A technician with a laptop working on a server rack in a data centre
Home » Blog » When the Marketing List Leaks: Singapore’s Data Breach Rules for Marketers

When the Marketing List Leaks: Singapore’s Data Breach Rules for Marketers

Ask a Singapore SME where its personal data lives and you will usually be pointed at the finance system or the HR folder. Ask where the largest collection of personal data lives and the honest answer is almost always the marketing stack: the email platform, the CRM, the form submissions sitting in a shared inbox, the customer-match list uploaded to an ad platform, and the export somebody made into a spreadsheet for a campaign three years ago and never deleted.

That is also where breaches happen, because marketing data is the most copied, most exported and most widely shared data in the business. And the PDPA’s mandatory notification regime, in force since 1 February 2021, has a feature that catches marketers off guard: a leaked marketing list will rarely trip the “significant harm” trigger, and will almost always trip the “significant scale” one. The exposure is a volume exposure, and marketing lists are big by definition.

This guide works through Part 6A of the Act and the notification regulations as they actually apply to a marketing stack: which leaks are notifiable, who starts the clock when your agency or your email platform is the one that lost the data, the single control that switches off the duty to notify customers, and what to do in the first 72 hours.

It assumes you have the consent side covered — if not, start with PDPA and marketing tracking in Singapore. This is general information, not legal advice.

What counts as a breach, including the limb everyone forgets

Section 26A defines a data breach in two limbs. The first is the familiar one: “the unauthorised access, collection, use, disclosure, copying, modification or disposal of personal data”. The second is easier to overlook: “the loss of any storage medium or device on which personal data is stored in circumstances where the unauthorised access, collection, use, disclosure, copying, modification or disposal of the personal data is likely to occur”.

That second limb is why a laptop left in a taxi with a customer export on the desktop is a data breach in exactly the same sense as a hacked database. So is a lost USB stick of event registration data, and so is a departing contractor’s unreturned device. In marketing teams, which run on laptops and shared drives, the loss limb is the more common one.

The two triggers, and why marketing lists fail one and pass the other

Under section 26B, a breach is notifiable if it “results in, or is likely to result in, significant harm to an affected individual”, or if it is “of a significant scale“. Both are then given hard edges by the Personal Data Protection (Notification of Data Breaches) Regulations 2021.

Significant scale is 500. Regulation 4 prescribes the number of affected individuals for section 26B(3)(a) as 500. There is no harm assessment attached to it: 500 records is notifiable because of how many people are affected, full stop.

Significant harm is deemed only for a specific list. Regulation 3 deems a breach to result in significant harm where it relates to an individual’s full name or alias or identification number together with a category in Part 1 of the Schedule — or, separately, to an account identifier together with a password, security code, access code, security-question answer, biometric or other data used to access that account.

Read Part 1 of that Schedule and a pattern jumps out. It is financial, health, family and legal-status data: remuneration; income from the sale of goods or property; credit, charge or debit card numbers; bank account numbers; net worth; deposits and withdrawals; loans and facilities; creditworthiness; outstanding debts; investments in capital markets products; insurance policy terms and claims; the diagnosis or treatment of specified conditions; fertility and abortion treatment; organ donation; suicide or attempted suicide; abuse; adoption; and information identifying children or vulnerable adults in specified proceedings.

Not one item on that list is an email address, a mobile number, a postal address, a job title, a purchase history, a browsing record or a marketing preference. Which produces the finding that matters here.

What leaked Deemed significant harm? Notifiable anyway?
Name + email of 300 newsletter subscribers No — nothing in Part 1 No, on these two deeming limbs — but you must still assess actual likely harm under s26B(1)(a)
Name + email of 5,000 newsletter subscribers No Yes — significant scale, over 500
Name + NRIC of 40 event registrants Assess — an identification number alone is not enough; it must pair with a Part 1 category Assess actual harm
Customer accounts: username + password hash dump, 200 records Yes — reg 3(1)(b), account identifier plus access credential Yes, regardless of number
E-commerce orders with card numbers, 50 records Yes — Part 1 item 3 Yes, regardless of number
B2B lead form capturing salary or company turnover, 600 records Assess — remuneration data is Part 1 item 1 Yes on scale in any event

Two practical consequences. First, the deemed-harm limb is not your main exposure — unless you run an account system or take payments, in which case regulation 3(1)(b) makes even a small credential leak notifiable. Second, your main exposure is arithmetic. If your list is over 500 records, and almost every commercially useful list is, then a leak of it is notifiable irrespective of how benign the fields look. The most common marketing asset in Singapore is, by construction, a notifiable breach waiting for an incident.

One caution against reading the table too mechanically: the deeming provisions are floors, not ceilings. Section 26B(1)(a) still asks whether the breach results in or is likely to result in significant harm on the facts, and a small list can qualify on its own merits — a leaked list of attendees at a support group, say, tells you something about them that their email address alone does not.

Is the marketing breach notifiable?Two deeming limbs, then a judgement call. Marketing lists nearly always fail on the second.Suspected breach — assess under s26C, reasonably and expeditiously1. Account identifier + credential (reg 3(1)(b))? Or name / ID number + a Part 1 category(card or bank numbers, creditworthiness, debts, insurance, specified health data)?YES → significant harm is DEEMED. Notifiable at any number.2. Are 500 or more individuals affected? (reg 4)YES → significant SCALE. Notifiable regardless of how harmless the fields look.This is the limb a marketing list fails.3. Neither? You still assess actual likely significant harm under s26B(1)(a). The deeming limbs are floors, not ceilings.A commercially useful list clears 500 long before it contains anything on the Part 1 list.

The internal-only carve-out, and the two gaps in it

Section 26B(4) provides that a breach relating to “the unauthorised access, collection, use, disclosure, copying or modification of personal data only within an organisation” is deemed not to be a notifiable breach. An intern browsing a customer table they had no business opening is not, without more, a notifiable event.

Two gaps are worth noticing, because both are marketing-shaped.

The carve-out lists access, collection, use, disclosure, copying and modification. It does not list disposal, which appears in the section 26A definition but is absent here. And it addresses only the first limb of the definition — it says nothing about the loss of a storage medium or device. An internally lost laptop is not carved out by its internality.

The other gap is that “within an organisation” is narrower than it sounds in a marketing context. Your agency, your freelance designer, your email service provider and your CRM vendor are separate organisations. A file shared to any of them is not internal.

The clock: what actually starts it

The timings are widely reported as “three days”, which is right about the number and wrong about what it counts from.

Section 26C(2): where an organisation has reason to believe a breach affecting personal data in its possession or under its control has occurred, it must conduct an assessment of whether the breach is notifiable “in a reasonable and expeditious manner”. The PDPC’s guidance sets an outer expectation of 30 calendar days for that assessment, while making clear that taking 30 days without good reason is not acceptable.

Section 26D(1): where the assessment concludes the breach is notifiable, the organisation must notify the Commission “as soon as is practicable, but in any case no later than 3 calendar days after the day the organisation makes that assessment“.

So the three days run from your own assessment, not from discovery — which is a trap in both directions. It gives you room to investigate properly. It also means a slow, undocumented assessment is itself a compliance problem, and regulation 5(2) requires a late notification to state the reasons for lateness and include supporting evidence. The single most useful habit is to date and record the moment you conclude the assessment, because that timestamp is the one the regulator will work from.

The clock runs from your assessment, not from discoveryWhich is why the single most useful habit is to date the moment the assessment closes.REASON TO BELIEVEs26C(2): assess in areasonable andexpeditious manner.PDPC outer guide:30 calendar daysASSESSMENT DATEDThe event that startsthe statutory clock.Record the date.NOTIFY PDPCs26D(1): as soon aspracticable, and nolater than3 calendar daysNOTIFY PEOPLESignificant-harmlimb only, unlesss26D(5) applies.A late notification must state the reasons for lateness and include supporting evidence (reg 5(2)).

When your agency or your email platform is the one that leaked

This is the provision most marketing teams have never read, and it is the one that decides who is holding the clock.

Section 26C(3) provides that where a data intermediary has reason to believe a breach has occurred in relation to personal data it is processing on your behalf, the intermediary “must, without undue delay, notify that other organisation of the occurrence of the data breach” — and you, on being notified, must conduct the assessment of whether it is notifiable.

Note what the intermediary does not do. It does not notify the PDPC. It does not assess. Its entire statutory duty is to tell you, quickly. The assessment, the three-day notification, the customer communications and the exposure to a financial penalty are all yours. Your agency’s breach is your notification.

That has one clear implication for how you contract with anyone who touches your marketing data:

  • Write the notification duty into the agreement, with a defined period in hours rather than the statute’s “without undue delay”, and name the person at your end it goes to.
  • Require the facts you will need, because regulation 5 requires your notification to the Commission to include when and how you first became aware, a chronological account of your steps, how the breach occurred, the number of individuals affected, the categories of data, the potential harm, the remedial action, and your plan for informing individuals. You cannot assemble that from a vendor who will only say “an incident occurred”.
  • Keep an inventory of who holds what, which is also the artefact that makes the assessment fast.

This is one of the questions worth asking during procurement rather than during an incident — alongside the other diligence in agency red flags in Singapore and the platform choices in choosing a CRM for a Singapore SME.

Telling customers, and the control that switches the duty off

Under section 26D(2), once you have notified the Commission, you must also notify each affected individual where the breach is notifiable on the significant harm limb. Note the asymmetry: a breach notifiable only because it crossed 500 records does not by itself trigger individual notification.

Section 26D(5) then gives two off-switches. You need not notify an individual if, on or after assessing the breach as notifiable, you take action “that renders it unlikely that the notifiable data breach will result in significant harm” to them — or if you “had implemented, prior to the occurrence of the notifiable data breach, any technological measure that renders it unlikely” that it will cause significant harm.

That second limb is the most valuable sentence in Part 6A for a marketing team, because it is the only one that rewards work done in advance. In practice it means encryption, properly implemented, on the exports and backups where marketing data actually sits. A stolen encrypted file whose key was never with it is a very different conversation from a stolen spreadsheet.

Two further limits. Section 26D(6) prohibits notifying individuals where a prescribed law enforcement agency so instructs or the Commission so directs, and s26D(7) lets the Commission waive individual notification on written application. And s26D(8) confirms that notifying does not put you in breach of confidentiality duties or professional conduct rules — a point worth having to hand when someone argues for silence on contractual grounds.

What it costs to get wrong

Part 6A sits inside the provisions carrying financial penalties under section 48J. Where the Commission is satisfied an organisation intentionally or negligently contravened Part 6A, it may require payment of a financial penalty, capped by s48J(3) at 10% of annual turnover in Singapore for an organisation whose Singapore turnover exceeds $10 million, and at $1 million in any other case. That branch structure is usually shorthanded as “whichever is higher”, which happens to work out, but the statute frames it as two cases.

More useful than the ceiling is section 48J(6), which lists what the Commission must weigh. Several of the factors are things you control after the fact: whether you took action to mitigate, and how timely and effective that action was; whether you had nonetheless implemented adequate measures for compliance; whether you have previously failed to comply; and your compliance with any directions given. The nature and duration of the non-compliance and the type of data are in there too. In short, a fast, documented, honest response is not merely good practice — it is a statutory mitigating factor.

Where the data actually is, and the first 72 hours

Most of the delay in a real incident is spent working out what was in the file. An inventory removes that.

Marketing asset Typical volume Notifiable if leaked? The control that matters
Email platform subscriber list Thousands Yes, on scale Two-factor authentication; remove ex-staff and ex-agency logins
CRM contact records Hundreds to thousands Yes, on scale Role-based permissions; restrict who can export
Web form submissions in a shared inbox Hundreds Often, on scale Route to a system, not an inbox; retention limit
Ad platform customer-match uploads Thousands Yes, on scale Hash before upload; delete the source file after
Campaign exports in spreadsheets Anything Yes, on scale Encrypt, and delete on a schedule. The single highest-yield fix.
E-commerce order and account data Any Yes — deemed harm, at any volume Never store card numbers; encrypt credentials
Agency and freelancer shared drives Anything Yes, and not internal Contractual notice duty; time-limited access

And the sequence when something happens:

Hours 0–4: contain. Revoke the credential, pull the link, take the export offline. Do not delete evidence — you will need the chronology for regulation 5(b).

Hours 4–24: establish scope. Which file, which fields, how many individuals, whose system. Write it down as you go, with times.

Hours 24–72: complete and date the assessment against the two triggers. If it is notifiable, the three-day clock starts from that date, so record it explicitly. Prepare the regulation 5 information while it is fresh.

Then: notify the Commission in the form specified on its website; notify individuals where the significant-harm limb applies and neither off-switch in s26D(5) does, including the regulation 6 content — what happened, what data of theirs was involved, the potential harm, what you are doing, what they should do, and a contact. Then fix the cause, and record that you did.

Frequently asked questions

Is a leaked email list a notifiable data breach in Singapore?

Usually yes, but on the scale limb rather than the harm limb. Regulation 4 of the Personal Data Protection (Notification of Data Breaches) Regulations 2021 sets the significant-scale threshold at 500 affected individuals, and a breach at or above that number is notifiable regardless of how benign the fields look. Names and email addresses are not among the categories in Part 1 of the Schedule that deem significant harm, so a list of 300 subscribers would not be notifiable on either deeming limb — though you must still assess whether significant harm is likely on the facts.

How long do I have to report a data breach to the PDPC?

Section 26D(1) requires notification as soon as practicable and in any case no later than three calendar days after the day you make the assessment that the breach is notifiable. The three days therefore run from your assessment, not from discovery. Section 26C(2) separately requires that assessment to be conducted in a reasonable and expeditious manner, with the PDPC’s guidance setting an outer expectation of 30 calendar days. Record the date you complete the assessment, because that is the date the clock runs from, and a late notification must state the reasons and include supporting evidence.

My agency lost the data. Do they report it, or do I?

You do. Under section 26C(3), a data intermediary that has reason to believe a breach has occurred in relation to data it processes for you must notify you without undue delay — and you must then conduct the assessment. The intermediary does not notify the PDPC and does not make the assessment. The three-day notification, the customer communications and the exposure to a financial penalty all sit with your organisation, which is why the contract should set a notification period in hours and specify the facts they must give you.

Do I always have to tell affected customers?

No. The duty to notify individuals under section 26D(2) applies to breaches notifiable on the significant-harm limb, so a breach notifiable only because it crossed 500 records does not by itself require individual notification. Section 26D(5) provides two further exceptions: action taken after the assessment that makes significant harm unlikely, and a technological measure implemented before the breach that has the same effect. That second exception is the practical case for encrypting marketing exports and backups in advance.

Is an employee snooping in the CRM a notifiable breach?

Generally not, on its own. Section 26B(4) deems a breach relating to unauthorised access, collection, use, disclosure, copying or modification of personal data only within an organisation not to be a notifiable breach. Two limits are worth noting: that carve-out does not mention unauthorised disposal, and it does not cover the separate limb of the definition dealing with the loss of a storage medium or device, so an internally lost laptop is not excluded by its internality. It also does not extend to your agency or vendors, who are separate organisations.

What is the penalty for failing to notify?

Part 6A falls within the provisions attracting financial penalties under section 48J. Where the Commission is satisfied an organisation intentionally or negligently contravened it, the penalty is capped at 10 per cent of annual turnover in Singapore for organisations whose Singapore turnover exceeds $10 million, and at $1 million in any other case. Section 48J(6) requires the Commission to weigh factors including the gravity and duration of the non-compliance, the type of data, whether the organisation mitigated and how promptly, whether it had adequate compliance measures in place, and its history — so a fast, documented response is a statutory mitigating factor.

Where this leaves you

The uncomfortable summary is that the marketing stack is the highest-volume personal data estate in most Singapore SMEs, is the least governed, and sits above the notification threshold by default. Nothing about a mailing list is sensitive in the Schedule’s sense; everything about it is large.

Three things are worth doing before an incident, because none of them can be done during one. Write down where the data is and who holds it. Encrypt the exports and delete them on a schedule, because section 26D(5)(b) rewards only the measure you implemented beforehand. And put a notification clause, measured in hours, into every contract with anyone who touches the list.

If you would like the data side reviewed as part of a broader look at how your marketing is measured and governed, that is the kind of groundwork our performance marketing engagements begin with, and the outcomes we report are in our Singapore case studies.

Sources: Personal Data Protection Act 2012 (Singapore), Part 6A (ss 26A–26E) and s48J, Singapore Statutes Online, current version as at 4 September 2026; Personal Data Protection (Notification of Data Breaches) Regulations 2021 (S 64/2021), regulations 3 to 6 and the Schedule, Singapore Statutes Online; PDPC, Guide on Managing and Notifying Data Breaches under the PDPA; DLA Piper, Data Protection Laws of the World, Singapore breach notification. This is general information, not legal advice; rules change — verify before relying on them.

Want to know where you actually rank?

We will run a free visibility check across your target searches and send back an honest read — no obligation.

Picture of Adrian Tan

Adrian Tan

A seasoned digital marketing professional with over 15 years of experience, I have built and executed high-impact digital strategies across SEO, SEM, Social Media Marketing (SMM), Social Media Advertising (SMA), content marketing, performance marketing, and integrated digital campaigns. My expertise extends beyond individual channels, focusing on how every aspect of digital marketing works together to drive measurable business growth. Throughout my career, I have successfully managed and optimized campaigns across a wide range of industries, including technology, finance, healthcare, retail, e-commerce, education, real estate, hospitality, and professional services. This cross-industry experience has enabled me to develop data-driven strategies tailored to unique business objectives, customer behaviors, and competitive landscapes. I have partnered with multinational corporations (MNCs) as well as established enterprises and high-growth businesses, helping them strengthen their digital presence, increase brand visibility, generate qualified leads, improve customer acquisition, and maximize return on marketing investment. From developing comprehensive digital strategies to managing multi-channel campaigns with substantial budgets, I have consistently delivered results through continuous optimization, analytics, and innovation. My expertise includes technical and on-page SEO, enterprise SEO strategies, paid search (Google Ads, Microsoft Ads), paid social campaigns across Meta, LinkedIn, TikTok, and other platforms, marketing automation, conversion rate optimization (CRO), web analytics, audience segmentation, content strategy, and performance reporting. I combine analytical thinking with creative problem-solving to ensure every campaign aligns with broader business goals. What sets me apart is my holistic understanding of the digital marketing ecosystem. Rather than viewing SEO, paid media, social media, and content as isolated disciplines, I develop integrated strategies where every channel supports the customer journey—from awareness and engagement to conversion, retention, and advocacy. This full-funnel approach allows businesses to achieve sustainable growth while adapting to evolving market trends and consumer expectations. Driven by continuous learning and innovation, I stay at the forefront of emerging technologies, AI-powered marketing, automation, and evolving digital platforms. My passion lies in transforming complex marketing challenges into scalable, measurable, and sustainable growth opportunities that deliver long-term business success.

On this page

Share

Get found by customers already looking for you

A free, honest look at where you stand today and what it would take to move.

Not sure where you stand?

Tell us about your business and we will take an honest look at where you are today — and what it would take to get where you want to be.

No obligation · a human replies within one working day