Singapore legislation

Regulation 3

of Personal Data Protection (Notification of Data Breaches) Regulations 2021

Regulation 3

Data breach resulting in significant harm to individuals

Subregulation 1

For the purposes of section 26B(2) of the Act, a data breach is deemed to result in significant harm to an individual if the data breach relates to —

(a)

the individual’s full name or alias or identification number, and any of the personal data or classes of personal data relating to the individual set out in Part 1 of the Schedule, subject to Part 2 of the Schedule; or

(b)

all of the following personal data relating to an individual’s account with an organisation:

(i)

the individual’s account identifier, such as an account name or number;

(ii)

any password, security code, access code, response to a security question, biometric data or other data that is used or required to allow access to or use of the individual’s account.

Subregulation 2

In paragraph (1)(b), “account identifier” includes a number assigned to any account the individual has with an organisation that is a bank or finance company.