Singapore Records Retention Requirements 2026: How Long Must Companies Keep Documents?

Singapore Records Retention Requirements 2026: How Long Must Companies Keep Documents?

A data retention policy in Singapore is the written schedule and set of procedures an organisation follows to decide how long each type of document or personal data is kept, where it is stored, and how it is disposed of once its retention period expires. Singapore has no single "Data Retention Act" — instead, a retention policy has to reconcile several overlapping obligations at once: the Personal Data Protection Act (PDPA) 2012's retention limitation obligation, sector minimums set by ACRA, IRAS, and MAS, and any applicable litigation hold. Getting the schedule right avoids two opposite risks: keeping personal data longer than PDPA permits, and destroying records before a statutory minimum has passed.

Key Facts: Singapore Document Retention Requirements (2026)

  • ACRA (Companies Act): Company records minimum 5 years; financial statements minimum 7 years from end of financial year
  • IRAS: Business records (income tax) minimum 5 years from end of relevant year of assessment
  • MAS TRM: Financial institutions must retain records 5–10 years depending on document type
  • PDPA 2012: Personal data must not be retained longer than necessary for its purpose — organisations must have documented retention and disposal schedules
  • Employment Act: Employee records minimum 2 years after employment ends; CPF records minimum 5 years
  • Legal proceedings: Records relevant to ongoing or anticipated litigation must be retained until proceedings are fully resolved
  • NLB/NHB institutions: Follow NHB Collection Policy and NLB retention schedules — heritage materials may require permanent retention
  • Destruction: Physical records must be destroyed via NEA-compliant certified shredding; digital records via certified data destruction with audit trail
  • GeBIZ-registered scanning vendor: Micrographics Data Pte Ltd — advises on retention scheduling as part of every enterprise scanning engagement since 1989

What Should a Singapore Data Retention Policy Include?

A PDPA-compliant data retention policy is a written document, not just an internal habit — the PDPA's Retention Limitation Obligation (Section 25) requires organisations to stop retaining personal data, or anonymise it, as soon as it is reasonable to assume the purpose for which it was collected is no longer served and retention is no longer necessary for legal or business purposes. A complete policy typically covers:

  • Scope — which entities, departments, and data/document categories the policy applies to (HR, finance, customer, legal, heritage/archival records)
  • Data and document inventory — a classification of what is held, in what format (paper, digital, microfilm), and where
  • Retention schedule — the specific retention period assigned to each document/data type, tied to the statutory authority that sets it
  • Legal basis — the regulation or contractual requirement driving each retention period (PDPA, ACRA, IRAS, MAS TRM, Limitation Act, sector-specific rules)
  • Storage and security controls — how records are protected for the duration of the retention period (access controls, encryption, physical security, archival microfilm for permanent records)
  • Disposal procedure — the method of destruction (certified shredding for paper, certified data wiping for digital, with an audit trail) once the retention period lapses
  • Ownership and review — a named data protection officer or records manager responsible for the schedule, reviewed at least annually

Sample Data Retention Schedule for Singapore Organisations

The table below summarises commonly cited minimum retention periods for Singapore organisations. Always confirm current requirements against the relevant authority, as minimums can vary by sector and document sub-type.

Document / Data Type Typical Minimum Retention Governing Authority
Company statutory records (registers, minutes) 5 years ACRA / Companies Act
Financial statements and accounting records 7 years from end of financial year ACRA / Companies Act
Income tax business records 5 years from end of relevant Year of Assessment IRAS
Financial institution records (varies by type) 5–10 years MAS Technology Risk Management Guidelines
Personal data (general) Only as long as purpose is served PDPA 2012, Retention Limitation Obligation
Employee personnel records Minimum 2 years after employment ends Employment Act
CPF contribution records Minimum 5 years CPF Board
Records under active or anticipated litigation Until proceedings fully resolved Limitation Act / common law
Heritage and national archival materials Permanent (may be indefinite) NHB Collection Policy / NLB retention schedules

How to Build a PDPA-Compliant Retention and Disposal Policy

Most Singapore organisations build a working retention policy in four stages:

