SlideShare une entreprise Scribd logo
1  sur  41
1
2

PERSONAL DATA PROTECTION
ACT 2010
3

Personal Data Protection Act 2010

• Passed on 10 June 2010

• The Minister has appointed a Director General & created
a PDP Dept
• Once the PDPA comes into force the DG may assume
the role of Data Protection Commissioner
• Once the PDPA is brought into force - Data Users have 3
months to comply
4

Minister of
Information
Communication
and Culture

Appeal
Mechanism

Personal Data
Protection
Commissioner

Data User
Forum

Advisory
Committee

Data User
5

Growth of computer networks & internet –
Huge impact on society
• Over the last 3 decades computer networks have made pervasive inroads in
our everyday lives, both in business as well as the home

• The internet came along and connected the world
• Computer networks enabled efficient collection, manipulation and storage of
data – and vast quantities of it too

• Data can be stored anywhere in the world – not necessarily where it is
collected
• Gigabytes of personal data are accessed and used on daily basis

• New threats affecting privacy and data protection (identity theft, facebook,
twitter, friendster, etc)
6

Has your Personal Data been abused lately?
• How many marketing sms’s do you receive in a day?
• Has a bank offered you a pre-approved loan lately?

• Does your telco send you “I love you” mms’s without your consent?
• Did you get a season’s greeting from the Prime Minister lately?
• Did you get an email telling you that you have won USD5 million in a
European lottery?

None of these activities may have had your consent
7

What is Personal data
• Personal Data (PD) means any information which relates directly or
indirectly to a data subject, who is identified or identifiable from that
information
 Examples : Name, Address, Photographs, IC, Bank Account details,
Medical Records / History
Some Definitions
Data Subject (DS) – an individual who is the subject of the PD –
includes patients and employees
Data User (DU) – a person who processed any PD or has control
over or authorizes the processing of any PD but does not include a
data processor
8

Processing is defined widely
• Processing – means collecting, recording, holding, storing and
carrying out of operations with that data like organizations,

adaptation, retrieval, use, disclosure, transmission, transfer,
correction, erasure & destruction

Collection

Use

Disclosure

Destruction
9

Application of the PDPA
• The act applies to :
(a) personal data which is processed;
(b) any person who processes and any person who has control over or
authorizes the processing of any personal data in respect of
commercial transactions and such a person is a “data user”;

Commercial transactions –
“... of a commercial nature, whether contractual or not, which includes
any matters relating to the supply or exchange of goods or services,
agency, investments, financing, banking and insurance, but does not
include a credit reporting business carried out by a credit reporting
agency under the Credit Reporting Agencies Act 2010”.
10

Personal Data Flow - patient
HRM

Discharge/Payment

•HIS

Patient
Registration
(demographics )

HRM
PATIENT
Clinical
Information
at Clinic

Procedures

•HIS
•LIS
•OIS
10

HRM

HRM

Clinical
Information
at Wards

HRM
11

The PDPA – Who Does it NOT Apply To?

• The PDPA does not apply to :
The Federal Government
The State Government
 PD processed outside Malaysia UNLESS intended to be further
processed in Malaysia
12

Healthcare Sector in Malaysia
Current Position
Pre PDPA
2010
13

Current Regulatory Position – Piecemeal
Approach to Data Protection
Private
Healthcare &
Services Act

MMC Guide on
Confidentiality

Medical Act

MMC Guide on
Medical Records
and Medical
Reports

MMA Code on
Medical Ethics

Patient’s Charter

MMC Code of
Professional
Conduct
14

Pre-PDPA – How Personal Data was dealt with
• PHFSA – hospitals must have a policy on Patients rights:
Information concerning medical treatment and care;

Be provided with patient’s medical report within a reasonable time
• Reg 30 – patient’s MR is the property of Hospital . Patient has a right to
request for medical report
• Retention of MR is for the Limitation Period
• Doctors have right of access to MR of old patients to defend civil actions
15

MMC Guidelines on Doctors
• On medical records and reports
Medical records belong to the hospital

Information in MR belong morally and ethically to the patient
 Doctors have obligation to provide comprehensive medical reports upon
request by patient (for 2nd opinion, litigation etc)

• Doctor patient confidentially
No disclosure to 3rd parties without consent of patient
Should not reveal patient PD in medical publications
Drs must exert all powers to preserve patient confidentiality
16

MMC Guidelines for Doctors – Disclosure to 3rd
Parties
• Disclosure within Medical Teams
Drs must obtain consent of Patient to share PD with other doctors
Patient can refuse consent for sharing of PD between doctors
• Disclosure to Employers, Insurers
Dr must inform Patient and obtain consent before disclosure to
these parties
• Disclosure for Medical Teaching and medical audit
Should anonymise PD as far as possible

Doctors who decide to disclose PD must be prepared to explain
and justify their decision (MMC Guideline)
17

PDPA
The 7 Data Protection Principles Under the
PDPA
General
principle
Notice &
Choice
Principle

Access
Principle

PDPA
Data
Integrity
Principle

Disclosure
Principle

Retention
Principle

Security
Principle

18
19

No

PDP
Principles

What it covers

1

General
Principle

Consent of DS is required to process PD.
For Sensitive Personal Data – explicit consent is required

2

Notice &
Choice
Principle

DU give Notice to DS of the processing, description of PD,
purpose, source of info and right to request access, 3P to
whom DU discloses, how to limit the processing, whether it is
obligatory or voluntary to supply PD

3

Disclosure
Principle

No disclosure of PD without consent of DS

4

Security
Principle

DU must take practical steps to protect PD (IT System &
Internal processes)

5

Retention
Principle

PD should not be kept longer than necessary – must destroy
after purpose is met

6

Data Integrity
Principle

DU must ensure Data processed is accurate, complete and upto-date having regard to the purpose of collection

7

Access
Principle

DS must have access and be able to correct if inaccurate
20

1. General Principle - consent
• A data user cannot process any PD about a Data Subject unless the Data Subject has
given his consent.
• Consent can be expressed or implied
• PD cannot be processed unless :
 PD is processed for a lawful purpose directly related to the activity of the Data
User
The processing of PD is necessary for or directly related to that purpose
Directly related to that purpose means the reason that the PD was collected.
Eg: a person comes for a blood test and his consent is acquired to conduct all the
necessary test. However, the consent shall not extend to the publication of his blood
test results in a medical article.

PD is adequate but not excessive in relation to that purpose
Eg: a patients comes to ER to see the doctor for fever medication. It is not necessary to
ask the patient of his grandparents, aunt, uncle’s names, IC, add etc.

Distinction between consent for medical purpose and other purpose
21
22

2. Notice & Choice Principle
• A DS is required to give written consent to DU:
That PD is being processed and provide a description of the PD being
processed
The purposes for which the PD is collected and processed
 DS’s right to request access to and request correction of the PD
Disclosure to any 3rd parties that may be made
23

3. Disclosure principle
• No Personal Data shall be disclosed without the consent of the DS:
For any other purpose other than the original purpose as disclosed to the
DS at the time of collection
A purpose directly related to the purpose above
To any party other than a 3rd party already notified to the DS (under Notice
Principle)

• Disclosure for the purpose of research, discussions in medical meetings /
seminars :This disclosure is allowed as long as the data that is being disclosed cannot be
related to a particular person

• Note: Disclosure to the Ministry of Health – this is a compulsory disclosure
and thus shall be exempted.
24

Case note - disclosure
Improper
disclosure of
SPD to
Government
Agency

The complainant had medical
tests at a pathology clinic and
asked that the results be
provided only to their treating
medical specialist and solicitor.
The tests results were to be part
of a claim that the complainant
was making to a federal
government agency.
The complainant later became
aware that the clinic had
provided the results directly to
that government agency.
DS complained to the Data
Commissioner

The clinic advised the clinic
staff to send directly to the
government agency noted on
the complainant’s form.
The clinic contended that this
was an isolated error.
As this information was
disclosed for a purpose other
than the primary purpose for
which it was collected. The
commissioner formed the view
that the disclosure was an
interference with the
complainant’s privacy.

The clinic paid compensation
to the DS.
25

The security
principle need
to be adequate
but it
shouldn’t be
unreasonable.
26

4. Security Principle
• DU shall take practical steps to protect PD from any
Loss, misuse, modification
Unauthorized or accidental access or disclosure
Alteration or destruction
Having regard to location, IT systems and mode of transfer of PD
• Hospital IT systems such as the HMIS, HIS and LIS need strict policies
• Transfer to 3rd party service providers such as outside lab and transfers of PD overseas
Security issues : use of portable devices (laptops, USB, External hard drive, CD, DVD)
Transmission of patient info via fax
Medical devices storage function
Remote access to MR

Doctors have to comply with Hospital’s policies regarding
PDPA requirements
27
28

Sony fined GBP 250,000 for Breach of
Security
• A cyber attack on the SONY’s PlayStation Network in April 2011 put a
huge number of consumers at risk of identity theft including credit card
details
• It could have been prevented if Sony’s software was up-to-date and
technical developments hadn’t made passwords unsecure
• “There’s no disguising that this is a business that should have known
better,” said the ICO’s data protection director David Smith
• It is a company that trades on its technical expertise and there is no
doubt in my mind that they had access to both the technical expertise
and the resources to keep this information safe.
29

Data Processor
• Where PD is processed on behalf of DU the DU shall ensure that the
Data Processor :
 Provides guarantees in respect of technical and security
measures governing the processing; and
 Takes reasonable steps to ensure compliance with those
measures
 Eg: The IT system in SDMC PC – system designed for SDH and they do have
access to our patient records.

Data Processor = Outsourced Service Providers
30

5. Retention Principle
31

Retention Principle
• PD shall not be kept longer than is necessary for the fulfillment of the original
purpose
• DU has duty to take all reasonable steps to ensure that PD is :
• Destroyed (must be done in a proper manner); or
• Permanently deleted

…… if it is no longer required for the purpose for which it was processed
QUESTION : how long is long?
 Depends on the nature of your business and the commercial reasons to
keep data
 7 years / 25 years / hospital policy
32
33

6. Data Integrity Principle
34

Data Integrity Principle
• DU has duty to take all reasonable steps to ensure that PD is :
• Accurate

• Complete
• Not misleading; and

• Kept up to date
35

7. Access Principle
• A data subject shall be given access to his personal data upon Data Access Request
• All information that is being processed by or on behalf of the Data User
• Entitled to an intelligible
copy of the PD
• Access can be just to view or
get a copy

• Subject to some exceptions

Under the PDPA, patient may now get
access to his entire MR
36

Case note

Who can
access PD

Hospital prepared a health
report for an insurance
company
Patient wanted a copy under
access principle
Hospital refused

DC held that all PD held by
the hospital, including
report should be provided
to the data subject
Regardless for whom it was
prepared
37
38

GE Healthcare Admits Sending NHS Patient
Data to US
• Personal details of 600,000 patients were sent to the US following a
mistake made by the NHS’s IT provider, GE Healthcare
• GE Healthcare admitted that the error had occurred after it had obtained
more patient data than it needed, but stressed that there was no need to
worry
• Overloaded in PD
• GE Healthcare recently discovered that they obtained more patient data
from diagnostic imaging products than they needed to perform services
to their customers
39

NHS Trust fined 325,000 for data breach
• Brighton and Sussex University Hospital NHS Trust has been fined
400,000 euros following a serious breach of the UK Data Protection Act

• Highly sensitive personal data belonging to tens of thousands of patients
and staff, including some relating to HIV and Genito Urinary Medicine
patients, on hard drives sold on an Internet auction site in October and
November 2010
• The Data breach occurred when an individual engaged by the Trust’s IT
service provider, was tasked to destroy approximately 1000 hard drives
• The individual sold 4 hard drives on an internet auction in December
2010
40

Offences and Penalties
• If a body corporate commits an offence under the PDPA, any person who at the
time of the offence was a director, CEO, COO, Manager etc may be charged
jointly or severally with the company
• Liability also is attached to Senior Management for acts or omissions of any
employee acting in the course of their employment.
• Section 5 (1)
Anyone who contravenes the Personal Data Protection Principles commits and
offence and shall, on conviction, be liable to a fine not exceeding RM300,000
or to imprisonment for a term not exceeding 2 years or to both
 Penalties for other offences ranges from RM100k to RM500k with
imprisonment ranging from 1 – 3 years

 Eg. For unlawful collection or selling of PD – 500k and 3 years
41

THANK YOU

Contenu connexe

Tendances

General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...Cvent
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by QualsysQualsys Ltd
 
Data Privacy in India and data theft
Data Privacy in India and data theftData Privacy in India and data theft
Data Privacy in India and data theftAmber Gupta
 
General data protection
General data protectionGeneral data protection
General data protectionBrijeshR3
 
Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and PrivacyVertex Holdings
 
Privacy & Data Protection
Privacy & Data ProtectionPrivacy & Data Protection
Privacy & Data Protectionsp_krishna
 
Data protection ppt
Data protection pptData protection ppt
Data protection pptgrahamwell
 
PDPA Compliance Preparation
PDPA Compliance PreparationPDPA Compliance Preparation
PDPA Compliance PreparationLawPlus Ltd.
 
Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Andrew Sharpe
 
Digital personal data protection act, 2023.pptx
Digital personal data protection act, 2023.pptxDigital personal data protection act, 2023.pptx
Digital personal data protection act, 2023.pptxDineshPrasad64
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) Kimberly Simon MBA
 
An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill Komal Gadia
 

Tendances (20)

General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
Data Privacy in India and data theft
Data Privacy in India and data theftData Privacy in India and data theft
Data Privacy in India and data theft
 
Overview on data privacy
Overview on data privacy Overview on data privacy
Overview on data privacy
 
General data protection
General data protectionGeneral data protection
General data protection
 
GDPR and Security.pdf
GDPR and Security.pdfGDPR and Security.pdf
GDPR and Security.pdf
 
GDPR
GDPRGDPR
GDPR
 
An Overview of GDPR
An Overview of GDPR An Overview of GDPR
An Overview of GDPR
 
Privacy and Data Protection
Privacy and Data ProtectionPrivacy and Data Protection
Privacy and Data Protection
 
Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and Privacy
 
Privacy & Data Protection
Privacy & Data ProtectionPrivacy & Data Protection
Privacy & Data Protection
 
Data protection ppt
Data protection pptData protection ppt
Data protection ppt
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
PDPA Compliance Preparation
PDPA Compliance PreparationPDPA Compliance Preparation
PDPA Compliance Preparation
 
Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)
 
Digital personal data protection act, 2023.pptx
Digital personal data protection act, 2023.pptxDigital personal data protection act, 2023.pptx
Digital personal data protection act, 2023.pptx
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill
 
Information Privacy
Information PrivacyInformation Privacy
Information Privacy
 
What about GDPR?
What about GDPR?What about GDPR?
What about GDPR?
 

En vedette

Personal Data Protection in Malaysia
Personal Data Protection in MalaysiaPersonal Data Protection in Malaysia
Personal Data Protection in Malaysiakhenghoe
 
Data protection act
Data protection act Data protection act
Data protection act Iqbal Bocus
 
Half day public-seminar_on_pdpa_2010_-_250711
Half day public-seminar_on_pdpa_2010_-_250711Half day public-seminar_on_pdpa_2010_-_250711
Half day public-seminar_on_pdpa_2010_-_250711Quotient Consulting
 
Presentation ICT2
Presentation ICT2Presentation ICT2
Presentation ICT2safa
 
Tindak Malaysia: The Die Is Cast
Tindak Malaysia: The Die Is CastTindak Malaysia: The Die Is Cast
Tindak Malaysia: The Die Is CastAlan Teh
 
PMPASKL 52nd AGM and ASM
PMPASKL 52nd AGM and ASMPMPASKL 52nd AGM and ASM
PMPASKL 52nd AGM and ASMAlan Teh
 
Stem congress brochure 180912
Stem congress brochure 180912Stem congress brochure 180912
Stem congress brochure 180912Alan Teh
 
Role of cancer genomics and next generation sequencing.pptx 2
Role of cancer genomics and next generation sequencing.pptx  2Role of cancer genomics and next generation sequencing.pptx  2
Role of cancer genomics and next generation sequencing.pptx 2Alan Teh
 
Survey results on EMR
Survey results on EMRSurvey results on EMR
Survey results on EMRAlan Teh
 
Impact of ict on privacy and personal data
Impact of ict on privacy and personal dataImpact of ict on privacy and personal data
Impact of ict on privacy and personal datamohd kamal
 
Understanding your heart health with your helo
Understanding your heart health with your heloUnderstanding your heart health with your helo
Understanding your heart health with your heloAlan Teh
 
Lower Urinary Tract Symptoms in Men for GPs
Lower Urinary Tract Symptoms in Men for GPsLower Urinary Tract Symptoms in Men for GPs
Lower Urinary Tract Symptoms in Men for GPsAlan Teh
 
Multiple Myeloma
Multiple MyelomaMultiple Myeloma
Multiple MyelomaAlan Teh
 
Legal Framework of Internet Banking
Legal Framework of Internet BankingLegal Framework of Internet Banking
Legal Framework of Internet BankingMahyuddin Khalid
 
Hacking and Hacktivism
Hacking and HacktivismHacking and Hacktivism
Hacking and Hacktivismrashidirazali
 
GST for Doctors
GST for DoctorsGST for Doctors
GST for DoctorsAlan Teh
 

En vedette (20)

Personal Data Protection in Malaysia
Personal Data Protection in MalaysiaPersonal Data Protection in Malaysia
Personal Data Protection in Malaysia
 
Data protection act
Data protection act Data protection act
Data protection act
 
Half day public-seminar_on_pdpa_2010_-_250711
Half day public-seminar_on_pdpa_2010_-_250711Half day public-seminar_on_pdpa_2010_-_250711
Half day public-seminar_on_pdpa_2010_-_250711
 
Presentation ICT2
Presentation ICT2Presentation ICT2
Presentation ICT2
 
Tindak Malaysia: The Die Is Cast
Tindak Malaysia: The Die Is CastTindak Malaysia: The Die Is Cast
Tindak Malaysia: The Die Is Cast
 
PMPASKL 52nd AGM and ASM
PMPASKL 52nd AGM and ASMPMPASKL 52nd AGM and ASM
PMPASKL 52nd AGM and ASM
 
Stem congress brochure 180912
Stem congress brochure 180912Stem congress brochure 180912
Stem congress brochure 180912
 
Role of cancer genomics and next generation sequencing.pptx 2
Role of cancer genomics and next generation sequencing.pptx  2Role of cancer genomics and next generation sequencing.pptx  2
Role of cancer genomics and next generation sequencing.pptx 2
 
Survey results on EMR
Survey results on EMRSurvey results on EMR
Survey results on EMR
 
MOH1Care
MOH1CareMOH1Care
MOH1Care
 
Cyberlaw
CyberlawCyberlaw
Cyberlaw
 
Chapter 1
Chapter 1Chapter 1
Chapter 1
 
Impact of ict on privacy and personal data
Impact of ict on privacy and personal dataImpact of ict on privacy and personal data
Impact of ict on privacy and personal data
 
Understanding your heart health with your helo
Understanding your heart health with your heloUnderstanding your heart health with your helo
Understanding your heart health with your helo
 
Lower Urinary Tract Symptoms in Men for GPs
Lower Urinary Tract Symptoms in Men for GPsLower Urinary Tract Symptoms in Men for GPs
Lower Urinary Tract Symptoms in Men for GPs
 
Multiple Myeloma
Multiple MyelomaMultiple Myeloma
Multiple Myeloma
 
Legal Framework of Internet Banking
Legal Framework of Internet BankingLegal Framework of Internet Banking
Legal Framework of Internet Banking
 
Hacking and Hacktivism
Hacking and HacktivismHacking and Hacktivism
Hacking and Hacktivism
 
GST for Doctors
GST for DoctorsGST for Doctors
GST for Doctors
 
Consent
ConsentConsent
Consent
 

Similaire à Personal Data Protection Act 2010 Summary

Information governance
Information governanceInformation governance
Information governanceGerardo Medina
 
Things you need to know about info governance to sell healthtech products int...
Things you need to know about info governance to sell healthtech products int...Things you need to know about info governance to sell healthtech products int...
Things you need to know about info governance to sell healthtech products int...3GDR
 
Confidentiality and Data Protection in Health Care
Confidentiality and Data Protection in Health CareConfidentiality and Data Protection in Health Care
Confidentiality and Data Protection in Health CareVaileth Mdete
 
Data Privacy and Security in Clinical Trials: Safeguarding Patient Information
Data Privacy and Security in Clinical Trials: Safeguarding Patient InformationData Privacy and Security in Clinical Trials: Safeguarding Patient Information
Data Privacy and Security in Clinical Trials: Safeguarding Patient InformationClinosolIndia
 
PHIE Privacy Guidelines
PHIE Privacy GuidelinesPHIE Privacy Guidelines
PHIE Privacy GuidelinesRomsty
 
General Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsGeneral Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsWSO2
 
Imac 2011
Imac 2011Imac 2011
Imac 2011sebmojo
 
Master thesis defence Merve Şimşek
Master thesis defence Merve ŞimşekMaster thesis defence Merve Şimşek
Master thesis defence Merve ŞimşekMIPLM
 
Training innovations information governance slideshare 2015
Training innovations information governance slideshare 2015Training innovations information governance slideshare 2015
Training innovations information governance slideshare 2015Patrick Doyle
 
Chapter 08 – Data Protection, Privacy and Freedom of Information - BIT IT5104
Chapter 08 – Data Protection, Privacy and Freedom of Information - BIT IT5104 Chapter 08 – Data Protection, Privacy and Freedom of Information - BIT IT5104
Chapter 08 – Data Protection, Privacy and Freedom of Information - BIT IT5104 Upekha Vandebona
 
Care data against
Care data   againstCare data   against
Care data against3GDR
 
HIPAA INSERVICE 2017
HIPAA INSERVICE 2017 HIPAA INSERVICE 2017
HIPAA INSERVICE 2017 Meg Oser
 
Technology, policy, privacy and freedom
Technology, policy, privacy and freedomTechnology, policy, privacy and freedom
Technology, policy, privacy and freedomG Prachi
 
What’s Up eDoc?: A Health IT Privacy Primer
What’s Up eDoc?: A Health IT Privacy PrimerWhat’s Up eDoc?: A Health IT Privacy Primer
What’s Up eDoc?: A Health IT Privacy PrimerMaRS Discovery District
 
Data Privacy and consent management .. .
Data Privacy and consent management  ..  .Data Privacy and consent management  ..  .
Data Privacy and consent management .. .ClinosolIndia
 
Data privacy and consent management (K.sailaja).pptx
Data privacy and consent management (K.sailaja).pptxData privacy and consent management (K.sailaja).pptx
Data privacy and consent management (K.sailaja).pptxkandalamsailaja17
 

Similaire à Personal Data Protection Act 2010 Summary (20)

Protection of patient data in EU vs. US
Protection of patient data in EU vs. USProtection of patient data in EU vs. US
Protection of patient data in EU vs. US
 
Information governance
Information governanceInformation governance
Information governance
 
Things you need to know about info governance to sell healthtech products int...
Things you need to know about info governance to sell healthtech products int...Things you need to know about info governance to sell healthtech products int...
Things you need to know about info governance to sell healthtech products int...
 
Confidentiality and Data Protection in Health Care
Confidentiality and Data Protection in Health CareConfidentiality and Data Protection in Health Care
Confidentiality and Data Protection in Health Care
 
Data Privacy and Security in Clinical Trials: Safeguarding Patient Information
Data Privacy and Security in Clinical Trials: Safeguarding Patient InformationData Privacy and Security in Clinical Trials: Safeguarding Patient Information
Data Privacy and Security in Clinical Trials: Safeguarding Patient Information
 
PHIE Privacy Guidelines
PHIE Privacy GuidelinesPHIE Privacy Guidelines
PHIE Privacy Guidelines
 
General Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsGeneral Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity Architects
 
Imac 2011
Imac 2011Imac 2011
Imac 2011
 
Master thesis defence Merve Şimşek
Master thesis defence Merve ŞimşekMaster thesis defence Merve Şimşek
Master thesis defence Merve Şimşek
 
Training innovations information governance slideshare 2015
Training innovations information governance slideshare 2015Training innovations information governance slideshare 2015
Training innovations information governance slideshare 2015
 
Chapter 08 – Data Protection, Privacy and Freedom of Information - BIT IT5104
Chapter 08 – Data Protection, Privacy and Freedom of Information - BIT IT5104 Chapter 08 – Data Protection, Privacy and Freedom of Information - BIT IT5104
Chapter 08 – Data Protection, Privacy and Freedom of Information - BIT IT5104
 
Hipaa inservice
Hipaa inserviceHipaa inservice
Hipaa inservice
 
Care data against
Care data   againstCare data   against
Care data against
 
HIPAA INSERVICE 2017
HIPAA INSERVICE 2017 HIPAA INSERVICE 2017
HIPAA INSERVICE 2017
 
Technology, policy, privacy and freedom
Technology, policy, privacy and freedomTechnology, policy, privacy and freedom
Technology, policy, privacy and freedom
 
HIPAA Privacy and Security
HIPAA Privacy and SecurityHIPAA Privacy and Security
HIPAA Privacy and Security
 
What’s Up eDoc?: A Health IT Privacy Primer
What’s Up eDoc?: A Health IT Privacy PrimerWhat’s Up eDoc?: A Health IT Privacy Primer
What’s Up eDoc?: A Health IT Privacy Primer
 
Data Privacy and consent management .. .
Data Privacy and consent management  ..  .Data Privacy and consent management  ..  .
Data Privacy and consent management .. .
 
Data privacy and consent management (K.sailaja).pptx
Data privacy and consent management (K.sailaja).pptxData privacy and consent management (K.sailaja).pptx
Data privacy and consent management (K.sailaja).pptx
 
Data Management Protection Acts
Data Management Protection ActsData Management Protection Acts
Data Management Protection Acts
 

Plus de Alan Teh

Talk on Prostate Cancer, KL
Talk on Prostate Cancer, KLTalk on Prostate Cancer, KL
Talk on Prostate Cancer, KLAlan Teh
 
Guide to GST for Healthcare services (16 Nov)
Guide to GST for Healthcare services (16 Nov)Guide to GST for Healthcare services (16 Nov)
Guide to GST for Healthcare services (16 Nov)Alan Teh
 
1st Joine ESMO-MOS Conference
1st Joine ESMO-MOS Conference1st Joine ESMO-MOS Conference
1st Joine ESMO-MOS ConferenceAlan Teh
 
Dialogue with Datuk Seri Gopal Sri Ram
Dialogue with Datuk Seri Gopal Sri RamDialogue with Datuk Seri Gopal Sri Ram
Dialogue with Datuk Seri Gopal Sri RamAlan Teh
 
Guide to GST for Healthcare Services (Malaysia)
Guide to GST for Healthcare Services (Malaysia)Guide to GST for Healthcare Services (Malaysia)
Guide to GST for Healthcare Services (Malaysia)Alan Teh
 
eKlinikmd sponsored edition 2014
eKlinikmd sponsored edition 2014 eKlinikmd sponsored edition 2014
eKlinikmd sponsored edition 2014 Alan Teh
 
The Malaysian Calendar 2014
The Malaysian Calendar 2014The Malaysian Calendar 2014
The Malaysian Calendar 2014Alan Teh
 
HRI Workshop February 2014
HRI Workshop February 2014HRI Workshop February 2014
HRI Workshop February 2014Alan Teh
 
Obstructive Sleep Apnoea
Obstructive Sleep ApnoeaObstructive Sleep Apnoea
Obstructive Sleep ApnoeaAlan Teh
 
Health metropolis the star e paper metro central - 6 sep 2013 - page #4
Health metropolis the star e paper   metro central - 6 sep 2013 - page #4Health metropolis the star e paper   metro central - 6 sep 2013 - page #4
Health metropolis the star e paper metro central - 6 sep 2013 - page #4Alan Teh
 
