How to Report a Data Breach to PDPC Singapore: A Complete 2026 Guide
A data breach is one of the most stressful events any Singapore organisation can face — and under the Personal Data Protection Act (PDPA), how you respond in the first 72 hours can make the difference between a manageable incident and a serious regulatory penalty. Since the Mandatory Data Breach Notification (MDBN) obligation came into force in February 2021, businesses of all sizes must know exactly when, how, and to whom they must report a qualifying breach.
This guide walks you through the entire process of reporting a data breach to the Personal Data Protection Commission (PDPC) Singapore — from the moment you detect the incident through post-notification obligations. Whether you run a small e-commerce store, a fintech startup, or a large enterprise, you'll find the exact thresholds, forms, and steps you need to comply with Singapore's data protection law.
What Is the PDPC and Why Data Breach Notification Matters
The Personal Data Protection Commission (PDPC) is Singapore's main regulator responsible for administering and enforcing the Personal Data Protection Act 2012 (PDPA). It oversees how organisations collect, use, disclose, and protect personal data of individuals in Singapore.
Under Part VIA of the PDPA, organisations must notify the PDPC — and in certain cases, affected individuals — when a data breach meets specific thresholds. Failure to notify a notifiable breach can result in financial penalties of up to S$1 million, or 10% of annual turnover in Singapore for organisations with revenue above S$10 million (whichever is higher).
Beyond the legal risk, prompt and transparent breach reporting protects your customers, preserves brand trust, and demonstrates good governance to partners, investors, and auditors.
When Is a Data Breach Notifiable Under the PDPA?
Not every data breach must be reported. Under Section 26B of the PDPA, a breach is notifiable if it meets either of these two criteria:
- Significant harm threshold: The breach results in, or is likely to result in, significant harm to affected individuals.
- Significant scale threshold: The breach affects, or is likely to affect, 500 or more individuals.
What Counts as "Significant Harm"?
The PDPC has prescribed categories of personal data whose unauthorised access or disclosure is deemed to cause significant harm. These include:
- Full name or alias combined with NRIC/FIN/passport number
- Financial account details (bank account, credit/debit card numbers)
- Health information, medical history, or diagnoses
- Life, accident, and health insurance data
- Information relating to adoption, sexual orientation, or private life
- Login credentials granting access to accounts containing the above
Common Examples of Notifiable Breaches
- A ransomware attack encrypting a customer database of 1,200 records
- An employee accidentally emailing a spreadsheet with 800 NRIC numbers to the wrong recipient
- A misconfigured cloud storage bucket exposing scanned identity documents
- A phishing incident leading to unauthorised access to payroll systems
The Mandatory Timeline: 30 Days and 72 Hours
Timelines are the most misunderstood part of the notification obligation. Here's what you need to remember:
| Action | Deadline | Trigger |
|---|---|---|
| Complete internal assessment | Within 30 calendar days | From the day you have reason to believe a breach occurred |
| Notify the PDPC | As soon as practicable, but no later than 3 calendar days (72 hours) | After you assess the breach is notifiable |
| Notify affected individuals | On or after PDPC notification, as soon as practicable | If the breach is likely to cause significant harm |
You do not need to notify affected individuals if remedial action prevents significant harm, or if the compromised data was encrypted to a standard that renders it unintelligible.
Step-by-Step: How to Report a Data Breach to PDPC
Step 1: Contain the Breach Immediately
Before any paperwork, stop the bleeding. Isolate affected systems, revoke compromised credentials, disable suspicious accounts, and preserve logs and forensic evidence. Document every containment action with timestamps — the PDPC will ask about this in the notification form.
Step 2: Assess Whether the Breach Is Notifiable
Convene your Data Protection Officer (DPO), IT, and legal teams. Assess:
- What personal data was involved?
- How many individuals are affected?
- Does the data fall within the "significant harm" categories?
- Was the data encrypted or otherwise protected?
- What is the likelihood of misuse?
You must complete this assessment within 30 days of first suspecting a breach.
Step 3: Prepare Your Notification
Gather the information PDPC requires:
- Organisation details and DPO contact information
- Date, time, and duration of the breach
- Cause and circumstances of the breach
- Type and volume of personal data involved
- Number and categories of affected individuals
- Potential harm to individuals
- Remedial actions taken and planned
- Plan for notifying affected individuals (if applicable)
Step 4: Submit the Notification via the PDPC Website
Notifications are submitted through the official PDPC Data Breach Notification form on pdpc.gov.sg. Navigate to "Report a Data Breach" and complete the online form. You will need CorpPass to log in on behalf of your organisation.
If you don't yet have all the details within 72 hours, submit what you know and update the PDPC as investigations progress. Delay in complete information is not an excuse to miss the deadline.
Step 5: Notify Affected Individuals (If Required)
If the breach is likely to cause significant harm, notify affected individuals in a clear, plain-language manner. Include:
- What happened and when
- What data was involved
- What steps you're taking
- What they should do (e.g., change passwords, monitor accounts)
- Who to contact for questions
Step 6: Cooperate With PDPC Follow-Up
Once notified, PDPC may request additional information, conduct interviews, or open an investigation. Respond promptly and preserve all evidence. Cooperation and demonstrable remediation often result in more lenient outcomes.
What to Include in the Notification Form
The PDPC's online form is structured into clearly labelled sections. Here's what to prepare in advance so you can complete it in one sitting:
| Section | Details Required |
|---|---|
| Organisation Information | UEN, business name, industry, DPO name and contact |
| Breach Overview | Discovery date, incident date, breach duration |
| Nature of Breach | Cause (cyberattack, human error, system fault), attack vector |
| Data Affected | Categories (contact, financial, health, ID), volume, encryption status |
| Affected Individuals | Number, categories (customers, employees, minors) |
| Impact Assessment | Potential harm, likelihood of misuse |
| Remedial Actions | Containment, mitigation, preventive measures |
| Communication Plan | How and when affected individuals will be notified |
Common Mistakes Organisations Make
- Waiting for full investigation before notifying. The 72-hour clock starts when you conclude the breach is notifiable, not when you know every detail.
- Underestimating the scale. Counting only confirmed victims rather than potentially affected records.
- Assuming encryption exempts you. Only encryption that renders data unintelligible to unauthorised parties qualifies, and PDPC may still expect notification.
- Sending vague notifications to individuals. Generic emails erode trust and may be deemed inadequate.
- Not appointing a DPO. Every organisation in Singapore must have a DPO — and their contact must be publicly available.
Preventing the Next Breach: Practical Security Measures
Reporting is a legal duty; prevention is a business imperative. Practical steps that meaningfully reduce breach risk include:
- Enforce multi-factor authentication (MFA) across all admin, email, and cloud accounts.
- Encrypt personal data at rest and in transit using industry-standard algorithms.
- Minimise data collection. If you don't collect it, you can't leak it.
- Run quarterly access reviews. Remove dormant accounts and stale permissions.
- Deploy encrypted DNS and network-level filtering to block malicious domains before employees click.
- Train staff every six months on phishing, social engineering, and secure handling of personal data.
- Monitor shortened and redirected links. Attackers often disguise malicious URLs, so use trusted link management platforms like Lunyb that provide analytics, expiry controls, and safe-link previews to help teams share URLs without exposing themselves to hidden redirects.
- Maintain an incident response playbook that includes PDPC notification templates and contact trees.
For teams that publish or share many external links — marketing, support, HR — using a professional shortener with tracking and access controls can materially reduce phishing risk. If you're evaluating options, see our 2026 buyer's guide to URL shorteners and our honest review of Lunyb.
Penalties for Non-Compliance
Since October 2022, PDPC has been empowered to impose the higher of:
- S$1 million, or
- 10% of an organisation's annual turnover in Singapore, if that turnover exceeds S$10 million.
Beyond fines, PDPC can issue directions to stop collecting data, destroy unlawfully obtained data, or publish a public apology. Enforcement decisions are published on the PDPC website, creating lasting reputational impact.
Special Situations
Breaches Involving Data Intermediaries
If a vendor or processor (data intermediary) suffers a breach, they must notify you "without undue delay." As the data controller, you remain responsible for notifying PDPC and affected individuals. Ensure your vendor contracts include breach notification clauses with tight timelines (ideally 24 hours).
Cross-Border Breaches
If personal data of Singapore residents is breached overseas — for example, at a cloud provider in the EU — Singapore's PDPA still applies. You may also have GDPR or other foreign obligations. Coordinate legal counsel across jurisdictions.
Small Businesses and Sole Proprietors
There is no size exemption. Even a one-person business collecting personal data must comply with the MDBN. However, PDPC generally considers proportionality when assessing penalties.
Frequently Asked Questions
1. How long do I have to report a data breach to PDPC Singapore?
You must notify PDPC as soon as practicable, and no later than 3 calendar days (72 hours) after you assess that the breach is notifiable. You have up to 30 days from initial discovery to complete that assessment, but delaying the assessment unreasonably may itself be a breach of the PDPA.
2. What if fewer than 500 people are affected — do I still need to notify?
Yes, if the breach is likely to cause significant harm — for example, if it exposes NRIC numbers, financial account details, or health data — you must notify PDPC and affected individuals regardless of the number. The 500-individual threshold is an alternative trigger, not a minimum.
3. Do I have to notify affected individuals if I've already notified PDPC?
Yes, if the breach is likely to result in significant harm to those individuals. However, you're exempt if you've taken remedial action that eliminates the risk of harm, or if the compromised data was strongly encrypted and the keys were not exposed. PDPC may also waive individual notification in specific circumstances such as ongoing law enforcement investigations.
4. What information do I need before submitting the notification form?
At minimum: your organisation and DPO details, the date and duration of the breach, its cause, the type and volume of personal data involved, the number of affected individuals, potential harm, and remedial actions taken. If you don't have complete information within 72 hours, submit what you know and update PDPC as your investigation progresses.
5. Can I be penalised even if the breach wasn't my fault?
Yes. The PDPA holds organisations accountable for reasonable security arrangements. If a breach occurred because of inadequate safeguards — even due to third-party negligence or employee error — PDPC can impose financial penalties. Demonstrating strong pre-breach controls, prompt notification, and effective remediation are the most reliable ways to mitigate penalties.
Final Thoughts
Reporting a data breach to PDPC Singapore isn't just a compliance checkbox — it's a critical part of maintaining customer trust and protecting your business. The key takeaways: assess quickly (30 days), notify quickly (72 hours), be transparent with affected individuals, and invest in prevention so you rarely need to use this playbook.
Build your incident response plan today, appoint (and empower) your DPO, and treat every piece of personal data your organisation holds as a liability worth protecting. When the next breach happens — and statistically, it will — you'll be ready.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Set Up Link Retargeting: A Complete Step-by-Step Guide
Link retargeting lets you build ad audiences from clicks on any URL you share — even third-party content. This step-by-step guide walks you through pixel setup, platform comparisons, compliance, and advanced tactics for scaling campaigns.
How to Remove Your Data from the Internet: A Complete 2026 Guide
Learn how to remove your data from the internet with this step-by-step guide. Discover how to opt out of data brokers, delete old accounts, scrub search results, and lock down your digital footprint for good.
How to Lock Apps and Photos with Face ID: Complete 2026 Guide
Learn how to lock apps and photos with Face ID on your iPhone using iOS 18's built-in features. This step-by-step guide covers per-app locking, hidden albums, and best practices for keeping your private content secure.
How to Remove Your Personal Information from Data Brokers: Complete 2026 Guide
Data brokers collect and sell your personal information to anyone willing to pay. This step-by-step 2026 guide shows exactly how to remove your data from major people-search sites, exercise your legal rights, and keep your information off the web long-term.