facebook-pixel

How to Report a Data Breach to PDPC Singapore: Complete 2026 Guide

L
Lunyb Security Team
··9 min read

Data breaches are a serious concern for any organisation operating in Singapore. Under the Personal Data Protection Act (PDPA), organisations have a legal duty to notify the Personal Data Protection Commission (PDPC) and affected individuals when a notifiable data breach occurs. Failing to do so can result in significant financial penalties and reputational damage.

This comprehensive guide walks you through exactly how to report a data breach to PDPC Singapore, including the legal thresholds, timelines, required information, and best practices for handling the aftermath.

What Is a Data Breach Under Singapore's PDPA?

A data breach under the PDPA refers to the unauthorised access, collection, use, disclosure, copying, modification, or disposal of personal data, or the loss of any storage medium or device on which personal data is stored, where such loss is likely to result in unauthorised access or use.

Since the Personal Data Protection (Amendment) Act 2020 came into force on 1 February 2021, mandatory data breach notification has been a legal requirement for organisations in Singapore. The PDPC enforces this obligation and expects organisations to have proper breach response procedures in place.

Common Types of Data Breaches

  • Cyberattacks: Ransomware, phishing, malware infections, or unauthorised system intrusions
  • Human error: Sending emails to the wrong recipients, misconfigured databases, lost USB drives
  • Insider threats: Malicious employees accessing or exfiltrating data
  • Physical theft: Stolen laptops, mobile devices, or paper records
  • Third-party breaches: Incidents involving vendors or data processors

When Must You Report a Data Breach to PDPC?

Not every data breach is notifiable. Under Section 26B of the PDPA, an organisation must notify the PDPC of a data breach that is assessed to be a "notifiable data breach" based on two key thresholds.

The Two Notification Thresholds

  1. Significant harm threshold: The breach results in, or is likely to result in, significant harm to affected individuals. This typically applies when the compromised data includes prescribed categories such as full name plus NRIC, financial account information, medical records, or biometric data.
  2. Significant scale threshold: The breach affects, or is likely to affect, 500 or more individuals, regardless of the type of data involved.

If either threshold is met, the breach becomes notifiable. Even if a breach doesn't meet these thresholds, organisations should document their assessment and remediation actions internally.

Reporting Timelines: How Fast Must You Act?

Timing is critical when reporting a data breach to PDPC. The PDPA sets out specific timeframes that organisations must adhere to.

Key Deadlines to Remember

  • Assessment period: Once you become aware of a potential breach, you have up to 30 calendar days to conduct a reasonable and expeditious assessment to determine whether it is notifiable.
  • PDPC notification: Notify the PDPC as soon as practicable, but no later than 3 calendar days after determining the breach is notifiable.
  • Individual notification: Notify affected individuals on or after informing the PDPC, unless an exception applies (such as when law enforcement advises against it or remedial action makes notification unnecessary).

Delays without reasonable justification may lead to enforcement action. Document every step, including when the breach was discovered, when the assessment began, and when key decisions were made.

Step-by-Step: How to Report a Data Breach to PDPC

Follow this structured process to ensure your breach notification is complete, timely, and compliant with PDPA requirements.

Step 1: Contain the Breach

Immediately take action to stop the breach and limit further damage. This may include:

  • Disconnecting compromised systems from the network
  • Changing passwords and revoking access credentials
  • Recovering lost devices or documents
  • Shutting down affected services temporarily
  • Engaging your IT security team or external incident response experts

Step 2: Assess the Breach

Conduct a thorough assessment to understand the scope and impact. Key questions to answer include:

  1. What personal data was involved?
  2. How many individuals are affected?
  3. What is the likely harm to those individuals?
  4. Was the data encrypted or otherwise protected?
  5. Has the data been recovered or is it still exposed?

Step 3: Determine If It's Notifiable

Apply the two thresholds (significant harm and significant scale). If either applies, proceed to formal notification. If neither applies, document your assessment and reasoning for internal records.

Step 4: Submit the Notification to PDPC

Notifications are submitted via the PDPC's official online Data Breach Notification Form, accessible on the PDPC website (pdpc.gov.sg). You'll need to provide:

  • Organisation details and contact person
  • Date and time the breach was discovered
  • Nature and cause of the breach
  • Types of personal data involved
  • Number of affected individuals
  • Potential harm to individuals
  • Containment and remediation actions taken
  • Plans to notify affected individuals

Step 5: Notify Affected Individuals

Unless an exception applies, you must inform affected individuals in a clear and understandable manner. Include:

  • What happened and when
  • What data was involved
  • Potential consequences
  • Steps the organisation is taking
  • Steps individuals can take to protect themselves
  • Contact information for questions

Step 6: Document Everything

Maintain a detailed breach register that includes timelines, decisions, communications, and lessons learned. This documentation is essential if the PDPC requests further information or conducts an investigation.

Exceptions to Individual Notification

You may not need to notify affected individuals in certain circumstances, though PDPC notification is still required.

