facebook-pixel

How to Report a Data Breach to PDPC Singapore: Complete 2026 Guide

L
Lunyb Security Team
··9 min read

If your organisation has suffered a data breach in Singapore, you may be legally required to notify the Personal Data Protection Commission (PDPC) within 72 hours. Since the Personal Data Protection Act (PDPA) amendments came into force in February 2021, mandatory data breach notification is no longer optional—it is a statutory obligation with serious financial and reputational consequences for non-compliance.

This comprehensive guide walks you through exactly how to report a data breach to PDPC Singapore, when notification is required, what information you need to submit, and how to manage the aftermath of a breach professionally.

What Is a Data Breach Under Singapore's PDPA?

A data breach under the PDPA refers to any unauthorised access, collection, use, disclosure, copying, modification, or disposal of personal data in the possession or control of an organisation. It also includes the loss of storage media or devices where personal data is stored.

Common examples of data breaches include:

  • Cyberattacks such as ransomware, phishing, or hacking incidents
  • Lost or stolen laptops, USB drives, or mobile devices containing personal data
  • Accidental email disclosures sending personal data to the wrong recipient
  • Unauthorised employee access to customer records
  • Misconfigured cloud storage exposing personal data publicly
  • Physical document theft or improper disposal

When Must You Report a Data Breach to PDPC?

Under Section 26D of the PDPA, an organisation must notify the PDPC of a notifiable data breach as soon as practicable, and in any case, no later than 3 calendar days (72 hours) after determining that the breach is notifiable.

A data breach is considered notifiable if it meets either of these thresholds:

1. Significant Harm Threshold

The breach results in, or is likely to result in, significant harm to affected individuals. The PDPA specifies certain categories of personal data that are deemed likely to cause significant harm if compromised, including:

  • Full name or alias combined with NRIC, FIN, passport, or work permit numbers
  • Financial information such as bank account details or credit card numbers
  • Health information and medical records
  • Life insurance and accident policy details
  • Personal data of vulnerable individuals (minors, seniors)
  • Login credentials that could enable account takeover

2. Significant Scale Threshold

The breach affects, or is likely to affect, 500 or more individuals. Even if the data type is relatively low-risk, the sheer volume triggers the notification obligation.

Step-by-Step: How to Report a Data Breach to PDPC

Follow this structured process to ensure timely and complete notification:

  1. Contain the breach immediately. Isolate affected systems, revoke compromised credentials, and stop ongoing data exfiltration before doing anything else.
  2. Assess whether the breach is notifiable. You have up to 30 days from initial awareness to assess, but you must act expeditiously. Determine if it meets the significant harm or significant scale threshold.
  3. Prepare your notification. Gather all required information (see next section) and document your incident response actions.
  4. Submit online via the PDPC website. Go to pdpc.gov.sg and access the Data Breach Notification form under the "Report a Data Breach" section.
  5. Notify affected individuals. If the breach is likely to cause significant harm, you must also notify the affected individuals in a clear and easily understandable manner.
  6. Cooperate with PDPC. Respond promptly to any follow-up queries from the Commission and provide supplementary information as requested.
  7. Document everything. Maintain records of the breach, your assessment, notification, and remediation for at least the duration required by PDPC.

Information Required in a PDPC Data Breach Notification

The PDPC online form requires comprehensive details about the incident. Prepare the following before starting:

Organisation Details

  • Organisation name and Unique Entity Number (UEN)
  • Registered address and contact information
  • Name, designation, and contact details of the Data Protection Officer (DPO)

Breach Details

  • Date and time the breach occurred (if known)
  • Date and time the breach was discovered
  • Description of how the breach happened
  • Type of personal data affected (NRIC, financial, health, etc.)
  • Number of individuals affected
  • Categories of affected individuals (customers, employees, minors, etc.)

Response Actions

  • Steps taken to contain the breach
  • Assessment of potential harm to individuals
  • Whether affected individuals have been or will be notified
  • Remediation measures and preventive actions planned

Notification Timelines at a Glance

ActionTimelineLegal Basis
Initial breach containmentImmediately upon discoveryGeneral duty of care
Assessment of notifiabilityUp to 30 days (expeditiously)Section 26C, PDPA
Notification to PDPCWithin 3 calendar days of assessmentSection 26D(1), PDPA
Notification to affected individualsAt the same time or after notifying PDPCSection 26D(2), PDPA
Data intermediaries notifying their principalWithout undue delaySection 26C(3), PDPA

When You Don't Need to Notify Affected Individuals

Even if a breach is notifiable to the PDPC, you may be exempt from notifying individuals in these circumstances:

  • Remedial action taken: Your organisation has taken action that renders it unlikely the breach will result in significant harm.
  • Technological protection: The personal data was encrypted or otherwise protected by technological measures such that the breach cannot cause significant harm.
  • Law enforcement direction: The PDPC or a prescribed law enforcement agency instructs you to withhold notification (usually to protect ongoing investigations).

Penalties for Failing to Report a Data Breach

The PDPC takes non-compliance seriously. Under the amended PDPA, financial penalties for breaches have increased significantly:

  • Organisations with annual turnover exceeding S$10 million: Up to 10% of annual turnover in Singapore
  • Other organisations: Up to S$1 million
  • Reputational damage: PDPC publishes enforcement decisions on its website, creating lasting public records
  • Civil action: Affected individuals may pursue private civil action for damages

Recent enforcement cases have seen fines ranging from S$5,000 for smaller SMEs to over S$750,000 for major organisations that failed to implement adequate security measures.

Best Practices for Data Breach Preparedness

Prevention and preparation are always better than reaction. Implement these practices to strengthen your organisation's readiness:

1. Develop a Data Breach Response Plan

Create a documented incident response plan that clearly defines roles, escalation paths, communication templates, and decision criteria. Test it through tabletop exercises at least annually.

2. Appoint a Data Protection Officer (DPO)

Under the PDPA, every organisation must appoint a DPO whose contact details must be publicly available. The DPO leads breach assessment and coordinates with PDPC.

3. Implement Strong Access Controls

Use role-based access control, multi-factor authentication, and the principle of least privilege. Most breaches involve credential compromise or excessive access rights.

4. Encrypt Sensitive Data

Encryption at rest and in transit can qualify for the technological protection exemption from individual notification. This is one of the most valuable safeguards.

5. Secure Your Digital Communications

Phishing and malicious link injection remain top attack vectors. When sharing links in customer communications, use trusted URL management platforms. Tools like Lunyb provide secure, trackable short links with click analytics, helping teams monitor suspicious activity and maintain a professional communications posture. Compare options in our 2026 URL shortener buyer's guide.

6. Maintain a Data Inventory

Know what personal data you hold, where it is stored, and who has access. During a breach, this inventory is critical for scoping impact quickly.

7. Train Your Staff

Human error causes a large percentage of breaches. Conduct regular PDPA awareness training and phishing simulations for all employees.

What to Include in Your Notification to Affected Individuals

When you must notify affected individuals, your communication should be clear, honest, and actionable. Include:

  • A plain-language description of what happened
  • The specific types of personal data involved
  • The potential consequences and risks to the individual
  • Steps the organisation has taken and will take
  • Specific actions the individual should take (e.g., change passwords, monitor bank statements)
  • Contact details for further questions—typically the DPO's email and hotline

Data Intermediaries and Their Obligations

If your organisation is a data intermediary (processing personal data on behalf of another organisation under contract), your obligation is different. You must notify the principal organisation without undue delay when you become aware of a breach. The principal organisation then assesses notifiability and reports to PDPC.

However, data intermediaries still bear responsibility for the Protection Obligation under the PDPA and can be penalised for security failures.

Common Mistakes to Avoid

  • Delaying assessment: Waiting too long to determine notifiability can push you past the 3-day deadline.
  • Underestimating scope: Failing to fully investigate can lead to incomplete notifications and follow-up penalties.
  • Poor documentation: Without clear records, defending your response actions becomes very difficult.
  • Overpromising to individuals: Avoid statements you cannot substantiate about the cause or containment.
  • Ignoring root cause: Simply containing the immediate breach without fixing systemic issues invites recurrence.
  • Not engaging legal counsel: For significant breaches, involve legal advisors early to manage regulatory and litigation risks.

Frequently Asked Questions

How quickly must I report a data breach to PDPC Singapore?

You must report a notifiable data breach to the PDPC as soon as practicable, and no later than 3 calendar days (72 hours) after you determine that the breach is notifiable. The assessment itself should be completed expeditiously, typically within 30 days of first becoming aware of the incident.

What happens if my breach doesn't meet the notification thresholds?

If a breach does not meet the significant harm or 500-individual threshold, you are not legally required to notify PDPC. However, you must still document the incident, take remedial action, and maintain records. The PDPC may still request information if the breach is discovered through other means.

Do I need to notify PDPC if the data was encrypted?

You may still need to notify the PDPC, but you may be exempt from notifying affected individuals if the encryption was strong enough to prevent unauthorised access to the personal data. The technological protection exemption applies to individual notification, not to PDPC notification.

Can I be fined even if I report the breach on time?

Yes. Timely notification does not absolve you of the underlying breach of the Protection Obligation. However, prompt notification, transparent cooperation, and demonstrated remediation efforts are considered mitigating factors that can substantially reduce financial penalties imposed by the PDPC.

Who should sign off on the PDPC notification submission?

The Data Protection Officer (DPO) is typically responsible for submitting the notification, but the content should be reviewed and approved by senior management, legal counsel, and the CEO or equivalent. This ensures accuracy, legal defensibility, and appropriate accountability at the organisational level.

Final Thoughts

Reporting a data breach to the PDPC is a legal obligation with tight timelines and serious consequences for non-compliance. The key to managing a breach well is preparation: have a response plan, know your data, empower your DPO, and build security into your everyday operations. When a breach does occur, act decisively, communicate transparently, and cooperate fully with the Commission.

Remember that the PDPA framework is designed to protect individuals and encourage responsible data stewardship. Organisations that treat compliance as a genuine commitment—rather than a checkbox exercise—not only avoid penalties but also earn the lasting trust of their customers.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles