Suspect a PDPA Data Breach? Here’s What to Do Next

Last updated on October 7, 2022

thief stealing confidential data

If you suspect that your personal information has been misused by an organisation, Singapore’s Personal Data Protection Act (PDPA) provides you with some protections on which you may rely.

This article will highlight the aspects of the PDPA that would be relevant in those circumstances. It will cover:

What are the Obligations of Organisations Under the PDPA?

First, organisations have a range of responsibilities to you in how they handle your data, pursuant to the PDPA. These responsibilities relate primarily to how they collect, store, use or share your data. In short, they need to obtain your consent to do certain things with your data, and they can operate only within the bounds of that consent.

For example, an organisation cannot share your personal data with a third-party, unless you have given your express consent for them to do so. Even if consent is given, they can share it with only the kinds of parties and for the purposes that they informed you of when they obtained your consent.

For more detail, see our other article on organisations’ obligations under the PDPA.

Is the Information That Has Allegedly been Misused Protected by the PDPA?

Next, you must ensure that the data allegedly misused by an organisation is actually the kind of data that is protected by the PDPA. Most kinds of data that would personally identify you or provide information about you such as contact details or addresses would be protected.

However, your business contact information is not protected. This refers to information such as your work phone number or work email address as opposed to your personal phone number or email address.

That said, if your business contact information such as your work email address is given out for personal use, e.g. when signing up for a yoga class, then such information will not be treated as business contact information and will be protected under the PDPA in such scenarios of personal use.

What Can You Do If You Suspect a PDPA Breach?

If you believe that protected personal data has been misused by an organisation, you can file a complaint with the Personal Data Protection Commission (PDPC). The PDPC will usually open an investigation and contact the organisation to find out more.

Depending on the circumstances, you may also consider filing a police report. If you believe your data has been illegally accessed as a result of a computer hacking incident, a cybersecurity breach or something of that nature, then an offence under the Computer Misuse Act may have been committed. The police may be interested in investigating the matter if you have any evidence that suggests this is what may have happened.

In the event of a data security breach, organisations are required to report the incident to the PDPC if it had been conducted by individuals outside of the organisation, and has resulted in (or is likely to result in) significant harm to an affected individual, or if it is (or is likely to be) of a significant scale. If required, the reporting has to be done within 3 days of assessing whether the breach needs to be reported.

If you suffer losses as a result of a personal data breach in Singapore, you may also be able to sue for compensation.

What are the Penalties for PDPA Breaches?

Although you may not be able to obtain compensation for a data breach, there are potential consequences for companies that fail to discharge their obligations under the PDPA. Such organisations could face a financial penalty of 10% of the organisation’s annual turnover in Singapore for organisations with annual local turnover exceeding S$10 million, or up to S$1 million, whichever is higher.

Various high-profile companies including Singtel, SPH Magazines and Royal Caribbean Cruises have already been levied with financial penalties by PDPC for violating the PDPA. The usual range of financial penalties so far have been from high 4-figure sums to modest 5-figure sums.

So far, one of the largest financial penalties meted out by PDPC has been $60,000 on IT vendor Learnaholic. Many of these financial penalties have been meted out for cybersecurity breaches that have led to the unauthorised access and exposure of individuals’ personal data.

If you encounter an issue involving misuse of your personal data in Singapore and you wish to take action against the organisation responsible for it, it is advisable to consult a data protection lawyer.

A good data protection lawyer will usually be able to give you a quick assessment of whether or not you have any recourse and can assist you in preparing a more professional complaint to the PDPC.

The lawyer can also assist in drafting a letter to the offending organisation to complain about the breach, demand a copy of all of your personal data that they have, and/or demand that they destroy any of your personal data that they have.

Appointment and Removal of Company Officers and Other Key Personnel
  1. What is a Nominee Director & How to Appoint One in Singapore (With FAQs)
  2. Independent Directors: Who are They and What is Their Role?
  3. Board of Advisors: Who Are They and What Is Their Role?
  4. Appointing Company Directors in Singapore: Eligibility, Process etc.
  5. Managing Director vs CEO in Singapore: Roles and Obligations
  6. Guide to Directors' Remuneration in Singapore
  7. Directors' Duties in Singapore
  8. Shadow Directors: Who are They and What Duties Do They Owe to the Company?
  9. How to Remove a Director from a Company in Singapore
  10. Removal and Resignation of Company Auditor in Singapore
  11. Appointing a Company Secretary: Roles and Responsibilities
  12. Appointing an Authorised Representative for Foreign Companies in Singapore
  13. Process Agents in Singapore
Holding Meetings
  1. What are Annual General Meetings (AGMs) in Singapore?
  2. How to Hold Extraordinary General Meetings (EGMs) in Singapore
  3. How to Hold a Board Meeting in Singapore
Shareholder Matters
  1. Share Buybacks in Singapore: Procedure, Cost and More
  2. How to Split Shares (or Stocks) in a Singapore Company
  3. 2 Ways to Remove a Singapore Company Shareholder ASAP
  4. What are Treasury Shares? Guide for Singapore Companies
  5. A Guide to Paid-Up Capital in Singapore
  6. Preparing a Register of Shareholders for a Singapore Company
  7. How to Issue Shares in a Singapore Private Company
  8. Guide to Transferring Shares in a Singapore Private Company
  9. Your Guide to Share Certificates in Singapore: Usage and How to Prepare
  10. Shareholder Rights in Singapore Private Companies
  11. Shareholder Roles and Obligations in Singapore Companies
  12. Dividend Payments Guide for Singapore Business Owners
  13. Share Transmission: What Happens If a Shareholder Dies in Singapore?
  14. How to Reduce the Share Capital of Your Singapore Company
  15. Buy-Sell Agreements: How to Write & Fund Them in Singapore
  16. Oppression of Minority Shareholders
  1. Is Your Business Collaboration Competition Law-Compliant?
  2. Explained: Registered Filing Agent for Singapore Businesses
  3. Transfer Pricing Obligations of Singapore Companies
  4. Adhering to Trading Sanctions and Restrictions in Singapore
  5. Cyber Hygiene Compliance Guide for Singapore Companies
  6. Corporate Social Responsibility For Businesses in Singapore
  7. A Guide to Food Standards in Singapore
  8. Essential Regulatory Compliance Guide for Singapore Companies
  9. Dormant Companies and Their Filing Obligations in Singapore
  10. Anti-Money Laundering Regulations and Your Business: What You Need to Know
  11. Price-Fixing, Bid-Rigging and Other Anti-Competitive Practices to Avoid
  12. Can Singapore Businesses Legally Conduct Lucky Draws?
  13. Restaurant Inspection and Food Safety Rules in Singapore
Company Management
  1. Does Your Company Need a Legal Team (In-House Counsel)?
  2. Acqui-Hiring of Singapore Companies: How Does It Work?
  3. Can a Company Director Take Legal Action Against Another Director?
  4. How to Change the Name of Your Singapore Company
  5. Can Directors be Liable for Company Debts in Singapore?
  6. Company Loans to Directors/Shareholders in Singapore
  7. 3 Types of Insurance Every Singapore Business Needs
  8. Creating and Registering Charges in Singapore: Guide for Companies
  9. Guide to Effective Business Continuity Planning in Singapore
  10. Business Asset Sale & Disposal in Singapore: How Do They Work?
  11. 5 Ways To Resolve Business Partnership Disputes in Singapore
  12. How to Commence a Derivative Action on Behalf of a Company in Singapore
  13. Business Will: How to Pass on Your Business to Your Successors in Singapore
Company Documents
  1. Record-Keeping Requirements for Singapore Companies
  2. Company Constitutions in Singapore and How to Draft One
  3. Company Memorandum and Articles of Association
  4. Company Resolutions: What are They?
  5. Board Resolutions in Singapore
  6. Minutes of Company Meeting in Singapore: How to Record
  7. How to Set Up a Register of Controllers
  8. How to Set Up a Register of Nominee Directors
  9. Guide to Filing Financial Statements for Singapore Business Owners
