facebook-pixel

How to Report a Data Breach to PDPC Singapore: Complete 2026 Guide

L
Lunyb Security Team
··8 min read

Under Singapore's Personal Data Protection Act (PDPA), organisations that suffer a notifiable data breach are legally required to inform the Personal Data Protection Commission (PDPC) — and, in many cases, affected individuals — within strict timelines. Failing to report correctly can result in financial penalties of up to S$1 million or 10% of annual turnover in Singapore, whichever is higher.

This guide walks you through exactly how to report a data breach to the PDPC, when notification is mandatory, what information you must provide, and how to build a response process that keeps your organisation compliant in 2026.

What Counts as a Data Breach Under the PDPA?

A data breach under Singapore's PDPA refers to the unauthorised access, collection, use, disclosure, copying, modification, or disposal of personal data, or the loss of any storage medium or device on which personal data is stored. This definition covers both malicious incidents (like hacking or phishing) and accidental events (like emailing a spreadsheet to the wrong recipient).

Since the PDPA amendments took effect on 1 February 2021, the Mandatory Data Breach Notification Obligation requires organisations to assess and, where applicable, notify the PDPC and affected individuals of qualifying breaches.

Common Examples of Reportable Breaches

  • Ransomware or malware compromising customer databases
  • Phishing attacks leading to credential theft and unauthorised system access
  • Lost or stolen laptops, USB drives, or mobile devices containing personal data
  • Misconfigured cloud storage exposing files to the public internet
  • Employees emailing or sending sensitive documents to wrong recipients
  • Insider misuse of customer records

When Is a Data Breach Notifiable to PDPC?

Not every data breach must be reported. Under Section 26B of the PDPA, a breach is notifiable to the PDPC if it meets either of the following thresholds:

  1. Significant harm threshold: The breach results in, or is likely to result in, significant harm to affected individuals. This typically applies when the personal data involved falls into prescribed categories such as NRIC numbers, financial account details, health information, or account credentials.
  2. Significant scale threshold: The breach affects, or is likely to affect, 500 or more individuals — regardless of harm severity.

If either threshold is met, notification to PDPC is mandatory. If only the significant harm threshold applies, affected individuals must also be notified.

Prescribed Categories of Personal Data

CategoryExamples
Identification dataNRIC, FIN, passport numbers
Financial dataCredit card numbers, bank account details, CVV codes
Life insurance & healthMedical records, diagnoses, insurance claims
Account credentialsUsernames, passwords, security answers
Sensitive personal dataAdoption records, criminal records, private communications

PDPC Data Breach Notification Timeline

The PDPA sets clear deadlines. Miss them, and you risk enforcement action.

  1. Assessment: Once you have reason to believe a breach has occurred, you must conduct a reasonable and expeditious assessment — typically completed within 30 calendar days.
  2. Notify PDPC: If the breach is notifiable, inform the PDPC as soon as practicable, and in any case no later than 3 calendar days after making the assessment.
  3. Notify affected individuals: Where required, notify affected individuals at the same time as, or after, notifying the PDPC — unless doing so would compromise an ongoing investigation or remedial action.

Step-by-Step: How to Report a Data Breach to PDPC

Here is the practical process organisations should follow when a suspected breach is discovered.

Step 1: Contain the Breach

Before anything else, stop the bleeding. Isolate affected systems, revoke compromised credentials, disable exposed endpoints, and preserve logs and evidence. Do not wipe systems prematurely — forensic data will be crucial for the PDPC submission.

Step 2: Assemble Your Response Team

Activate your Data Breach Management Team. This usually includes your Data Protection Officer (DPO), IT security lead, legal counsel, communications, and senior management. Assign a single point of coordination.

Step 3: Assess the Breach

Determine:

  • What personal data was involved and in what volume?
  • How many individuals are affected?
  • What is the likely harm (financial, reputational, physical)?
  • Does it meet the significant harm or significant scale threshold?

Step 4: Submit the Notification via PDPC's Online Form

Reports are filed through the PDPC website at pdpc.gov.sg using the Data Breach Notification form. You will need to provide:

  • Organisation details and DPO contact information
  • Date and time the breach was discovered
  • Nature and cause of the breach
  • Categories and volume of personal data affected
  • Number of individuals affected
  • Containment and remedial measures taken
  • Whether affected individuals have been or will be notified

If not all information is available within 3 days, submit what you have and follow up with additional details as they emerge.

Step 5: Notify Affected Individuals

Where required, notify affected individuals directly through email, SMS, letter, or in-app notification. The notice should include:

  • A clear description of what happened
  • The type of personal data involved
  • Potential consequences and risks
  • Steps individuals can take to protect themselves (e.g., changing passwords, monitoring accounts)
  • Contact details for follow-up questions

Step 6: Remediate and Document

Implement long-term fixes: patch vulnerabilities, retrain staff, revise access controls, and update your data protection policies. Maintain a written record of the entire incident, decisions made, and evidence collected — the PDPC may request this during follow-up.

Exceptions: When You Don't Need to Notify Individuals

Even if a breach meets the notification threshold, you may be exempt from notifying affected individuals in specific circumstances:

  • Remedial action taken: If you took action that renders significant harm unlikely (e.g., remote-wiping a stolen laptop before data was accessed).
  • Technological protection: If the personal data was encrypted or otherwise protected to a standard that makes the data inaccessible or unintelligible.
  • Law enforcement request: If a prescribed law enforcement agency instructs you to delay notification for investigation purposes.

Note: These exceptions apply only to individual notification. You still must notify the PDPC.

Common Mistakes to Avoid

MistakeConsequenceHow to Avoid
Delaying assessmentMissing 30-day windowTrigger response plan on first suspicion
Under-reporting scopeRegulatory follow-up, penaltiesErr on the side of full disclosure
Skipping individual noticeBreach of Section 26DVerify exemption criteria in writing
Poor documentationCannot defend decisionsMaintain a live incident log
No DPO appointedSeparate PDPA violationRegister a DPO with PDPC

Building a Breach-Ready Organisation

Reporting a breach effectively depends on preparation done long before an incident happens. A robust data protection posture includes:

1. A Written Data Breach Management Plan

Document roles, escalation paths, assessment criteria, and notification templates. Test it annually with tabletop exercises.

2. Data Inventory and Classification

You cannot protect what you cannot see. Maintain an up-to-date inventory of what personal data you hold, where it lives, and who has access.

3. Technical Safeguards

Deploy encryption at rest and in transit, multi-factor authentication, endpoint detection, regular patching, and network segmentation. Encrypted data significantly reduces breach severity and may exempt you from individual notification.

4. Vendor Management

Many breaches originate through third-party processors. Ensure your data processing agreements require prompt breach notification to you — ideally within 24-48 hours — so you can meet your own PDPC deadline.

5. Safer Link Handling

Phishing remains a top breach vector. Using a reputable link management platform like Lunyb helps teams create branded, trackable short links and inspect suspicious URLs before clicking — a small but meaningful layer of defence against credential harvesting attacks. You can read our honest review of Lunyb or compare it against alternatives in our 2026 buyer's guide to URL shorteners.

Penalties for Non-Compliance

Since October 2022, the PDPC can impose financial penalties of up to S$1 million on organisations with annual local turnover below S$10 million, or up to 10% of annual turnover in Singapore for larger organisations. Beyond fines, the PDPC publishes enforcement decisions publicly, creating significant reputational damage.

Recent enforcement decisions have consistently penalised organisations for failing to notify breaches on time, insufficient security arrangements, and inadequate DPO oversight — often more heavily than the underlying breach itself.

Frequently Asked Questions

How quickly must I report a data breach to PDPC?

You must notify the PDPC no later than 3 calendar days after determining that the breach is notifiable. Your assessment itself should be completed expeditiously, typically within 30 days of first suspecting a breach.

Do I need to notify affected individuals as well as PDPC?

Yes, if the breach is likely to cause significant harm to individuals. You are exempt only if you took remedial action that makes harm unlikely, the data was strongly encrypted, or a law enforcement agency instructs you to delay. Notification to PDPC is still required in all cases.

What happens if I don't know all the details within 3 days?Submit an initial notification with the information you have, clearly stating what remains under investigation. The PDPC expects you to follow up with additional details as they become available. Late-but-partial reporting is far better than silence.

Do I need a Data Protection Officer to report a breach?

Yes. Every organisation in Singapore is required under the PDPA to appoint at least one DPO and register their business contact information with the PDPC. The DPO typically leads breach notification.

Are near-misses or attempted breaches reportable?

Attempted breaches that did not result in unauthorised access to personal data are generally not notifiable. However, you should document them internally and review whether they reveal vulnerabilities that need remediation. If you are uncertain, err toward assessing the incident formally.

Final Thoughts

Reporting a data breach to the PDPC is not just a legal obligation — it is a chance to demonstrate accountability, protect affected individuals, and rebuild trust. The organisations that fare best after a breach are those that prepared before it happened: clear response plans, appointed DPOs, encrypted systems, and disciplined vendor oversight.

If you have not reviewed your data breach management plan in the last 12 months, treat this article as your prompt. Update your templates, test your escalation paths, and make sure your DPO knows exactly what to do when — not if — an incident occurs.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles