If you run a TCM clinic — acupuncture, tuina, herbal dispensary, a family shophouse practice — you might assume the PDPA is a "big company" thing. It isn't. You hold some of the most sensitive data there is, and the law treats you accordingly. So this is worth ten minutes. Let's keep it simple.
First: yes, the PDPA applies to you
There's a common belief that the PDPA is only for banks, telcos and big chains. It's not. The PDPA applies to every organisation in Singapore that collects personal data — and that includes a one-room TCM clinic. Part of that law is simple: every organisation must appoint a Data Protection Officer (DPO) and make their contact available. There's no size exemption. If you'd like the full picture on that one duty, I wrote a companion guide: does my clinic need a DPO? (Short version: yes.)
What patient data a TCM clinic actually holds
It's more than you'd think. A typical TCM clinic is sitting on:
- ✓Name & contact — phone, sometimes NRIC, address, next-of-kin.
- ✓Health conditions & symptoms — what the patient came in for, their history, allergies.
- ✓Your diagnosis & treatment notes — the TCM syndrome pattern, pulse and tongue findings, acupuncture points used.
- ✓Herbal prescriptions — the formula, doses, and what you dispensed over time.
- ✓Photos — sometimes of skin, tongue, injuries, or posture, often taken on a phone.
- ✓Payment & visit records — who came, when, and what they paid.
Every one of those is personal data, and most of it is health data — the kind where a leak genuinely harms someone. That's why the protection bar is higher for you than for the shop next door.
The everyday gaps (this is where clinics slip)
Nobody gets caught out by the big dramatic things. It's the ordinary daily habits — the "we've always done it this way" ones — that quietly break the rules:
- ✓WhatsApp on staff personal phones — appointment reminders and patient chats sitting in a receptionist's private phone. When that person leaves, your patients' data walks out with them.
- ✓Patient cards on the counter — paper record cards left face-up where the next patient in the queue can read them.
- ✓Promotions without consent — blasting a herbal-tonic offer to everyone in your phone book. Consent to treatment is not consent to marketing (more on this below).
- ✓Over-collecting NRIC — asking for the full NRIC by default on every intake form. You may only collect it when it's truly necessary.
- ✓Keeping records forever — a decade of old paper cards in a back room "just in case." The PDPA says don't keep data longer than you need it.
The three consents — the #1 mistake
This is the single most common thing TCM clinics get wrong, so it's worth slowing down on. There are three separate things a patient might consent to, and they are not the same:
- 1Consent to treatment — the patient agrees to the acupuncture, the tuina, the herbs. This is a clinical decision.
- 2Consent to use their data — that you can hold and use their records to care for them.
- 3Consent to marketing — that you can send them promotions, offers, and health tips.
A patient agreeing to be treated has not agreed to receive your monthly promotion. Mixing these up — treating "they're my patient" as permission to market to them — is the mistake I see most often. Keep marketing consent separate and clearly opt-in, give an easy way to unsubscribe, and remember the Do Not Call rules apply to phone and SMS marketing too.
How long to keep records
Here's the tension clinics have to reconcile. On one side, MOH generally wants medical records kept — as a rule of thumb, at least 6 years for adults, and for children until they turn 21, plus 6 years. On the other side, the PDPA says don't keep personal data longer than you need it. The answer isn't to pick one — it's to write a retention schedule that satisfies MOH's minimum and then disposes of data securely once you're genuinely past it. A clear, written schedule is what turns "boxes of old cards forever" into something defensible.
So — what should a TCM clinic actually do?
You don't need to become a data-protection expert overnight. The practical steps are:
- 1Appoint a DPO — you legally must. It can be you or a staff member.
- 2Map your data — write down what you hold and where it lives (system, paper cards, WhatsApp, phone photos).
- 3Write a simple privacy notice — one plain page telling patients what you collect and why.
- 4Fix the consents — separate treatment, data use, and marketing.
- 5Train your front desk — the counter, the phone, WhatsApp habits. Most leaks start here.
- 6Set a retention schedule — keep what MOH needs, safely dispose of the rest.
You can do all of this in-house if someone genuinely has the time and the know-how. If they don't — which is most small clinics — you can have it done for you: mapped, documented, staff trained, and a named DPO on call if a patient complains. For a neighbourhood TCM clinic that's usually the cheaper and calmer route, because your real risk isn't a random audit — it's an incident you weren't set up for.
Common questions
Yes. Under the PDPA every organisation must appoint at least one Data Protection Officer and make their business contact available — and a TCM clinic is no exception, no matter how small. There is no size exemption.
Yes, but carefully. WhatsApp is fine for things a patient expects, like an appointment reminder, but the exposure is staff using personal phones — patient chats and photos of records sitting on a private device. Use a clinic number, keep chats to what is necessary, and never send marketing blasts without separate consent.
MOH generally requires medical records to be kept for at least 6 years for adults, and for children until they turn 21 plus 6 years. The PDPA also says do not keep data longer than needed, so a TCM clinic needs a retention schedule that reconciles both.
Only with separate marketing consent. A patient agreeing to treatment is not agreeing to receive promotions. You need their clear consent to market to them, an easy way to opt out, and you must respect Do Not Call rules for phone and SMS.
Sources
- Personal Data Protection Commission (PDPC) — pdpc.gov.sg (appointing a DPO; consent & Do Not Call; Healthcare Sector Advisory Guidelines)
- Ministry of Health (MOH) — record-keeping requirements & the Healthcare Services Act (HCSA)
Want this handled for your TCM clinic?
We help Singapore TCM clinics get PDPA-ready and stand in as your outsourced DPO — mapped, documented, staff trained, done for you. Let's talk.