How to Report a Data Breach to PDPC Singapore: Complete 2026 Guide
Under Singapore's Personal Data Protection Act (PDPA), organisations that suffer a notifiable data breach are legally required to inform the Personal Data Protection Commission (PDPC) within 72 hours. Since the mandatory Data Breach Notification (DBN) framework came into effect on 1 February 2021, businesses across Singapore have had to build formal processes for detecting, assessing, and reporting breaches. This guide walks you through exactly how to report a data breach to PDPC, when notification is required, and what happens after you submit.
Whether you run a small e-commerce store, a fintech startup, or an enterprise handling millions of records, understanding the DBN process is essential. Getting it wrong can lead to financial penalties of up to S$1 million or 10% of your annual turnover in Singapore, whichever is higher.
What Counts as a Data Breach Under the PDPA?
A data breach under the PDPA is any unauthorised access, collection, use, disclosure, copying, modification, or disposal of personal data. It also includes loss of storage media or devices where personal data is held. In short, if personal data has been exposed, altered, or lost outside of authorised handling, a breach has occurred.
Common examples include:
- A ransomware attack that encrypts customer records.
- An employee emailing a customer database to the wrong recipient.
- A misconfigured cloud storage bucket exposing files publicly.
- A stolen laptop containing unencrypted client information.
- A phishing attack that compromises staff credentials tied to CRM systems.
Not every breach is notifiable, but every breach must be assessed. The PDPC expects organisations to have documented processes for triaging incidents quickly.
When Must You Notify the PDPC?
A breach is notifiable under the PDPA when it meets either of these thresholds:
- Significant harm threshold: The breach is likely to result in significant harm to affected individuals. This includes financial loss, identity theft, reputational damage, or exposure of sensitive data such as NRIC numbers, financial account details, medical information, or biometric data.
- Significant scale threshold: The breach affects 500 or more individuals, regardless of the type of data involved.
If either threshold is met, you must notify the PDPC within 72 hours of assessing the breach as notifiable. If the significant harm threshold is met, you must also notify affected individuals as soon as practicable.
Prescribed Personal Data That Triggers Notification
The PDPA regulations list specific categories of personal data that are deemed to cause significant harm if breached:
- Full name or alias combined with NRIC, FIN, work permit, or passport numbers.
- Account identifiers such as bank account numbers, credit card details, or e-wallet credentials.
- Details of insurance policies, life or accident coverage.
- Health information including medical conditions, diagnoses, or treatment history.
- Information about children under 18.
- Login credentials to online accounts.
Step-by-Step: How to Report a Data Breach to PDPC
Here is the exact process to follow when reporting a notifiable breach.
Step 1: Contain the Breach Immediately
Before any reporting, stop the bleeding. Isolate affected systems, revoke compromised credentials, disable exposed URLs, and preserve logs for forensic review. Document every containment action with timestamps — this evidence will be requested by the PDPC.
Step 2: Conduct a Breach Assessment
You have 30 days from becoming aware of a suspected breach to complete your assessment. During this period, determine:
- What personal data was involved and how many individuals are affected.
- The cause of the breach (malicious attack, human error, system failure).
- Whether the data was encrypted or otherwise protected.
- The likelihood of significant harm to individuals.
Document everything. The PDPC expects a defensible, reasoned assessment — not a rushed conclusion.
Step 3: Notify the PDPC Within 72 Hours
Once you determine the breach is notifiable, you have 72 hours to submit a notification. Use the official channel:
- Go to the PDPC website at pdpc.gov.sg.
- Navigate to the "Report a Data Breach" section.
- Complete the online Data Breach Notification form.
- Provide organisation details, breach description, affected data types, number of individuals, containment actions taken, and remediation plans.
- Submit and retain the acknowledgement reference number.
If you cannot provide full details within 72 hours, submit what you have and update the PDPC as investigation progresses. Late notification without reasonable justification is itself a breach of the PDPA.
