If you run a GP or family clinic, patient data is the quiet risk sitting in your practice every day — and most owners have never been walked through it plainly. So let's do that. No jargon, just what actually applies to a Singapore clinic and what to do about it.
Yes, the PDPA applies — and you need a DPO
The PDPA covers every organisation in Singapore, and a clinic is no exception, no matter how small. That means two baseline things. First, you must appoint a Data Protection Officer (DPO) and make their business contact available (a name or role plus an email, at reception or on your site). Second, you have to actually handle patient data the way the law expects — consent, protection, retention, and access requests. Most small clinics don't realise the DPO rule even exists, which means many are already non-compliant without knowing it. If you want the full picture on that one piece, I've written a dedicated guide: does my clinic need a DPO?
The data a GP clinic actually holds
It's worth seeing it written out, because the volume and the sensitivity are the whole reason the bar is higher for you:
- ✓Full medical records — diagnoses, notes, test results, chronic conditions.
- ✓NRIC and contact details — name, address, phone, email, next of kin.
- ✓Medication history — prescriptions, allergies, repeat scripts.
- ✓MCs — often shared with the patient's employer or school.
- ✓Referrals — letters to specialists, hospitals and allied health.
- ✓Vaccination & health-screening records — including workplace and travel screening.
- ✓Insurance, MediSave & CHAS-subsidy claims — claim forms, policy and subsidy details.
That's a high volume of sensitive data flowing through a small front desk every single day. Singapore's PDPA doesn't have a separate "sensitive data" category like the EU, but the PDPC treats medical information as data where a breach causes significant harm — so clinics are held to a higher standard of protection. The PDPC and MOH even publish a specific Advisory Guideline for the Healthcare Sector (last revised September 2023).
The everyday gaps that trip clinics up
The problems are almost never dramatic hacks. They're small, routine habits. These are the ones I see most:
- 1Referrals & sharing — sending records to specialists, insurers, employers or panel administrators without a clear basis. A referral for care is usually fine; sending records to an insurer or employer needs the patient's clear consent, and you should only send what's actually needed.
- 2Reception privacy — open files, sign-in sheets and screens visible to the next patient in the queue; names called out across a full waiting room.
- 3NRIC over-collection — copying or collecting the full NRIC by default on every form, when it's only truly needed for specific things (identity for a record, or a claim that requires it).
- 4WhatsApp & personal phones — staff messaging patients or snapping photos of records and MCs on personal devices is a real, common exposure.
- 5Retention — no clear schedule, so old records and files just pile up indefinitely (more on the rules below).
The three separate consents
This is the single most common clinic mistake, so it gets its own section. A patient agreeing to one thing is not agreeing to everything:
- 1Consent to treatment — they're happy for you to examine and treat them. That does not, by itself, cover anything else.
- 2Consent to share — sending their records onward (specialist, insurer, employer, panel) is a separate agreement, and they should know what's going where.
- 3Consent to marketing — texting or emailing them health tips, promos or recall campaigns is a different consent again, and it's the one clinics most often assume they have when they don't.
Keep these three cleanly separate on your forms and in your system, and you've closed the biggest gap in a clinic's PDPA posture.
How long to keep records
Two rules pull in opposite directions, and you have to reconcile them. MOH generally wants medical records kept for a minimum period — around 6 years for adults, and for children until they turn 21, plus 6 years. The PDPA, meanwhile, says don't keep personal data longer than you need it. The answer isn't to pick one — it's to write a simple retention schedule that meets the MOH minimum and then disposes of data securely once you're past it. Having that schedule on paper is also exactly what shows you're doing the right thing if you're ever asked.
So — what should you do?
You don't need to boil the ocean. In order:
- 1Appoint a DPO and publish their contact — it's the legal baseline.
- 2Split your consents — treatment, sharing and marketing, cleanly separated on your forms.
- 3Tidy the front desk — screens angled away, files out of sight, a quieter way to call names.
- 4Set an NRIC rule — collect it only when genuinely necessary.
- 5Get devices in order — no patient data on personal WhatsApp or phones.
- 6Write a retention schedule — reconciling MOH minimums with the PDPA.
That's the whole job, really. It's a handful of sensible habits and a couple of documents — and once it's in place, it mostly runs itself. If you'd rather not work through it yourself, this is exactly the kind of thing we do for clinics, done for you: mapped, documented, staff briefed, and a named DPO standing behind it.
Common questions
Yes. Under the PDPA every organisation — including a GP or family clinic — must appoint at least one Data Protection Officer and make their business contact available. There's no exemption for small clinics, and because clinics hold sensitive health data the bar is higher.
Yes, but only with a proper basis. Sharing with a specialist for a referral is usually part of your care and consented to. Sharing with an insurer, employer or a panel administrator needs your clear consent — the clinic should tell you what's being sent, to whom and why, and only send what's needed.
Only when it's truly necessary — for example to verify identity for a medical record, or for a CHAS, MediSave or MediShield claim that requires it. A clinic shouldn't copy or collect your full NRIC by default on every form when a lesser identifier would do.
MOH generally requires records kept at least 6 years for adults, and for children until they turn 21 plus 6 years. The PDPA also says don't keep data longer than needed — so a clinic needs a retention schedule that reconciles both.
Sources
- Personal Data Protection Commission (PDPC) — pdpc.gov.sg (appointing a DPO; Healthcare Sector Advisory Guidelines, rev. Sept 2023)
- Ministry of Health (MOH) — record-keeping requirements & the Healthcare Services Act (HCSA)
Want this handled for your clinic?
We help Singapore GP and family clinics get PDPA-ready and stand in as your outsourced DPO — mapped, documented, staff briefed, done for you. Let's talk.