Balance — Singapore Country Annex
Effective date: 28 June 2026 Last updated: 28 June 2026
Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every Singapore resident covered by this Annex; the Data Protection Officer ("DPO") under s 11(3) of the Personal Data Protection Act 2012 (Singapore) (No. 26 of 2012) ("PDPA"), with business contact published as the publicly-accessible DPO contact required by s 11(5) PDPA read with the Personal Data Protection Regulations 2014 and the Personal Data Protection Regulations 2021; the designated contact point for the Personal Data Protection Commission ("PDPC"), the Infocomm Media Development Authority ("IMDA"), the Council for Estate Agencies (n/a), the Singapore Police Force ("SPF") National Cyber Crime Unit, and the Ministry of Social and Family Development ("MSF") under their respective intake protocols.
Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to the Personal Data Protection Act 2012 (Singapore) — including the bringing into force of any provision of the Personal Data Protection (Amendment) Act 2020 (No. 40 of 2020) that is not yet operationally in force at the Effective date (in particular the data portability provisions at PDPA Part VIB (ss 26H–26P) which require subsidiary regulations to be made under s 26P before they are operationally in force; the s 26P regulations had not been made at the Effective date — § 18 versioning protocol provides for an immediate off-cycle update on their making and the consequential commencement of Part VIB); (b) any amendment to the Personal Data Protection Regulations 2014, the Personal Data Protection (Notification of Data Breaches) Regulations 2021, the Personal Data Protection (Composition of Offences) Regulations 2021, the Personal Data Protection (Composition of Offences) Regulations 2022, the Personal Data Protection (Enforcement) Regulations 2021, the Personal Data Protection (Do Not Call Registry) Regulations 2013, or to any successor PDPA subsidiary regulation; (c) any Advisory Guideline or PDPC Decision issued by the Personal Data Protection Commission under PDPA s 49 — including the Advisory Guidelines on the PDPA for Children's Personal Data, the Advisory Guidelines on Key Concepts in the PDPA, the Advisory Guidelines on the PDPA for NRIC and Other National Identification Numbers, the Advisory Guidelines on the PDPA for Selected Topics, the Guide to Active Enforcement, the Guide to Managing Data Breaches 2.0, the Guide to Data Protection Practices for ICT Systems, the Guide to Notification, and the body of PDPC decisions published at https://www.pdpc.gov.sg/Commissions-Decisions/Data-Protection-Enforcement-Cases; (d) any decision of the Data Protection Appeal Panel (constituted under PDPA s 47) or of any Singapore court under PDPA Part IX; (e) any amendment to the Spam Control Act 2007 (Singapore) or its associated regulations; (f) any amendment to the Cybersecurity Act 2018 (Singapore) (only relevant if Balance were ever designated a Critical Information Infrastructure ("CII") — not in scope at the Effective date); (g) any amendment to the Online Criminal Harms Act 2023 (Singapore) ("OCHA") (in force from 1 February 2024) or to any Direction issued by the Minister for Home Affairs or the Commissioner of Police thereunder; (h) any amendment to the Broadcasting Act 1994 (Singapore) including its Code of Practice for Online Safety (in force from 18 July 2023 for "Designated Online Communications Services") or to any Direction under the Online Safety (Miscellaneous Amendments) Act 2022; (i) any amendment to the Protection from Online Falsehoods and Manipulation Act 2019 (Singapore) ("POFMA") (relevant only contextually — Balance does not generate or host online falsehoods); (j) any amendment to the Penal Code 1871 (Singapore, revised), in particular ss 354 (outrage of modesty), 376–376E (sexual offences against minors and sexual grooming), 376EB (sexual exposure to minor under 16), 376G (sexual penetration of a person under 18 by trust), ss 377BA–377BJ (offences relating to child sexual exploitation including sexual communication with minors, CSAM-related offences), s 377BG (causing minor under 16 to be a recipient of sexual material), s 377BH (production/distribution/possession of CSAM), s 416A (cheating by personation); (k) any amendment to the Children and Young Persons Act 1993 (Singapore) ("CYPA") including the Children and Young Persons (Amendment) Act 2019 which strengthened protection of children and young persons; (l) any amendment to the Computer Misuse Act 1993 (Singapore) ("CMA"), the Criminal Procedure Code 2010 (Singapore) ("CPC"), or the Mutual Assistance in Criminal Matters Act 2000 (Singapore) ("MACMA"); (m) any amendment to the Films Act 1981 (Singapore), the Undesirable Publications Act 1967 (Singapore), or the Broadcasting Act 1994 (Singapore) on undesirable / restricted content; (n) any amendment to the Consumer Protection (Fair Trading) Act 2003 (Singapore) ("CPFTA"), the Sale of Goods Act 1979 (Singapore, as adopted), the Unfair Contract Terms Act 1977 (Singapore, as adopted), the Lemon Law amendments at CPFTA Part III, or any subsidiary regulation; (o) any amendment to a sub-processor's Singapore data-handling posture under our sub-processor register; (p) the bringing into force of any post-Effective-date Singapore regulation governing automated processing or related techniques (covered by the deliberate-silence carve-out in § 2 of this Annex).
Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.
This Annex discharges the country-annex obligations referenced in:
- Privacy Policy § 18 (Country annexes — Singapore row).
- Children's Privacy Notice § 14 (Country annexes — Singapore row).
- Child Safety Standards § 13 (Country annexes — Singapore row).
- Terms of Service § 19 (Singapore consumer-protection carve-out under CPFTA + Sale of Goods Act + Unfair Contract Terms Act).
- Subscription Terms § 20 (Singapore consumer-rights overlay — Lemon Law CPFTA Part III + the unfair-practices regime at CPFTA s 4 + Sale of Goods Act / Unfair Contract Terms Act).
- Data Retention & Deletion Policy § 14 (Singapore PDPC complaint route).
- our breach-notification runbook § 9 (Singapore mandatory-data-breach-notification route under PDPA Part VIA — 3 calendar days PDPC notification — the strictest data-breach-notification deadline in the landing-country set).
- our international-transfer pack § 6 (PDPA s 26 cross-border-transfer-comparable-standard treatment + accountability paperwork + APEC Cross-Border Privacy Rules ("CBPR") + onward-flow contractual paperwork).
This Annex is the canonical Singapore-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants a Singapore resident a right that the global Policy does not, this Annex governs. Where the global Policy grants a Singapore resident a right that this Annex does not, the global Policy governs. The two are read together.
This Annex is drafted in English. Singapore's four official languages are English, Malay, Mandarin Chinese, and Tamil (Constitution of the Republic of Singapore Art 153A). English is the working language of the Singapore Government, the language of the courts, and the language in which all Singapore statutes are authoritative. Localised translations into Malay, Mandarin Chinese, and Tamil are queued for the Phase-2 locale rollout per our internal compliance tracker. No translation is statutorily required at the Effective date for the English-language privacy notice to a Singapore resident (PDPA does not require multilingual notification).
1. Scope and applicability
This Annex applies to every Balance user (parent or kid) whose country of residence is the Republic of Singapore — the city-state with no internal subdivision beyond the five Community Development Councils (CDCs) and the planning regions of the Urban Redevelopment Authority. There is no provincial or territorial overlay.
We determine country of residence at install/sign-up time by (a) the country the parent self-declares in the in-app onboarding flow, (b) the IP-geolocation read at sign-up (which we discard immediately after the residence decision — our internal data-flow map § 2.1 stores no IP after the authentication request closes), and (c) the Play Store account locale that Google Play passes to us at install. The residence determination is reviewable at any time by the parent at Settings → Account → Region.
Where any of the three signals identifies Singapore as the country of residence, this Annex applies, even if the other signals are non-Singaporean. The most-protective-for-the-data-subject reading is the controlling reading per our internal compliance plan § 6.3.
The PDPA has extraterritorial effect under s 2(1) — the Act applies to organisations whether they are formed or recognised under the law of Singapore, resident or located in Singapore, or operating from outside Singapore. The PDPC's Advisory Guidelines on Key Concepts in the PDPA Chapter 7 + the body of PDPC decisions confirm that an organisation outside Singapore is subject to the PDPA in respect of its collection, use, or disclosure of personal data of individuals in Singapore where the organisation directs activities towards Singapore. Balance squarely targets Singapore residents through Google Play Singapore, through publication of this Annex at balance.babayagaprogram.com, and through delivery of the parental-control service to Singapore-resident parents and kids; the PDPA applies in full.
2. Statutory framework — what applies
The Singapore personal-data-protection regime is dominated by the Personal Data Protection Act 2012, as modernised by the Personal Data Protection (Amendment) Act 2020 (No. 40 of 2020) (substantively in force in tranches from 1 February 2021), supplemented by the suite of subsidiary regulations and the Personal Data Protection Commission's binding Advisory Guidelines. The PDPA is the principal layer. Adjacent layers: the Spam Control Act 2007; the Online Criminal Harms Act 2023 and the Code of Practice for Online Safety under the Broadcasting Act 1994; the Penal Code 1871; the Children and Young Persons Act 1993; the Consumer Protection (Fair Trading) Act 2003; the Cybersecurity Act 2018 (only for CII designation — not engaged); the Computer Misuse Act 1993; the Criminal Procedure Code 2010; and the Mutual Assistance in Criminal Matters Act 2000.
| Instrument | Short cite | What it does | Balance's posture |
|---|---|---|---|
| Constitution of the Republic of Singapore | Constitution — Part IV (Fundamental Liberties — Art 9 right to life and personal liberty; Art 12 equal protection; Art 14 freedom of speech, assembly and association); Art 152 (minorities and special position of Malays); Art 153A (official languages — Malay, Mandarin, Tamil, English). Privacy is not explicitly enumerated; Re Wong Sin Yee [2014] 4 SLR 532 and Public Prosecutor v Mas Swan bin Adnan [2012] 3 SLR 527 acknowledge but do not entrench a constitutional privacy right. | The constitutional anchor. Privacy in Singapore is statutory (PDPA) rather than constitutional. | Applies as the constitutional layer. Treatment in §§ 3, 6, 13 below. |
| Personal Data Protection Act 2012 (Singapore) | PDPA — No. 26 of 2012, in force 2 January 2013 (institutional provisions) + 2 January 2014 (DNC Registry) + 2 July 2014 (Data Protection provisions); as substantively amended by the Personal Data Protection (Amendment) Act 2020 (No. 40 of 2020) in force in tranches from 1 February 2021. Substantive sections: Part I preliminaries; Part II (s 11 — accountability + mandatory DPO at s 11(3) + public availability of DPO contact at s 11(5)); Part III — Collection, Use and Disclosure of Personal Data (s 13–17 consent obligation + deemed consent + s 18 purpose obligation + s 20 notification obligation + s 21 access obligation + s 22 correction obligation + s 23 accuracy obligation + s 24 protection obligation + s 25 retention obligation + s 26 transfer-limitation obligation + s 26A right of withdrawal of consent + ss 26B–26E Part VIA mandatory data breach notification in force 1 February 2021 + ss 26F–26G PDPC deemed-consent-for-contractual-necessity + deemed-consent-for-legitimate-interests new bases + ss 26H–26P Part VIB data portability framework provisions only — operationally in force on the making of subsidiary regulations under s 26P which have not been made at the Effective date); Part IV (Care of Personal Data — s 24 protection / s 25 retention); Part V (s 26A right of withdrawal); Part VI (collection, use, disclosure carve-outs for business-asset transactions, employment, research, etc.); Part VIA — Notification of Data Breaches (s 26A–26E in force 1 February 2021; s 26B definition of notifiable data breach — significant-harm-to-individual or significant-scale ≥ 500 individuals test + ss 26C–26D PDPC notification within 3 calendar days + affected-individual notification at the same time unless prohibited by law enforcement or where the data has been rendered unintelligible); Part VIB — Data Portability (ss 26H–26P — framework not yet operationally in force); Part VII (the Do Not Call Registry + s 36–48); Part VIII (Administration — s 49 Advisory Guidelines power + s 50–55 PDPC powers); Part IX (Enforcement — s 56–62 investigations + s 60 financial penalties up to the greater of 10% of annual turnover in Singapore or SGD 1 million for organisations with annual turnover in Singapore exceeding SGD 10 million / up to SGD 1 million for smaller organisations); Part X (Appeals — Data Protection Appeal Panel + appeals to the General Division of the High Court); Part XI (Miscellaneous — Right of Private Action at s 48O** — individuals may commence a private civil action in the District Court / General Division of the High Court for loss or damage suffered by reason of a contravention of Part IV/V/VI). | The principal statute. Applies in full to Balance as an organisation operating from outside Singapore directing activities to Singapore residents (per PDPC Advisory Guidelines on Key Concepts Chapter 7). Treatment in §§ 3, 4, 6, 7, 8, 11, 13 below. | |
| Personal Data Protection Regulations 2014 (Singapore) | PDPR 2014 — the principal subsidiary regulation. Sets the operational details for the PDPA (definitions; access procedures; transfer-limitation conditions; etc.). Regulation 9–11 sets out the prescribed mechanisms for cross-border transfer comparable to PDPA s 26 — including (i) the data subject's consent; (ii) the transfer is necessary for the performance of a contract between the organisation and the individual; (iii) the recipient is bound by legally enforceable obligations to provide a standard of protection comparable to the PDPA (typically via written contract, binding corporate rules ("BCRs"), or certification under an approved cross-border privacy scheme such as the APEC Cross-Border Privacy Rules ("CBPR")). | Applies in full. Treatment in § 8 below. | |
| Personal Data Protection (Notification of Data Breaches) Regulations 2021 | PDPR-NDB 2021 — subsidiary regulation operationalising PDPA Part VIA. | Applies in full. Treatment in § 11 below. | |
| Personal Data Protection (Do Not Call Registry) Regulations 2013 | PDPR-DNC 2013 — subsidiary regulation operationalising PDPA Part VII (DNC Registry). | Applies. Balance does not place telemarketing calls; the DNC Registry is not engaged. | |
| Personal Data Protection (Enforcement) Regulations 2021 | PDPR-Enforcement 2021 — subsidiary regulation operationalising PDPA Part IX. | Applies in full as the PDPC enforcement-procedure layer. | |
| PDPC Advisory Guidelines | PDPC's binding interpretive guidance, issued under PDPA s 49 — including the Advisory Guidelines on Key Concepts in the PDPA (most recent revision), the Advisory Guidelines on the PDPA for Children's Personal Data (the principal children's-data interpretive instrument), the Advisory Guidelines on the PDPA for NRIC and Other National Identification Numbers, the Advisory Guidelines on the PDPA for Selected Topics, the Guide to Active Enforcement, the Guide to Managing Data Breaches 2.0, the Guide to Data Protection Practices for ICT Systems, the Guide to Notification, and the body of PDPC decisions published at https://www.pdpc.gov.sg/Commissions-Decisions/Data-Protection-Enforcement-Cases. |
Sets the PDPC's binding interpretive layer on the PDPA. | Applies. Balance's posture is operationalised consistently with the Advisory Guidelines on the PDPA for Children's Personal Data in particular. |
| Spam Control Act 2007 (Singapore) | SCA — regulates unsolicited commercial electronic messages with a Singapore-link computer. Schedule I requires identification + unsubscribe; Schedule II requires unsubscribe facility. Civil penalties for non-compliance enforced via the District Court (s 13). | Applies. Balance does not send commercial electronic messages to Singapore residents; the only email Balance sends is transactional. Treatment in § 12.3 below. | |
| Cybersecurity Act 2018 (Singapore) | Cybersecurity Act — establishes the Cyber Security Agency of Singapore ("CSA"); designates Critical Information Infrastructure ("CII") under s 7; imposes incident-reporting + protection obligations on CII owners. | Applies only to organisations designated as CII operators. Balance is not designated as a CII operator at the Effective date; therefore the Cybersecurity Act's substantive obligations do not engage Balance directly. Applies as a context-setting fact. | |
| Online Criminal Harms Act 2023 (Singapore) | OCHA — in force 1 February 2024. Empowers the Minister for Home Affairs and the Commissioner of Police to issue Directions to online service providers (including content-removal, access-restriction, app-removal, and account-restriction Directions) where there is reasonable suspicion that an offence is being committed using an online service. | Regulates online services that may be used to facilitate criminal harms (scams, malicious cyber activity, etc.). Balance's posture: Balance is best characterised as a private parental-control client that does not host third-party content publicly, does not enable user-to-user communication outside the parent-kid pairing of a single household, and does not provide a service in the sense engaged by the OCHA Directions regime; Balance nevertheless will cooperate with any properly-issued Direction served on Balance under the routes in § 13 + § 14 below. | |
| Broadcasting Act 1994 (Singapore) + Code of Practice for Online Safety | The Online Safety (Miscellaneous Amendments) Act 2022 (in force 1 February 2023) amended the Broadcasting Act to establish the Code of Practice for Online Safety applicable to Designated Online Communications Services ("DOCS"). The Code came into operation on 18 July 2023 for DOCS designated by IMDA. | Designated services (DOCS — at the Effective date, the IMDA has designated a small number of social-media services including Facebook, Instagram, TikTok, X, HardwareZone, YouTube — none being Balance) must implement child-safety measures, content-moderation systems, and reporting tools. Balance has not been designated as a DOCS and the IMDA Designation Order at the Effective date does not extend to parental-control services. Applies as a context-setting fact. | |
| Protection from Online Falsehoods and Manipulation Act 2019 (Singapore) | POFMA | Applies to online communications of falsehoods. Balance does not generate or host online communications of falsehoods. | Not engaged. |
| Penal Code 1871 (Singapore, revised) | Penal Code — s 354 (outrage of modesty); s 376 (rape); s 376A (sexual penetration of a minor under 16); s 376AA (sexual communication with a minor under 16 — sexting offence introduced by the Criminal Law Reform Act 2019); s 376B (commercial sex with a minor under 18); s 376C (commercial sex with a minor under 18 outside Singapore — extraterritorial); s 376E (sexual grooming of a minor under 16 — grooming offence introduced by the Penal Code (Amendment) Act 2007); s 376EB (sexual exposure to a minor under 16); s 376G (sexual penetration of a person under 18 by a person in a position of trust); ss 377BA–377BJ (offences relating to child sexual exploitation including sexual communication with minors and possession/production/distribution of CSAM — introduced by the Criminal Law Reform Act 2019 in force 1 January 2020); s 416A (cheating by personation — relevant for grooming-by-impersonation scenarios). | The principal Singapore criminal statute for CSAE, online-grooming, intimate-image, and CSAM offences. | Applies. Cross-reference in Child Safety Standards § 8.1 + § 14 below. |
| Children and Young Persons Act 1993 (Singapore) | CYPA — as amended by the Children and Young Persons (Amendment) Act 2019. Definitions — child means a person under 14 years; young person means a person 14 years or above and under 16 years (s 2). Establishes the framework for protection of children and young persons; mandatory reporting of child abuse (s 14); offences (Part II); MSF / Child Protective Service ("CPS") cooperation. | The principal child-welfare statute. | Applies. Treatment in § 5 + § 14 below. |
| Computer Misuse Act 1993 (Singapore) | CMA — the principal cybercrime statute. s 3 (unauthorised access to computer material); s 4 (access with intent to commit or facilitate commission of offence); s 5 (unauthorised modification of computer material); s 6 (unauthorised use or interception of computer service); s 7 (unauthorised obstruction of use of computer); s 8 (unauthorised disclosure of access code). | Applies. Treatment in § 13 below. | |
| Criminal Procedure Code 2010 (Singapore) | CPC — sets the procedural rules for police powers including production orders + search warrants under Part IV. | The lawful-access framework for criminal investigations. | Applies. Treatment in § 13 below. |
| Mutual Assistance in Criminal Matters Act 2000 (Singapore) | MACMA — Singapore's framework for assisting foreign states with criminal-justice cooperation. | The mutual-assistance framework. | Applies. Treatment in § 13 below. |
| Films Act 1981 + Undesirable Publications Act 1967 (Singapore) | Films Act + UPA — IMDA-administered classification of films + prohibition of undesirable publications including CSAM. | The principal undesirable-content classification statutes. | Applies as a context-setting fact. |
| Consumer Protection (Fair Trading) Act 2003 (Singapore) | CPFTA — Singapore's principal consumer-protection statute. s 4 (unfair practices — false claims, misleading representations, exploitative conduct); Part III (the Lemon Law amendments in force 1 September 2012 — implied terms of quality and fitness for purpose; the consumer's right to repair, replacement, reduction in price, or rescission; the 6-month presumption of defect rule); s 6 (consumer's right to commence civil action). Enforced by Competition and Consumer Commission of Singapore ("CCCS") and the Consumers Association of Singapore ("CASE"). | The principal consumer-protection statute. | Applies in full. Treatment in § 16 below. |
| Sale of Goods Act 1979 (Singapore, adopted) + Unfair Contract Terms Act 1977 (Singapore, adopted) | English statutes received into Singapore law via the Application of English Law Act 1993, with subsequent local amendments. SGA Part III implied terms; UCTA s 11 reasonableness requirement. | Apply as additional consumer-protection layers. | Apply. Treatment in § 16 below. |
| EU adequacy | None. Singapore does not hold an EU adequacy decision under GDPR Art 45 at the Effective date. EU/EEA → Singapore transfers are governed by EU SCCs + Transfer Impact Assessment. | Cross-reference in EU / EEA annex § 8. | The absence of EU adequacy does not affect Balance's posture because Balance has no Singapore data residency (the backend is in the US — see § 9 below). |
| APEC Cross-Border Privacy Rules (CBPR) | Singapore is a participating economy in the APEC Cross-Border Privacy Rules (APEC CBPR) system since 2018 + the APEC Privacy Recognition for Processors (PRP) system since 2018. The Singapore Accountability Agent under the APEC CBPR is IMDA (with PDPC supporting). | The APEC CBPR is one of the lawful-cross-border-transfer mechanisms recognised under PDPR 2014 Reg 10. | Applies as a context-setting fact (Balance relies on the PDPR 2014 Reg 10 contract-based route rather than APEC CBPR certification at the Effective date). |
| Convention 108 / Convention 108+ | Not applicable. Singapore is not a party to the Council of Europe Convention 108 or Convention 108+. | Applies as a context-setting fact. | The Council-of-Europe layer is not engaged. |
(Any prospective Singapore regulation governing automated processing, algorithmic decisions, or related techniques — including any post-Effective-date PDPC Advisory Guideline in that area, the IMDA's voluntary Model AI Governance Framework (2024 edition, voluntary and applies to government and industry by adoption only), the Model AI Governance Framework for Generative AI (May 2024, voluntary), the AI Verify framework (voluntary testing toolkit), any future Singapore AI Act or Model AI Bill before the Singapore Parliament, and any successor instrument — is intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such Singapore regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence on the topic is deliberate and is not to be read as an implicit statement either way.)
3. Supervisory authorities
3.1 PDPC — Personal Data Protection Commission
The principal supervisory authority is the Personal Data Protection Commission ("PDPC"), established as a statutory body under PDPA s 5 + the Personal Data Protection Commission Act 2012 (Singapore). The PDPC is administratively part of the Infocomm Media Development Authority ("IMDA") + the Ministry of Communications and Information ("MCI") (now the Ministry of Digital Development and Information ("MDDI") since the 2024 restructure).
| Field | Value |
|---|---|
| Name | Personal Data Protection Commission (PDPC) |
| Headquarters | 10 Pasir Panjang Road, #03-01 Mapletree Business City, Singapore 117438 |
| Website | https://www.pdpc.gov.sg/ |
| Complaint channel | PDPC online complaint form at https://www.pdpc.gov.sg/lodge-a-complaint, or via the PDPC's Personal Data Protection (Notice and Complaint Form); email info@pdpc.gov.sg |
| Phone | +65 6377 3131 |
| Mandatory-Breach-Notification channel | PDPC online Data Breach Notification (Section 26D) form per PDPA Part VIA + PDPR-NDB 2021 — at https://eservice.pdpc.gov.sg/case/db — submission within 3 calendar days of the organisation determining that the breach is a notifiable data breach |
| Commissioner | At the Effective date — Lew Chuen Hong (in his capacity as Chief Executive of IMDA) and the PDPC Commissioner as published at the PDPC website |
The PDPC is the first-line forum for any PDPA-grounded complaint from any Singapore resident. A Singapore resident may petition the PDPC after first raising the matter with Balance (PDPC's published Guide to Complaints Process recommends this sequencing, but the PDPC also accepts direct complaints). We accept all DSAR / privacy enquiries at (named individual: , in his capacity as the DPO under PDPA s 11(3)) and respond within the PDPA timelines (see § 6 below).
A Singapore resident may also pursue private remedies against Balance via the Right of Private Action at PDPA s 48O (District Court / General Division of the High Court — loss or damage from a Part IV/V/VI contravention).
3.2 IMDA — Infocomm Media Development Authority
The Infocomm Media Development Authority ("IMDA") administers the Broadcasting Act 1994, the Films Act 1981, the Telecommunications Act 1999, the Spam Control Act 2007 (in part), and other digital-infrastructure statutes; the IMDA is also the Singapore Accountability Agent for the APEC CBPR.
| Field | Value |
|---|---|
| Name | Infocomm Media Development Authority (IMDA) |
| Headquarters | 10 Pasir Panjang Road, Mapletree Business City, Singapore 117438 |
| Website | https://www.imda.gov.sg/ |
| Phone | +65 6377 3800 |
3.3 Other regulatory bodies
| Body | Subject matter | URL |
|---|---|---|
| Ministry of Home Affairs (MHA) | OCHA Directions; cybercrime policy | https://www.mha.gov.sg/ |
| Singapore Police Force (SPF) — Police Cybercrime Command | CMA + Penal Code cybercrime investigation | https://www.police.gov.sg/ |
| Ministry of Social and Family Development (MSF) — Child Protective Service (CPS) | CYPA — child protection | https://www.msf.gov.sg/ + https://www.msf.gov.sg/our-services/Pages/Child-Protective-Service.aspx |
| Competition and Consumer Commission of Singapore (CCCS) | CPFTA + competition law | https://www.cccs.gov.sg/ |
| Consumers Association of Singapore (CASE) | CPFTA consumer-protection advocacy | https://www.case.org.sg/ |
| National Council of Social Service (NCSS) | Children-related social-service coordination | https://www.ncss.gov.sg/ |
| TOUCH Cyber Wellness | Children's online-safety education and counselling | https://www.touch.org.sg/ |
| Singapore Children's Society | Children's welfare NGO | https://www.childrensociety.org.sg/ |
3.4 The DPO
PDPA s 11(3) requires every organisation to designate one or more individuals (whose responsibility is the policy and operational implementation of the PDPA — the Data Protection Officer — "DPO") to be responsible for ensuring that the organisation complies with the PDPA. PDPA s 11(5) requires that the business contact information of at least one DPO be made publicly available (typically on the organisation's website).
The Balance DPO is:
- , Director, BabaYaga Program, TOO —
.
The DPO's business contact is published in this Annex, in the global Privacy Policy (Privacy Policy § 1), and at balance.babayagaprogram.com — satisfying PDPA s 11(5). The DPO is the contact point for the PDPC on any regulatory matter and for data subjects on rights-exercise matters. The DPO need not be located in Singapore (PDPC Advisory Guidelines on Key Concepts Chapter 11.2).
4. Lawful bases — PDPA Part III consent obligation + deemed-consent + carve-outs
The PDPA is a consent-based regime modulated by deemed-consent provisions (introduced by the 2020 Amendment Act) and limited statutory carve-outs. Balance processes personal data of Singapore residents on the following PDPA mapping:
| Processing purpose | PDPA basis | Cross-reference |
|---|---|---|
| Run the parental-control service the parent signed up for (account creation, family configuration, kid profile, limits, schedules, tasks, earned-time ledger, end-to-end-encrypted proof media) | PDPA s 13(a) consent obligation (the parent's express consent at sign-up) + PDPA s 15(1) deemed consent by conduct (where the individual voluntarily provides personal data for a purpose, the individual is deemed to consent to the collection use or disclosure for that purpose) + PDPA s 15A deemed consent by contractual necessity (in force 1 February 2021 — where collection use or disclosure of personal data about an individual is reasonably necessary for the conclusion or performance of a contract or transaction to which the individual is a party) + PDPA s 18 purpose obligation + PDPA s 20 notification obligation | H1 § 4; H7 PA-01 through PA-08; § 7 of this Annex |
| Process the kid's personal data | PDPA s 13(a) + PDPA s 14 — the parent's consent on behalf of the kid + PDPC Advisory Guidelines on the PDPA for Children's Personal Data (which provides that an organisation should obtain consent of the parent/guardian for children under 13) | § 7 of this Annex; our Data Protection Impact Assessment § 6 |
| Deliver operational alerts | PDPA s 13(a) + s 18 (primary purpose) | H1 § 4; H7 PA-09; M3 |
| Detect, prevent, and respond to security incidents, abuse, fraud, and unauthorised access | PDPA s 17(1) read with First Schedule paragraphs 1(b)(i) and 1(b)(ii) (collection use or disclosure necessary for any investigation or proceedings + necessary for evaluation suitable for an emergency that threatens the life health or safety of any individual) + PDPA s 24 protection obligation | H7 PA-15; § 13 below |
| Comply with legal, regulatory, and supervisory obligations | PDPA s 17(1) read with First Schedule paragraph 1(d) (collection use or disclosure required or authorised by any written law) | § 13 below; M1; § 14 below |
| Process Verifiable Parental Consent for the kid's data | PDPA s 13(a) — collection of the parent's personal data for the primary purpose of obtaining VPC | § 7 of this Annex; A-US § 5 |
| Process the parent's billing / subscription data | PDPA s 15A deemed consent by contractual necessity — necessary for the performance of the subscription contract; CPFTA + Lemon Law overlay in § 16 below | H4; § 16 below |
Balance does not rely on deemed consent by legitimate interests at PDPA s 15B (in force 1 February 2021) for any kid-side processing, even though the s 15B basis is theoretically available, because the express consent + deemed consent by contractual necessity bases are sufficient and more parent-aligned.
Balance does not collect any NRIC (National Registration Identity Card) number or other national identification number of any Singapore resident. The PDPC's Advisory Guidelines on the PDPA for NRIC and Other National Identification Numbers (issued 31 August 2018, in force from 1 September 2019) restrict the collection use or disclosure of an individual's NRIC number (and FIN — Foreign Identification Number, or BC number — Birth Certificate number, or other national identification numbers) except in specific permitted scenarios. Balance's posture aligns: no NRIC / FIN / BC number is collected.
5. Children's rights overlay
Singapore does not have a children-specific data-protection statute equivalent to COPPA (US), GDPR Art 8, or Quebec Private Sector Act s 8.1, at the Effective date. The children's regime is built up from (i) the PDPA + the PDPC's binding Advisory Guidelines on the PDPA for Children's Personal Data (issued under PDPA s 49); (ii) the Children and Young Persons Act 1993 (CYPA); (iii) the Penal Code 1871 age-of-consent provisions (16 for general consent; 18 for commercial sex); (iv) the common-law doctrine of parental authority and the Guardianship of Infants Act 1934 (Singapore — provides for joint parental responsibility); (v) the UN Convention on the Rights of the Child (Singapore acceded 5 October 1995, with reservations).
5.1 Definitions
For the purposes of this Annex:
- Child (under CYPA): a person below the age of 14 years (CYPA s 2).
- Young person (under CYPA): a person of or above the age of 14 years but below the age of 16 years (CYPA s 2).
- Minor (general — age of majority for contracts): 18 years (Civil Law Act 1909 s 36 — Age of Majority Act effect).
- Children's-data-consent rule (per PDPC Advisory Guidelines on the PDPA for Children's Personal Data): for a child below 13 years, the organisation should obtain consent from the parent or guardian; for a child 13 years or older, the organisation may rely on the child's own consent if the child is of sufficient maturity to understand the nature and consequences of giving consent. Balance applies the most-protective reading and obtains parental consent regardless of the child's age.
5.2 Verifiable Parental Consent (VPC) for Singapore kids
Balance applies the most-protective reading and obtains Verifiable Parental Consent for every Singapore kid regardless of age, using the VPC mechanism in United States annex § 5 (email-verified parent account creation + payment-method capture at subscription time + parent's affirmative in-app action of creating the kid profile and pairing the kid's device). The VPC screen for Singapore residents itemises the categories of personal data being authorised, the purposes for which it is being processed, the third parties to whom it may be disclosed (sub-processors), and the data subject's rights under the PDPA.
5.3 No kid-self-serve consent path
Balance does not provide a kid-self-serve consent path inside the app. The parent always consents on behalf of the kid; the kid app's UI is designed for the kid to see their own limits, schedules, tasks, and earned-time ledger, and to request changes through the in-app "request change" affordance, which is forwarded to the parent device for the parent's decision. This is the most-protective reading of the PDPA + the PDPC Advisory Guidelines on the PDPA for Children's Personal Data + the CYPA's protection framework.
5.4 No advertising directed at children
Balance does not display advertising to any user (parent or kid), does not allow any third party to display advertising in Balance, and does not build a behavioural-advertising profile of any user. This is consistent with: (i) the PDPC's interpretive position on advertising to children; (ii) the Singapore Code of Advertising Practice by the Advertising Standards Authority of Singapore ("ASAS"); (iii) IMDA's Code of Practice for Online Safety (although Balance is not a designated DOCS). Cross-references: the Play Console Data Safety form § 2 (Contains ads: No); the Play Console Child Safety Standards declaration § 3 ATTESTATION-D.
5.5 Cooperation routes
The principal Singapore child-protection bodies are: (i) the Ministry of Social and Family Development (MSF) — Child Protective Service (CPS) — the principal child-welfare agency under the CYPA; (ii) the Singapore Police Force (SPF) — Anti-Scam Centre + Police Cybercrime Command — the principal law-enforcement nodes for cyber-CSAE; (iii) the National Council of Social Service (NCSS); (iv) TOUCH Cyber Wellness — children's online-safety education and counselling; (v) Singapore Children's Society; (vi) Tinkle Friend — Singapore Children's Society's helpline for children aged 7–12 (1800-274-4788); (vii) National CARE Hotline (1800-202-6868) — government 24/7 helpline. Balance cooperates with each on incidents involving Singapore kids — see § 14 below.
6. PDPA rights catalogue
6.1 The rights catalogue
A Singapore resident has the following rights under the PDPA + PDPR as in force at the Effective date.
- PDPA s 21 — Access obligation. An organisation shall, upon request of an individual, provide to the individual (i) personal data about the individual that is in the possession or under the control of the organisation; and (ii) information about the ways in which the personal data has been or may have been used or disclosed by the organisation within a year before the date of the request. Honored at
and in-app at Settings → Family → [kid name] → "Export this kid's data". Format: machine-readable JSON archive, with a plain-language English summary. - PDPA s 22 — Correction obligation. An organisation shall correct an error or omission in the personal data about the individual that is in the possession or under the control of the organisation. Honored in-app at Settings → Account → Edit and at
. - PDPA s 26A — Right of withdrawal of consent. An individual may at any time withdraw any consent given, or deemed to have been given under the Act, in respect of the collection use or disclosure by an organisation of personal data about the individual for any purpose. The organisation must inform the individual of the likely consequences of withdrawal.
- PDPA s 16 — Right to request information on the use of personal data. An individual may request information on the ways in which the personal data has been or may have been used or disclosed by the organisation.
- PDPA Part VIB — Right to data portability (ss 26H–26P) — framework only at the Effective date; the operational regulations under s 26P have not been made. § 18 versioning protocol covers their making and commencement.
- PDPA s 48O — Right of private action. An individual who suffers loss or damage directly as a result of a contravention of Part IV/V/VI by an organisation may commence a private civil action against the organisation in the District Court or the General Division of the High Court.
- Common-law remedies — equitable cause of action for breach of confidence; the common-law right of action established in Wee Cheng Lin v Lee Kuan Yew [2014] 4 SLR 757 + the equitable injunction.
6.2 Timeline
- PDPA s 21 access: the organisation must respond as soon as reasonably possible and in any event within 30 days of the request (Personal Data Protection Regulations 2014 Reg 4).
- PDPA s 22 correction: as soon as practicable, in any event within 30 days.
- PDPA s 26A withdrawal: Balance gives effect to a withdrawal of consent within 30 days, consistent with PDPC published guidance.
- PDPC complaint: the PDPC's published target is to resolve complaints in a reasonable time; complex matters may take longer.
Where the request would be vexatious or where the access carve-outs at PDPA s 21(3) / s 21(4) / Fifth Schedule apply, Balance may decline to provide access and explain the reasons.
6.3 Identity verification
Where there is reasonable doubt about the identity of the natural person making the request, Balance may request additional information necessary to confirm the identity. The identity-verification protocol uses the parent's existing authentication credential.
6.4 Fees
Under PDPA s 28(2) + PDPR 2014 Reg 7, an organisation may charge a reasonable fee for processing an access request, provided the fee does not exceed the reasonable costs incurred. Balance does not charge for access in practice.
6.5 Language
A request may be submitted in English. The PDPC accepts complaints in English.
7. Children's data — PDPA + Advisory Guidelines on the PDPA for Children's Personal Data + CYPA
Balance processes personal data of Singapore kids under the following layered framework:
- PDPA consent obligation s 13 + s 14 read with the PDPC's Advisory Guidelines on the PDPA for Children's Personal Data — for a child below 13 years, the organisation should obtain consent from the parent or guardian; for a child 13 years or older with sufficient maturity, the child may give their own consent. Balance applies the most-protective reading and obtains parental consent regardless of age.
- CYPA ss 4–14 — protection framework + mandatory reporting (s 14).
- Guardianship of Infants Act 1934 (Singapore) + the common-law doctrine of parental responsibility — the doctrinal anchor for parental authority on behalf of the kid.
- UN Convention on the Rights of the Child (Singapore acceded 5 October 1995 with reservations on Arts 12, 17, 19, 22, 28, 32, 37) — internalised through Singapore's child-welfare statutes.
For Balance:
- Verifiable Parental Consent. Identical mechanism to A-US § 5. The VPC screen is in English (Malay / Mandarin Chinese / Tamil queued for Phase 2 locale rollout).
- No kid-self-serve consent path. Per § 5.3 above.
A parent may revoke consent at any time at Settings → Family → [kid name] → "Delete this kid" (or by email to ). Revocation triggers the cascade documented in Data Retention & Deletion Policy § 7. Revocation does not affect the lawfulness of processing carried out before the revocation.
8. International data transfers from Singapore — PDPA s 26 + PDPR 2014 Reg 9–11
The controller (BabaYaga Program, TOO) is established in Kazakhstan. The backend (Emergent Labs Inc.) is hosted in the United States. Proof-media storage (Google Cloud Storage) is in the United States. Push (Firebase Cloud Messaging), sign-in (Google Sign-In), and billing (Google Play Billing) are operated by Google LLC and dispatched from the United States. Transactional email (Resend) is dispatched from the United States. Accordingly, every Singapore resident's personal data leaves Singapore at the point of being uploaded to the Balance backend.
8.1 The Singapore-to-US transfer mechanism — PDPA s 26
PDPA s 26 is the transfer-limitation obligation: an organisation must not transfer any personal data to a country or territory outside Singapore except in accordance with requirements prescribed under the Act, to ensure that organisations provide a standard of protection to personal data so transferred that is comparable to the protection under the PDPA. PDPR 2014 Reg 9–11 sets out the prescribed conditions:
- Reg 10(1)(a) — the transferring organisation has taken appropriate steps to ascertain whether, and to ensure that, the recipient of the personal data in that country or territory outside Singapore is bound by legally enforceable obligations to provide to the transferred personal data a standard of protection comparable to that under the PDPA.
- Reg 10(1)(b) — the data subject has, in connection with the transfer, given his or her consent to the transfer of the personal data to the recipient in the country or territory; and the consent was given on the basis of the data subject having been informed of any risk or change in the protection afforded.
- Reg 10(2) — legally enforceable obligations may include obligations imposed on the recipient under (i) any law; (ii) any contract that imposes such obligations to provide a standard of protection comparable to the PDPA; (iii) any binding corporate rules; or (iv) any other legally binding instrument including any certification under a recognised cross-border privacy-protection scheme such as the APEC Cross-Border Privacy Rules (CBPR).
Balance relies on the following stack to satisfy PDPA s 26 + Reg 10 for the Singapore → US transfer:
- Reg 10(2)(ii) contract. Each US sub-processor (Emergent Labs Inc.; Google LLC for GCS, FCM, Sign-In, and Play Billing; Resend, Inc.) is bound by a written processor agreement that imposes legally enforceable obligations on the recipient to provide a standard of protection comparable to the PDPA. The full transfer pack is in our international-transfer pack § 6. The contractual safeguards are reinforced by EU SCC substance + UK IDTA substance + APP-aligned substance + Quebec-Private-Sector-Act-aligned substance as substantive overlays.
- Reg 10(1)(b) consent. As a belt-and-braces overlay, the parent's sign-up consent prominently and expressly discloses the cross-border transfer to the United States, expressly states that the US recipient is bound by contractual obligations to provide PDPA-comparable protection, identifies the country of destination and the categories of recipients, and informs the parent of any risk arising from the transfer.
- Supplementary measures — most importantly, the end-to-end encryption of proof media documented in our encryption-posture record. The E2EE is the principal supplementary measure ensuring that even a compelled-production scenario in the US yields only opaque ciphertext, not plaintext media.
- Onward-transfer restrictions — every sub-processor's processor agreement forbids onward transfer of Singapore-resident personal data to a third country outside the s 26 + Reg 10 framework without the controller's prior written authorisation.
8.2 The Singapore-to-KZ axis (controller administrative access)
The controller's personnel in Kazakhstan have administrative access to the US-hosted backend for operational purposes. Because Kazakhstan is a third country, the Singapore-KZ axis is covered by the Reg 10(2)(ii) contract route + Reg 10(1)(b) consent route — written processor agreements signed between Emergent Labs (as processor) and BabaYaga Program, TOO (as controller) in inverse, with EU-SCC substance preserved. The transfer-impact analysis for the KZ leg is in our international-transfer pack § 7.
9. Data residency for Singapore residents
| Question | Answer |
|---|---|
| Where is the backend hosted? | United States. Emergent Labs Inc. (Delaware) on US infrastructure. |
| Where is the MongoDB database located? | United States. |
| Where is the proof-media storage located? | United States — Google Cloud Storage us multi-region. |
| Where are push notifications dispatched from? | United States — Firebase Cloud Messaging. |
| Is any Singapore resident's personal data held in Singapore? | No. Every Singapore resident's personal data is held in the United States. The PDPA s 26 + Reg 10 transfer mechanism in § 8 above is the legal basis for the transfer. |
| Where is the controller? | Kazakhstan (BabaYaga Program, TOO). The controller has administrative access to the US-hosted backend via written processor agreements. |
| Is there a Singapore establishment? | No. Balance has no permanent establishment in Singapore. The PDPA's extraterritorial reach (s 2(1) + PDPC Advisory Guidelines on Key Concepts Chapter 7) is the basis for Balance's PDPA compliance. |
| Where is the supervisory authority? | Singapore — PDPC + IMDA + the regulatory bodies in § 3.3 above. |
The decision to centralise on a US-only backend is documented in our internal compliance plan § 6. Singapore does not impose a comprehensive data-localisation mandate on parental-control services at the Effective date, with the exception of certain sector-specific regimes (e.g., the Cybersecurity Act 2018 in respect of CII operators — not applicable to Balance) and the Banking Act 1970 in respect of banking services (not applicable to Balance).
10. Sub-processors touching Singapore-resident data
| Sub-processor | Role | Location of processing | Singapore transfer paperwork |
|---|---|---|---|
| Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (MongoDB, Inc., US) for the production database; relationship governed by Emergent ToS (22 Dec 2025) + Privacy Policy (28 May 2026) as the GDPR Art 28(3) "other legal act" (no standalone DPA available outside Enterprise per Emergent final position 2026-06-10; full handling in our internal vendor-handling plan); MongoDB Atlas Customer DPA + EU SCCs Module 2 + UK IDTA Addendum at https://www.mongodb.com/legal/dpa cover the storage layer | Hosts the FastAPI backend + MongoDB cluster | United States | PDPR 2014 Reg 10(2)(ii) contract — written processor agreement with PDPA-comparable-protection clauses + Reg 10(1)(b) parent's consent on file per our international-transfer pack § 6; E2EE supplementary measure for proof media. |
| Google LLC — Google Cloud Storage (USA) | Stores end-to-end-encrypted proof-media ciphertext | United States (us multi-region) |
Reg 10(2)(ii) contract (Google Cloud Data Processing Addendum) + Reg 10(1)(b) consent; ciphertext-only handling. |
| Google LLC via Google Cloud (USA) | Periodic (daily) backups of our operational database | United States (us multi-region) |
Reg 10(2)(ii) contract (Google Cloud Data Processing Addendum) + Reg 10(1)(b) consent; the backup archive holds the operational data we hold about the resident (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens), other than the items that never reach our backend in readable form (the kid's proof media and the media-encryption keys); retained on a 30-day rolling window, then automatically deleted. |
| Google LLC — Firebase Cloud Messaging | Delivers push notifications to Singapore kid + parent devices | United States | Reg 10(2)(ii) + Reg 10(1)(b) as above; push body deliberately free of sensitive content (cross-reference: the just-in-time permission disclosures). |
| Google LLC — Google Sign-In | Authenticates parent Google identity (when used) | United States | Reg 10(2)(ii) + Reg 10(1)(b) as above. |
| Google LLC — Google Play Billing | Processes subscription purchases | United States | Reg 10(2)(ii) + Reg 10(1)(b) + Google Play Developer Distribution Agreement. |
| Resend, Inc. (San Francisco, CA, USA) | Delivers transactional email to Singapore parent users | United States | Reg 10(2)(ii) + Reg 10(1)(b). |
Every sub-processor is bound by a written data-processing agreement that forbids processing of any data we transmit for any purpose other than performing the service we engaged them for, and that incorporates the security and confidentiality controls in our Records of Processing Activities (Article 30) § 7 + PDPA s 24 protection obligation. The full sub-processor list, with each row's processor-agreement status, is at our sub-processor register.
11. Breach notification — PDPA Part VIA (Mandatory Data Breach Notification scheme)
PDPA Part VIA (ss 26A–26E, in force since 1 February 2021 + PDPR-NDB 2021) is the strictest breach-notification regime in the landing-country set, with a hard 3-calendar-day deadline for PDPC notification:
| Audience | Trigger | Deadline | Channel |
|---|---|---|---|
| PDPC | A notifiable data breach has occurred — defined at PDPA s 26B + PDPR-NDB 2021 Reg 3 as a data breach that (i) results in or is likely to result in significant harm to an affected individual (the significant-harm test, with Reg 3 specifying significant-harm categories) OR (ii) is of significant scale (a data breach affecting 500 or more individuals — PDPR-NDB 2021 Reg 3(2)). | Within 3 calendar days of the organisation determining (after assessment) that the breach is a notifiable data breach. The organisation must conduct the assessment in a reasonable and expeditious manner (PDPA s 26C + PDPR-NDB 2021 Reg 4). Balance internal anchor: as soon as practicable but no later than 72 hours from initial discovery (matched to the GDPR Art 33 benchmark), with the formal PDPC notification submitted on the assessment-completion timestamp within the statutory 3-calendar-day window. | PDPC online Data Breach Notification form per PDPA Part VIA + PDPR-NDB 2021 at https://eservice.pdpc.gov.sg/case/db |
| Affected individuals | A notifiable data breach that meets the significant-harm-to-individual limb at PDPA s 26D(1)(a) — i.e., the breach results in or is likely to result in significant harm to an affected individual. No notification to individuals is required where the notification only meets the significant-scale limb at s 26B(1)(b) and where Reg 8 carve-outs apply (significant-scale-only breach without significant harm). | At the same time or as soon as practicable after notifying the PDPC (PDPA s 26D + PDPR-NDB 2021 Reg 7). | Direct email to the affected parent on file; in-app banner where the parent is logged in; out-of-app contact via the public-website incident page if email is no longer deliverable. The notification is in English. |
| CSAE-specific | An incident with a CSAE component. | Per § 14 below + the internal runbook (M1). | SPF + MSF CPS + TOUCH Cyber Wellness. |
The internal breach-decision SLA is at our breach-notification runbook § 5.4 + § 9: preliminary classification within one business day, formal assessment under PDPA s 26C completed within 72 hours of discovery, PDPC notification within the statutory 3-calendar-day deadline (the strictest deadline in the landing-country set), affected-individual notification at the same point unless one of the s 26D(5) / Reg 8 carve-outs applies (notification likely to compromise an ongoing investigation; the organisation has taken effective remedial action that renders significant harm to the individual no longer likely; etc.).
11.1 Minimum content of the PDPC notification (PDPA s 26C + PDPR-NDB 2021 Reg 5)
The PDPC notification states:
- the date and circumstances of the notifiable data breach;
- the personal data and categories of personal data involved;
- the number of affected individuals (or the best estimate);
- the manner in which the personal data was affected (including whether the data has been rendered unintelligible or whether the data has been retrieved or remains under unauthorised access);
- the steps taken or proposed to be taken by the organisation in response to the breach (including any steps to remedy the breach + steps to contain the breach + steps to notify affected individuals);
- the contact information of the DPO (, named individual: ).
The English-language template lives in our breach-notification runbook § 8.1.
11.2 Non-compliance — PDPA s 26E
Failure to notify the PDPC of a notifiable data breach is an offence and on conviction the organisation is liable to a fine not exceeding SGD 100,000 under PDPA s 26E. The PDPC may also impose financial penalties under PDPA s 60 for the underlying contravention of the protection obligation.
12. Cookies, spam, and electronic direct marketing
Singapore does not have a dedicated ePrivacy / cookies statute. The substantive position on cookies and electronic direct marketing is derived from: (i) PDPA s 13 + s 18 + s 20 for any cookie that processes personal data; (ii) the PDPC's Advisory Guidelines on the PDPA for Selected Topics Chapter on cookies; (iii) the Spam Control Act 2007 for commercial electronic messages; (iv) the PDPA Part VII Do Not Call Registry for telemarketing voice calls + SMS / faxes (s 36–48).
12.1 In-app — strictly-necessary storage only
The Balance app (parent and kid) does not deploy any cookie-equivalent storage that is not strictly necessary for the service. The strictly-necessary storage Balance uses (authentication tokens in Android SecureStore; the device-pairing key wrap; the kid app's earned-time cache) is operationally necessary and is covered by the parent's sign-up consent.
12.2 Public legal-documents site — no analytics, no advertising, no tracking
The public legal-documents site (balance.babayagaprogram.com) uses only strictly-necessary cookies; no analytics cookies; no advertising cookies; no third-party trackers; no fingerprinting; no embedded social plugins.
12.3 Electronic direct marketing — not sent
Balance does not send commercial electronic messages within the meaning of Spam Control Act 2007 s 2(1) to Singapore residents. The only email Balance sends to Singapore parent users is transactional — account creation, password reset, subscription receipts, security alerts, and parent-action notifications. The SCA's "commercial electronic message" definition requires the message to promote or solicit the supply of goods or services; transactional messages are outside the definition. If Balance ever introduces a marketing channel, we will comply with SCA Schedule I (sender identification + valid unsubscribe + accurate message subject) and Schedule II (unsubscribe facility), and we will check the PDPA Part VII Do Not Call Registry for any number we intend to call before placing a telemarketing call.
12.4 No telemarketing
Balance does not place telemarketing voice calls, SMS, or faxes to Singapore residents. The PDPA Part VII Do Not Call Registry obligations are not engaged.
13. Lawful-access requests and the encryption posture
Singapore authorities may serve a lawful-access request on Balance via:
- A judicial production order under the Criminal Procedure Code 2010 (Singapore) Part IV — the principal mechanism for compelling production of stored personal data in connection with a criminal investigation.
- A judicial search warrant under the CPC Part IV.
- An Order of the Minister for Home Affairs or the Commissioner of Police under the Online Criminal Harms Act 2023 (OCHA) — content-removal Direction, access-restriction Direction, app-removal Direction, or account-restriction Direction.
- A judicial production order under the Mutual Assistance in Criminal Matters Act 2000 (MACMA), where the request comes from a foreign state with a bilateral or multilateral mutual-assistance treaty with Singapore.
- A PDPC investigation under PDPA s 50–55 (the Commissioner has powers analogous to those of a court for the purposes of an investigation).
- A judicial order under the Computer Misuse Act 1993 (CMA) ss 23–25 (preservation + production orders).
- An ordinary civil court production order or subpoena under the Rules of Court 2021 (Singapore).
- A Cybercrime Convention equivalent — Singapore is not a party to the Budapest Convention on Cybercrime as of the Effective date (Singapore has been a non-Member observer + cooperator).
The Balance architectural posture interacts with these mechanisms as follows:
- Proof media is end-to-end encrypted. The kid's device generates a fresh per-file file-encryption key, encrypts the proof file with XChaCha20-Poly1305, wraps the file-encryption key to each authorised parent device's X25519 public key, and uploads only the resulting ciphertext + the recipient-wrap envelopes. We do not retain a master key, a backdoor, or any other means by which we could ourselves decrypt the proof media.
- No assistance with bulk plaintext interception. Balance does not perform bulk plaintext content scanning. Balance does not deploy a server-side content-moderation engine on the proof-media payload. There is no plaintext on our side to be intercepted.
- Response protocol. On receipt of a lawful-access request directed at proof media, we will: 1. acknowledge receipt within one business day; 2. engage Singapore counsel to assess the validity of the request and the appropriate response under PDPA s 17(1) read with First Schedule paragraph 1(d) (collection use or disclosure required or authorised by any written law); 3. preserve the relevant ciphertext for the period the request requires (subject to our retention rules); 4. inform the requesting authority that the proof media is end-to-end encrypted and that plaintext is not available from us; 5. cooperate in identifying and serving the lawful-process route to the parent — who holds the decryption key — if that is the appropriate channel.
- CSAE-cooperation overlay. Notwithstanding the encryption posture, Balance cooperates fully with the SPF Police Cybercrime Command, the MSF Child Protective Service, TOUCH Cyber Wellness, and the National Council of Social Service on any CSAE-related referral, via the routes in § 14 below.
- Notification of the data subject. Where the lawful-access request is not accompanied by a non-disclosure obligation, we will inform the affected parent of the request (PDPA s 20 notification obligation). Where the request is accompanied by a statutory non-disclosure obligation (e.g., under the CPC, the OCHA, or the MACMA), we will comply with the order and inform the parent as soon as the order permits.
The full encryption posture is in our encryption-posture record.
14. CSAE reporting routes — Singapore
A Singapore resident (parent, kid, or third party) who wishes to report a CSAE concern about Balance, about a third party encountered outside Balance, or about a Balance user, may use any of the following routes:
- Balance Designated Child Safety Officer:
(named individual: ). Acknowledgement within one business day, in English. - Singapore Police Force (SPF) — emergency 999 (Triple Nine); non-emergency 1800-255-0000. SPF Police Cybercrime Command (
https://www.police.gov.sg/) is the principal law-enforcement node for cyber-CSAE. - Singapore Police Force — i-Witness portal at
https://eservices.police.gov.sg/content/policehubhome/forms/iwitness.html— online reporting. - Ministry of Social and Family Development (MSF) — Child Protective Service (CPS) — for child-welfare concerns. Phone: 1800-777-0000 (Family Service Centre Hotline). Online:
https://www.msf.gov.sg/our-services/Pages/Child-Protective-Service.aspx. - National CARE Hotline — government 24/7 helpline. Phone: 1800-202-6868.
- TOUCH Cyber Wellness — children's online-safety education and counselling. Phone: 1800-377-2252 (TOUCHline). Online:
https://www.touch.org.sg/. - Tinkle Friend — Singapore Children's Society's helpline for children aged 7–12. Phone: 1800-274-4788. Online chat at
https://www.tinklefriend.sg/. - Singapore Children's Society — Phone: 6273 2010. Online:
https://www.childrensociety.org.sg/. - Samaritans of Singapore (SOS) — 24/7 emotional-support helpline. Phone: 1767. Online:
https://www.sos.org.sg/. - ICMEC — International Centre for Missing & Exploited Children —
https://www.icmec.org/. Singapore coordination via SPF + INTERPOL Singapore. - INHOPE — Singapore does not currently have a domestic INHOPE-member hotline at the Effective date. Reports involving cross-border CSAM material flow through SPF + INTERPOL Singapore + the international INHOPE network.
The full CSAE Country Routing Table is in Child Safety Standards § 8.6.
15. Complaint routes (summary)
A Singapore resident who is dissatisfied with Balance's handling of a privacy enquiry or a child-safety concern may complain to any of the following authorities:
| Authority | Subject matter | Address / URL |
|---|---|---|
| Personal Data Protection Commission (PDPC) | PDPA | 10 Pasir Panjang Road, #03-01, Mapletree Business City, Singapore 117438; https://www.pdpc.gov.sg/; +65 6377 3131 |
| Infocomm Media Development Authority (IMDA) | Broadcasting Act + Films Act + Code of Practice for Online Safety + APEC CBPR Accountability Agent | 10 Pasir Panjang Road, Mapletree Business City, Singapore 117438; https://www.imda.gov.sg/; +65 6377 3800 |
| Singapore Police Force (SPF) — Police Cybercrime Command | CMA + Penal Code | https://www.police.gov.sg/; emergency 999; non-emergency 1800-255-0000 |
| Ministry of Social and Family Development (MSF) — CPS | CYPA | https://www.msf.gov.sg/; 1800-777-0000 |
| Competition and Consumer Commission of Singapore (CCCS) | CPFTA + competition law | https://www.cccs.gov.sg/; +65 6325 8255 |
| Consumers Association of Singapore (CASE) | CPFTA consumer-protection advocacy | https://www.case.org.sg/; +65 6100 0315 |
| Data Protection Appeal Panel | Appeals from PDPC decisions under PDPA Part X | via PDPC |
| District Court of Singapore | PDPA s 48O private right of action + CPFTA s 6 civil action | https://www.judiciary.gov.sg/ |
| General Division of the High Court of Singapore | PDPA s 48O above District Court limits; appeals from Data Protection Appeal Panel | https://www.judiciary.gov.sg/ |
A Singapore resident may always first raise the matter with us at (DSAR; named individual: , in his capacity as the DPO under PDPA s 11(3)). We will respond within the PDPA timelines. Raising the matter with us first is recommended by the PDPC but is not a precondition to complaining to the PDPC.
16. Consumer rights — the CPFTA + Lemon Law + Sale of Goods Act + Unfair Contract Terms Act overlay
The Consumer Protection (Fair Trading) Act 2003 (Singapore) ("CPFTA"), as substantively amended to include the Lemon Law provisions at CPFTA Part III (in force 1 September 2012), applies to Balance's subscription flow as a consumer transaction — the parent is a consumer within CPFTA s 2 (not engaged in trade or business in the transaction). The Sale of Goods Act 1979 (Singapore, as adopted) and the Unfair Contract Terms Act 1977 (Singapore, as adopted) layer additional implied terms. Treatment is implemented in Subscription Terms § 20.
16.1 Unfair practices (CPFTA s 4)
CPFTA s 4 prohibits unfair practices — false claims, misleading representations, exploitative conduct, accepting payment when there are reasonable grounds to believe the supplier will not be able to supply, taking advantage of a consumer's inability to protect his or her own interests, etc. The Specified Acts under the Second Schedule include over 20 categories of prohibited conduct. The Balance Terms of Service (Terms of Service) and the in-app subscription flow are drafted to avoid each CPFTA s 4 risk.
16.2 Lemon Law — CPFTA Part III (in force 1 September 2012)
The CPFTA Part III "Lemon Law" extends implied consumer guarantees and remedies. The principal Lemon Law rules:
- CPFTA s 12B — 6-month presumption of defect — where the goods do not conform to the contract within 6 months from delivery, the non-conformance is presumed to have existed at the time of delivery; the burden of proof shifts to the supplier to demonstrate that the goods conformed at delivery.
- CPFTA s 12C — Hierarchy of remedies — repair / replacement first; if not possible or reasonable, reduction in price or rescission.
- CPFTA Part III applies to services by reference to s 12B(1) (goods including services where the contract is for the supply of goods + services).
The Lemon Law applies in modified form to subscription services where the service is supplied as a discrete continuing supply (i.e., Balance subscription).
16.3 Sale of Goods Act + Unfair Contract Terms Act
The Sale of Goods Act 1979 implied terms include: SGA s 13 description; SGA s 14 satisfactory quality + fitness for purpose. The Unfair Contract Terms Act 1977 s 11 requires that any term restricting liability satisfy the reasonableness test, having regard to the resources of the parties + the bargaining position + whether the consumer received an inducement.
16.4 Forum and choice of law
The Balance Terms of Service preserve the consumer's domicile forum (see Terms of Service § 19); choice-of-law clauses that would displace the CPFTA, Lemon Law, Sale of Goods Act, or Unfair Contract Terms Act to the prejudice of the Singapore consumer are subject to the reasonableness test under the UCTA s 11 + the public policy doctrine. The CCCS may seek injunctive relief under CPFTA s 9A in respect of unfair practices.
16.5 Refunds and the Singapore subscription posture
Balance honors a voluntary 14-day no-questions refund window via Google Play Billing, exceeding the CPFTA + Lemon Law minimum standards for a subscription-service supply. The 14-day refund window is documented at Subscription Terms § 20.
17. Cross-references
- Global Privacy Policy: Privacy Policy (H1).
- Children's Privacy Notice: Children's Privacy Notice (H2).
- Terms of Service: Terms of Service (H3).
- Subscription Terms: Subscription Terms (H4).
- Child Safety Standards: Child Safety Standards (H5).
- Retention Policy: Data Retention & Deletion Policy (H6).
- Records of Processing: our Records of Processing Activities (Article 30) (H7).
- DPIA + LIA: our Data Protection Impact Assessment (H8).
- Breach Runbook: our breach-notification runbook (M1).
- Transfer Pack: our international-transfer pack (M2) — written processor agreements with PDPA-comparable-protection clauses on file.
- JIT Permission Disclosures: the just-in-time permission disclosures (M3).
- Play Console Permission Declarations: the Play Console permission declarations (M4).
- Play Console Data Safety: the Play Console Data Safety form (M5).
- Play Console Child Safety Standards Declaration: the Play Console Child Safety Standards declaration (M6).
- Play Console Target Audience + IARC: the Play Console Target Audience form (M7).
- US Country Annex: United States annex (A-US).
- UK Country Annex: United Kingdom annex (A-UK).
- EU/EEA Country Annex: EU / EEA annex (A-EU-EEA).
- Argentina Country Annex: Argentina annex (A-AR).
- Chile Country Annex: Chile annex (A-CL).
- Colombia Country Annex: Colombia annex (A-CO).
- Peru Country Annex: Peru annex (A-PE).
- Uruguay Country Annex: Uruguay annex (A-UY).
- Canada Country Annex: Canada annex (A-CA).
- Australia Country Annex: Australia annex (A-AU).
- New Zealand Country Annex: New Zealand annex (A-NZ).
- App Classification: our country classification table.
- Sub-processor list: our sub-processor register.
- Android Permissions Register: our permissions register.
- Encryption Posture: our encryption-posture record.
- Data Flow / Inventory Map: our internal data-flow map.
- Phase-2 Placeholder Tracker: our internal compliance tracker.
- Compliance Plan: our internal compliance plan.
18. Versioning and review
This Annex follows the same strict versioning protocol as the rest of the Phase-1 bundle:
- Every change to a substantive row in §§ 2–16 bumps the Last updated date at the top of this file and triggers a re-publication at Privacy Policy and Children's Privacy Notice.
- A material amendment to the PDPA, the PDPR 2014, the PDPR-NDB 2021, or any associated subsidiary regulation triggers an off-cycle rewrite of §§ 2, 4, 6, 8, and 11.
- The making of the subsidiary regulations under PDPA s 26P to operationalise Part VIB (data portability) triggers an off-cycle update to § 6 + § 8 of this Annex.
- A new PDPC Advisory Guideline under PDPA s 49 — in particular any revision to the Advisory Guidelines on the PDPA for Children's Personal Data — that materially affects Balance's posture triggers an off-cycle update.
- A material amendment to the Spam Control Act 2007 triggers an off-cycle update to § 12.
- A material amendment to the OCHA, the Broadcasting Act 1994 / Code of Practice for Online Safety, the Online Safety (Miscellaneous Amendments) Act 2022, or any IMDA Designation Order extending the DOCS framework to parental-control services triggers an off-cycle update to § 2 + § 5 + § 13.
- A material amendment to the Penal Code 1871 (in particular ss 376–376E, 377BA–377BJ) or to the Children and Young Persons Act 1993 triggers an off-cycle update to § 13 + § 14.
- A material amendment to the Computer Misuse Act 1993, the Criminal Procedure Code 2010, the Mutual Assistance in Criminal Matters Act 2000, or any successor cybercrime statute triggers an off-cycle update to the relevant operational section.
- A material amendment to the CPFTA, the Lemon Law, the Sale of Goods Act 1979, or the Unfair Contract Terms Act 1977 triggers an off-cycle update to § 16 + Subscription Terms.
- A material PDPC decision under PDPA Part IX, or any decision of the Data Protection Appeal Panel under PDPA Part X, or any judgment of the District Court or the General Division of the High Court on PDPA s 48O private-right-of-action matters triggers an off-cycle update.
- Singapore's accession to the Council of Europe Convention 108 or Convention 108+, or the Budapest Convention on Cybercrime, triggers an off-cycle update to § 2 + § 13.
- A new EU adequacy decision for Singapore (currently none at the Effective date) triggers an off-cycle update to § 8 + § 9.
- A material change to a sub-processor's PDPA-comparable-protection status triggers an off-cycle update to § 8 + § 10 + our sub-processor register.
- The annual review is by 9 June. The DPO signs the review off; the Designated Child Safety Officer co-signs any change to § 3 (supervisory authorities), § 5 (children's rights), § 11 (breach), § 13 (lawful-access), or § 14 (CSAE routes).
- This Annex is republished alongside H1 and H2 at the public legal-documents site (Privacy Policy and Children's Privacy Notice) and is incorporated by reference. The Malay, Mandarin Chinese, and Tamil translations are queued for the Phase-2 locale rollout per our internal compliance tracker.
End of Singapore Country Annex.