How to Report a Data Breach to PDPC Singapore: A Complete 2026 Guide
If your organisation has suffered a data breach in Singapore, you may have a legal obligation to notify the Personal Data Protection Commission (PDPC) within 3 calendar days. Under the amended Personal Data Protection Act (PDPA), mandatory data breach notification became law in February 2021, and non-compliance can result in financial penalties of up to S$1 million or 10% of annual turnover in Singapore.
This guide walks you through exactly how to report a data breach to the PDPC, when notification is required, what information to include, and how to manage the process to protect both affected individuals and your organisation.
What Is a Data Breach Under Singapore's PDPA?
A data breach under the PDPA is any unauthorised access, collection, use, disclosure, copying, modification, or disposal of personal data, or the loss of any storage medium or device on which personal data is stored where such loss is likely to lead to unauthorised access or use.
The definition is deliberately broad and covers incidents such as:
- Cyberattacks including ransomware, phishing, and system intrusions
- Lost or stolen laptops, USB drives, or mobile phones containing personal data
- Accidental disclosure via misaddressed emails or misconfigured cloud storage
- Insider misuse of customer or employee records
- Physical loss of paper records or documents
When Must You Report a Data Breach to PDPC?
You must notify the PDPC when a data breach meets either of the two notification thresholds set out in Section 26B of the PDPA: it results in significant harm to affected individuals, or it involves personal data of 500 or more individuals.
Threshold 1: Significant Harm to Individuals
The Personal Data Protection (Notification of Data Breaches) Regulations 2021 prescribe specific categories of personal data that are deemed likely to result in significant harm if compromised. These include:
- Full name or alias combined with NRIC, FIN, work permit, or passport numbers
- Financial account details such as bank account or credit card numbers
- Health information, medical records, or diagnoses
- Life or accident insurance details
- Adoption records or information about mental capacity
- Records of criminal history, private key data, or biometric identifiers
Threshold 2: Scale of 500 or More Individuals
Even if the data does not fall into the significant harm categories, you must still notify the PDPC if the breach affects 500 or more individuals. This threshold ensures large-scale incidents are reported regardless of data sensitivity.
Mandatory Notification Timelines
Timing is critical when reporting to the PDPC. Miss the deadlines and you compound the breach with a compliance failure.
| Action | Deadline | Legal Basis |
|---|---|---|
| Assess whether breach is notifiable | Within 30 calendar days of becoming aware | PDPA Section 26C |
| Notify PDPC of notifiable breach | As soon as practicable, no later than 3 calendar days | PDPA Section 26D |
| Notify affected individuals | At the same time or after notifying PDPC (with exceptions) | PDPA Section 26D |
| Data intermediary notifies main organisation | Without undue delay | PDPA Section 26A(2) |
Step-by-Step: How to Report a Data Breach to PDPC
Follow these seven steps to manage the notification process correctly and demonstrate compliance.
Step 1: Contain the Breach Immediately
- Isolate affected systems from the network to prevent further compromise
- Reset compromised credentials and revoke access tokens
- Preserve logs, forensic evidence, and system snapshots
- Engage your incident response team or external forensic specialists
Step 2: Assess the Breach
Within 30 days of becoming aware of a potential breach, you must reasonably and expeditiously assess whether it is notifiable. Document:
- What personal data was involved and in what volume
- How the breach occurred and whether it is ongoing
- Which individuals or categories of individuals are affected
- Likelihood and severity of harm to individuals
Step 3: Determine Notification Obligations
Apply both notification thresholds. If either is met, you must notify the PDPC. If only the significant harm threshold is met, you generally must also notify affected individuals unless an exception applies (for example, if remedial action makes harm unlikely, or if notification would compromise a law enforcement investigation).
Step 4: Prepare the Notification
Gather the required information before submitting. The PDPC's online form requires the following details:
- Organisation name, UEN, and contact details of the DPO
- Date and time the breach occurred and was discovered
- Description of the breach and how it happened
- Type and volume of personal data involved
- Number of affected individuals
- Potential harm to individuals
- Actions taken or planned to contain the breach and mitigate harm
- Whether affected individuals have been or will be notified
Step 5: Submit via the PDPC Data Breach Notification Form
Submit through the official online form on the PDPC website at pdpc.gov.sg. The form is accessible via Singpass or Corppass. Save the acknowledgement reference number for your records.
Step 6: Notify Affected Individuals
Where individual notification is required, communicate clearly and directly. Notifications should include:
- The facts of the breach and when it occurred
- The types of personal data affected
- Potential consequences and risks
- Steps taken by the organisation to address the breach
- Actions the individual can take to protect themselves
- Contact information for further queries
Step 7: Document Everything
Maintain a comprehensive breach register even for non-notifiable incidents. The PDPC may request records during an investigation, and demonstrating a thorough assessment process is a strong mitigating factor in enforcement decisions.
What Happens After You Notify PDPC?
Once your notification is submitted, the PDPC will review the incident and may take one or more of the following actions:
- Request additional information or documentation
- Provide guidance on remediation and individual notification
- Open a formal investigation under Section 50 of the PDPA
- Direct the organisation to take specific remedial steps
- Issue a financial penalty or written directions if breaches of the PDPA are found
Cooperation, transparency, and evidence of a mature data protection programme significantly influence outcomes. Organisations that self-report promptly and demonstrate genuine remediation typically receive more lenient treatment than those found to have concealed incidents.
Common Mistakes to Avoid
Delaying Assessment to Avoid the Clock
Some organisations delay formally acknowledging a breach in the hope of managing it quietly. The 30-day assessment window and 3-day notification deadline start from when the organisation had reason to believe a breach occurred, not when it decided to formally investigate.
Underestimating the Scale of Affected Data
Without proper data mapping, organisations often understate the volume of records exposed. Invest in data inventory tools and access logging before an incident forces the issue.
Poor Communication with Affected Individuals
Vague or overly technical notifications erode trust. Use clear, plain-language explanations and offer concrete protective actions such as credit monitoring or password resets.
Failing to Vet Data Intermediaries
If your vendor suffers a breach involving your data, you remain the accountable party. Include breach notification clauses in every data processing contract.
Preventive Measures to Reduce Breach Risk
The best breach report is the one you never have to file. Strengthen your posture with layered controls:
- Access controls: Enforce least-privilege access, multi-factor authentication, and quarterly access reviews
- Encryption: Encrypt personal data both at rest and in transit using current standards
- Staff training: Run phishing simulations and PDPA awareness training at least annually
- Secure link sharing: When sharing links to internal resources, customer portals, or campaign assets, use a reputable shortener with analytics and access controls. Platforms like Lunyb allow you to track link usage and revoke access if a link is compromised, reducing the risk of unauthorised data exposure through leaked URLs.
- Endpoint protection: Deploy EDR solutions and enforce device encryption on all laptops and mobile devices
- Incident response plan: Test your IR plan with tabletop exercises at least twice a year
For teams managing marketing campaigns and shortened links, understanding the security and privacy features of your tools matters. Our 2026 buyer's guide to URL shorteners compares platforms on privacy, analytics, and access controls, while our honest Lunyb review examines its security posture in detail.
Penalties for Non-Compliance
Failure to notify a notifiable data breach is itself a breach of the PDPA. Since October 2022, the maximum financial penalty for organisations with annual turnover exceeding S$10 million is 10% of annual Singapore turnover or S$1 million, whichever is higher. Smaller organisations remain subject to the S$1 million cap.
Recent PDPC enforcement decisions show penalties are proportionate to factors such as breach severity, number of affected individuals, adequacy of security measures before the breach, promptness of response, and cooperation during investigation.
Role of the Data Protection Officer
Every organisation in Singapore must appoint at least one Data Protection Officer (DPO). During a breach, the DPO typically:
- Leads the notifiability assessment
- Coordinates with legal, IT, and communications teams
- Prepares and submits the PDPC notification
- Manages communications with affected individuals
- Maintains the breach register and post-incident review
Ensure your DPO's contact details are published on your website and registered with ACRA, as required by the PDPA.
Frequently Asked Questions
How long do I have to report a data breach to PDPC?
You must notify the PDPC as soon as practicable and no later than 3 calendar days after determining that a breach is notifiable. You have up to 30 days from becoming aware of a suspected breach to complete your assessment of whether it is notifiable.
Do I need to notify affected individuals as well as PDPC?
Yes, if the breach is likely to result in significant harm, you must notify affected individuals at the same time or after notifying PDPC. Exceptions include cases where remedial action makes harm unlikely, or where notification would compromise an investigation or the security of a computer system.
What if fewer than 500 individuals are affected and no significant harm is likely?
You are not legally required to notify the PDPC, but you should still document the incident in your internal breach register, investigate the root cause, and implement corrective measures. The PDPC may still review these records during an audit.
What are the penalties for failing to report a data breach?
Organisations with annual Singapore turnover above S$10 million face financial penalties of up to 10% of that turnover. Smaller organisations face penalties of up to S$1 million. Penalties are additional to any harm caused by the breach itself and can significantly damage brand reputation.
Can a data intermediary report a breach directly to PDPC?
No. Data intermediaries must notify the organisation they process data for without undue delay. The primary organisation is responsible for the assessment and PDPC notification, though intermediaries can be held separately liable for failing to protect personal data under their protection obligation.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Create a Link in Bio Page in 2026: Complete Step-by-Step Guide
A step-by-step guide to creating a high-converting link in bio page in 2026 — from choosing the right tool and custom domain to design, analytics, and optimization. Includes best practices, tool comparisons, and answers to common questions.
How to Create Branded Short Links: The Complete 2026 Guide
Branded short links can boost click-through rates by up to 39% while reinforcing your brand with every share. This complete 2026 guide walks through choosing a short domain, connecting it to a shortener, creating your first link, and scaling with automation.
How to Lock Apps and Photos with Face ID: The Complete 2026 Guide
Learn how to lock apps and photos with Face ID using built-in iOS features. This step-by-step guide covers app locking, hiding apps, protecting the Hidden album, and troubleshooting tips for 2026.
How to Remove Your Personal Information from Data Brokers: Complete 2026 Guide
Data brokers sell your personal information to anyone willing to pay, exposing you to identity theft, stalking, and scams. This comprehensive guide shows you exactly how to remove your data from the top brokers, protect your privacy long-term, and leverage your legal rights.