Law / Singapore

Personal Data Protection Act, data breach notification

Personal Data Protection Act 2012, Part 6A, ss.26A-26E, as added by Act 40 of 2020

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 1 February 2021.

A breach notification rule binding private bodies.

As of 29 August 2026.

What it requires

  • An app that experiences a data breach affecting an individual's personal data in Singapore must assess whether the breach is likely to cause significant harm or is of significant scale, and if so must notify the PDPC as soon as practicable and in any case within 3 calendar days of that assessment, and must also notify each affected individual unless a statutory exception applies.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Part 6A, added by the 2020 amendment, makes a data breach notifiable if it results in, or is likely to result in, significant harm to an affected individual, or is or is likely to be of significant scale; an internal-only breach is deemed not notifiable.

The organisation must notify the PDPC as soon as practicable, and in any case no later than 3 calendar days after assessing the breach is notifiable, and must also notify each affected individual, subject to exceptions where technological measures render significant harm unlikely or a law-enforcement agency or the PDPC directs otherwise.

When LexLint raises it

  • processes_biometrics
  • processes_voice
  • crawls_web

Read the law

official statute text, Singapore Statutes Online (SSO)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app