Singapore legislation

Regulation 6

of Personal Data Protection (Notification of Data Breaches) Regulations 2021

Regulation 6

Notification to affected individuals

For the purposes of section 26D(3) of the Act, the notification by an organisation to an affected individual affected by a notifiable data breach under section 26D(2) of the Act must contain all of the following information:

(a)

the circumstances in which the organisation first became aware that the notifiable data breach had occurred;

(b)

the personal data or classes of personal data relating to the affected individual affected by the notifiable data breach;

(c)

the potential harm to the affected individual as a result of the notifiable data breach;

(d)

information on any action by the organisation, whether taken before or to be taken after the organisation notifies the affected individual —

(i)

to eliminate or mitigate any potential harm to the affected individual as a result of the notifiable data breach; and

(ii)

to address or remedy any failure or shortcoming that the organisation believes to have caused, or enabled or facilitated the occurrence of, the notifiable data breach;

(e)

the steps that the affected individual may take to eliminate or mitigate any potential harm as a result of the notifiable data breach, including preventing the misuse of the affected individual’s personal data affected by the notifiable data breach;

(f)

the business contact information of at least one authorised representative of the organisation.