CCCS Guidelines on Price Transparency have been in effect since 1 November 2020 under the Consumer Protection (Fair Trading) Act, and they apply to suppliers online and offline. Two of the four practices they name are website practices.
Drip pricing: unavoidable or mandatory charges — fees, surcharges, taxes — are expected to be incorporated into the headline price, and where a charge genuinely cannot be calculated in advance, its existence must be disclosed clearly and prominently alongside the headline price. Optional add-ons should be opt-in or opt-neutral, not pre-ticked at checkout.
Discount and price comparison claims: where you strike through your own previous price, the price benefit must be genuine and you must have a valid basis for the comparison, and CCCS encourages suppliers to keep records of past sales and prices to prove it. The practical instruction is simple: export your actual selling prices for the weeks before a sale and archive the file. We worked through this in detail for the mega-sale calendar in the 9.9, 11.11 and 12.12 campaign guide.
The signup form: two more rules attach the moment you capture an email
An email capture is the point at which the site stops being a brochure and starts being a marketing channel, and two further regimes engage.
Under the PDPA, you need consent for the purpose you actually intend, notified at the point of collection — and if you will send marketing messages to a Singapore telephone number, the Do Not Call provisions apply on the very first message. Under the Spam Control Act, bulk commercial email needs an unsubscribe facility that stays valid for at least 30 days, with the sender stopping within 10 business days of a request. We set out how those two regimes overlap, and where they disagree, in the guide to WhatsApp marketing rules in Singapore.
The practical consequence for the site itself: the consent checkbox must not be pre-ticked, the purpose must be stated next to it rather than buried in a linked policy, and the confirmation email must carry a working unsubscribe link from the first send.
What Singapore law does not require
Equally useful, because it is where the budget usually goes.
- A cookie banner, as such. The PDPA has no cookie provision. It governs the personal data your cookies and tags collect, and a banner is one practical way to obtain and evidence consent for advertising and cross-site tracking — it is a means, not a mandate. An EU-styled banner with unconfigured categories, blocking nothing, is worse than useless: it is a public statement about your practices that is not true.
- A GDPR-worded privacy policy, unless you actually process the data of people in the EU. A policy describing rights your users do not have, under a regulation that does not apply, tells a regulator you copied it.
- A separate “Terms of Service” page, for a brochure site with no account, no transaction and no user content. It does real work on an e-commerce or SaaS site and almost none on a five-page site.
- The UEN on every page — the footer, which appears on every page, is the easy way to do it, but the obligation attaches to documents rather than to page templates.
- An accessibility statement. Singapore has no general statutory accessibility mandate for private-sector websites. Building accessibly is still worth doing on its own merits, and much of it overlaps with what search engines reward.
The footer that satisfies all of it
Almost every obligation above resolves to one block of footer text and two linked pages. A compliant version looks like this:
Acme Ventures Pte. Ltd. (UEN 201812345A) · 1 Example Road #05-01 Singapore 123456 · +65 6123 4567 · Data protection enquiries: dpo@acme.sg · Privacy Policy · All prices shown are in SGD and inclusive of GST.
That single line carries the registered name, the UEN, a reachable DPO contact satisfying s11(5), a link to the s12 policies, and the GST statement. It takes ten minutes to add, and it closes more genuine exposure than any cookie banner.
Who is responsible when the agency built the site
A question worth settling before it matters. Under the PDPA, the organisation is responsible for personal data in its possession or under its control (s11(2)), and designating a DPO does not relieve it of any obligation (s11(6)). A web developer or agency processing personal data on your behalf is at most a data intermediary. That status limits what the intermediary owes directly, but it does not transfer your duties to them — the DPO contact, the policy, the price displays and the footer line are yours.
Two things follow. Put the compliance items in the build scope explicitly, as named deliverables, rather than assuming a developer will infer them: they are legal requirements, not design preferences, and no developer can know your GST status or who your DPO is. And put a clause in the contract requiring the intermediary to tell you promptly about any incident affecting the data they hold for you, because if something leaks it is your notification obligation, not theirs.
| Check | Where it lives | Source of the duty |
|---|---|---|
| Registered company name (not the trading name) | Footer, invoices, order confirmations | Companies Act s144(1) |
| UEN / registration number | Footer, invoices, official notices | Companies Act s144(1A) |
| DPO business contact, publicly available | Footer and contact page | PDPA s11(5) |
| Privacy policy describing actual practices | Linked from footer and every form | PDPA s12 |
| GST-inclusive prices everywhere prices appear | Product pages, rate cards, PDFs, ads | IRAS price display rules |
| Mandatory fees in the headline price | Product pages and checkout | CCCS Price Transparency Guidelines |
| Evidence file for any struck-through price | Internal, archived before the sale | CCCS Price Transparency Guidelines |
| Unticked consent box with the purpose stated | Every form | PDPA consent and notification |
| Working unsubscribe from the first send | Email templates | Spam Control Act |
Run this list at launch, and again whenever the site is rebuilt — a redesign is where footers get rewritten and these lines quietly vanish. It belongs in the same pass as the checks in our website redesign checklist and the recurring items in website maintenance.
Frequently asked questions
Do I need to display my UEN on my website in Singapore?
Section 144(1A) of the Companies Act 1967 requires a company’s registration number to appear on all business letters, statements of account, invoices, official notices and publications. The Act does not define “publications”, and its application to a corporate website has not been definitively settled, so there is a genuine argument either way. Given that compliance costs one line of footer text and non-compliance is an offence under s144(1B), the practical answer is to display it. The obligation on invoices, quotations and order confirmations is not arguable at all.
Does Singapore law require a cookie banner?
No. The PDPA contains no cookie provision and there is no Singapore equivalent of the EU ePrivacy Directive. What the PDPA governs is the personal data your cookies and tags collect: if a cookie can identify an individual, you need consent and you must notify the purpose. A banner is a practical way to obtain and evidence that consent for advertising and cross-site tracking, but it is a means rather than a legal mandate, and a copied banner that blocks nothing while claiming to manage categories is a misstatement of your own practices.
Do I have to publish a data protection officer’s contact on my site?
Yes. Section 11(3) of the PDPA requires you to designate at least one individual responsible for compliance, and section 11(5) requires you to make that person’s business contact information available to the public. A monitored role address such as dpo@yourcompany.sg with a Singapore phone number satisfies it; a personal name is not required. Section 11(5A) also deems the duty satisfied where the information is made available in a prescribed manner, which is the basis for the PDPC’s filing channel through ACRA’s BizFile portal.
Do I have to show GST-inclusive prices on my website?
If you are GST-registered, yes. IRAS requires GST-inclusive prices on all price displays to the public, and websites and advertisements are expressly named alongside price tags, price lists and brochures. Where both a GST-inclusive and a GST-exclusive price are shown, the inclusive price must be at least as prominent. Non-compliance can attract a fine of up to $5,000. Hotels and F&B establishments that impose a service charge are excepted; most other businesses are not.
Can I advertise “no GST” or “GST absorbed” during a sale?
Not if you are GST-registered. IRAS’s position is that a business intending to give a discount equal to the GST amount should not advertise that there is no GST, because GST remains included in the post-discount price and must still be accounted for. Advertise the equivalent discount instead — for example, an eight per cent discount rather than a claim that GST has been waived.
If my agency built the site, are they responsible for compliance?
No. Section 11(2) of the PDPA makes the organisation responsible for personal data in its possession or under its control, and section 11(6) confirms that designating a DPO does not relieve it of any obligation. An agency or developer processing personal data for you is at most a data intermediary, which limits what they owe directly but does not move your duties onto them. Name the compliance items as explicit deliverables in the build scope, and require prompt notice of any incident affecting data they hold for you.
Where this leaves you
Singapore’s website requirements are not onerous. They are simply scattered, which is why a site can pass a designer’s review, a developer’s review and a marketing review and still miss all four. The compliance work is one footer line, one honest privacy policy, one reachable DPO address, one pass over every place a price appears, and one archived price file before each sale.
The reason to do it is not the fines, which are small. It is that these are the cheapest trust signals on a website — a registered name, a UEN, a real address, a contactable person — and they are the ones a cautious Singapore buyer checks before filling in a form.
If you are planning a build or a rebuild and want the compliance pass folded into it rather than bolted on afterwards, that is part of how we scope web design projects, and you can see the results we report in our Singapore case studies.
Sources: Companies Act 1967 (Singapore), s144, Singapore Statutes Online, current version as at 4 September 2026; Personal Data Protection Act 2012 (Singapore), ss 11 and 12, Singapore Statutes Online, current version as at 4 September 2026; IRAS guidance on displaying and quoting prices, and on the responsibilities of GST-registered businesses; CCCS Guidelines on Price Transparency, in effect 1 November 2020 under the Consumer Protection (Fair Trading) Act; PDPC guidance on data protection officer registration via ACRA BizFile, deadline 30 September 2024. This is general information, not legal advice; rules change — verify before relying on them.


