All Insights Personal Data Solution

Handling a Personal Data Breach in Singapore: What the Law Requires You to Do

A data breach on its own isn't automatically a Personal Data Protection Act (PDPA) violation. How you respond in the days after it is where most organisations actually get into trouble.

Compliz Insights · Personal Data Solution · ·

A personal data breach can happen to a well-run company: a lost laptop, a misdirected email with an attachment, a vendor's system compromised, an employee error. What separates a manageable incident from a regulatory problem is often not the breach itself, but how it's assessed and handled afterward. The PDPA's Notification Obligation sets out exactly what's expected.

Step 1: Contain and Assess

The first response to a suspected breach is containment: stopping the ongoing exposure, whether that's revoking access, taking a system offline, or recalling a misdirected communication where possible. Once contained, the organisation must assess whether the incident is a "notifiable data breach" under the PDPA.

When Notification Is Required

A data breach is notifiable if it results in, or is likely to result in, significant harm to affected individuals, or if it is of a significant scale (affecting a large number of individuals, based on a threshold set out in the Act's subsidiary legislation). "Significant harm" is assessed based on the type of data involved: financial information, national identification numbers, and health information generally carry a lower threshold for what counts as significant harm than, say, a name and email address alone.

This assessment needs to be documented, not just made informally, since PDPC can ask to see the reasoning behind a decision not to notify.

Who Needs to Be Notified, and By When

The 3-day clock starts from when the organisation determines the breach is notifiable, not from when the breach itself occurred. Organisations are still expected to carry out that assessment promptly rather than delaying the determination itself.

What the Notification Needs to Cover

If a Data Intermediary Is Involved

If a vendor processing data on your behalf (a data intermediary) suffers the breach, they're required to notify you without undue delay once they become aware of it. Responsibility for assessing notifiability and notifying PDPC and affected individuals generally still sits with your organisation as the one that determines the purpose of processing, which is why vendor contracts should include a clear breach-notification clause with defined timelines back to you.

Being Ready Before It Happens

The 3-day window is short enough that improvising a response process during an actual breach usually means missing it, or notifying with incomplete information. A basic incident response plan, covering who assesses, who decides, who drafts the notification and who contacts PDPC, prepared in advance turns a stressful scramble into a checklist to follow.

Want a breach response plan in place before you need one?

Compliz helps businesses build a PDPA-compliant breach response process, and can act as your outsourced DPO to manage the assessment and notification if a breach occurs.

Request a Quote

Frequently Asked Questions

Do I need to notify PDPC for every data breach?

No. Only breaches that meet the "significant harm" or "significant scale" thresholds are notifiable, though smaller incidents should still be assessed and documented even if not reported.

What counts as "significant harm"?

It depends on the type of data involved; financial information, national identification numbers and health data generally carry a lower threshold than basic contact details.

Can I notify affected individuals before PDPC?

Individuals are generally notified at the same time as or after PDPC, unless a specific exception applies, such as when early notification would worsen the situation.

What if my vendor causes the breach, not us?

As the organisation that determines the purpose of processing, you generally remain responsible for assessing and notifying, so vendor contracts should include a clear breach-notification clause.

What are the penalties for failing to notify a breach?

PDPC can impose financial penalties for failing to comply with the Notification Obligation, in addition to any separate penalties for the underlying data protection failure.