How Data Brokers and Ad Tracking Build Your Profile Through Cookies and Pixels
How data brokers use cookies and tracking pixels to build your profile, what the PDPA requires of them in Singapore, and how to opt out.
How Data Brokers And Ad Tracking Work Singapore: The Machinery That Builds Your Profile
Stop automatic image loading in your email client now. That single action blocks the invisible tracking pixels that tell senders when, where and on what device you read their messages. Every time you load a webpage in Singapore, up to 50 different companies receive data about that single visit before the page finishes rendering. That is how data brokers and ad tracking work Singapore: a silent auction for your attention that completes in under 100 milliseconds, powered by your browsing history, device identifiers and location data.
The system uses three specific technologies that operate on every site you visit, every email you open and every app you use. Understanding those technologies is the only way to control what leaves your device. Below you will find exactly how cookies, tracking pixels and device profiling assemble a picture of you that data brokers sell to advertisers. You will get the settings paths to limit tracking on every major platform and browser, plus what Singapore's Personal Data Protection Act (PDPA) requires of the organisations collecting your data. The goal is to make the invisible machinery visible enough that you can decide what to do about it.
Cookies Tracking Pixels Explained: The Three Tools That Track You
Ad tracking in Singapore runs on three core technologies. Each works differently, and each collects a different kind of data. Knowing the difference is the first step to limiting them.
First-Party Vs Third-Party Cookies
A first-party cookie is set by the site you are visiting. It remembers your login status, your language preference and what is in your shopping cart. It is useful and largely benign. A third-party cookie is set by a domain other than the site you are on. When a Singapore news site loads an ad server from a different company, that server drops a cookie on your device. Every site that uses that same ad server sees the same cookie, so the ad server builds a map of everywhere you go. Google began phasing out third-party cookies on Chrome in 2024, with full removal completed by Q1 2025. It replaced them with the Topics API, which assigns broad interest categories on your device itself. That reduces the raw data flow but does not eliminate tracking.
Tracking Pixels In Web Pages And Emails
A tracking pixel is a 1x1 transparent image embedded in a web page or email. When your device loads that image, it sends data to the pixel's server: your IP address, the time, your device type, and a unique identifier. Marketers use pixels to know whether you opened an email, which links you clicked and which pages you visited after clicking. The pixel itself is invisible. You cannot see it, but your device communicates with it every time. An email from a Singapore retailer that contains a tracking pixel tells that retailer the exact minute you opened the message, your rough location from your IP address, and whether you read it on a phone or a laptop.
Device Fingerprinting And Mobile Advertising IDs
Device fingerprinting collects attributes of your device: browser version, installed fonts, screen resolution, time zone and operating system. The combination is unique for roughly 90 to 95 percent of device pairs. Unlike a cookie, a fingerprint cannot be deleted. Mobile advertising IDs, the Identifier for Advertisers (IDFA) on iOS and the Android Advertising ID (AAID), are resetable but persistent until you reset them. Apple's App Tracking Transparency framework, launched with iOS 14.5 in April 2021, requires apps to ask permission before tracking you across other apps and websites. The opt-in rate globally settled at roughly 25 to 35 percent of users as of 2023, meaning most users still allow tracking because they tap Accept without reading the prompt.
Data Broker Profiling Singapore: How Your Digital Shadow Becomes A Product
A data broker is a company that collects personal data from multiple sources and sells it to other organisations. Under the PDPA, it is called a data intermediary: an organisation that processes personal data on behalf of another. The distinction matters because data intermediaries are subject to the Protection Obligation and Retention Limitation Obligation under the Act, but they are not exempt from accountability.
Where The Profile Comes From
Data brokers in Singapore aggregate data from public records, loyalty programmes, online surveys, cookie data and third-party data purchases. They cross-reference these sources to build a profile that includes your name, address, phone number, email, date of birth, gender, marital status, education level, occupation, income bracket, purchase history, browsing behaviour, location data and device identifiers. A typical profile contains between 1,000 and 5,000 data attributes per individual.
Your digital footprint is what you actively leave: a social media post, a forum comment, a product review. Your digital shadow is what is collected about you passively: the pages you browse, the ads you hover over, the time you spend on each article, the route you drive. Data brokers trade in your digital shadow. You never gave them that data directly, yet it is the most valuable part of the profile because it reveals behaviour you do not consciously broadcast.
How Your Profile Gets Sold
Real-time bidding (RTB) is where this profile meets money. When you load a webpage, your device sends a bid request to an ad exchange. That request contains your IP address, device type, browser, operating system, approximate location and the site you are on. Between 10 and 50 intermediaries may receive that bid request data per single impression. The auction completes in under 100 milliseconds. The winning advertiser pays 2 to 10 times more for a targeted ad than a non-targeted one, because the profile makes the ad more likely to generate a click.
Opt Out Ad Tracking Singapore: The Exact Settings Paths That Work
Opting out of ad tracking is not a single action. It is a sequence of changes across your browser, your phone and the platforms you use. These are the steps that reduce the data available to data brokers.
On Your Browser
On Chrome, go to Settings then Privacy and Security then Cookies and other site data. Enable Block third-party cookies. On Safari, go to Settings then Privacy then uncheck Allow cross-site tracking. On Firefox, go to Settings then Privacy and Security then select Strict under Enhanced Tracking Protection. All three browsers also offer a Do Not Track request, but advertisers are not legally required to honour it in Singapore. The browser-level block is what stops the cookie.
On Your Phone
On iOS, go to Settings then Privacy and Security then Tracking and toggle off Allow Apps to Request to Track. This stops all apps from using your IDFA. On Android, go to Settings then Google then Ads and tap Delete advertising ID. Then toggle Opt out of Ads Personalization. These controls do not delete the data already collected, but they stop new data from being linked to your advertising ID.
On Social Media Platforms
On Facebook, go to Settings and Privacy then Settings then Ads then Ad Settings. Under Data about your activity from partners, choose Not allowed. On Instagram, the same controls apply because it uses Facebook's ad system. On TikTok, go to Settings and Privacy then Privacy then Personalization and toggle off Personalized ads. On LinkedIn, go to Settings and Privacy then Data Privacy then Ad preferences and toggle off Ads based on data from partners.
On Email Clients
To block tracking pixels in email, disable automatic image loading. In Gmail, this is already the default on desktop: images are loaded via a proxy that blocks the pixel's tracking data. In Apple Mail, go to Settings then Privacy and enable Protect Mail Activity, which loads images privately and masks your IP address. In Outlook, go to Settings then Mail then Layout and toggle off Automatically download pictures.
These adjustments reduce tracking but do not eliminate it. Browser fingerprinting cannot be disabled by a single toggle. The only complete protection is to use a browser that blocks fingerprinting by default, such as Firefox with Enhanced Tracking Protection set to Strict, or the Brave browser. Even then, some data leaks through the sites you choose to log into.
PDPA Data Broker Obligations Singapore: What The Law Requires Of Organisations Collecting Your Data
The Personal Data Protection Act (PDPA) sets nine core obligations that apply to any organisation collecting personal data in Singapore. Data brokers and advertisers are not exempt. The Personal Data Protection Commission (PDPC) enforces these obligations through complaints, investigations and public enforcement decisions. In 2023, the PDPC received 3,800 data protection complaints and issued 58 enforcement decisions. The maximum financial penalty for a breach is 10 percent of the organisation's annual turnover in Singapore or S$1 million, whichever is higher, a penalty that took effect from 1 October 2022.
Consent Obligation And Purpose Limitation
Organisations must obtain consent before collecting, using or disclosing personal data unless an exception applies. The PDPC's position on cookie consent is explicit: pre-checked boxes and implied consent through continued browsing are not valid forms of consent. The organisation must tell you what it is collecting and why, and you must actively agree. The purpose limitation obligation requires that data collected for one purpose cannot be used for a different purpose without fresh consent. When a data broker buys browsing history from an ad network and sells it to an insurer, that is a new use requiring new consent. The PDPC has issued enforcement decisions against organisations that collected data beyond what was necessary for the stated purpose. One example: an organisation that collected NRIC numbers for a simple membership programme, when the PDPC's advisory on NRIC numbers states that organisations may collect NRIC numbers only when required by law or necessary to verify identity to a high degree of fidelity.
Notification Obligation And Access Rights
On or before collecting your data, the organisation must inform you of the purposes for collection, use and disclosure. This is why websites show a cookie banner. The notification obligation is separate from consent: even if the banner does not require your consent under an exception, the organisation must still tell you what it is doing. You also have the right to access the personal data an organisation holds about you, including information about how it has been used or disclosed in the past year. The organisation must respond within 30 calendar days. You have the right to request correction of errors. Organisations may charge a reasonable fee for access requests but must provide an estimate before proceeding. The data portability obligation, introduced in the 2020 amendment, is not yet in force as of 2026, meaning you cannot currently demand that a data broker transfer your profile to another provider.
Protection Obligation And Retention Limitation
Organisations must make reasonable security arrangements to protect personal data from unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks. This applies to data intermediaries as well. The retention limitation obligation requires organisations to cease retention of personal data, or to remove the means of association with individuals, when the purpose for which the data was collected is no longer served and retention is no longer necessary for legal or business purposes. A data broker that keeps your browsing history for five years after you last visited any site in its network is likely violating this obligation. If a breach occurs that results in significant harm to affected individuals or affects 500 or more individuals, the organisation must notify the PDPC as soon as practicable, no later than three calendar days after assessment.
The Do Not Call Registry
The Do Not Call (DNC) Registry, established by the PDPC in 2014, allows individuals to register Singapore telephone numbers to opt out of unsolicited marketing calls, messages and faxes. As of 2023, approximately 1.2 million numbers were registered. The DNC Registry does not stop data brokers from collecting and selling your number. It stops organisations from using that number to contact you for marketing without your consent. If a data broker sells your number to an advertiser and that advertiser calls you, you can report the advertiser to the PDPC. The DNC Registry is a remedy for nuisance, not for privacy.
Who This System Suits And Who Should Skip It
Understanding how data brokers and ad tracking work suits the everyday Singaporean who wants to stop receiving eerily specific ads and unsolicited marketing calls. It suits the small-business owner who does not want their browsing history sold to competitors. It suits the parent who wants to know what data their child's apps are sending to third parties. It suits anyone who has ever searched for a product once and then seen ads for it everywhere for weeks.
It does not suit the reader who believes there is nothing to be done and that privacy is dead. That reader will find the settings paths and legal obligations here, but they must decide to use them. It does not suit the reader who wants to sue a data broker for S$1 million in damages. The PDPA does not provide a private right of action; only the PDPC can impose financial penalties. It does not suit the reader who wants a single button that fixes everything. There is no such button. The controls are spread across six different interfaces and must be maintained after each browser or OS update. The single thing that most often goes wrong is that people do one thing, delete their cookies, and assume they are done. They are not. The system is designed to make opting out tedious because every toggle you miss is data you keep giving away.
Common Questions
Can I see what data a data broker has on me?
Yes. Under the PDPA, you have the right of access to personal data held by any organisation, including data brokers. Submit a written request to the broker. They must respond within 30 calendar days. They may charge a reasonable fee but must give you an estimate first.
Does deleting cookies stop ad tracking?
It stops third-party cookies but not device fingerprinting, tracking pixels or mobile advertising IDs. Deleting cookies removes the specific tracker file, but the fingerprint of your device persists. You must combine cookie deletion with the platform-level controls listed above.
Is it legal for a Singapore website to track me without asking?
No. Under the PDPA, organisations must obtain consent before collecting personal data, and pre-checked boxes or implied consent through browsing do not count. Tracking via cookies, pixels or fingerprinting that collects personal data requires active, informed consent.
What happens if a data broker ignores my access request?
You can file a complaint with the Personal Data Protection Commission (PDPC). The PDPC will investigate. If the broker is found to have breached the access obligation, the PDPC can issue directions to comply and impose financial penalties up to 10 percent of annual turnover or S$1 million.