Personal Data Protection Act 2012 |
Personal Data Protection (Notification of Data Breaches) Regulations 2021 |
|
Citation and commencement |
1. These Regulations are the Personal Data Protection (Notification of Data Breaches) Regulations 2021 and come into operation on 1 February 2021. |
Definitions |
2. In these Regulations, unless the context otherwise requires —
|
Data breach resulting in significant harm to individuals |
Data breach of significant scale |
4. For the purposes of section 26B(3)(a) of the Act, the prescribed number of affected individuals is 500. |
Notification to Commission |
5.—(1) For the purposes of section 26D(3) of the Act, the notification by an organisation to the Commission of a notifiable data breach under section 26D(1) of the Act must include all of the following information:
|
Notification to affected individuals |
6. For the purposes of section 26D(3) of the Act, the notification by an organisation to an affected individual affected by a notifiable data breach under section 26D(2) of the Act must contain all of the following information:
|
Chairman, Info-communications Media Development Authority, Singapore. |
[AG/LEGIS/SL/227A/2020/1 Vol. 1] |