How to Report a Data Breach to PDPC Singapore: A Complete 2026 Guide
If your organisation has suffered a data breach in Singapore, notifying the Personal Data Protection Commission (PDPC) is not optional — it's a legal obligation under the Personal Data Protection Act (PDPA). Since the Mandatory Data Breach Notification obligation came into force on 1 February 2021, businesses must act quickly and follow a defined process to avoid penalties that can reach up to S$1 million or 10% of annual turnover in Singapore.
This guide walks you through exactly how to report a data breach to PDPC, when notification is required, what information to include, and how to protect your organisation before, during, and after an incident.
What Counts as a Data Breach Under the PDPA?
Under Section 26A of the PDPA, a data breach is defined as the unauthorised access, collection, use, disclosure, copying, modification, disposal of personal data, or the loss of any storage medium containing personal data. In simple terms, if personal data has been compromised or exposed to someone who shouldn't have access, it counts as a breach.
Common examples include:
- Ransomware or malware attacks on customer databases
- Lost or stolen laptops, USB drives, or mobile devices containing personal data
- Emails with personal information sent to the wrong recipient
- Employees accessing customer records without authorisation
- Misconfigured cloud storage exposing files publicly
- Phishing attacks that compromise staff email accounts
Notifiable vs Non-Notifiable Breaches
Not every breach must be reported. Under the PDPA, a data breach is notifiable if it:
- Results in, or is likely to result in, significant harm to affected individuals; OR
- Is of a significant scale — affecting 500 or more individuals.
"Significant harm" typically applies when the breach involves sensitive categories such as NRIC numbers, financial account details, medical records, insurance information, or login credentials.
PDPC Data Breach Notification Timelines
Time is critical. The PDPA sets out strict deadlines that every organisation must follow once a breach is discovered:
| Action | Deadline | Details |
|---|---|---|
| Assess the breach | Within 30 calendar days | Determine if the breach is notifiable |
| Notify PDPC | Within 72 hours of assessing as notifiable | Submit online via PDPC's Data Breach Notification form |
| Notify affected individuals | As soon as practicable | Only required if breach is likely to cause significant harm |
| Data intermediary to notify organisation | Without undue delay | Data processors must alert the data controller upon discovery |
Missing these deadlines is one of the most common reasons organisations face enforcement action from PDPC.
Step-by-Step: How to Report a Data Breach to PDPC
Here is the exact process your organisation should follow when a breach occurs:
Step 1: Contain the Breach Immediately
Before doing anything else, stop the bleeding. Disconnect compromised systems, revoke exposed credentials, isolate infected devices, and preserve evidence for forensic analysis. Do not shut down systems in a way that destroys logs — they'll be essential later.
Step 2: Assess the Scope and Impact
Within 30 days, your Data Protection Officer (DPO) or incident response team must determine:
- What personal data was involved (names, NRIC, financial data, etc.)
- How many individuals are affected
- The cause of the breach (cyberattack, human error, insider threat)
- Whether the breach meets the "significant harm" or "500+ individuals" threshold
- Whether the data was encrypted or otherwise unreadable
If encrypted data was stolen but the encryption keys remain secure, the breach may not be notifiable — but you still need to document your assessment.
Step 3: Notify PDPC Within 72 Hours
Once you conclude the breach is notifiable, you have 72 hours to submit a notification to PDPC. This is done through the official Data Breach Notification form on the PDPC website (www.pdpc.gov.sg).
The form requires:
- Organisation name, UEN, and contact details of the DPO
- Date and time of the breach and its discovery
- Description of the incident and its cause
- Types of personal data compromised
- Number of individuals affected
- Potential harm to affected individuals
- Steps taken to contain and remediate the breach
- Plans for notifying affected individuals
If you don't have complete information within 72 hours, submit what you know and update PDPC as further details emerge. Delaying notification while gathering "perfect" information is a common mistake.
Step 4: Notify Affected Individuals
If the breach is likely to cause significant harm, you must inform the affected individuals as soon as practicable. Your notification should include:
- What happened and when
- What personal data was involved
- Potential consequences for the individual
- Steps the organisation has taken
- Actions individuals should take (e.g., change passwords, monitor accounts)
- Contact details for follow-up questions
PDPC may waive this requirement in specific cases — for example, if notification would compromise an ongoing investigation, or if the organisation has taken remedial action that makes harm unlikely.
Step 5: Document and Remediate
Maintain thorough records of the breach, your assessment, the notification, and remediation steps. PDPC can request this documentation for up to several years. Then implement long-term fixes: patch vulnerabilities, retrain staff, update policies, and strengthen technical controls.
What Information PDPC Expects in Your Notification
To streamline your submission, prepare the following before opening the online form:
| Category | Details to Provide |
|---|---|
| Organisation Info | Legal name, UEN, industry, DPO name and contact |
| Incident Timeline | Date of breach, date of discovery, date of assessment |
| Nature of Breach | Cyberattack, human error, physical loss, insider misuse |
| Data Compromised | Categories (NRIC, financial, health, contact), volume, sensitivity |
| Affected Individuals | Approximate number, demographics, whether they're customers or employees |
| Containment | Immediate actions taken, systems isolated, credentials revoked |
| Remediation | Long-term fixes, policy changes, training plans |
| Individual Notification | Whether individuals will be notified, method, timing |
Penalties for Non-Compliance
Failure to report a notifiable breach — or reporting it late — can result in significant financial and reputational damage. Under amendments to the PDPA that took effect in 2022:
- Organisations with annual turnover exceeding S$10 million can be fined up to 10% of their annual turnover in Singapore
- Smaller organisations can be fined up to S$1 million
- PDPC also publishes enforcement decisions publicly, which can damage brand trust
Recent enforcement cases have shown PDPC willing to impose six-figure fines even on well-known local brands for breaches that involved inadequate security controls or delayed notifications.
Best Practices to Prepare Before a Breach Happens
The best time to prepare for a data breach is before one occurs. Here are the essentials every Singapore organisation should have in place:
1. Appoint a Data Protection Officer (DPO)
The PDPA requires every organisation to appoint at least one DPO whose business contact information is publicly available. The DPO leads your breach response and liaises with PDPC.
2. Build a Data Breach Response Plan
Document clear roles, escalation paths, communication templates, and decision criteria. Run tabletop exercises at least annually to test the plan.
3. Maintain a Personal Data Inventory
You cannot assess a breach quickly if you don't know what data you hold, where it's stored, and who has access. Keep this inventory updated.
4. Strengthen Technical Controls
Implement encryption at rest and in transit, multi-factor authentication, least-privilege access, endpoint detection, and regular patching. Encrypted data that is stolen but unreadable often falls outside notification requirements.
5. Vet Your Data Intermediaries
If you use third-party vendors to process personal data (cloud providers, marketing tools, URL shorteners, analytics platforms), ensure they are PDPA-compliant. When choosing tools that handle links and user click data, opt for privacy-respecting platforms like Lunyb, which is reviewed in our honest Lunyb review, or evaluate alternatives in our 2026 URL shortener buyer's guide.
6. Train Your Staff
Human error is the leading cause of data breaches. Regular training on phishing, secure email handling, and physical device security dramatically reduces risk.
Common Mistakes Organisations Make When Reporting
Even well-intentioned organisations trip up during breach reporting. Watch for these pitfalls:
- Waiting for complete information before notifying. The 72-hour clock does not pause. Submit what you know and update later.
- Under-assessing severity. Downplaying breach impact to avoid notification often backfires when PDPC investigates.
- Poor internal communication. If IT discovers a breach but doesn't escalate to the DPO for days, you've already burned your assessment window.
- Forgetting to notify individuals. Notifying PDPC is not a substitute for notifying affected people when significant harm is likely.
- Inadequate documentation. Without records of your investigation and decisions, you cannot defend your actions if PDPC asks questions later.
What Happens After You Notify PDPC?
Once PDPC receives your notification, they will typically:
- Acknowledge receipt and assign a case officer
- Request additional information or documentation
- Assess whether your organisation complied with the PDPA
- Determine whether enforcement action is warranted
- Publish an enforcement decision if a breach of the Act is found
Cooperation, transparency, and demonstrating that you had reasonable security measures in place (even if imperfect) heavily influence PDPC's response. Organisations that self-report promptly and remediate thoroughly often receive lighter penalties — or none at all.
Frequently Asked Questions
Do I need to report every data breach to PDPC?
No. Only breaches that are likely to cause significant harm to affected individuals, or that affect 500 or more individuals, must be reported. However, you should document your assessment for every incident, even non-notifiable ones.
What if the breach happened at my vendor, not my organisation?
If you are the data controller and the vendor is a data intermediary (data processor), you remain responsible for notifying PDPC. Your contract with the vendor should require them to notify you of any breach without undue delay.
Can I be fined even if I report the breach on time?
Yes. Notification is separate from liability. If PDPC finds that your organisation failed to protect personal data with reasonable security arrangements, you can still be penalised — but timely notification and cooperation typically reduce the penalty.
Is encrypted data still considered a breach if stolen?
Generally, if personal data was strongly encrypted and the encryption keys were not compromised, the breach may not meet the "significant harm" threshold. However, you must still assess and document the incident, and notify if there is any residual risk.
How long should I keep breach records?
While the PDPA does not specify a fixed retention period for breach records, it's best practice to retain them for at least 5 years. PDPC may request evidence of your assessment, notification, and remediation during investigations or audits.
Final Thoughts
Reporting a data breach to PDPC is a structured, time-sensitive process — but it doesn't have to be overwhelming if you've prepared in advance. The keys are speed, transparency, thorough documentation, and demonstrating that you took reasonable steps to protect personal data before the incident occurred.
Treat PDPC not as an adversary but as a regulator that rewards good-faith compliance. Organisations that respond quickly, cooperate fully, and learn from breaches consistently fare better than those that try to hide or delay. Build your response plan today, so that if the worst happens, you're ready to act with confidence.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Create a Link in Bio Page in 2026: Complete Step-by-Step Guide
A link in bio page turns social media's single-link limit into a powerful conversion hub. This step-by-step 2026 guide covers tools, design tips, analytics, and promotion tactics to help you build a bio page that actually drives results.
How to Track Link Clicks: A Complete Guide for 2026
Learn how to track link clicks using URL shorteners, UTM parameters, pixels, and email analytics. This 2026 guide compares every method with step-by-step instructions, pros and cons, and privacy tips to help you choose the right approach.
How to Remove Your Personal Information from Data Brokers: Complete 2026 Guide
Data brokers collect and sell your personal information without your consent — but you have the right to opt out. This step-by-step 2026 guide shows you exactly how to remove your data from people-search sites and stay off their radar for good.
How to Set Up Link Retargeting: A Complete Step-by-Step Guide
Link retargeting lets you pixel visitors who click your shortened URLs — even on third-party content. This step-by-step guide shows you how to set it up in under an hour, choose the right platform, and launch your first campaign.