Singapore legislation
Regulation 6
of Personal Data Protection (Notification of Data Breaches) Regulations 2021
Regulation 6
Notification to affected individuals
For the purposes of section 26D(3) of the Act, the notification by an organisation to an affected individual affected by a notifiable data breach under section 26D(2) of the Act must contain all of the following information:
the circumstances in which the organisation first became aware that the notifiable data breach had occurred;
the personal data or classes of personal data relating to the affected individual affected by the notifiable data breach;
the potential harm to the affected individual as a result of the notifiable data breach;
information on any action by the organisation, whether taken before or to be taken after the organisation notifies the affected individual —
to eliminate or mitigate any potential harm to the affected individual as a result of the notifiable data breach; and
to address or remedy any failure or shortcoming that the organisation believes to have caused, or enabled or facilitated the occurrence of, the notifiable data breach;
the steps that the affected individual may take to eliminate or mitigate any potential harm as a result of the notifiable data breach, including preventing the misuse of the affected individual’s personal data affected by the notifiable data breach;
the business contact information of at least one authorised representative of the organisation.