PERSONAL DATA PROTECTION ACT 2010 NOTICE AND CONSENT (PERSONAL DATA NOTICE
KPJ PENANG SPECIALIST HOSPITAL is subject to the personal data protection principles under the Personal Data Protection Act 2010 (hereafter referred to as PDPA) with effect from 15 November 2013, which regulates the processing of personal data in commercial transactions. The terms
“personal data”, “processing” and “commercial transactions”shall have the meaning provided in the PDPA.
It is obligatory that you supply us with your personal data. If you fail to supply us with such personal data, we may not be able to process and/or disclose your data for the purposes as provided in item C) below.
This Personal Data Notice and Consent applies to any person whose personal data is being processed by KPJ PENANG SPECIALIST HOSPITAL.
We wish to inform you how your personal data is being processed by and on behalf of KPJ PENANG SPECIALIST HOSPITAL.
A) Source of the Personal Data
Your personal data is collected from various sources, including information you have provided us, information from third parties and information in the public domain.
B) Description of the Personal Data
Your personal data processed by us may include, where relevant:- name, date of birth, identity card or passport, name of employer/company, home and office address, telephone/handphone number, faximile number, email address, occupation, age, gender, marital status, weight, height, photos, race, nationality, religion, family and/or next of kin information, medical checkup result, medical record, Medical Report No. (MRN), medical report, diagnosis, personal health information, criminal history, investigation result, insurance details and any other personal data required for the purposes set out in item C) below.
C) Purposes of the Personal Data
Your personal data may be processed for the following purposes, where relevant:-
1. For medical and healthcare services
2. To facilitate the patients personal needs (i.e. extension of stay for health tourists)
3. To establish and manage medical records and medical reports
4. To facilitate payment process relating to the patients
5. To institute debt recovery proceedings against defaulters
6. To report the personal data to the relevant authorities and/or third parties under the governing laws relevant to the healthcare industry
7. To share the personal data with KPJ Healthcare Berhad and its related companies as defined in the Companies Act 1965
8. To conduct research, analysis and improvement
9. To market and advertise products and services
10. To administer and respond to requests, queries, complaints and legal issues
11. For education and training
12. For any other purpose that is incidental or in furtherance to the above
D) Disclosure of the Personal Data
Your personal data may be disclosed to the following parties,where relevant:-
1. Healthcare professional (as defined in PDPA)
2. KPJ Healthcare Berhad and its related companies (as defined under CA 1965)
3. Government agencies, local authorities, non government agencies
4. Paying and insurance agents
5. Debt collection authorities and agencies
6. Financial institutions
7. Legal firms
10. Other private and public hospitals
11. Other Healthcare providers
12. Training providers
13. Family and next of kin
14. To such parties as may be required by law, court, regulator or legal process to disclose
15. To such parties as may be permitted under the laws of Malaysia
16. Any other person which KPJ PENANG SPECIALIST HOSPITAL may deem necessary
E)Access and Update the Personal Data
We shall do our best to ensure that the personal data we hold about you is accurate, complete, not misleading and up-to-date. If there are any changes to your personal data or if you believe that the personal data we have about you is inaccurate, incomplete, misleading or not up-to-date, please contact us so that we may take steps to update your personal data.
You have the right to access your personal data. If you would like to request access to your personal data, please contact us.We recommend that your request for access to your personal data held by KPJ PENANG SPECIALIST HOSPITAL be made in writing. We may also take steps to verify your identity before fulfilling your request for access to your personal data.
In accordance with the PDPA:
i. Depending on the information requested, we may charge a fee as stipulated in the First Schedule (Regulation 2) of Personal Data Protection [Fees] Regulations 2013 for processing your request for access; and
ii. We may refuse to comply with your request to access or make a correction in accordance with PDPA.
F) How to Contact Us
Please contact us by using any of the following modes if you have any queries or complaints in respect of your personal data:-
KPJ PENANG SPECIALIST HOSPITAL
570 JALAN PERDA UTAMA, BANDAR PERDA,
14000 BUKIT MERTAJAM
SEBERANG PERAI, PULAU PINANG
Attention: Medical Record Services
Telephone Number: 04-5486688
Email Address: firstname.lastname@example.org
We provide this Personal Data Notice and Consent in both English and Bahasa Malaysia. In case of any inconsistencies between these two, the English version shall prevail.
G) Consent (Please Tick (√), Where Relevant)
By providing to you my personal data, I hereby consent to the processing of mypersonal data in accordance with all of the foregoing.
By providing to youmy personal data, I hereby consent to the processing of my personal data in accordance with all of the foregoing EXCEPT for the following:-
SIGNATURE : ______________________________
NAME : ______________________________
I/C NUMBER : ______________________________
DATE : ______________________________