M cenaly.ru
🇸🇬 Singapore · Customers

Data Breach Response Plan

Data breach response plan under the PDPA Data Breach Notification Obligation (in force since February 2021) — the Personal Data Protection Commission (PDPC) must be notified within 3 calendar days of determining that a breach is notifiable.

All templates
Country
🇸🇬 Singapore
Category
Customers
Language of the text
EN
Version
1

⚠️ This is a blank template, not legal advice: check the wording with a lawyer and adapt it to your jurisdiction and your case.

This template has no optional clauses: the text is the same for everyone. Field placeholders are shown as labels — on the site the template is read-only, values are entered inside the system.

Document

DATA BREACH RESPONSE PLAN

Organisation: Organisation name

This plan implements the PDPA Data Breach Notification Obligation, in force since February 2021: the organisation must assess a suspected breach (PDPC guidance: aim to conclude the assessment within around 30 days), and if the breach is notifiable — because it results in, or is likely to result in, significant harm to affected individuals, or affects 500 or more individuals — notify the Personal Data Protection Commission (PDPC) as soon as practicable and in any case no later than 3 calendar days after determining the breach is notifiable, and notify affected individuals as soon as practicable.

1. INCIDENT 1.1. Incident date and description

2. DATA AND INDIVIDUALS AFFECTED 2.1. Data types involved and estimated number of individuals affected

3. NOTIFIABILITY ASSESSMENT 3.1. Notifiability assessment

4. CONTAINMENT 4.1. Containment actions taken

5. NOTIFICATION 5.1. PDPC notified on: Date PDPC was notified 5.2. Affected individuals notified on: Date affected individuals were notified 5.3. Exceptions applied (if not notifiable): Exceptions applied (if not notifiable)

6. CORRECTIVE MEASURES 6.1. Corrective and preventive measures

7. RESPONSIBILITY AND LOGGING 7.1. Responsible DPO: Responsible DPO 7.2. Logged at: Reference to the incident log

— — — ⚠️ This is a boilerplate template, not legal advice. Singapore's Employment Act, CPF, PDPA, and MOM/SFA/PDPC compliance regimes are subject to near-term and phased changes — including the Workplace Fairness Act (commencing end of 2027), the SAFE food-safety framework (phasing in from 19 January 2026, with the Food Safety and Security Act 2025 phasing in through 2028), the Local Qualifying Salary rising to S$1,800/month (or S$10.50/hour) on 1 July 2026, and CPF contribution-rate and work-pass policy updates — have this template reviewed and adapted by a lawyer before use, and confirm the current rules and thresholds at mom.gov.sg, pdpc.gov.sg, and sfa.gov.sg on the date of use.

Fields of the document

Fields that belong to a switched-off clause are dimmed — they are not asked for.

  • Organisation nametextrequired
  • Incident date and descriptionlong textrequired
  • Data types involved and estimated number of individuals affectedlong textrequired
  • Notifiability assessmentchoicerequired

    PDPC guidance is to complete this assessment within around 30 days of becoming aware of the incident

  • Containment actions takenlong textrequired
  • Date PDPC was notifieddateoptional

    Must be no later than 3 calendar days after determining the breach is notifiable

  • Date affected individuals were notifieddateoptional

    As soon as practicable, in tandem with or after notifying the PDPC

  • Exceptions applied (if not notifiable)long textoptional

    e.g. encryption or other technological measures rendering the data unintelligible

  • Corrective and preventive measureslong textrequired
  • Responsible DPOtextrequired
  • Reference to the incident logtextoptional

    ALL incidents, including non-notifiable ones, should be logged

In Cenaly this template fills itself in

0 of 11 fields are taken from the company, employee or counterparty record, the questionnaire can be dictated to the AI, and the finished document comes with a number, a PDF and an acknowledgement record.