Law note · Singapore
Personal Data Protection Act, data breach notification
cite Personal Data Protection Act 2012, Part 6A, ss.26A-26E, as added by Act 40 of 2020
stage IN FORCE in force since 2021-02-01
kind Breach notification
binds private bodies
reviewed 2026-08-29
What it requires
- An app that experiences a data breach affecting an individual's personal data in Singapore must assess whether the breach is likely to cause significant harm or is of significant scale, and if so must notify the PDPC as soon as practicable and in any case within 3 calendar days of that assessment, and must also notify each affected individual unless a statutory exception applies.
When LexLint raises it
processes_biometricsprocesses_voicecrawls_web
What we found
Part 6A, added by the 2020 amendment, makes a data breach notifiable if it results in, or is likely to result in, significant harm to an affected individual, or is or is likely to be of significant scale; an internal-only breach is deemed not notifiable.
The organisation must notify the PDPC as soon as practicable, and in any case no later than 3 calendar days after assessing the breach is notifiable, and must also notify each affected individual, subject to exceptions where technological measures render significant harm unlikely or a law-enforcement agency or the PDPC directs otherwise.