  10. Filing Annual Returns For Your Business
Tax, Accounting and Audit Matters
  1. Carbon Tax in Singapore: What is the Rate and Who Must Pay?
  2. Laws and Penalties for GST Evasion in Singapore
  3. 6 Common Taxes in Singapore For Individuals & Businesses
  4. Singapore Corporate Tax: How to Pay, Tax Rate, Exemptions
  5. Start-Up Tax Exemption Guide for New Singapore Companies
  6. GST Registration: Requirements and Procedure in Singapore
  7. What is Withholding Tax and When to Pay It in Singapore
  8. Singapore Influencers: Here's How to Calculate Your Income Tax
  9. Investigating Tax-Evading Business Owners in Singapore
  10. Small Business Accounting Services in Singapore
  11. Company Audits in Singapore: Requirements and Exemptions
Data Protection
  1. Suspect a PDPA Data Breach? Here's What to Do Next
  2. Must You Notify PDPC About a Data Breach in Your Business?
  3. Data Room: Should Your Singapore Company Set Up One?
  4. Victim of a Data Breach? Here’s What You Can Do
  5. Summary: Your Organisation's 10 Main PDPA Obligations
  6. Essential PDPA Compliance Guide for Singapore Businesses
  7. PDPA Consent Requirements: How Can Your Business Comply?
  8. Is It Legal for Businesses to Ask for Your NRIC in Singapore?
  9. How To Prevent Unauthorised Disclosure When Processing and Sending Personal Data
  10. Cloud Storage of Personal Data: Your Business’ Data Protection Obligations
  11. Drafting a Comprehensive Privacy Policy For Your Singapore Website
  12. GDPR Compliance in Singapore: Is it Required and How to Comply
  13. Appointing a Data Protection Officer For Your Business: All You Need to Know
  14. How Can Companies Dispose of Documents Containing Personal Data?
  15. Check the Do-Not-Call Registry Before Marketing to Singapore Phone Numbers
  16. How to Legally Install CCTVs for Home/Business Use in Singapore
  17. Is Web Scraping or Crawling Legal in Singapore?
  18. Legal Options If Employees Breach Confidentiality in Singapore
  1. Social Media Marketing: Legal Guide for Singapore Businesses
  2. Your Guide to E-commerce Website Terms of Service in Singapore
  3. Dealing with Defamation of Your Business: Can You Sue?
  4. Sending Email Newsletters That Comply With Singapore Law
  5. A legal guide to drafting a social media policy for your company
  6. Your Guide to a Media Release Form in Singapore
  7. Your Guide to an Influencer Marketing Agreement in Singapore
  8. Outdoor Advertising: How to Legally Display Public Ads in Singapore
Fintech and Payment Services Advisory
  1. A Guide to Digital Bank Regulation in Singapore
  2. Applying for a Major Payment Institution Licence in Singapore
  3. Applying to the MAS FinTech Regulatory Sandbox
  4. Payment Services Act Licensing Guide for Fintech Businesses
  5. How to Get a Payment Service Provider Licence in Singapore
  6. Financial Adviser's Licence Guide for Singapore Businesses
  7. Capital Markets (CMS) Licence Requirements in Singapore
  8. How to Offer E-Wallet Services in Singapore: Licensing Guide
  9. Digital Payment Token Services Licence Guide in Singapore
  10. How to Legally Offer Crypto Services in Singapore
  1. Starting a Franchise in Singapore: What Franchisors Should Look Out For
  2. Running a Franchise in Singapore: What To Look Out for as a Franchisee
Debt Restructuring
  1. What is Judicial Management and How It Works in Singapore
  2. Schemes of Arrangement: How They Work and How to Apply
  3. Informal Debt Restructuring and Workout in Singapore
Ending a Business
  1. How to Restore a Struck-Off Company in Singapore
  2. Claw-Back of Assets From Unfair Preference and Undervalued Transactions
  3. Should You Save or Close Your Zombie Company in Singapore?
  4. Voluntary Suspension of Business in Singapore: How to Handle
  5. Winding Up a Singapore Company: Grounds and Procedure
  6. Closing Your Singapore Business: What You Need to Settle
  7. Striking Off a Company
  8. Restoring a Company That was Struck Off Without You Knowing
  9. Dissolution of partnerships in Singapore
  10. What Should a Creditor Do When a Company Becomes Insolvent?
  11. How to File a Proof of Debt Against a Company in Liquidation
  12. Validation of Payments Made by Companies Being Wound Up