DisclosureLens
SINGAPOREUnknownLow

Cold Press Index Pte Ltd

bd_79430a3fd3272855 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Oct 2, 2025

To disclose

Affected

Not disclosed

Confidence

90%
Full breach record for Cold Press Index Pte Ltd

Regulator's decision — not a breach notification

This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.

Background On 3 April 2025, the Personal Data Protection Commission (the “ Commission ”) received a complaint from an individual (the “ Complainant ”) against Cold Press Index Private Limited (the “ Organisation ”) on disclosure of the Complainant’s personal data without consent. The Complainant had discovered that the Organisation had posted the Complainant’s personal data (name, residential address, contact number) in its replies to two of the Complainant’s reviews on the Organisation on its Google Review Pages (the “ Incident ”). The Complainant had provided the said personal data to the Organisation for purposes of contact and fulfilling delivery of an order placed with the Organisation. After being informed on the day of the delivery that the order could not be fulfilled and being refunded, the Complainant shared the negative experience in a public review on three of the Organisation’s Google Review Pages. In response to the Complainant’s reviews, the Organisation posted the said personal data as part of its replies on two of the three Google Review Pages, to “shame” the Complainant. The Organisation did not limit disclosure to the extent necessary for the original consent, did not notify the Complainant of the new purpose of the disclosure or seek fresh consent before the disclosure on the Google Review Pages as required under sections 13(a), 18 and 20(1) of the Personal Data Protection Act 2012 (“ PDPA ”). The Commission notes that the Organisation did not disclose personal data in its replies for other reviews on its Google Review Pages. The Organisation did not have a data protection officer and did not provide this information to the public as required to comply with section 11 of the PDPA. The Organisation has since appointed a data protection officer and published this information, removed the Complainant’s personal data on the Google Review Pages, reviewe

Incident timeline — partial

? — ?

Breach window unknown

Oct 2, 2025

Filed

No linked breach filing · watching

Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Source ceiling

  • outcome + obligations
  • fine (SGD) and affected count where a grounds document states them
  • discovery date
  • notification clock

See the underlying breach notice, if any.