How to Report a Data Breach to PDPC Singapore: A Complete 2026 Guide
Data breaches are no longer a matter of "if" but "when" for most organisations operating in Singapore. Under the Personal Data Protection Act (PDPA), businesses have a legal obligation to notify the Personal Data Protection Commission (PDPC) and affected individuals when a notifiable data breach occurs. Failing to do so can result in financial penalties of up to S$1 million or 10% of annual turnover for larger organisations.
This comprehensive guide walks you through exactly how to report a data breach to PDPC Singapore, including the mandatory notification thresholds, timelines, required information, and best practices for handling the aftermath.
What Is a Data Breach Under Singapore's PDPA?
A data breach under the PDPA refers to the unauthorised access, collection, use, disclosure, copying, modification, or disposal of personal data, or the loss of any storage medium or device on which personal data is stored, where unauthorised access is likely to occur.
Since the PDPA (Amendment) Act 2020 came into force on 1 February 2021, Singapore has operated under a mandatory data breach notification regime. This means organisations can no longer decide on their own whether to disclose a breach — the law dictates when notification is compulsory.
Common Examples of Data Breaches
- A ransomware attack encrypting customer databases
- An employee accidentally emailing a spreadsheet of customer records to the wrong recipient
- A stolen or lost laptop containing unencrypted personal data
- A misconfigured cloud storage bucket exposing files publicly
- Phishing attacks compromising employee credentials with access to personal data
- Unauthorised insider access to HR or payroll systems
When Must You Notify the PDPC?
Not every data breach requires notification. The PDPA requires notification only when the breach is notifiable, meaning it meets one of two thresholds under Section 26B of the Act.
The Two Notification Thresholds
- Significant harm threshold: The breach results in, or is likely to result in, significant harm to affected individuals. This includes financial loss, identity theft, physical harm, damage to reputation, or loss of employment opportunities.
- Significant scale threshold: The breach affects, or is likely to affect, 500 or more individuals — regardless of whether significant harm is likely.
Categories of Data Presumed to Cause Significant Harm
The PDPC has prescribed certain categories of personal data that, if breached, are presumed to cause significant harm. These include:
- Full name or alias combined with NRIC, FIN, passport number, or work permit number
- Financial account details (bank account, credit card numbers)
- Login credentials for online accounts
- Medical records and health information
- Information about vulnerable individuals (minors, victims of abuse)
- Private communications and intimate images
Timelines for Reporting a Data Breach to PDPC
Timeliness is critical. The PDPA specifies clear deadlines that organisations must meet from the moment a breach is discovered.
| Action Required | Deadline | Who to Notify |
|---|---|---|
| Assess whether the breach is notifiable | Within 30 calendar days of becoming aware | Internal assessment |
| Notify the PDPC | As soon as practicable, no later than 3 calendar days after determining it is notifiable | Personal Data Protection Commission |
| Notify affected individuals | On or after PDPC notification, unless exceptions apply | Affected data subjects |
| Data intermediary notifies main organisation | Without undue delay | Data controller |
Step-by-Step: How to Report a Data Breach to PDPC
Below is the complete process for reporting a notifiable data breach to the PDPC in Singapore.
Step 1: Contain the Breach Immediately
Before notifying anyone, take immediate action to stop the breach from continuing or escalating. This might include:
- Disconnecting affected systems from the network
- Revoking compromised user credentials
- Recalling misdirected emails or physical documents
- Removing publicly exposed data from the internet
- Preserving evidence for forensic investigation
Step 2: Assess the Breach
Conduct a rapid but thorough assessment to determine:
- What personal data was involved (categories and volume)
- How many individuals are affected
- The cause and nature of the breach
- The likely consequences for affected individuals
- Whether the breach meets either notification threshold
Document every step of your assessment. The PDPC expects organisations to demonstrate reasonable diligence, and your assessment records may be requested during any subsequent investigation.
Step 3: Prepare Your Notification Submission
Gather the information required for your notification. The PDPC's Data Breach Notification Form requires:
- Organisation name, UEN, and contact details
- Contact details of the Data Protection Officer (DPO)
- Date and time the breach was discovered
- Date and time the breach occurred (if known)
- Description of the breach circumstances
- Types and volume of personal data affected
- Number of affected individuals
- Cause of the breach
- Remedial actions taken or planned
- Plans for notifying affected individuals
Step 4: Submit the Notification Online
Submit your notification through the PDPC's official portal at eservice.pdpc.gov.sg. You will need to log in using Singpass or Corppass. The online Data Breach Notification Form is the preferred and fastest channel for submission.
If the online portal is unavailable, you may notify the PDPC via email at info@pdpc.gov.sg, but you should follow up with the official form submission as soon as possible.
Step 5: Notify Affected Individuals
Unless an exception applies, you must also notify the affected individuals in a clear and understandable manner. Your notification should include:
- A description of what happened
- What personal data was involved
- Potential consequences and risks
- Steps the organisation has taken to address the breach
- Steps individuals can take to protect themselves
- Contact information for questions or support
Step 6: Follow Up with the PDPC
The PDPC may request additional information or clarifications after your initial submission. Respond promptly and provide updates as your investigation progresses. If new material facts emerge, submit an updated notification.
When You May Not Need to Notify Affected Individuals
There are two main exceptions where you may still need to notify the PDPC but not the affected individuals:
- Remedial action exception: You have taken action that renders it unlikely the breach will result in significant harm (for example, the data was encrypted with strong encryption and the decryption key was not compromised).
- Technological protection exception: The affected personal data was protected by technological measures such that the risk of significant harm is negligible.
Additionally, notification to individuals may be delayed if a law enforcement agency instructs the organisation not to notify (to avoid compromising an investigation) or if the Commission directs otherwise.
Penalties for Non-Compliance
The consequences of failing to properly report a data breach can be severe. Under the amended PDPA, the PDPC has enhanced enforcement powers:
- Financial penalties: Up to S$1 million, or 10% of an organisation's annual turnover in Singapore (whichever is higher) for organisations with annual local turnover exceeding S$10 million
- Directions: The PDPC can order specific remedial actions
- Reputational damage: Enforcement decisions are published on the PDPC website
- Civil action: Affected individuals can pursue private civil action for loss or damage
Best Practices for Preventing Data Breaches
Prevention is always better than notification. Here are proven strategies to reduce your breach risk.
Implement Strong Access Controls
Apply the principle of least privilege — employees should only access data necessary for their role. Use multi-factor authentication (MFA) for all systems containing personal data, and review access logs regularly.
Encrypt Sensitive Data
Encryption at rest and in transit is one of the most effective protections. Encrypted data that is compromised may qualify for the technological protection exception, potentially removing the need to notify affected individuals.
Secure Your Links and URLs
Many breaches originate from phishing links or malicious URLs. When sharing links externally, use trusted platforms with built-in security features. Services like Lunyb provide secure URL shortening with click analytics and safety scanning, helping teams share links safely while maintaining visibility over how they are accessed. For a broader comparison of options, see our best URL shorteners buyer's guide.
Train Employees Regularly
Human error remains a leading cause of data breaches. Conduct quarterly training on phishing recognition, secure data handling, password hygiene, and incident reporting procedures.
Maintain an Incident Response Plan
Every organisation handling personal data should have a documented, tested incident response plan that includes:
- A designated incident response team with clear roles
- Escalation procedures and decision trees
- Contact lists for key stakeholders, legal counsel, and the PDPC
- Templates for internal and external communications
- Post-incident review processes
Conduct Regular Risk Assessments
Perform Data Protection Impact Assessments (DPIAs) for high-risk processing activities. Regularly audit third-party vendors and data intermediaries who handle personal data on your behalf.
Role of the Data Protection Officer (DPO)
Every organisation in Singapore is required to appoint at least one Data Protection Officer. In the event of a breach, the DPO plays a central role:
- Coordinating the initial response and containment
- Leading the breach assessment
- Preparing and submitting the PDPC notification
- Communicating with affected individuals
- Liaising with the PDPC on follow-up queries
- Conducting post-incident reviews and updating policies
Ensure your DPO's contact details are current on your website and registered with ACRA.
What Happens After You Notify the PDPC?
Once you submit your notification, the PDPC will typically acknowledge receipt and may request additional information. Depending on the severity and circumstances of the breach, the Commission may:
- Close the case without further action if your response was adequate
- Issue directions requiring specific remedial measures
- Launch a formal investigation
- Impose financial penalties for PDPA breaches
- Publish an enforcement decision
Organisations that demonstrate strong data protection practices, prompt containment, transparent communication, and genuine remedial action typically face more favourable outcomes.
Frequently Asked Questions
How quickly must I report a data breach to the PDPC?
You must notify the PDPC as soon as practicable, and no later than 3 calendar days after determining that the breach is notifiable. You have up to 30 days from discovery to complete your assessment of whether the breach meets the notification thresholds.
What counts as a notifiable data breach under Singapore's PDPA?
A breach is notifiable if it is likely to result in significant harm to affected individuals, or if it affects 500 or more individuals. Breaches involving prescribed categories of data — such as NRIC numbers combined with names, financial account details, or medical records — are presumed to cause significant harm.
Do I need to notify individuals if I notify the PDPC?
Generally yes, but exceptions apply. If you have taken remedial action that renders significant harm unlikely, or if the data was protected by strong technological measures such as encryption, you may only need to notify the PDPC. Law enforcement may also direct that individual notification be delayed.
What are the penalties for failing to report a data breach?
Organisations can face financial penalties of up to S$1 million, or 10% of annual Singapore turnover for organisations with local turnover exceeding S$10 million — whichever is higher. The PDPC can also issue directions requiring specific remedial actions and publish enforcement decisions.
Where do I submit the data breach notification form?
Submit your notification through the PDPC's e-service portal at eservice.pdpc.gov.sg using Singpass or Corppass. If the portal is unavailable, you may email info@pdpc.gov.sg as an interim measure and follow up with the official form.
Does the PDPA apply to data intermediaries?
Yes. Data intermediaries (organisations processing personal data on behalf of another) must notify the main organisation without undue delay upon becoming aware of a breach. The main organisation remains responsible for assessing whether the breach is notifiable and reporting to the PDPC.
Final Thoughts
Reporting a data breach to the PDPC is not just a legal obligation — it is an opportunity to demonstrate accountability and rebuild trust with your customers. Organisations that respond swiftly, transparently, and with genuine remedial intent typically emerge stronger from these incidents.
The best time to prepare for a breach is before one happens. Review your incident response plan today, ensure your DPO is empowered and trained, and invest in the technical and organisational measures that reduce your risk. Compliance with the PDPA is not a one-time exercise but an ongoing commitment to protecting the personal data entrusted to your organisation.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Lock Apps and Photos with Face ID: The Complete 2026 Guide
Learn how to lock apps and photos with Face ID on your iPhone using iOS 18's built-in features. This step-by-step guide covers app locking, hiding apps, protecting your Photos library, and troubleshooting common issues.
How to Shorten a URL: The Complete Step-by-Step Guide (2026)
Learn how to shorten a URL in seconds with this complete step-by-step guide. Covers free tools, custom branded links, click tracking, QR codes, mobile methods, and best practices to keep your links safe and professional.
How to Set Up Link Retargeting: A Complete Step-by-Step Guide
Link retargeting turns every shared URL into an audience-building asset — even links to content you don't own. This step-by-step guide shows you how to install pixels, create retargeting-enabled short links, build custom audiences, and launch high-ROI campaigns.
How to Improve Your Phone's Security Score: A Complete 2026 Guide
Your phone's security score reveals how well-protected your device really is. This complete 2026 guide walks through 10 practical steps — from screen locks and 2FA to permissions, encrypted backups, and monthly audits — to help you raise your score and dramatically reduce your risk of compromise.