Refund Policy Generator Singapore
The PDPA, a mandatory Data Protection Officer, the Do Not Call registry and mandatory breach notification.
Singapore has no general cooling-off right for online purchases, so the published policy largely is the consumer’s entitlement - but the Lemon Law gives remedies for goods that do not conform, and the Consumer Protection (Fair Trading) Act makes misleading refund claims actionable.
Singapore’s Personal Data Protection Act has an obligation most regimes do not: every organisation must appoint at least one Data Protection Officer and make their business contact information publicly available. It is a small requirement that is missed constantly, and it is trivially checkable.
The 2020 amendments added mandatory breach notification, a data portability obligation, and a deemed-consent-by-notification route that lets organisations proceed without express consent where an assessment shows no adverse effect - a mechanism with no direct GDPR equivalent.
Marketing is governed separately through the Do Not Call provisions. Before sending a marketing message to a Singapore number you must check the DNC registry unless you have clear and unambiguous consent in evidential form, and penalties are enforced actively.
What a refund policy in Singapore has to cover
That there is no statutory cooling-off period for most online purchases
Lemon Law remedies for non-conforming goods: repair, replacement, reduction or refund
The six-month presumption that a defect existed at delivery
Your own return window, conditions and who bears return costs
Accurate description of rights, since misleading claims are actionable under fair trading rules
How Singapore actually moves personal data
NRIC and identity numbers
The PDPC restricts collection of NRIC numbers and copies of the identity card to narrow circumstances. Using NRIC as a customer reference is the classic Singapore compliance failure.
Deemed consent by notification
A route to proceed without express consent after an assessment of adverse effect and a notification period. It has to be documented to be relied on.
Marketing to Singapore numbers
DNC checks are a per-campaign operational step, with records kept to demonstrate the check happened.
Cross-border transfers
The organisation stays accountable, so the transfer clause and the recipient obligations belong in the policy and in the contract.
Data portability
The amendment introduced a portability obligation for applicable data, with implementation phased - the direction of travel is towards machine-readable transmission on request.
Third parties the draft will ask you about
Stripe · PayNow · GrabPay · AWS ap-southeast-1 · Xero · Salesforce · Twilio · SingPost
The rules that apply
PDPA 2012 (as amended 2020)
Consent, purpose limitation, notification, access and correction, accuracy, protection, retention limitation, transfer limitation and accountability.
Mandatory DPO
At least one designated individual, with business contact information published. Failure to appoint is itself a breach.
Data breach notification
Notifiable breaches must be reported to the PDPC within three calendar days of assessment, and to affected individuals where significant harm is likely.
Do Not Call registry
Checks required before marketing to Singapore telephone numbers, with exemptions only for clear and unambiguous consent or an ongoing relationship in defined terms.
Transfer limitation
Overseas recipients must be bound to a comparable standard of protection, typically through contract.
What the generated refund policy contains
The statutory right, stated separately
Consumer cancellation rights exist whatever your policy says, so they are set out first and your goodwill terms second.
Time limits and how they are counted
When the clock starts, whether it runs in calendar or working days, and what stops it.
Condition and evidence requirements
What state goods must come back in, and what proof of purchase you accept.
Who pays return postage
Split between faulty and change-of-mind returns, because the law treats them differently.
Refund method and timing
Original payment method, and the deadline you commit to once goods or notice are received.
Exclusions, stated lawfully
Perishables, personalised goods, unsealed hygiene items and downloaded digital content - the exclusions the law actually permits.
PDPA implementation essentials
Appoint and publish a DPO
A named role with contact details on the website, and internal authority to act.
Review NRIC collection
Remove it wherever a different identifier will do.
Document consent and deemed consent
Express consent records, plus the assessments underpinning any deemed-consent reliance.
Build the breach assessment and 3-day notification path
With a decision test for what makes a breach notifiable.
Bind overseas recipients contractually
To a comparable standard, and reflect that in the transfer clause.
Where this usually goes wrong
No published DPO contact
The requirement is not just to appoint but to publish business contact information. An unnamed "privacy team" inbox does not obviously satisfy it.
Collecting NRIC numbers by default
Permitted only where required by law or necessary to verify identity to a high degree of fidelity. Loyalty schemes and delivery forms are not that.
Skipping DNC checks
Consent has to be clear, unambiguous and in evidential form to displace the registry check. Implied consent from a purchase does not.
Missing the three-day notification window
It is calendar days from assessment, which is far tighter than most teams expect.
Frequently asked questions
Do I need a Data Protection Officer in Singapore?
Yes. Every organisation covered by the PDPA must designate at least one individual and make their business contact information available. There is no size exemption.
How quickly must I report a data breach?
To the PDPC within three calendar days of determining a breach is notifiable, and to affected individuals as soon as practicable where significant harm is likely.
Can I collect NRIC numbers?
Only where required by law or necessary to accurately establish identity to a high degree of fidelity. The PDPC guidance is restrictive and enforcement is active.
Can I run a no-refunds policy?
Not against statutory rights. In the UK and EU a consumer’s cancellation and faulty-goods rights apply regardless of what your policy says, and advertising "no refunds" is itself treated as a misleading practice.
Do digital products have to be refundable?
The cancellation right can be waived for digital content, but only if the customer gave express consent to immediate delivery and acknowledged losing the right. That acknowledgement has to be captured at checkout, not assumed.
How long do I have to issue a refund?
In the UK and EU, within 14 days of receiving the goods back or of the customer proving they returned them. Card scheme rules and marketplace policies often impose something tighter.
Refund Policy Generator Singapore
Answer a short questionnaire and get a draft written for Singapore. Free to start, no card required.
Generate your refund policyOther documents for Singapore
Each one is written for the same context, not a generic template.
The same document, by country
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.