Since 1 February 2021, every Singapore organisation has been under a statutory duty to assess data breaches and notify the Personal Data Protection Commission (PDPC) — and in many cases the affected individuals — within strict deadlines. The Personal Data Protection (Amendment) Act 2020 introduced this regime, codified in Sections 26A to 26E of the PDPA. In 2026, the PDPC is enforcing these obligations actively, and companies that miss the notification deadlines are seeing financial penalties of SGD 30,000–SGD 1m.
This guide explains what counts as a notifiable breach, the 72-hour deadline, the assessment process, and the practical playbook a board should have in the drawer when a breach hits.
1. The statutory framework
Sections 26A–26E of the PDPA, read with Part III of the PDPA Regulations 2021, set out:
- Section 26B: the threshold for a notifiable data breach.
- Section 26C: the duty to assess whether a data breach is notifiable.
- Section 26D: the obligation to notify the PDPC and affected individuals.
- Section 26E: exceptions to the duty to notify individuals.
The full text is on Singapore Statutes Online (PDPA). The PDPC’s Advisory Guidelines on the Data Protection Provisions set out the regulator’s expectations.
2. What counts as a “data breach”?
A data breach is any unauthorised access, collection, use, disclosure, copying, modification or disposal of personal data — including loss of any storage medium or device. It captures:
- Cyber incidents — phishing, ransomware, SQL injection, business email compromise.
- Lost or stolen laptops and USB drives containing customer data.
- Misdirected emails attaching a database to the wrong recipient.
- Insider misuse — an employee taking client lists to a competitor.
- Cloud misconfigurations exposing a public S3 bucket.
- Physical breaches — paper files left at a reception or in a taxi.
3. The notifiable-breach threshold (Section 26B)
A breach is notifiable if it:
(a) results in, or is likely to result in, significant harm to an affected individual; OR
(b) is of a significant scale — affecting 500 or more individuals.
Either limb triggers notification. You only need ONE to apply.
“Significant harm” — the prescribed list
The PDP (Notification of Data Breaches) Regulations 2021 list the categories of personal data that, if compromised, are presumed to cause significant harm. These include:
- Full name combined with NRIC/FIN/passport number.
- Bank account numbers, credit/debit card numbers, CVV.
- Health information — medical conditions, treatment records.
- Information about minors or vulnerable individuals.
- Sensitive personal data — sexual orientation, religion, political views.
- Income, tax data, financial position data.
- Account credentials — usernames and passwords combined.
If even ONE affected individual’s data falls into these categories, the breach is notifiable for that individual regardless of total numbers.
“Significant scale” — 500 or more individuals
If 500 or more individuals are affected — even if the data is low-sensitivity (e.g. names and email addresses only) — the PDPC must be notified.
4. The 72-hour deadline (Section 26D)
Once the company has assessed a breach as notifiable, it must:
- Notify the PDPC as soon as practicable, and in any case within 3 calendar days (72 hours) after determining the breach is notifiable.
- Notify affected individuals at the same time or before notifying the PDPC, unless an exception in Section 26E applies.
The 72 hours starts from the moment the company concludes the breach is notifiable — not from the moment of the breach itself. But the assessment must also be “expeditious”: the PDPC will not accept a 6-month delay in assessment as a way to defer the 72-hour clock.
5. Exceptions to notifying individuals (Section 26E)
The company may withhold notification to individuals if:
- Remedial action taken: the company has taken any action that renders it unlikely the breach will result in significant harm. For example, the lost laptop is recovered intact and forensics confirm no data exfiltration; or the data was strongly encrypted with the key never compromised.
- Technological protection: the personal data was protected by technological measures (encryption, tokenisation) that make it unlikely to be accessed by an unauthorised person.
- PDPC waives or prohibits notification: typically because notification would prejudice an ongoing law enforcement investigation.
- Other prescribed law enforcement reasons.
The PDPC must still be notified even when individuals are not.
6. What the PDPC notification must contain
The notification (made through the PDPC’s online breach reporting portal at pdpc.gov.sg) must include:
- Date and time of the breach.
- Nature of the breach (cyber, physical, insider, misdirected disclosure).
- Categories of personal data compromised.
- Number of affected individuals.
- Containment measures already taken.
- Remedial action plan and timeline.
- Whether affected individuals have been notified (and if not, why).
- Contact details of the Data Protection Officer (DPO).
7. Penalties for non-compliance
Section 48J of the PDPA gives the PDPC power to impose a financial penalty of up to:
- 10% of an organisation’s annual Singapore turnover (if turnover exceeds SGD 10m); or
- SGD 1 million, whichever is higher.
Recent PDPC enforcement actions show penalties of SGD 30,000–SGD 100,000 are common for breach-notification failures, with the largest penalties reserved for breaches showing systemic security failings (e.g. unpatched servers, weak access controls).
8. The board playbook — what to do when a breach is discovered
Hour 0 to Hour 24 — contain and assess
- Activate the incident response team — DPO, CIO/CTO, in-house counsel, CEO, COO.
- Contain — isolate affected systems, change credentials, block exfiltration.
- Preserve evidence — forensic image of affected systems, log files, audit trails.
- Scope assessment — what data, how many individuals, what time period.
- Engage external incident-response counsel if scale is significant.
Hour 24 to Hour 72 — assess notifiability
- Apply the Section 26B threshold (significant harm? significant scale?).
- Consider Section 26E exceptions.
- Document the assessment in writing — the PDPC will request this.
- Prepare the notification draft for the PDPC and for affected individuals.
- Board update — the directors should be briefed before notification goes out.
Day 3 — notify
- File the PDPC notification through the online portal.
- Send notification to affected individuals (email, SMS, or letter — whichever is most likely to reach them).
- Prepare media holding statement if the breach is likely to become public.
Week 1 to Month 3 — remediate
- Root cause analysis and remediation plan.
- Update security policies and conduct staff retraining.
- Respond to PDPC information requests — the regulator typically follows up within 2 weeks.
- Document lessons learned in the breach register.
9. Preventive measures — what good practice looks like
- Appoint a DPO and register their contact details with ACRA and the PDPC. The DPO does not need to be a Singapore resident but must be reasonably contactable.
- Maintain a data inventory — what personal data, where stored, who has access, retention period.
- Implement encryption for personal data at rest and in transit. This invokes the Section 26E “technological protection” exception in the worst case.
- Vendor due diligence — under PDPA compliance principles, you remain responsible for personal data processed by your vendors. Contractually require breach notification within 24 hours.
- Run breach simulations twice a year so the incident response team has muscle memory.
- Cyber insurance — coverage for forensic costs, regulator fines (where insurable), and individual notification costs is now common in Singapore.
10. Cross-border breaches
A breach affecting Singapore individuals must be notified to the PDPC even if the company is based overseas — Singapore’s PDPA applies extra-territorially under Section 4 to organisations that collect, use, or disclose personal data in Singapore. A multinational that suffers a global breach should treat Singapore as one of multiple notification jurisdictions (alongside GDPR, Hong Kong PCPD, Australia OAIC etc.).
11. Frequently asked questions
What if I am not sure the breach is notifiable — should I notify anyway?
Over-notification is generally safer than under-notification. The PDPC publishes a model notification template precisely because conservative reporting is encouraged. If in doubt, file.
Does the 72-hour clock start at the moment of the breach or the moment of discovery?
The clock starts from the moment the company concludes the breach is notifiable. The PDPC expects assessment to be “expeditious” — generally within 30 days of discovery. Sitting on a known breach to defer the clock invites enforcement action.
Can we delay notifying individuals to avoid reputational harm?
No. The only grounds for not notifying individuals are the Section 26E exceptions (remedial action, technological protection, or law enforcement). Reputational harm is not an exception.
What records do I need to keep?
Maintain a written breach register — even for breaches that are not notifiable. The register should record date of discovery, nature, scope, assessment outcome, and remedial action. The PDPC may request this during an investigation or routine audit.
Are directors personally liable?
Directors and DPOs can be personally fined under Section 56 of the PDPA where the offence was committed with their consent or connivance, or attributable to their neglect. Directors who ignore obvious cyber-security gaps face individual exposure.
See related reading on AML compliance and D&O liability insurance.
Raffles Corporate Services helps boards build the practical apparatus — incident response plans, vendor DPA templates, DPO secondment arrangements, and post-breach PDPC liaison. The 72-hour clock is short. Most of the work has to happen before the breach, not after.
— The Editorial Team, Raffles Corporate Services