facebook-pixel

How to Report a Data Breach to PDPC Singapore: Complete 2026 Guide

L
Lunyb Security Team
··8 min read

Data breaches are no longer a matter of if but when. In Singapore, organisations that suffer a notifiable data breach have strict legal obligations under the Personal Data Protection Act (PDPA) to notify the Personal Data Protection Commission (PDPC) — and in many cases, affected individuals — within specific timeframes. Failing to do so can result in financial penalties of up to S$1 million or 10% of annual turnover for larger organisations.

This guide walks Singapore-based businesses through the entire process of reporting a data breach to the PDPC, including how to determine notifiability, what information to prepare, and how to complete the notification form correctly.

What Is a Data Breach Under Singapore's PDPA?

Under the PDPA, a data breach is any unauthorised access, collection, use, disclosure, copying, modification, or disposal of personal data, as well as any loss of storage media or devices where personal data is stored. The Data Breach Notification (DBN) obligation, which came into force on 1 February 2021, requires organisations to notify the PDPC of certain breaches.

Not every incident qualifies as a "notifiable" breach. The PDPA sets specific thresholds that determine when notification becomes mandatory.

Types of Incidents That May Count as Breaches

  • Hacking or ransomware attacks exposing customer records
  • Lost or stolen laptops, USB drives, or mobile devices containing personal data
  • Emails containing personal data sent to the wrong recipient
  • Unauthorised employees accessing HR or financial records
  • Misconfigured cloud storage exposing files publicly
  • Phishing incidents leading to credential compromise

When Must You Notify the PDPC?

A data breach must be notified to the PDPC if it meets either of the following thresholds:

  1. Significant harm threshold: The breach is likely to result in significant harm to affected individuals (e.g. financial loss, identity theft, or reputational damage).
  2. Significant scale threshold: The breach affects 500 or more individuals, regardless of the severity of harm.

What Counts as "Significant Harm"?

The PDPC's guidelines identify categories of personal data whose unauthorised disclosure is deemed to cause significant harm. These include:

  • Full name combined with NRIC, FIN, passport, or work permit number
  • Financial account details (bank account, credit card numbers)
  • Login credentials for online accounts
  • Health and medical information
  • Information about vulnerable individuals (e.g. minors, domestic abuse victims)
  • Private communications such as SMS or emails

Notification Timelines You Must Follow

Timelines under the PDPA's DBN framework are strict, and the clock starts ticking the moment you become aware of a suspected breach.

ActionDeadlineWho to Notify
Assess whether the breach is notifiableWithin 30 calendar days of awarenessInternal assessment
Notify the PDPCAs soon as practicable, no later than 3 calendar days after assessmentPDPC via online form
Notify affected individualsAs soon as practicable (concurrently with or after PDPC notification)Affected individuals (unless exceptions apply)
Data intermediary informing main organisationWithout undue delay upon awarenessThe data controller

The 30-day assessment window is not a grace period — the PDPC expects organisations to complete assessments promptly and be able to justify any delays.

Step-by-Step: How to Report a Data Breach to the PDPC

Step 1: Contain the Breach Immediately

Before notification, take action to stop the breach and limit further damage. This may include:

  1. Disconnecting compromised systems from the network
  2. Resetting passwords and revoking access tokens
  3. Recalling misdirected emails where possible
  4. Preserving logs and evidence for forensic review
  5. Engaging your incident response team or external cybersecurity consultants

Step 2: Assess the Breach

Determine the nature, cause, and scope of the incident. Document:

  • Date and time of the breach and discovery
  • Types of personal data involved
  • Number of affected individuals
  • Likely cause (human error, malicious attack, system failure)
  • Potential harm to individuals

Use this information to determine whether the breach crosses the notifiability threshold.

Step 3: Gather Required Information for Notification

Before opening the PDPC notification form, prepare the following:

  • Organisation name, UEN, and contact details of the Data Protection Officer (DPO)
  • Date and time the breach occurred and was discovered
  • Description of the breach and its cause
  • Categories and volume of personal data compromised
  • Number of affected individuals
  • Remedial actions already taken and planned
  • Plans for notifying affected individuals

Step 4: Submit the Notification Online

Notifications are submitted via the PDPC's official website at pdpc.gov.sg. Navigate to the "Report a Data Breach" section and complete the online Data Breach Notification form. You will need to log in using Singpass or Corppass.

  1. Go to the PDPC website and select "Report a Data Breach"
  2. Authenticate with Corppass (recommended for organisations)
  3. Complete all mandatory fields in the form
  4. Upload any supporting documentation (incident reports, communications drafts)
  5. Review carefully before submitting
  6. Save the acknowledgment reference number for future correspondence

Step 5: Notify Affected Individuals

If the breach is likely to cause significant harm, you must also notify affected individuals. The notification should be clear and include:

  • What happened and when
  • The types of personal data involved
  • Potential consequences
  • Steps individuals can take to protect themselves
  • Actions your organisation has taken
  • Contact information for further questions

Step 6: Document Everything

Maintain a comprehensive breach register including internal assessments, communications with the PDPC, notifications sent, and remedial actions. The PDPC may request this documentation during any investigation.

When You Don't Need to Notify Individuals

Even if a breach is notifiable to the PDPC, you may be exempt from notifying individuals if:

  1. You have taken action that renders the data unusable (e.g. strong encryption of stolen data)
  2. You have implemented remedial actions that make significant harm unlikely
  3. A prescribed law enforcement agency or the PDPC has instructed you not to notify

You still, however, must notify the PDPC in these situations.

Common Mistakes When Reporting Breaches

1. Delayed Assessment

Waiting until day 29 of the 30-day window to begin assessment often results in incomplete information and potential enforcement action. Start immediately.

2. Under-reporting the Scope

Organisations sometimes report only confirmed impacts, missing potentially affected records. Err on the side of transparency; you can update the notification later.

3. Poor Communication with Individuals

Vague or overly technical notifications frustrate customers and attract regulatory scrutiny. Use plain English and provide actionable guidance.

4. Failing to Engage the DPO Early

Every Singapore organisation must appoint a Data Protection Officer. The DPO should be involved from the moment a suspected breach is discovered.

5. Ignoring Data Intermediary Obligations

If you are a vendor processing data on behalf of another organisation, you must notify that organisation without undue delay. They then handle PDPC notification.

Penalties for Non-Compliance

Since October 2022, financial penalties for PDPA breaches have increased significantly. Organisations can face:

  • Up to S$1 million, or
  • Up to 10% of annual turnover in Singapore (for organisations with local turnover exceeding S$10 million), whichever is higher

Beyond fines, the PDPC publishes enforcement decisions publicly, which can cause significant reputational damage.

Reducing Breach Risk Through Better Link and Data Hygiene

Prevention is always cheaper than notification. Many breaches in Singapore stem from simple issues such as phishing links, misdirected URLs, or unsecured data sharing. Using a trusted link management platform like Lunyb allows organisations to control, track, and revoke shared links — reducing the risk that a leaked or forwarded URL exposes sensitive dashboards or documents. You can read more in our honest Lunyb review or compare tools in our 2026 URL shortener buyer's guide.

Additional preventative measures include:

  • Encrypting personal data at rest and in transit
  • Enforcing multi-factor authentication on all accounts
  • Using encrypted DNS and private browsers for sensitive workflows
  • Running regular staff training on phishing and social engineering
  • Conducting annual PDPA compliance audits
  • Maintaining a tested incident response plan

What Happens After You Notify the PDPC?

After submission, the PDPC will typically acknowledge receipt within a few working days. Depending on the severity, they may:

  1. Request further information or clarification
  2. Open a formal investigation
  3. Provide directions on remedial actions
  4. Refer the matter for enforcement proceedings
  5. Close the case with no further action if remediation is satisfactory

Cooperate fully and respond to requests within the timeframes stated. Voluntary and comprehensive cooperation can be a mitigating factor in any enforcement decision.

Building a Breach-Ready Organisation

The best time to prepare for a data breach notification is before one happens. Create a written incident response playbook that assigns clear roles, defines escalation paths, and includes ready-to-use notification templates. Run tabletop exercises at least annually so your DPO, IT, legal, and communications teams know exactly what to do when minutes matter.

Frequently Asked Questions

1. How quickly must I report a data breach to the PDPC in Singapore?

Once you have assessed that a breach is notifiable, you must notify the PDPC as soon as practicable, and no later than 3 calendar days after making that assessment. The assessment itself should be completed within 30 calendar days of becoming aware of the incident.

2. What is the threshold for notifying a data breach in Singapore?

A breach is notifiable if it is likely to result in significant harm to affected individuals, or if it affects 500 or more individuals. Meeting either threshold triggers mandatory notification to the PDPC.

3. Do I have to notify affected individuals as well as the PDPC?

Yes, if the breach is likely to cause significant harm. However, you may be exempt if the data was rendered unusable (e.g. through strong encryption), if remedial action makes harm unlikely, or if a law enforcement agency or the PDPC instructs you not to notify.

4. What are the penalties for failing to report a data breach?

Financial penalties can reach up to S$1 million, or up to 10% of annual turnover in Singapore for organisations with local turnover exceeding S$10 million — whichever is higher. Enforcement decisions are also published publicly.

5. Where do I submit the data breach notification?

Notifications are submitted through the online Data Breach Notification form on the PDPC's official website at pdpc.gov.sg. You will need to authenticate via Singpass or Corppass to complete the submission.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles