" /> PDPA and data breaches: what Singapore organisations must do | IT-FIXED

PDPA and data breaches: what Singapore organisations must do | IT-FIXED

PDPA and data breaches: what Singapore organisations must do | IT-FIXED

PDPA and data breaches: what Singapore organisations must do | IT-FIXED

PDPA and data breaches: what Singapore organisations must do | IT-FIXED

PDPA and data breaches: what Singapore organisations must do | IT-FIXED
PDPA and data breaches: what Singapore organisations must do | IT-FIXED

PDPA and data breaches: what Singapore organisations must do

ARTICLES

7 October 2026

Since 1 February 2021, organisations in Singapore have been required to notify the Personal Data Protection Commission (PDPC) of certain data breaches. Since 1 October 2022, the maximum financial penalty for breaching the PDPA has been up to 10% of annual turnover in Singapore for organisations with turnover above S$10 million, or S$1 million, whichever is higher. Data protection is now a board-level matter, not just an IT one.

This article is a practical overview, not legal advice. Please refer to the PDPC’s guidance or your legal adviser for your specific situation.

When a breach must be reported

A breach is notifiable if it is likely to result in significant harm to the individuals affected, or if it affects 500 or more individuals. Once you suspect a breach, you are expected to assess it without undue delay (the PDPC expects this within 30 days). Once you determine it is notifiable, you must inform the PDPC within 3 calendar days, and in cases of significant harm, notify the affected individuals as well.

The IT safeguards that matter most

  • Multi-factor authentication on email, remote access and every cloud service.
  • Timely patching of operating systems, firewalls and applications, and retirement of unsupported systems.
  • Endpoint protection with monitoring, so suspicious activity is noticed and investigated.
  • Encryption of laptops and portable storage.
  • Access control: staff can reach only the data they need, and accounts are removed promptly when people leave.
  • Reliable, tested backups, including an offline or immutable copy.
  • Logs that let you establish what happened and which records were affected.

Be ready before anything happens

Three days is very little time to investigate a breach from scratch. Write a short incident response plan now: who decides, who investigates, who contacts the PDPC and customers, and which IT partner you call. Rehearse it once a year. Organisations that have done this find that an incident becomes a managed process rather than a crisis.

Let’s discuss your IT. If you would like our IT support team to look at your own environment, arrange a consultation and we will be in touch within one business day.