WorldPrivacyAtlas
Laws by country

Data Security & Breach Notification

Personal Data Protection Act 2012 — notifiable data breaches

PDPA Part 6A

Singapore · February 1, 2021

A breach is notifiable if it is of significant scale — the Regulations set that at 500 or more affected individuals — or if it results, or is likely to result, in significant harm to any affected individual. Once the organisation has assessed a breach as notifiable it must notify the PDPC as soon as practicable and in any case no later than three calendar days after that assessment, and notify affected individuals as soon as practicable where the significant-harm limb is engaged. The three days run from the assessment, not from discovery, but the assessment itself must be prompt — an organisation cannot extend its own deadline by taking longer to decide. Data intermediaries must notify the organisation they act for without undue delay.

Act No. 26 of 2012, Part 6A (ss. 26A-26E); Personal Data Protection (Notification of Data Breaches) Regulations 2021Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.