How to Report a Data Breach to PDPC Singapore: Complete 2026 Guide
If your organisation has suffered a data breach in Singapore, you may be legally required to notify the Personal Data Protection Commission (PDPC) under the Personal Data Protection Act (PDPA). Since the mandatory Data Breach Notification (DBN) obligation came into force in February 2021, Singapore businesses have faced strict timelines and clear thresholds for reporting. This guide walks you through exactly how to report a data breach to the PDPC, what qualifies as a notifiable breach, and how to protect your organisation before and after an incident occurs.
What Is a Data Breach Under Singapore's PDPA?
A data breach, under Singapore's Personal Data Protection Act, is the unauthorised access, collection, use, disclosure, copying, modification, or disposal of personal data, or the loss of any storage medium or device on which personal data is stored. It also includes situations where personal data has been exposed to a significant risk of such treatment.
In practical terms, a breach can occur from many sources: a ransomware attack, a lost laptop containing customer records, an employee accidentally emailing a spreadsheet to the wrong recipient, misconfigured cloud storage, or a malicious insider exfiltrating files. The PDPA treats all of these as potential breaches that must be assessed for notifiability.
Who Must Comply?
The DBN obligation applies to every organisation that collects, uses, or discloses personal data in Singapore, regardless of size. This includes SMEs, multinational corporations, non-profits, and even sole proprietors. Data intermediaries (service providers processing data on behalf of another organisation) have a duty to notify the organisation they serve, who then becomes responsible for assessing and reporting to the PDPC.
When Must You Notify the PDPC?
A data breach is notifiable to the PDPC if it meets either of two thresholds set out in Section 26B of the PDPA:
- Significant harm threshold: The breach is likely to result in significant harm to affected individuals.
- Significant scale threshold: The breach affects, or is likely to affect, 500 or more individuals.
What Counts as "Significant Harm"?
The Personal Data Protection (Notification of Data Breaches) Regulations 2021 prescribe categories of personal data that are deemed to result in significant harm if breached. These include:
- Full name or alias combined with NRIC/FIN/passport numbers
- Financial information such as credit card numbers, bank account details, or CPF balances
- Health information, medical records, or details of mental health
- Information about adoption, sexual orientation, or domestic abuse
- Private key authentication credentials to accounts
- Information about vulnerable persons such as minors
If a breach involves these categories, you should treat it as notifiable unless you can clearly demonstrate otherwise.
Timelines You Must Follow
Timing is one of the most important aspects of PDPA compliance. The regulations impose strict deadlines once a breach is discovered.
| Action | Deadline | Reference |
|---|---|---|
| Assess whether the breach is notifiable | Within 30 calendar days of becoming aware | PDPA s.26C |
| Notify the PDPC | As soon as practicable, no later than 3 calendar days after assessing it is notifiable | PDPA s.26D(1) |
| Notify affected individuals | As soon as practicable (on or after notifying PDPC) | PDPA s.26D(2) |
| Data intermediary notifies the organisation | Without undue delay after becoming aware | PDPA s.26A(3) |
The 3-day clock does not start from the moment of the breach, but from when you have reasonably assessed it to be notifiable. However, you cannot drag out the assessment: 30 days is the maximum, and the PDPC expects you to move faster when the facts are clear.
Step-by-Step: How to Report a Data Breach to PDPC
Step 1: Contain the Breach Immediately
Before anything else, stop the bleeding. Disconnect compromised systems from the network, revoke access credentials, patch exploited vulnerabilities, and preserve logs. Containment is both a legal defence and an operational necessity. Document every action you take with timestamps, as PDPC may ask for your incident timeline.
Step 2: Convene Your Response Team
Activate your Data Breach Management Plan. Your team should include:
- The Data Protection Officer (DPO) – mandatory under the PDPA
- IT or cybersecurity lead
- Legal counsel
- Communications or PR representative
- Senior management decision-maker
Step 3: Assess the Breach
Determine the facts: what data was involved, how many individuals, what categories of personal data, who had access, and what the likely consequences are. Measure the incident against the two notification thresholds. Even if you decide not to notify, document your reasoning – PDPC can request this during audits.
Step 4: Submit the Notification Online
The PDPC accepts data breach notifications through its online portal. Here is the submission process:
- Go to the PDPC website at pdpc.gov.sg and navigate to "Report a Data Breach".
- Log in using Singpass (for Singapore citizens/residents) or Corppass (for organisations).
- Complete the Data Breach Notification Form with details including: organisation information, DPO contact, breach discovery date, nature of breach, categories and volume of data affected, number of individuals, potential harm, and remedial actions taken.
- Upload supporting documents such as incident reports, forensic findings, or communications sent to affected parties.
- Submit and retain the acknowledgement reference number for your records.
If the full details are not yet known within the 3-day window, submit a preliminary notification with what you know and update PDPC as the investigation progresses.
Step 5: Notify Affected Individuals
Where the breach meets the significant harm threshold, you must also inform affected individuals. The notification must be clear and in a form that the individual will likely receive – typically email, SMS, letter, or a prominent website notice. It should include:
- A description of the breach
- The categories of personal data involved
- Steps the organisation has taken or will take
- Steps the individual can take to protect themselves
- Contact details for further enquiries
Exceptions apply: you do not need to notify individuals if remedial actions have made significant harm unlikely, if the data was technologically protected (for example, strong encryption), or if a law enforcement agency instructs you not to.
Step 6: Follow Up and Remediate
After notification, continue the investigation, implement long-term fixes, update policies, retrain staff, and prepare for potential PDPC enquiries. The commission may issue directions, impose financial penalties (up to S$1 million or 10% of annual turnover in Singapore for organisations with turnover above S$10 million – whichever is higher), or require specific remediation measures.
What Information Does PDPC Require?
Being prepared with the right information speeds up your submission. The notification form typically requires:
| Category | Details Required |
|---|---|
| Organisation details | Name, UEN, industry sector, DPO contact |
| Breach timeline | Date of occurrence, discovery, assessment, and notification |
| Breach description | Cause, type (cyber, physical, human error, malicious), systems involved |
| Data affected | Categories (NRIC, financial, health, etc.), volume, format |
| Individuals affected | Estimated number, demographic (customers, employees, minors) |
| Risk assessment | Likely harm, risk mitigation already in place (encryption, access controls) |
| Response actions | Containment, remediation, individual notification plans |
Common Mistakes Organisations Make
Underestimating the Scale
Many organisations initially report a small number of affected individuals, only to discover the breach was far larger. PDPC prefers an early, honest estimate with later updates rather than a lowball figure that erodes trust.
Delaying the Assessment
Using the full 30-day assessment window when the facts are obvious invites scrutiny. If a stolen laptop contained an unencrypted customer database, you do not need 30 days to decide it is notifiable.
Poor Documentation
If you cannot show when you discovered the breach, who was informed, and what steps you took, PDPC may conclude your response was negligent. Keep a detailed incident log from the first alert onwards.
Forgetting Data Intermediaries
If your cloud provider, payroll processor, or marketing agency suffers a breach involving your data, you are still accountable. Make sure your contracts require immediate notification from them.
Preventing Breaches Before They Happen
The best breach report is one you never have to file. Strong preventive controls are expected under the PDPA's Protection Obligation (Section 24). Consider the following:
- Encrypt data at rest and in transit – encryption can even remove the obligation to notify individuals.
- Enforce multi-factor authentication on all admin and customer-facing systems.
- Minimise data collection – you cannot lose what you do not hold.
- Audit third parties who handle personal data on your behalf.
- Train staff at least annually on phishing, device security, and data handling.
- Use secure link-sharing tools – when sharing documents or campaign links externally, platforms like Lunyb allow you to create tracked, password-protected short links so you can monitor who accesses sensitive resources and revoke access instantly if something looks wrong.
- Monitor DNS and endpoint telemetry to detect data exfiltration early.
For teams managing many outbound links across marketing, HR, and operations, consolidating link management is also a quiet security win. Our 2026 buyer's guide to URL shorteners compares the leading options and their security features, and if you want a deeper look at Lunyb specifically, see our honest Lunyb review.
What Happens After You Report?
Once submitted, PDPC acknowledges receipt and may follow up with questions. Possible outcomes include:
- Case closed with no further action – if your response was timely, proportionate, and well-documented.
- Advisory or warning – minor shortcomings addressed through guidance.
- Directions – PDPC may require specific remedial steps, such as policy changes or audits.
- Financial penalty – imposed in serious cases of negligence or repeated failures.
- Public enforcement decision – PDPC publishes decisions on its website, naming organisations found in breach.
Transparent, cooperative engagement with the commission significantly improves outcomes. Organisations that self-report promptly and demonstrate strong remediation have historically received lighter sanctions than those discovered through complaints or media coverage.
Frequently Asked Questions
Do I need to report every data breach to PDPC?
No. Only breaches that meet the significant harm threshold or affect 500 or more individuals are notifiable. However, you must still document every breach internally and take remedial action. If in doubt, err on the side of notification – PDPC generally views unnecessary caution more favourably than under-reporting.
What is the penalty for failing to report a data breach in Singapore?
Failure to notify a notifiable breach is a breach of the PDPA. Organisations can face financial penalties of up to S$1 million, or 10% of annual turnover in Singapore for larger organisations (those with local turnover exceeding S$10 million), whichever is higher. Repeated or egregious failures can also attract public enforcement decisions that damage reputation.
Can I report a breach anonymously?
No. Organisations must identify themselves and provide a DPO contact when submitting a notification. Individuals who wish to complain about an organisation can do so through PDPC's complaints channel, which is separate from the DBN process and does offer some confidentiality protections.
What if the breach happened at my overseas office but affects Singapore residents?
The PDPA applies to organisations collecting, using, or disclosing personal data in Singapore, regardless of where the breach physically occurred. If Singapore residents' data is affected and the thresholds are met, you must notify PDPC. You may also have parallel obligations in other jurisdictions (such as GDPR notifications in the EU).
How long should I keep records of a data breach?
PDPC recommends retaining breach records for at least the duration permitted under your retention policy, and no less than several years, to demonstrate compliance during audits or investigations. Many organisations keep breach documentation permanently for institutional learning.
Does encryption remove my obligation to notify?
Encryption can remove the obligation to notify affected individuals if it makes significant harm unlikely – but you may still need to notify PDPC if the breach affects 500 or more individuals. Strong, properly implemented encryption with secure key management is one of the most effective protections available.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Do a Reverse Image Search to Find Your Photos Online
Learn how to do a reverse image search to find your photos online, protect your work from theft, and track where your images are being used. This complete guide covers the best tools, step-by-step instructions for every device, and what to do when you find infringement.
How to Encrypt Your Internet Traffic: A Complete 2026 Guide
Learn how to encrypt your internet traffic using HTTPS, encrypted DNS, Tor, SSH tunnels, WireGuard, and end-to-end encrypted messaging. This 2026 guide walks through practical, layered steps to keep your browsing, communications, and data private.
How to Check if a Link Is Safe Before Clicking: Complete 2026 Guide
Unsafe links are the #1 entry point for phishing and malware attacks. Learn how to check if a link is safe using free scanners, URL previews, and simple red-flag checks — before you click.
How to Create Branded Short Links: A Complete 2026 Guide
Branded short links boost click-through rates, build trust, and strengthen brand recognition. Learn how to choose a custom domain, configure DNS, and launch your first branded link in under an hour with this complete 2026 guide.