facebook-pixel

How to Report a Data Breach to PDPC Singapore: Complete 2026 Guide

L
Lunyb Security Team
··10 min read

If your organisation has suffered a data breach in Singapore, you may be legally required to notify the Personal Data Protection Commission (PDPC) under the Personal Data Protection Act (PDPA). Since the mandatory Data Breach Notification (DBN) obligation came into force in February 2021, Singapore businesses have faced strict timelines and clear thresholds for reporting. This guide walks you through exactly how to report a data breach to the PDPC, what qualifies as a notifiable breach, and how to protect your organisation before and after an incident occurs.

What Is a Data Breach Under Singapore's PDPA?

A data breach, under Singapore's Personal Data Protection Act, is the unauthorised access, collection, use, disclosure, copying, modification, or disposal of personal data, or the loss of any storage medium or device on which personal data is stored. It also includes situations where personal data has been exposed to a significant risk of such treatment.

In practical terms, a breach can occur from many sources: a ransomware attack, a lost laptop containing customer records, an employee accidentally emailing a spreadsheet to the wrong recipient, misconfigured cloud storage, or a malicious insider exfiltrating files. The PDPA treats all of these as potential breaches that must be assessed for notifiability.

Who Must Comply?

The DBN obligation applies to every organisation that collects, uses, or discloses personal data in Singapore, regardless of size. This includes SMEs, multinational corporations, non-profits, and even sole proprietors. Data intermediaries (service providers processing data on behalf of another organisation) have a duty to notify the organisation they serve, who then becomes responsible for assessing and reporting to the PDPC.

When Must You Notify the PDPC?

A data breach is notifiable to the PDPC if it meets either of two thresholds set out in Section 26B of the PDPA:

  1. Significant harm threshold: The breach is likely to result in significant harm to affected individuals.
  2. Significant scale threshold: The breach affects, or is likely to affect, 500 or more individuals.

What Counts as "Significant Harm"?

The Personal Data Protection (Notification of Data Breaches) Regulations 2021 prescribe categories of personal data that are deemed to result in significant harm if breached. These include:

  • Full name or alias combined with NRIC/FIN/passport numbers
  • Financial information such as credit card numbers, bank account details, or CPF balances
  • Health information, medical records, or details of mental health
  • Information about adoption, sexual orientation, or domestic abuse
  • Private key authentication credentials to accounts
  • Information about vulnerable persons such as minors

If a breach involves these categories, you should treat it as notifiable unless you can clearly demonstrate otherwise.

Timelines You Must Follow

Timing is one of the most important aspects of PDPA compliance. The regulations impose strict deadlines once a breach is discovered.

ActionDeadlineReference
Assess whether the breach is notifiableWithin 30 calendar days of becoming awarePDPA s.26C
Notify the PDPCAs soon as practicable, no later than 3 calendar days after assessing it is notifiablePDPA s.26D(1)
Notify affected individualsAs soon as practicable (on or after notifying PDPC)PDPA s.26D(2)
Data intermediary notifies the organisationWithout undue delay after becoming awarePDPA s.26A(3)

The 3-day clock does not start from the moment of the breach, but from when you have reasonably assessed it to be notifiable. However, you cannot drag out the assessment: 30 days is the maximum, and the PDPC expects you to move faster when the facts are clear.

Step-by-Step: How to Report a Data Breach to PDPC

Step 1: Contain the Breach Immediately

Before anything else, stop the bleeding. Disconnect compromised systems from the network, revoke access credentials, patch exploited vulnerabilities, and preserve logs. Containment is both a legal defence and an operational necessity. Document every action you take with timestamps, as PDPC may ask for your incident timeline.

Step 2: Convene Your Response Team

Activate your Data Breach Management Plan. Your team should include:

  • The Data Protection Officer (DPO) – mandatory under the PDPA
  • IT or cybersecurity lead
  • Legal counsel
  • Communications or PR representative
  • Senior management decision-maker

Step 3: Assess the Breach

Determine the facts: what data was involved, how many individuals, what categories of personal data, who had access, and what the likely consequences are. Measure the incident against the two notification thresholds. Even if you decide not to notify, document your reasoning – PDPC can request this during audits.

Step 4: Submit the Notification Online

The PDPC accepts data breach notifications through its online portal. Here is the submission process:

  1. Go to the PDPC website at pdpc.gov.sg and navigate to "Report a Data Breach".
  2. Log in using Singpass (for Singapore citizens/residents) or Corppass (for organisations).
  3. Complete the Data Breach Notification Form with details including: organisation information, DPO contact, breach discovery date, nature of breach, categories and volume of data affected, number of individuals, potential harm, and remedial actions taken.
  4. Upload supporting documents such as incident reports, forensic findings, or communications sent to affected parties.
  5. Submit and retain the acknowledgement reference number for your records.

If the full details are not yet known within the 3-day window, submit a preliminary notification with what you know and update PDPC as the investigation progresses.

Step 5: Notify Affected Individuals

Where the breach meets the significant harm threshold, you must also inform affected individuals. The notification must be clear and in a form that the individual will likely receive – typically email, SMS, letter, or a prominent website notice. It should include:

  • A description of the breach
  • The categories of personal data involved
  • Steps the organisation has taken or will take
  • Steps the individual can take to protect themselves
  • Contact details for further enquiries

Exceptions apply: you do not need to notify individuals if remedial actions have made significant harm unlikely, if the data was technologically protected (for example, strong encryption), or if a law enforcement agency instructs you not to.

Step 6: Follow Up and Remediate

After notification, continue the investigation, implement long-term fixes, update policies, retrain staff, and prepare for potential PDPC enquiries. The commission may issue directions, impose financial penalties (up to S$1 million or 10% of annual turnover in Singapore for organisations with turnover above S$10 million – whichever is higher), or require specific remediation measures.

What Information Does PDPC Require?

Being prepared with the right information speeds up your submission. The notification form typically requires:

CategoryDetails Required
Organisation detailsName, UEN, industry sector, DPO contact
Breach timelineDate of occurrence, discovery, assessment, and notification
Breach descriptionCause, type (cyber, physical, human error, malicious), systems involved
Data affectedCategories (NRIC, financial, health, etc.), volume, format
Individuals affectedEstimated number, demographic (customers, employees, minors)
Risk assessmentLikely harm, risk mitigation already in place (encryption, access controls)
Response actionsContainment, remediation, individual notification plans

Common Mistakes Organisations Make

Underestimating the Scale

Many organisations initially report a small number of affected individuals, only to discover the breach was far larger. PDPC prefers an early, honest estimate with later updates rather than a lowball figure that erodes trust.

Delaying the Assessment

Using the full 30-day assessment window when the facts are obvious invites scrutiny. If a stolen laptop contained an unencrypted customer database, you do not need 30 days to decide it is notifiable.

Poor Documentation

If you cannot show when you discovered the breach, who was informed, and what steps you took, PDPC may conclude your response was negligent. Keep a detailed incident log from the first alert onwards.

Forgetting Data Intermediaries

If your cloud provider, payroll processor, or marketing agency suffers a breach involving your data, you are still accountable. Make sure your contracts require immediate notification from them.

Preventing Breaches Before They Happen

The best breach report is one you never have to file. Strong preventive controls are expected under the PDPA's Protection Obligation (Section 24). Consider the following:

  • Encrypt data at rest and in transit – encryption can even remove the obligation to notify individuals.
  • Enforce multi-factor authentication on all admin and customer-facing systems.
  • Minimise data collection – you cannot lose what you do not hold.
  • Audit third parties who handle personal data on your behalf.
  • Train staff at least annually on phishing, device security, and data handling.
  • Use secure link-sharing tools – when sharing documents or campaign links externally, platforms like Lunyb allow you to create tracked, password-protected short links so you can monitor who accesses sensitive resources and revoke access instantly if something looks wrong.
  • Monitor DNS and endpoint telemetry to detect data exfiltration early.

For teams managing many outbound links across marketing, HR, and operations, consolidating link management is also a quiet security win. Our 2026 buyer's guide to URL shorteners compares the leading options and their security features, and if you want a deeper look at Lunyb specifically, see our honest Lunyb review.

What Happens After You Report?

Once submitted, PDPC acknowledges receipt and may follow up with questions. Possible outcomes include:

  • Case closed with no further action – if your response was timely, proportionate, and well-documented.
  • Advisory or warning – minor shortcomings addressed through guidance.
  • Directions – PDPC may require specific remedial steps, such as policy changes or audits.
  • Financial penalty – imposed in serious cases of negligence or repeated failures.
  • Public enforcement decision – PDPC publishes decisions on its website, naming organisations found in breach.

Transparent, cooperative engagement with the commission significantly improves outcomes. Organisations that self-report promptly and demonstrate strong remediation have historically received lighter sanctions than those discovered through complaints or media coverage.

Frequently Asked Questions

Do I need to report every data breach to PDPC?

No. Only breaches that meet the significant harm threshold or affect 500 or more individuals are notifiable. However, you must still document every breach internally and take remedial action. If in doubt, err on the side of notification – PDPC generally views unnecessary caution more favourably than under-reporting.

What is the penalty for failing to report a data breach in Singapore?

Failure to notify a notifiable breach is a breach of the PDPA. Organisations can face financial penalties of up to S$1 million, or 10% of annual turnover in Singapore for larger organisations (those with local turnover exceeding S$10 million), whichever is higher. Repeated or egregious failures can also attract public enforcement decisions that damage reputation.

Can I report a breach anonymously?

No. Organisations must identify themselves and provide a DPO contact when submitting a notification. Individuals who wish to complain about an organisation can do so through PDPC's complaints channel, which is separate from the DBN process and does offer some confidentiality protections.

What if the breach happened at my overseas office but affects Singapore residents?

The PDPA applies to organisations collecting, using, or disclosing personal data in Singapore, regardless of where the breach physically occurred. If Singapore residents' data is affected and the thresholds are met, you must notify PDPC. You may also have parallel obligations in other jurisdictions (such as GDPR notifications in the EU).

How long should I keep records of a data breach?

PDPC recommends retaining breach records for at least the duration permitted under your retention policy, and no less than several years, to demonstrate compliance during audits or investigations. Many organisations keep breach documentation permanently for institutional learning.

Does encryption remove my obligation to notify?

Encryption can remove the obligation to notify affected individuals if it makes significant harm unlikely – but you may still need to notify PDPC if the breach affects 500 or more individuals. Strong, properly implemented encryption with secure key management is one of the most effective protections available.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles