- Lists past decisions used by PDPC to illustrate aggravating and mitigating factors in financial penalty calibration.
"Past enforcement cases"
A PDPC case may end with no breach, a warning, directions, a financial penalty, directions plus a penalty, suspension or discontinuation, or a voluntary undertaking.
This page helps brief product, privacy, security, and leadership teams on what PDPC can require, what evidence matters, and how published cases should feed back into controls.
Structured answer sets in this page tree.
Cited legal and guidance references.
A Singapore PDPA matter can end without a breach finding or with a warning, directions, a , directions plus a penalty, or a , depending on the facts and the route PDPC selects. This guide explains those outcomes, the response process, and representative published cases that show how duration, data sensitivity, financial benefit, and remediation affect enforcement.
The PDPC's Active Enforcement Framework starts with the facts of the incident and the likely impact on affected individuals. Low-impact matters may be resolved through facilitation, mediation, suspension or discontinuation of the investigation, sometimes with an advisory notice that identifies improvements without making a breach finding.
Where PDPC takes a matter through investigation and determines a breach, the possible outcomes include a warning, directions, a , or both directions and a financial penalty. For high-impact incidents, the guide says PDPC may launch a full investigation early, especially where many individuals are affected or the personal data could cause significant harm.
Do not treat every incident as a fine scenario. An enforcement intake should separate impact, data sensitivity, affected population, remedial action, cooperation, repeat issues, and whether the matter may be suitable for facilitation, a , an expedited decision, or a full investigation. PDPC decides the route.
Directions are remedial orders. The enforcement guidelines describe section 48I directions as measures PDPC may issue to secure compliance, including stopping non-compliant collection, use, or disclosure, destroying personal data collected in contravention of the PDPA, complying with review directions, preventing or reducing harm, and rectifying processes.
PDPC may accept a written where an organisation is ready to implement an effective remediation plan. The Active Enforcement guide says executing a voluntary undertaking does not amount to an admission of breach. PDPC is unlikely to accept one where the organisation refutes responsibility, repeats a similar breach cause, lacks a credible remediation plan, asks for more time to prepare one, or the breach is wilful or egregious.
An has the opposite admission posture: the organisation must indicate its intention early, make an upfront voluntary admission of liability, provide the relevant incident facts, and confirm that it is willing to comply with the directions or notice. The procedure can shorten the investigation but can lead to the same breach findings and enforcement outcomes.
Published decisions and summaries are operational learning material. PDPC generally publishes decisions where an organisation is found to have contravened the PDPA so other organisations can see how the law was applied and take preventive measures.
For intentional or negligent contraventions of the PDPA Data Protection Provisions, the enforcement guidelines state that PDPC may require an organisation to pay a of up to S$1 million or 10% of the organisation's annual turnover in Singapore, whichever is higher where annual turnover in Singapore exceeds S$10 million.
For intentional or negligent contraventions of DNC provisions involving dictionary attacks and address-harvesting software, the guidelines state a cap of up to S$200,000 for an individual and, for an organisation, up to S$1 million or 5% of annual turnover in Singapore, whichever is higher where annual turnover in Singapore exceeds S$20 million. Other DNC contraventions are described separately: up to S$200,000 for an individual and up to S$1 million in other cases.
Penalty calibration is not a flat schedule. PDPC assesses harm and culpability, then considers factors such as mitigation, previous PDPA failures, voluntary admission of liability, cooperation during investigation, first-time offender status, proportionality, deterrence, and likely impact on the organisation.
Before issuing a direction or , PDPC gives the organisation or person a written notice. The accompanying preliminary decision typically states the preliminary findings, evidence, reasons, and proposed action. The recipient has 14 days to make written representations and should include the documents or information needed to support them.
PDPC may extend the representation period if exceptional circumstances in the particular case warrant an extension. It considers timely representations before issuing the final decision. If no representations arrive by the specified deadline, PDPC may finalise the decision in line with the preliminary decision.
A notice specifies the payment period, which PDPC guidance says will be no earlier than 28 days after issue. An eligible aggrieved organisation or person may apply for reconsideration within 28 days of issuance or appeal an eligible decision or direction within 28 days. These routes are alternatives at the first stage: an appeal concerning the same decision is deemed withdrawn if a reconsideration application is made.
PDPC's decisions page explains that published decisions provide insights and lessons so organisations can prevent similar occurrences. The enforcement guidelines also list past cases used to illustrate penalty factors, including examples involving duration of non-compliance, sensitive personal data, profiteering from sale of personal data, prompt mitigation, previous similar incidents, and the proportionality of penalties.
Representative examples in the enforcement guidelines show why the underlying facts matter. A disclosure to one unintended recipient for 10 minutes in Institute of Singapore Chartered Accountants [2018] SGPDPC 28 was mitigating; failure to resolve a known exposed tracking-page risk for more than two years in Ninja Logistics Pte Ltd [2019] SGPDPC 39 was aggravating; and disclosure of medical condition and sum assured in Aviva Ltd [2018] SGPDPC 4 was aggravating because of the sensitive personal data involved.
A useful case review identifies more than the organisation name and penalty amount. Record the breached obligation, failure mode, affected data, harm and culpability factors, directions or remediation required, penalty factors if any, and the internal control that prevents recurrence.
Turn each relevant case into an implementation record that engineering, security, marketing, HR, legal, privacy, and vendor-management teams can act on. For example, exposed customer pages should lead to access-control and testing evidence; repeated mailing errors should lead to training, vendor oversight, and exception monitoring. These examples are control-mapping suggestions, not findings that every similar incident breaches the PDPA.
This Singapore PDPA enforcement guide helps convert PDPC directions, undertakings, penalty factors, and published case lessons into assigned remediation records in Sorena.
Turn enforcement lessons into scoped controls, owners, evidence fields, and remediation tasks.
Use Research Copilot to compare internal controls against PDPC enforcement guidance and published cases.
Review PDPA enforcement exposure, evidence gaps, and practical remediation actions with Sorena.
"Past enforcement cases"
"Enforcement Cases"
"Types of Enforcement Outcomes"
"Undertakings"