PDPA Data Breach Notification: The 72-Hour Clock Singapore SMEs Keep Getting Wrong
Under Singapore's Personal Data Protection Act, you do not have a flat 72 hours from the moment something goes wrong. You have two clocks running in sequence: a reasonable and expeditious assessment period - which PDPC guidance treats as no more than 30 calendar days from the day you become aware of a suspected breach - followed by a hard 3 calendar days to notify PDPC once you determine the breach is notifiable. The popular "72-hour" shorthand is borrowed from Europe's GDPR and describes the wrong deadline. Understanding which clock you are on, and being able to prove when it started, is the entire difference between a routine notification and a regulator asking why your organisation could not say what happened.
What does the PDPA actually require after a breach?
The Data Breach Notification Obligation has been mandatory since 1 February 2021. The sequence is fixed:
- Become aware. Someone in your organisation learns of a suspected breach - a laptop gone, a mailbox compromised, a customer list emailed to the wrong recipient.
- Assess, expeditiously. Determine whether the breach is notifiable. Take longer than 30 days and you should be able to explain why.
- Notify PDPC within 3 calendar days of determining it is notifiable, using PDPC's online data breach notification form.
- Notify affected individuals as soon as practicable - at the same time as, or after, notifying PDPC.
Where a vendor holds data on your behalf - a payroll bureau, a cloud POS provider, an outsourced IT firm - that data intermediary must notify you without undue delay once it becomes aware. Your clock starts then. This is precisely why the vendor contract matters more than the firewall.
Which breaches are actually notifiable?
Two triggers, and either one is enough. First, significant harm: the breach involves prescribed categories of personal data set out in the Notification of Data Breaches Regulations - identification numbers combined with financial information, bank and credit card details, insurance and medical information, and similar sensitive combinations. Second, significant scale: the breach affects 500 or more individuals.
The exception most SMEs never claim, because they cannot evidence it: if you take remedial action before significant harm occurs, or the compromised data was subject to technological protection such that it is unlikely to result in harm, notification to affected individuals may not be required. Encryption at rest on your laptops and a documented remote-wipe capability turn a notifiable incident into a manageable one. Retrofitting that after the fact is not an option.
Penalties are no longer nominal. Since October 2022, PDPC may impose financial penalties of up to 10% of an organisation's annual turnover in Singapore where that turnover exceeds S$10 million, or S$1 million, whichever is higher.
Why do most SME breaches start in a system nobody owns?
In our client work, the breach almost never originates in the ERP or the accounting system - those have named administrators and audit logs. It originates in the gaps between systems: a WhatsApp group where the sales team forwards customer NRICs to arrange delivery, a shared Google Sheet built by a staff member who has since left, an Excel export from the POS sitting on a personal Dropbox because "the report doesn't give me the columns I need."
Those shadow systems exist because the real systems do not talk to each other. Every manual re-keying step produces an intermediate file, and every intermediate file is a copy of your customer database with no owner, no retention rule, and no access log. When you eliminate double entry between POS, accounting and inventory, you are not only saving admin hours - you are deleting the copies that make a breach both likelier and impossible to scope. If you cannot answer "how many individuals were in that file," you cannot assess against the 500-person threshold, and your 30 days evaporate.
What should be in place before Q4?
Q4 is when this risk peaks: temporary staff onboarded for the year-end and Chinese New Year run-up, experienced admin executives resigning in November and December, and accounts that nobody remembers to close. Five things, none of which need a consultant to start:
- A data asset register. One page. Every system holding personal data, who owns it, how many individuals, where the exports go. Include the WhatsApp groups.
- A named breach coordinator and a deputy. The clock does not pause because your IT person is on leave in December.
- An awareness log. A simple dated record of when a suspected breach was reported internally. Without it you cannot prove when the 30 days began.
- Offboarding as a checklist, not a memory. Email, cloud drive, POS login, accounting system, VPN, WhatsApp Business access, and any shared password. Executed the same day, signed off.
- A pre-filled notification draft. Walk PDPC's online form once, in calm conditions, and note what information it demands. Discovering the required fields on day two of three is how organisations miss the deadline.
How long does a readiness pass take?
For a 15 to 40 person SME, the register and offboarding checklist are an afternoon of interviews and a morning of writing. Closing the shadow-system gaps - integrating POS to accounting, replacing the manual export with a scheduled sync - is a project measured in weeks, and it is worth starting before the November filing pile-up consumes your finance team's attention entirely. The compliance benefit is real, but the operational one usually pays for the work on its own.
Frequently asked questions
Do I still notify PDPC if the breach affected fewer than 500 people?
Yes, if it is likely to result in significant harm - the two triggers are independent. A single misdirected email containing an NRIC together with bank account details can be notifiable. Scale is not a safe harbour.
Our cloud vendor was breached, not us. Are we off the hook?
No. If the vendor processes personal data on your behalf, you remain the organisation with the notification obligation. The vendor must inform you without undue delay; you then assess and notify. Check that your contract obliges them to do so within a defined period, in writing.
What if we discover the breach happened months ago?
The clock runs from awareness, not from the incident date. Assess and notify on the normal timeline, and document the discovery. Historic breaches are common and manageable; concealing one after discovery is the thing PDPC treats seriously.
Digital Perpetual helps Singapore SMEs map where personal data actually lives and close the manual gaps that create uncontrolled copies of it. If you want a readiness pass before Q4, get in touch.
Ready to Transform Your Business?
Let Digital Perpetual help you automate, streamline, and grow.
Get Started with Digital Perpetual →