Part 6A, Notification of Data Breaches
Is this legally binding?
Binding. Binding law. It applies to everyone in scope, whether or not anyone points at it.
Mandatory data breach notification regime (in force 1 Feb 2021): organisations must assess suspected breaches (s 26C) and notify the PDPC within 3 calendar days of assessing a breach as notifiable, and notify affected individuals where significant harm is likely (s 26D).
What this connects to
4 relations. Official relations are the ones the source documents state; anything marked GAGE analysis is our reading, not an agency's.
Cites3
- ObligationDuty to Assess Data Breaches (s 26C)Binding
Structural decomposition of the source instrument
- ObligationDuty to Notify Notifiable Data Breaches (s 26D)Binding
Structural decomposition of the source instrument
- Concept'Notifiable Data Breach' (s 26B)Binding
Structural decomposition of the source instrument
Cited by1
- EventPersonal Data Protection (Amendment) Act 2020Binding
Act 40 of 2020 inserted Part 6A
Learn this properly
This page tells you what Part 6A, Notification of Data Breaches is and whether it binds you. The AI Governance program teaches the whole discipline, with dedicated coverage of the Singapore governance stack and the MAS regime, and every topic is passed by explaining it back in your own words, graded against the source.
See the AI Governance programVerified against the official source on 2026-08-17. GAGE is not affiliated with or endorsed by any agency named here, and nothing on this page is legal advice. How this is built and checked.
Readers of this also ask
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.