PERSONAL DATA PROTECTION ACT

PERSONAL DATA PROTECTION ACT 2010 NOTICE AND CONSENT
(PERSONAL DATA NOTICE AND CONSENT)

Kedah Medical Centre (KMC) is subject to the personal data protection principles under the Personal Data Protection Act 2010 (hereafter referred to as PDPA) with effect from 15 November 2013, which regulates the processing of personal data in commercial transactions. The terms “personal data”, “processing” and “commercial transactions” shall have the meaning provided in the PDPA.

It is obligatory that you supply us with your personal data. If you fail to supply us with such personal data, we may not be able to process and/or disclose your data for the purposes as provided in item C) below.

This Personal Data Notice and Consent applies to any person whose personal data is being processed by Kedah Medical Centre (KMC).

We wish to inform you how your personal data is being processed by and on behalf of Kedah Medical Centre (KMC).

  1. Source of the Personal Data
    Your personal data is collected from various sources, including information you have provided us, information from third parties and information in the public domain.
  2. Description of the Personal Data
    Your personal data processed by us may include, where relevant:- name, date of birth, identity card or passport, name of employer/company, home and office address, telephone/handphone number, faximile number, email address, occupation, age, gender, marital status, weight, height, photos, race, nationality, religion, family and/or next of kin information, medical checkup result, medical record, Medical Report No. (MRN), medical report, diagnosis, personal health information, criminal history, investigation results, insurance details and any other personal data required for the purposes set out in item (C) below.
  3. Purposes of the Personal Data
    Your personal data may be processed for the following purposes, where relevant:
    • for medical and healthcare services, to facilitate the patients personal needs i.e. extension of stay for health tourists,
    • to establish and manage medical records and medical reports,
    • to facilitate payment process relating to the patients,
    • to institute debt recovery proceedings against defaulters,
    • to report the personal data to the relevant authorities and/or third parties under the governing laws relevant to the healthcare industry,
    • to share the personal data with KPJ Healthcare Berhad and its related companies as defined in the Companies Act 1965,
    • to conduct research, analysis and improvement,
    • to market and advertise products and services,
    • to administer and respond to request, queries, complaints and legal issues,
    • for education and training and
    • for any other purpose that is incidental or in furtherance to the above purposes.
  4. Disclosure of the Personal Data
    Your personal data may be disclosed to the following parties,where relevant:
    Healthcare professional (as defined in PDPA), KPJ Healthcare Berhad and its related companies (as defined under CA 1965), Government agencies, Local authorities, non government agencies, Paying and insurance agent, Debt collection authorities and agencies, Financial institutions, Legal firms, Auditors, Vendor/Contractor, Other private and public hospitals, Other Healthcare providers, Training provider, Family and next of kin, to such parties as may be required by law, court, regulator or legal process to disclose, to such parties as may be permitted under the laws of Malaysia and any other person which Kedah Medical Centre (KMC) may deem necessary.
  5. Access and Update the Personal Data
    We shall do our best to ensure that the personal data we hold about you is accurate, complete, not misleading and up-to-date. If there are any changes to your personal data or if you believe that the personal data we have about you is inaccurate, incomplete, misleading or not up-to-date, please contact us so that we may take steps to update your personal data.
    You have the right to access your personal data. If you would like to request access to your personal data, please contact us. We recommend that your request for access to your personal data held by Kedah Medical Centre (KMC) be made in writing. We may also take steps to verify your identity before fulfilling your request for access to your personal data.
    In accordance with the PDPA:
    1. Depending on the information requested, we may charge a fee as stipulated in the First Schedule (Regulation 2) of Personal Data Protection [Fees] Regulations 2013 for processing your request for access; and
    2. We may refuse to comply with your request to access or make a correction in accordance with PDPA.