Information, not legal advice
This article is general information about how the PDPA framework is described in the Personal Data Protection Commission's published advisory guidelines. It is not legal advice, and reading it does not make any recording lawful. How the PDPA applies turns on the specific facts — who is recording, what is captured, for what purpose, and on whose behalf. For your own situation, consult a Singapore-qualified lawyer.
Sourcing. Both PDPC guidelines quoted here were read directly, in full: the Advisory Guidelines on Key Concepts in the Personal Data Protection Act (revised 1 October 2021) and the Advisory Guidelines on the Personal Data Protection Act (PDPA) for Selected Topics (revised 23 May 2024). The Act itself was not read first-hand — Singapore Statutes Online returned HTTP 403 to our request — so every statutory reference below is quoted as stated in the PDPC's guidelines, which are the Commission's own published interpretation, not the text of the statute.
What law governs this, and who does it apply to?
The relevant law is the Personal Data Protection Act 2012 ("PDPA"), administered by the Personal Data Protection Commission ("PDPC"). On the consent requirement, the PDPC's Advisory Guidelines on the PDPA for Selected Topics (revised 23 May 2024) state at paragraph 4.5:
"Among other obligations, the Data Protection Provisions require consent from the individual to be obtained for the purposes of the collection, use or disclosure of his personal data. Exceptions to this Consent Obligation may apply depending on the circumstances, for example where the photographer is acting in his personal or domestic capacity, such as when he takes photographs or video recordings for his own personal purposes at a gathering for family and friends."
Who carries that obligation is a separate question from whether it exists. The Advisory Guidelines on Key Concepts in the PDPA (revised 1 October 2021) set out three excluded categories on whom the Data Protection Provisions impose no obligations: an individual acting in a personal or domestic capacity, "Any employee acting in the course of his or her employment with an organisation", and any public agency. Those guidelines also explain that an individual "acts in a personal capacity if he or she undertakes activities for his or her own purposes" — which is not what a salesperson recording a client for their employer is doing.
Selected Topics puts the consequence plainly, at paragraph 4.6:
"Similarly, if the photographer or videographer is an employee acting in the course of his employment with an organisation, he will not be required to comply with the Data Protection Provisions and instead his employer will be required to comply".
So the employee exclusion is not a loophole that makes recording unregulated. It moves the obligation onto the business.
Is a recording of a client conversation personal data?
It can be. Selected Topics, paragraph 4.2:
"An audio recording may comprise personal data if an individual can be identified from that audio recording, or from that recording and other information that the organisation has or is likely to have access to."
Footnote 10 to that paragraph adds: "An individual may be identified from his voice, for example, where the voice clip is sufficiently clear and of a sufficient duration." A recorded sales meeting normally clears that bar comfortably — the client is named, their circumstances are discussed, and the organisation holds a client record it can match the voice to.
Is there a "public place" exception, and does it cover a sales conversation?
There is a real exception, and the Key Concepts guidelines describe both where it comes from and what it means:
"Another significant exception in paragraph 1 under Part 2 of the First Schedule to the PDPA relates to personal data that is publicly available. The term “publicly available” is defined in section 2(1) of the PDPA and refers to personal data (about an individual) that is generally available to the public, including personal data which can be observed by reasonably expected means at a location or an event at which the individual appears and that is open to the public."
That is the PDPC's account of section 2(1) and of First Schedule, Part 2, paragraph 1 — the two statutory anchors for this exception. On the "generally available" limb, the guidelines add: "Personal data is generally available to the public if any member of the public could obtain or access the data with few or no restrictions. In some situations, the existence of restrictions may not prevent the data from being publicly available."
On the "open to the public" limb: "A location or event would be considered “open to the public” if members of the public can enter or access the location with few or no restrictions. Generally speaking, the more restrictions there are for access to a particular location, the less likely it would be considered “open to the public”."
The important part for anyone meeting a client in a café is what the guidelines say next. "The Commission recognises that there can be private spaces within public spaces." And: "In addition, a location is not open to the public merely because members of the public may look into the premises or location."
The worked illustration is a taxi: "During the period(s) of hire, the interior of the taxi would not be considered a location that is open to the public, even though the taxi itself may be in a public space." The conclusion the Commission draws from it is hedged, and the hedging is the point:
"The “publicly available data” exception may not apply to such private spaces within public spaces and an organisation must typically provide appropriate notification and obtain consent before collecting, using or disclosing personal data (e.g. in-vehicle video cameras which collect personal data of the passengers in a taxi)".
The phrases "may not apply" and "must typically" are the Commission's own, not a softening of them. The guidelines do not say the exception never applies inside a private space, and they do not address a salesperson recording a client at all — that comparison is ours, not the Commission's. What the guidelines do rule out is the shorthand this post exists to test: there is no blanket rule that a location open to the public makes the personal data collected there publicly available. A private, identifiable, one-to-one business conversation sits closer to the consent-required end of the Commission's own examples than to a photo of a passer-by at a public event.
Does that mean sales conversations can never be recorded?
No. It means the route the guidelines describe is notification and consent, rather than an assumption that the venue disposes of the question. Consent under the PDPA is not only the express, signed kind: Key Concepts describes deemed consent by conduct, by contractual necessity and by notification, and says of the first:
"Deemed consent by conduct applies to situations where the individual voluntarily provides his personal data to the organisation. The purposes are limited to those that are objectively obvious and reasonably appropriate from the surrounding circumstances."
Whether a particular disclosure at the start of a particular meeting establishes valid consent for a particular purpose is exactly the fact-specific question the guidelines do not answer for you, and this page cannot either. What is clear from the guidelines is the direction of travel: tell the person, state the purpose, and do it before you record — rather than reasoning backwards from where you happen to be sitting.
What does this mean practically for a sales team in Singapore?
- > Do not treat "we're in a public place" as the end of the analysis. The Commission's own guidelines recognise private spaces within public spaces and say the exception "may not apply" to them.
- > Notification and consent are what the guidelines describe as typical where a private space is involved — "must typically provide appropriate notification and obtain consent" is the phrasing used.
- > The obligation sits with the employer, not the employee who pressed record. Selected Topics 4.6 is explicit that the employer is the one required to comply.
- > No tool discharges the disclosure for you. Closer has no consent prompt and no recording announcement, and no certification of any kind. Using it says nothing about your compliance position.
- > Get a Singapore-qualified lawyer to look at your actual process — especially where sensitive personal data, cross-border processing (audio and transcript text are processed by a third-party provider outside Singapore) or clients with their own confidentiality obligations are involved.
Key takeaways
- > The PDPC's guidelines state that an audio recording may comprise personal data where the individual can be identified from it.
- > The guidelines describe the consent obligation as the general rule, with exceptions that "may apply depending on the circumstances".
- > The publicly available data exception rests on a location being open to the public — the guidelines recognise private spaces within public spaces, and say it "may not apply" there.
- > Where it does not apply, an organisation "must typically provide appropriate notification and obtain consent" before collecting personal data.
- > The compliance obligation falls on the employer, not the individual employee acting in the course of employment.
- > Closer makes no disclosure to your client and holds no certification; that part is entirely yours.