PDPA • Do Not Call • Written Consent

PDPA and marketing for Singapore clinics

Your advertising collects some of the most sensitive data there is. Agreeing to treatment doesn't let you market to a patient, one form can't cover three separate permissions, and every phone number in your CRM sits behind a national opt-out list.

By Marcus Goh, Founder & Director, PULSE Digital Published Checked against rules in force as at 19 May 2026

Can a Singapore clinic use patient data for marketing?

Not without separate permission for marketing. Under the PDPA, a patient who gives you their details for treatment is treated as agreeing to that but not to marketing. The PDPC's healthcare guidance (written with MOH) treats marketing as its own purpose that needs its own consent[cite: 7]. One "blanket" form covering treatment, data, and marketing is a mistake the PDPC calls out directly[cite: 7]. And before you text a Singapore number a marketing message, you have to check the Do Not Call list unless you hold clear written consent[cite: 7].

The MOH rules cover what your ad says[cite: 7]. The HSA rules cover the product it names[cite: 7]. This page covers what happens after the click—the patient data your advertising collects, and what the Personal Data Protection Act (PDPA) lets you do with it[cite: 7].

It matters more in healthcare than almost anywhere, because the data is more sensitive[cite: 7]. The regulator treats the sector specifically: its healthcare guidance was written together with MOH and updated in September 2023[cite: 7].

One Patient • Three Distinct Consents
Consent 1
Treatment
To the medical procedure or care[cite: 7].
Deemed on volunteering[cite: 7].
Consent 2
Data
To collect, use and disclose data for stated purposes[cite: 7].
Explicit consent required[cite: 7].
Consent 3
Marketing
To promotional communications[cite: 7].
Never deemed[cite: 7].

✕ One blanket form covering all three — The mistake the PDPC names

Consent must be voluntary, informed and specific[cite: 7]. Pre-ticked boxes do not count[cite: 7]. Each purpose stated clearly enough for the patient to decide on it separately, with an opt-out[cite: 7].

Here's the rule underneath the diagram: when a patient hands over data for one thing, that's the only thing you can use it for[cite: 7]. Someone giving a phone number to book a consultation has agreed to be contacted about that consultation[cite: 7]. They haven't agreed to a newsletter, a promotion, or a campaign about a different treatment[cite: 7]. Marketing is a new purpose, and it needs fresh, specific, opt-in permission—freely given, informed, and never a pre-ticked box[cite: 7].

The Do Not Call layer

Even once the data permission is sorted, there's a second gate for texts and calls[cite: 7]. Before you send a marketing message to a Singapore number, you have to check it against the Do Not Call list[cite: 7].

There's one way around the check, and it's specific: the person has given clear, unambiguous written consent (or something similarly firm) to receiving those messages[cite: 7]. That's a higher bar than ordinary data consent[cite: 7].

The Reminder-vs-Marketing Line • PDPA DNC

The regulator's own example: a patient who ticks a box to get appointment-reminder texts has clearly agreed to those reminders, because their whole point is to help with something the patient already booked[cite: 7]. That same tick does not cover promotional messages about other treatments[cite: 7]. Reminders and marketing are different messages with different consent rules[cite: 7].

And the written-consent rule on top

There's a third gate, and it's easy to miss because it lives in the advertising rules, not the data rules[cite: 7]. The MOH clinic rules separately say you can't push an ad to someone—or hand them free advertising material—without their written consent up front (Reg. 6(4))[cite: 7].

So a single promotional text to a patient can need, all at once: PDPA marketing consent to use their data; DNC clearance (or written consent) for the channel; and written consent for the push itself[cite: 7]. Three rulebooks, three permissions, none of which covers the others[cite: 7].

The Remarketing Footnote

This is also where ad targeting collides with data law[cite: 7]. Building an audience from people who visited a condition-specific page can hint at a health condition—which the ad platforms restrict under their own policies—and the underlying data still has to have been collected properly under the PDPA[cite: 7].

Penalties

The PDPA isn't a soft-touch[cite: 7]. The regulator can impose a financial penalty of up to $1 million, or up to 10% of your annual turnover in Singapore if that turnover tops $10 million—whichever is higher[cite: 7]. It can also order you to stop or fix a breach[cite: 7]. For a clinic, the reputation hit from a data-protection finding usually costs more than the fine[cite: 7].

Common Questions

Can a clinic use patient data for marketing?
Not without separate marketing permission[cite: 7]. Data given for treatment can only be used for treatment[cite: 7]. The regulator's healthcare guidance, written with MOH, treats marketing as its own purpose needing its own consent, and warns against bundling everything into one form[cite: 7].
Is agreeing to treatment the same as agreeing to marketing?
No—treatment, data and marketing are three separate permissions[cite: 7]. Agreeing to treatment doesn't let you send promotions[cite: 7]. Consent has to be freely given, informed and specific, and pre-ticked boxes don't count[cite: 7].
Do I need to check the Do Not Call list before texting patients?
Yes, for marketing messages—unless the person gave clear written consent to receiving them[cite: 7]. Before texting a Singapore number, check it against the list[cite: 7]. Appointment reminders a patient agreed to are treated differently from promotions[cite: 7].
Does the PDPA apply on top of the MOH rules?
Yes[cite: 7]. The MOH rules cover the ad's content and where it runs; the PDPA covers the data the ad collects; and a separate MOH rule (Reg. 6(4)) requires written consent before you push an ad to someone[cite: 7]. All three apply at once[cite: 7].
What are the penalties for breaching the PDPA?
Up to $1 million, or up to 10% of your Singapore turnover if that's over $10 million—whichever is higher—plus orders to stop or fix the breach[cite: 7].

Statutory Sources

  1. Personal Data Protection Act 2012; Do Not Call provisions[cite: 7]. Singapore Statutes Online[cite: 7].
  2. Personal Data Protection Commission, Advisory Guidelines for the Healthcare Sector (developed with MOH; updated September 2023)[cite: 7].
  3. PDPC, Advisory Guidelines on Requiring Consent for Marketing Purposes; on the Do Not Call Provisions; on Key Concepts in the PDPA[cite: 7].
  4. Healthcare Services (Advertisement) Regulations 2021, regulation 6(4)[cite: 7].

Disclaimer: General information, not legal advice[cite: 7]. PDPA duties depend on the specific data, purposes and consents involved, and the guidance and penalties change[cite: 7]. Last reviewed 18 July 2026[cite: 7]. Check against the PDPA and current PDPC guidance, and take your own advice[cite: 7]. PULSE Digital is a marketing agency, not a law firm, and isn't affiliated with the PDPC[cite: 7].

Newsletter Sign up

Medical AI Tips Weekly!

I release tips and tricks on how to use AI to succeed in your medical practice – completely free, every single week. Register for my newsletter here!