PDPA and marketing for Singapore clinics
Your advertising collects some of the most sensitive data there is. Agreeing to treatment doesn't let you market to a patient, one form can't cover three separate permissions, and every phone number in your CRM sits behind a national opt-out list.
Can a Singapore clinic use patient data for marketing?
Not without separate permission for marketing. Under the PDPA, a patient who gives you their details for treatment is treated as agreeing to that but not to marketing. The PDPC's healthcare guidance (written with MOH) treats marketing as its own purpose that needs its own consent[cite: 7]. One "blanket" form covering treatment, data, and marketing is a mistake the PDPC calls out directly[cite: 7]. And before you text a Singapore number a marketing message, you have to check the Do Not Call list unless you hold clear written consent[cite: 7].
The MOH rules cover what your ad says[cite: 7]. The HSA rules cover the product it names[cite: 7]. This page covers what happens after the click—the patient data your advertising collects, and what the Personal Data Protection Act (PDPA) lets you do with it[cite: 7].
It matters more in healthcare than almost anywhere, because the data is more sensitive[cite: 7]. The regulator treats the sector specifically: its healthcare guidance was written together with MOH and updated in September 2023[cite: 7].
✕ One blanket form covering all three — The mistake the PDPC names
Consent must be voluntary, informed and specific[cite: 7]. Pre-ticked boxes do not count[cite: 7]. Each purpose stated clearly enough for the patient to decide on it separately, with an opt-out[cite: 7].
Here's the rule underneath the diagram: when a patient hands over data for one thing, that's the only thing you can use it for[cite: 7]. Someone giving a phone number to book a consultation has agreed to be contacted about that consultation[cite: 7]. They haven't agreed to a newsletter, a promotion, or a campaign about a different treatment[cite: 7]. Marketing is a new purpose, and it needs fresh, specific, opt-in permission—freely given, informed, and never a pre-ticked box[cite: 7].
The Do Not Call layer
Even once the data permission is sorted, there's a second gate for texts and calls[cite: 7]. Before you send a marketing message to a Singapore number, you have to check it against the Do Not Call list[cite: 7].
There's one way around the check, and it's specific: the person has given clear, unambiguous written consent (or something similarly firm) to receiving those messages[cite: 7]. That's a higher bar than ordinary data consent[cite: 7].
The regulator's own example: a patient who ticks a box to get appointment-reminder texts has clearly agreed to those reminders, because their whole point is to help with something the patient already booked[cite: 7]. That same tick does not cover promotional messages about other treatments[cite: 7]. Reminders and marketing are different messages with different consent rules[cite: 7].
And the written-consent rule on top
There's a third gate, and it's easy to miss because it lives in the advertising rules, not the data rules[cite: 7]. The MOH clinic rules separately say you can't push an ad to someone—or hand them free advertising material—without their written consent up front (Reg. 6(4))[cite: 7].
So a single promotional text to a patient can need, all at once: PDPA marketing consent to use their data; DNC clearance (or written consent) for the channel; and written consent for the push itself[cite: 7]. Three rulebooks, three permissions, none of which covers the others[cite: 7].
This is also where ad targeting collides with data law[cite: 7]. Building an audience from people who visited a condition-specific page can hint at a health condition—which the ad platforms restrict under their own policies—and the underlying data still has to have been collected properly under the PDPA[cite: 7].
Penalties
The PDPA isn't a soft-touch[cite: 7]. The regulator can impose a financial penalty of up to $1 million, or up to 10% of your annual turnover in Singapore if that turnover tops $10 million—whichever is higher[cite: 7]. It can also order you to stop or fix a breach[cite: 7]. For a clinic, the reputation hit from a data-protection finding usually costs more than the fine[cite: 7].