Step 4: Notify Affected Individuals
If the breach is likely to cause significant harm, notify affected individuals as soon as practicable — typically at the same time as or shortly after notifying the PDPC. Your notification should include:
- A clear description of what happened.
- The type of personal data involved.
- Steps the organisation has taken to address the breach.
- Actions individuals can take to protect themselves (e.g. change passwords, monitor bank statements).
- Contact details for further queries.
Individual notification can be waived in limited circumstances, such as when the PDPC directs otherwise, when notification would compromise a criminal investigation, or when technological measures (like strong encryption) render the data unusable.
Step 5: Cooperate With PDPC Follow-Up
After submission, the PDPC may request additional information, forensic reports, or evidence of remediation. Respond promptly and thoroughly. In serious cases, the PDPC may open a formal investigation.
Notification Timeline at a Glance
| Stage | Deadline | Action Required |
|---|---|---|
| Breach discovered | Immediate | Contain, preserve evidence, activate response team |
| Assessment | Within 30 days | Determine if breach is notifiable |
| Notify PDPC | Within 72 hours of assessment | Submit online DBN form |
| Notify affected individuals | As soon as practicable | Required if significant harm is likely |
| Post-breach review | Ongoing | Update policies, retrain staff, submit follow-ups |
Information You Need Before Submitting the DBN Form
To speed up your submission, prepare the following before opening the form:
- Organisation profile: UEN, registered address, DPO name and contact.
- Breach summary: Date and time of occurrence, date of discovery, cause.
- Affected data: Categories of personal data, number of individuals, whether data was encrypted.
- Impact assessment: Likelihood of harm, potential consequences.
- Containment measures: Actions already taken to limit damage.
- Remediation plan: Technical and organisational improvements planned.
- Communication plan: How and when affected individuals will be informed.
Common Mistakes Organisations Make
Even well-resourced companies stumble during breach response. Watch out for these pitfalls:
Waiting Too Long to Assess
The 30-day assessment clock starts when you become aware of a suspected breach — not when you confirm it. Delaying triage while "waiting for more information" is one of the most common compliance failures.
Under-Reporting the Scope
Some organisations minimise the number of affected individuals to appear less culpable. The PDPC routinely uncovers under-reporting during investigations, which results in harsher penalties than the original breach would have attracted.
Failing to Notify Individuals
Notifying the PDPC does not discharge your duty to inform affected persons. These are two separate obligations under the PDPA.
Poor Documentation
If you cannot show a documented assessment, containment log, or decision rationale, the PDPC will assume you did not have one. Contemporaneous records are your best defence.
How to Prepare Before a Breach Happens
The best breach response starts long before an incident. Here are foundational controls every Singapore organisation should have in place.
1. Appoint a Data Protection Officer (DPO)
The PDPA requires every organisation to designate a DPO. This person coordinates breach response, liaises with the PDPC, and owns your data protection policies.
2. Build a Data Breach Management Plan
Your plan should cover detection, containment, assessment, notification, and post-incident review. Test it with tabletop exercises at least annually.
3. Maintain a Data Inventory
You cannot assess a breach in 30 days if you do not know what personal data you hold, where it lives, and who has access. Keep an updated data map.
4. Harden Third-Party and Link Handling
Many breaches originate from insecure links, phishing pages, or compromised vendors. Use trusted, security-conscious tools for anything customer-facing. For instance, when sharing marketing or transactional links, a reliable shortener like Lunyb gives you HTTPS-protected redirects, click analytics, and the ability to disable a link instantly if it becomes part of a phishing incident. You can learn more in our honest review of Lunyb or compare options in our 2026 buyer's guide.
5. Encrypt Sensitive Data
Encryption at rest and in transit can significantly reduce the harm from a breach — and in some cases removes the individual notification requirement entirely.
6. Train Staff Regularly
Human error is the leading cause of reportable breaches in Singapore. Quarterly phishing simulations and PDPA refreshers dramatically lower risk.
Penalties for Non-Compliance
Since October 2022, the PDPC has been empowered to impose financial penalties of up to S$1 million or 10% of annual turnover in Singapore, whichever is higher, on organisations with annual turnover exceeding S$10 million. Smaller organisations face capped penalties of S$1 million.
Penalties are assessed based on factors including the nature of personal data involved, the number of affected individuals, the organisation's cooperation, and remediation efforts. Publicised enforcement decisions on the PDPC website show that transparent, prompt reporting typically results in lower penalties than concealment or delay.
What Happens After You Report
Once your DBN is submitted, the PDPC will:
- Acknowledge receipt, usually within a few business days.
- Review the notification and may request clarifications.
- Decide whether to open a formal investigation.
- Issue directions or advisories on remediation.
- Publish anonymised or named decisions if enforcement action is taken.
Most breaches that are promptly reported, well-contained, and accompanied by strong remediation plans do not escalate to public enforcement. This is why transparency and speed matter far more than perfect information at the 72-hour mark.
Frequently Asked Questions
Do I need to report every data breach to the PDPC?
No. Only breaches that meet the significant harm threshold or affect 500 or more individuals must be reported. However, you must assess every breach and document your decision — even if you conclude notification is not required.
What if I discover the breach happened months ago?
The 72-hour clock starts when you complete your assessment that the breach is notifiable, not from when the breach originally occurred. However, be prepared to explain the delay in detection, and expect the PDPC to scrutinise why your monitoring did not catch it earlier.
Can I be penalised for reporting a breach voluntarily?
The PDPC does not penalise organisations simply for reporting. Enforcement is based on whether the organisation failed to protect personal data reasonably. Prompt, transparent notification is consistently treated as a mitigating factor.
Do I need to notify affected individuals if data was encrypted?
If personal data was protected by technological measures (such as strong encryption) that make the data unintelligible to unauthorised parties, individual notification may not be required. You still need to notify the PDPC and demonstrate that the protection was effective.
What is the difference between a data intermediary and an organisation?
A data intermediary processes personal data on behalf of another organisation. Data intermediaries must notify the organisation they process data for without undue delay when a breach occurs. The organisation, not the intermediary, is responsible for notifying the PDPC and affected individuals.
Final Thoughts
Reporting a data breach to the PDPC is not just a legal box to tick — it is a test of your organisation's maturity. Companies that respond quickly, document thoroughly, and communicate honestly with regulators and customers tend to emerge with reputations intact. Those that delay, downplay, or conceal breaches face compounding consequences.
Build your breach response plan now, before you need it. Train your team, encrypt sensitive data, and treat every suspected incident with the seriousness it deserves. When a breach does happen — and statistically, it will — you will be ready to meet the 72-hour deadline with confidence.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Set Up Link Retargeting: A Complete Step-by-Step Guide
Link retargeting lets you build advertising audiences from every click on a shortened URL — even links pointing to third-party sites. This step-by-step guide shows you how to set up pixels, choose the right tool, and launch your first retargeting campaign in under an hour.
How to Lock Apps and Photos with Face ID: The Complete 2026 Guide
Learn how to lock apps and photos with Face ID on your iPhone using built-in iOS tools and trusted third-party options. This complete 2026 guide covers step-by-step instructions, hidden albums, notes, troubleshooting, and privacy best practices.
Who Called Me? How to Identify an Unknown Number in 2026
Getting calls from unknown numbers can be unnerving—and sometimes dangerous. This guide covers 8 proven methods to identify unknown callers, spot scams instantly, and protect your phone from unwanted contact in 2026.
How to Shorten a URL: The Complete 2026 Guide
Learn how to shorten a URL with this complete 2026 guide. Discover free tools, custom branded links, mobile methods, API integration, and best practices for safe, effective link sharing.