Data Breach Notification Duties in Singapore

Since 2021, Singapore organisations have had a legal duty to report serious data breaches. The rules set out when a breach must be reported, how quickly, and who has to be told: the regulator, the affected people, or both. This guide walks through the sequence and the thresholds that decide it.
This is general legal information, not legal advice. Consult a qualified advocate and solicitor about your situation.
Information last verified on 23 July 2026. This page provides general legal information about Singapore law and is not legal advice in an individual case.
Two questions: is it a breach, and is it notifiable
The regime works in two stages. First, is there a data breach at all? The Act defines a data breach broadly as unauthorised access, collection, use, disclosure, copying, modification or disposal of personal data, or the loss of a storage device where such unauthorised access is likely to occur.
Second, is that breach notifiable? Not every breach has to be reported. Only breaches that cross one of two thresholds trigger the notification duties, and the organisation has to work out which, if any, applies.
The assessment duty
When an organisation has reason to believe a breach has occurred, it must assess, in a reasonable and expeditious manner, whether the breach is notifiable. There is no fixed deadline on the assessment step itself; the standard is that it be reasonable and prompt. The deadlines that follow are triggered by the outcome of that assessment, not by the moment of discovery.

The two triggers: significant harm or significant scale
A breach is notifiable if either trigger is met. The first is significant harm: the breach results in, or is likely to result in, significant harm to an affected individual. The categories of data that raise a significant-harm risk, such as identification numbers combined with financial or account details, are set out in regulations.
The second is significant scale. A breach is of a significant scale if it affects 500 or more individuals. This is a fixed number set by the Notification of Data Breaches Regulations 2021, so a breach can be notifiable on scale alone even if the harm to each person is limited.
There is an important carve-out. A breach that occurs entirely within the organisation, where the personal data was not accessed by anyone outside it, is treated as not notifiable.
Notifying the PDPC: the 3-day clock
If the organisation assesses that the breach is notifiable, it must notify the PDPC as soon as practicable, and in any case no later than 3 calendar days after the day it makes that assessment. The clock runs from the assessment, not from when the breach was first discovered, so the assessment step matters: it is what starts the 3-day count.
Notifying affected individuals: only the significant-harm limb
The duty to notify individuals is narrower than the duty to notify the PDPC. An organisation must also notify each affected individual only where the breach is notifiable under the significant-harm limb. A breach that is notifiable purely because of its scale (500 or more affected individuals), without significant harm, requires notice to the PDPC but does not, by itself, require a notice to every affected individual.

This is a distinction that is easy to get wrong. It is not correct to say that any breach affecting 500 people means everyone must be written to. The PDPC always has to be told; the individuals have to be told when the significant-harm limb is engaged.
Exceptions to notifying individuals
Even where the significant-harm limb is met, individual notification is not required in certain cases. It is not required where the organisation has already taken remedial action that makes significant harm to the individual unlikely, or where the affected data was protected by technological measures such as encryption to the same effect. It is also barred where a law enforcement agency instructs the organisation not to notify, or where the PDPC directs otherwise, and the PDPC can waive the requirement on written application.
Data intermediaries and the notification chain
Many organisations use a data intermediary to process personal data on their behalf, such as an IT vendor or a payroll processor. Where a data intermediary has reason to believe a breach has occurred in data it processes for another organisation, it must notify that other organisation without undue delay. The organisation on whose behalf the data was processed then carries the assessment and notification duties. The PDPA duties also apply on top of any sector-specific breach-reporting rule, not instead of it.
What happens if an organisation does not notify
Breach notification is one of the obligations the PDPC enforces, and a failure to notify can lead to a financial penalty alongside any penalty for the underlying security lapse. If you are an individual who has been affected by a breach, the breach notification duty runs to the regulator and to you; a separate route exists if you want to seek compensation. For how to raise a concern, see the guide on how to complain to the PDPC, and for the framework as a whole see the data protection and the PDPA section page.

Frequently Asked Questions
When does a Singapore organisation have to report a data breach?
A breach must be reported when it is notifiable, meaning it results in or is likely to result in significant harm to affected individuals, or it is of a significant scale of 500 or more affected individuals. The organisation must first assess whether either trigger is met.
How quickly must a data breach be reported to the PDPC?
As soon as practicable, and no later than 3 calendar days after the day the organisation assesses the breach to be notifiable. The 3-day clock runs from the organisation's own assessment, not from the moment the breach was discovered.
Does every large breach mean every affected person must be told?
No. The duty to notify each affected individual is tied to the significant-harm limb. A breach that is notifiable only because it affects 500 or more people, without significant harm, requires notice to the PDPC but does not by itself require a notice to every individual.
Is a breach that stays inside the organisation notifiable?
Generally no. A breach that occurs entirely within the organisation, where the personal data was not accessed by anyone outside it, is treated as not notifiable under the PDPA.
What are an organisation's duties if a vendor causes the breach?
A data intermediary that has reason to believe a breach has occurred in data it processes for another organisation must notify that organisation without undue delay. The organisation on whose behalf the data was processed then carries out the assessment and any required notifications to the PDPC and affected individuals.
Updates
The mandatory data breach notification obligation under Part 6A of the PDPA came into force, applying to data breaches occurring on or after this date.
Sources and References
- Personal Data Protection Act 2012, Part 6A (Notification of data breaches, ss 26A to 26E)(sso.agc.gov.sg).gov
- Personal Data Protection (Notification of Data Breaches) Regulations 2021 (reg 3 significant harm, reg 4 the 500 threshold)(sso.agc.gov.sg).gov
- Personal Data Protection Commission, guide on managing and notifying data breaches(pdpc.gov.sg).gov