Handling a Personal Data Breach in Singapore: What the Law Requires You to Do
A data breach on its own isn't automatically a Personal Data Protection Act (PDPA) violation. How you respond in the days after it is where most organisations actually get into trouble.
A personal data breach can happen to a well-run company: a lost laptop, a misdirected email with an attachment, a vendor's system compromised, an employee error. What separates a manageable incident from a regulatory problem is often not the breach itself, but how it's assessed and handled afterward. The PDPA's Notification Obligation sets out exactly what's expected.
Step 1: Contain and Assess
The first response to a suspected breach is containment: stopping the ongoing exposure, whether that's revoking access, taking a system offline, or recalling a misdirected communication where possible. Once contained, the organisation must assess whether the incident is a "notifiable data breach" under the PDPA.
When Notification Is Required
A data breach is notifiable if it results in, or is likely to result in, significant harm to affected individuals, or if it is of a significant scale (affecting a large number of individuals, based on a threshold set out in the Act's subsidiary legislation). "Significant harm" is assessed based on the type of data involved: financial information, national identification numbers, and health information generally carry a lower threshold for what counts as significant harm than, say, a name and email address alone.
This assessment needs to be documented, not just made informally, since PDPC can ask to see the reasoning behind a decision not to notify.
Who Needs to Be Notified, and By When
- The Personal Data Protection Commission (PDPC). As soon as practicable, and in any case within 3 calendar days of determining that the breach is notifiable.
- Affected individuals. Notified at the same time as, or after, PDPC, unless a specific exception applies (for example, if notifying individuals would itself worsen the situation, or if the organisation has already taken remedial action that renders the breach unlikely to result in significant harm).
The 3-day clock starts from when the organisation determines the breach is notifiable, not from when the breach itself occurred. Organisations are still expected to carry out that assessment promptly rather than delaying the determination itself.
What the Notification Needs to Cover
- The circumstances of the breach, including when and how it was discovered.
- The types of personal data involved.
- What the organisation has done or plans to do in response, including containment and remedial steps.
- Contact information for someone who can answer questions about the breach (typically the data protection officer (DPO)).
If a Data Intermediary Is Involved
If a vendor processing data on your behalf (a data intermediary) suffers the breach, they're required to notify you without undue delay once they become aware of it. Responsibility for assessing notifiability and notifying PDPC and affected individuals generally still sits with your organisation as the one that determines the purpose of processing, which is why vendor contracts should include a clear breach-notification clause with defined timelines back to you.
Being Ready Before It Happens
The 3-day window is short enough that improvising a response process during an actual breach usually means missing it, or notifying with incomplete information. A basic incident response plan, covering who assesses, who decides, who drafts the notification and who contacts PDPC, prepared in advance turns a stressful scramble into a checklist to follow.
Want a breach response plan in place before you need one?
Compliz helps businesses build a PDPA-compliant breach response process, and can act as your outsourced DPO to manage the assessment and notification if a breach occurs.
Request a QuoteFrequently Asked Questions
Do I need to notify PDPC for every data breach?
No. Only breaches that meet the "significant harm" or "significant scale" thresholds are notifiable, though smaller incidents should still be assessed and documented even if not reported.
What counts as "significant harm"?
It depends on the type of data involved; financial information, national identification numbers and health data generally carry a lower threshold than basic contact details.
Can I notify affected individuals before PDPC?
Individuals are generally notified at the same time as or after PDPC, unless a specific exception applies, such as when early notification would worsen the situation.
What if my vendor causes the breach, not us?
As the organisation that determines the purpose of processing, you generally remain responsible for assessing and notifying, so vendor contracts should include a clear breach-notification clause.
What are the penalties for failing to notify a breach?
PDPC can impose financial penalties for failing to comply with the Notification Obligation, in addition to any separate penalties for the underlying data protection failure.
