Data Protection

Data Breach Response Plan

Two clocks run. Assessment must be prompt and reasonable, completed within **30 days**. Where the breach is determined notifiable, the Commission must be notified within **3 calendar days of that determination**, and affected individuals as soon as practicable. The three days runs from determination, not discovery — which is why the determination date must be recorded.

Download as Word7 pages22 KBFree
[HEADER — replace with your organisation’s letterhead, if used]

Data Breach Response Plan

[COMPANY NAME]

Two clocks run. Assessment must be prompt and reasonable, completed within 30 days. Where the breach is determined notifiable, the Commission must be notified within 3 calendar days of that determination, and affected individuals as soon as practicable. The three days runs from determination, not discovery — which is why the determination date must be recorded.

ItemDetail
Organisation[COMPANY NAME], UEN [UEN]
Data Protection Officer[NAME], [EMAIL], [PHONE]
Deputy[NAME], [EMAIL], [PHONE]
Report a suspected breach to[EMAIL] and [PHONE] — immediately, at any hour
Incident response team[DPO, IT lead, legal, communications, business owner]
External support on call[Forensic provider / Legal adviser / Insurer — names and numbers]
Cyber insurance[Insurer, policy number, notification requirement]
Approved by[NAME], [DESIGNATION], on [DATE]
Last tested[DATE]

1. What Counts as a Data Breach

1.1A data breach is the unauthorised access, collection, use, disclosure, copying, modification or disposal of personal data, or the loss of a storage medium or device on which personal data is stored where unauthorised access is likely.

TypeExamples
MaliciousHacking, ransomware, phishing leading to account compromise, insider theft, credential stuffing
AccidentalEmail sent to the wrong recipient, attachment containing more data than intended, misconfigured cloud storage, mis-set access permissions
PhysicalLost or stolen laptop, phone or USB drive; documents left behind; unsecured disposal of records
VendorA breach at a processor holding data on our behalf — our obligation, not only theirs
SystemA software fault exposing data to the wrong users; a database left accessible without authentication

1.2A near miss — where a breach was prevented or the data recovered before access occurred — should still be reported internally and recorded.

2. Report Immediately — Do Not Assess First

2.1Any person who suspects a breach must report it immediately to the Data Protection Officer, at any hour, using the contacts above.

2.2Do not attempt to assess whether it is serious, investigate the cause, or fix it before reporting. Containment time is the most valuable resource in a breach, and well-meaning attempts to resolve something quietly are the most common cause of its loss.

Generated from www.helionerp.com1

6 more pages in the Word file

This is page 1 of the Word document, exactly as it appears when you open it. Fields shown like THIS are placeholders for you to complete.

Notes for use

These notes accompany the template and explain the drafting choices, the compliance points and the mistakes most often made with this document. They appear as a final page in the Word file, intended to be deleted before the document is executed.

Thirty days to assess, three days to notify from determination

The assessment must be prompt and reasonable and completed within thirty days of becoming aware of a suspected breach. Where determined notifiable, the Commission must be notified within three calendar days **of the determination**, and affected individuals as soon as practicable. Because the three days runs from determination rather than discovery, the determination date is the single most important entry in the register.

Do not let assessment drift to day thirty

Thirty days is an outer limit for a genuinely complex investigation, not a target. Most breaches can be assessed within a few days, and a determination made a month after discovery, with individuals notified after that, is difficult to defend as prompt even if technically within the period.

Two independent tests

Notifiability arises on significant harm **or** significant scale. A small breach of highly sensitive data is notifiable on harm; a large breach of low-sensitivity data is notifiable on scale. Assessing only one of them is the most common analytical error.

Record the reasoning when you decide not to notify

Organisations diligently document notified breaches and document nothing about those assessed and dismissed. If the decision is later questioned, the absence of a record is indistinguishable from never having assessed. Clause 4.2 and the register both require it.

Report first, investigate second

Clause 2.2 is the most important operational instruction in this plan. The costliest delays come from someone discovering a problem and trying to fix or understand it before telling anyone — which loses containment time and frequently destroys the logs needed to establish scope.

Never punish a false alarm

Clause 2.4 exists because staff who fear looking foolish will hesitate, and hesitation is measured in hours that matter. Say it in training, and mean it the first time someone reports something trivial.

Preserve the evidence

Suspending routine log rotation and deletion is an early containment step, not an afterthought. Many organisations discover during a breach that their logging retention is shorter than the period they need to investigate — checklist item 6 tests that in advance.

A processor breach is your breach

Where a vendor holding data on your behalf is breached, the obligation to assess and notify rests with you. That is why processor agreements must require immediate notification to you — a vendor that tells you three weeks later makes your own timeline impossible. Checklist item 8 tests the contract, not the relationship.

If you are the processor, notify the controller without delay

Where the Company processes data for another organisation and a breach occurs, the obligation is to notify that organisation without undue delay so that they can meet their own deadlines. Clause 4.3 states this.

Encryption is a mitigating factor, not an exemption

Where data was encrypted or otherwise unintelligible, or was fully recovered before any access, significant harm may be unlikely. That must be assessed and documented on the facts — including whether the key was also compromised — not assumed because a system is described as encrypted.

Tell individuals something they can act on

Notification advice such as "please remain vigilant" is not useful. Tell people specifically what to change, which account to watch, and what a fraudulent contact might look like. The quality of that section is what determines whether the notification helps anyone.

Do not minimise

A notification that understates the scope, and is later corrected, causes more damage than the original breach. It also converts a regulatory matter into a credibility problem. Say what happened.

Notify the insurer early

Cyber policies typically require prompt notification and may require the insurer to approve forensic or legal providers before engagement. Engaging your own forensic firm first can prejudice cover. Item 13 of the checklist requires the policy conditions to be understood before an incident, not during one.

Test the plan before you need it

A tabletop exercise reliably surfaces the gaps — nobody knows the out-of-hours number, the response team includes someone who left, logs are only kept a week, nobody has authority to take a system offline. Item 11 makes it annual. A plan that has never been walked through is a document, not a capability.

Current as of

Reflects Singapore law current as of {{DATE OF USE}}. Notification thresholds, prescribed data categories, the scale threshold, timelines and Commission guidance all change — confirm the current position with the Personal Data Protection Commission, and take legal advice during any significant breach rather than after it.

This is a ready-to-use template provided for convenience. Laws and requirements change, and every situation is different — please have it reviewed by a qualified professional (a lawyer, corporate secretary, or accountant as relevant) before you rely on it.