You will be able to describe what the PDPA expects when you collect an email address for marketing and how a person withdraws consent.
Mei Ling bakes custom cakes from her flat in Punggol. Over two years she has collected a few hundred email addresses: from the order form on her website, from a sign-up sheet at a weekend market, and from parents who emailed to ask about prices. She wants to send them all a note about her new festive range. Before she does, she needs to answer a simple question. Which of these people agreed to hear from her about that?
That question sits at the centre of Singapore's Personal Data Protection Act, the PDPA. It sets out how organisations collect, use and disclose personal data, and an email address tied to a person counts. A home business is an organisation for this purpose too, so the rules apply to Mei Ling as much as to a bank. This lesson covers what the Act expects when you collect an address for marketing, and what happens when someone changes their mind. Treat it as a plain-language overview that helps you ask the right questions. A lawyer gives legal advice; this lesson does not.
The PDPA works on two linked ideas. You tell people what you are collecting their data for, and you get their consent for that purpose. Consent is tied to the purpose you named. If you collected an address to send an order confirmation, you have consent to send order confirmations. You do not automatically have consent to send a monthly newsletter.
So the words next to your form matter. "Sign up for updates" is vague. "Get our monthly email with new flavours, order dates for festive seasons and the occasional offer" tells the person what they are agreeing to. When the purpose is clear, the consent is clear, and you know later exactly what you are allowed to send.
The most common mistake small businesses make is treating every address they hold as a marketing address. Someone who asked Mei Ling for a quote gave their email so she could reply with a price. Someone who placed an order gave it so she could confirm the date and send a receipt. Neither of them asked for marketing email.
The fix is to ask separately. On an order form, keep the address field required for the order, and add a separate, unticked checkbox: "Also send me the monthly cake email." The person who ticks it has given marketing consent. The person who leaves it blank still gets the receipt and nothing else. Priya, who runs a maths tuition centre in Tampines and who you may know from earlier marketing courses, does the same on her trial class booking form. Parents who book a trial get the booking details. Only parents who tick the box get her termly email about new classes.
Pre-ticked boxes are worth avoiding. A box the person never touched tells you very little about what they actually agreed to, and it is a weak record if anyone ever asks.
Consent is not permanent. Under the PDPA a person can withdraw consent, and once they do, you have to stop using their data for that purpose. For email, the practical version is simple: when someone unsubscribes or replies "please stop", they stop getting marketing email.
That sounds obvious, but it fails in ordinary ways. An owner exports the list into a spreadsheet, the spreadsheet sits on a laptop for six months, and then someone imports it back into a new email tool, including everyone who unsubscribed in the meantime. Or a customer asks to be removed by WhatsApp and nobody updates the email list. Your system has to carry the withdrawal everywhere the address lives. Most email tools keep unsubscribed contacts on a suppression list so they cannot be emailed again by accident, which is one good reason to keep your list inside the tool rather than in loose files.
If a customer, or the Personal Data Protection Commission, ever asks why you emailed someone, you want to be able to show it. A useful consent record has four parts: when the person signed up, where (which form, which page, which event), what they were told at the time, and how they agreed (ticked a box, clicked a confirmation link).
Email tools capture some of this on their own. A form built inside the tool usually stores the signup date and the form name, and double opt-in, which you will meet in lesson 2.3, adds the confirmation click. The part tools do not keep for you is the wording people saw. When you change your form, save a screenshot of the old version with the date. For paper sign-up sheets at a market, keep the sheet, or at least a photo of it, with the consent line printed at the top.
The Personal Data Protection Commission, or PDPC, publishes advisory guidelines on the key concepts in the Act, including consent, along with guides written for small businesses. They are free on the PDPC website. Summaries in blog posts, including the one you are reading now, leave things out, and the guidelines are updated from time to time. When you are deciding something specific, such as whether you can email people who gave a business card at an event, read what the PDPC says, and if your business handles sensitive data or large lists, ask a lawyer.
The next lesson, 1.3, The Spam Control Act and unsolicited email, covers the second law that applies to marketing email. For now, look at your own signup point. In the activity below you will write the consent line that goes under your form, the one sentence that tells people what they will get and how often, and then hold it up against the PDPC's published guidance.
Write the consent line you will put under your signup form, naming what you will send and how often, then check it against the PDPC's published guidance.
Junxiong-WFG Organisation is an authorised representative of AIA Financial Advisers Private Limited (Reg. No. 201715016G).