facebook-pixel

How to Report a Data Breach to PDPC Singapore: A Complete 2026 Guide

L
Lunyb Security Team
··10 min read

A data breach is one of the most stressful events any Singapore organisation can face — and under the Personal Data Protection Act (PDPA), how you respond in the first 72 hours can make the difference between a manageable incident and a serious regulatory penalty. Since the Mandatory Data Breach Notification (MDBN) obligation came into force in February 2021, businesses of all sizes must know exactly when, how, and to whom they must report a qualifying breach.

This guide walks you through the entire process of reporting a data breach to the Personal Data Protection Commission (PDPC) Singapore — from the moment you detect the incident through post-notification obligations. Whether you run a small e-commerce store, a fintech startup, or a large enterprise, you'll find the exact thresholds, forms, and steps you need to comply with Singapore's data protection law.

What Is the PDPC and Why Data Breach Notification Matters

The Personal Data Protection Commission (PDPC) is Singapore's main regulator responsible for administering and enforcing the Personal Data Protection Act 2012 (PDPA). It oversees how organisations collect, use, disclose, and protect personal data of individuals in Singapore.

Under Part VIA of the PDPA, organisations must notify the PDPC — and in certain cases, affected individuals — when a data breach meets specific thresholds. Failure to notify a notifiable breach can result in financial penalties of up to S$1 million, or 10% of annual turnover in Singapore for organisations with revenue above S$10 million (whichever is higher).

Beyond the legal risk, prompt and transparent breach reporting protects your customers, preserves brand trust, and demonstrates good governance to partners, investors, and auditors.

When Is a Data Breach Notifiable Under the PDPA?

Not every data breach must be reported. Under Section 26B of the PDPA, a breach is notifiable if it meets either of these two criteria:

  1. Significant harm threshold: The breach results in, or is likely to result in, significant harm to affected individuals.
  2. Significant scale threshold: The breach affects, or is likely to affect, 500 or more individuals.

What Counts as "Significant Harm"?

The PDPC has prescribed categories of personal data whose unauthorised access or disclosure is deemed to cause significant harm. These include:

  • Full name or alias combined with NRIC/FIN/passport number
  • Financial account details (bank account, credit/debit card numbers)
  • Health information, medical history, or diagnoses
  • Life, accident, and health insurance data
  • Information relating to adoption, sexual orientation, or private life
  • Login credentials granting access to accounts containing the above

Common Examples of Notifiable Breaches

  • A ransomware attack encrypting a customer database of 1,200 records
  • An employee accidentally emailing a spreadsheet with 800 NRIC numbers to the wrong recipient
  • A misconfigured cloud storage bucket exposing scanned identity documents
  • A phishing incident leading to unauthorised access to payroll systems

The Mandatory Timeline: 30 Days and 72 Hours

Timelines are the most misunderstood part of the notification obligation. Here's what you need to remember:

ActionDeadlineTrigger
Complete internal assessmentWithin 30 calendar daysFrom the day you have reason to believe a breach occurred
Notify the PDPCAs soon as practicable, but no later than 3 calendar days (72 hours)After you assess the breach is notifiable
Notify affected individualsOn or after PDPC notification, as soon as practicableIf the breach is likely to cause significant harm

You do not need to notify affected individuals if remedial action prevents significant harm, or if the compromised data was encrypted to a standard that renders it unintelligible.

Step-by-Step: How to Report a Data Breach to PDPC

Step 1: Contain the Breach Immediately

Before any paperwork, stop the bleeding. Isolate affected systems, revoke compromised credentials, disable suspicious accounts, and preserve logs and forensic evidence. Document every containment action with timestamps — the PDPC will ask about this in the notification form.

Step 2: Assess Whether the Breach Is Notifiable

Convene your Data Protection Officer (DPO), IT, and legal teams. Assess:

  1. What personal data was involved?
  2. How many individuals are affected?
  3. Does the data fall within the "significant harm" categories?
  4. Was the data encrypted or otherwise protected?
  5. What is the likelihood of misuse?

You must complete this assessment within 30 days of first suspecting a breach.

Step 3: Prepare Your Notification

Gather the information PDPC requires:

  • Organisation details and DPO contact information
  • Date, time, and duration of the breach
  • Cause and circumstances of the breach
  • Type and volume of personal data involved
  • Number and categories of affected individuals
  • Potential harm to individuals
  • Remedial actions taken and planned
  • Plan for notifying affected individuals (if applicable)

Step 4: Submit the Notification via the PDPC Website

Notifications are submitted through the official PDPC Data Breach Notification form on pdpc.gov.sg. Navigate to "Report a Data Breach" and complete the online form. You will need CorpPass to log in on behalf of your organisation.

If you don't yet have all the details within 72 hours, submit what you know and update the PDPC as investigations progress. Delay in complete information is not an excuse to miss the deadline.

Step 5: Notify Affected Individuals (If Required)

If the breach is likely to cause significant harm, notify affected individuals in a clear, plain-language manner. Include:

  • What happened and when
  • What data was involved
  • What steps you're taking
  • What they should do (e.g., change passwords, monitor accounts)
  • Who to contact for questions

Step 6: Cooperate With PDPC Follow-Up

Once notified, PDPC may request additional information, conduct interviews, or open an investigation. Respond promptly and preserve all evidence. Cooperation and demonstrable remediation often result in more lenient outcomes.

What to Include in the Notification Form

The PDPC's online form is structured into clearly labelled sections. Here's what to prepare in advance so you can complete it in one sitting:

SectionDetails Required
Organisation InformationUEN, business name, industry, DPO name and contact
Breach OverviewDiscovery date, incident date, breach duration
Nature of BreachCause (cyberattack, human error, system fault), attack vector
Data AffectedCategories (contact, financial, health, ID), volume, encryption status
Affected IndividualsNumber, categories (customers, employees, minors)
Impact AssessmentPotential harm, likelihood of misuse
Remedial ActionsContainment, mitigation, preventive measures
Communication PlanHow and when affected individuals will be notified

Common Mistakes Organisations Make

  • Waiting for full investigation before notifying. The 72-hour clock starts when you conclude the breach is notifiable, not when you know every detail.
  • Underestimating the scale. Counting only confirmed victims rather than potentially affected records.
  • Assuming encryption exempts you. Only encryption that renders data unintelligible to unauthorised parties qualifies, and PDPC may still expect notification.
  • Sending vague notifications to individuals. Generic emails erode trust and may be deemed inadequate.
  • Not appointing a DPO. Every organisation in Singapore must have a DPO — and their contact must be publicly available.

Preventing the Next Breach: Practical Security Measures

Reporting is a legal duty; prevention is a business imperative. Practical steps that meaningfully reduce breach risk include:

  1. Enforce multi-factor authentication (MFA) across all admin, email, and cloud accounts.
  2. Encrypt personal data at rest and in transit using industry-standard algorithms.
  3. Minimise data collection. If you don't collect it, you can't leak it.
  4. Run quarterly access reviews. Remove dormant accounts and stale permissions.
  5. Deploy encrypted DNS and network-level filtering to block malicious domains before employees click.
  6. Train staff every six months on phishing, social engineering, and secure handling of personal data.
  7. Monitor shortened and redirected links. Attackers often disguise malicious URLs, so use trusted link management platforms like Lunyb that provide analytics, expiry controls, and safe-link previews to help teams share URLs without exposing themselves to hidden redirects.
  8. Maintain an incident response playbook that includes PDPC notification templates and contact trees.

For teams that publish or share many external links — marketing, support, HR — using a professional shortener with tracking and access controls can materially reduce phishing risk. If you're evaluating options, see our 2026 buyer's guide to URL shorteners and our honest review of Lunyb.

Penalties for Non-Compliance

Since October 2022, PDPC has been empowered to impose the higher of:

  • S$1 million, or
  • 10% of an organisation's annual turnover in Singapore, if that turnover exceeds S$10 million.

Beyond fines, PDPC can issue directions to stop collecting data, destroy unlawfully obtained data, or publish a public apology. Enforcement decisions are published on the PDPC website, creating lasting reputational impact.

Special Situations

Breaches Involving Data Intermediaries

If a vendor or processor (data intermediary) suffers a breach, they must notify you "without undue delay." As the data controller, you remain responsible for notifying PDPC and affected individuals. Ensure your vendor contracts include breach notification clauses with tight timelines (ideally 24 hours).

Cross-Border Breaches

If personal data of Singapore residents is breached overseas — for example, at a cloud provider in the EU — Singapore's PDPA still applies. You may also have GDPR or other foreign obligations. Coordinate legal counsel across jurisdictions.

Small Businesses and Sole Proprietors

There is no size exemption. Even a one-person business collecting personal data must comply with the MDBN. However, PDPC generally considers proportionality when assessing penalties.

Frequently Asked Questions

1. How long do I have to report a data breach to PDPC Singapore?

You must notify PDPC as soon as practicable, and no later than 3 calendar days (72 hours) after you assess that the breach is notifiable. You have up to 30 days from initial discovery to complete that assessment, but delaying the assessment unreasonably may itself be a breach of the PDPA.

2. What if fewer than 500 people are affected — do I still need to notify?

Yes, if the breach is likely to cause significant harm — for example, if it exposes NRIC numbers, financial account details, or health data — you must notify PDPC and affected individuals regardless of the number. The 500-individual threshold is an alternative trigger, not a minimum.

3. Do I have to notify affected individuals if I've already notified PDPC?

Yes, if the breach is likely to result in significant harm to those individuals. However, you're exempt if you've taken remedial action that eliminates the risk of harm, or if the compromised data was strongly encrypted and the keys were not exposed. PDPC may also waive individual notification in specific circumstances such as ongoing law enforcement investigations.

4. What information do I need before submitting the notification form?

At minimum: your organisation and DPO details, the date and duration of the breach, its cause, the type and volume of personal data involved, the number of affected individuals, potential harm, and remedial actions taken. If you don't have complete information within 72 hours, submit what you know and update PDPC as your investigation progresses.

5. Can I be penalised even if the breach wasn't my fault?

Yes. The PDPA holds organisations accountable for reasonable security arrangements. If a breach occurred because of inadequate safeguards — even due to third-party negligence or employee error — PDPC can impose financial penalties. Demonstrating strong pre-breach controls, prompt notification, and effective remediation are the most reliable ways to mitigate penalties.

Final Thoughts

Reporting a data breach to PDPC Singapore isn't just a compliance checkbox — it's a critical part of maintaining customer trust and protecting your business. The key takeaways: assess quickly (30 days), notify quickly (72 hours), be transparent with affected individuals, and invest in prevention so you rarely need to use this playbook.

Build your incident response plan today, appoint (and empower) your DPO, and treat every piece of personal data your organisation holds as a liability worth protecting. When the next breach happens — and statistically, it will — you'll be ready.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles