pdpa-compliance7 min read28 September 2026

PDPA Mandatory Breach Notification: 500 Affected Individuals Threshold

A Singapore SME guide to PDPA mandatory breach notification: when the 500 affected individuals threshold applies, the 3-day PDPC deadline, and how to respond.

ComplyHQ Team

PDPA Mandatory Breach Notification: 500 Affected Individuals Threshold

PDPA Mandatory Breach Notification: 500 Affected Individuals Threshold

Since 1 February 2021, PDPA compliance in Singapore has included a mandatory breach notification obligation — and one of its clearest triggers is the 500 affected individuals threshold. If a data breach affects 500 or more individuals, your organisation must notify the Personal Data Protection Commission (PDPC). This guide breaks down exactly when the threshold applies, the deadlines you must meet, and the concrete steps your business should take to stay compliant.

TL;DR — Key Takeaways

  • A data breach is notifiable if it affects 500 or more individuals OR is likely to cause significant harm to any affected individual.
  • You must notify the PDPC within 3 calendar days of determining the breach is notifiable.
  • Affected individuals must be notified as soon as practicable (with limited exceptions).
  • Penalties reach up to S$1 million or 10% of annual Singapore turnover, whichever is higher.
  • The obligation is set out in Sections 26A–26E of the PDPA.

What Is PDPA Mandatory Breach Notification?

PDPA mandatory breach notification is a legal obligation requiring organisations to report certain data breaches to the PDPC and, in most cases, to affected individuals. It was introduced through the Personal Data Protection (Amendment) Act 2020 and took effect on 1 February 2021 as the Data Breach Notification Obligation under Sections 26A–26E of the PDPA.

The obligation exists to give both the regulator and affected individuals the chance to limit harm — for example, by cancelling compromised cards, resetting passwords, or watching for fraud. A data breach becomes "notifiable" the moment it meets either of two tests: the significant-scale test (500 or more affected individuals) or the significant-harm test. Your organisation does not get to choose which test applies — you must assess both.

Understanding this obligation is now a baseline part of running a compliant business in Singapore, and it sits alongside your other duties such as the Consent, Purpose Limitation, and Protection Obligations covered in our PDPA compliance checklist for Singapore SMEs.

When Does the 500 Affected Individuals Threshold Apply?

The 500 affected individuals threshold applies whenever a single data breach affects, or is likely to affect, personal data belonging to 500 or more individuals. When this "significant scale" condition is met, the breach is automatically notifiable to the PDPC — regardless of how sensitive the data is.

This is the part many SME owners misunderstand. You do not need to prove that harm occurred; reaching 500 affected individuals is sufficient on its own to make the breach notifiable to the PDPC. A leaked marketing database of 800 email addresses and names, for instance, is notifiable purely on scale — even though email addresses alone might seem low-risk.

Two practical points about the threshold:

  • It counts individuals, not records. If one person appears in your database three times, that is still one affected individual.
  • "Likely to affect" is enough. If you cannot yet confirm the exact number but it is reasonably likely to reach 500 or more, you should proceed as though the threshold is met.

If your business handles large customer lists — common in e-commerce, F&B loyalty programmes, and retail — the 500 threshold can be crossed by a single misconfigured database or a lost laptop. Sector-specific risks are explored further in our guides on PDPA compliance for e-commerce and PDPA for F&B and restaurants.

When Is a Breach Notifiable Below 500 Individuals?

A breach affecting fewer than 500 individuals is still notifiable if it is likely to result in significant harm to any affected individual. This "significant harm" test is separate from the scale test, and even a breach involving a single person can require notification.

To make this test objective, the PDPC has prescribed specific categories of personal data that are deemed to cause significant harm if compromised. If a breach involves any of these prescribed data types, it is treated as likely to result in significant harm and is therefore notifiable — no matter how few individuals are affected. These categories include, among others:

  • Full NRIC, FIN, work permit, or passport numbers
  • Financial information such as bank account and credit card numbers, and account credentials
  • Health and medical information, including mental health and diagnoses
  • Information about vulnerabilities, such as domestic abuse or debt
  • Biometric and genetic data

So a breach exposing the bank details of just 30 customers is notifiable under the significant-harm test, while a breach exposing the names and emails of 600 customers is notifiable under the significant-scale test. Every notifiable breach must satisfy at least one of these two triggers — and prudent organisations assess both every time.

How Long Do You Have to Notify the PDPC?

Once your organisation has determined that a breach is notifiable, you must notify the PDPC as soon as practicable, and no later than 3 calendar days. This is one of the strictest reporting timelines in Singapore's data protection framework, and the clock starts from the moment you assess the breach as notifiable — not from when you fully resolve it.

There are two distinct time expectations to manage:

  1. Assessment window: After becoming aware of a possible breach, you must assess whether it is notifiable in a reasonable and expeditious manner. The PDPC generally expects this assessment to be completed within 30 days. Taking longer without justification is itself a compliance risk.
  2. Notification window: Once assessed as notifiable, the PDPC must be informed within 3 calendar days.

Affected individuals must also be notified — at the same time or after notifying the PDPC — as soon as practicable, so they can take protective action. There are narrow exceptions: for example, where a law enforcement agency or the PDPC directs you not to, or where you have already taken remedial action that renders significant harm unlikely.

Missing these deadlines converts a manageable incident into an enforcement matter. For a walkthrough of the operational response, see our step-by-step guide on what to do if your Singapore business has a data breach.

What Are the Penalties for Non-Compliance?

Failing to notify a notifiable data breach is a breach of the Data Breach Notification Obligation and can attract significant financial penalties. Following amendments that took effect on 1 October 2022, the PDPC can impose a financial penalty of up to S$1 million, or up to 10% of an organisation's annual turnover in Singapore — whichever is higher — for organisations with local annual turnover exceeding S$10 million.

The PDPC's enforcement record shows it treats delayed or absent notification, and inadequate protection measures, seriously. Organisations have been penalised not only for the breach itself but for how slowly and poorly they responded. In practice, a swift, well-documented notification often reduces regulatory exposure, while silence and delay amplify it. Real enforcement outcomes and the lessons behind them are analysed in our review of PDPA penalties and enforcement cases.

A Practical Breach Notification Checklist for Your Business

Snippet summary: The fastest way to stay compliant is to have a documented response plan before a breach happens. Below is a practical sequence your organisation can follow the moment a potential breach is discovered.

  1. Contain and record. Stop the ongoing exposure (e.g. revoke access, take the system offline) and log the time you became aware.
  2. Assess the triggers. Count affected individuals and check the data types against the prescribed significant-harm categories. Ask: does it hit 500, or does it involve NRIC, financial, or health data?
  3. Decide notifiability. Complete this assessment reasonably and expeditiously (within 30 days).
  4. Notify the PDPC. If notifiable, submit the breach notification within 3 calendar days via the PDPC's online portal.
  5. Notify affected individuals. As soon as practicable, unless an exception applies. Tell them what happened and what they should do.
  6. Remediate and document. Fix the root cause, record every decision, and update your policies.

Building this muscle also depends on your people. A breach is often triggered — or missed — because staff are untrained, which is why the PDPA staff training requirements are so closely tied to breach readiness.

How ComplyHQ Helps You Meet the Threshold Obligation

Tracking affected-individual counts, mapping data types to the PDPC's prescribed categories, and hitting a 3-day deadline under pressure is exactly where SMEs stumble. ComplyHQ delivers AI-powered compliance that handles your PDPA obligations in minutes, not weeks — including breach assessment workflows that help you determine notifiability against both the 500 threshold and the significant-harm test, and generate the documentation the PDPC expects.

For organisations that also need custom systems, integrations, or a broader security posture such as ISO 27001 certification, the team at Adaptels builds tailored digital solutions for Singapore SMEs that complement your compliance programme.

Key Takeaway

The PDPA mandatory breach notification regime rests on two clear triggers: the 500 affected individuals threshold and the significant-harm test. Assess both, act within 3 calendar days of determining notifiability, and document everything. Doing so is not just about avoiding penalties of up to S$1 million — it is about protecting the customers whose trust your business depends on.


Sources & References

  1. PDPC — Guide on Managing and Notifying Data Breaches Under the PDPA
  2. PDPC — Personal Data Protection Act Overview
  3. Singapore Statutes Online — Personal Data Protection Act 2012 (Sections 26A–26E)
  4. PDPC — Report a Data Breach
  5. ComplyHQ — AI-Powered PDPA Compliance for Singapore SMEs

Simplify Your Compliance

ComplyHQ's AI can assess your PDPA compliance gaps in under 15 minutes and generate the policies you need.

Try Free Assessment

Frequently Asked Questions

Do I have to notify the PDPC if fewer than 500 individuals are affected by a data breach?
Possibly. The 500-individual threshold is only one of two triggers. Even if fewer than 500 people are affected, the breach is still notifiable if it is likely to result in significant harm — for example, if it involves NRIC numbers, financial account details, or health information. You must assess both triggers, not just the headcount.
How long do I have to report a data breach to the PDPC in Singapore?
Once your organisation determines a breach is notifiable, you must notify the PDPC as soon as practicable, and in any case no later than 3 calendar days. Separately, your assessment of whether a breach is notifiable should be conducted in a reasonable and expeditious manner — the PDPC generally expects this within 30 days of becoming aware of a potential breach.
What is the maximum penalty for failing to report a notifiable data breach?
Under the PDPA, the PDPC can impose a financial penalty of up to S$1 million, or up to 10% of an organisation's annual turnover in Singapore (whichever is higher) for organisations with local turnover exceeding S$10 million. Failure to notify is treated as a breach of the Data Breach Notification Obligation under Sections 26A–26E.
Tags:PDPASingapore complianceSMEdata protectionPDPC

Ready to get PDPA compliant?

Stop guessing about compliance. ComplyHQ uses AI to assess your gaps, generate policies, and guide you through every PDPA obligation.

Gap AssessmentPolicy GeneratorAI Compliance Chat
16 September 20267 min read

Business Contact Information Under PDPA: What You Can Use Freely

A clear guide to business contact information under Singapore's PDPA — what your business can collect, use and disclose without consent, plus the DNC traps to avoid.

Read more
13 September 20267 min read

PDPA Deemed Consent: When You Can Collect Data Without Explicit Consent

A clear guide to PDPA deemed consent for Singapore SMEs — when you can collect data without explicit consent, the rules under PDPA 2012, and how to stay compliant.

Read more
14 July 20267 min read

PDPA Withdrawal of Consent: What Happens When Customers Opt Out

PDPA withdrawal of consent guide for Singapore SMEs: what to do when customers opt out, your legal timelines, obligations under the PDPA, and how to stay compliant.

Read more