Singapore sets the bar with the PDPA: ‘reasonable security arrangements’, assessment of suspected breaches, and notification to the PDPC within 3 calendar days of assessing a breach as notifiable. The Cybersecurity Act 2018 adds incident-reporting duties for designated CII owners. Neither mandates a certificate. An ISO 27001 ISMS is how you evidence ‘reasonable’ to a regulator.
Singapore’s Personal Data Protection Act 2012 asks for “reasonable security arrangements” — technology-neutral, no standard named. The 2020 amendments added the mandatory breach-notification duty, with the mechanics set out in the Personal Data Protection (Notification of Data Breaches) Regulations 2021. The regulator is the Personal Data Protection Commission (PDPC).
The breach regime turns on two triggers and one unusual clock:
| Question | The PDPA’s answer |
|---|---|
| When is a breach notifiable? | When it causes or is likely to cause significant harm to affected individuals, or is of significant scale — 500 or more individuals |
| When do you tell the PDPC? | No later than 3 calendar days after assessing the breach as notifiable |
| When do you tell individuals? | Where significant harm is likely |
Notice what the clock is anchored to. Not the breach; the assessment. Suspect a breach, and the job is to assess whether it meets a trigger — then, once assessed as notifiable, notification to the PDPC is due within 3 calendar days. Both triggers are evidence questions: “significant harm” needs to know what data was exposed, and “500 or more individuals” needs an actual count. Neither can be answered from an incident you can’t reconstruct.
Beyond the PDPA, the Cybersecurity Act 2018 runs Singapore’s critical information infrastructure regime: designated CII owners report prescribed incidents to the Commissioner of Cybersecurity at the Cyber Security Agency of Singapore. And on data location, the PDPA imposes no residency rule — its transfer-limitation obligation instead requires comparable protection for personal data sent overseas.
“Reasonable” is an argument you have to be able to win after something has gone wrong. A certified ISMS is the strongest version of that argument: a risk assessment across all 93 Annex A controls, applicability recorded in the Statement of Applicability, and an independent auditor’s confirmation that the controls operate.
| Singapore obligation | Where the ISMS answers it |
|---|---|
| “Reasonable security arrangements” (PDPA) | The risk assessment and Statement of Applicability — a documented, independently audited case for what’s reasonable |
| Assessing suspected breaches | Logging and monitoring that can reconstruct what happened, whose data was involved, and how many people are affected |
| PDPC notification within 3 days of assessment | Incident management with the assessment step built in and evidenced, so the notifiable/not-notifiable call is a record, not a recollection |
| CII incident reporting (Cybersecurity Act 2018) | Monitoring and reporting discipline scoped over the designated systems |
| Transfer limitation | Supplier and transfer controls, with records of where personal data flows and what protects it there |
Already have Vanta or Drata? We make them work and run the security they don’t — the platform tracks the tasks; someone still has to operate the monitoring the assessment duty assumes.
The certification audit — Stage 1 documentation review, then Stage 2 interviews and evidence — is performed by a certification body accredited by the Singapore Accreditation Council (SAC), administered under Enterprise Singapore. Never by Secure60. Audit fees are set by the certification body and vary with the size and scope of the certified system; surveillance audits run annually, recertification every three years.
Singapore is often the anchor entity for a regional scope: certify once with a multi-country boundary and the same certificate answers questionnaires from Bangkok to Auckland. Secure60 has delivery infrastructure in Singapore via Rackcorp, with a datacentre in-country, so collection and monitoring can run locally on our security platform where that’s expected.
“Three calendar days” gets read as generous — a full day more than the region’s 72-hour clocks. But the Singapore clock starts after you assess the breach as notifiable, and that’s not the concession it sounds like. The assessment is itself the duty, and it can’t stretch indefinitely: an assessment that takes weeks because nothing was logged is not a defence, it just relocates the failure earlier in the timeline.
In practice the regime rewards exactly one thing: being able to answer “what happened, whose data, how many people” quickly and from records. Get that capability in place and the 3-day window is comfortable. Without it, no notification window would be.
We build the ISMS, implement the controls, and operate what the assessment duty actually depends on — logging, monitoring, incident management with an evidenced assessment step — with delivery on Singapore infrastructure via Rackcorp. The certification audit belongs to an SAC-accredited certification body; we make sure everything it samples is running when it arrives. We’re ISO 27001:2022 certified ourselves, so the questions your auditor will ask are questions we answer about our own system every year.
Is ISO 27001 legally mandatory in Singapore?
No. The PDPA requires ‘reasonable security arrangements’ without naming a standard. A certified ISMS is the practical way to show the PDPC — and enterprise customers — what reasonable means for your organisation and that it’s actually running.
When is a data breach notifiable in Singapore?
When it causes or is likely to cause significant harm to affected individuals, or when it’s of significant scale — 500 or more individuals. You notify the PDPC no later than 3 calendar days after assessing the breach as notifiable, and affected individuals where significant harm is likely.
Does the Cybersecurity Act apply to us?
Only if you’re a designated critical information infrastructure owner. The Cybersecurity Act 2018 requires designated CII owners to report prescribed incidents to the Commissioner of Cybersecurity at the Cyber Security Agency of Singapore.
Does data have to stay in Singapore?
No — the PDPA has no residency rule. Its transfer-limitation obligation requires comparable protection for personal data moved overseas, which is a controls-and-contracts question your ISMS records and evidences.
Who performs the ISO 27001 certification audit in Singapore?
A certification body accredited by the Singapore Accreditation Council (SAC), administered under Enterprise Singapore — not Secure60. Audit fees are set by the certification body and vary with the size and scope of what’s being certified.
Can Secure60 deliver in Singapore?
Yes — we have delivery infrastructure in Singapore via Rackcorp, with a datacentre in-country, so collection and monitoring can run locally. We don’t have local offices, and we never perform the certification audit.