facebook-pixel

How to Report a Data Breach to PDPC Singapore: A Complete 2026 Guide

L
Lunyb Security Team
··10 min read

Data breaches are no longer a rare occurrence in Singapore's digital-first economy. Under the Personal Data Protection Act (PDPA), organisations that suffer a notifiable data breach must report it to the Personal Data Protection Commission (PDPC) — and failure to do so can result in significant financial penalties and reputational damage. This comprehensive guide walks you through exactly how to report a data breach to PDPC Singapore, when notification is mandatory, and how to prepare your organisation to respond effectively.

What Is a Data Breach Under Singapore's PDPA?

A data breach under Singapore's PDPA is any unauthorised access, collection, use, disclosure, copying, modification, or disposal of personal data, or any loss of storage media on which personal data is stored. The Personal Data Protection (Amendment) Act 2020, which came into force on 1 February 2021, introduced a mandatory data breach notification regime that fundamentally changed how organisations must handle security incidents.

Personal data includes any information that can identify an individual, whether on its own or combined with other information the organisation has or is likely to have access to. This encompasses names, NRIC numbers, contact details, financial records, health data, biometric identifiers, and much more.

Common Examples of Data Breaches

  • Ransomware or malware attacks that compromise customer databases
  • Phishing incidents leading to unauthorised account access
  • Lost or stolen laptops, USB drives, or paper records containing personal data
  • Accidental emails sent to the wrong recipient with sensitive attachments
  • Misconfigured cloud storage exposing files to the public internet
  • Insider threats where employees exfiltrate or misuse personal data

When Must You Report a Data Breach to PDPC?

Not every data breach requires notification. Under Section 26D of the PDPA, a breach is notifiable if it meets either of these two thresholds:

  1. Significant harm threshold: The breach results in, or is likely to result in, significant harm to affected individuals.
  2. Significant scale threshold: The breach is of a significant scale, meaning it affects 500 or more individuals.

What Counts as "Significant Harm"?

The Personal Data Protection (Notification of Data Breaches) Regulations 2021 prescribe specific categories of personal data that are deemed to result in significant harm if compromised. These include:

  • Full name or alias combined with NRIC, FIN, passport, birth certificate, or work permit numbers
  • Financial information such as credit card numbers, bank account details, or income records
  • Health information including medical records, diagnoses, and treatment history
  • Life insurance and accident insurance policy details
  • Adoption records and other sensitive relational data
  • Information about vulnerabilities of individuals (e.g., domestic abuse, mental health)

Mandatory Timelines for Reporting a Data Breach

The PDPA sets strict, non-negotiable timelines once an organisation determines that a breach is notifiable. Understanding these deadlines is critical because they begin ticking from the moment you have credible grounds to believe a breach has occurred.

Assessment Period: 30 Calendar Days

From the moment your organisation becomes aware of a suspected breach, you have up to 30 calendar days to conduct a reasonable and expeditious assessment to determine whether it is notifiable. This assessment period does not extend the notification deadline once you conclude the breach is notifiable.

Notification to PDPC: 3 Calendar Days

Once you have assessed that a breach is notifiable, you must notify the PDPC as soon as practicable, but no later than 3 calendar days. This is one of the strictest timelines in the Asia-Pacific region for breach notification.

Notification to Affected Individuals

You must notify affected individuals on or after notifying the PDPC, unless a prescribed exception applies. Notification to individuals must be done in a manner that is reasonable in the circumstances — typically by email, letter, phone, or public notice where individual contact is impractical.

Step-by-Step: How to Report a Data Breach to PDPC

Follow this structured process to ensure your organisation meets its legal obligations and minimises regulatory exposure.

Step 1: Contain the Breach Immediately

Before any reporting, take immediate action to stop the ongoing exposure. This may include disconnecting affected systems, revoking compromised credentials, patching vulnerabilities, and preserving forensic evidence. Document every action taken with timestamps.

Step 2: Activate Your Data Breach Response Plan

Convene your Data Breach Management Team (DBMT), which typically includes your Data Protection Officer (DPO), IT security lead, legal counsel, communications lead, and senior management. If you don't have a formal plan, this is your priority action.

Step 3: Conduct the Notifiability Assessment

Within 30 days, determine whether the breach meets either the significant harm or 500-individual threshold. Document your reasoning even if you conclude the breach is not notifiable — the PDPC may request this record.

Step 4: Prepare Your Notification Submission

Gather the required information before submitting the online form. You'll need:

  • Facts and cause of the breach
  • Number of affected individuals
  • Types of personal data compromised
  • Potential harm to affected individuals
  • Measures taken or planned to contain the breach and mitigate harm
  • Contact details of your DPO

Step 5: Submit the Notification via PDPC's Online Portal

Notifications are submitted through the PDPC's official website at pdpc.gov.sg using the Data Breach Notification Form. Log in via Corppass to file the report. If you don't have all the information at the 3-day mark, submit what you have and update the PDPC as more details emerge.

Step 6: Notify Affected Individuals

Provide clear, plain-language notifications that include the nature of the breach, types of data involved, potential consequences, steps individuals can take to protect themselves, and your organisation's remediation actions and contact information.

Step 7: Document and Learn

Maintain a comprehensive breach register. After resolution, conduct a post-incident review to identify root causes and implement systemic improvements.

Notification Requirements at a Glance

Requirement Timeline Recipient Method
Breach assessment Within 30 calendar days of becoming aware Internal Documented internal review
Notify PDPC Within 3 calendar days of assessment Personal Data Protection Commission Online form via pdpc.gov.sg
Notify affected individuals On or after notifying PDPC Affected data subjects Email, letter, phone, or public notice
Data intermediary duty Without undue delay The data controller As agreed in contract

Exceptions to Individual Notification

You may be exempted from notifying affected individuals in the following circumstances:

  • Remedial actions taken: If your organisation has taken action to render the breach unlikely to result in significant harm (e.g., strong encryption of the stolen data with keys still secure).
  • Technological protection: If the personal data was protected by technological measures rendering it inaccessible or unintelligible.
  • PDPC waiver: The PDPC may direct or agree that notification is not required.
  • Law enforcement: Where notification would compromise an ongoing investigation.

Even when exempt from individual notification, the PDPC notification obligation still applies if thresholds are met.

Penalties for Non-Compliance

The stakes for failing to report or delaying notification are substantial. Under the amended PDPA, financial penalties for breaches include:

  • Up to 10% of an organisation's annual turnover in Singapore for entities with turnover exceeding SGD 10 million, or
  • Up to SGD 1 million, whichever is higher

Beyond financial penalties, organisations face reputational damage, potential civil claims from affected individuals under Section 48O (private right of action), and increased regulatory scrutiny.

Best Practices for Data Breach Preparedness

Meeting PDPC's tight timelines is nearly impossible without preparation. The organisations that respond well are those that treat breach readiness as a continuous operational discipline.

1. Appoint and Empower a Data Protection Officer

Every organisation processing personal data in Singapore must appoint a DPO. Make sure your DPO has authority, budget, and direct access to senior leadership. Publish their contact details as required by law.

2. Maintain a Data Inventory

You cannot protect — or accurately report on — data you don't know you have. Maintain a live inventory of what personal data you collect, where it's stored, who has access, and how long it's retained.

3. Implement Strong Technical Safeguards

Encryption at rest and in transit, multi-factor authentication, endpoint detection, secure DNS, and regular vulnerability scans dramatically reduce breach likelihood. Where you share links or files that could expose customer identifiers, consider using privacy-focused tools like Lunyb, which lets you shorten and manage URLs without leaking metadata through unsafe redirects — a small but often-overlooked component of a strong data hygiene posture.

4. Train Your Staff Regularly

The vast majority of breaches involve a human element. Conduct quarterly training on phishing recognition, secure handling of personal data, and internal breach reporting procedures.

5. Run Tabletop Exercises

Simulate breach scenarios at least annually. Test whether your team can realistically hit the 3-day PDPC notification window under pressure. Refine your playbook after each exercise.

6. Vet Your Data Intermediaries

Vendors and processors are frequent breach vectors. Contractually require them to notify you of breaches without undue delay, and audit their security posture regularly.

Data Intermediary Obligations

Data intermediaries — organisations that process personal data on behalf of another under contract — have a distinct legal duty. Under Section 26C of the PDPA, a data intermediary must notify the organisation on whose behalf it is processing the data without undue delay upon becoming aware of a breach. The primary organisation then bears responsibility for the PDPC notification.

If you're a data intermediary, your contract should clearly specify notification timelines (typically 24–48 hours), the information you must provide, and the assistance you'll render during the investigation.

What to Include in Your Individual Notification

When notifying affected individuals, use plain language and include:

  1. A clear description of what happened and when
  2. The specific types of personal data involved
  3. Likely consequences of the breach
  4. Steps the individual should take (e.g., change passwords, monitor bank statements, request a credit freeze)
  5. Steps your organisation has taken and will take
  6. Contact details for further questions
  7. Whether identity monitoring or other remediation services are being offered

Common Mistakes Organisations Make

  • Waiting until they have "all the facts" — the PDPC expects preliminary notification within 3 days even if details are still emerging.
  • Under-scoping the breach — organisations often underestimate the number of affected individuals in early stages.
  • Poor documentation — failing to log assessment reasoning leaves organisations vulnerable during PDPC investigations.
  • Notifying individuals before PDPC — the sequence matters legally and operationally.
  • Overlooking data intermediaries — a vendor breach is your breach for notification purposes.

Related Reading

Frequently Asked Questions

How long do I have to report a data breach to PDPC Singapore?

You must notify the PDPC as soon as practicable and no later than 3 calendar days after you have assessed that the breach is notifiable. The assessment itself must be conducted expeditiously and typically within 30 calendar days of becoming aware of the incident.

What is the threshold for a notifiable data breach under the PDPA?

A breach is notifiable if it either results in, or is likely to result in, significant harm to affected individuals (based on prescribed data categories like NRIC, financial, or health data), or affects 500 or more individuals in Singapore.

Do I need to notify affected individuals for every breach?

No. Individual notification is required only for notifiable breaches, and even then, exceptions apply — for example, if the compromised data was strongly encrypted, if remedial action has rendered harm unlikely, or if the PDPC waives the requirement due to law enforcement considerations.

What are the penalties for failing to report a data breach?

Financial penalties can reach up to 10% of an organisation's annual turnover in Singapore (for organisations with turnover above SGD 10 million) or SGD 1 million, whichever is higher. Organisations may also face civil claims from affected individuals and reputational consequences.

How do I submit a breach notification to PDPC?

Notifications are submitted online via the PDPC website (pdpc.gov.sg) using the official Data Breach Notification Form, accessed through Corppass. Provide as much detail as available and follow up with the PDPC if additional information becomes available after initial submission.

Final Thoughts

Singapore's mandatory data breach notification regime is one of the strictest in the region, and the PDPC has demonstrated willingness to enforce it aggressively. The organisations that navigate a breach successfully are not necessarily those with the best technology — they're the ones that prepared before the incident occurred. Build your response plan, train your people, appoint your DPO, and document everything. When a breach happens — and statistically, it will — you'll be ready to protect your customers, your reputation, and your regulatory standing.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles