facebook-pixel

How to Report a Data Breach to PDPC Singapore: Complete 2026 Guide

L
Lunyb Security Team
··9 min read

If your organisation has suffered a personal data breach in Singapore, notifying the Personal Data Protection Commission (PDPC) is not optional — it is a legal obligation under the Personal Data Protection Act (PDPA). Since the Mandatory Data Breach Notification obligation took effect on 1 February 2021, businesses that process personal data in Singapore must assess, escalate, and report qualifying breaches within strict timelines.

This guide walks you through exactly how to report a data breach to PDPC, when notification is required, what information to prepare, and how to manage communications with affected individuals. Whether you are an SME, a multinational, or a data intermediary, following this process correctly can significantly reduce your regulatory risk and reputational damage.

What Counts as a Data Breach Under the PDPA?

A data breach under Singapore's PDPA is any unauthorised access, collection, use, disclosure, copying, modification, disposal, or loss of personal data in an organisation's possession or control. It can be accidental (e.g. an email sent to the wrong recipient) or malicious (e.g. a ransomware attack).

Common examples include:

  • Hacking or unauthorised access to databases and cloud storage
  • Lost or stolen laptops, USB drives, or mobile devices containing personal data
  • Misconfigured servers exposing customer records publicly
  • Phishing attacks compromising employee email accounts
  • Insider misuse or accidental disclosure of personal data
  • Ransomware encrypting personal data files

When Must You Notify the PDPC?

Under Section 26D of the PDPA, an organisation must notify the PDPC of a notifiable data breach as soon as practicable, but no later than 3 calendar days after determining that the breach is notifiable. A breach is considered notifiable if it meets either of these thresholds:

  1. Significant harm threshold: The breach results in, or is likely to result in, significant harm to affected individuals. This includes financial loss, identity theft, physical harm, or damage to reputation.
  2. Significant scale threshold: The breach affects, or is likely to affect, 500 or more individuals.

The PDPC's Personal Data Protection (Notification of Data Breaches) Regulations 2021 also prescribe categories of personal data that automatically trigger the "significant harm" test, such as full name combined with NRIC/FIN, financial account details, health information, or account credentials.

Breaches That Do Not Require Notification

You are not required to notify the PDPC if:

  • Remedial action taken renders it unlikely the breach will result in significant harm (e.g. data was encrypted and keys were not compromised)
  • Technological protections make the data unintelligible or inaccessible to unauthorised parties
  • The breach only involves employee personal data within the same organisation

However, you must still document the breach internally and be able to justify your assessment if audited.

Step-by-Step: How to Report a Data Breach to PDPC

Step 1: Contain the Breach Immediately

Before notification, take urgent steps to stop the breach and prevent further data loss. Actions may include:

  1. Isolating affected systems from the network
  2. Revoking compromised credentials and access tokens
  3. Shutting down or patching vulnerable services
  4. Recovering lost devices or data where possible
  5. Preserving logs and forensic evidence

Step 2: Assess the Breach Within 30 Days

You have up to 30 days to conduct a reasonable and expeditious assessment to determine whether the breach is notifiable. During assessment, evaluate:

  • The type and volume of personal data involved
  • The cause and extent of the breach
  • Whether affected data is encrypted or otherwise protected
  • Number of individuals affected
  • Likelihood of significant harm

Step 3: Notify the PDPC Within 3 Days

Once you determine the breach is notifiable, submit your notification within 3 calendar days via the PDPC's online Data Breach Notification form at eservice.pdpc.gov.sg. Log in using CorpPass to access the form.

Step 4: Notify Affected Individuals

If the breach meets the significant harm threshold, you must also notify affected individuals on or after notifying the PDPC. Notification to individuals is not required if:

  • The PDPC directs you not to notify
  • A prescribed law enforcement agency instructs you not to
  • Remedial actions render harm unlikely, or the data is protected by technological measures

Step 5: Document and Remediate

Maintain a full internal record of the breach, your assessment, notifications made, and remedial steps. The PDPC may request this documentation during any subsequent investigation.

Information You Need to Submit

The PDPC's online notification form requires detailed information. Prepare the following before you start:

CategoryDetails Required
Organisation DetailsLegal name, UEN, industry sector, DPO contact information
Breach DescriptionDate and time of breach, date discovered, how it was discovered, cause
Personal Data InvolvedTypes of data (NRIC, financial, health, etc.), volume, format
Affected IndividualsEstimated number, categories (customers, employees, minors)
Impact AssessmentLikely harm, whether data was encrypted, risk to individuals
Containment ActionsImmediate steps taken, systems isolated, credentials reset
Remediation PlanLong-term measures, staff training, technical improvements
Individual NotificationWhether/when individuals will be notified, communication channels

Timeline Summary: PDPA Data Breach Obligations

StageTimelineAction
DiscoveryDay 0Detect and contain the breach
AssessmentWithin 30 daysDetermine if the breach is notifiable
PDPC NotificationWithin 3 calendar days of determinationSubmit online notification form
Individual NotificationOn or after PDPC notificationInform affected individuals if significant harm applies
Data Intermediary DutyWithout undue delayNotify the main organisation of any breach

Special Rules for Data Intermediaries

A data intermediary (i.e. a vendor processing personal data on behalf of another organisation) has a separate obligation. Under Section 26C, it must notify the organisation it works for without undue delay upon becoming aware of a breach. The main organisation, not the intermediary, is responsible for assessing and notifying the PDPC.

Cloud providers, IT outsourcing firms, marketing agencies, and payroll processors typically fall under this category. Contracts should clearly define breach notification timelines, ideally 24–48 hours.

Penalties for Non-Compliance

Failure to comply with the mandatory data breach notification obligation can trigger significant financial penalties. Since 1 October 2022, the PDPC has been empowered to impose financial penalties of up to:

  • 10% of an organisation's annual turnover in Singapore, or
  • S$1 million, whichever is higher

Recent enforcement decisions have shown the PDPC is willing to publish decisions naming organisations, which can cause substantial reputational damage on top of the fine.

Best Practices to Prepare Before a Breach Happens

Organisations that handle breaches well are almost always the ones that prepared in advance. Consider these practices:

1. Appoint a Data Protection Officer (DPO)

Every organisation in Singapore is required to appoint at least one DPO and register their business contact information with ACRA. The DPO leads breach response.

2. Maintain a Breach Response Playbook

Document clear roles, escalation paths, decision criteria for notification, template communications, and legal contacts. Rehearse it annually with tabletop exercises.

3. Encrypt Personal Data at Rest and in Transit

Strong encryption is one of the strongest defences against a breach becoming notifiable. If data is unintelligible to attackers, notification to individuals may not be required.

4. Secure Your Marketing and Web Assets

Many breaches originate from third-party tools — link trackers, form builders, email platforms. Choose vendors that publish clear security practices. For example, when sharing campaign links, using a privacy-conscious link management platform like Lunyb can reduce data exposure compared to trackers that log excessive user metadata. For a broader comparison of options, see our 2026 buyer's guide to URL shorteners.

5. Train Staff Regularly

Human error — phishing clicks, misaddressed emails, weak passwords — accounts for a large share of PDPC-reported incidents. Quarterly awareness training measurably reduces this.

6. Vet Data Intermediaries

Perform due diligence on vendors, require ISO 27001 or similar certifications where possible, and include strict breach notification clauses in contracts.

Communicating With Affected Individuals

When you must notify affected individuals, the message should be clear, timely, and actionable. Include:

  • What happened and when
  • What personal data was involved
  • Potential consequences for the individual
  • Steps the organisation has taken
  • Steps the individual should take (change passwords, monitor accounts, etc.)
  • Contact details for further questions

Avoid legalistic language. The PDPC has been critical of notifications that downplay severity or bury key facts. Where you send links to a breach information page, ensure the destination is secure, HTTPS-enabled, and free of unnecessary trackers.

Voluntary Notification and the PDPC's Response

Even when a breach is not strictly notifiable, voluntary notification can demonstrate good faith and is often viewed favourably during enforcement. The PDPC's Active Enforcement Framework rewards organisations that self-report, cooperate, and remediate promptly — often through Undertakings or expedited decisions with reduced penalties.

Frequently Asked Questions

How quickly must I report a data breach to PDPC Singapore?

You must notify the PDPC within 3 calendar days of determining that a breach is notifiable. The determination itself should be made within a reasonable and expeditious period, generally no more than 30 days from discovery.

What is the threshold for a notifiable data breach under the PDPA?

A breach is notifiable if it is likely to result in significant harm to individuals, or if it affects 500 or more individuals. Certain data types — such as NRIC combined with financial or health information — automatically meet the significant harm test.

Do I need to notify affected individuals as well as the PDPC?

Yes, if the breach meets the significant harm threshold. Notification to individuals is not required if remedial actions or technological protections make harm unlikely, or if the PDPC or a law enforcement agency directs you not to notify.

What happens if I fail to report a data breach?

Non-compliance can attract financial penalties of up to 10% of annual Singapore turnover or S$1 million, whichever is higher. The PDPC may also publish an enforcement decision naming the organisation, causing reputational damage.

Where do I actually submit the notification?

Submit via the PDPC's online e-Service portal at eservice.pdpc.gov.sg using CorpPass. There is a dedicated Data Breach Notification form that guides you through the required fields.

Final Thoughts

Reporting a data breach to the PDPC does not have to be chaotic. With a clear playbook, a designated DPO, and prepared templates, most organisations can meet the 3-day notification window comfortably. Prevention still matters most — encrypt sensitive data, vet vendors, and minimise the personal data you collect in the first place. When incidents do happen, transparency and speed are your strongest allies in maintaining trust with both regulators and customers.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles