What Laws and Regulations Apply?
Electronic marketing in Singapore is primarily regulated by two key laws: the Spam Control Act (SCA) and the Personal Data Protection Act of 2012 (PDPA).
Spam is defined in Singapore law as unsolicited commercial electronic messages sent in bulk to individuals who have not requested or consented to receive them. Both acts govern how businesses can use email, text, and other messaging systems for marketing.
The Spam Control Act
Who and What Does the Act Apply To?
The Spam Control Act regulates the content and labeling of unsolicited commercial electronic messages sent in Singapore. It applies to:
- Emails, SMS, and multimedia messages.
- Any electronic message with a Singapore link, which covers situations where:
- The message originates in Singapore.
- The sender is an individual located in Singapore at the time of sending.
- The sender is an entity whose central management or control is in Singapore.
- The recipient is physically in Singapore at the time of receiving.
- The recipient is an entity conducting business in Singapore.
- The message is likely to have been accessed through computers, servers, or mobile devices located in Singapore.
Important Terms
- Unsolicited: Under Section 5, a message is unsolicited if the recipient did not request or consent to receive it.
- Bulk Sending Thresholds:
- More than 100 messages with the same or similar content in 24 hours.
- More than 1,000 messages with the same or similar content in 30 days.
- More than 10,000 messages with the same or similar content in one year.
If these thresholds are crossed, the message will be considered bulk communication and subject to regulation.
Compliance Requirements
Part III of the Act requires compliance with the following:
- Unsubscribe Facility
- Messages must include an unsubscribe option that is valid for at least 30 days.
- It must not cost more than the standard rate to unsubscribe.
- Requests must be honored within 10 days.
- Contact information must be clear, conspicuous, and in English (or English alongside any other language used).
- Email campaigns must include a valid unsubscribe email address. SMS or MMS campaigns must provide a mobile number for opt-out.
- Labeling and Content Rules
- Subject field titles must not be false or misleading.
- The marker “” must be included in the subject line to indicate advertising.
- Header information must not be misleading.
- A valid and functional sender contact address must be provided.
Risks of Non-Compliance
Recipients may pursue civil proceedings for damages if a sender breaches the Spam Control Act. Remedies include:
- Injunctions to prevent further non-compliance.
- Damages equal to actual loss, or statutory damages of SGD 25 per message, capped at SGD 1 million.
The Personal Data Protection Act (PDPA)
The Personal Data Protection Act of 2012 regulates the collection, use, and disclosure of personal data. It requires businesses to obtain consent before sending marketing communications using personal data such as email addresses.
The Act also established the Do Not Call (DNC) Registry (PDPC DNC Registry), which allows individuals to register phone numbers to block unwanted marketing messages by SMS, MMS, and voice calls. Email is not covered by the DNC Registry, but PDPA requirements still apply to email addresses collected, stored, and used for campaigns.
Under PDPA:
- Consent must be clear and informed.
- Collected data must only be used for the purposes stated at the point of collection.
- Organizations must provide a mechanism to withdraw consent and have a data protection officer to manage compliance.
Best Practices for Email Marketing Compliance in Singapore
To safely run email campaigns in Singapore in 2025, businesses should:
- Ensure Consent
Use opt-in forms to confirm that recipients have consented to receive communication. Avoid pre-ticked checkboxes or implied consent.
- Provide Clear Unsubscribes
All messages should contain an easily accessible unsubscribe link or instructions that work for at least 30 days after sending.
- Apply Accurate Labeling
Always include “” in the subject field for commercial messages and avoid misleading subject lines.
- Maintain Proper Records
Store evidence of consent and the time of collection. This is critical in the event of regulatory investigations.
- Respect the DNC Registry
Although email is not part of the registry, integrate DNC compliance with any cross-channel marketing (SMS, phone).
- Check Local Guidance
Organizations in Singapore like the IMDA offer compliance checklists and best practices. Consult them before launching campaigns.
Key Links and Resources
- Spam Control Act
- Personal Data Protection Act of 2012
- Personal Data Protection Commission – DNC Registry
- Singapore Law To Control Spam – IMDA
- Direct Marketing Association of Singapore (DMAS) – Email Marketing Compliance Checklist
- Consumers Association of Singapore (CASE)
- Singapore Business Federation
Key Takeaways for 2025
- The Spam Control Act applies to bulk unsolicited marketing messages with a Singapore link.
- The PDPA governs personal data usage and requires consent for collection and use.
- Non-compliance may lead to statutory fines, damages, or injunctions.
- Always provide unsubscribe options, avoid misleading headers, and label content clearly.
- Use opt-in methods and integrate compliance into all digital campaigns.
Email marketing in Singapore requires careful legal compliance as well as best practices in data handling. By respecting privacy laws and ensuring transparency, businesses not only avoid penalties but also build trust with Singaporean consumers.