Singapore requires a notifiable data breach to be reported within 3 calendar days. Malaysia requires it within 72 hours. Those are the same length of time, so the two obligations look interchangeable, and compliance summaries routinely present them side by side as though they were.

They are not comparable. The deadline is the simple part; the complexity is in the trigger. The two clocks start at different events, and in Malaysia's case the binding instrument and the regulator's own guideline describe two different triggers.

Singapore: three days, from a moment the Act does not date

Section 26D(1) of the Personal Data Protection Act is precise about the deadline and about what it runs from:

"Where an organisation assesses, in accordance with section 26C, that a data breach is a notifiable data breach, the organisation must notify the Commission as soon as is practicable, but in any case no later than 3 calendar days after the day the organisation makes that assessment."

The three days begin once the assessment is complete. The time allowed for that assessment is governed by section 26C(2), which gives a standard rather than a fixed period:

"…the organisation must conduct, in a reasonable and expeditious manner, an assessment of whether the data breach is a notifiable data breach."

The only figure attached to that step lives in the Commission's advisory guidelines, not in the Act:

"organisations should generally do so within 30 calendar days."

⚠️ The modality is the whole point. "No later than 3 calendar days" is statute; "should generally … within 30 calendar days" is guidance. The hard, enforceable deadline governs the short final step, while the soft guidance governs the assessment period that makes up most of the elapsed time.

The 30 days is not toothless, since the same guidelines state that any unreasonable delay in assessing a breach is itself a contravention. It is, however, a standard to be argued after the fact rather than a date you can diary.

Malaysia: 72 hours, from the breach itself

Malaysia's obligation lives in a Commissioner's circular issued under section 12B. Its wording runs from the event, not from discovery:

"Within seventy-two (72) hours from the personal data breach, the data controller shall submit to the Commissioner the following information: …"

The accompanying guideline restates the same rule in English:

"The notification shall be made as soon as practicable and no later than seventy-two (72) hours from the occurrence of the personal data breach."

Read literally, that clock can run out before anyone knows there is a clock. A breach discovered on day five was already unreportable on day four.

And then the same document does something else entirely

The paragraph immediately after that sentence gives worked examples. Every one of them starts the clock at awareness:

"When a USB key containing unencrypted personal data is reported as lost, the 72-hour notification period to the Commissioner begins as soon as the data controller is informed of the loss."

"In cases where a data controller's network is potentially compromised or infiltrated, the 72-hour notification period to the Commissioner begins as soon as the data controller confirms, during the inspection of their system, that the system has indeed been compromised."

⚠️ In consecutive paragraphs of the same document, the rule specifies occurrence while every worked example uses awareness. On a plain reading they cannot both be right.

There is a corroborating detail pointing the same way. The circular's own reporting form asks the controller to state the date and time the breach was noticed. Awareness is a field you fill in — which is what you would expect if awareness were not the thing starting the clock.

The examples are the reading that makes the obligation workable, and they are almost certainly the intended one. A controller who follows them is acting on the regulator's own published understanding. The risk is that the instrument which binds is the circular, and the circular says occurrence, leaving a gap between rule and guidance that the controller, not the regulator, has to carry.

The two timelines, side by side

Let day 0 be the breach, and day d the day you first have credible grounds to believe it happened.

RegimeClock starts atReport due
Malaysia, circular as writtenthe breachday 0 + 3
Malaysia, the guideline's examplesawarenessday d + 3
Singapore, s.26D(1)end of your assessmentday d + assessment + 3

Taking the Commission's own 30-day figure for the assessment, Singapore's worst compliant report lands at day d + 33 against Malaysia's day d + 3:

33 ÷ 3 = 11

That is an eleven-fold difference between two obligations with identical headline numbers. Under Malaysia's literal reading the gap is not eleven-fold but undefined, because the window may close before discovery. The circular does require a controller who misses the 72 hours to state the reasons with supporting evidence, which suggests the problem is anticipated.

What this does not mean

It does not mean Singapore is lax. A 33-day worst case is a ceiling on a process that also carries an enforceable "reasonable and expeditious" duty, and most breaches are assessed in days.

It does not mean Malaysia's rule is unworkable either — the guideline's examples make it workable, and a controller who follows them is doing what the regulator has published.

The narrower point is that you cannot plan against the headline number in either country. The "72 hours" or the "3 days" is the last step of a process whose start you must establish separately, and in Malaysia's case the two official documents locate that start differently.

What to do about it

Write the trigger into your incident runbook, not the deadline. A runbook that says "notify within 72 hours" tells the responder nothing about when to start counting, which is the only part anyone gets wrong under pressure. Record the moment of awareness with a timestamp, in both jurisdictions, because it is the input every reading depends on.

⚠️ And count calendar days. Singapore's Act says "3 calendar days" and Malaysia's circular says 72 hours; neither is expressed in working days, so a weekend consumes most of the window. If your planning habitually uses a working days calculator, this is precisely the case where that is the wrong instrument.

Two thresholds worth keeping to hand while you are there. Singapore's scale trigger is 500 affected individuals, prescribed by regulation — though a breach can be notifiable at any scale on the basis of the categories of data involved. Malaysia's penalty for failing to notify is a fine not exceeding RM250,000, imprisonment for up to two years, or both.

Where this comes from, and what will date it

Singapore's deadline and its trigger are quoted from sections 26D(1) and 26C(2) of the Personal Data Protection Act 2012; the 30-day figure and the unreasonable-delay hook are from the Commission's advisory guidelines on key concepts, in the revision current at the time of writing; the 500-individual threshold is from the notification regulations. Malaysia's 72 hours, the occurrence wording, the worked examples, the reporting form's awareness field, the late-notification provision and the penalty are all from the Commissioner's 2025 circular and its accompanying guideline. Section 12B has been in force since 1 June 2025.

⚠️ Two limits, stated rather than smoothed over. We read Malaysia's obligation through the Commissioner's circular and guideline rather than the statutory text of section 12B itself, which we could not retrieve. And we are describing what the documents say, not how the regulator enforces them — no published enforcement action turning on the occurrence-versus-awareness question was found, so the practical consequence of the gap is untested.

⚠️ A trap for anyone checking this themselves: the Singapore guidelines PDF whose URL contains a 2022 date is internally marked as revised in 2026. Cite the document's own revision line, not its filename.

The contradiction is the part most likely to date, and in the good direction. Regulators fix this sort of gap in routine revisions, and if Malaysia aligns the rule with its own examples this specific finding becomes history. The structural point would survive it: a notification deadline is only as meaningful as the event it counts from.