10th apchg 2nd ann (13 august)
10th apchg 2nd ann (13 august)10th apchg 2nd ann (13 august)
10th apchg 2nd ann (13 august)Alan Teh
 
Haemostasis workshop final announcement
Haemostasis workshop final announcementHaemostasis workshop final announcement
Haemostasis workshop final announcementAlan Teh
 
Haemostasis workshop final announcement
Haemostasis workshop final announcementHaemostasis workshop final announcement
Haemostasis workshop final announcementAlan Teh
 
Introductory bioinformatics workshop flyer
Introductory bioinformatics workshop flyerIntroductory bioinformatics workshop flyer
Introductory bioinformatics workshop flyerAlan Teh
 
AFH 2012 flyer
AFH 2012 flyerAFH 2012 flyer
AFH 2012 flyerAlan Teh
 
Annualreport2012
Annualreport2012Annualreport2012
Annualreport2012Alan Teh
 
Agmmins2011
Agmmins2011Agmmins2011
Agmmins2011Alan Teh
 
Taknak 1care forum sitiawan
Taknak 1care forum sitiawanTaknak 1care forum sitiawan
Taknak 1care forum sitiawanAlan Teh
 
1 Care Concept Caper
1 Care Concept Caper 1 Care Concept Caper
1 Care Concept Caper Alan Teh
 
Healthcare forum on 1Care
Healthcare forum on 1CareHealthcare forum on 1Care
Healthcare forum on 1CareAlan Teh
 

Plus de Alan Teh (20)

Talk on Prostate Cancer, KL
Talk on Prostate Cancer, KLTalk on Prostate Cancer, KL
Talk on Prostate Cancer, KL
 
Guide to GST for Healthcare services (16 Nov)
Guide to GST for Healthcare services (16 Nov)Guide to GST for Healthcare services (16 Nov)
Guide to GST for Healthcare services (16 Nov)
 
1st Joine ESMO-MOS Conference
1st Joine ESMO-MOS Conference1st Joine ESMO-MOS Conference
1st Joine ESMO-MOS Conference
 
Dialogue with Datuk Seri Gopal Sri Ram
Dialogue with Datuk Seri Gopal Sri RamDialogue with Datuk Seri Gopal Sri Ram
Dialogue with Datuk Seri Gopal Sri Ram
 
Guide to GST for Healthcare Services (Malaysia)
Guide to GST for Healthcare Services (Malaysia)Guide to GST for Healthcare Services (Malaysia)
Guide to GST for Healthcare Services (Malaysia)
 
eKlinikmd sponsored edition 2014
eKlinikmd sponsored edition 2014 eKlinikmd sponsored edition 2014
eKlinikmd sponsored edition 2014
 
The Malaysian Calendar 2014
The Malaysian Calendar 2014The Malaysian Calendar 2014
The Malaysian Calendar 2014
 
HRI Workshop February 2014
HRI Workshop February 2014HRI Workshop February 2014
HRI Workshop February 2014
 
Obstructive Sleep Apnoea
Obstructive Sleep ApnoeaObstructive Sleep Apnoea
Obstructive Sleep Apnoea
 
Health metropolis the star e paper metro central - 6 sep 2013 - page #4
Health metropolis the star e paper   metro central - 6 sep 2013 - page #4Health metropolis the star e paper   metro central - 6 sep 2013 - page #4
Health metropolis the star e paper metro central - 6 sep 2013 - page #4
 
10th apchg 2nd ann (13 august)
10th apchg 2nd ann (13 august)10th apchg 2nd ann (13 august)
10th apchg 2nd ann (13 august)
 
Haemostasis workshop final announcement
Haemostasis workshop final announcementHaemostasis workshop final announcement
Haemostasis workshop final announcement
 
Haemostasis workshop final announcement
Haemostasis workshop final announcementHaemostasis workshop final announcement
Haemostasis workshop final announcement
 
Introductory bioinformatics workshop flyer
Introductory bioinformatics workshop flyerIntroductory bioinformatics workshop flyer
Introductory bioinformatics workshop flyer
 
AFH 2012 flyer
AFH 2012 flyerAFH 2012 flyer
AFH 2012 flyer
 
Annualreport2012
Annualreport2012Annualreport2012
Annualreport2012
 
Agmmins2011
Agmmins2011Agmmins2011
Agmmins2011
 
Taknak 1care forum sitiawan
Taknak 1care forum sitiawanTaknak 1care forum sitiawan
Taknak 1care forum sitiawan
 
1 Care Concept Caper
1 Care Concept Caper 1 Care Concept Caper
1 Care Concept Caper
 
Healthcare forum on 1Care
Healthcare forum on 1CareHealthcare forum on 1Care
Healthcare forum on 1Care
 

Dernier

Russian Call Girls in Jaipur Riya WhatsApp ❤8445551418 VIP Call Girls Jaipur
Russian Call Girls in Jaipur Riya WhatsApp ❤8445551418 VIP Call Girls JaipurRussian Call Girls in Jaipur Riya WhatsApp ❤8445551418 VIP Call Girls Jaipur
Russian Call Girls in Jaipur Riya WhatsApp ❤8445551418 VIP Call Girls Jaipurparulsinha
 
The Most Attractive Hyderabad Call Girls Kothapet 𖠋 6297143586 𖠋 Will You Mis...
The Most Attractive Hyderabad Call Girls Kothapet 𖠋 6297143586 𖠋 Will You Mis...The Most Attractive Hyderabad Call Girls Kothapet 𖠋 6297143586 𖠋 Will You Mis...
The Most Attractive Hyderabad Call Girls Kothapet 𖠋 6297143586 𖠋 Will You Mis...chandars293
 
Call Girls Bareilly Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Bareilly Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Bareilly Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Bareilly Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
VIP Mumbai Call Girls Hiranandani Gardens Just Call 9920874524 with A/C Room ...
VIP Mumbai Call Girls Hiranandani Gardens Just Call 9920874524 with A/C Room ...VIP Mumbai Call Girls Hiranandani Gardens Just Call 9920874524 with A/C Room ...
VIP Mumbai Call Girls Hiranandani Gardens Just Call 9920874524 with A/C Room ...Garima Khatri
 
Call Girls Coimbatore Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Coimbatore Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Coimbatore Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Coimbatore Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Call Girls Service Surat Samaira ❤️🍑 8250192130 👄 Independent Escort Service ...
Call Girls Service Surat Samaira ❤️🍑 8250192130 👄 Independent Escort Service ...Call Girls Service Surat Samaira ❤️🍑 8250192130 👄 Independent Escort Service ...
Call Girls Service Surat Samaira ❤️🍑 8250192130 👄 Independent Escort Service ...CALL GIRLS
 
Call Girls Aurangabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Aurangabad Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Aurangabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Aurangabad Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Call Girls Bangalore Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Bangalore Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Bangalore Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Bangalore Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
VIP Service Call Girls Sindhi Colony 📳 7877925207 For 18+ VIP Call Girl At Th...
VIP Service Call Girls Sindhi Colony 📳 7877925207 For 18+ VIP Call Girl At Th...VIP Service Call Girls Sindhi Colony 📳 7877925207 For 18+ VIP Call Girl At Th...
VIP Service Call Girls Sindhi Colony 📳 7877925207 For 18+ VIP Call Girl At Th...jageshsingh5554
 
Call Girls Dehradun Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Dehradun Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Dehradun Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Dehradun Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Call Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Low Rate Call Girls Kochi Anika 8250192130 Independent Escort Service Kochi
Low Rate Call Girls Kochi Anika 8250192130 Independent Escort Service KochiLow Rate Call Girls Kochi Anika 8250192130 Independent Escort Service Kochi
Low Rate Call Girls Kochi Anika 8250192130 Independent Escort Service KochiSuhani Kapoor
 
Top Rated Bangalore Call Girls Mg Road ⟟ 8250192130 ⟟ Call Me For Genuine Sex...
Top Rated Bangalore Call Girls Mg Road ⟟ 8250192130 ⟟ Call Me For Genuine Sex...Top Rated Bangalore Call Girls Mg Road ⟟ 8250192130 ⟟ Call Me For Genuine Sex...
Top Rated Bangalore Call Girls Mg Road ⟟ 8250192130 ⟟ Call Me For Genuine Sex...narwatsonia7
 
Chandrapur Call girls 8617370543 Provides all area service COD available
Chandrapur Call girls 8617370543 Provides all area service COD availableChandrapur Call girls 8617370543 Provides all area service COD available
Chandrapur Call girls 8617370543 Provides all area service COD availableDipal Arora
 
Vip Call Girls Anna Salai Chennai 👉 8250192130 ❣️💯 Top Class Girls Available
Vip Call Girls Anna Salai Chennai 👉 8250192130 ❣️💯 Top Class Girls AvailableVip Call Girls Anna Salai Chennai 👉 8250192130 ❣️💯 Top Class Girls Available
Vip Call Girls Anna Salai Chennai 👉 8250192130 ❣️💯 Top Class Girls AvailableNehru place Escorts
 
Russian Escorts Girls Nehru Place ZINATHI 🔝9711199012 ☪ 24/7 Call Girls Delhi
Russian Escorts Girls  Nehru Place ZINATHI 🔝9711199012 ☪ 24/7 Call Girls DelhiRussian Escorts Girls  Nehru Place ZINATHI 🔝9711199012 ☪ 24/7 Call Girls Delhi
Russian Escorts Girls Nehru Place ZINATHI 🔝9711199012 ☪ 24/7 Call Girls DelhiAlinaDevecerski
 
Call Girls Cuttack Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Cuttack Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Cuttack Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Cuttack Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
VIP Call Girls Indore Kirti 💚😋 9256729539 🚀 Indore Escorts
VIP Call Girls Indore Kirti 💚😋  9256729539 🚀 Indore EscortsVIP Call Girls Indore Kirti 💚😋  9256729539 🚀 Indore Escorts
VIP Call Girls Indore Kirti 💚😋 9256729539 🚀 Indore Escortsaditipandeya
 
Best Rate (Hyderabad) Call Girls Jahanuma ⟟ 8250192130 ⟟ High Class Call Girl...
Best Rate (Hyderabad) Call Girls Jahanuma ⟟ 8250192130 ⟟ High Class Call Girl...Best Rate (Hyderabad) Call Girls Jahanuma ⟟ 8250192130 ⟟ High Class Call Girl...
Best Rate (Hyderabad) Call Girls Jahanuma ⟟ 8250192130 ⟟ High Class Call Girl...astropune
 
Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...Dipal Arora
 

Dernier (20)

Russian Call Girls in Jaipur Riya WhatsApp ❤8445551418 VIP Call Girls Jaipur
Russian Call Girls in Jaipur Riya WhatsApp ❤8445551418 VIP Call Girls JaipurRussian Call Girls in Jaipur Riya WhatsApp ❤8445551418 VIP Call Girls Jaipur
Russian Call Girls in Jaipur Riya WhatsApp ❤8445551418 VIP Call Girls Jaipur
 
The Most Attractive Hyderabad Call Girls Kothapet 𖠋 6297143586 𖠋 Will You Mis...
The Most Attractive Hyderabad Call Girls Kothapet 𖠋 6297143586 𖠋 Will You Mis...The Most Attractive Hyderabad Call Girls Kothapet 𖠋 6297143586 𖠋 Will You Mis...
The Most Attractive Hyderabad Call Girls Kothapet 𖠋 6297143586 𖠋 Will You Mis...
 
Call Girls Bareilly Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Bareilly Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Bareilly Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Bareilly Just Call 9907093804 Top Class Call Girl Service Available
 
VIP Mumbai Call Girls Hiranandani Gardens Just Call 9920874524 with A/C Room ...
VIP Mumbai Call Girls Hiranandani Gardens Just Call 9920874524 with A/C Room ...VIP Mumbai Call Girls Hiranandani Gardens Just Call 9920874524 with A/C Room ...
VIP Mumbai Call Girls Hiranandani Gardens Just Call 9920874524 with A/C Room ...
 
Call Girls Coimbatore Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Coimbatore Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Coimbatore Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Coimbatore Just Call 9907093804 Top Class Call Girl Service Available
 
Call Girls Service Surat Samaira ❤️🍑 8250192130 👄 Independent Escort Service ...
Call Girls Service Surat Samaira ❤️🍑 8250192130 👄 Independent Escort Service ...Call Girls Service Surat Samaira ❤️🍑 8250192130 👄 Independent Escort Service ...
Call Girls Service Surat Samaira ❤️🍑 8250192130 👄 Independent Escort Service ...
 
Call Girls Aurangabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Aurangabad Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Aurangabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Aurangabad Just Call 9907093804 Top Class Call Girl Service Available
 
Call Girls Bangalore Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Bangalore Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Bangalore Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Bangalore Just Call 9907093804 Top Class Call Girl Service Available
 
VIP Service Call Girls Sindhi Colony 📳 7877925207 For 18+ VIP Call Girl At Th...
VIP Service Call Girls Sindhi Colony 📳 7877925207 For 18+ VIP Call Girl At Th...VIP Service Call Girls Sindhi Colony 📳 7877925207 For 18+ VIP Call Girl At Th...
VIP Service Call Girls Sindhi Colony 📳 7877925207 For 18+ VIP Call Girl At Th...
 
Call Girls Dehradun Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Dehradun Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Dehradun Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Dehradun Just Call 9907093804 Top Class Call Girl Service Available
 
Call Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service Available
 
Low Rate Call Girls Kochi Anika 8250192130 Independent Escort Service Kochi
Low Rate Call Girls Kochi Anika 8250192130 Independent Escort Service KochiLow Rate Call Girls Kochi Anika 8250192130 Independent Escort Service Kochi
Low Rate Call Girls Kochi Anika 8250192130 Independent Escort Service Kochi
 
Top Rated Bangalore Call Girls Mg Road ⟟ 8250192130 ⟟ Call Me For Genuine Sex...
Top Rated Bangalore Call Girls Mg Road ⟟ 8250192130 ⟟ Call Me For Genuine Sex...Top Rated Bangalore Call Girls Mg Road ⟟ 8250192130 ⟟ Call Me For Genuine Sex...
Top Rated Bangalore Call Girls Mg Road ⟟ 8250192130 ⟟ Call Me For Genuine Sex...
 
Chandrapur Call girls 8617370543 Provides all area service COD available
Chandrapur Call girls 8617370543 Provides all area service COD availableChandrapur Call girls 8617370543 Provides all area service COD available
Chandrapur Call girls 8617370543 Provides all area service COD available
 
Vip Call Girls Anna Salai Chennai 👉 8250192130 ❣️💯 Top Class Girls Available
Vip Call Girls Anna Salai Chennai 👉 8250192130 ❣️💯 Top Class Girls AvailableVip Call Girls Anna Salai Chennai 👉 8250192130 ❣️💯 Top Class Girls Available
Vip Call Girls Anna Salai Chennai 👉 8250192130 ❣️💯 Top Class Girls Available
 
Russian Escorts Girls Nehru Place ZINATHI 🔝9711199012 ☪ 24/7 Call Girls Delhi
Russian Escorts Girls  Nehru Place ZINATHI 🔝9711199012 ☪ 24/7 Call Girls DelhiRussian Escorts Girls  Nehru Place ZINATHI 🔝9711199012 ☪ 24/7 Call Girls Delhi
Russian Escorts Girls Nehru Place ZINATHI 🔝9711199012 ☪ 24/7 Call Girls Delhi
 
Call Girls Cuttack Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Cuttack Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Cuttack Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Cuttack Just Call 9907093804 Top Class Call Girl Service Available
 
VIP Call Girls Indore Kirti 💚😋 9256729539 🚀 Indore Escorts
VIP Call Girls Indore Kirti 💚😋  9256729539 🚀 Indore EscortsVIP Call Girls Indore Kirti 💚😋  9256729539 🚀 Indore Escorts
VIP Call Girls Indore Kirti 💚😋 9256729539 🚀 Indore Escorts
 
Best Rate (Hyderabad) Call Girls Jahanuma ⟟ 8250192130 ⟟ High Class Call Girl...
Best Rate (Hyderabad) Call Girls Jahanuma ⟟ 8250192130 ⟟ High Class Call Girl...Best Rate (Hyderabad) Call Girls Jahanuma ⟟ 8250192130 ⟟ High Class Call Girl...
Best Rate (Hyderabad) Call Girls Jahanuma ⟟ 8250192130 ⟟ High Class Call Girl...
 
Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...
 

Personal Data Protection Act 2010 Summary

  • 1. 1
  • 3. 3 Personal Data Protection Act 2010 • Passed on 10 June 2010 • The Minister has appointed a Director General & created a PDP Dept • Once the PDPA comes into force the DG may assume the role of Data Protection Commissioner • Once the PDPA is brought into force - Data Users have 3 months to comply
  • 4. 4 Minister of Information Communication and Culture Appeal Mechanism Personal Data Protection Commissioner Data User Forum Advisory Committee Data User
  • 5. 5 Growth of computer networks & internet – Huge impact on society • Over the last 3 decades computer networks have made pervasive inroads in our everyday lives, both in business as well as the home • The internet came along and connected the world • Computer networks enabled efficient collection, manipulation and storage of data – and vast quantities of it too • Data can be stored anywhere in the world – not necessarily where it is collected • Gigabytes of personal data are accessed and used on daily basis • New threats affecting privacy and data protection (identity theft, facebook, twitter, friendster, etc)
  • 6. 6 Has your Personal Data been abused lately? • How many marketing sms’s do you receive in a day? • Has a bank offered you a pre-approved loan lately? • Does your telco send you “I love you” mms’s without your consent? • Did you get a season’s greeting from the Prime Minister lately? • Did you get an email telling you that you have won USD5 million in a European lottery? None of these activities may have had your consent
  • 7. 7 What is Personal data • Personal Data (PD) means any information which relates directly or indirectly to a data subject, who is identified or identifiable from that information  Examples : Name, Address, Photographs, IC, Bank Account details, Medical Records / History Some Definitions Data Subject (DS) – an individual who is the subject of the PD – includes patients and employees Data User (DU) – a person who processed any PD or has control over or authorizes the processing of any PD but does not include a data processor
  • 8. 8 Processing is defined widely • Processing – means collecting, recording, holding, storing and carrying out of operations with that data like organizations, adaptation, retrieval, use, disclosure, transmission, transfer, correction, erasure & destruction Collection Use Disclosure Destruction
  • 9. 9 Application of the PDPA • The act applies to : (a) personal data which is processed; (b) any person who processes and any person who has control over or authorizes the processing of any personal data in respect of commercial transactions and such a person is a “data user”; Commercial transactions – “... of a commercial nature, whether contractual or not, which includes any matters relating to the supply or exchange of goods or services, agency, investments, financing, banking and insurance, but does not include a credit reporting business carried out by a credit reporting agency under the Credit Reporting Agencies Act 2010”.
  • 10. 10 Personal Data Flow - patient HRM Discharge/Payment •HIS Patient Registration (demographics ) HRM PATIENT Clinical Information at Clinic Procedures •HIS •LIS •OIS 10 HRM HRM Clinical Information at Wards HRM
  • 11. 11 The PDPA – Who Does it NOT Apply To? • The PDPA does not apply to : The Federal Government The State Government  PD processed outside Malaysia UNLESS intended to be further processed in Malaysia
  • 12. 12 Healthcare Sector in Malaysia Current Position Pre PDPA 2010
  • 13. 13 Current Regulatory Position – Piecemeal Approach to Data Protection Private Healthcare & Services Act MMC Guide on Confidentiality Medical Act MMC Guide on Medical Records and Medical Reports MMA Code on Medical Ethics Patient’s Charter MMC Code of Professional Conduct
  • 14. 14 Pre-PDPA – How Personal Data was dealt with • PHFSA – hospitals must have a policy on Patients rights: Information concerning medical treatment and care; Be provided with patient’s medical report within a reasonable time • Reg 30 – patient’s MR is the property of Hospital . Patient has a right to request for medical report • Retention of MR is for the Limitation Period • Doctors have right of access to MR of old patients to defend civil actions
  • 15. 15 MMC Guidelines on Doctors • On medical records and reports Medical records belong to the hospital Information in MR belong morally and ethically to the patient  Doctors have obligation to provide comprehensive medical reports upon request by patient (for 2nd opinion, litigation etc) • Doctor patient confidentially No disclosure to 3rd parties without consent of patient Should not reveal patient PD in medical publications Drs must exert all powers to preserve patient confidentiality
  • 16. 16 MMC Guidelines for Doctors – Disclosure to 3rd Parties • Disclosure within Medical Teams Drs must obtain consent of Patient to share PD with other doctors Patient can refuse consent for sharing of PD between doctors • Disclosure to Employers, Insurers Dr must inform Patient and obtain consent before disclosure to these parties • Disclosure for Medical Teaching and medical audit Should anonymise PD as far as possible Doctors who decide to disclose PD must be prepared to explain and justify their decision (MMC Guideline)
  • 18. The 7 Data Protection Principles Under the PDPA General principle Notice & Choice Principle Access Principle PDPA Data Integrity Principle Disclosure Principle Retention Principle Security Principle 18
  • 19. 19 No PDP Principles What it covers 1 General Principle Consent of DS is required to process PD. For Sensitive Personal Data – explicit consent is required 2 Notice & Choice Principle DU give Notice to DS of the processing, description of PD, purpose, source of info and right to request access, 3P to whom DU discloses, how to limit the processing, whether it is obligatory or voluntary to supply PD 3 Disclosure Principle No disclosure of PD without consent of DS 4 Security Principle DU must take practical steps to protect PD (IT System & Internal processes) 5 Retention Principle PD should not be kept longer than necessary – must destroy after purpose is met 6 Data Integrity Principle DU must ensure Data processed is accurate, complete and upto-date having regard to the purpose of collection 7 Access Principle DS must have access and be able to correct if inaccurate
  • 20. 20 1. General Principle - consent • A data user cannot process any PD about a Data Subject unless the Data Subject has given his consent. • Consent can be expressed or implied • PD cannot be processed unless :  PD is processed for a lawful purpose directly related to the activity of the Data User The processing of PD is necessary for or directly related to that purpose Directly related to that purpose means the reason that the PD was collected. Eg: a person comes for a blood test and his consent is acquired to conduct all the necessary test. However, the consent shall not extend to the publication of his blood test results in a medical article. PD is adequate but not excessive in relation to that purpose Eg: a patients comes to ER to see the doctor for fever medication. It is not necessary to ask the patient of his grandparents, aunt, uncle’s names, IC, add etc. Distinction between consent for medical purpose and other purpose
  • 21. 21
  • 22. 22 2. Notice & Choice Principle • A DS is required to give written consent to DU: That PD is being processed and provide a description of the PD being processed The purposes for which the PD is collected and processed  DS’s right to request access to and request correction of the PD Disclosure to any 3rd parties that may be made
  • 23. 23 3. Disclosure principle • No Personal Data shall be disclosed without the consent of the DS: For any other purpose other than the original purpose as disclosed to the DS at the time of collection A purpose directly related to the purpose above To any party other than a 3rd party already notified to the DS (under Notice Principle) • Disclosure for the purpose of research, discussions in medical meetings / seminars :This disclosure is allowed as long as the data that is being disclosed cannot be related to a particular person • Note: Disclosure to the Ministry of Health – this is a compulsory disclosure and thus shall be exempted.
  • 24. 24 Case note - disclosure Improper disclosure of SPD to Government Agency The complainant had medical tests at a pathology clinic and asked that the results be provided only to their treating medical specialist and solicitor. The tests results were to be part of a claim that the complainant was making to a federal government agency. The complainant later became aware that the clinic had provided the results directly to that government agency. DS complained to the Data Commissioner The clinic advised the clinic staff to send directly to the government agency noted on the complainant’s form. The clinic contended that this was an isolated error. As this information was disclosed for a purpose other than the primary purpose for which it was collected. The commissioner formed the view that the disclosure was an interference with the complainant’s privacy. The clinic paid compensation to the DS.
  • 25. 25 The security principle need to be adequate but it shouldn’t be unreasonable.
  • 26. 26 4. Security Principle • DU shall take practical steps to protect PD from any Loss, misuse, modification Unauthorized or accidental access or disclosure Alteration or destruction Having regard to location, IT systems and mode of transfer of PD • Hospital IT systems such as the HMIS, HIS and LIS need strict policies • Transfer to 3rd party service providers such as outside lab and transfers of PD overseas Security issues : use of portable devices (laptops, USB, External hard drive, CD, DVD) Transmission of patient info via fax Medical devices storage function Remote access to MR Doctors have to comply with Hospital’s policies regarding PDPA requirements
  • 27. 27
  • 28. 28 Sony fined GBP 250,000 for Breach of Security • A cyber attack on the SONY’s PlayStation Network in April 2011 put a huge number of consumers at risk of identity theft including credit card details • It could have been prevented if Sony’s software was up-to-date and technical developments hadn’t made passwords unsecure • “There’s no disguising that this is a business that should have known better,” said the ICO’s data protection director David Smith • It is a company that trades on its technical expertise and there is no doubt in my mind that they had access to both the technical expertise and the resources to keep this information safe.
  • 29. 29 Data Processor • Where PD is processed on behalf of DU the DU shall ensure that the Data Processor :  Provides guarantees in respect of technical and security measures governing the processing; and  Takes reasonable steps to ensure compliance with those measures  Eg: The IT system in SDMC PC – system designed for SDH and they do have access to our patient records. Data Processor = Outsourced Service Providers
  • 31. 31 Retention Principle • PD shall not be kept longer than is necessary for the fulfillment of the original purpose • DU has duty to take all reasonable steps to ensure that PD is : • Destroyed (must be done in a proper manner); or • Permanently deleted …… if it is no longer required for the purpose for which it was processed QUESTION : how long is long?  Depends on the nature of your business and the commercial reasons to keep data  7 years / 25 years / hospital policy
  • 32. 32
  • 33. 33 6. Data Integrity Principle
  • 34. 34 Data Integrity Principle • DU has duty to take all reasonable steps to ensure that PD is : • Accurate • Complete • Not misleading; and • Kept up to date
  • 35. 35 7. Access Principle • A data subject shall be given access to his personal data upon Data Access Request • All information that is being processed by or on behalf of the Data User • Entitled to an intelligible copy of the PD • Access can be just to view or get a copy • Subject to some exceptions Under the PDPA, patient may now get access to his entire MR
  • 36. 36 Case note Who can access PD Hospital prepared a health report for an insurance company Patient wanted a copy under access principle Hospital refused DC held that all PD held by the hospital, including report should be provided to the data subject Regardless for whom it was prepared
  • 37. 37
  • 38. 38 GE Healthcare Admits Sending NHS Patient Data to US • Personal details of 600,000 patients were sent to the US following a mistake made by the NHS’s IT provider, GE Healthcare • GE Healthcare admitted that the error had occurred after it had obtained more patient data than it needed, but stressed that there was no need to worry • Overloaded in PD • GE Healthcare recently discovered that they obtained more patient data from diagnostic imaging products than they needed to perform services to their customers
  • 39. 39 NHS Trust fined 325,000 for data breach • Brighton and Sussex University Hospital NHS Trust has been fined 400,000 euros following a serious breach of the UK Data Protection Act • Highly sensitive personal data belonging to tens of thousands of patients and staff, including some relating to HIV and Genito Urinary Medicine patients, on hard drives sold on an Internet auction site in October and November 2010 • The Data breach occurred when an individual engaged by the Trust’s IT service provider, was tasked to destroy approximately 1000 hard drives • The individual sold 4 hard drives on an internet auction in December 2010
  • 40. 40 Offences and Penalties • If a body corporate commits an offence under the PDPA, any person who at the time of the offence was a director, CEO, COO, Manager etc may be charged jointly or severally with the company • Liability also is attached to Senior Management for acts or omissions of any employee acting in the course of their employment. • Section 5 (1) Anyone who contravenes the Personal Data Protection Principles commits and offence and shall, on conviction, be liable to a fine not exceeding RM300,000 or to imprisonment for a term not exceeding 2 years or to both  Penalties for other offences ranges from RM100k to RM500k with imprisonment ranging from 1 – 3 years  Eg. For unlawful collection or selling of PD – 500k and 3 years