PDPA-Compliant Marketing Tracking in Singapore: What the Rules Actually Say
There are two ways a Singapore business gets its marketing tracking wrong, and they are opposite errors.
The first is to install a European cookie banner — the kind that blocks the page until you choose, with six toggle categories and a legitimate-interest tab — because a plugin offered it and it looked like the responsible thing to do. Singapore does not require that. The banner adds friction, costs conversions, and in the version most sites deploy it does not even record consent in a way anyone could later rely on.
The second is to assume that because Singapore has no cookie law of its own, nothing applies. That is also wrong, and it is the more expensive error. The Personal Data Protection Act does not mention cookies in its text, but the Personal Data Protection Commission has published guidance that applies the Act to them directly, and the obligations attach the moment your tracking can identify a person.
This guide covers what the PDPA actually requires of a marketing tracking stack in Singapore, quoting the Commission’s own guidance rather than paraphrasing someone else’s blog post: when tracking data becomes personal data, where consent is genuinely needed, how the common tools sit against the rules, and what a defensible setup looks like.
This is a practitioner’s guide to marketing tracking, not legal advice. For a binding view on your specific setup, take advice from a Singapore-qualified lawyer or a certified data protection professional.
Start here: what the PDPC actually says about cookies
The relevant text is Chapter 7, “Online Activities”, of the Advisory Guidelines on the PDPA for Selected Topics, revised May 2024. It is worth reading the actual paragraphs, because they are more permissive and more precise than the summaries circulating online.
On scope, paragraph 7.7 is blunt: “The PDPA applies to the collection, use, or disclosure of personal data using cookies.” The obligation follows the personal data, not the technology.
On whether you need consent at all, paragraph 7.9 sets the first boundary: “not all cookies collect personal data”, and “Consent is not needed for cookies that do not collect personal data.” Paragraph 7.10 sets the second: for internet activities the user has clearly requested, consent may not be needed where the individual is aware of the purpose and voluntarily provided the data — and it gives examples, including storing what a user types into a web form to complete a purchase, and “reasonable activities that cannot take place without cookies”, such as authentication and security, user preference, network management and streaming content.
On advertising, paragraph 7.14 is the one that matters most to marketers: “Where targeting of advertisements involves the collection and use of personal data through cookies, the individual’s consent is required.” The same paragraph adds, as good practice, that organisations “should provide individuals with the ability to set their cookie preferences within the website”.
And on the trap people miss — paragraph 7.12 says consent can be reflected in how a user configures their browser, but closes the door on assuming it: “the mere failure of an individual to actively manage his browser settings does not imply that the individual has consented to the collection, use and disclosure of his personal data by all websites for their stated purpose.”
Put those together and the Singapore position is clear, and genuinely different from the European one. There is no requirement to block trackers before a user acts. There is a requirement to obtain consent for advertising and targeting that involves personal data — and silence does not count as that consent.
When does tracking data become personal data?
This is the question everything else hangs on, and the guidelines answer it with a threshold rather than a list.
Paragraph 7.1 names the identifiers explicitly: identifiers the user gives you, identifiers you assign, and identifiers that are generated programmatically — and the examples given include “hash generated from email address, device fingerprints, IP addresses and cookies”. A hashed email is named in the guidance as an identifier. Hashing is a security measure, not an exit from the PDPA, which is the single most common misunderstanding we encounter when a client has been uploading customer lists to ad platforms.
On IP addresses, paragraphs 7.3 to 7.5 take a contextual position: an IP address in isolation identifies a device rather than a person, and a shared office computer is unlikely to be traceable to one individual. But the Commission then sets out the accumulation principle — “the more data points associated to a unique IP address an organisation collects, the more likely that an individual may be identifiable” — and gives the example of profiling websites visited, items purchased and other activity tied to one address over a long period.
Paragraph 7.2 completes the picture: behavioural data such as browsing and search activity, “when linked to an identifier, will form part of the personal data that the organisation is collecting”.
Paragraph 7.13 adds a nuance that surprises most marketers: where an organisation operates a website that a third party uses to collect personal data, and the site operator is not itself collecting it, the obligation to obtain consent sits with the third party. That is not a licence to shrug off responsibility for the pixels on your site — you are almost always collecting data of your own alongside them, and you chose to install the tag — but it does mean the compliance picture for embedded advertising technology is shared rather than sitting entirely on you.
The tracking stack, obligation by obligation
Here is how the tools in an ordinary Singapore marketing stack sit against the Act. The pattern to notice: measurement configured conservatively is largely fine, and everything that personalises or targets needs consent.
| Tool or activity | Personal data? | What is required in practice |
|---|---|---|
| GA4, standard configuration | Usually not, if you do not send user IDs or PII and you leave Google Signals off | Disclose analytics in your privacy policy. Never pass email addresses, NRIC numbers or phone numbers into event parameters — that is the failure we see most often, usually via a form-field capture or a URL query string. |
| GA4 with Google Signals or User-ID | Yes — it links behaviour to a signed-in individual for ads personalisation | Consent before it runs, and a way to withdraw. This is the switch that moves analytics from measurement into the para 7.14 territory. |
| Meta Pixel and Conversions API | Yes — it builds a profile tied to a Meta account and passes hashed identifiers | Consent for advertising purposes. Note that CAPI is a server-side path for the same data, so it does not remove the obligation; if anything it makes ignoring consent state a deliberate act rather than an oversight. |
| Google Ads remarketing tag | Yes, where it builds audiences tied to individuals | Consent, plus honouring withdrawal by excluding the user from future audience building. |
| Enhanced conversions and offline conversion imports | Yes — you are sending hashed customer data to a third party | Consent that covers disclosure to a third party for advertising, not just “we use cookies”. Hashing does not change the analysis; para 7.1 lists an email hash as an identifier. |
| Customer Match and Custom Audience list uploads | Yes, unambiguously | The highest-risk item in most accounts. You are disclosing a customer list to an overseas platform for marketing. The consent you rely on must have covered that disclosure at the point of collection. |
| Call tracking and recorded calls | Yes | Notify at the start of the call, state the purpose, and obtain consent for recording. Retain only as long as the purpose requires. |
| WhatsApp follow-up to a lead | Yes, and it triggers the Do Not Call provisions | Marketing messages to a Singapore telephone number are covered by the DNC rules regardless of how the number was obtained. The ad is unregulated; the follow-up message is not. |
| Email marketing to a purchased or scraped list | Yes | No lawful basis. Consent must be given by the individual to you, for that purpose. Buying a list does not transfer consent. |
Two of those rows deserve expanding, because they carry most of the real exposure.
Customer list uploads. When you export a customer list from your CRM and upload it to build a Custom Audience or a Customer Match audience, you are disclosing personal data to a third party for a marketing purpose. The platforms require you to confirm you have the necessary rights, and that confirmation is a contractual promise you are making, not a compliance assessment they have done for you. The question to answer honestly is whether the notice those customers saw when they bought from you disclosed that their details might be used for advertising on third-party platforms. If the notice said “we will use your details to fulfil your order and contact you about it”, the answer is no. Our guide to retargeting and custom audiences covers the mechanics; this is the permission layer underneath it.
The legitimate interests exception does not rescue direct marketing. The 2021 amendments introduced a legitimate interests exception to the consent obligation, and it is genuinely useful for fraud prevention, security and similar purposes. It is explicitly not available for sending marketing messages to a Singapore telephone number. It cannot be used as a workaround for the Do Not Call provisions, and organisations generally still need consent for direct marketing.
What a cookie banner should actually do here
Most Singapore sites either have no banner or have one that does nothing except appear. A useful one does four things, and the fourth is the one that is nearly always missing.
- Tell the user what is collected and why, in language a person can read, before the advertising tags fire.
- Offer a genuine choice on advertising and personalisation, with reject at least as easy as accept. Para 7.14’s good-practice line about letting individuals set cookie preferences within the website is the standard to design to.
- Actually gate the tags. A banner that displays while the Meta Pixel has already fired is decoration. Consent state must control tag firing, which usually means a consent platform wired into your tag manager rather than a standalone plugin.
- Record the consent. If a complaint reaches the Commission, the burden is on you to show that valid consent was obtained. A banner that stores a boolean in local storage and nothing else cannot demonstrate what was shown, when, or to whom.
What you do not need is the European pattern of blocking all non-essential processing until an affirmative choice is made. Singapore has no such prior-blocking requirement. The practical middle ground most of our clients land on: essential and aggregate analytics run on load, advertising and personalisation tags wait for consent, the notice is short and specific, and the consent record is stored with a timestamp and the policy version.
The obligations that sit around the tracking
Tracking is not a standalone compliance topic. Four other duties routinely catch marketing teams.
| Obligation | What it means for marketing |
|---|---|
| Notification | State the purpose before or at the point of collection. A privacy policy nobody is directed to is weak evidence; a one-line purpose statement at the form is strong. |
| Withdrawal of consent | Individuals can withdraw at any time with reasonable notice, and you must stop. In practice this means unsubscribing must also remove them from ad audiences, not just from the mailing list — a step almost no SME automates. |
| Retention limitation | Stop retaining personal data when the purpose has ended and there is no legal need to keep it. A CRM with 2015 leads and no deletion policy is a live issue, and it is also why GA4’s data-retention setting is worth deliberately choosing. |
| Accountability and the DPO | Every organisation must appoint a data protection officer and make the business contact information available. This is a legal requirement, not best practice, and it is one of the easiest things for a complainant to check. |
Two more dates belong in any 2026 plan. Financial penalties under the PDPA now reach the higher of S$1 million or 10% of annual turnover in Singapore for organisations with local turnover above S$10 million, following the enhanced regime that took effect on 1 October 2022. And organisations must stop using NRIC numbers — full or partial — for authentication by 31 December 2026, with the Commission stepping up enforcement from 1 January 2027. If any part of your marketing stack uses the last three digits of an NRIC as a lookup key, a loyalty login or a “verify your identity” step in a campaign, that is a deadline with your name on it.
A ten-point audit you can run this week
- List every tag firing on your site. Use the browser’s network panel, not your tag manager’s list — they differ more often than they should, because plugins and themes inject their own.
- For each tag, write down what it collects and whether it serves measurement or advertising. This alone resolves most uncertainty.
- Check your forms for PII leaking into analytics: email in a URL parameter, phone in an event label, NRIC anywhere at all.
- Read the consent notice your customers actually saw at the point of collection. Does it cover disclosure to advertising platforms?
- Check whether unsubscribing removes someone from your ad audiences as well as your mailing list. It usually does not.
- Confirm your DPO is appointed and their business contact is published.
- Set a retention policy for leads and old CRM records, and actually schedule the deletion.
- Confirm your GA4 data-retention setting is a deliberate choice rather than the default.
- Audit every use of NRIC in a marketing or loyalty flow against the 31 December 2026 authentication deadline.
- Store consent records with a timestamp and the version of the notice shown. If you cannot evidence consent, you do not effectively have it.
Frequently asked questions
Does Singapore require a cookie consent banner?
Not in the European sense. There is no requirement to block cookies before an affirmative choice. But where cookies collect personal data for advertising targeting, the PDPC’s guidance says consent is required, and it also says that a user’s failure to manage their browser settings does not imply consent. A banner is the practical way most sites obtain and evidence that consent — it is a means, not a legal mandate in itself.
Is hashed data still personal data under the PDPA?
Treat it as personal data. The Commission’s own guidance lists a “hash generated from email address” among the identifiers assigned to individuals online. Hashing is an appropriate security measure and you should use it, but it does not put customer-list uploads outside the Act.
Do I need consent to run GA4?
For a standard configuration that does not send user identifiers, does not receive PII in event parameters and has Google Signals off, you are generally dealing with aggregate data rather than personal data, and para 7.9’s carve-out is doing the work. Turn on Google Signals or User-ID, or start passing customer identifiers, and the analysis changes — that is advertising-adjacent personal data and needs consent. Our GA4 setup guide covers which of those settings are hard to reverse.
Can I send a WhatsApp message to someone who filled in my form?
Careful here, because two regimes overlap. The PDPA consent question is whether they agreed to be contacted for that purpose. The Do Not Call provisions apply separately to marketing messages sent to a Singapore telephone number, and the legitimate interests exception is expressly unavailable for that purpose. If the form clearly said you would follow up by WhatsApp about their enquiry and they submitted it, you are on reasonable ground for that follow-up; using the same number later for a promotional blast is a different question.
What happens if we get this wrong?
Financial penalties reach the higher of S$1 million or 10% of annual turnover in Singapore for organisations with local turnover above S$10 million; for smaller organisations the S$1 million ceiling applies. In practice, most enforcement follows a complaint or a breach rather than a proactive audit, and outcomes commonly include directions to fix the process alongside a penalty. The reputational cost of a published decision usually exceeds the fine for an SME.
Who is responsible when a marketing agency runs the tracking?
The organisation whose customers they are remains accountable. An agency acting purely on your instructions and processing on your behalf is generally a data intermediary with narrower duties, but that does not transfer your obligations to notify, obtain consent and protect the data. Get the arrangement written down, including what the agency may and may not upload to advertising platforms.
What to do with this
Start with the tag inventory. It takes an afternoon, it is not a legal exercise, and it usually surfaces two or three things nobody knew were running — an old remarketing tag from a previous agency, a chat widget writing identifiers, a form plugin appending an email address to a thank-you URL where analytics dutifully records it.
Then fix the two items that carry real exposure: whether the consent your customers gave covers disclosing their details to advertising platforms, and whether withdrawal actually propagates to your ad audiences. Those two are where a complaint becomes a problem, and they are both solvable in a week.
Everything else — the banner design, the policy wording, the retention schedule — is worth doing properly and rarely the thing that bites first.
If you would rather have the whole stack reviewed and rebuilt so it measures properly and stands up to scrutiny, that is the first phase of every engagement with our performance marketing team. The measurement framework it sits inside is in our performance marketing guide, the tagging detail in our guides to conversion tracking and UTM discipline, the customer-value side in lifetime value, and the work we have done for other Singapore businesses in our case studies.
Last updated 2 August 2026. Written by Adrian Tan and the SDM team. Sources: PDPC Advisory Guidelines on the PDPA for Selected Topics, Chapter 7 “Online Activities” (revised May 2024); PDPC guidance on the Do Not Call provisions and the legitimate interests exception; PDPC announcements on the cessation of NRIC use for authentication by 31 December 2026 and enforcement from 1 January 2027; PDPC materials on the enhanced financial penalty regime in force from 1 October 2022; Google Analytics 4 and Google Ads help documentation. This article is general information, not legal advice.


