My bookmarksSign up free
← Personal Data Protection Act 2012

Personal Data Protection Act 2012 s 26B

Personal Data Protection Act 2012 s 26B

s 26B Notifiable data breaches

26B.—(1) A data breach is a notifiable data breach if the data breach —(a) results in, or is likely to result in, significant harm to an affected individual; or (b) is, or is likely to be, of a significant scale.[40/2020] (2) Without limiting subsection (1)(a), a data breach is deemed to result in significant harm to an individual —(a) if the data breach is in relation to any prescribed personal data or class of personal data relating to the individual; or (b) in other prescribed circumstances.[40/2020] (3) Without limiting subsection (1)(b), a data breach is deemed to be of a significant scale —(a) if the data breach affects not fewer than the prescribed number of affected individuals; or (b) in other prescribed circumstances.[40/2020] (4) Despite subsections (1), (2) and (3), a data breach that relates to the unauthorised access, collection, use, disclosure, copying or modification of personal data only within an organisation is deemed not to be a notifiable data breach.[40/2020]

Read this section in the full act → · Open PART 6A →

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. Read the official text ↗

Source: Singapore Statutes Online (Attorney-General's Chambers), © Government of Singapore.

The Singapore legislation on this platform is subject to copyright of the Singapore Government and is used/reproduced for the purposes of this platform with the permission of the Attorney-General's Chambers. Users of this platform may check Singapore Statutes Online for the latest version of the Singapore legislation.

What to look at next