Let’s talk

Insights for your business.

Mandatory Data Breach Notification Under Singapore’s PDPA: What Companies Must Do (2026)

Wooden gavel on a dark surface

Since 1 February 2021, every Singapore organisation has been under a statutory duty to assess data breaches and notify the Personal Data Protection Commission (PDPC) — and in many cases the affected individuals — within strict deadlines. The Personal Data Protection (Amendment) Act 2020 introduced this regime, codified in Sections 26A to 26E of the PDPA. In 2026, the PDPC is enforcing these obligations actively, and companies that miss the notification deadlines are seeing financial penalties of SGD 30,000–SGD 1m.

This guide explains what counts as a notifiable breach, the 72-hour deadline, the assessment process, and the practical playbook a board should have in the drawer when a breach hits.

1. The statutory framework

Sections 26A–26E of the PDPA, read with Part III of the PDPA Regulations 2021, set out:

The full text is on Singapore Statutes Online (PDPA). The PDPC’s Advisory Guidelines on the Data Protection Provisions set out the regulator’s expectations.

2. What counts as a “data breach”?

A data breach is any unauthorised access, collection, use, disclosure, copying, modification or disposal of personal data — including loss of any storage medium or device. It captures:

3. The notifiable-breach threshold (Section 26B)

A breach is notifiable if it:

(a) results in, or is likely to result in, significant harm to an affected individual; OR

(b) is of a significant scale — affecting 500 or more individuals.

Either limb triggers notification. You only need ONE to apply.

“Significant harm” — the prescribed list

The PDP (Notification of Data Breaches) Regulations 2021 list the categories of personal data that, if compromised, are presumed to cause significant harm. These include:

If even ONE affected individual’s data falls into these categories, the breach is notifiable for that individual regardless of total numbers.

“Significant scale” — 500 or more individuals

If 500 or more individuals are affected — even if the data is low-sensitivity (e.g. names and email addresses only) — the PDPC must be notified.

4. The 72-hour deadline (Section 26D)

Once the company has assessed a breach as notifiable, it must:

The 72 hours starts from the moment the company concludes the breach is notifiable — not from the moment of the breach itself. But the assessment must also be “expeditious”: the PDPC will not accept a 6-month delay in assessment as a way to defer the 72-hour clock.

5. Exceptions to notifying individuals (Section 26E)

The company may withhold notification to individuals if:

  1. Remedial action taken: the company has taken any action that renders it unlikely the breach will result in significant harm. For example, the lost laptop is recovered intact and forensics confirm no data exfiltration; or the data was strongly encrypted with the key never compromised.
  2. Technological protection: the personal data was protected by technological measures (encryption, tokenisation) that make it unlikely to be accessed by an unauthorised person.
  3. PDPC waives or prohibits notification: typically because notification would prejudice an ongoing law enforcement investigation.
  4. Other prescribed law enforcement reasons.

The PDPC must still be notified even when individuals are not.

6. What the PDPC notification must contain

The notification (made through the PDPC’s online breach reporting portal at pdpc.gov.sg) must include:

7. Penalties for non-compliance

Section 48J of the PDPA gives the PDPC power to impose a financial penalty of up to:

Recent PDPC enforcement actions show penalties of SGD 30,000–SGD 100,000 are common for breach-notification failures, with the largest penalties reserved for breaches showing systemic security failings (e.g. unpatched servers, weak access controls).

8. The board playbook — what to do when a breach is discovered

Hour 0 to Hour 24 — contain and assess

  1. Activate the incident response team — DPO, CIO/CTO, in-house counsel, CEO, COO.
  2. Contain — isolate affected systems, change credentials, block exfiltration.
  3. Preserve evidence — forensic image of affected systems, log files, audit trails.
  4. Scope assessment — what data, how many individuals, what time period.
  5. Engage external incident-response counsel if scale is significant.

Hour 24 to Hour 72 — assess notifiability

  1. Apply the Section 26B threshold (significant harm? significant scale?).
  2. Consider Section 26E exceptions.
  3. Document the assessment in writing — the PDPC will request this.
  4. Prepare the notification draft for the PDPC and for affected individuals.
  5. Board update — the directors should be briefed before notification goes out.

Day 3 — notify

  1. File the PDPC notification through the online portal.
  2. Send notification to affected individuals (email, SMS, or letter — whichever is most likely to reach them).
  3. Prepare media holding statement if the breach is likely to become public.

Week 1 to Month 3 — remediate

  1. Root cause analysis and remediation plan.
  2. Update security policies and conduct staff retraining.
  3. Respond to PDPC information requests — the regulator typically follows up within 2 weeks.
  4. Document lessons learned in the breach register.

9. Preventive measures — what good practice looks like

10. Cross-border breaches

A breach affecting Singapore individuals must be notified to the PDPC even if the company is based overseas — Singapore’s PDPA applies extra-territorially under Section 4 to organisations that collect, use, or disclose personal data in Singapore. A multinational that suffers a global breach should treat Singapore as one of multiple notification jurisdictions (alongside GDPR, Hong Kong PCPD, Australia OAIC etc.).

11. Frequently asked questions

What if I am not sure the breach is notifiable — should I notify anyway?

Over-notification is generally safer than under-notification. The PDPC publishes a model notification template precisely because conservative reporting is encouraged. If in doubt, file.

Does the 72-hour clock start at the moment of the breach or the moment of discovery?

The clock starts from the moment the company concludes the breach is notifiable. The PDPC expects assessment to be “expeditious” — generally within 30 days of discovery. Sitting on a known breach to defer the clock invites enforcement action.

Can we delay notifying individuals to avoid reputational harm?

No. The only grounds for not notifying individuals are the Section 26E exceptions (remedial action, technological protection, or law enforcement). Reputational harm is not an exception.

What records do I need to keep?

Maintain a written breach register — even for breaches that are not notifiable. The register should record date of discovery, nature, scope, assessment outcome, and remedial action. The PDPC may request this during an investigation or routine audit.

Are directors personally liable?

Directors and DPOs can be personally fined under Section 56 of the PDPA where the offence was committed with their consent or connivance, or attributable to their neglect. Directors who ignore obvious cyber-security gaps face individual exposure.

See related reading on AML compliance and D&O liability insurance.

Raffles Corporate Services helps boards build the practical apparatus — incident response plans, vendor DPA templates, DPO secondment arrangements, and post-breach PDPC liaison. The 72-hour clock is short. Most of the work has to happen before the breach, not after.

— The Editorial Team, Raffles Corporate Services

Submit a Comment

Your email address will not be published. Required fields are marked *

Real people. Right here in Singapore.

Let’s get to work.

Hop on Raffles Corporate Services