SAC-SINGLAS Accredited ISO/IEC 17025 Acc. No. LA-2023-0845-C Traceable to Singapore's NMC View Scope
Data & Compliance

PDPA and Calibration Records: What Singapore Laboratories and Their Customers Need to Know

Most calibration certificates contain personal data. The name of the instrument owner, the engineer who received the instrument, or the person who authorised the calibration. Singapore's Personal Data Protection Act 2012 (PDPA) applies to this personal data, creating obligations for both calibration laboratories (as data processors) and their customers (as data controllers). This article explains how PDPA intersects with calibration records management, what obligations apply, and how to structure your calibration document management to remain compliant.

Unitest Technical Team June 2026 9 min read Data & Compliance
Laboratory professional reviewing calibration records and documentation at a precision instrument workstation
Direct Answer Singapore's PDPA applies to personal data contained in calibration certificates and records. Including the names, signatures, and contact details of engineers and authorised persons. Calibration laboratories are data intermediaries; their customers are data controllers. Both have obligations under PDPA. The good news: retaining calibration records for quality and regulatory purposes is a legitimate business purpose. The personal data is incidental and PDPA does not override the quality system's retention requirements.

Key Takeaways

  • PDPA applies to any personal data in calibration records. Names, signatures, email addresses of engineers and contact persons
  • Calibration laboratories are data intermediaries processing personal data on behalf of their customers (the data controllers)
  • Retaining calibration certificates for ISO 9001, GMP, HACCP, or other quality purposes is a legitimate business purpose under PDPA
  • Customers should use a dedicated business email rather than personal email addresses in calibration correspondence
  • Calibration records should be stored in access-controlled systems, not in open shared folders or personal email inboxes
  • When calibration records reach their retention period end, they must be properly disposed of. Not just abandoned in storage

PDPA and the Calibration Laboratory Relationship

The Personal Data Protection Act 2012 (PDPA) governs the collection, use, disclosure, and care of personal data in Singapore. It applies to all organisations (including calibration laboratories and their customers), that collect, use, or disclose personal data in the course of their activities. The Act defines personal data broadly as data about an individual who can be identified from that data or from that data and other information to which the organisation has or is likely to have access.

In the calibration context, two distinct roles exist under PDPA. Understanding which role your organisation occupies is the starting point for determining your obligations.

The calibration laboratory is typically a data intermediary. It processes personal data (such as the customer contact's name, signature, and delivery address) on behalf of the customer, for the purpose of producing a calibration certificate. The laboratory does not decide what personal data to include. The customer's purchase order, instrument label, and correspondence determine this. The laboratory processes the data to fulfil the calibration service contract.

The customer (the manufacturer, laboratory, hospital, food factory, or other regulated entity) is the data controller. It decides the purpose for which the calibration record is collected and how long it will be retained. The customer holds the calibration certificate as part of its quality management system, and the purpose of that retention (ISO 9001 compliance, GMP documentation, HACCP record-keeping), is the customer's decision.

This distinction matters because PDPA places different obligations on data intermediaries versus data controllers. A data intermediary's primary obligations are security and compliance with the data controller's instructions; a data controller's obligations are broader, encompassing collection purpose, accuracy, retention, and individual access rights. The customer retaining the calibration certificate bears primary responsibility for the personal data management obligations associated with that record.

Many organisations operating quality management systems (ISO 9001, ISO 13485, GMP, HACCP), have not considered whether their calibration records constitute personal data records under PDPA. They almost always do. A calibration certificate that bears the name of the instrument custodian, the authorised signatory, or the receiving engineer contains personal data about those individuals and is therefore subject to PDPA.

What Personal Data Appears in Calibration Records

Personal data in calibration records is not always obvious, because calibration is fundamentally a technical process. The focus is on the instrument, the measurement result, and the traceability chain. The personal data is incidental, but it is present in almost every calibration record set.

The table below maps the common types of calibration records and the personal data elements each typically contains.

Record Type Personal Data Elements Who Is Affected
Calibration certificate (front page) Customer contact name, authorised signatory name, delivery address Customer (data controller)
Calibration certificate (technician section) Calibration technician name, signature, employee ID Calibration laboratory (data controller for its own staff data)
Accompanying delivery receipt / job order Name of person who received the instrument, signature, timestamp Both parties
Calibration correspondence (email) Customer engineer's name, personal email address, phone number (if given) Both parties
Calibration management software records Asset owner (name), approver name, purchase order approver Customer (data controller)
Calibration recall notifications Engineer's email address, name, instrument assignment Customer (data controller)

It is worth noting that the calibration laboratory's own staff data (the technician's name and signature on the certificate), is personal data for which the laboratory is the data controller, not an intermediary. The laboratory must manage this data under its own data protection obligations, separate from its intermediary obligations with respect to customer data.

PDPA Obligations for Calibration Laboratories (Data Intermediaries)

Under PDPA, data intermediaries must protect personal data in their possession using reasonable security measures; not retain personal data longer than necessary for the purpose of processing; comply with the data controller's instructions; and notify the data controller of any data breach involving their personal data.

Security of Customer Data

For calibration laboratories, the security obligation means that the laboratory's internal job records (containing the customer contact's name, instrument details, and correspondence), should be stored in access-controlled systems. Calibration job management software, if used, should require authenticated access. Printed calibration certificates awaiting dispatch should not be left in publicly accessible areas. Electronic records should not be stored in open shared drives or unprotected folders accessible to all laboratory staff regardless of role.

Retention of Customer Data

The laboratory should not retain customer personal data indefinitely. A reasonable retention period tied to the laboratory's business needs and its accreditation requirements applies. ISO/IEC 17025:2017 requires calibration laboratories to retain their own records (including the raw data, calibration reports, and job records), for a defined period (typically at least 5 years or as specified by the accreditation body). During this retention period, the customer personal data incidentally captured in these records may be retained. At the end of the retention period, records should be properly disposed of.

Marketing Restrictions

Calibration laboratories should not use customer personal data for purposes beyond fulfilling the calibration contract. Using the calibration engineer's personal email address (as opposed to a business email) to send unsolicited marketing material would require specific consent under PDPA. A business email address sent in the course of a commercial transaction is generally understood to be available for business communications related to that transaction, but using it for unrelated marketing requires separate consent or must fall within the permitted exceptions under the PDPA's Do Not Call (DNC) provisions.

Data Breach Notification

In the event of a data breach, for example, customer calibration records exposed in a cyberattack on the laboratory's systems, or an email sent to the wrong recipient containing a customer's calibration certificate with personal data. The laboratory must notify the Personal Data Protection Commission (PDPC) and affected individuals within 3 days if the breach is a notifiable data breach under the 2020 PDPA amendments. A notifiable data breach is one that causes or is likely to cause significant harm to affected individuals. The laboratory should also notify the affected customer (as data controller) promptly so the customer can fulfil its own notification obligations.

Documented Data Protection Policy

Calibration laboratories should have a documented personal data protection policy and appoint a data protection officer (DPO) or an individual responsible for data protection compliance. The PDPC does not mandate a specific role title, but the function must exist. For small calibration laboratories, this is typically the quality manager or laboratory director, in addition to their other responsibilities.

Calibration Records You Can Trust

SAC-SINGLAS Certificates Delivered Securely, with Documented Data Handling

Unitest issues accredited calibration certificates with documented data handling procedures, access-controlled record storage, and clear retention policies, so your quality audit is straightforward and your PDPA obligations are supported.

PDPA Obligations for Calibration Record Holders (Data Controllers)

Organisations retaining calibration records as part of a quality management system are data controllers for the personal data in those records. As data controllers, they bear the broader set of PDPA obligations. Not merely security, but also purpose limitation, accuracy, retention, and individual rights.

Documented Purpose

Organisations must have a documented purpose for retaining calibration records. This is, in practice, straightforward. ISO 9001, GMP, HACCP, ISO 13485, and most other quality standards explicitly require calibration records to be maintained as documented information or controlled records. The quality system requirement is the purpose. This purpose should be reflected in the organisation's data protection policy or privacy notice.

Accuracy of Records

PDPA requires that personal data be accurate and complete where it is likely to be used to make decisions affecting the individual. For calibration records, accuracy means ensuring the correct engineer's name is captured on the certificate and the record accurately reflects who authorised the calibration. This aligns with the data integrity requirements of ISO/IEC 17025 and GMP. The record must accurately reflect what happened.

Access and Correction Rights

Individuals whose personal data appears in calibration records have the right to access that data and to request corrections if it is inaccurate. In practice, this right is most likely to be exercised by employees who have left the organisation and wish to know what personal data about them remains in company records, or by contract engineers who want to understand what data the company holds. Organisations should have a process for handling such requests within the PDPA's 30-day response timeline.

Communicating the Purpose

The purpose for which personal data is collected must be communicated to individuals where practicable. In practice, employees and contractors authorising calibration services typically provide their information in the course of their professional role, and the business purpose is implicit. Their name on a calibration certificate indicates they authorised the calibration of a company instrument. Organisations should nonetheless reference calibration records in their employee privacy notices and, where external contractors are involved, in the contractor engagement terms.

Cross-Border Data Transfers

If calibration records are stored on cloud-based platforms with servers outside Singapore (a common scenario with cloud calibration management software, enterprise asset management systems, or ERP systems), the organisation must ensure the overseas recipient provides a standard of personal data protection comparable to PDPA. This is typically addressed through the service provider's data processing agreement, which should include standard contractual clauses or equivalent protections. Organisations should review their calibration management software vendor's data processing agreement to confirm this is in place.

The Legitimate Business Purpose for Long-Term Retention

PDPA's retention principle requires organisations not to retain personal data longer than necessary. The word "necessary" is key. It is determined by the purpose of retention, not by an arbitrary time limit. For calibration records, the purpose is compliance with quality and regulatory requirements, and those requirements specify minimum retention periods.

Regulatory Retention Requirements

ISO 9001:2015 requires calibration records to be retained as documented information. The specific retention period is left to the organisation to determine based on legal, regulatory, or contractual requirements applicable to their industry. Most organisations in regulated industries define this in their quality management procedures.

ISO 13485:2016 (medical devices) specifies that records must be retained for a period at least equivalent to the lifetime of the device, but not less than 2 years from the date of release of the product by the manufacturer. For many medical devices, this means 5–10 years of calibration record retention is required.

GMP (Good Manufacturing Practice) (whether Singapore's HSA GMP requirements, EU GMP, or FDA 21 CFR), typically requires calibration records to be retained for a minimum of 5 years, or 1 year beyond the expiry date of the product, whichever is longer. For pharmaceutical manufacturers with products with long shelf lives, calibration records may need to be retained for a decade or more.

HACCP / SFA requirements for food manufacturers in Singapore generally require calibration and maintenance records to be retained for at least 2 years, consistent with the traceability requirements of the food safety management system.

How PDPA Applies to These Retention Periods

These regulatory retention periods constitute a clear legitimate business purpose under PDPA. The personal data on the calibration certificate (the contact person's name and signature), is incidental to the primary purpose of the record, which is the calibration result and the evidence of metrological traceability. PDPA does not override these regulatory retention requirements. If GMP requires retaining a calibration record for 6 years, the personal data incidentally captured on that certificate may also be retained for 6 years, provided it is protected and not used for unrelated purposes.

This is one of the most common misconceptions organisations have about PDPA and calibration records, that PDPA somehow requires them to delete or anonymise calibration records at some point that conflicts with their quality system requirements. It does not. PDPA and the quality system's retention requirements work together, not against each other.

Disposal at the End of the Retention Period

At the end of the retention period, records must be properly disposed of. Not merely archived indefinitely "because we might need them." This is where many organisations fail the PDPA retention principle. A documented retention schedule and a disposal procedure must exist. The schedule should specify, for each class of calibration record, the applicable regulatory retention requirement and the disposal date. The disposal procedure should describe the method of destruction (cross-cut shredding for paper records, verified deletion or physical destruction for electronic records), and require that disposal be documented with a destruction record.

Practical Recommendations for Calibration Record Management

The following practical measures address both the PDPA obligations and the data integrity requirements of quality and regulatory frameworks, they are complementary, not competing.

Use Dedicated Business Contact Details

Ensure that calibration correspondence and certificates use the organisation's business email address and role-based contact details, for example, quality@company.com or calibration.lab@company.com rather than john.tan@company.com. This reduces the personal data footprint in calibration records significantly. A role-based email address does not constitute personal data in the same way as an individual's name in an email address, and it survives staff turnover without creating orphaned personal data in the laboratory's job records.

Access Controls on Calibration Records

Calibration records (whether in a physical binder, a shared network drive, or calibration management software), should be accessible only to staff with a legitimate operational need: quality assurance, regulatory compliance, calibration coordinators, and auditors. Open shared drive access (where anyone in the organisation can read or modify calibration records) is not adequate. Role-based access controls should be implemented, with access requests documented and approved by the quality manager or a delegated authority.

Electronic Calibration Records and Document Management

For organisations receiving calibration certificates electronically (as PDF files), a document management system with version control, audit trail, and access logging is the appropriate storage solution. Storing calibration certificates in a single person's email inbox is a common but problematic practice. It creates single points of failure, makes audits difficult, and leaves personal data in an uncontrolled location if the employee leaves. Certificates should be filed in a centralised, access-controlled document repository as soon as they are received.

Calibration Management Software

If using software to manage calibration schedules and recall notifications (such as Blue Mountain RAM, Limble CMMS, Maximo, or a custom-built solution), ensure the software vendor's data processing agreement addresses PDPA requirements. Key questions to ask the vendor: Where are data servers located? Is personal data encrypted at rest and in transit? What is the vendor's data breach notification procedure? Can data be exported and deleted on request? For vendors with servers outside Singapore, what comparable data protection obligations apply?

Secure Transmission of Calibration Certificates

Sending calibration certificates by plain unencrypted email is standard practice in the industry, but it creates PDPA risk if the certificate contains personal data and the email is intercepted or sent to an incorrect recipient. For organisations handling sensitive calibration records (e.g. in the pharmaceutical, medical device, or defence sectors), consider encrypted email or a secure document portal for certificate delivery. At minimum, the laboratory should confirm the recipient's email address before dispatch and should not send certificates to personal email addresses where a business address is available.

Documented Retention and Disposal Procedure

Develop and implement a documented retention schedule for calibration records, specifying the applicable regulatory requirement and the retention period for each record class. Link the retention schedule to a disposal procedure that describes how records are destroyed at the end of the retention period and requires that disposal be documented. Review the retention schedule when regulatory requirements change. Train quality and administrative staff on the procedure so that disposal actually happens. Rather than records accumulating indefinitely in storage rooms or archive drives.

PDPA, Data Integrity, and Calibration Records

ISO/IEC 17025:2017 includes explicit data integrity requirements for calibration laboratories. Records must be protected against unauthorised modification, deletion, or corruption, and the laboratory must have procedures to prevent unauthorised access. PDPA's security obligation aligns precisely with this requirement. For accredited laboratories, implementing PDPA-compliant data security for calibration records is not an additional burden. It is largely the same requirement expressed in a different regulatory language.

ALCOA+ and PDPA

For regulated industries operating under GMP or ISO 13485, the ALCOA+ data integrity framework (Attributable, Legible, Contemporaneous, Original, Accurate, and also Complete, Consistent, Enduring, Available), is a compliance requirement that overlaps substantially with PDPA's accuracy and security obligations. A calibration record that is attributable (the technician's name and signature are correct and verifiable) and accurate (the measurement result is correct) satisfies both the data integrity requirement and PDPA's accuracy principle. A calibration record that is protected from unauthorised modification (the Consistent and Enduring elements of ALCOA+) satisfies both the data integrity requirement and PDPA's security obligation.

Audit Trails

Electronic calibration records must have audit trails showing who accessed, created, or modified the record. This is a data integrity requirement under GMP and ISO 13485. Electronic records must capture metadata including user identity, timestamp, and the nature of the action. It is also a best practice under PDPA's accountability obligation, which requires organisations to be able to demonstrate compliance. An audit trail on a calibration record simultaneously satisfies GMP's data integrity requirement and provides the evidence needed to demonstrate PDPA-compliant access control.

The PDPC's Position on Records for Compliance Purposes

The Personal Data Protection Commission's advisory guidelines acknowledge that records maintained for compliance and regulatory purposes benefit from the legitimate interest basis and are not subject to the same restrictions as records held for purely commercial purposes. Calibration records held for quality system compliance (to demonstrate to customers, regulators, and auditors that instruments are performing within specification), are squarely within this category. The PDPA framework is designed to protect individuals from the misuse of their personal data, not to impede the legitimate record-keeping obligations of regulated industries.

In Practice: A Low-Burden Obligation

In practice, the PDPA obligations for most calibration record holders are not burdensome, provided a few foundational disciplines are in place. Use business contact details in calibration correspondence and on certificates. Store records in access-controlled systems. Define a documented retention period tied to the applicable regulatory requirement. Dispose properly at the end of the retention period. These four measures address the majority of PDPA obligations relevant to calibration records, and three of the four are already expected by ISO 9001, GMP, and HACCP. Calibration records management and PDPA compliance are largely the same problem, viewed from different angles.

Frequently Asked Questions

Does PDPA apply to calibration certificates and records?

Yes. Singapore's PDPA applies to any information about an individual, and calibration certificates typically contain personal data such as the name of the instrument contact person, the engineer who received the instrument, authorised signatory names, and signatures. Both the calibration laboratory (as data intermediary) and the customer retaining the certificate (as data controller) have obligations under PDPA. The good news is that retaining calibration records for quality system compliance is a clear legitimate business purpose.

What personal data is typically found in calibration records?

Common personal data in calibration records includes: the name and contact details of the customer's nominated contact person; the name and signature of the person who authorised or received the calibration; the name and signature of the calibration technician on the certificate; and the engineer's email address in calibration correspondence. All of these constitute personal data under PDPA if they identify or can identify an individual.

How long should calibration records be retained under PDPA?

PDPA requires that personal data not be retained longer than necessary for the purpose. For calibration records, the retention period is determined by the applicable quality or regulatory requirement. ISO 9001 (organisation-defined), ISO 13485 (minimum 2 years from device release), GMP (minimum 5 years or 1 year beyond product shelf life), HACCP/SFA (minimum 2 years). These regulatory requirements constitute a legitimate purpose for retaining the personal data incidentally captured on the calibration certificate for the same period. At the end of the retention period, records must be properly disposed of.

What are a calibration laboratory's PDPA obligations?

A calibration laboratory is a data intermediary under PDPA when processing customer personal data on behalf of the customer. Its obligations include: protecting customer personal data with reasonable security measures; not retaining personal data longer than necessary for the calibration purpose; complying with customer instructions regarding personal data; and notifying the customer and PDPC within 3 days if a notifiable data breach involving customer data occurs. The laboratory should have a documented data protection policy and appoint a data protection officer (DPO).

How should calibration records be disposed of when no longer needed?

When calibration records reach the end of their documented retention period, they must be securely disposed of, not merely archived indefinitely. For paper records: cross-cut shredding or a contracted document destruction service with a destruction certificate. For electronic records: verified deletion using overwrite software, degaussing of magnetic media, or physical destruction of storage devices. The disposal should be documented. Record the date, the records disposed of, and the disposal method.

Does sending calibration certificates by email comply with PDPA?

Sending calibration certificates by standard unencrypted email is common in the industry but creates PDPA risk if the certificate contains personal data and the email is intercepted or sent to the wrong recipient. Best practice is to use encrypted email, a secure document portal, or at minimum ensure certificates are sent to verified business email addresses rather than personal email addresses. If using plain email, the organisation should document this in its data handling procedures and obtain acknowledgement from the receiving party.

Is there a conflict between PDPA retention limits and quality system record retention requirements?

No, there is no conflict. PDPA's retention principle requires that personal data not be kept longer than necessary for the purpose. For calibration records, the purpose is quality system compliance and regulatory adherence. The applicable quality standard's retention period (GMP: 5+ years; ISO 13485: 2+ years; HACCP: 2+ years) defines "necessary." The personal data incidentally captured on the calibration certificate may be retained for the same period as the record itself. PDPA does not override regulatory retention requirements. It requires that at the end of the regulatory retention period, the records (and the personal data in them) be properly disposed of.

SAC-SINGLAS Accredited Laboratory
Written By

Unitest Technical Team. Singapore's SAC-SINGLAS accredited calibration laboratory (Acc. No. LA-2023-0845-C), providing traceable calibration services for electrical, electronic, temperature, pressure, and dimensional instruments since 2011. Our articles are reviewed by qualified calibration engineers and quality managers with active ISO/IEC 17025 laboratory experience.

Ready for a Compliant Calibration Partner?

Unitest issues SAC-SINGLAS accredited calibration certificates with documented data handling procedures, access-controlled records, and clear retention policies. Supporting your quality audits and your PDPA obligations.

SAC-SINGLAS Accredited · ISO/IEC 17025 · Traceable to NMC Singapore