The maximum PDPA fine in Singapore is S$1 million, or 10% of annual Singapore turnover for organisations turning over more than S$10 million, whichever is higher. That is the number people quote. It is not the number most businesses should plan around. Actual penalties against smaller organisations have commonly landed between S$3,000 and S$50,000, and they are issued for a short, repetitive list of failures that are cheap to fix before a breach and expensive to explain afterwards.
Under section 48J of the PDPA, the Personal Data Protection Commission can impose a financial penalty on an organisation for breaching the Data Protection Provisions. Since 1 October 2022 the ceiling has been:
The higher of the two applies. The increase came from the 2020 amendments to the PDPA, but commencement was held back during the pandemic and only took effect in October 2022.
Published enforcement decisions are the honest guide to exposure. The table below lists notable financial penalties, drawn from PDPC decisions and press releases.
| Organisation | Date | Penalty | Scale and finding |
|---|---|---|---|
| IHiS | Jan 2019 | S$750,000 | SingHealth cyberattack. Over 1.5 million patients affected. Largest single penalty issued to date. |
| Marina Bay Sands | Oct 2025 | S$315,000 | Breach of the Protection Obligation. The largest penalty issued since the 2022 increase. |
| SingHealth | Jan 2019 | S$250,000 | Penalised as owner of the patient database system in the same cyberattack. |
| Air Sino-Euro Associates Travel | Oct 2025 | S$47,000 | 336,759 individuals affected. No DPO appointed, no internal data-handling policies, outdated operating systems, no multifactor authentication. |
| Singapore Data Hub | Apr 2025 | S$17,500 | 689,000 individuals affected across two intrusions. No reasonable access controls, no periodic security review, outdated systems. |
| People Central | Jan 2026 | S$17,500 | 95,000 individuals plus 24,765 emergency contacts. No periodic security review, no layered security, no vulnerability assessment. |
| Ascentis | Oct 2023 | S$10,000 | Failure to put in place reasonable security arrangements to protect personal data. |
At the lower end, penalties on small businesses have been reported at S$9,000 for Century Evergreen and S$3,000 for Autobahn Rent A Car. These are the figures a small Singapore company is realistically closer to than the headline cap.
Notice what the table shows. Two organisations exposed the data of hundreds of thousands of people and were fined S$17,500 each. A casino operator was fined S$315,000. A national health system was fined S$1 million between two entities after the largest breach in Singapore’s history.
Penalty size tracks the seriousness of the failure and the sensitivity of the data, not simply the headcount in the leak. The PDPC weighs how egregious the security lapse was, how sensitive the data was, how the organisation responded, and what it did to put things right. An organisation with 689,000 records exposed can be fined less than one with none exposed at all if the first cooperated and remediated and the second was reckless.
Read enough decisions and the same failures recur. Across the cases above, the findings cluster into a handful of causes:
None of these are exotic. They are the controls a competent annual review would catch.
This is the part organisations most often assume is a technicality. Under the PDPA every organisation must appoint at least one individual as its Data Protection Officer and make that person’s business contact information publicly available. The DPO can be an existing employee or an outsourced provider, but the appointment itself is not optional.
In the Air Sino-Euro Associates Travel decision of October 2025, the PDPC’s findings expressly included that the organisation had not appointed a data protection officer before the breach, alongside its failure to establish internal data-handling policies and processes. The S$47,000 penalty was for breaching both the Accountability Obligation and the Protection Obligation.
In other words, the absence of a DPO was not treated as a paperwork oversight discovered along the way. It formed part of what the organisation was penalised for.
A PDPA gap assessment maps your current position against the obligations the PDPC actually enforces, and tells you what to fix first. Fixed price, no guesswork.
Get a PDPA Gap AssessmentSince the mandatory breach notification regime took effect, a breach must be reported to the PDPC no later than 3 calendar days after you determine it is notifiable. Calendar days, not working days: weekends and public holidays count.
A breach is notifiable if either of these is true:
The clock starts when you complete your assessment, not when the breach happened. That is not an invitation to assess slowly: the PDPC expects the assessment to be done promptly, generally within 30 days of becoming aware of the incident, and an unreasonably delayed assessment is itself a problem. If you do not yet have the full picture, submit a preliminary notification and update it. Early and incomplete beats late and tidy.
The PDPC weighs conduct after the breach as well as the failure that caused it. Consistently, the factors that help are:
That last point is the quiet argument for appointing a DPO before you need one. The organisation that can show a named DPO, a written policy and a dated security review is in a materially different position from one producing all three for the first time in response to an investigation.
Since 1 October 2022, the maximum financial penalty under section 48J of the PDPA is 10% of an organisation’s annual turnover in Singapore for organisations whose Singapore turnover exceeds S$10 million, or S$1 million in every other case, whichever is higher. For most SMEs, whose turnover is below S$10 million, the effective cap is S$1 million.
Real PDPC decisions against smaller organisations have landed well below the cap, commonly in the S$3,000 to S$50,000 range. Reported examples include S$3,000 for Autobahn Rent A Car, S$9,000 for Century Evergreen, S$10,000 for Ascentis, and S$17,500 each for Singapore Data Hub and People Central. The headline S$1 million cap is not the number an SME should plan around.
The largest remains the SingHealth cyberattack penalties of January 2019, totalling S$1 million: S$750,000 against Integrated Health Information Systems (IHiS) and S$250,000 against SingHealth. The breach exposed the personal data of more than 1.5 million patients. The largest since the 2022 penalty increase is S$315,000 against Marina Bay Sands in October 2025.
Yes. Failure to appoint a DPO is a breach of the Accountability Obligation and has featured directly in enforcement decisions. In October 2025 the PDPC fined Air Sino-Euro Associates Travel S$47,000, and the findings expressly included that the organisation had not appointed a data protection officer before the breach, alongside its failure to establish internal data-handling policies.
You must notify the PDPC no later than 3 calendar days after determining that a breach is notifiable. Calendar days include weekends and public holidays. A breach is notifiable if it is likely to result in significant harm to affected individuals, or if it involves the personal data of 500 or more individuals. The PDPC expects the assessment itself to be completed promptly, generally within 30 days of becoming aware of the incident.
Yes. Enforcement decisions are published on the PDPC website and name the organisation, the breach, and the penalty. For most small businesses the reputational cost of a published decision outweighs the financial penalty itself, because it is permanent, searchable, and increasingly quoted back by AI assistants when someone researches your company.
Disclaimer: This article is for general information only and does not constitute legal advice. Penalty amounts and dates are drawn from published PDPC enforcement decisions and press releases and are accurate to the best of our knowledge at the date of publication. Penalty caps, obligations and enforcement practice change. For current requirements and the full text of any decision, refer to the Personal Data Protection Commission (PDPC) and seek qualified advice for your specific situation.