Singapore PDPA Transfer Limitation: What a Processor Contract Should Cover
Founder & Lead Engineer, RAITHub
If a Singapore organisation sends personal data to an overseas vendor, the PDPA's Transfer Limitation Obligation makes it responsible for ensuring the recipient gives a comparable standard of protection. The usual route is a written contract that imposes the Protection, Retention Limitation and breach-notification obligations and names the countries the data may go to. Financial penalties can reach S$1 million.
This guide is for founders, CTOs and operations leads in Singapore who are about to hire an offshore development team. RAITHub is a software studio in Dhaka, so we have an interest in the answer; we are the overseas vendor in this picture, and we have no office in Singapore. Every point below is drawn from the Personal Data Protection Commission's own guidance and linked so you can read it. This is general information, not legal advice. Confirm every point with your adviser and the Personal Data Protection Commission (PDPC) before you sign.
Is an offshore developer a data intermediary under the PDPA?
Usually, yes, if it only touches personal data to do work for you. The PDPC defines a data intermediary as "an organisation that processes personal data on behalf of another organisation" (PDPC Advisory Guidelines on Key Concepts in the PDPA, revised 29 April 2026, paragraph 6.15). Where it does so under a written contract, the intermediary carries only three of the obligations directly: Protection, Retention Limitation, and notifying you of a data breach (6.16).
That status has limits that matter for a build contract:
- You stay responsible. Section 4(3) gives you the same obligations for data an intermediary processes for you as if you processed it yourself (6.20). The contract does not move the risk off your books.
- Going beyond your instructions ends the status. If the vendor uses the data for its own purposes, it is no longer a data intermediary for that use, and all the obligations apply to it (6.25).
- Due diligence is yours. The PDPC calls checking an intermediary's ability to protect the data good practice (6.20).
What does the Transfer Limitation Obligation actually require?
It applies when personal data leaves Singapore and you give up possession or direct control of it. The guidelines give servers you own overseas, where the data stays in your control, as a case where it does not apply (19.1). When it does apply, you must ensure the recipient is bound by legally enforceable obligations giving the data a standard of protection comparable to the PDPA (19.4).
Those obligations can come from four places (19.5):
- a law that applies to the recipient;
- a contract that imposes a comparable standard and specifies the countries and territories the data may be transferred to;
- binding corporate rules, for transfers inside a group; or
- another legally binding instrument.
A recipient can also be treated as bound if it holds a specified certification. For a data intermediary, the guidelines list the Global or APEC Cross-Border Privacy Rules (CBPR) and the Global or APEC Privacy Recognition for Processors (PRP) (19.6). There are fallbacks too, such as consent after giving the individual a written summary of the protection abroad, or a transfer necessary for a contract with the individual (19.7). For a development vendor, the contract is the practical route, and the PDPC encourages the ASEAN Model Contract Clauses as a starting template (19.10).
This holds whichever way the data moves. If you transfer data to an overseas intermediary, or your Singapore intermediary sends it abroad, the PDPC treats the Transfer Limitation Obligation as yours, and the onus is on you to obtain assurances, which can include relying on the intermediary's policies and certifications (6.22 to 6.23).
What should a processor contract with an offshore vendor contain?
For a data intermediary, the PDPC's table of minimum contractual protections lists Protection, Retention Limitation and data breach notification, meaning the intermediary notifies you without undue delay (19.9). A contract you can actually operate needs a little more around those three. The table maps each clause to the paragraph it comes from.
| Clause | Where it comes from | What to ask the vendor for |
|---|---|---|
| Scope and instructions | 6.21, 6.25 | A written list of the data categories, the purposes, and a promise to use the data only on your instructions. |
| Named countries and territories | 19.5 | Where the data is stored and from where it may be accessed, for example storage in Singapore and approved access from Bangladesh only. |
| Protection | 19.9, 17.5 | Access controls, encryption, confidentiality obligations on every team member, and multi-factor sign-in on production systems. |
| Retention limitation | 19.9, 18.4 | Deletion or return of your data when the purpose ends or the contract ends, with written confirmation and no copies on laptops. |
| Breach notification to you | 6.21, 19.9, 20.9 | Notice without undue delay once the vendor has credible grounds to believe a breach occurred, a named contact on each side, and help with your assessment. |
| Sub-processors and onward transfer | 6.22–6.23 | A list of sub-processors, your approval before any new one, and the same terms flowed down to each. |
| Assurance and due diligence | 6.20, 6.23 | Written security policies, answers to your security questionnaire, and a right to review evidence. |
| Template | 19.10 | Willingness to work from the ASEAN Model Contract Clauses, or your own data processing agreement, rather than the vendor's. |
Put the IP assignment and NDA in the same bundle; the offshore IP assignment checklist covers those clauses. If you have worked with European vendors, the structure will feel familiar; outsourcing under GDPR shows the equivalent clauses there.
What are the breach notification deadlines when a vendor is involved?
The clock is short, and it starts with the vendor. The intermediary does not decide whether a breach is notifiable; you do (20.8). The guidelines suggest writing the breach procedure into the contract (20.9).
| Step | Who | Deadline in the guidelines |
|---|---|---|
| Tell you about a suspected breach | Vendor | Without undue delay from the time it has credible grounds to believe a breach occurred (6.21) |
| Assess whether the breach is notifiable | You | Reasonably quickly, and generally within 30 calendar days (20.4) |
| Decide the trigger | You | Notifiable if it is likely to cause significant harm, including for prescribed classes such as financial data or NRIC numbers with names, or if it affects 500 or more individuals (20.15, 20.20; PDPA s26B) |
| Notify the PDPC | You | Within 3 calendar days of deciding the breach is notifiable (20.22; PDPA s26D(1)) |
| Notify affected individuals | You | Where significant harm is likely, at the same time as or after notifying the PDPC (20.22) |
In engineering terms, the vendor's job is to make that first row fast and the rest possible: logs that show which records were touched, and by whom. Designing a SaaS audit log covers what to record.
Can the data stay in Singapore while the team works from Dhaka?
Often, yes, and it is the simplest way to shrink the problem. Host production in Singapore, for example in the AWS Asia Pacific (Singapore) region, ap-southeast-1 (AWS Regions), and let the team build against synthetic data. This is engineering guidance; whether remote access to a Singapore-hosted system counts as a transfer in your set-up is a question for your adviser.
- Synthetic data by default. Development and staging run on generated records, never a copy of production.
- No standing production access. Access for a live incident is requested, approved by you, time-limited and logged.
- Tenant isolation in the database. Row-level security keeps one customer's rows away from another's even if application code slips; see the Postgres row-level security guide.
- A guard in the seed script, so fake data can never be written to the production database by mistake:
// scripts/seed.ts: synthetic data goes to dev and staging only.
const ALLOWED_HOSTS = ['localhost', 'staging-db.internal']
const host = new URL(process.env.DATABASE_URL ?? 'postgres://unset').hostname
if (!ALLOWED_HOSTS.includes(host)) {
throw new Error('Refusing to seed ' + host + ': not a dev or staging database')
}
For the wider checklist, SaaS security practices covers secrets, sessions and dependency updates.
Who is the data protection officer when the team is offshore?
You are, or someone you appoint. The data protection officer (DPO) obligations sit with the Singapore organisation, and the PDPC expects your business contact information to be reachable during Singapore business hours (21.5, 21.7). A vendor can support your DPO with records and fast answers; it cannot take the role over. Singapore is 2 hours ahead of Dhaka all year, so with both sides on a 9:00 to 18:00 day there are about 7 shared working hours, 11:00 to 18:00 Singapore time, for incident calls.
What is at stake if the transfer goes wrong?
The guidelines list a financial penalty of up to S$1 million, or in due course up to S$1 million or 10% of annual turnover in Singapore, whichever is higher (21.14). The larger cost is usually the incident itself: forensic time, customer notices and lost enterprise deals. Enterprise buyers will also ask these questions in their vendor review; answering a first security questionnaire without SOC 2 shows how to answer honestly.
Why RAITHub for this
- We sign your paper. RAITHub signs DPAs and SCCs, will work from the ASEAN Model Contract Clauses if your adviser chooses them, and follows your controls. NDA is standard, and the client owns the IP.
- Synthetic data first. Builds default to generated data and seed guards like the one above, so most of the team never needs production access.
- Access control we have shipped. Sundor Skin runs 146 PostgreSQL tables with row-level security, 88 permission codes and 12 staff roles, covered by 530+ tests.
- A same-day overlap. About 7 shared hours with Singapore, plus written daily handoffs, so an incident question gets a live answer.
- A clear next step. Multi-tenant products run under SaaS development; integration-heavy work under API and backend development.
When you don't need us
- You need a vendor with CBPR or PRP certification. RAITHub holds neither, nor SOC 2 or ISO 27001. If your policy requires one, choose a certified vendor.
- You need legal advice. RAITHub has no legal expertise. Have a Singapore data protection lawyer draft or review the contract.
- Your policy says no personal data may be accessed outside Singapore at all. Then use a local team, or keep the offshore team strictly on synthetic data with no incident role.
- You want a developer placed in your team. RAITHub does not offer staff augmentation.
For a wider view of the vendor risk, see is it safe to hire a Bangladesh software agency.
Sources checked on 30 September 2026, against the PDPC Advisory Guidelines on Key Concepts in the PDPA as revised on 29 April 2026. Paragraph numbers refer to that document. General information only; confirm with your adviser and the PDPC.
If none of those rule us out, book the free 15-minute technical audit. Bring a list of the personal data your product holds, and we will tell you on the call what the team would and would not need to see.
Frequently asked questions
Does the PDPA allow personal data to be sent to a vendor outside Singapore?
Yes, if you ensure the recipient is bound by legally enforceable obligations that give a comparable standard of protection, most often through a contract naming the countries the data may go to. This is general information; confirm the current rule with your adviser and the PDPC.
Is an offshore development agency a data intermediary?
Usually, if it processes personal data only on your behalf and under a written contract. It then carries the Protection, Retention Limitation and breach-notification obligations directly, while you remain responsible for the data as if you processed it yourself.
What must a data intermediary contract include under the PDPA?
The PDPC's minimum list for an intermediary is protection of the data, retention limitation, and notifying you of a breach without undue delay. In practice, add the scope of processing, the permitted countries, sub-processor approval and a right to review evidence.
How fast must a data breach be reported to the PDPC?
Within 3 calendar days of deciding the breach is notifiable. A breach is notifiable if it is likely to cause significant harm or affects 500 or more individuals, and the assessment should generally finish within 30 days.
Can I use the ASEAN Model Contract Clauses with an offshore developer?
The PDPC encourages them as a template for transfer contracts. RAITHub will work from them if your adviser chooses them, or from your own data processing agreement.
Is RAITHub certified under APEC CBPR or PRP?
No. RAITHub holds no CBPR, PRP, SOC 2 or ISO 27001 certification. It signs DPAs and SCCs and follows your controls, which means your transfer would rest on the contract rather than a certification.
Related posts
Ready to discuss your project?
Book a free 15-minute technical audit with our engineering team.