Buyer Guides · 7 MIN
How to hire a software development partner in Singapore
What a Singapore company should check before hiring a software partner abroad: PDPA transfer rules, breach timelines, GST, MAS expectations and time overlap.
A Singapore company hiring a software partner should check four things before signing: who is a data intermediary under the PDPA and what that means for liability, how personal data leaves Singapore, how fast a breach reaches you, and how GST and time zones will work day to day. This guide covers each, with the official sources, so you can brief your counsel quickly.
- Under the PDPA, your company stays responsible for personal data a vendor handles for you, so the contract has to carry real obligations.
- Sending personal data outside Singapore triggers the Transfer Limitation Obligation, which needs comparable protection for the data abroad.
- A data intermediary must tell you about a breach without undue delay, and you then have a short window to notify the PDPC.
- Singapore is 2.5 hours ahead of India with no daylight saving, which gives a clean overlap of about five and a half hours.
- Regulated firms add MAS expectations on outsourcing and technology risk on top of the PDPA.
- Nactore is an AI-native product engineering team based in Mumbai that builds, ships and documents work so a Singapore buyer can show its auditors how data moves.
What does the PDPA say about hiring a software vendor?
The Personal Data Protection Act 2012 splits the world into organizations and data intermediaries. If your vendor processes personal data on your behalf and under a contract, it is a data intermediary. The Act is on Singapore Statutes Online, and the regulator is the Personal Data Protection Commission.
The key point is who carries the weight. A data intermediary processing for you under a written contract is directly bound by only a few duties: protecting the data (section 24), not keeping it longer than needed (section 25) and notifying you of breaches (section 26C(3)(a)). You, the organization, remain responsible as if you had done the processing yourself. A vendor that says "we are only a processor, so it is not our problem" is describing the law correctly, which is why your contract must push obligations down to them.
How does the Transfer Limitation Obligation affect an India-based team?
Section 26 of the PDPA and the Personal Data Protection Regulations 2021 say you may transfer personal data out of Singapore only if the recipient is bound by legally enforceable obligations that give protection at least comparable to the Act. Contracts are the usual route, and the Regulations also accept binding corporate rules and certain certifications, such as the APEC Cross-Border Privacy Rules or, for a vendor acting as a data intermediary, the APEC Privacy Recognition for Processors System.
For a software project this matters less than people fear, because much of the work needs no live personal data at all. The practical options are:
- Use synthetic or masked data in development and testing, so no personal data crosses the border.
- Keep production data in a Singapore cloud region and give engineers access through controlled, logged sessions.
- Sign contract clauses that bind the vendor to PDPA-standard protection, including onward transfers.
Whichever you choose, write down which data fields are involved and why. That record is what you show the PDPC if asked.
How quickly must a breach be reported?
Under the PDPA's data breach notification rules, an organization must notify the PDPC as soon as practicable and no later than 3 calendar days after it assesses that a breach is notifiable. A data intermediary must notify the organization without undue delay once it has reason to believe a breach occurred (section 26C(3)).
So your contract should set a number for the vendor's own notice, such as 24 hours from discovery, because your own clock starts running only when you assess the breach. Ask the vendor how it detects incidents, who is on call, and whether it has a written incident procedure.
What does GST mean when you pay a vendor abroad?
Singapore's GST rate is 9 percent. When a Singapore business buys services from an overseas supplier, the reverse charge can apply, which means you account for GST yourself instead of the vendor charging it. IRAS says it applies to GST-registered businesses that are not entitled to full input tax credit, for example because they make exempt supplies or receive non-business receipts. A business entitled to full input tax credit is outside this rule. The detail is on the IRAS page for local businesses buying imported services.
Withholding tax is a separate question. Some payments to non-residents, such as royalties and certain software payments, can attract it. For services, IRAS says that where a non-resident company provides them by electronic means from overseas, without sending staff to Singapore, the services are rendered outside Singapore and withholding tax is not applicable. See the IRAS withholding tax page for non-resident companies. Which bucket your contract falls into depends on how it is written. Confirm with your accountant before the first invoice.
Which extra rules apply to financial institutions?
If you are a bank, insurer, payments firm or other MAS-regulated entity, the vendor sits inside your outsourcing risk framework. The Monetary Authority of Singapore's Guidelines on Outsourcing (Banks) and Guidelines on Outsourcing (Financial Institutions other than Banks), both effective from 11 December 2024, expect due diligence on the provider, audit and inspection rights, termination and exit terms, and notice of adverse developments. They also point to MAS's Technology Risk Management Guidelines. Expect your risk team to ask for these in the contract.
How much time overlap will you get with a Mumbai team?
Singapore time (SGT) is UTC+8 and India (IST) is UTC+5:30, so Singapore is 2.5 hours ahead. Neither country uses daylight saving, so the gap never changes. Assuming a 10:00 to 19:00 IST day for the India team and 09:00 to 18:00 for Singapore:
| Item | Singapore (SGT) | India (IST) |
|---|---|---|
| India team day | 12:30 to 21:30 | 10:00 to 19:00 |
| Singapore team day | 09:00 to 18:00 | 06:30 to 15:30 |
| Shared working window | 12:30 to 18:00 | 10:00 to 15:30 |
| Overlap | 5.5 hours | 5.5 hours |
Mornings in Singapore are quiet unless the India team starts earlier, so schedule the daily meeting around 13:00 SGT. For ways to run work across zones, see working across time zones.
What should a Singapore buyer ask before signing?
Use this checklist in your vendor review.
- Which personal data will the vendor see, and can the work be done on masked data?
- Where will data be stored, and who can access it from where?
- What is the notice period for a suspected breach?
- Are sub-processors named, and can you object to new ones?
- What happens to your data and code at the end of the contract?
- Can you audit the vendor, or receive its security evidence on request?
For the IP and data terms behind items 4 and 5, read IP and data terms for AI projects.
Ask the PDPC-facing question first. "If the PDPC asked us to show how this vendor handles personal data, what would we hand over?" If the answer is vague, the contract is not ready.
Frequently asked questions
Is a foreign software vendor a data intermediary under the PDPA?
If it processes personal data for you under a contract, yes, wherever it is based. It owes you the duties in the contract and certain PDPA duties, and you remain responsible to individuals and the PDPC.
Do we need the vendor to have a Singapore entity?
No. The PDPA does not require it. The Transfer Limitation Obligation requires comparable protection through enforceable obligations, which a contract can provide.
What is the Data Protection Trustmark?
It is a Singapore certification that shows an organization's data protection practices were assessed. It is helpful evidence but not a legal requirement for a vendor.
Does this replace legal advice?
No. This is a plain-language guide with official sources. Confirm your specific setup with Singapore counsel and your accountant.
A short close
A Singapore buyer needs a partner who can explain, in writing, where data goes and who answers when something breaks. Get those answers before the scope discussion, not after.
Want this built for your team? Book a free 30-minute call.
Want to apply this to your business?
Book a free 30-minute call. We will tell you what we would do first.