Cold Press Index Pte Ltd
bd_79430a3fd3272855 · schema v1 · pii pii-v1
Full breach record for Cold Press Index Pte Ltd →Regulator's decision — not a breach notification
This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.
Background On 3 April 2025, the Personal Data Protection Commission (the “ Commission ”) received a complaint from an individual (the “ Complainant ”) against Cold Press Index Private Limited (the “ Organisation ”) on disclosure of the Complainant’s personal data without consent. The Complainant had discovered that the Organisation had posted the Complainant’s personal data (name, residential address, contact number) in its replies to two of the Complainant’s reviews on the Organisation on its Google Review Pages (the “ Incident ”). The Complainant had provided the said personal data to the Organisation for purposes of contact and fulfilling delivery of an order placed with the Organisation. After being informed on the day of the delivery that the order could not be fulfilled and being refunded, the Complainant shared the negative experience in a public review on three of the Organisation’s Google Review Pages. In response to the Complainant’s reviews, the Organisation posted the said personal data as part of its replies on two of the three Google Review Pages, to “shame” the Complainant. The Organisation did not limit disclosure to the extent necessary for the original consent, did not notify the Complainant of the new purpose of the disclosure or seek fresh consent before the disclosure on the Google Review Pages as required under sections 13(a), 18 and 20(1) of the Personal Data Protection Act 2012 (“ PDPA ”). The Commission notes that the Organisation did not disclose personal data in its replies for other reviews on its Google Review Pages. The Organisation did not have a data protection officer and did not provide this information to the public as required to comply with section 11 of the PDPA. The Organisation has since appointed a data protection officer and published this information, removed the Complainant’s personal data on the Google Review Pages, reviewe
P pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Oct 2, 2025
Filed
—
No linked breach filing · watching
Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- outcome + obligations
- fine (SGD) and affected count where a grounds document states them
- discovery date
- notification clock
See the underlying breach notice, if any.