How to Report a Data Breach to PDPC Singapore: A Complete 2026 Guide
If your organisation has suffered a data breach in Singapore, you may be legally required to notify the Personal Data Protection Commission (PDPC) within 72 hours. Since the introduction of the mandatory Data Breach Notification (DBN) obligation under the amended Personal Data Protection Act (PDPA) in February 2021, all organisations handling personal data must have a clear response plan. This guide walks you through exactly how to report a data breach to PDPC, when notification is required, and what to do before, during, and after filing.
What Counts as a Data Breach Under Singapore's PDPA?
A data breach under the PDPA is any unauthorised access, collection, use, disclosure, copying, modification, or disposal of personal data, or the loss of any storage medium or device on which personal data is stored. In practical terms, it includes hacking incidents, ransomware attacks, lost laptops, misconfigured cloud storage, misdirected emails, and even insider misuse.
The PDPA applies to almost every private-sector organisation in Singapore that collects, uses, or discloses personal data, regardless of company size. Public agencies are governed separately under the Public Sector (Governance) Act, so this guide focuses on private organisations.
Common Examples of Reportable Breaches
- Ransomware attacks that encrypt customer databases
- Phishing incidents that expose employee credentials and downstream customer data
- Lost or stolen unencrypted USB drives, laptops, or mobile phones
- Cloud storage buckets accidentally set to public
- System errors that display one customer's information to another
- Employees emailing personal data to the wrong recipient in bulk
When Must You Notify the PDPC?
Not every breach must be reported. Under Section 26D of the PDPA, notification to the PDPC is mandatory only when the breach is deemed a notifiable data breach. A breach becomes notifiable if it meets either of the following thresholds:
- Significant harm threshold: The breach results in, or is likely to result in, significant harm to affected individuals.
- Scale threshold: The breach affects, or is likely to affect, 500 or more individuals.
The PDPC has prescribed categories of personal data that are automatically presumed to cause significant harm if compromised. These include full name plus NRIC/FIN/passport number, financial account details, health information, insurance information, and login credentials that permit access to accounts containing personal data.
Notification Timelines You Must Meet
| Action | Deadline | Trigger |
|---|---|---|
| Assess whether breach is notifiable | Within 30 calendar days | From when you have reason to believe a breach occurred |
| Notify PDPC | As soon as practicable, no later than 72 hours | From assessment that breach is notifiable |
| Notify affected individuals | As soon as practicable | Simultaneously with or after PDPC notification (with limited exceptions) |
Step-by-Step: How to Report a Data Breach to PDPC
Here is the practical process for filing a data breach notification with the PDPC once you have confirmed the incident is notifiable.
Step 1: Contain the Breach Immediately
Before you file anything, take immediate containment action. Disconnect affected systems, revoke compromised credentials, isolate infected endpoints, and stop any ongoing data exfiltration. Preserve logs and forensic evidence — you will need this information later for both the PDPC and any internal investigation.
Step 2: Assemble the Incident Response Team
Your Data Protection Officer (DPO) should lead the response, working alongside IT security, legal counsel, communications, and senior management. If you have engaged an external cybersecurity firm, involve them from the start. Document every decision with timestamps.
Step 3: Conduct a Rapid Assessment
Determine four things quickly:
- What personal data was involved (categories and volume)?
- How many individuals are affected?
- What is the likely harm — identity theft, financial loss, reputational damage?
- Does the breach meet the notifiable threshold (significant harm or 500+ individuals)?
You have up to 30 days to complete this assessment, but faster is better. The 72-hour clock to notify PDPC starts the moment you conclude the breach is notifiable.
Step 4: File the Notification via the PDPC Website
Notifications are submitted through the official PDPC data breach notification form available at pdpc.gov.sg. You will need to log in using CorpPass. The online form asks for:
- Organisation details and DPO contact information
- Date and time the breach was discovered
- Date and time the breach occurred (if known)
- Description of the breach, including cause and how it was discovered
- Types and volume of personal data affected
- Number of affected individuals
- Assessment of likely harm
- Containment and remediation actions taken
- Whether affected individuals have been or will be notified
Step 5: Notify Affected Individuals
You must also notify affected individuals as soon as practicable if the breach is likely to cause significant harm. Notifications should be clear, in plain language, and include what happened, what data was involved, what the organisation is doing about it, and what steps individuals can take to protect themselves (such as changing passwords or monitoring bank statements).
There are limited exceptions where you do not need to notify individuals — for example, if you have taken remedial actions that make significant harm unlikely, or if the affected data was subject to technological protection (like strong encryption) that renders it unreadable.
Step 6: Submit Follow-Up Information
Your initial notification may be incomplete if the investigation is still ongoing. That is acceptable — the PDPC expects you to notify within 72 hours even if some facts are still emerging. You must then update the PDPC as new information becomes available, typically through the same case reference number.
Information You Should Prepare Before Notifying
Having a pre-built incident response pack drastically reduces the stress of a real breach. Prepare these items in advance:
- An up-to-date data inventory showing what personal data you hold and where
- System architecture diagrams and data flow maps
- Contact list for your DPO, IT security lead, legal counsel, and executive sponsors
- A pre-drafted breach notification template for both PDPC and affected individuals
- CorpPass access credentials for the person submitting the notification
- Contracts with data intermediaries clearly stating their breach-reporting duties to you
What Happens After You Notify the PDPC?
Once your notification is received, the PDPC will acknowledge it and may open an investigation. The scope and intensity of the investigation depend on the severity of the breach, the sensitivity of the data, and your organisation's response.
Possible Outcomes
| Outcome | When It Applies |
|---|---|
| No further action | Minor breach with adequate response and no systemic issues |
| Warning or advisory | Small compliance gaps identified but no serious harm caused |
| Directions to remediate | Specific security or process improvements required |
| Financial penalty | Serious breach of PDPA obligations — up to S$1 million or 10% of annual turnover in Singapore (whichever is higher) for organisations with turnover above S$10 million |
Recent enforcement decisions show the PDPC weighs cooperation, transparency, and the strength of your existing security controls when deciding penalties. Organisations that respond quickly and honestly typically fare much better than those that delay or downplay incidents.
Common Mistakes to Avoid
Even well-intentioned organisations stumble during breach response. Watch out for these pitfalls:
- Delaying assessment. Sitting on a suspected breach hoping it will "turn out to be nothing" is one of the fastest ways to miss the 72-hour deadline.
- Under-reporting scope. Guessing low on affected numbers and later revising upward damages your credibility with the PDPC.
- Ignoring data intermediaries. If a vendor processes data on your behalf and suffers a breach, you as the data controller remain accountable for notifying PDPC.
- Poor individual notifications. Vague, jargon-heavy letters generate complaints and often lead to additional PDPC scrutiny.
- No post-incident review. Failing to update policies and controls after a breach almost guarantees a repeat incident — and much harsher regulatory treatment.
Strengthening Your Defences Before a Breach Happens
Prevention is always cheaper than notification. A layered approach to personal data protection should include access controls with multi-factor authentication, encryption at rest and in transit, regular vulnerability scanning, staff training on phishing and social engineering, and clear vendor risk management.
Pay particular attention to the small tools your team uses daily, including link-sharing services. Choosing a privacy-respecting link shortener like Lunyb helps ensure that when your marketing or support teams share links containing tracking parameters, the underlying analytics and click data are handled responsibly rather than passed to opaque third parties. For a broader look at options in this category, our 2026 buyer's guide to URL shorteners compares features and privacy postures across major providers.
Working With Data Intermediaries
Many Singapore organisations rely on cloud providers, SaaS platforms, and outsourced IT services. Under the PDPA, these are considered data intermediaries when they process personal data on your behalf. If they discover a breach, they must notify you "without undue delay" so you can meet your own timelines.
Make sure your contracts with intermediaries include:
- An explicit obligation to notify you of any breach within a defined short window (24 hours is common practice)
- Cooperation clauses requiring them to help with your investigation and PDPC notification
- Rights to audit their security controls
- Clear allocation of costs for breach response, forensic investigation, and individual notification
Documentation and Record-Keeping
Even for breaches that do not meet the notifiable threshold, you must keep internal records. The PDPC may request evidence of your assessment and reasoning during audits or complaint investigations. At a minimum, document:
- When and how the incident was discovered
- The assessment process and conclusion (notifiable or not, and why)
- Containment and remediation steps
- Communications with affected individuals, if any
- Lessons learned and follow-up actions
Retain these records for at least several years, aligned with your broader retention schedule.
FAQ
How long do I have to report a data breach to PDPC in Singapore?
You must notify the PDPC as soon as practicable, and no later than 72 hours, after determining that the breach is notifiable. You have up to 30 days from discovery to complete that assessment, but the 72-hour clock starts the moment you conclude the breach meets the notification threshold.
What if the breach involves fewer than 500 individuals?
Notification is still required if the breach is likely to cause significant harm — for example, if it exposes NRIC numbers, financial account details, health data, or account credentials, even for a small number of people. The 500-individual threshold is a separate, independent trigger.
Do I need to notify affected individuals as well as PDPC?
Yes, in most cases. If the breach is likely to result in significant harm, you must notify affected individuals as soon as practicable, ideally at the same time as or shortly after notifying PDPC. Exceptions exist where remediation has eliminated the risk or the data was rendered unreadable by strong encryption.
What are the penalties for failing to report a data breach?
Failure to comply with the Data Breach Notification obligation is itself a breach of the PDPA and can attract financial penalties. Since October 2022, organisations with annual turnover in Singapore above S$10 million can face penalties of up to 10% of that turnover, or S$1 million, whichever is higher. Non-financial directions to remediate may also be issued.
Who should submit the notification on behalf of the organisation?
The Data Protection Officer (DPO) typically submits the notification, though it can be delegated to another authorised officer with access to CorpPass. Every organisation subject to the PDPA is required to designate a DPO and register their business contact details with the PDPC.
What if the breach happened at a cloud provider or vendor?
You remain accountable as the data controller. Your vendor (a data intermediary) must notify you promptly, and you must then assess and notify the PDPC and affected individuals within the standard timelines. Strong contractual clauses and a rehearsed joint response plan are essential.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Use UTM Parameters with Short Links: A Complete Guide
UTM parameters tell you exactly where your traffic comes from, but they create ugly, unwieldy URLs. Combining them with short links gives you precise campaign tracking plus clean, shareable links. This guide walks through the entire workflow with examples.
How to Password Protect a Short Link: Complete 2026 Guide
Learn how to password protect a short link with step-by-step instructions, tool comparisons, and best practices. Secure sensitive URLs, gate premium content, and control access without complex setup.
How to Report a Scam Phone Number: A Complete 2026 Guide
Scam calls and texts are relentless, but reporting them is easier than you think. This complete guide covers how to report a scam number to the FTC, FCC, mobile carriers, and international agencies, plus how to protect yourself going forward.
How to Check if Your Password Was Leaked in a Data Breach
Discover how to quickly check if your password was exposed in a data breach using free, trusted tools like Have I Been Pwned and browser password monitors. Learn what to do if your credentials are compromised and how to prevent future leaks.