facebook-pixel

How to Report a Data Breach to PDPC Singapore: A Complete 2026 Guide

L
Lunyb Security Team
··9 min read

If your organisation has suffered a data breach in Singapore, you may have a legal obligation to notify the Personal Data Protection Commission (PDPC) within 3 calendar days. Under the amended Personal Data Protection Act (PDPA), mandatory data breach notification became law in February 2021, and non-compliance can result in financial penalties of up to S$1 million or 10% of annual turnover in Singapore.

This guide walks you through exactly how to report a data breach to the PDPC, when notification is required, what information to include, and how to manage the process to protect both affected individuals and your organisation.

What Is a Data Breach Under Singapore's PDPA?

A data breach under the PDPA is any unauthorised access, collection, use, disclosure, copying, modification, or disposal of personal data, or the loss of any storage medium or device on which personal data is stored where such loss is likely to lead to unauthorised access or use.

The definition is deliberately broad and covers incidents such as:

  • Cyberattacks including ransomware, phishing, and system intrusions
  • Lost or stolen laptops, USB drives, or mobile phones containing personal data
  • Accidental disclosure via misaddressed emails or misconfigured cloud storage
  • Insider misuse of customer or employee records
  • Physical loss of paper records or documents

When Must You Report a Data Breach to PDPC?

You must notify the PDPC when a data breach meets either of the two notification thresholds set out in Section 26B of the PDPA: it results in significant harm to affected individuals, or it involves personal data of 500 or more individuals.

Threshold 1: Significant Harm to Individuals

The Personal Data Protection (Notification of Data Breaches) Regulations 2021 prescribe specific categories of personal data that are deemed likely to result in significant harm if compromised. These include:

  • Full name or alias combined with NRIC, FIN, work permit, or passport numbers
  • Financial account details such as bank account or credit card numbers
  • Health information, medical records, or diagnoses
  • Life or accident insurance details
  • Adoption records or information about mental capacity
  • Records of criminal history, private key data, or biometric identifiers

Threshold 2: Scale of 500 or More Individuals

Even if the data does not fall into the significant harm categories, you must still notify the PDPC if the breach affects 500 or more individuals. This threshold ensures large-scale incidents are reported regardless of data sensitivity.

Mandatory Notification Timelines

Timing is critical when reporting to the PDPC. Miss the deadlines and you compound the breach with a compliance failure.

ActionDeadlineLegal Basis
Assess whether breach is notifiableWithin 30 calendar days of becoming awarePDPA Section 26C
Notify PDPC of notifiable breachAs soon as practicable, no later than 3 calendar daysPDPA Section 26D
Notify affected individualsAt the same time or after notifying PDPC (with exceptions)PDPA Section 26D
Data intermediary notifies main organisationWithout undue delayPDPA Section 26A(2)

Step-by-Step: How to Report a Data Breach to PDPC

Follow these seven steps to manage the notification process correctly and demonstrate compliance.

Step 1: Contain the Breach Immediately

  1. Isolate affected systems from the network to prevent further compromise
  2. Reset compromised credentials and revoke access tokens
  3. Preserve logs, forensic evidence, and system snapshots
  4. Engage your incident response team or external forensic specialists

Step 2: Assess the Breach

Within 30 days of becoming aware of a potential breach, you must reasonably and expeditiously assess whether it is notifiable. Document:

  • What personal data was involved and in what volume
  • How the breach occurred and whether it is ongoing
  • Which individuals or categories of individuals are affected
  • Likelihood and severity of harm to individuals

Step 3: Determine Notification Obligations

Apply both notification thresholds. If either is met, you must notify the PDPC. If only the significant harm threshold is met, you generally must also notify affected individuals unless an exception applies (for example, if remedial action makes harm unlikely, or if notification would compromise a law enforcement investigation).

Step 4: Prepare the Notification

Gather the required information before submitting. The PDPC's online form requires the following details:

  • Organisation name, UEN, and contact details of the DPO
  • Date and time the breach occurred and was discovered
  • Description of the breach and how it happened
  • Type and volume of personal data involved
  • Number of affected individuals
  • Potential harm to individuals
  • Actions taken or planned to contain the breach and mitigate harm
  • Whether affected individuals have been or will be notified

Step 5: Submit via the PDPC Data Breach Notification Form

Submit through the official online form on the PDPC website at pdpc.gov.sg. The form is accessible via Singpass or Corppass. Save the acknowledgement reference number for your records.

Step 6: Notify Affected Individuals

Where individual notification is required, communicate clearly and directly. Notifications should include:

  • The facts of the breach and when it occurred
  • The types of personal data affected
  • Potential consequences and risks
  • Steps taken by the organisation to address the breach
  • Actions the individual can take to protect themselves
  • Contact information for further queries

Step 7: Document Everything

Maintain a comprehensive breach register even for non-notifiable incidents. The PDPC may request records during an investigation, and demonstrating a thorough assessment process is a strong mitigating factor in enforcement decisions.

What Happens After You Notify PDPC?

Once your notification is submitted, the PDPC will review the incident and may take one or more of the following actions:

  • Request additional information or documentation
  • Provide guidance on remediation and individual notification
  • Open a formal investigation under Section 50 of the PDPA
  • Direct the organisation to take specific remedial steps
  • Issue a financial penalty or written directions if breaches of the PDPA are found

Cooperation, transparency, and evidence of a mature data protection programme significantly influence outcomes. Organisations that self-report promptly and demonstrate genuine remediation typically receive more lenient treatment than those found to have concealed incidents.

Common Mistakes to Avoid

Delaying Assessment to Avoid the Clock

Some organisations delay formally acknowledging a breach in the hope of managing it quietly. The 30-day assessment window and 3-day notification deadline start from when the organisation had reason to believe a breach occurred, not when it decided to formally investigate.

Underestimating the Scale of Affected Data

Without proper data mapping, organisations often understate the volume of records exposed. Invest in data inventory tools and access logging before an incident forces the issue.

Poor Communication with Affected Individuals

Vague or overly technical notifications erode trust. Use clear, plain-language explanations and offer concrete protective actions such as credit monitoring or password resets.

Failing to Vet Data Intermediaries

If your vendor suffers a breach involving your data, you remain the accountable party. Include breach notification clauses in every data processing contract.

Preventive Measures to Reduce Breach Risk

The best breach report is the one you never have to file. Strengthen your posture with layered controls:

  • Access controls: Enforce least-privilege access, multi-factor authentication, and quarterly access reviews
  • Encryption: Encrypt personal data both at rest and in transit using current standards
  • Staff training: Run phishing simulations and PDPA awareness training at least annually
  • Secure link sharing: When sharing links to internal resources, customer portals, or campaign assets, use a reputable shortener with analytics and access controls. Platforms like Lunyb allow you to track link usage and revoke access if a link is compromised, reducing the risk of unauthorised data exposure through leaked URLs.
  • Endpoint protection: Deploy EDR solutions and enforce device encryption on all laptops and mobile devices
  • Incident response plan: Test your IR plan with tabletop exercises at least twice a year

For teams managing marketing campaigns and shortened links, understanding the security and privacy features of your tools matters. Our 2026 buyer's guide to URL shorteners compares platforms on privacy, analytics, and access controls, while our honest Lunyb review examines its security posture in detail.

Penalties for Non-Compliance

Failure to notify a notifiable data breach is itself a breach of the PDPA. Since October 2022, the maximum financial penalty for organisations with annual turnover exceeding S$10 million is 10% of annual Singapore turnover or S$1 million, whichever is higher. Smaller organisations remain subject to the S$1 million cap.

Recent PDPC enforcement decisions show penalties are proportionate to factors such as breach severity, number of affected individuals, adequacy of security measures before the breach, promptness of response, and cooperation during investigation.

Role of the Data Protection Officer

Every organisation in Singapore must appoint at least one Data Protection Officer (DPO). During a breach, the DPO typically:

  1. Leads the notifiability assessment
  2. Coordinates with legal, IT, and communications teams
  3. Prepares and submits the PDPC notification
  4. Manages communications with affected individuals
  5. Maintains the breach register and post-incident review

Ensure your DPO's contact details are published on your website and registered with ACRA, as required by the PDPA.

Frequently Asked Questions

How long do I have to report a data breach to PDPC?

You must notify the PDPC as soon as practicable and no later than 3 calendar days after determining that a breach is notifiable. You have up to 30 days from becoming aware of a suspected breach to complete your assessment of whether it is notifiable.

Do I need to notify affected individuals as well as PDPC?

Yes, if the breach is likely to result in significant harm, you must notify affected individuals at the same time or after notifying PDPC. Exceptions include cases where remedial action makes harm unlikely, or where notification would compromise an investigation or the security of a computer system.

What if fewer than 500 individuals are affected and no significant harm is likely?

You are not legally required to notify the PDPC, but you should still document the incident in your internal breach register, investigate the root cause, and implement corrective measures. The PDPC may still review these records during an audit.

What are the penalties for failing to report a data breach?

Organisations with annual Singapore turnover above S$10 million face financial penalties of up to 10% of that turnover. Smaller organisations face penalties of up to S$1 million. Penalties are additional to any harm caused by the breach itself and can significantly damage brand reputation.

Can a data intermediary report a breach directly to PDPC?

No. Data intermediaries must notify the organisation they process data for without undue delay. The primary organisation is responsible for the assessment and PDPC notification, though intermediaries can be held separately liable for failing to protect personal data under their protection obligation.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles