facebook-pixel

How to Report a Data Breach to PDPC Singapore: A Complete 2026 Guide

L
Lunyb Security Team
··10 min read

Data breaches are no longer a rare misfortune — they are an operational risk that every Singapore organisation must be ready to handle. Since the Personal Data Protection (Amendment) Act 2020 came into force on 1 February 2021, mandatory data breach notification has been part of Singapore law. If your organisation suffers a notifiable data breach, you must inform the Personal Data Protection Commission (PDPC), and in many cases the affected individuals, within strict timelines.

This guide walks you through exactly how to report a data breach to PDPC Singapore in 2026, including who must notify, what counts as a notifiable breach, timelines, the notification form, and what happens after you submit it.

What Is a Data Breach Under Singapore's PDPA?

Under the Personal Data Protection Act (PDPA), a data breach is the unauthorised access, collection, use, disclosure, copying, modification, or disposal of personal data — or the loss of any storage medium or device on which personal data is stored, where unauthorised access is likely.

In plain terms, a breach occurs when personal data leaves your control in a way it shouldn't. Common examples include:

  • A hacker accessing your customer database.
  • An employee emailing a spreadsheet of personal data to the wrong recipient.
  • A lost or stolen laptop, USB drive, or mobile phone containing customer records.
  • Ransomware encrypting files that contain personal data.
  • A misconfigured cloud storage bucket exposing files to the public internet.
  • Phishing attacks that compromise staff email accounts.

When Must You Report a Data Breach to PDPC?

Not every data breach must be reported. A breach is notifiable under the PDPA if it meets either of these thresholds:

  1. Significant harm: The breach results in, or is likely to result in, significant harm to affected individuals. This includes financial loss, identity theft, or exposure of sensitive information such as NRIC numbers, financial details, or health records.
  2. Significant scale: The breach affects, or is likely to affect, 500 or more individuals.

If either threshold is met, notification to PDPC is mandatory. If only the "significant harm" threshold is met, you must also notify affected individuals directly.

Categories of Personal Data Deemed to Cause Significant Harm

The PDPC has prescribed specific data categories that are automatically deemed likely to cause significant harm if breached:

  • Full name or alias combined with NRIC, FIN, passport, or work permit numbers.
  • Financial information such as credit card numbers, bank account numbers, or CPF details.
  • Life and health insurance information.
  • Medical records, diagnoses, and treatment history.
  • Information about vulnerable individuals, including minors and persons with disabilities.
  • Adoption records, private sexual behaviour data, and similarly sensitive categories.

Timelines: How Fast Must You Act?

Speed is critical. The PDPA sets clear timelines that your response plan must meet:

StageTimelineWhat Must Happen
AssessmentWithin 30 calendar days of becoming awareAssess whether the breach is notifiable.
Notify PDPCAs soon as practicable, no later than 3 calendar days after determining it is notifiableSubmit the Data Breach Notification form to PDPC.
Notify individualsAt the same time or after notifying PDPCInform affected individuals if significant harm is likely.
Data intermediary dutyWithout undue delayData intermediaries must notify the main organisation as soon as they become aware.

Missing these deadlines can result in financial penalties of up to 10% of annual turnover in Singapore for organisations with revenue exceeding S$10 million, or S$1 million — whichever is higher.

Step-by-Step: How to Report a Data Breach to PDPC

Step 1: Contain the Breach Immediately

Before anything else, stop the bleeding. Containment activities may include:

  1. Isolating compromised systems from the network.
  2. Resetting passwords and revoking access tokens.
  3. Recovering lost devices or remotely wiping them.
  4. Recalling erroneously sent emails using Microsoft 365 or Google Workspace recall features.
  5. Taking affected servers offline while forensic evidence is preserved.

Step 2: Assemble Your Data Breach Response Team

Your Data Protection Officer (DPO) should lead the response. The team typically includes IT/security, legal, communications, HR, and senior management. If you do not have an in-house DPO, engage an external one — the PDPA requires every organisation in Singapore to designate one.

Step 3: Assess Whether the Breach Is Notifiable

You have up to 30 days to complete this assessment, but faster is better. Document:

  • What personal data was involved.
  • How many individuals are affected.
  • Whether the data falls into the "significant harm" categories.
  • Whether the data was encrypted or otherwise protected.
  • The likelihood of misuse.

If encryption rendered the data unintelligible to unauthorised parties, the breach may not be notifiable — but this must be properly documented.

Step 4: Submit the Notification to PDPC

Once you determine the breach is notifiable, you must file within 3 calendar days. To submit:

  1. Visit the PDPC website at pdpc.gov.sg.
  2. Navigate to "Report a Data Breach" under the Organisations section.
  3. Log in via Corppass to access the online Data Breach Notification form.
  4. Complete all mandatory fields — the form will save your progress if you need more time.
  5. Submit and download the acknowledgement PDF for your records.

Step 5: Notify Affected Individuals

Where the significant harm threshold is met, notify individuals in a clear, easy-to-understand manner. The notification must include:

  • The facts of the breach.
  • The types of personal data involved.
  • Steps taken to address the breach.
  • Actions individuals can take to protect themselves (e.g., changing passwords, monitoring bank statements).
  • Contact details for further enquiries.

You may notify by email, letter, SMS, phone call, or in-person conversation. Public notices via your website or newspaper are only acceptable if direct contact is not feasible.

Step 6: Remediate and Document

After the immediate response, complete a root-cause analysis and implement corrective measures. Keep detailed records — PDPC may request them during any follow-up investigation.

Information You Need for the PDPC Notification Form

Prepare the following before you begin filling in the form:

CategoryDetails Required
Organisation detailsUEN, registered name, industry, DPO contact information.
Breach descriptionDate discovered, date occurred, cause, and how it was detected.
Personal data involvedData types, sensitivity, volume, and whether encryption applied.
Affected individualsEstimated number, categories (customers, employees, minors, etc.).
Containment actionsSteps taken to stop and mitigate the breach.
Notification to individualsWhether, when, and how affected individuals were informed.
Preventive measuresLong-term steps to prevent recurrence.

Common Mistakes to Avoid

1. Waiting Too Long to Investigate

Some organisations delay assessment hoping the issue will "resolve itself." The 30-day assessment window is a maximum, not a target. Regulators expect organisations to act promptly upon discovery.

2. Under-Reporting the Scale

Deliberately understating the number of affected individuals to avoid crossing the 500-person threshold is a serious offence. If you are unsure, err on the side of over-reporting.

3. Poor Communication With Affected Individuals

Vague, jargon-heavy notifications erode trust. Write in plain language. Tell people what happened, what you're doing, and what they should do.

4. Not Having a Response Plan Before a Breach Occurs

Trying to build a response process in the middle of a live incident guarantees mistakes. Draft, test, and rehearse your plan annually.

5. Ignoring Data Intermediary Obligations

If your organisation processes data on behalf of another (as a data intermediary), you have a statutory duty to notify your client organisation without undue delay — even if you have no direct duty to notify PDPC.

Building a Prevention-First Culture

The best breach response is the one you never need. Strong preventive controls reduce both the frequency and severity of incidents:

  • Access controls: Enforce role-based access, multi-factor authentication, and least-privilege principles.
  • Encryption: Encrypt personal data at rest and in transit. Encrypted data that remains unintelligible after a breach may not trigger notification duties.
  • Employee training: Phishing remains the top attack vector. Regular training is non-negotiable.
  • Vendor management: Vet your data intermediaries carefully and include breach notification clauses in every contract.
  • Link hygiene: Careless sharing of links can leak confidential resources. Using a trusted shortener like Lunyb with password protection and expiry controls helps ensure sensitive links stay in the right hands. Learn more in our honest Lunyb review.
  • Logging and monitoring: You cannot report what you cannot detect. Invest in SIEM tooling and endpoint monitoring.

If you regularly share marketing or customer-facing links, review your tooling choices too — our 2026 URL shortener buyer's guide compares platforms on privacy and security features.

What Happens After You Notify PDPC?

After submission, PDPC will acknowledge receipt and may request further information. Possible outcomes include:

  1. No further action: If your response was appropriate and preventive measures are sound, the matter may be closed.
  2. Advisory notice: PDPC may issue guidance on improvements you should make.
  3. Formal investigation: For serious or repeated breaches, PDPC will investigate more thoroughly.
  4. Enforcement action: This may include directions to remediate, financial penalties, or public findings that affect your organisation's reputation.

Cooperation, transparency, and demonstrable remedial action significantly influence outcomes.

Special Situations

Cross-Border Breaches

If personal data was transferred overseas before the breach, both Singapore's PDPA and the destination jurisdiction's laws may apply. Coordinate legal advice across all relevant regulators (e.g., Hong Kong PCPD, EU DPAs under GDPR, Australia's OAIC).

Breaches Involving Ransomware

Even if data was only encrypted (not exfiltrated), PDPC treats loss of access to personal data as a potential breach. Ransomware incidents almost always require notification analysis.

Breaches Discovered by Third Parties

If a researcher, journalist, or customer reports the breach to you, the clock starts when your organisation becomes aware — not when the third party first discovered it. Have a clear intake process for such reports.

Frequently Asked Questions

1. How long do I have to report a data breach to PDPC?

You must notify PDPC as soon as practicable and no later than 3 calendar days after determining that the breach is notifiable. You have up to 30 days from awareness to make that determination, but faster action is expected.

2. Do I need to notify PDPC for every data breach?

No. Only breaches that cause (or are likely to cause) significant harm to individuals, or that affect 500 or more people, must be notified. However, you should document all breaches internally, even minor ones.

3. What are the penalties for failing to report a data breach?

Failure to notify PDPC when required can attract financial penalties of up to 10% of the organisation's annual turnover in Singapore (for those with revenue above S$10 million), or up to S$1 million — whichever is higher.

4. Can I report a data breach anonymously?

No. Organisations must identify themselves through Corppass when submitting the Data Breach Notification form. Individuals who wish to report a suspected breach affecting them can lodge a complaint separately through PDPC's complaint channel.

5. What if I discover a breach happened months ago?

Notify PDPC as soon as you become aware, regardless of when the breach occurred. Explain in the notification why the breach was only discovered late and what detection improvements you are implementing.

Final Thoughts

Reporting a data breach to PDPC is not just a legal box-ticking exercise — it is a test of how mature and trustworthy your organisation truly is. Companies that respond quickly, communicate honestly, and demonstrate genuine remediation preserve customer trust even after a serious incident. Those that delay, downplay, or dodge often suffer far greater reputational damage than the breach itself would have caused.

Build your response plan today, appoint a capable DPO, encrypt what matters, and train your people. If a breach ever does happen, you'll be ready to handle it with the calm, professional response Singapore regulators — and your customers — expect.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles