Country-specific guidance Current
Setting a record-retention schedule for compliance evidence
Two obligations pull in different directions, and a retention schedule needs to satisfy both.
Singapore's anti-money laundering framework sets a minimum period client due diligence records must be kept, while the PDPA separately requires personal data not to be kept longer than necessary. This guide sets out how to reconcile the two. It is general information, not legal or tax advice.
Action plan
1 Apply the CDD record-keeping minimum where your firm is a registered CSP Where your firm is captured, this sets a floor for how long records must be kept.
Where a firm is a registered corporate service provider under the Corporate Service Providers Act 2024 framework, its customer due diligence records are commonly understood to be subject to a minimum retention period of five years. Confirm your firm's own registered status and the exact provision it relies on rather than assuming this figure applies without checking.
- Confirm whether your firm is a registered corporate service provider
- Apply a five-year minimum to CDD records where that status applies
- Confirm the exact provision your firm relies on rather than assuming the figure
Done when: A retention period consistent with the CDD minimum is applied to records covered by it
ACRA: Corporate Service Providers Act 20242 Apply the PDPA's Retention Limitation Obligation once the CDD minimum is met Meeting the CDD floor doesn't mean personal data can be kept indefinitely afterwards.
The PDPA's Retention Limitation Obligation requires an organisation to stop retaining personal data, or remove the means of associating it with a particular individual, once it's reasonable to assume the purpose for which it was collected is no longer being served and retention is no longer necessary for legal or business purposes. The PDPA doesn't prescribe a specific number of years; it requires a genuine, ongoing assessment instead.
- Reassess whether retention is still necessary once the CDD minimum period has passed
- Stop retaining personal data once neither the original purpose nor a legal or business need remains
- Don't treat the absence of a PDPA-prescribed number as licence to keep data indefinitely
Done when: Retention beyond the CDD minimum is based on a genuine ongoing need, not an indefinite default
Singapore Statutes Online: Personal Data Protection Act 20123 Build a single schedule that satisfies both obligations, not two conflicting ones The two obligations aren't in real conflict once the retention floor and the review point are both built in.
Set a retention schedule with a firm floor for CDD-covered records at the applicable minimum, and a scheduled review point at or after that floor to decide whether continued retention is still justified under the PDPA. This avoids disposing of records too early to meet the CDD minimum, and avoids keeping them indefinitely once that minimum has passed.
- Set the CDD minimum as a firm floor in the retention schedule
- Build in a review point at or after that floor to reassess PDPA justification
- Apply the same reconciled schedule consistently, not case by case
Done when: A single retention schedule reflects both the CDD minimum and a genuine PDPA review point
See storing client identity evidence securely