A free, printable checklist for managing a personal data breach under Singapore's PDPA. 29 actions across four phases, ordered by when you actually need them, and built around the deadline that makes breach response hard: 3 calendar days to notify the PDPC once you determine a breach is notifiable.
Four phases, 29 actions, plus a key contacts block to fill in before you need it. Free, via a short form on our resources page.
Get the template| Phase | When | Actions | Covers |
|---|---|---|---|
| 1. Immediate response | First 24 hours | 9 | Confirm and contain, preserve evidence, activate the response team, isolate systems, rotate compromised credentials, notify the DPO and management |
| 2. Assessment | 24 to 72 hours | 8 | Establish what data was affected and how sensitive it is, how many individuals, and whether the breach meets the notification thresholds |
| 3. Notification | Within the deadline | 6 | Notifying the PDPC, notifying affected individuals, and recording what was sent and when |
| 4. Recovery and prevention | After | 6 | Closing the gap that caused it, reviewing controls, and documenting lessons so the same failure does not recur |
It also includes a key contacts block and the PDPC notification criteria on the page itself. Fill the contacts in now: the point of a response plan is that nobody is looking up phone numbers at 11pm.
You must notify the PDPC no later than 3 calendar days after determining that a breach is notifiable. Calendar days, not working days, so a Friday discovery does not buy you the weekend.
A breach is notifiable if either applies:
The clock starts when you complete your assessment, not when the breach happened. That is not licence to assess slowly: the PDPC expects the assessment to be prompt, and an unreasonably delayed one is itself a problem. Phases 1 and 2 of the template exist to get you to that determination quickly and defensibly.
The PDPA does not list a breach response plan as a separate obligation. What it requires, under the Accountability Obligation, is that you develop and implement policies and practices to meet your obligations. A three-day notification deadline is short enough that an unplanned response usually misses it, which is how a containable incident becomes a second finding.
In published PDPC decisions, the absence of established practices has counted against organisations directly. See PDPA fines in Singapore for what those decisions actually said and cost.
A gap assessment produces the data inventory the plan depends on, which is the part that makes the first 48 hours cheap instead of expensive.
Get a Gap AssessmentAt minimum: how you contain the breach and preserve evidence, how you assess whether it is notifiable, who notifies the PDPC and affected individuals and by when, and what remediation follows. Our free template covers 29 actions across four phases, from the first 24 hours through to prevention, with a key contacts block you fill in ahead of time.
No later than 3 calendar days after determining the breach is notifiable, and calendar days include weekends and public holidays. A breach is notifiable if it is likely to result in significant harm to affected individuals, or if it involves the personal data of 500 or more individuals. The PDPC expects the assessment itself to be completed promptly.
The PDPA does not name a written plan as a separate obligation, but the Accountability Obligation requires you to have policies and practices in place to meet your obligations, and the notification deadline is short enough that an unplanned response usually misses it. In published enforcement decisions, the absence of established practices has counted against organisations.
Yes. Download it, fill in your own contacts and escalation names, and use it internally. It is a starting point written for Singapore SMEs, not legal advice, and you should adapt it to how your organisation actually works.
Disclaimer: This template and article are for general information only and do not constitute legal advice. Notification thresholds and deadlines are set by the PDPA and PDPC guidance and can change. Adapt the template to your own organisation, and for a live incident seek qualified advice promptly.