facebook-pixel

How to Report a Data Breach to PDPC Singapore: A Complete 2026 Guide

L
Lunyb Security Team
··9 min read

If your organisation has suffered a data breach in Singapore, notifying the Personal Data Protection Commission (PDPC) is not optional — it's a legal obligation under the Personal Data Protection Act (PDPA). Since the Mandatory Data Breach Notification obligation came into force on 1 February 2021, businesses must act quickly and follow a defined process to avoid penalties that can reach up to S$1 million or 10% of annual turnover in Singapore.

This guide walks you through exactly how to report a data breach to PDPC, when notification is required, what information to include, and how to protect your organisation before, during, and after an incident.

What Counts as a Data Breach Under the PDPA?

Under Section 26A of the PDPA, a data breach is defined as the unauthorised access, collection, use, disclosure, copying, modification, disposal of personal data, or the loss of any storage medium containing personal data. In simple terms, if personal data has been compromised or exposed to someone who shouldn't have access, it counts as a breach.

Common examples include:

  • Ransomware or malware attacks on customer databases
  • Lost or stolen laptops, USB drives, or mobile devices containing personal data
  • Emails with personal information sent to the wrong recipient
  • Employees accessing customer records without authorisation
  • Misconfigured cloud storage exposing files publicly
  • Phishing attacks that compromise staff email accounts

Notifiable vs Non-Notifiable Breaches

Not every breach must be reported. Under the PDPA, a data breach is notifiable if it:

  1. Results in, or is likely to result in, significant harm to affected individuals; OR
  2. Is of a significant scale — affecting 500 or more individuals.

"Significant harm" typically applies when the breach involves sensitive categories such as NRIC numbers, financial account details, medical records, insurance information, or login credentials.

PDPC Data Breach Notification Timelines

Time is critical. The PDPA sets out strict deadlines that every organisation must follow once a breach is discovered:

ActionDeadlineDetails
Assess the breachWithin 30 calendar daysDetermine if the breach is notifiable
Notify PDPCWithin 72 hours of assessing as notifiableSubmit online via PDPC's Data Breach Notification form
Notify affected individualsAs soon as practicableOnly required if breach is likely to cause significant harm
Data intermediary to notify organisationWithout undue delayData processors must alert the data controller upon discovery

Missing these deadlines is one of the most common reasons organisations face enforcement action from PDPC.

Step-by-Step: How to Report a Data Breach to PDPC

Here is the exact process your organisation should follow when a breach occurs:

Step 1: Contain the Breach Immediately

Before doing anything else, stop the bleeding. Disconnect compromised systems, revoke exposed credentials, isolate infected devices, and preserve evidence for forensic analysis. Do not shut down systems in a way that destroys logs — they'll be essential later.

Step 2: Assess the Scope and Impact

Within 30 days, your Data Protection Officer (DPO) or incident response team must determine:

  1. What personal data was involved (names, NRIC, financial data, etc.)
  2. How many individuals are affected
  3. The cause of the breach (cyberattack, human error, insider threat)
  4. Whether the breach meets the "significant harm" or "500+ individuals" threshold
  5. Whether the data was encrypted or otherwise unreadable

If encrypted data was stolen but the encryption keys remain secure, the breach may not be notifiable — but you still need to document your assessment.

Step 3: Notify PDPC Within 72 Hours

Once you conclude the breach is notifiable, you have 72 hours to submit a notification to PDPC. This is done through the official Data Breach Notification form on the PDPC website (www.pdpc.gov.sg).

The form requires:

  • Organisation name, UEN, and contact details of the DPO
  • Date and time of the breach and its discovery
  • Description of the incident and its cause
  • Types of personal data compromised
  • Number of individuals affected
  • Potential harm to affected individuals
  • Steps taken to contain and remediate the breach
  • Plans for notifying affected individuals

If you don't have complete information within 72 hours, submit what you know and update PDPC as further details emerge. Delaying notification while gathering "perfect" information is a common mistake.

Step 4: Notify Affected Individuals

If the breach is likely to cause significant harm, you must inform the affected individuals as soon as practicable. Your notification should include:

  • What happened and when
  • What personal data was involved
  • Potential consequences for the individual
  • Steps the organisation has taken
  • Actions individuals should take (e.g., change passwords, monitor accounts)
  • Contact details for follow-up questions

PDPC may waive this requirement in specific cases — for example, if notification would compromise an ongoing investigation, or if the organisation has taken remedial action that makes harm unlikely.

Step 5: Document and Remediate

Maintain thorough records of the breach, your assessment, the notification, and remediation steps. PDPC can request this documentation for up to several years. Then implement long-term fixes: patch vulnerabilities, retrain staff, update policies, and strengthen technical controls.

What Information PDPC Expects in Your Notification

To streamline your submission, prepare the following before opening the online form:

CategoryDetails to Provide
Organisation InfoLegal name, UEN, industry, DPO name and contact
Incident TimelineDate of breach, date of discovery, date of assessment
Nature of BreachCyberattack, human error, physical loss, insider misuse
Data CompromisedCategories (NRIC, financial, health, contact), volume, sensitivity
Affected IndividualsApproximate number, demographics, whether they're customers or employees
ContainmentImmediate actions taken, systems isolated, credentials revoked
RemediationLong-term fixes, policy changes, training plans
Individual NotificationWhether individuals will be notified, method, timing

Penalties for Non-Compliance

Failure to report a notifiable breach — or reporting it late — can result in significant financial and reputational damage. Under amendments to the PDPA that took effect in 2022:

  • Organisations with annual turnover exceeding S$10 million can be fined up to 10% of their annual turnover in Singapore
  • Smaller organisations can be fined up to S$1 million
  • PDPC also publishes enforcement decisions publicly, which can damage brand trust

Recent enforcement cases have shown PDPC willing to impose six-figure fines even on well-known local brands for breaches that involved inadequate security controls or delayed notifications.

Best Practices to Prepare Before a Breach Happens

The best time to prepare for a data breach is before one occurs. Here are the essentials every Singapore organisation should have in place:

1. Appoint a Data Protection Officer (DPO)

The PDPA requires every organisation to appoint at least one DPO whose business contact information is publicly available. The DPO leads your breach response and liaises with PDPC.

2. Build a Data Breach Response Plan

Document clear roles, escalation paths, communication templates, and decision criteria. Run tabletop exercises at least annually to test the plan.

3. Maintain a Personal Data Inventory

You cannot assess a breach quickly if you don't know what data you hold, where it's stored, and who has access. Keep this inventory updated.

4. Strengthen Technical Controls

Implement encryption at rest and in transit, multi-factor authentication, least-privilege access, endpoint detection, and regular patching. Encrypted data that is stolen but unreadable often falls outside notification requirements.

5. Vet Your Data Intermediaries

If you use third-party vendors to process personal data (cloud providers, marketing tools, URL shorteners, analytics platforms), ensure they are PDPA-compliant. When choosing tools that handle links and user click data, opt for privacy-respecting platforms like Lunyb, which is reviewed in our honest Lunyb review, or evaluate alternatives in our 2026 URL shortener buyer's guide.

6. Train Your Staff

Human error is the leading cause of data breaches. Regular training on phishing, secure email handling, and physical device security dramatically reduces risk.

Common Mistakes Organisations Make When Reporting

Even well-intentioned organisations trip up during breach reporting. Watch for these pitfalls:

  1. Waiting for complete information before notifying. The 72-hour clock does not pause. Submit what you know and update later.
  2. Under-assessing severity. Downplaying breach impact to avoid notification often backfires when PDPC investigates.
  3. Poor internal communication. If IT discovers a breach but doesn't escalate to the DPO for days, you've already burned your assessment window.
  4. Forgetting to notify individuals. Notifying PDPC is not a substitute for notifying affected people when significant harm is likely.
  5. Inadequate documentation. Without records of your investigation and decisions, you cannot defend your actions if PDPC asks questions later.

What Happens After You Notify PDPC?

Once PDPC receives your notification, they will typically:

  • Acknowledge receipt and assign a case officer
  • Request additional information or documentation
  • Assess whether your organisation complied with the PDPA
  • Determine whether enforcement action is warranted
  • Publish an enforcement decision if a breach of the Act is found

Cooperation, transparency, and demonstrating that you had reasonable security measures in place (even if imperfect) heavily influence PDPC's response. Organisations that self-report promptly and remediate thoroughly often receive lighter penalties — or none at all.

Frequently Asked Questions

Do I need to report every data breach to PDPC?

No. Only breaches that are likely to cause significant harm to affected individuals, or that affect 500 or more individuals, must be reported. However, you should document your assessment for every incident, even non-notifiable ones.

What if the breach happened at my vendor, not my organisation?

If you are the data controller and the vendor is a data intermediary (data processor), you remain responsible for notifying PDPC. Your contract with the vendor should require them to notify you of any breach without undue delay.

Can I be fined even if I report the breach on time?

Yes. Notification is separate from liability. If PDPC finds that your organisation failed to protect personal data with reasonable security arrangements, you can still be penalised — but timely notification and cooperation typically reduce the penalty.

Is encrypted data still considered a breach if stolen?

Generally, if personal data was strongly encrypted and the encryption keys were not compromised, the breach may not meet the "significant harm" threshold. However, you must still assess and document the incident, and notify if there is any residual risk.

How long should I keep breach records?

While the PDPA does not specify a fixed retention period for breach records, it's best practice to retain them for at least 5 years. PDPC may request evidence of your assessment, notification, and remediation during investigations or audits.

Final Thoughts

Reporting a data breach to PDPC is a structured, time-sensitive process — but it doesn't have to be overwhelming if you've prepared in advance. The keys are speed, transparency, thorough documentation, and demonstrating that you took reasonable steps to protect personal data before the incident occurred.

Treat PDPC not as an adversary but as a regulator that rewards good-faith compliance. Organisations that respond quickly, cooperate fully, and learn from breaches consistently fare better than those that try to hide or delay. Build your response plan today, so that if the worst happens, you're ready to act with confidence.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles