PDPC Singapore: PDPA & DNC Registry Guide for Businesses [2026]

Planning to start telemarketing in Singapore? Before contacting prospective customers, businesses should understand the key PDPA and Do Not Call (DNC) requirements that may apply to their marketing activities.

Learn more about   Juzz Telemarketing Services Singapore

Last updated: August 2026

If your business collects customer information, generates leads, conducts telemarketing or sends marketing messages in Singapore, you may have encountered the terms PDPC, PDPA and DNC.

Although these terms are closely related, they mean different things.

The Personal Data Protection Commission (PDPC) is Singapore’s regulator for personal data protection. The Personal Data Protection Act (PDPA) establishes Singapore’s personal data protection framework, while the Do Not Call (DNC) Registry allows individuals to register Singapore telephone numbers to opt out of certain marketing messages.

For businesses involved in lead generation, telemarketing, appointment setting and digital marketing, understanding these requirements is particularly important.

This guide explains PDPC, PDPA and the DNC Registry and highlights important considerations for businesses conducting marketing activities in Singapore.

This article provides general information and does not constitute legal advice. Businesses should refer to the latest guidance from the Personal Data Protection Commission for their specific circumstances.

What Is the PDPC in Singapore?

PDPC stands for Personal Data Protection Commission.

The PDPC administers and enforces Singapore’s personal data protection regime.

Businesses that collect or handle customers’ personal information should therefore understand the requirements and guidance issued by the PDPC.

Examples of information that businesses commonly handle may include:

  • Names
  • Mobile numbers
  • Email addresses
  • Residential addresses
  • Employment information
  • Customer records
  • Other information that can identify an individual

This is particularly relevant to businesses conducting lead-generation campaigns because prospect information can include a person’s name, telephone number, email address, age range, occupation or other information.

Businesses should have appropriate processes governing how personal information is collected, used, disclosed, stored and protected.

For current regulatory information, businesses should refer to the official Personal Data Protection Commission Singapore website.

What Is the PDPA?

PDPA stands for Personal Data Protection Act.

The PDPA establishes Singapore’s baseline standard for personal data protection while recognising organisations’ legitimate needs to collect, use and disclose personal data for appropriate purposes.

Businesses handling personal information have a range of obligations under the PDPA.

These include areas such as:

  • Accountability
  • Notification of purposes
  • Consent
  • Purpose limitation
  • Accuracy
  • Protection of personal data
  • Retention limitation
  • Transfer limitation
  • Access and correction
  • Data breach notification

Organisations are also required to designate at least one person as their Data Protection Officer (DPO) and make the DPO’s business contact information publicly available.

For businesses involved in sales and marketing, it is important to understand why personal information is being collected, how it will be used and disclosed, and what requirements apply to the particular marketing activity.

PDPC vs PDPA – What’s the Difference?

PDPC and PDPA are sometimes confused, but they are not the same thing.

Term Full Name Meaning
PDPC Personal Data Protection Commission Singapore’s personal data protection regulator
PDPA Personal Data Protection Act Singapore’s personal data protection legislation
DNC Do Not Call Registry Registry allowing individuals to opt out of certain marketing messages

An easy way to remember the difference is:

PDPC = Regulator

PDPA = Law

DNC = Do Not Call Registry

What Is Personal Data?

Personal data generally refers to data about an individual who can be identified from that data alone or together with other information to which an organisation has or is likely to have access.

For example, businesses conducting lead generation may collect information such as:

  • Name
  • Mobile number
  • Email address
  • Age range
  • Occupation
  • Income range
  • Service interests
  • Appointment preferences

Businesses collecting and using this information should consider their obligations under the PDPA.

Personal information can potentially be collected through many different channels, including:

  • Websites
  • Online enquiry forms
  • Landing pages
  • Events
  • Surveys
  • Telephone campaigns
  • Referral campaigns
  • Social media
  • Customer databases
  • Third-party marketing campaigns

What Is the DNC Registry in Singapore?

The Do Not Call Registry, commonly known as the DNC Registry, allows individuals to register Singapore telephone numbers to opt out of certain unsolicited marketing messages.

Singapore has three DNC Registers:

No Voice Call Register

For marketing voice calls.

No Text Message Register

For marketing text messages, including SMS and MMS.

No Fax Message Register

For marketing fax messages.

Businesses conducting marketing campaigns should determine whether their activities fall within the DNC provisions and whether they need to check the relevant register before contacting a telephone number.

Do Businesses Need to Check the DNC Registry?

Generally, organisations must ensure that covered marketing messages are not sent to Singapore telephone numbers registered with the relevant DNC Registry unless an applicable exception applies.

This can apply whether an organisation sends the marketing message itself or causes or authorises another organisation to send it.

One important exception is where an organisation has obtained the recipient’s clear and unambiguous consent to receive marketing messages at the Singapore telephone number.

Businesses relying on such consent should maintain appropriate records showing how the consent was obtained.

What Is Clear and Unambiguous Consent?

For DNC purposes, businesses should not assume that silence or failure to opt out automatically means a prospect has agreed to receive marketing messages.

PDPC guidance recommends an opt-in approach where organisations intend to rely upon clear and unambiguous consent.

The prospect should understand that marketing messages will be sent to their Singapore telephone number and take an affirmative action indicating consent.

This is particularly important for businesses operating online lead-generation forms.

How Does the PDPA Apply to Telemarketing in Singapore?

Telemarketing continues to be used by businesses to reach prospective customers in Singapore.

However, before conducting a telemarketing campaign, businesses should consider both the PDPA and applicable DNC requirements.

Questions businesses should consider include:

Where did the telephone number come from?

What information was given to the individual when their information was collected?

What consent or permission was obtained?

Does the DNC Registry need to be checked?

Has the individual previously asked not to be contacted?

Are appropriate records being maintained?

Businesses should therefore avoid treating a database of telephone numbers simply as a list that can automatically be called without considering how the information was obtained and what requirements apply.

PDPA and Lead Generation in Singapore

Lead generation involves identifying or attracting prospective customers who may be interested in a company’s products or services.

A prospect might, for example, submit an online enquiry asking to learn more about financial planning, renovation, insurance, property or another service.

Information collected could include:

  • Name
  • Mobile number
  • Email address
  • Age range
  • Occupation
  • Income range
  • Preferred appointment time
  • Type of service required

Because this information may constitute personal data, businesses involved in generating, receiving and using leads should consider how that information was obtained and the purpose for which it can be used.

Consent and Lead Generation

Consent can be an important consideration when generating leads.

Where consent is being relied upon, businesses should clearly communicate the relevant purposes for which personal information will be collected, used or disclosed.

For example, if an individual submits an enquiry requesting to be contacted regarding a particular service, the information provided at the point of collection should appropriately explain how the individual’s information will be used.

Businesses should also maintain appropriate records relating to the collection and use of prospect information.

Can You Contact Someone Who Is Registered on the DNC Registry?

Registration on the DNC Registry does not necessarily mean that an individual can never receive a marketing message from any organisation.

For example, an organisation does not need to check the DNC Registry where it has obtained the recipient’s clear and unambiguous consent to send the relevant marketing messages to that Singapore telephone number.

Other exceptions or exclusions may also apply depending on the circumstances.

Businesses should therefore assess each campaign against current PDPC requirements.

Does the DNC Registry Apply to B2B Marketing?

There is an important distinction between consumer marketing and genuine business-to-business (B2B) marketing.

PDPC states that messages targeting businesses rather than individuals are excluded from the DNC provisions.

However, businesses should properly distinguish B2B communication from marketing directed at an individual consumer.

If there is uncertainty, businesses should refer to the latest PDPC guidance.

Does the DNC Registry Apply to WhatsApp Marketing?

Businesses increasingly use messaging platforms such as WhatsApp to communicate with customers and prospects.

Businesses should not assume that using a messaging application automatically removes applicable data-protection or marketing requirements.

Before conducting a marketing campaign, businesses should consider:

  • How the telephone number was obtained
  • What the individual agreed to receive
  • The nature and purpose of the message
  • Whether relevant DNC requirements apply
  • Whether the individual has requested to opt out

Businesses should therefore assess the actual communication and circumstances rather than assuming that changing the communication platform automatically changes their obligations.

What Happens When Someone Opts Out?

Businesses should have processes for dealing with individuals who indicate that they no longer wish to receive marketing communications.

For example, someone might say:

“Please don’t call me again.”

The organisation should have an appropriate process to record and honour applicable opt-out requests.

For covered DNC marketing messages, PDPC states that organisations should provide a way to opt out using the same medium through which the message was sent and, upon receiving an opt-out request, have 21 days to ensure the relevant marketing messages stop being sent to that telephone number.

Maintaining an internal suppression or opt-out list can therefore be an important part of managing larger marketing databases.

PDPA Considerations When Buying Leads

Businesses purchasing leads should not evaluate a lead provider based only on the number of telephone numbers being supplied.

Important questions include:

How were the leads generated?

What information was provided to the prospect?

What did the prospect agree to?

For what purpose was the information collected?

Who may contact the prospect?

How recent is the information?

How are opt-out requests handled?

A database containing thousands of telephone numbers is not necessarily equivalent to a properly generated marketing lead.

Businesses should understand the source and permitted use of prospect information before using it for marketing activities.

PDPA Considerations for Financial Advisors

Financial advisors frequently conduct prospecting and may handle information such as:

  • Prospect names
  • Mobile numbers
  • Age ranges
  • Occupations
  • Income ranges
  • Appointment information
  • Financial-planning interests

Advisors should understand their own organisation’s compliance requirements and approved prospecting procedures before conducting marketing activities.

A structured lead-generation process can help advisors spend less time sourcing prospects and more time engaging potential customers.

Juzz Marketing provides several lead generation solutions for financial advisors, including targeted leads, appointment setting, AI-assisted leads and opt-in leads.

[View Juzz Marketing’s Financial Advisor Lead Generation Services]

PDPA Considerations for Appointment Setting

Appointment setting involves more than simply obtaining a telephone number.

A typical process could involve:

Lead Generation → Prospect Contact → Qualification → Appointment Setting → Advisor or Business Follow-Up

Depending on the campaign, information such as a prospect’s name, mobile number, age range, occupation and preferred appointment details may be collected.

Businesses involved at different stages of the process should understand their responsibilities regarding the handling and use of personal information.

How Can Businesses Improve Their PDPA Practices?

Businesses handling customer and prospect information should establish appropriate data-protection policies and operational processes.

Good practices can include:

  1. Understanding what personal data the business collects.
  2. Identifying why the information is required.
  3. Notifying individuals of the relevant purposes.
  4. Obtaining and recording consent where required.
  5. Maintaining appropriate DNC and marketing procedures.
  6. Protecting databases against unauthorised access.
  7. Restricting customer information to authorised personnel.
  8. Maintaining withdrawal and opt-out processes.
  9. Reviewing third-party service providers that handle personal data.
  10. Regularly reviewing data-protection policies and procedures.

The PDPC’s current framework also requires organisations to take accountability and security seriously, including having a DPO and appropriate protection measures.

Frequently Asked Questions About PDPC, PDPA and DNC

What does PDPC stand for in Singapore?

PDPC stands for Personal Data Protection Commission. It administers and enforces Singapore’s personal data protection regime.

What does PDPA stand for?

PDPA stands for Personal Data Protection Act.

It establishes Singapore’s personal data protection framework.

What is the difference between PDPC and PDPA?

The simplest way to remember the difference is:

PDPC = regulator

PDPA = law

The PDPC administers and enforces Singapore’s personal data protection regime.

What does DNC mean?

DNC stands for Do Not Call.

The DNC Registry allows individuals to register Singapore telephone numbers to opt out of certain marketing messages.

Can businesses still conduct telemarketing in Singapore?

Telemarketing itself is not simply prohibited. Businesses need to ensure their particular marketing activities comply with applicable PDPA, DNC and other legal requirements.

Does being on the DNC Registry mean nobody can market to that number?

Not necessarily.

Exceptions and exclusions can apply. One important example is where the organisation has obtained clear and unambiguous consent to send the relevant marketing messages to that Singapore telephone number.

Does DNC apply to business-to-business calls?

PDPC identifies messages targeting businesses rather than individuals as excluded from the DNC provisions.

Does PDPA apply to lead generation?

Lead generation frequently involves information such as names, telephone numbers and email addresses.

Businesses involved in collecting, using or disclosing personal information should understand the PDPA requirements applicable to their particular activities.

Can I simply buy a database and start calling everyone?

Businesses should first understand where the information originated, how it was collected, the purpose for which it may be used and whether applicable PDPA and DNC requirements have been addressed.

Where Can I Find Official PDPC Information?

For current legislation, DNC requirements, guidelines and data-protection resources, businesses should refer directly to the Personal Data Protection Commission Singapore.

Lead Generation and Appointment Setting with Juzz Marketing

Juzz Marketing provides lead generation, telemarketing and appointment-setting solutions for businesses and financial advisors in Singapore.

Our services include:

  • Targeted lead generation
  • Appointment setting
  • AI-assisted lead engagement
  • Opt-in lead generation
  • Financial advisor prospecting
  • Digital marketing
  • Business process and AI automation

Our objective is to help businesses build a more consistent prospecting pipeline while reducing the amount of time their sales teams spend sourcing potential customers.

Financial advisors can learn more about our Financial Advisor Lead Generation Services.

Contact Juzz Marketing to discuss a lead-generation or appointment-setting campaign for your business.

 

0 replies

Leave a Reply

Want to join the discussion?
Feel free to contribute!

Leave a Reply

Your email address will not be published. Required fields are marked *