Singapore legislation

Clause 80

of Health Information Bill

Clause 80

Duty to notify affected individuals of occurrence of notifiable data breach

(1)

Subject to subsections (3), (4) and (5), a relevant person must, on or after notifying the Minister under section 79(1), notify each affected individual affected by a notifiable data breach mentioned in section 77(1)(a) in any manner that is reasonable in the circumstances.

(2)

The notification under subsection (1) must contain, to the best of the knowledge and belief of the relevant person at the time the relevant person notifies the affected individual, all the information that is prescribed for this purpose.

(3)

Subsection (1) does not apply to a System Operator in respect of a notifiable data breach mentioned in section 77(1)(a) that has occurred in relation to health information processed by or in the national electronic records system.

(4)

Subsection (1) does not apply if the relevant person —

(a)

upon or after assessing that a data breach is a notifiable data breach mentioned in section 77(1)(a), takes any action, in accordance with the prescribed requirements (if any), that renders it unlikely that the notifiable data breach will result in significant harm to the affected individual; or

(b)

had implemented, prior to the occurrence of the notifiable data breach mentioned in section 77(1)(a), any technological measure that renders it unlikely that the notifiable data breach will result in significant harm to the affected individual.

(5)

A relevant person must not notify any affected individual in accordance with subsection (1) if —

(a)

a prescribed law enforcement agency so instructs; or

(b)

the Minister so directs.

(6)

The Minister may, on the written application of a relevant person, waive the requirement to notify an affected individual under subsection (1) subject to any conditions that the Minister thinks fit.

(7)

A relevant person is not, by reason only of notifying an affected individual under subsection (1), to be regarded as being in breach of —

(a)

any duty or obligation under any written law, rule of law or contract as to secrecy or other restriction on the disclosure of information; or

(b)

any rule of professional conduct or ethics applicable to the relevant person.