English中文
Singapore flag

Singapore

Data Breach Notification Duties in Singapore

Independently fact-checkedBy Recording Law Editorial Team7 min read

Independently fact-checked against primary sources (last audited July 22, 2026). · 3 primary sources cited on this page. How we verify our legal content

Data Breach Notification Duties in Singapore

Frequently Asked Questions

When does a Singapore organisation have to report a data breach?

A breach must be reported when it is notifiable, meaning it results in or is likely to result in significant harm to affected individuals, or it is of a significant scale of 500 or more affected individuals. The organisation must first assess whether either trigger is met.

How quickly must a data breach be reported to the PDPC?

As soon as practicable, and no later than 3 calendar days after the day the organisation assesses the breach to be notifiable. The 3-day clock runs from the organisation's own assessment, not from the moment the breach was discovered.

Does every large breach mean every affected person must be told?

No. The duty to notify each affected individual is tied to the significant-harm limb. A breach that is notifiable only because it affects 500 or more people, without significant harm, requires notice to the PDPC but does not by itself require a notice to every individual.

Is a breach that stays inside the organisation notifiable?

Generally no. A breach that occurs entirely within the organisation, where the personal data was not accessed by anyone outside it, is treated as not notifiable under the PDPA.

What are an organisation's duties if a vendor causes the breach?

A data intermediary that has reason to believe a breach has occurred in data it processes for another organisation must notify that organisation without undue delay. The organisation on whose behalf the data was processed then carries out the assessment and any required notifications to the PDPC and affected individuals.

Updates

Independently fact-checked against the cited primary sources

The mandatory data breach notification obligation under Part 6A of the PDPA came into force, applying to data breaches occurring on or after this date.

Sources and References

  1. Personal Data Protection Act 2012, Part 6A (Notification of data breaches, ss 26A to 26E)(sso.agc.gov.sg).gov
  2. Personal Data Protection (Notification of Data Breaches) Regulations 2021 (reg 3 significant harm, reg 4 the 500 threshold)(sso.agc.gov.sg).gov
  3. Personal Data Protection Commission, guide on managing and notifying data breaches(pdpc.gov.sg).gov
Share: