How to Report a Data Breach to PDPC Singapore: Complete 2026 Guide
Data breaches are no longer a matter of if but when. In Singapore, organisations that suffer a notifiable data breach have strict legal obligations under the Personal Data Protection Act (PDPA) to notify the Personal Data Protection Commission (PDPC) — and in many cases, affected individuals — within specific timeframes. Failing to do so can result in financial penalties of up to S$1 million or 10% of annual turnover for larger organisations.
This guide walks Singapore-based businesses through the entire process of reporting a data breach to the PDPC, including how to determine notifiability, what information to prepare, and how to complete the notification form correctly.
What Is a Data Breach Under Singapore's PDPA?
Under the PDPA, a data breach is any unauthorised access, collection, use, disclosure, copying, modification, or disposal of personal data, as well as any loss of storage media or devices where personal data is stored. The Data Breach Notification (DBN) obligation, which came into force on 1 February 2021, requires organisations to notify the PDPC of certain breaches.
Not every incident qualifies as a "notifiable" breach. The PDPA sets specific thresholds that determine when notification becomes mandatory.
Types of Incidents That May Count as Breaches
- Hacking or ransomware attacks exposing customer records
- Lost or stolen laptops, USB drives, or mobile devices containing personal data
- Emails containing personal data sent to the wrong recipient
- Unauthorised employees accessing HR or financial records
- Misconfigured cloud storage exposing files publicly
- Phishing incidents leading to credential compromise
When Must You Notify the PDPC?
A data breach must be notified to the PDPC if it meets either of the following thresholds:
- Significant harm threshold: The breach is likely to result in significant harm to affected individuals (e.g. financial loss, identity theft, or reputational damage).
- Significant scale threshold: The breach affects 500 or more individuals, regardless of the severity of harm.
What Counts as "Significant Harm"?
The PDPC's guidelines identify categories of personal data whose unauthorised disclosure is deemed to cause significant harm. These include:
- Full name combined with NRIC, FIN, passport, or work permit number
- Financial account details (bank account, credit card numbers)
- Login credentials for online accounts
- Health and medical information
- Information about vulnerable individuals (e.g. minors, domestic abuse victims)
- Private communications such as SMS or emails
Notification Timelines You Must Follow
Timelines under the PDPA's DBN framework are strict, and the clock starts ticking the moment you become aware of a suspected breach.
| Action | Deadline | Who to Notify |
|---|---|---|
| Assess whether the breach is notifiable | Within 30 calendar days of awareness | Internal assessment |
| Notify the PDPC | As soon as practicable, no later than 3 calendar days after assessment | PDPC via online form |
| Notify affected individuals | As soon as practicable (concurrently with or after PDPC notification) | Affected individuals (unless exceptions apply) |
| Data intermediary informing main organisation | Without undue delay upon awareness | The data controller |
The 30-day assessment window is not a grace period — the PDPC expects organisations to complete assessments promptly and be able to justify any delays.
Step-by-Step: How to Report a Data Breach to the PDPC
Step 1: Contain the Breach Immediately
Before notification, take action to stop the breach and limit further damage. This may include:
- Disconnecting compromised systems from the network
- Resetting passwords and revoking access tokens
- Recalling misdirected emails where possible
- Preserving logs and evidence for forensic review
- Engaging your incident response team or external cybersecurity consultants
Step 2: Assess the Breach
Determine the nature, cause, and scope of the incident. Document:
- Date and time of the breach and discovery
- Types of personal data involved
- Number of affected individuals
- Likely cause (human error, malicious attack, system failure)
- Potential harm to individuals
Use this information to determine whether the breach crosses the notifiability threshold.
Step 3: Gather Required Information for Notification
Before opening the PDPC notification form, prepare the following:
- Organisation name, UEN, and contact details of the Data Protection Officer (DPO)
- Date and time the breach occurred and was discovered
- Description of the breach and its cause
- Categories and volume of personal data compromised
- Number of affected individuals
- Remedial actions already taken and planned
- Plans for notifying affected individuals
Step 4: Submit the Notification Online
Notifications are submitted via the PDPC's official website at pdpc.gov.sg. Navigate to the "Report a Data Breach" section and complete the online Data Breach Notification form. You will need to log in using Singpass or Corppass.
- Go to the PDPC website and select "Report a Data Breach"
- Authenticate with Corppass (recommended for organisations)
- Complete all mandatory fields in the form
- Upload any supporting documentation (incident reports, communications drafts)
- Review carefully before submitting
- Save the acknowledgment reference number for future correspondence
Step 5: Notify Affected Individuals
If the breach is likely to cause significant harm, you must also notify affected individuals. The notification should be clear and include:
- What happened and when
- The types of personal data involved
- Potential consequences
- Steps individuals can take to protect themselves
- Actions your organisation has taken
- Contact information for further questions
Step 6: Document Everything
Maintain a comprehensive breach register including internal assessments, communications with the PDPC, notifications sent, and remedial actions. The PDPC may request this documentation during any investigation.
When You Don't Need to Notify Individuals
Even if a breach is notifiable to the PDPC, you may be exempt from notifying individuals if:
- You have taken action that renders the data unusable (e.g. strong encryption of stolen data)
- You have implemented remedial actions that make significant harm unlikely
- A prescribed law enforcement agency or the PDPC has instructed you not to notify
You still, however, must notify the PDPC in these situations.
Common Mistakes When Reporting Breaches
1. Delayed Assessment
Waiting until day 29 of the 30-day window to begin assessment often results in incomplete information and potential enforcement action. Start immediately.
2. Under-reporting the Scope
Organisations sometimes report only confirmed impacts, missing potentially affected records. Err on the side of transparency; you can update the notification later.
3. Poor Communication with Individuals
Vague or overly technical notifications frustrate customers and attract regulatory scrutiny. Use plain English and provide actionable guidance.
4. Failing to Engage the DPO Early
Every Singapore organisation must appoint a Data Protection Officer. The DPO should be involved from the moment a suspected breach is discovered.
5. Ignoring Data Intermediary Obligations
If you are a vendor processing data on behalf of another organisation, you must notify that organisation without undue delay. They then handle PDPC notification.
Penalties for Non-Compliance
Since October 2022, financial penalties for PDPA breaches have increased significantly. Organisations can face:
- Up to S$1 million, or
- Up to 10% of annual turnover in Singapore (for organisations with local turnover exceeding S$10 million), whichever is higher
Beyond fines, the PDPC publishes enforcement decisions publicly, which can cause significant reputational damage.
Reducing Breach Risk Through Better Link and Data Hygiene
Prevention is always cheaper than notification. Many breaches in Singapore stem from simple issues such as phishing links, misdirected URLs, or unsecured data sharing. Using a trusted link management platform like Lunyb allows organisations to control, track, and revoke shared links — reducing the risk that a leaked or forwarded URL exposes sensitive dashboards or documents. You can read more in our honest Lunyb review or compare tools in our 2026 URL shortener buyer's guide.
Additional preventative measures include:
- Encrypting personal data at rest and in transit
- Enforcing multi-factor authentication on all accounts
- Using encrypted DNS and private browsers for sensitive workflows
- Running regular staff training on phishing and social engineering
- Conducting annual PDPA compliance audits
- Maintaining a tested incident response plan
What Happens After You Notify the PDPC?
After submission, the PDPC will typically acknowledge receipt within a few working days. Depending on the severity, they may:
- Request further information or clarification
- Open a formal investigation
- Provide directions on remedial actions
- Refer the matter for enforcement proceedings
- Close the case with no further action if remediation is satisfactory
Cooperate fully and respond to requests within the timeframes stated. Voluntary and comprehensive cooperation can be a mitigating factor in any enforcement decision.
Building a Breach-Ready Organisation
The best time to prepare for a data breach notification is before one happens. Create a written incident response playbook that assigns clear roles, defines escalation paths, and includes ready-to-use notification templates. Run tabletop exercises at least annually so your DPO, IT, legal, and communications teams know exactly what to do when minutes matter.
Frequently Asked Questions
1. How quickly must I report a data breach to the PDPC in Singapore?
Once you have assessed that a breach is notifiable, you must notify the PDPC as soon as practicable, and no later than 3 calendar days after making that assessment. The assessment itself should be completed within 30 calendar days of becoming aware of the incident.
2. What is the threshold for notifying a data breach in Singapore?
A breach is notifiable if it is likely to result in significant harm to affected individuals, or if it affects 500 or more individuals. Meeting either threshold triggers mandatory notification to the PDPC.
3. Do I have to notify affected individuals as well as the PDPC?
Yes, if the breach is likely to cause significant harm. However, you may be exempt if the data was rendered unusable (e.g. through strong encryption), if remedial action makes harm unlikely, or if a law enforcement agency or the PDPC instructs you not to notify.
4. What are the penalties for failing to report a data breach?
Financial penalties can reach up to S$1 million, or up to 10% of annual turnover in Singapore for organisations with local turnover exceeding S$10 million — whichever is higher. Enforcement decisions are also published publicly.
5. Where do I submit the data breach notification?
Notifications are submitted through the online Data Breach Notification form on the PDPC's official website at pdpc.gov.sg. You will need to authenticate via Singpass or Corppass to complete the submission.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Use UTM Parameters with Short Links: A Complete Guide
UTM parameters tell you exactly where your traffic comes from, but they create ugly, unwieldy URLs. Combining them with short links gives you precise campaign tracking plus clean, shareable links. This guide walks through the entire workflow with examples.
How to Password Protect a Short Link: Complete 2026 Guide
Learn how to password protect a short link with step-by-step instructions, tool comparisons, and best practices. Secure sensitive URLs, gate premium content, and control access without complex setup.
How to Report a Scam Phone Number: A Complete 2026 Guide
Scam calls and texts are relentless, but reporting them is easier than you think. This complete guide covers how to report a scam number to the FTC, FCC, mobile carriers, and international agencies, plus how to protect yourself going forward.
How to Check if Your Password Was Leaked in a Data Breach
Discover how to quickly check if your password was exposed in a data breach using free, trusted tools like Have I Been Pwned and browser password monitors. Learn what to do if your credentials are compromised and how to prevent future leaks.