If you run a dental clinic, you're not just fixing teeth β you're holding a pile of sensitive patient data, most of it in a cloud system you didn't build. So this is worth ten minutes. Let's keep it plain.
Yes, the PDPA applies β and you need a DPO
There's no "we're just a small clinic" exemption. Singapore's PDPA applies to every organisation, and the first thing it asks of you is to appoint a Data Protection Officer (DPO) and make their business contact available. A dental clinic is no exception β solo practice or five-chair group, the rule is the same. If you've never formally named a DPO, that's the baseline gap to close first. (I wrote a fuller guide on this: does my clinic need a DPO?)
And because you handle health data, the PDPC treats a leak from a clinic as capable of causing significant harm β so you're held to a higher standard than a regular shop. On top of the PDPA, dental clinics also sit under MOH rules and the Healthcare Services Act (HCSA).
The data a dental clinic actually holds
It's more than you might picture. A typical dental clinic collects and keeps:
- βPatient records β full name, contact details, NRIC, medical and dental history.
- βDental X-rays and clinical photos β imaging and before/after shots tied to a named patient.
- βTreatment plans and clinical notes β diagnoses, procedures, medications.
- βFinancing and instalment data β for implants, braces or aligners, plus any third-party payment plan details.
- βInsurance and claims info β policy numbers, claim forms, corporate panel details.
Nearly all of it now lives in a cloud dental practice-management system β appointments, records, imaging and billing in one place. That's convenient, but it doesn't make the responsibility someone else's, as we'll see.
Where dental clinics actually slip
These are the everyday gaps that turn "we've been fine for years" into an incident:
- 1X-rays and clinical photos β how they're stored, who can open them, and how they're shared. Emailing an image to a specialist or a lab, or snapping a photo of a scan on a personal phone, is a real exposure if it's not done securely.
- 2The cloud practice-management system β good software is a strong start, but it only covers how the software holds data. The PDPA still holds your clinic responsible: you need your own DPO, your own policies, and your own consent process. Secure software plus no policies is still non-compliant.
- 3WhatsApp reminders β appointment and recall messages sent from a personal number, or a shared group with patient details in it, blur the line between clinic data and someone's private phone.
- 4Reception privacy β the next patient in the queue seeing a screen, a chart, or overhearing NRIC and treatment details read aloud at the front desk.
- 5Marketing without consent β sending promotions for whitening or aligners to patients who only ever consented to treatment. That's the single most common clinic mistake.
- 6Retention β keeping every record and image forever "just in case", with no schedule for what to delete and when.
The three consents to keep separate
This trips up more clinics than anything else. A patient agreeing to one thing is not agreeing to the others:
- 1Consent to treatment β clinical care. This does not, on its own, let you market to them.
- 2Consent to use their data β for running the clinic: records, billing, recalls, referrals.
- 3Consent to marketing β promotions, newsletters, "come back for a check-up" campaigns. This one is separate and must be freely given β and it can be withdrawn.
Using a before/after photo on your Instagram? That's its own consent again. When in doubt, ask β in writing.
How long to keep records
Two rules pull in opposite directions, and you need a schedule that reconciles them:
- βMOH generally wants medical records kept for at least 6 years for adults, and for children until they turn 21, plus 6 years.
- βThe PDPA says don't keep data longer than you need it β once the purpose and the retention period are done, dispose of it securely.
So the answer isn't "keep everything forever" and it isn't "clear it out early" β it's a written retention schedule that satisfies MOH's minimum and then disposes of data properly. (More detail here: how long must a clinic keep patient records?)
So β what should you do?
Three practical steps. One, appoint a DPO (you legally must) and be honest about whether that person has the knowledge and the time. Two, get the everyday basics right β secure image storage and sharing, clean consent, sensible reminders, a private front desk. Three, write down a retention schedule that meets MOH and the PDPA.
If nobody on your team has the hours or the specialist knowledge, this is the kind of thing you can have done for you β mapped, documented, staff trained, and a named DPO on call if a patient complains or something goes wrong. In a dental clinic, your risk isn't a random audit β it's an incident you weren't set up for, and patients' trust is your whole business.
Common questions
Yes. Under Singapore's PDPA every organisation must appoint at least one Data Protection Officer, and a dental clinic is no exception. There's no size exemption, so even a single-chair practice must name a DPO and make their business contact available.
No. Secure cloud practice-management software helps, but it only covers how the software stores data. The PDPA holds your clinic responsible, so you still need your own appointed DPO, your own consent and privacy policies, a retention schedule, staff habits, and a breach plan. The software is one piece, not the whole thing.
Yes β X-rays and clinical photos are patient records you may keep and use for the patient's care. But they're personal health data, so they must be stored securely and only shared with consent or a proper basis, such as referring to a specialist. Sending images over personal WhatsApp or leaving them on unsecured devices is a common gap.
MOH generally requires records kept at least 6 years for adults, and for children until they turn 21 plus 6 years. The PDPA also says don't keep data longer than needed β so a dental clinic needs a retention schedule that reconciles both.
Sources
- Personal Data Protection Commission (PDPC) β pdpc.gov.sg (appointing a DPO; Healthcare Sector Advisory Guidelines, rev. Sept 2023)
- Ministry of Health (MOH) β record-keeping requirements & the Healthcare Services Act (HCSA)
Want this handled for your dental clinic?
We help Singapore dental clinics get PDPA-ready and stand in as your outsourced DPO β X-rays, cloud software, consent and retention sorted, done for you. Let's talk.