  1. Audit — inventory every category of document and personal data the organisation holds, across paper archives, digital systems, and any microfilm or microfiche legacy records.
  2. Classify and schedule — assign each category a retention period against the applicable statutory minimum (see the schedule above), and flag anything subject to litigation hold.
  3. Secure storage for the retention period — active and semi-active records need access-controlled digital storage or a managed physical archive; records with very long or permanent retention requirements (heritage, government, some financial and legal records) are frequently kept on archival microfilm rated LE500 (500-year life expectancy under ISO 18902 storage conditions) as a durable, tamper-evident, non-rewritable backup layer that cannot be altered or ransomware-encrypted.
  4. Dispose on schedule — once a retention period lapses and no litigation hold applies, paper originals should be destroyed via certified shredding and digital data via certified, logged data destruction, with a Certificate of Destruction kept as the audit trail.

Micrographics Data Pte Ltd, GeBIZ-registered since 1989, advises Singapore organisations on retention scheduling as part of every corporate document scanning and digitisation engagement, and supplies the archival microfilm rolls and processing chemistry used for permanent-retention records that a retention policy classifies as needing indefinite, tamper-proof storage.

Digitisation vs. Physical Storage Under a Retention Policy

A retention policy has to specify not just how long a record is kept, but in what form. Digital records are fast to search and cheap to store short-term, but are vulnerable to ransomware, format obsolescence, and accidental deletion — a real concern for records with 5–10 year or permanent retention requirements. Physical paper storage avoids those digital risks but is slow to retrieve, expensive at scale in Singapore's commercial real estate market, and still exposed to fire, flood, and physical loss. Archival microfilm sits between the two: an LE500-rated microfilm roll is certified for 500 years of storage life, is air-gapped and cannot be remotely altered or encrypted, and is the standard long-term backup layer for government archives, national libraries, and financial institutions worldwide under NARA 36 CFR Part 1238 and equivalent standards. Many Singapore retention policies specify a hybrid approach: digital copies for day-to-day access, with microfilm or secure physical archiving for the permanent or long-duration retention tier.

Frequently Asked Questions: Data Retention Policy Singapore

Do I need a written data retention policy in Singapore?

The PDPA does not mandate a specific policy document format, but the Personal Data Protection Commission (PDPC) expects organisations to be able to demonstrate compliance with the Retention Limitation Obligation. In practice, a written, dated retention schedule is the standard way organisations document and defend their compliance.

What happens if a company retains personal data longer than necessary under the PDPA?

Retaining personal data beyond the point where its collection purpose is served, without a valid legal or business reason, is a breach of the PDPA's Retention Limitation Obligation and can expose the organisation to enforcement action by the PDPC.

How long should I keep customer personal data in Singapore?

There is no single fixed period — it depends on why the data was collected and whether another law (such as a 5-year tax or contractual record requirement) independently requires it to be kept longer. Once no purpose or legal requirement remains, the data should be deleted or anonymised.

Can scanned or digitised records satisfy Singapore's retention requirements?

Generally yes for most business and tax records, provided the digitisation process preserves completeness and integrity and the organisation can produce the record on request. Some original documents (e.g. certain legal instruments) may still need to be retained in physical form — confirm against the specific regulation that applies to that document type.

Can a records retention schedule change over time?

Yes — retention schedules should be reviewed at least annually, and whenever a relevant regulation (PDPA, ACRA, IRAS, MAS TRM, or a sector-specific rule) changes.

Get Help Building a Retention-Ready Archive

Micrographics Data Pte Ltd has advised Singapore government agencies, financial institutions, and corporates on document retention, scanning, and archival strategy since 1989. Whether your policy calls for PDPA-compliant digitisation, certified secure disposal, or 500-year archival microfilm for permanent records, our team can scope the right mix.

Shop microfilm supplies: micrographicsdataonline.com/collections/microfilm-supplies-rolls-chemistry
Contact: sales@micrographicsdata.com | +65 6472 7255

Quay lại blog

Để lại bình luận

Xin lưu ý, bình luận cần được phê duyệt trước khi được đăng.