← Insights Say hi 👋
Data protection · GP clinics

PDPA for GP & family clinics in Singapore

The short answer

The PDPA applies to your clinic in full — and the bar is higher for you than for a normal business. A GP or family clinic holds some of the most sensitive personal data there is: full medical records, NRIC, contact details, medication history, MCs, referrals, vaccination and screening records, and insurance, MediSave and CHAS-subsidy claim details. On top of the PDPA you also sit under MOH rules and the Healthcare Services Act (HCSA). The good news: getting compliant is mostly about a few sensible habits, and this guide walks you through them.

If you run a GP or family clinic, patient data is the quiet risk sitting in your practice every day — and most owners have never been walked through it plainly. So let's do that. No jargon, just what actually applies to a Singapore clinic and what to do about it.

Yes, the PDPA applies — and you need a DPO

The PDPA covers every organisation in Singapore, and a clinic is no exception, no matter how small. That means two baseline things. First, you must appoint a Data Protection Officer (DPO) and make their business contact available (a name or role plus an email, at reception or on your site). Second, you have to actually handle patient data the way the law expects — consent, protection, retention, and access requests. Most small clinics don't realise the DPO rule even exists, which means many are already non-compliant without knowing it. If you want the full picture on that one piece, I've written a dedicated guide: does my clinic need a DPO?

The data a GP clinic actually holds

It's worth seeing it written out, because the volume and the sensitivity are the whole reason the bar is higher for you:

That's a high volume of sensitive data flowing through a small front desk every single day. Singapore's PDPA doesn't have a separate "sensitive data" category like the EU, but the PDPC treats medical information as data where a breach causes significant harm — so clinics are held to a higher standard of protection. The PDPC and MOH even publish a specific Advisory Guideline for the Healthcare Sector (last revised September 2023).

The everyday gaps that trip clinics up

The problems are almost never dramatic hacks. They're small, routine habits. These are the ones I see most:

The three separate consents

This is the single most common clinic mistake, so it gets its own section. A patient agreeing to one thing is not agreeing to everything:

Keep these three cleanly separate on your forms and in your system, and you've closed the biggest gap in a clinic's PDPA posture.

How long to keep records

Two rules pull in opposite directions, and you have to reconcile them. MOH generally wants medical records kept for a minimum period — around 6 years for adults, and for children until they turn 21, plus 6 years. The PDPA, meanwhile, says don't keep personal data longer than you need it. The answer isn't to pick one — it's to write a simple retention schedule that meets the MOH minimum and then disposes of data securely once you're past it. Having that schedule on paper is also exactly what shows you're doing the right thing if you're ever asked.

So — what should you do?

You don't need to boil the ocean. In order:

That's the whole job, really. It's a handful of sensible habits and a couple of documents — and once it's in place, it mostly runs itself. If you'd rather not work through it yourself, this is exactly the kind of thing we do for clinics, done for you: mapped, documented, staff briefed, and a named DPO standing behind it.

On cost: getting your clinic PDPA-ready is more affordable than most owners expect — and right now we're running a founding-clinic offer (a substantial first-year discount) to make it easy to start. Ask us about it.
This is general information to help clinic owners understand the PDPA — it isn't legal advice. For your clinic's specific situation, check the PDPC's official guidance, the MOH healthcare guidelines, or a qualified professional.

Common questions

Yes. Under the PDPA every organisation — including a GP or family clinic — must appoint at least one Data Protection Officer and make their business contact available. There's no exemption for small clinics, and because clinics hold sensitive health data the bar is higher.

Yes, but only with a proper basis. Sharing with a specialist for a referral is usually part of your care and consented to. Sharing with an insurer, employer or a panel administrator needs your clear consent — the clinic should tell you what's being sent, to whom and why, and only send what's needed.

Only when it's truly necessary — for example to verify identity for a medical record, or for a CHAS, MediSave or MediShield claim that requires it. A clinic shouldn't copy or collect your full NRIC by default on every form when a lesser identifier would do.

MOH generally requires records kept at least 6 years for adults, and for children until they turn 21 plus 6 years. The PDPA also says don't keep data longer than needed — so a clinic needs a retention schedule that reconciles both.

Sources

  • Personal Data Protection Commission (PDPC) — pdpc.gov.sg (appointing a DPO; Healthcare Sector Advisory Guidelines, rev. Sept 2023)
  • Ministry of Health (MOH) — record-keeping requirements & the Healthcare Services Act (HCSA)
Eugene
Eugene

I build websites and help Singapore businesses run them well. HeyAda is my Singapore web studio — design, SEO, and the practical side of running a business online, including the patient data your clinic collects. I write these guides in plain English, and I can be your clinic's outsourced DPO. Getting your clinic PDPA-ready? Say hi.

Want this handled for your clinic?

We help Singapore GP and family clinics get PDPA-ready and stand in as your outsourced DPO — mapped, documented, staff briefed, done for you. Let's talk.