facebook-pixel

How to Report a Data Breach to PDPC Singapore: 2026 Guide

L
Lunyb Security Team
··9 min read

If your organisation has suffered a data breach in Singapore, you may be legally required to notify the Personal Data Protection Commission (PDPC) within 3 calendar days. Since the mandatory data breach notification regime took effect on 1 February 2021 under the amended Personal Data Protection Act (PDPA), the stakes for getting this process right have never been higher. This guide walks you through exactly how to report a data breach to PDPC Singapore, what qualifies as a notifiable breach, and how to minimise legal exposure.

What Is a Notifiable Data Breach Under Singapore's PDPA?

A notifiable data breach under Singapore's PDPA is any unauthorised access, collection, use, disclosure, copying, modification, or disposal of personal data that meets specific harm or scale thresholds set by the PDPC. Not every incident requires notification — only those that cross defined thresholds trigger the mandatory reporting obligation.

Under Section 26B of the PDPA, a data breach is notifiable if it:

  1. Results in, or is likely to result in, significant harm to affected individuals; or
  2. Affects 500 or more individuals, regardless of harm severity.

What Counts as "Significant Harm"?

The Personal Data Protection (Notification of Data Breaches) Regulations 2021 prescribe categories of personal data whose compromise is deemed to cause significant harm. These include:

  • Full name or alias combined with NRIC, FIN, passport, or work permit numbers
  • Financial account details (bank account, credit card numbers, CVV codes)
  • Health information, including medical diagnoses and treatment records
  • Life insurance policy details and claim information
  • Biometric data such as fingerprints, iris scans, or facial recognition data
  • Details of adoption orders, foster care, or child protection matters
  • Information about vulnerable individuals such as minors or persons with disabilities

Who Must Report a Data Breach to PDPC?

Any organisation subject to Singapore's PDPA — which includes virtually all private sector entities that collect, use, or disclose personal data in Singapore — must comply with the mandatory notification obligation. This applies whether you are a local SME, a multinational with a Singapore office, or a data intermediary processing data on behalf of another organisation.

Data Intermediaries Have Special Obligations

If you are a data intermediary (a third-party processor), you must notify the organisation that engaged you "without undue delay" once you become aware of a breach. The engaging organisation then becomes responsible for notifying the PDPC and affected individuals.

The 30-Day Assessment Window

Before the notification clock starts ticking, organisations have up to 30 calendar days to assess whether a suspected breach is actually notifiable. This assessment must be conducted "in a reasonable and expeditious manner" — you cannot use the full 30 days as a delay tactic.

During assessment, you should:

  1. Contain the breach and prevent further unauthorised access
  2. Identify the type and volume of personal data affected
  3. Estimate the number of individuals impacted
  4. Evaluate the likelihood and severity of harm
  5. Document your assessment methodology and conclusions

How to Report a Data Breach to PDPC: Step-by-Step

Once you determine a breach is notifiable, you must submit your report to the PDPC as soon as practicable, and in any case no later than 3 calendar days from the day you make that determination.

Step 1: Access the PDPC Data Breach Notification Form

Navigate to the official PDPC website at pdpc.gov.sg and locate the "Report a Data Breach" section. The PDPC provides an online submission portal, which is the preferred channel. You can also download the PDF version of the Data Breach Notification Form for reference before completing your submission.

Step 2: Gather Required Information

Before starting the submission, compile the following details:

  • Organisation name, UEN, and registered address
  • Contact details of your Data Protection Officer (DPO)
  • Date and time the breach occurred and was discovered
  • Description of what happened and how it was discovered
  • Types of personal data compromised (be specific)
  • Approximate number of affected individuals
  • Cause of the breach (cyberattack, human error, system flaw, etc.)
  • Containment measures already taken
  • Remediation plans and preventive actions
  • Whether affected individuals have been or will be notified

Step 3: Complete the Notification Form

Fill out each section accurately. The PDPC form is divided into segments covering the organisation's details, breach description, affected data and individuals, and mitigation actions. Be factual and avoid speculation — if certain details are unknown, indicate that clearly rather than guessing.

Step 4: Submit and Retain Acknowledgement

After submission, the PDPC will issue an acknowledgement reference number. Save this along with a copy of your full submission for your internal records. You may be contacted for follow-up information within days or weeks.

Step 5: Notify Affected Individuals

Unless an exception applies, you must also notify affected individuals on or after the day you notify the PDPC. Notifications must be clear, in an appropriate format (email, letter, SMS, or public notice), and include:

  • What happened and when
  • Types of personal data affected
  • Potential consequences
  • Actions taken by your organisation
  • Steps individuals can take to protect themselves
  • Contact information for further queries

PDPC Notification Timeline at a Glance

Stage Timeframe Action Required
Breach Discovery Day 0 Contain breach, activate incident response plan
Assessment Period Within 30 days Determine if breach is notifiable
PDPC Notification Within 3 calendar days of determination Submit Data Breach Notification Form
Individual Notification On or after PDPC notification Notify affected individuals (unless exempt)
Data Intermediary Reporting Without undue delay Notify engaging organisation

Exceptions to Individual Notification

You may be exempt from notifying affected individuals in specific circumstances:

  • Remedial action taken: If you have implemented technological measures (like strong encryption) that render the data inaccessible or unusable, individual notification may not be required.
  • Law enforcement instruction: If the police or another law enforcement agency instructs you to delay notification for investigation purposes.
  • PDPC waiver: You can apply to the PDPC in writing for a waiver, explaining why notification would not benefit affected individuals.

Even if you qualify for an exception on individual notification, you must still notify the PDPC.

Penalties for Non-Compliance

Failure to comply with the mandatory data breach notification obligation can result in significant financial penalties. Under the amended PDPA, the PDPC can impose fines of up to:

  • 10% of annual turnover in Singapore for organisations with local turnover exceeding S$10 million, or
  • S$1 million, whichever is higher

Beyond financial penalties, non-compliance can trigger regulatory directions, reputational damage, civil claims from affected individuals, and heightened scrutiny of future compliance.

Common Mistakes to Avoid

1. Delaying the Assessment

Some organisations wait too long to begin assessing a suspected breach, effectively burning through the 30-day window. Start the assessment immediately upon discovery.

2. Under-reporting the Scope

Reporting only the confirmed affected individuals when logs suggest a wider impact can be seen as bad faith. Be transparent about uncertainty and provide updates as new information emerges.

3. Poor Documentation

The PDPC expects organisations to maintain records of all data breach incidents, including those deemed non-notifiable. Documentation should include the assessment rationale, timeline, and remediation steps.

4. Neglecting Root Cause Analysis

Simply notifying the breach without addressing the underlying vulnerability invites repeat incidents. The PDPC often asks about long-term preventive measures.

5. Insecure Communication During Response

Sharing links to sensitive incident documentation via unsecured channels can worsen the breach. When distributing incident briefings, remediation instructions, or notification pages, use trusted tools with access controls. A link management platform like Lunyb lets you create trackable, password-protected short links so you can share sensitive resources with legal teams, regulators, or customers while maintaining a clear audit trail.

Building a Data Breach Response Plan

The best time to prepare a breach response plan is before you need it. A robust plan should include:

Incident Response Team

Designate roles including a DPO, IT security lead, legal counsel, communications lead, and executive sponsor. Ensure 24/7 contact information is maintained.

Detection and Containment Procedures

Deploy monitoring tools that flag anomalies quickly. Predefine containment playbooks for common breach types (ransomware, phishing compromise, misconfigured storage, insider threats).

Communication Templates

Draft template notifications for the PDPC, affected individuals, and internal stakeholders in advance. This shortens response time when every hour counts.

Regular Testing

Conduct tabletop exercises at least annually to test your plan against realistic scenarios. Update procedures based on lessons learned.

Vendor and Data Intermediary Management

Ensure contracts with data processors include clear breach notification obligations with defined timeframes. Regularly audit vendor security practices.

How Lunyb Can Support Your Breach Communications

During and after a data breach, secure communication with regulators, affected customers, and internal teams becomes critical. Lunyb provides a privacy-focused link management platform that helps organisations share sensitive breach-related resources through short, branded URLs with click analytics, expiry dates, and password protection. This is particularly useful when directing thousands of affected individuals to a dedicated incident information page or when coordinating internal response teams. For a broader look at URL shortening solutions, see our 2026 buyer's guide.

Frequently Asked Questions

How quickly must I report a data breach to PDPC?

You must notify the PDPC as soon as practicable, and no later than 3 calendar days after determining that a data breach is notifiable. You have up to 30 days to conduct the initial assessment, but this window must be used reasonably — not as a delay tactic.

What if I'm unsure whether a breach is notifiable?

Conduct a documented assessment considering the type of data, number of affected individuals, and potential harm. If the breach affects 500 or more individuals or involves prescribed categories of sensitive data, it is notifiable. When in doubt, consult legal counsel or reach out to the PDPC's helpline for guidance. Over-reporting is generally safer than under-reporting.

Do I need to notify affected individuals if I already notified PDPC?

Yes, in most cases. Individual notification is a separate obligation from PDPC notification. Exceptions apply when you have taken remedial measures (like effective encryption), when law enforcement instructs delay, or when the PDPC grants a waiver upon written request.

What happens after I submit the notification?

The PDPC reviews your submission and may request additional information, conduct an investigation, or issue directions requiring specific remediation. Depending on findings, the PDPC can impose financial penalties, issue warnings, or require public undertakings. Cooperation and transparency significantly influence outcomes.

Can small businesses be fined the full S$1 million penalty?

Yes, the PDPA's penalty framework applies to all organisations regardless of size, though the PDPC considers factors like turnover, culpability, cooperation, and remediation when determining actual penalties. Small businesses that respond promptly, cooperate fully, and demonstrate genuine remediation efforts typically face lower penalties than those that conceal or delay reporting.

Final Thoughts

Reporting a data breach to the PDPC is not just a legal box to tick — it is a fundamental part of maintaining trust with customers, employees, and business partners. Singapore's mandatory notification regime rewards organisations that prepare thoroughly, respond swiftly, and communicate transparently. By understanding the notification thresholds, respecting the 3-day reporting deadline, and building a robust incident response plan, your organisation can navigate even serious breaches with regulatory compliance and reputational integrity intact.

If you handle personal data in Singapore, treat breach preparedness as an ongoing programme, not a one-time project. Review your policies annually, train staff regularly, and ensure your technical safeguards keep pace with evolving threats.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles