Skip to content

Singapore

Selling technology from Singapore into Europe

A Singapore head office does not keep European regulation at arm's length. Once you serve customers, users or devices in the EU, some rules apply to you directly and others arrive through your customers' own obligations. This tells you which is which.

Before you invest in consultants, audits or a full GRC platform, start with a simple, evidence-based readiness check.

Check my EU readiness

About 3 minutes. No account. Free result.

The dataset

Built from official EU legal texts

Product scope

7
EU regulation families screened
3
distinct applicability categories
30
evidence artifacts mapped

Statutory maximum penalties

Up to €20M or 4%
GDPR

For certain infringements, where GDPR applies.

GDPR Article 83(5).

Up to €35M or 7%
EU AI Act

For non-compliance with the prohibited AI practices in Article 5.

AI Act Article 99(3).

For SMEs, including start-ups, the lower maximum applies (Article 99(6)).

Up to €15M or 2.5%
Cyber Resilience Act

For certain infringements of the essential cybersecurity requirements and specified obligations.

CRA Article 64(2).

€10M / 2%+
NIS2

For certain infringements by essential entities, Member States must set a maximum of at least €10 million or 2% of worldwide turnover, whichever is higher. National implementation and enforcement vary.

NIS2 Article 34(4).

Maximum statutory penalties. Actual exposure depends on applicability, role, infringement and enforcement circumstances.

What changes when Europe becomes a market

Most Singapore technology companies meet EU regulation commercially before they meet it legally: a European prospect sends a security questionnaire, a data processing agreement and a list of clauses their legal team requires, and the deal stalls while you work out what any of it means.

Two things are happening at once. Some EU instruments have extraterritorial reach and bind you regardless of where you are incorporated. Others bind your customer, who is contractually obliged to pass obligations down to suppliers, including you.

Treating both as one undifferentiated pile of “EU compliance” is what makes the work feel unbounded. Separated, it is usually a short list.

Direct obligation vs customer-driven requirement

A direct obligation exists whether or not a customer ever asks. If you offer a product to individuals in the EU or monitor their behaviour, data protection rules reach you at Singapore's doorstep and are enforced by EU supervisory authorities.

A customer-driven requirement exists because your buyer is regulated. An EU bank contracting a Singapore SaaS vendor must include specific terms in its ICT contracts; a covered operator must manage supply-chain security. You will be asked to sign up to those terms as a condition of the contract.

  • Direct: reaches you by law, enforced against you, does not disappear if the deal does
  • Customer-driven: reaches you by contract, negotiated commercially, blocks revenue when unmet
  • Possible: depends on a fact you have not yet established, worth resolving before a buyer asks

The rules that reach Singapore vendors

The dataset covers seven EU instruments. These are the ones that surface in European deals for companies based in Singapore.

GDPR
Reaches you directly where you target or monitor people in the EU, and contractually whenever you process personal data for a European customer.
DORA
Singapore has a dense financial-technology sector. Supplying an EU financial entity means accepting prescribed contractual terms, and more of them if your service supports a critical or important function.
NIS2
Usually arrives as supply-chain security due diligence from European customers in energy, health, digital infrastructure and public sector.
EU AI Act
Applies where AI output is used in the EU. Your obligations differ sharply depending on whether you build the model or embed someone else's.
CRA
Relevant to hardware and software products placed on the EU market, including vulnerability handling over the product's supported lifetime.
Data Act
Relevant to connected products, related services, and cloud providers facing customer switching and data access requests.
ePrivacy Directive
Applies to cookies, SDKs and analytics in anything you ship to EU users, separately from data protection law.

EU regulations we cover

A free 3-minute assessment

Six short steps: your company, what you sell, how you touch Europe, who buys from you, a few follow-up questions chosen from your answers, and what evidence you already hold.

The result separates direct obligations from customer-driven requirements, shows your evidence readiness, and names the documents you are missing. It is free, and there is no email gate.

How it works

  1. 01

    Answer 6 short steps

    Your company, EU activity, customers and current evidence.

  2. 02

    See what applies, and why

    Separate direct EU obligations from requirements flowing down from European customers.

  3. 03

    Get your action plan

    See your evidence gaps and the exact steps required to become EU-market ready.

  4. 04

    Build the evidence

    Documents, controls and a sequenced remediation roadmap, in the order to tackle them.

The $149 readiness plan

If you want the fix rather than the diagnosis, the RegRoute EU Readiness Pack is a one-time USD 149 purchase: the full sequenced remediation plan with owner and effort per step, article-level legal sources, practical evidence templates and a shareable PDF report.

One payment, no subscription, and no account to create.

$149 USD

Singapore-specific context

There is no current EU adequacy decision covering Singapore. That does not stop European data reaching your systems, but it does mean the transfer mechanism has to be assessed rather than assumed. Because of this, European buyers may request transfer paperwork from Singapore vendors that is not required from vendors in adequate countries.

PDPA compliance is a genuine starting advantage: you will already have a data inventory, a named privacy owner and breach procedures. It is not a substitute. The obligations differ in scope, in the rights individuals hold, and in what a European buyer expects to see documented.

For Singapore vendors working with EU financial-sector customers, DORA-related and supply-chain security questions can arise during procurement.

Guides for Singapore companies

Longer, sourced explanations of questions like these.

  • GDPR for Singapore companies

    When the GDPR applies to a Singapore company, how it differs from the PDPA, what EU customers ask for, and the transfer question Singapore vendors face. Sourced, with a 3-minute check.

  • DORA for SaaS vendors based in Singapore

    DORA binds EU financial entities, not their Singapore suppliers directly, except for the designated critical few. Here is how it reaches you through the contract, and what your MAS-regulated customer's EU parent will ask for.

  • Selling SaaS from Singapore to Europe

    The stages a European enterprise deal actually goes through, from first contact to signature, and which paperwork appears at each stage for a Singapore SaaS vendor.

Guides

Each guide answers one question directly, separates direct legal obligations from customer-driven requirements, and links to the official EU source.

What you receive

A management report, not a dashboard

Your result and, once unlocked, your complete plan are built to be read by a customer's security team or your own leadership, not just clicked through.

Illustrative example

EU market readiness

Direct, customer-driven and possible requirements, plus evidence readiness.

Your roadmap

Actions sequenced into do now, next and later.

Evidence

Have, partial, missing and unknown, artifact by artifact.

Find out what applies to your company.

Check my EU readiness

About 3 minutes. No account.

Singapore

General information, not legal advice. Applicability can depend on facts and national implementation. Verify material legal conclusions with qualified counsel.