ExceptionDescription
Remedial actionOrganisation has taken action that makes it unlikely the breach will result in significant harm
Technological protectionPersonal data was encrypted or protected by technology that renders it inaccessible
Law enforcement requestA prescribed law enforcement agency instructs you not to notify
PDPC waiverThe PDPC directs the organisation not to notify affected individuals

Penalties for Non-Compliance

Failing to report a notifiable data breach carries serious consequences under the amended PDPA. The financial penalty regime has been significantly strengthened.

  • For organisations with annual turnover exceeding S$10 million: Financial penalties of up to 10% of annual turnover in Singapore
  • For all other organisations: Financial penalties of up to S$1 million
  • Additional consequences: Directions to cease certain data processing activities, mandatory remediation programmes, and reputational damage

The PDPC regularly publishes enforcement decisions, meaning breaches often become public knowledge, further amplifying reputational harm.

Best Practices for Data Breach Preparedness

The best way to handle a data breach is to be prepared before one happens. Here are strategies every Singapore organisation should adopt.

1. Develop a Data Breach Management Plan

Create a documented plan that outlines roles, responsibilities, escalation procedures, and communication templates. Include contact lists for internal stakeholders, legal counsel, IT forensics providers, and public relations.

2. Appoint a Data Protection Officer (DPO)

Every organisation in Singapore is legally required to appoint a DPO. This individual should lead breach response efforts and serve as the primary liaison with the PDPC.

3. Conduct Regular Risk Assessments

Perform periodic reviews of your data inventory, access controls, and third-party vendors. Identify high-risk data assets and implement stronger protections around them.

4. Train Employees

Human error is a leading cause of breaches. Regular training on phishing awareness, secure data handling, and incident reporting can dramatically reduce risk.

5. Use Secure Tools for Sharing Information

When sharing links or files, use trusted services that offer encryption, access controls, and audit logs. For example, when distributing links containing sensitive information externally, a privacy-focused URL shortener like Lunyb can help you track access without exposing underlying URLs. You can learn more in our honest review of Lunyb or compare options in our 2026 URL shortener buyer's guide.

6. Test Your Response Plan

Run tabletop exercises simulating different breach scenarios. This helps identify gaps in your plan and ensures your team knows exactly what to do under pressure.

Common Mistakes to Avoid

Even well-prepared organisations can stumble during a breach. Watch out for these pitfalls.

  • Delaying assessment: Waiting too long to investigate can push you past regulatory deadlines
  • Incomplete notifications: Submitting vague or missing information may prompt follow-up investigations
  • Poor communication: Confusing or defensive messaging to affected individuals erodes trust
  • Failing to document: Without proper records, you can't demonstrate compliance
  • Ignoring root cause: Treating symptoms rather than underlying vulnerabilities invites repeat incidents
  • Not updating the PDPC: If new information emerges after initial notification, you must provide updates

What Happens After You Notify the PDPC?

Once you've submitted your notification, the PDPC will review the information and may take several actions depending on the severity and circumstances.

  1. Acknowledgement: You'll receive confirmation that your notification has been received
  2. Request for information: The PDPC may ask for additional details or clarification
  3. Investigation: For serious breaches, a formal investigation may be initiated
  4. Directions: The PDPC may issue directions requiring specific remedial actions
  5. Financial penalties: In cases of non-compliance or negligence, penalties may be imposed
  6. Publication: The PDPC often publishes summarised decisions on its website

Cooperate fully and transparently. Organisations that demonstrate good faith and effective remediation are typically treated more favourably than those that appear evasive.

Frequently Asked Questions

How long do I have to report a data breach to PDPC in Singapore?

You must notify the PDPC as soon as practicable and no later than 3 calendar days after determining that a breach is notifiable. You also have up to 30 days from becoming aware of a potential breach to complete your assessment.

What personal data types trigger the significant harm threshold?

Prescribed categories include full name combined with NRIC or FIN, financial account details, credit card information, medical records, insurance information, and certain biometric data. The full list is set out in the PDPC's Advisory Guidelines on Key Concepts in the PDPA.

Do I need to notify individuals if the data was encrypted?

If the personal data was protected by encryption or similar technology that renders it inaccessible or unusable to unauthorised parties, you may be exempted from notifying affected individuals. However, you must still notify the PDPC if the breach otherwise meets notification thresholds.

What if the breach was caused by a third-party vendor?

As the data controller, your organisation remains responsible for compliance. If a data intermediary experiences a breach, they must notify you without undue delay, and you must then determine whether PDPC notification is required and act accordingly.

Can I face criminal charges for a data breach?

The PDPA primarily imposes civil financial penalties on organisations. However, certain intentional acts, such as knowingly disclosing personal data without authorisation or unauthorised re-identification of anonymised data, can attract criminal liability for individuals under Sections 48D–48F of the PDPA.

Final Thoughts

Reporting a data breach to PDPC Singapore is not just a legal obligation—it's a critical component of responsible data stewardship. By understanding the notification thresholds, adhering to timelines, and implementing robust breach management practices, your organisation can respond effectively and maintain trust with customers, regulators, and stakeholders.

The most successful organisations treat data protection as an ongoing commitment rather than a one-time compliance exercise. Invest in prevention, prepare for the worst, and when incidents occur, act with transparency and urgency. Doing so will not only keep you on the right side of the PDPA but also demonstrate the kind of accountability that today's privacy-conscious public demands.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles