Data Security & Breach Notification
Personal Data Protection Act 2012 — notifiable data breaches
Singapore · February 1, 2021
A breach is notifiable if it is of significant scale — the Regulations set that at 500 or more affected individuals — or if it results, or is likely to result, in significant harm to any affected individual. Once the organisation has assessed a breach as notifiable it must notify the PDPC as soon as practicable and in any case no later than three calendar days after that assessment, and notify affected individuals as soon as practicable where the significant-harm limb is engaged. The three days run from the assessment, not from discovery, but the assessment itself must be prompt — an organisation cannot extend its own deadline by taking longer to decide. Data intermediaries must notify the organisation they act for without undue delay.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.