What to do when personal data is exposed: containment, deciding whether the incident is notifiable, notifying the PDPC within the deadline, and documenting the decision either way.
Data breaches require immediate action. You have just 3 days to report notifiable breaches to the PDPC. Poor handling can result in penalties up to S$1 million, massive reputational damage, and loss of customer trust. Do not face it alone: your DPO handles the assessment, the notification and the remediation.
Breach-response support is included in the outsourced DPO service according to the response arrangements of your tier: email on Essential, phone from Business, same-day on Enterprise.
We talk you through the steps that limit the exposure and preserve what you will need later: what to shut off, what to keep, and what not to touch.
Support with the PDPC notification: assessing whether the threshold is met, preparing the submission, and handling the correspondence that follows.
Establishing what data was involved and how many individuals are affected, which is what the notification decision turns on. Where technical forensics are needed, we work alongside whoever performs them.
We draft notifications to affected individuals, prepare FAQ documents, and manage customer inquiries professionally.
Post-breach security improvements, policy updates, and preventive measures to avoid future incidents.
We establish what was exposed, whose data it was and how far it went, then guide the containment actions that follow from that.
Determine what data was affected, how many individuals, and whether breach is notifiable under PDPA.
Prepare and submit required notifications to PDPC within 3-day deadline, with all mandatory information.
Draft and send notifications to affected individuals with clear guidance on protective actions they should take.
Conduct thorough investigation to identify root cause, assess full impact, and gather evidence.
Implement fixes, strengthen security controls, update policies, and prevent recurrence.
Under Singapore’s PDPA, you must notify the PDPC within 3 days if a breach meets either criteria:
Missing the 3-day deadline can result in additional penalties beyond those for the breach itself.
Your DPO helps you work out whether the breach is notifiable and supports the PDPC submission if it is, according to the response arrangements of your tier.
Employee falls for phishing email, compromising credentials or sensitive data
Systems encrypted by attackers demanding payment, potentially with data exfiltration
Accidental mass email exposing recipients’ addresses or attachments to wrong parties
Stolen or lost laptops, phones, or USB drives containing unencrypted personal data
Documents or devices with personal data discarded without proper destruction
Internal staff or external hackers accessing systems beyond authorization
Publicly accessible databases or storage buckets exposing customer information
Third-party data intermediaries experiencing breaches affecting your customers’ data
Whether you are dealing with an incident now or want a response plan before you need one, we can help. Breach readiness is part of our PDPA compliance services, and ongoing breach handling sits with your appointed outsourced DPO.
Talk to us about breach readinessOr call us on +65 8189 7974
Disclaimer: This guide is general information, not legal advice. The Personal Data Protection Act and the PDPC’s advisory guidelines are the authoritative sources on notification thresholds and deadlines, and requirements change. For a specific incident, seek qualified advice.