facebook-pixel

How to Report a Data Breach to PDPC Singapore: A Complete 2026 Guide

L
Lunyb Security Team
··9 min read

Reporting a data breach to Singapore's Personal Data Protection Commission (PDPC) is a legal obligation under the Personal Data Protection Act (PDPA). Since the mandatory data breach notification regime came into force on 1 February 2021, every organisation handling personal data in Singapore must know exactly when, how, and what to report. This guide walks you through the entire process, from assessing whether a breach is notifiable to submitting the official form and managing the aftermath.

What Counts as a Notifiable Data Breach in Singapore?

Under Section 26A of the PDPA, a data breach is any unauthorised access, collection, use, disclosure, copying, modification, or disposal of personal data, or the loss of storage media containing personal data. However, not every breach must be reported to the PDPC.

A breach becomes notifiable if it meets either of these two thresholds:

  1. Significant harm threshold: The breach is likely to result in significant harm to affected individuals (financial loss, identity theft, physical harm, damage to reputation, or loss of employment).
  2. Significant scale threshold: The breach affects 500 or more individuals, regardless of harm assessment.

Data Types Deemed to Cause Significant Harm

The Personal Data Protection (Notification of Data Breaches) Regulations 2021 prescribe categories of personal data that are automatically deemed to cause significant harm if compromised, including:

  • NRIC, FIN, passport, or work permit numbers
  • Full bank account or credit card details
  • Health and medical records
  • Life insurance information
  • Adoption records, criminal records, or private key data used for authentication

Timeline: When Must You Report a Data Breach to PDPC?

The PDPA imposes strict statutory deadlines. Missing these can result in enforcement action and financial penalties of up to S$1 million or 10% of annual turnover in Singapore (whichever is higher) for organisations with turnover exceeding S$10 million.

ActionDeadlineTrigger Event
Assess whether breach is notifiableWithin 30 calendar daysAwareness of a possible breach
Notify PDPCAs soon as practicable, no later than 3 calendar daysConfirmation that breach is notifiable
Notify affected individualsOn or after PDPC notificationConfirmation of significant harm
Data intermediary informs controllerWithout undue delayAwareness of a breach

Step-by-Step: How to Report a Data Breach to PDPC

Follow this structured seven-step process to ensure full compliance with the PDPA's notification obligations.

Step 1: Contain the Breach Immediately

Before anything else, stop the bleeding. Isolate affected systems, revoke compromised credentials, disable exposed accounts, and preserve evidence for forensic analysis. Document every containment action with timestamps.

Step 2: Convene Your Data Breach Response Team

Activate your incident response plan. The team typically includes your Data Protection Officer (DPO), IT security lead, legal counsel, communications, and senior management. If you do not yet have a DPO, appoint one immediately—this is a separate PDPA requirement under Section 11(3).

Step 3: Assess the Breach

Conduct a thorough assessment within 30 days to determine:

  1. What personal data was affected and in what volume
  2. How many individuals are impacted
  3. The cause and nature of the breach
  4. Whether prescribed harmful data categories are involved
  5. Likely consequences for affected individuals
  6. Remedial actions already taken or planned

Step 4: Determine Notification Obligations

If your assessment confirms either the significant harm or 500-individual threshold is met, notification to PDPC is mandatory. If only the significant harm threshold applies, you must also notify affected individuals. The 500-individual threshold alone does not automatically require individual notification—but it is strongly recommended.

Step 5: Submit the Notification via PDPC's Online Form

PDPC accepts notifications through their official Data Breach Notification Form available at pdpc.gov.sg. You'll need to provide:

  • Organisation details and DPO contact information
  • Date and time of breach discovery
  • Description of the breach and its cause
  • Types and volume of personal data affected
  • Number of affected individuals
  • Potential harm assessment
  • Containment and remediation measures
  • Plan for notifying individuals

If full information isn't available within 3 days, submit an initial notification and follow up with updates. PDPC prefers timely partial reporting over delayed complete reporting.

Step 6: Notify Affected Individuals

Where required, notify individuals in a clear, understandable manner. The notification should include: what happened, what data was involved, likely consequences, what you're doing about it, what they can do to protect themselves, and contact details for further queries.

Step 7: Document Everything and Review

Maintain a comprehensive breach register including timelines, decisions, communications, and post-incident reviews. PDPC may request this documentation during investigations.

Exceptions: When You Don't Need to Notify Individuals

Even when a breach is notifiable to PDPC, you may be exempt from notifying individuals in specific circumstances:

  • Technological protection: The personal data was encrypted or otherwise rendered unintelligible to unauthorised parties.
  • Remedial action taken: You have taken action that renders it unlikely the breach will result in significant harm (e.g., successfully retrieving lost media before access).
  • Law enforcement request: A prescribed law enforcement agency has instructed you to delay notification.
  • PDPC waiver: The Commission has directed that notification is not required.

Common Data Breach Scenarios in Singapore

Phishing and Credential Compromise

Employee credentials compromised through phishing remain the most common cause. If attackers accessed customer databases containing NRIC numbers, this is automatically notifiable regardless of scale.

Ransomware Attacks

Modern ransomware typically involves data exfiltration before encryption. Even if you restore from backups, the exfiltration itself is a reportable breach.

Misconfigured Cloud Storage

Publicly exposed S3 buckets or misconfigured databases have caused several high-profile Singapore breaches. Assessment must consider whether unauthorised access actually occurred, not just whether it was possible.

Insider Threats and Accidental Disclosure

Emails sent to wrong recipients, lost laptops, or employees exfiltrating data all qualify. The threshold assessment applies equally.

Preventive Measures: Reducing Breach Risk

The best breach response is prevention. Under the PDPA's Protection Obligation (Section 24), organisations must make reasonable security arrangements. Consider these baseline controls:

  1. Encrypt data at rest and in transit — encrypted data that's compromised often qualifies for the individual notification exception.
  2. Implement multi-factor authentication across all systems handling personal data.
  3. Use encrypted DNS and secure network segmentation to limit lateral movement if perimeter defences fail.
  4. Audit third-party links and integrations — malicious redirects can exfiltrate session data. Use a trusted link management platform like Lunyb to control, monitor, and audit outbound URLs your organisation shares, reducing phishing risk and providing an audit trail.
  5. Conduct annual DPIAs (Data Protection Impact Assessments) for high-risk processing.
  6. Run tabletop breach exercises at least twice yearly.
  7. Maintain an up-to-date data inventory so you can quickly scope the impact of any incident.

Penalties for Non-Compliance

Failing to notify PDPC of a notifiable breach, or failing to notify affected individuals when required, is a breach of the PDPA. Since the amendments took effect, PDPC has issued increased financial penalties:

  • Up to S$1 million for organisations with Singapore turnover below S$10 million
  • Up to 10% of annual Singapore turnover for larger organisations
  • Directions to remedy non-compliance
  • Public listing of enforcement decisions—significant reputational damage

Data Intermediaries: Special Considerations

Data intermediaries (processors handling data on behalf of another organisation) have distinct obligations. When a data intermediary becomes aware of a breach, it must notify the data controller without undue delay. The controller then bears the primary responsibility for PDPC notification. Ensure your data processing agreements clearly specify:

  • Notification timelines from intermediary to controller
  • Information the intermediary must provide
  • Cooperation obligations during investigation
  • Allocation of remediation costs

Building an Effective Data Breach Response Plan

A written Data Breach Management Plan should be a living document. Key components include:

  1. Roles and responsibilities — named individuals, not just titles
  2. Escalation matrix — clear criteria for escalation to executives and legal
  3. Communication templates — pre-drafted notices for PDPC, individuals, media, and staff
  4. Contact lists — forensics vendors, legal counsel, PR agency, cyber insurance
  5. Decision trees — for threshold assessments and notification decisions
  6. Post-incident review process — with mandatory lessons-learned reporting

Related Reading

If you're strengthening your organisation's data governance and link security posture, these resources may help:

Frequently Asked Questions

How quickly must I report a data breach to PDPC?

Once you have confirmed that a breach meets the notifiability threshold, you must notify PDPC as soon as practicable and no later than 3 calendar days. You have up to 30 days from awareness to complete your threshold assessment.

What if I'm not sure whether the breach is notifiable?

When in doubt, err on the side of notification. PDPC generally responds more favourably to over-reporting than under-reporting. You can submit an initial notification with available information and update as your investigation progresses. Consult your DPO or legal counsel early.

Do I need to notify individuals if their data was encrypted?

Generally no. If the personal data was encrypted or otherwise rendered unintelligible such that unauthorised parties cannot access it, you are exempt from notifying individuals. However, you may still need to notify PDPC if the breach meets the scale threshold, and you must document your reliance on the encryption exception.

What are the penalties for failing to report a data breach?

Non-notification can attract financial penalties of up to S$1 million, or 10% of annual Singapore turnover for organisations exceeding S$10 million in Singapore turnover. PDPC may also issue remedial directions and publish enforcement decisions publicly.

Do overseas organisations processing Singapore residents' data need to notify PDPC?

Yes. The PDPA applies extraterritorially. Any organisation that collects, uses, or discloses personal data of individuals in Singapore is subject to the Act, including its notification obligations, regardless of where the organisation is based.

Can I delegate PDPC notification to my data processor?

No. The data controller retains ultimate responsibility for PDPC notification. Your data intermediary must promptly inform you of any breach, but you—the controller—must make the notification to PDPC and to affected individuals.

Final Thoughts

Reporting a data breach to PDPC is not just a compliance checkbox—it's a demonstration of your organisation's respect for the individuals whose data you hold. Speed, transparency, and thoroughness matter. Build your response capability now, before you need it. The organisations that navigate breaches best are those that have rehearsed the process, understand the thresholds, and can act with confidence within the 3-day statutory window.

Combine strong technical controls—encryption, access management, secure link governance, and continuous monitoring—with a well-rehearsed response plan, and you'll be positioned to meet Singapore's data protection expectations even under pressure.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles