What Are Your PDPA Obligations If Your SME Suffers a Data Breach?
If your SME discovers a data breach, the Personal Data Protection Act requires you to assess it within 30 days and, if it's likely to cause significant harm, notify the Personal Data Protection Commission (PDPC) as soon as practicable — and in any case within 72 hours of forming that assessment. Miss this window, mishandle the notification, or fail to notify affected individuals when required, and you're exposed to financial penalties of up to 10% of annual turnover in Singapore, or S$1 million, whichever is higher. For most SMEs, the gap isn't malice — it's not knowing the clock has already started.
Why Are PDPA Breach Cases Rising Among Singapore SMEs in 2026?
Phishing remains the single most common entry point into SME systems, and attackers have gotten better at impersonating suppliers, banks, and even government agencies like IRAS during tax season. A staff member clicking a malicious invoice link, a compromised email account used to redirect payments, or an unsecured shared drive exposing customer records — these are the everyday scenarios PDPC enforcement decisions keep citing, not sophisticated nation-state attacks. SMEs are attractive targets precisely because they hold real customer data (names, NRICs, payment details) but typically lack dedicated IT security staff to catch an intrusion early. The PDPC has also signalled it is paying closer attention to smaller organisations, not just large enterprises, as breach notification numbers climb year over year.
What Counts as a Notifiable Data Breach Under the PDPA?
Not every incident triggers a mandatory report. The PDPA distinguishes between breaches that are merely unauthorised access or disclosure, and those "likely to result in significant harm" to individuals — this includes leaked NRIC numbers, financial information, health records, or passwords that could enable identity theft or fraud. A breach is also notifiable regardless of harm if it affects 500 or more individuals, since scale itself is treated as a risk factor. If your SME's customer database, payroll system, or POS platform is breached and any of these thresholds are met, notification isn't optional — it's a legal duty that starts the moment you become aware, not the moment you finish investigating.
What Exactly Must You Do in the First 72 Hours?
The clock starts when your organisation has "reasonable grounds to believe" a breach occurred — which can be earlier than most owners assume, sometimes triggered by a single suspicious login alert. Within that window, you need to: contain the breach (revoke compromised credentials, isolate affected systems); assess scope and severity (what data, how many individuals, what harm is plausible); and if the notifiable threshold is met, submit a report to the PDPC via their online portal with details of the breach, the data involved, and remediation steps taken. If individuals are at significant risk, you must also notify them directly, in a manner and timeframe that allows them to protect themselves — for example, changing passwords or watching for fraudulent transactions. Waiting until you have "the full picture" before notifying is a common and costly mistake; the law expects action on preliminary findings, with updates to follow.
How Should an SME Prepare Before a Breach Happens?
The businesses that handle breaches well have usually done three things in advance. First, they know where their personal data actually lives — customer records scattered across a CRM, a POS system, WhatsApp order threads, and a shared drive are much harder to secure and audit than data consolidated in one access-controlled system. Second, they have a named person (even if it's the owner) responsible for triggering the 72-hour assessment the moment an incident is suspected, so no one is waiting for someone else to act. Third, they've addressed the most common entry points proactively: enforcing multi-factor authentication on email and financial systems, training staff to recognise phishing attempts disguised as supplier or IRAS correspondence, and keeping software and POS terminals patched. None of this eliminates risk, but it compresses your response time from days to hours — which is often the difference between a contained incident and a reportable one with real financial exposure.
What Should You Do If You're Not Sure Whether a Breach Is Notifiable?
When in doubt, treat the 30-day assessment clock as already running and document your reasoning as you go — the PDPC has shown leniency toward organisations that acted promptly and transparently even when their final determination turned out to be an over-notification, but far less leniency toward those who sat on a known incident. If your SME lacks the internal expertise to make this call confidently, this is a reasonable moment to bring in outside help — whether that's a data protection consultant, a lawyer familiar with PDPA enforcement, or an IT partner who can confirm the technical scope of what was actually accessed. The cost of that consultation is almost always smaller than the cost of guessing wrong.
FAQ
Do small businesses with only a handful of customer records still need to comply with PDPA breach rules?
Yes. The PDPA applies to organisations of any size that collect, use, or disclose personal data in Singapore, with limited exceptions. There's no small-business carve-out for breach notification duties — what matters is the sensitivity and scale of the data involved, not your headcount or revenue.
What happens if my SME fails to notify the PDPC in time?
Failure to notify (or notifying late without reasonable justification) can result in financial penalties of up to 10% of annual turnover in Singapore or S$1 million, whichever is higher, plus reputational damage from public enforcement decisions the PDPC regularly publishes. Prompt, good-faith notification — even with incomplete information — is treated far more favourably than silence.
Is a phishing email that compromises one staff account automatically a notifiable breach?
Not automatically — it depends on what data that account could access and whether significant harm to individuals is likely. A compromised email with no access to customer financial or identity data may not meet the threshold, but you still need to formally assess and document that conclusion within the 30-day window rather than assume it away.
Ready to Transform Your Business?
Let Digital Perpetual help you automate, streamline, and grow.
Get Started with Digital Perpetual →