Frequently Asked Questions

What is considered a personal data breach under the PDPA?

A personal data breach under the PDPA is generally defined as the unauthorised access, collection, use, disclosure, copying, modification or disposal of personal data, or the loss of storage medium or device on which personal data is stored, in circumstances where unauthorised access to the data is likely to have occurred.

A breach can arise from a wide range of causes, including cyberattacks such as hacking or ransomware, human error such as sending personal data to the wrong recipient or losing an unencrypted device, and system failures that expose personal data to unauthorised access.

Not every incident involving personal data automatically constitutes a notifiable breach requiring formal reporting, since the PDPA’s notification regime specifically distinguishes between a general data breach and one that meets the specific criteria for being a notifiable breach based on the likely harm or scale involved.

Because properly identifying whether an incident constitutes a personal data breach, and if so whether it meets the notification threshold, requires a careful assessment against the specific PDPA criteria, organisations experiencing any incident involving personal data should conduct this assessment promptly, ideally with legal advice, rather than assuming an incident is too minor to warrant formal consideration.


When must an organisation notify the PDPC of a data breach?

An organisation must notify the Personal Data Protection Commission of a data breach where the breach is likely to result in significant harm to affected individuals, assessed against factors such as the sensitivity of the personal data involved and the likelihood of the data being misused if accessed by an unauthorised party.

An organisation must also notify the PDPC where the breach is of a significant scale, generally assessed by reference to the number of individuals affected meeting or exceeding a specified numerical threshold, regardless of whether significant harm to any individual is otherwise apparent.

Where a breach meets either of these notification criteria, the organisation is generally required to notify the PDPC as soon as practicable, and in any event within a specified short period, commonly understood to be measured in a small number of days, from the time the organisation determines the breach is notifiable.

Because the assessment of whether a breach meets the notification threshold, and the subsequent tight timeframe for notification once that determination is made, both require prompt and careful action, organisations experiencing a suspected data breach should engage their Data Protection Officer and, where appropriate, legal advice immediately to properly assess the situation and meet any applicable notification deadline.


When must affected individuals be notified directly?

Affected individuals generally need to be notified directly where the data breach is likely to result in significant harm to them, using similar criteria to the significant harm assessment that determines whether the breach is notifiable to the PDPC, since the purpose of individual notification is to allow affected individuals to take steps to protect themselves.

Where a breach meets the significant scale threshold based on the number of individuals affected, but is not independently assessed as likely to cause significant harm to those individuals, the organisation may not be strictly required to notify the affected individuals directly, though it would still need to notify the PDPC based on the scale of the breach.

Certain exceptions to the individual notification requirement can apply, such as where the organisation has already taken remedial action that makes it unlikely the breach will result in significant harm, or where notification is prohibited or restricted by another law applicable to the specific situation.

Because the assessment of whether individual notification is required involves specific criteria that can differ from the PDPC notification assessment, organisations should carefully and separately consider both questions when responding to a data breach, and should seek legal advice to properly determine their notification obligations to both the regulator and affected individuals.


What immediate containment and assessment steps should an organisation take?

An organisation that discovers a suspected data breach should immediately take steps to contain the breach, such as isolating affected systems, revoking compromised access credentials, or otherwise stopping the ongoing unauthorised access or disclosure, since containing the breach is generally the most urgent immediate priority.

The organisation should promptly assess the scope of the breach, including what personal data was involved, how many individuals are affected, and how the breach occurred, since this assessment forms the basis for determining whether the breach meets the notification thresholds under the PDPA.

The organisation should engage its Data Protection Officer and, where the breach appears significant, external legal and, where relevant, technical forensic advisers, to properly investigate the breach and ensure the organisation’s response, including any notification decisions, is properly informed and documented.

Because the effectiveness of the organisation’s response, including both containing the breach and properly meeting any notification obligations within the applicable tight timeframes, depends on acting quickly and in a coordinated manner, organisations should have an incident response plan prepared in advance of any actual breach, rather than attempting to develop a response process for the first time while already dealing with an active incident.


What records should be kept after a data breach is discovered?

Organisations should maintain a clear record of the timeline of the breach, including when it was discovered, when the organisation determined whether it met the notification thresholds, and the actions taken in response, since this record is important both for the organisation’s own governance and as evidence of the organisation’s response if later scrutinised by the PDPC.

Organisations should maintain records of the specific personal data involved in the breach, the number and, where identifiable, the identity of affected individuals, and the assessed likelihood and severity of harm to those individuals, since this information forms the basis for the organisation’s notification decisions and any subsequent PDPC review.

Where the organisation decides a breach does not meet the notification thresholds and therefore does not notify the PDPC or affected individuals, it should still maintain a clear record of this assessment and the reasoning behind it, since the PDPC can review an organisation’s handling of a breach even where the organisation determined notification was not required.

Because thorough contemporaneous records of the breach response process provide important protection for the organisation if its handling of the breach is later questioned, organisations should ensure their incident response process includes clear documentation requirements at each stage, from initial discovery through to final resolution and any post-incident review.


What counts specifically as a notifiable data breach, as opposed to a minor incident?

A notifiable data breach is one that meets either the significant harm threshold, assessed based on factors including the sensitivity of the data involved and the likelihood of misuse if accessed, or the significant scale threshold, generally based on the number of individuals affected meeting or exceeding the specified numerical benchmark.

A minor incident that does not meet either threshold, such as a very limited exposure of non-sensitive data affecting a small number of individuals with minimal realistic risk of harm, would not be a notifiable breach requiring formal PDPC notification, though organisations should still address and remediate any such incident as a matter of good data protection practice.

The assessment of significant harm involves considering the specific type of data involved, since exposure of highly sensitive data, such as financial information or data that could facilitate identity theft, is more likely to meet the significant harm threshold even for a relatively small number of affected individuals compared with exposure of more routine contact information.

Because the line between a notifiable breach and a minor incident depends on a careful factual assessment against the specific statutory criteria, rather than a simple bright line based solely on the type of incident, organisations should not assume an incident is too minor to require formal assessment, and should conduct this assessment properly for every incident involving personal data, ideally with legal input for anything beyond a clearly trivial matter.


What financial penalties can an organisation face for failing to report a data breach?

An organisation that fails to notify the PDPC of a notifiable data breach within the required timeframe can face financial penalties under the PDPA’s enforcement framework, which following recent amendments can reach up to ten percent of the organisation’s annual turnover in Singapore for larger organisations, or a specified fixed amount for smaller organisations, whichever is higher.

The failure to properly notify is generally treated as a separate compliance failure from the underlying data breach itself, meaning an organisation can face penalties both for inadequate data protection practices that allowed the breach to occur and separately for failing to properly notify once the breach was identified as notifiable.

The PDPC’s assessment of an appropriate penalty for a notification failure generally considers factors such as how long the delay in notification was, whether the delay caused additional harm to affected individuals, and whether the organisation’s failure was due to a genuine oversight or a more deliberate attempt to avoid or delay notification.

Because the financial consequences of a notification failure can be very significant, separate from and in addition to any penalty for the underlying breach itself, organisations should treat the notification assessment and timeline as a critical priority immediately upon discovering any potential data breach, rather than allowing uncertainty about whether notification is required to result in delay.


Can an individual claim compensation, including for emotional distress, after a data breach?

Yes, an individual affected by a data breach can potentially bring a private civil claim under the PDPA’s private right of action, seeking compensation for loss or damage suffered as a direct result of the organisation’s breach of its obligations under the Act.

Whether emotional distress alone, without accompanying financial loss, can support a successful claim depends on how the Singapore courts interpret the scope of recoverable loss or damage under the PDPA’s private right of action, and this is an area where the specific legal position continues to develop through case law.

Where a data breach results in more tangible financial loss, such as costs incurred addressing identity theft or fraud resulting from the exposed data, this type of loss is more straightforwardly capable of supporting a claim, since it represents a clearer and more readily quantifiable form of damage caused by the breach.

Because the scope of compensable harm under the PDPA’s private right of action, particularly regarding purely emotional or distress based harm, involves a developing area of law, individuals considering a claim following a data breach, and organisations assessing their potential exposure, should seek legal advice on the current state of this specific area given how it continues to evolve.


Should an organisation notify affected individuals even where notification is not strictly required?

Yes, many organisations choose to notify affected individuals as a matter of good practice even where the strict legal threshold for mandatory notification is not met, reflecting both an ethical commitment to transparency and a practical recognition that individuals may prefer to know about a breach affecting their data regardless of the assessed likelihood of significant harm.

Voluntary notification can also serve a risk management purpose for the organisation, since individuals who learn of a breach through their own means or through media coverage, rather than directly from the organisation, may react more negatively than if the organisation had proactively informed them, potentially amplifying reputational harm.

Where an organisation does choose to notify individuals voluntarily, it should ensure the notification is clear, accurate and genuinely helpful, explaining what happened, what data was involved, and what steps the individual might reasonably take to protect themselves, rather than a notification that is vague or primarily focused on limiting the organisation’s own liability.

Because the decision to notify beyond the strict legal requirement involves weighing reputational, ethical and practical considerations alongside the legal analysis, organisations facing this decision should discuss the specific circumstances with their legal and communications advisers to determine the most appropriate approach for their specific situation.


What should an individual do if they discover their own data was part of a breach?

An individual who discovers their personal data was involved in a breach, whether through direct notification from the organisation or through other means, should assess what specific data was exposed and consider the realistic risk this creates, such as risk of identity theft if financial or identification information was involved.

Where financial account information may have been exposed, the individual should consider contacting their bank or relevant financial institution to flag the potential risk and monitor for any suspicious activity, and should consider changing passwords for any accounts that may have been affected, particularly where the same password may have been reused across multiple services.

Where the individual believes the organisation responsible for the breach has not properly fulfilled its obligations, such as failing to provide adequate information about the breach or failing to notify when notification appears to have been required, the individual can raise a complaint with the Personal Data Protection Commission.

Where the individual has suffered genuine loss or damage as a result of the breach, they may wish to seek legal advice on whether they have a viable private claim against the organisation under the PDPA, particularly where the loss is significant enough to justify the time and cost of pursuing such a claim.


Thank you for sharing this FAQ...