aiweb.sg lucky cat logoaiweb.sg
28 August 2026 · 5 min read

PDPA-Compliant Forms & Cookies for SG Websites in 2026

In 2026, getting your website's contact forms and cookie banners right isn't just good practice—it's essential for PDPA compliance. Here's a practical guide for Singapore SME owners to protect customer data and build trust.

PDPA-Compliant Forms & Cookies for SG Websites in 2026

As a Singapore SME owner, you juggle a dozen things at once—sales, operations, GST filings, and more. It’s easy for website compliance to slip down the to-do list. But in 2026, how your site handles personal data isn't just a tech issue; it's a fundamental part of customer trust. Getting your contact forms and cookie notices right is crucial for complying with Singapore's Personal Data Protection Act (PDPA) and showing customers you respect their privacy.

This isn't about complex legal jargon or expensive software. It's about implementing clear, practical steps that align with the expectations of the Personal Data Protection Commission (PDPC). Let's break down what your business website needs today.

The PDPA is built on the idea of consent. But it's not as simple as having a button that says "I agree". For consent to be valid, the PDPC expects it to be clear and informed. This means your website visitors must understand three things before they hand over their data:

  1. What they are agreeing to: The specific action or purpose.
  2. Why you are collecting the data: The purpose for which you'll use it.
  3. How you will use it: The data handling practices.

In the past, a vague link to a 20-page Privacy Policy was considered enough. Not anymore. Today, the key information must be presented upfront, right where the user is submitting their data. This also includes 'deemed consent', where a person voluntarily provides their data for an obvious purpose (like giving their email to receive a quote). However, you cannot assume deemed consent for purposes that aren't obvious, like marketing.

Crafting a PDPA-Compliant Singapore Contact Form

Your 'Contact Us' page is often the first point of data collection. It’s your first and best chance to get consent right. Here's how to ensure your forms are compliant.

The "Purpose" Statement is Key

Right above your "Submit" button, you must have a clear and simple statement explaining what you will do with the information. Avoid generic legal phrases.

  • Old way (No longer sufficient): By submitting this form, you agree to our privacy policy.
  • New, compliant way (Much better): We will use your information to respond to your enquiry. We will not add you to a marketing list or share your details with other companies.

This simple sentence makes the purpose crystal clear at the point of collection.

Only Ask for What You Need

The PDPA includes a "Reasonableness" obligation. This means you should only collect personal data that is reasonable for your stated purpose. Does your simple enquiry form really need a customer's Date of Birth or NRIC number? Almost certainly not.

  • For a general enquiry: Name, Email, and Phone Number are usually sufficient.
  • For a property viewing (e.g., a real estate agent regulated by CEA): You might need more details to pre-qualify the client, which is reasonable for that specific purpose.
  • For an F&B delivery (regulated by SFA): You'll obviously need a delivery address.

Challenge every field on your form. If you can't justify why you need it for the immediate transaction, remove it.

Use Separate, Un-ticked Checkboxes for Marketing

This is the most common mistake we see on SME websites. You cannot bundle consent for an enquiry with consent for marketing. They are two separate purposes and require two separate actions from the user.

Do this:

[Contact Form Fields]

Purpose Statement: We'll use these details to reply to your message.

[ ] Please tick here if you would also like to receive our monthly e-newsletter with special offers.

[SUBMIT]

The key is that the checkbox for marketing must be un-ticked by default. The user must actively opt in. This simple change demonstrates clear, explicit consent for marketing communications.

There's a lot of confusion about cookie banners in Singapore, mostly because people mix up PDPA rules with Europe's stricter GDPR. The PDPA is primarily concerned with the collection of personal data.

So, what does this mean for cookies?

  • If cookies collect personal data: For example, if they track a user's browsing behaviour across different websites to build a detailed profile for targeted advertising, then you need consent.
  • If cookies are for basic functionality or anonymous analytics: For example, cookies that remember items in a shopping cart or Google Analytics tracking which pages are popular (without identifying the specific user), the PDPC's position is generally more relaxed. This can fall under deemed consent, as it's a reasonable part of operating a modern website.

However, for transparency and to future-proof your website, we recommend a simple, unobtrusive cookie banner for all Singapore business sites in 2026. It builds trust and shows you are proactive about privacy.

A good cookie banner should:

  1. Be easy to understand: Avoid jargon.
  2. Not block the entire page: Allow the user to continue browsing.
  3. Provide options: At a minimum, an "Accept" button and a link to your cookie policy.

Example Wording: This site uses cookies to improve your experience. By continuing to browse, you agree to our use of cookies. [Accept] [Learn More]

This approach is pragmatic, respects the user, and aligns with the spirit of the PDPA without being overly aggressive.

Data Retention: Don't Be a Digital Hoarder

The PDPA's "Retention Limitation Obligation" is clear: you should not keep personal data forever. Once the purpose for which the data was collected is fulfilled, you must have a process to cease retaining it.

For an SME, this means you need a simple data retention policy. You don't need a complex legal document; you need a business process.

  • Set a timeframe: Decide how long you will keep data from contact form submissions. A reasonable period might be 12-24 months for enquiries that do not lead to a sale.
  • Schedule regular purges: Once a quarter or twice a year, go into your website's backend (e.g., your WordPress form entries) and delete old submissions.
  • Why bother? Holding onto data you don't need is a liability. It increases your risk in the event of a data breach and shows the PDPC you are not following proper data governance.

Your PDPA Website Checklist for 2026

Feeling overwhelmed? Don't be. Here is a simple checklist to get your Singapore website on the right track.

  • Review All Forms: Audit every form on your site (contact, quote request, newsletter sign-up).
  • Add Clear Purpose Statements: Place a simple sentence above each "Submit" button explaining what the data will be used for.
  • Separate Marketing Consent: Use un-ticked, opt-in checkboxes for any marketing communications.
  • Remove Unnecessary Fields: If you don't need the data, don't ask for it.
  • Implement a Simple Cookie Banner: Use a clear, non-intrusive banner that links to your privacy policy.
  • Draft a Retention Policy: Decide on a timeframe and schedule regular deletion of old data.
  • Update Your Privacy Policy: Make sure it's easy to find, easy to read, and accurately reflects your current practices.

Building a PDPA-compliant website isn't just about avoiding fines. It's about building a trustworthy brand that customers feel safe interacting with. These practices are also positive signals for platforms like your Google Business Profile, as they contribute to a professional and reliable online presence.

FAQ

1. Do I need a cookie banner if I only use Google Analytics?

While the PDPA is less strict than Europe's GDPR for anonymous analytics, installing a simple banner is best practice for transparency. It shows customers you are thoughtful about data and future-proofs your site against evolving regulations. Ensure your Google Analytics is configured not to collect any personally identifiable information (PII).

2. Can I really get in trouble for a non-compliant contact form?

Yes. The PDPC can issue directions and financial penalties for breaches of the PDPA. Perhaps more damaging for an SME, a publicised breach can severely harm your brand's reputation and erode customer trust, which is much harder to win back than a fine is to pay.

3. Does the PSG grant cover making my website PDPA-compliant?

The Productivity Solutions Grant (PSG) supports SMEs in adopting IT solutions and improving productivity. While there isn't a specific grant for "PDPA compliance," these compliance features are an integral part of any professional web design or e-commerce development project. If you are using the PSG to build a new website, ensuring it is PDPA-compliant should be a core requirement for your chosen web design agency.

Want this kind of site for your Singapore business?

Free 1-page trial on aiweb.sg subdomain. Paid plans from S$89/month, live in 3–5 days.