How to Report a Data Breach to PDPC Singapore: Complete 2026 Guide
If your organisation has suffered a personal data breach in Singapore, notifying the Personal Data Protection Commission (PDPC) is not optional — it is a legal obligation under the Personal Data Protection Act (PDPA). Since the Mandatory Data Breach Notification obligation took effect on 1 February 2021, businesses that process personal data in Singapore must assess, escalate, and report qualifying breaches within strict timelines.
This guide walks you through exactly how to report a data breach to PDPC, when notification is required, what information to prepare, and how to manage communications with affected individuals. Whether you are an SME, a multinational, or a data intermediary, following this process correctly can significantly reduce your regulatory risk and reputational damage.
What Counts as a Data Breach Under the PDPA?
A data breach under Singapore's PDPA is any unauthorised access, collection, use, disclosure, copying, modification, disposal, or loss of personal data in an organisation's possession or control. It can be accidental (e.g. an email sent to the wrong recipient) or malicious (e.g. a ransomware attack).
Common examples include:
- Hacking or unauthorised access to databases and cloud storage
- Lost or stolen laptops, USB drives, or mobile devices containing personal data
- Misconfigured servers exposing customer records publicly
- Phishing attacks compromising employee email accounts
- Insider misuse or accidental disclosure of personal data
- Ransomware encrypting personal data files
When Must You Notify the PDPC?
Under Section 26D of the PDPA, an organisation must notify the PDPC of a notifiable data breach as soon as practicable, but no later than 3 calendar days after determining that the breach is notifiable. A breach is considered notifiable if it meets either of these thresholds:
- Significant harm threshold: The breach results in, or is likely to result in, significant harm to affected individuals. This includes financial loss, identity theft, physical harm, or damage to reputation.
- Significant scale threshold: The breach affects, or is likely to affect, 500 or more individuals.
The PDPC's Personal Data Protection (Notification of Data Breaches) Regulations 2021 also prescribe categories of personal data that automatically trigger the "significant harm" test, such as full name combined with NRIC/FIN, financial account details, health information, or account credentials.
Breaches That Do Not Require Notification
You are not required to notify the PDPC if:
- Remedial action taken renders it unlikely the breach will result in significant harm (e.g. data was encrypted and keys were not compromised)
- Technological protections make the data unintelligible or inaccessible to unauthorised parties
- The breach only involves employee personal data within the same organisation
However, you must still document the breach internally and be able to justify your assessment if audited.
Step-by-Step: How to Report a Data Breach to PDPC
Step 1: Contain the Breach Immediately
Before notification, take urgent steps to stop the breach and prevent further data loss. Actions may include:
- Isolating affected systems from the network
- Revoking compromised credentials and access tokens
- Shutting down or patching vulnerable services
- Recovering lost devices or data where possible
- Preserving logs and forensic evidence
Step 2: Assess the Breach Within 30 Days
You have up to 30 days to conduct a reasonable and expeditious assessment to determine whether the breach is notifiable. During assessment, evaluate:
- The type and volume of personal data involved
- The cause and extent of the breach
- Whether affected data is encrypted or otherwise protected
- Number of individuals affected
- Likelihood of significant harm
Step 3: Notify the PDPC Within 3 Days
Once you determine the breach is notifiable, submit your notification within 3 calendar days via the PDPC's online Data Breach Notification form at eservice.pdpc.gov.sg. Log in using CorpPass to access the form.
Step 4: Notify Affected Individuals
If the breach meets the significant harm threshold, you must also notify affected individuals on or after notifying the PDPC. Notification to individuals is not required if:
- The PDPC directs you not to notify
- A prescribed law enforcement agency instructs you not to
- Remedial actions render harm unlikely, or the data is protected by technological measures
Step 5: Document and Remediate
Maintain a full internal record of the breach, your assessment, notifications made, and remedial steps. The PDPC may request this documentation during any subsequent investigation.
Information You Need to Submit
The PDPC's online notification form requires detailed information. Prepare the following before you start:
| Category | Details Required |
|---|---|
| Organisation Details | Legal name, UEN, industry sector, DPO contact information |
| Breach Description | Date and time of breach, date discovered, how it was discovered, cause |
| Personal Data Involved | Types of data (NRIC, financial, health, etc.), volume, format |
| Affected Individuals | Estimated number, categories (customers, employees, minors) |
| Impact Assessment | Likely harm, whether data was encrypted, risk to individuals |
| Containment Actions | Immediate steps taken, systems isolated, credentials reset |
| Remediation Plan | Long-term measures, staff training, technical improvements |
| Individual Notification | Whether/when individuals will be notified, communication channels |
Timeline Summary: PDPA Data Breach Obligations
| Stage | Timeline | Action |
|---|---|---|
| Discovery | Day 0 | Detect and contain the breach |
| Assessment | Within 30 days | Determine if the breach is notifiable |
| PDPC Notification | Within 3 calendar days of determination | Submit online notification form |
| Individual Notification | On or after PDPC notification | Inform affected individuals if significant harm applies |
| Data Intermediary Duty | Without undue delay | Notify the main organisation of any breach |
Special Rules for Data Intermediaries
A data intermediary (i.e. a vendor processing personal data on behalf of another organisation) has a separate obligation. Under Section 26C, it must notify the organisation it works for without undue delay upon becoming aware of a breach. The main organisation, not the intermediary, is responsible for assessing and notifying the PDPC.
Cloud providers, IT outsourcing firms, marketing agencies, and payroll processors typically fall under this category. Contracts should clearly define breach notification timelines, ideally 24–48 hours.
Penalties for Non-Compliance
Failure to comply with the mandatory data breach notification obligation can trigger significant financial penalties. Since 1 October 2022, the PDPC has been empowered to impose financial penalties of up to:
- 10% of an organisation's annual turnover in Singapore, or
- S$1 million, whichever is higher
Recent enforcement decisions have shown the PDPC is willing to publish decisions naming organisations, which can cause substantial reputational damage on top of the fine.
Best Practices to Prepare Before a Breach Happens
Organisations that handle breaches well are almost always the ones that prepared in advance. Consider these practices:
1. Appoint a Data Protection Officer (DPO)
Every organisation in Singapore is required to appoint at least one DPO and register their business contact information with ACRA. The DPO leads breach response.
2. Maintain a Breach Response Playbook
Document clear roles, escalation paths, decision criteria for notification, template communications, and legal contacts. Rehearse it annually with tabletop exercises.
3. Encrypt Personal Data at Rest and in Transit
Strong encryption is one of the strongest defences against a breach becoming notifiable. If data is unintelligible to attackers, notification to individuals may not be required.
4. Secure Your Marketing and Web Assets
Many breaches originate from third-party tools — link trackers, form builders, email platforms. Choose vendors that publish clear security practices. For example, when sharing campaign links, using a privacy-conscious link management platform like Lunyb can reduce data exposure compared to trackers that log excessive user metadata. For a broader comparison of options, see our 2026 buyer's guide to URL shorteners.
5. Train Staff Regularly
Human error — phishing clicks, misaddressed emails, weak passwords — accounts for a large share of PDPC-reported incidents. Quarterly awareness training measurably reduces this.
6. Vet Data Intermediaries
Perform due diligence on vendors, require ISO 27001 or similar certifications where possible, and include strict breach notification clauses in contracts.
Communicating With Affected Individuals
When you must notify affected individuals, the message should be clear, timely, and actionable. Include:
- What happened and when
- What personal data was involved
- Potential consequences for the individual
- Steps the organisation has taken
- Steps the individual should take (change passwords, monitor accounts, etc.)
- Contact details for further questions
Avoid legalistic language. The PDPC has been critical of notifications that downplay severity or bury key facts. Where you send links to a breach information page, ensure the destination is secure, HTTPS-enabled, and free of unnecessary trackers.
Voluntary Notification and the PDPC's Response
Even when a breach is not strictly notifiable, voluntary notification can demonstrate good faith and is often viewed favourably during enforcement. The PDPC's Active Enforcement Framework rewards organisations that self-report, cooperate, and remediate promptly — often through Undertakings or expedited decisions with reduced penalties.
Frequently Asked Questions
How quickly must I report a data breach to PDPC Singapore?
You must notify the PDPC within 3 calendar days of determining that a breach is notifiable. The determination itself should be made within a reasonable and expeditious period, generally no more than 30 days from discovery.
What is the threshold for a notifiable data breach under the PDPA?
A breach is notifiable if it is likely to result in significant harm to individuals, or if it affects 500 or more individuals. Certain data types — such as NRIC combined with financial or health information — automatically meet the significant harm test.
Do I need to notify affected individuals as well as the PDPC?
Yes, if the breach meets the significant harm threshold. Notification to individuals is not required if remedial actions or technological protections make harm unlikely, or if the PDPC or a law enforcement agency directs you not to notify.
What happens if I fail to report a data breach?
Non-compliance can attract financial penalties of up to 10% of annual Singapore turnover or S$1 million, whichever is higher. The PDPC may also publish an enforcement decision naming the organisation, causing reputational damage.
Where do I actually submit the notification?
Submit via the PDPC's online e-Service portal at eservice.pdpc.gov.sg using CorpPass. There is a dedicated Data Breach Notification form that guides you through the required fields.
Final Thoughts
Reporting a data breach to the PDPC does not have to be chaotic. With a clear playbook, a designated DPO, and prepared templates, most organisations can meet the 3-day notification window comfortably. Prevention still matters most — encrypt sensitive data, vet vendors, and minimise the personal data you collect in the first place. When incidents do happen, transparency and speed are your strongest allies in maintaining trust with both regulators and customers.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Protect Your Privacy Online in 2026: The Complete Guide
A practical 2026 guide to protecting your privacy online, covering browser hardening, encrypted DNS, password hygiene, safer link sharing, and mobile security. Includes step-by-step instructions, tool comparisons, and a sustainable privacy routine anyone can follow.
How to Set Up Link Retargeting: A Complete 2026 Guide
Link retargeting lets you serve ads to anyone who clicks your shortened URLs — even when they lead to third-party pages. This step-by-step guide shows you how to attach retargeting pixels, build custom audiences, and launch profitable campaigns across Meta, Google, LinkedIn, and TikTok.
How to Encrypt Your Internet Traffic: A Complete 2026 Guide
Learn how to encrypt your internet traffic across every layer — from HTTPS and encrypted DNS to Tor and full-disk encryption. This practical 2026 guide walks you through step-by-step protections for browsing, messaging, and everyday privacy.
How to Create Branded Short Links: A Complete 2026 Guide
Branded short links boost click-through rates, build trust, and reinforce your brand every time someone shares a URL. This step-by-step guide walks you through registering a short domain, connecting it to a link shortener, and creating your first branded link.