IHH Singapore Personal Data Protection Notice (also known as “Privacy Policy”)
- Introduction
- This Personal Data Protection Notice (“Notice”) is published on 1 July 2024 (“Effective Date”).
- IHH Healthcare Singapore1 (“we”, “our”, “us”) is committed to protecting Individuals'2 (“your”, “you” and “yours”) personal data responsibly and in compliance with applicable data protection related laws. Where personal data is processed in Singapore, only the Singapore Personal Data Protection Act 2012 (“PDPA”) shall apply.
- This Notice applies to the Processing3 of your personal data by us. It explains how we Process your personal data when you interact with us.
- This Notice may be updated from time to time, with amendments to the PDPA or to provide you with additional information. We strongly encourage you to read this Notice.
- Personal Data
- For purposes of this Notice, Personal Data means any information or combination of information, relating, directly or indirectly to you.
- Depending on the nature of your interaction with us, the Personal Data we collect may include your personal identification information, health and medical information, account and profile information, network traffic and related data and/or any other information which have been provided to us or we may have access to, in the course of your interaction with us.
- For more details on Personal Data which may be collected, please refer to Appendix 1.
- Personal Data of Vulnerable Persons4:
- It is, our intention and policy to comply with law when it requires parent, guardian or legal representative’s permission before collecting, using or disclosing Personal Data of Vulnerable Persons.
- If a parent, guardian or legal representative becomes aware that Personal Data of a child or ward has been provided by that child or ward without the consent of the relevant parent, guardian or legal representative, please contact us (contact details provided below). Such Personal Data will be disposed of from our records.
- How do we collect Personal Data?
During our interactions with you, we may obtain Personal Data about you to fulfill a statutory or contractual requirement, or is required to perform or enter into a contract with you. In this case, you are obliged to provide your Personal Data. If you do not provide your Personal Data to us, we may not be able to accomplish some of the purposes outlined in this Notice.
In other cases, decision to provide us your Personal Data may be optional.
We collect Personal Data from you in the following ways:
- directly:
- when you create an account, register with us and/or submit any form to us or benefit from our services;
- when you disclose Personal Data in face-to-face meetings, telephone conversations, emails and/or over any registration, communication or messaging platforms with our teams;
- when you sign up for our marketing and promotional communications and/or any initiatives;
- when you interact, communicate with us and/or leave comments on our websites, mobile applications or social media platforms;
- when you enter into an agreement, partnership, collaboration and/or provide any other documentation or information in respect of your interactions, engagement and/or relationship with us;
- when you visit and/or are within our premises and your images are captured by us via CCTV cameras, photographs or videos taken by us or our representatives, agents, services providers or affiliates when you attend any of our events;
- when you submit application for employment, internship, attachment, education or accreditation;
- when you make available your Personal Data to us for any other reason;
- indirectly:
- when we seek and receive your Personal Data in connection with your interaction, engagement and/or relationship with us (including, but not limited to, for our products and services or work, education and accreditation applications) from other data sources;
- when we receive your Personal Data from other medical service providers (whether related or third party);
- when we receive your Personal Data from third parties who wish to seek to confer a benefit on you (e.g., your employer or insurer);
- if you act as an intermediary or are supplying us with Personal Data and information relating to a third-party/other individual (such as a Relative4, friend, colleague, patient, employee, etc.), you undertake that you have obtained all necessary consents from such third-party/other individual for Processing of their Personal Data by us;
- as we are collecting third-party/other individual's Personal Data from you, you undertake to make such third-party/other individual aware of all matters listed in this Notice by referring them to our website or informing them of the contents of this Notice; and/or
- any other information which we may collect from other sources.
- directly:
- Ensuring accuracy of Personal Data
- We strive to maintain Personal Data in a manner that is accurate, complete and up-to-date. The Personal Data you provide to us must be accurate, complete and up-to-date, and you must inform us of any significant changes to such Personal Data provided by you.
- Furthermore, if you act as an intermediary or are supplying us with Personal Data and information relating to a third-party/other individual, please note that you need to ensure that such Personal Data is collected in compliance with the PDPA. For example, you should inform such third-party/other individual about the contents of this Notice.
- For which purpose is Personal Data collected, use, disclosed or processed?
Personal Data may be collected, used, transferred or otherwise Processed for one or more of the following purposes:
- Provision of medical services purposes: For Processing necessary to provide you medical treatment and other reasonably related purposes.
- Business Purposes: These are legitimate purposes as appropriate to conduct our business. These include Processing necessary for the performance of contractual obligations, invoicing, billing and account management of Individuals, customer service and support, finance and accounting, research and development, internal management and control, and any other reasonably related activities.
- Human resources and personnel management: This includes Processing necessary for the performance of an employment or other contract with an employee (or to take necessary steps at the request of an employee prior to entering into a contract), or for managing the employment-at-will relationship.
- Health, safety and security: For Processing necessary to ensure occupational safety and health, the protection of our assets, your verification and your access rights and its status;
- Compliance with legal and regulatory obligations: For Processing necessary for compliance with a legal or regulatory obligation to which we are subject;
- Vital interests: For Processing necessary to protect your vital interests, for instance, situations that require us to protect your life or you from harm;
- Marketing and Promotion: We may, when Processing Personal Data for marketing communications and/or promotions, either:
- obtain your consent; and/or
- offer you opportunity to not proceed with the processing and/or to choose not to receive such communications.
If you wish to withdraw consent to receive such materials, please contact us (contact details provided below).
- Secondary Purposes: Processing of Personal Data (including previously collected data) for secondary purposes such as:
- transferring the Personal Data to an archive;
- conducting internal audits or investigations;
- implementing business controls;
- conducting statistical, historical or scientific research as required for our business operations;
- preparing or engaging in dispute resolution;
- using legal or business consulting services;
- managing insurance or other benefits related issues; and/or
- creating de-identified, aggregated and/or anonymised data from Personal Data from which you would not be identifiable, through removal of identifiable components, obfuscation, pseudonymisation, anonymisation, or any other means for purposes including, but not limited to (a) enhancing security; and/or (b) for further processing, aggregation, analysis (of the anonymised data that no longer contains your Personal Data only), for optimisation of patient care and improvement of healthcare services, products and research and developments which may include transferring such anonymised data to our affiliates and business partners in Singapore or abroad, for such purposes.
- Any other reasonably related purposes.
- For more details on purposes for which Personal Data is Processed, please refer to Appendix 2.
- Exceptions: Some of our obligations under this Notice may be overridden if, under the specific circumstances at issue, a pressing legitimate need exists that outweighs your interest. Such a situation exists if there is a need to:
- protect our Business Interests including:
- the health, security or safety of individuals;
- our intellectual property rights, trade secrets or reputation;
- the continuity of our business operations;
- the preservation of confidentiality in a proposed sale;
- merger or acquisition of a business;
- the involvement of authorised advisors or consultants for business, legal, tax, or insurance purposes.
- prevent or investigate suspected or actual violations of
- law (including cooperating with law enforcement);
- contracts; and/or
- our policies.
- otherwise protect or defend us, our personnel’s or other individual’s rights or freedoms
- protect our Business Interests including:
- Automated decision-making
- Automated tools may be used by us to Process your Personal Data and/or make decisions about you. Some extent of human intervention may be involved in the automated decision-making.
- Where permissible under law, we may undertake automated decision-making if:
- the decision is made by us for purposes of entering or performing a contract provided that the underlying request leading to a decision by us was made by you;
- you have provided explicit consent; and/or
- the use of automated tools is otherwise required.
- Sharing your Personal Data with others
- Your Personal Data may be shared with our employees, representatives and/or affiliates.
- Access to Personal Data, will be limited to those who have a need to know the information for the purposes described in this Notice.
- From time to time, we may need to share your Personal Data with external parties, which may include the following:
- service providers, vendors, suppliers: we contract with authorised external parties or companies that provide products and services to us necessary for our operations
- business and collaboration partners: we work with accredited doctors and specialists including, but not limited to, their clinic personnel and administrators, our corporate clients and/or partners (and their appointed service providers and/or customers), education and research institutes;
- public and governmental authorities: when required by law, or as necessary to protect our rights, we may share your Personal Data to public and governmental authorities that regulate or have jurisdiction over us;
- professional advisors and others: we work with and receive support from certain professional advisors such as banks, insurance companies, auditors, lawyers, accountants, and payroll advisors, consultants; and/or
- other parties in connection with corporate transactions: we may also, from time to time, share your Personal Data in the course of corporate transactions, such as during a sale of a business or a part of a business to another company, or any reorganisation, merger, joint venture, or other disposition of our business, assets, or stock.
- As appropriate, we will contractually protect and safeguard your interests at a similar level of protection as provided by us.
- Cross-border transfer of Personal Data
- Due to our international presence, your Personal Data may be accessed by or transferred to our affiliates and/or authorised external parties from various countries around the world in order for us fulfil the purposes described in this Notice.
- As a result, we may transfer your Personal Data to jurisdictions located outside of Singapore, which may have data protection related laws and rules that are different from the standards provided under the PDPA.
- Personal Data may be transferred to an authorised external party, located internationally only if, we believe it is necessary or appropriate to:
- ensure compliance with applicable data protection related laws which may include responding to requests from public and government authorities, cooperation with law enforcement agencies or other legal reasons; and/or
- satisfy purposes for which Personal Data has been collected by us or to enforce our terms and conditions.
- When do we retain your Personal Data?
- We keep your Personal Data as long as we need to fulfil the purposes for which it has been collected. We retain Personal Data only:
- for the period required to serve applicable Business Purpose;
- to the extent necessary to comply with an applicable legal and/or regulatory requirement; and/or
- as advised by Singapore laws.
- Promptly after applicable retention period has ended, your Personal Data will be appropriately:
- disposed; and/or
- de-identified
- We keep your Personal Data as long as we need to fulfil the purposes for which it has been collected. We retain Personal Data only:
- How do we protect your Personal Data?
- We are committed to maintaining the security of the Personal Data processed and restrict the Processing of Personal Data to those data/information that are reasonable, adequate for, and/or relevant to the purposes described under this Notice.
- To protect your Personal Data, we take appropriate measures, and we also require external parties to whom we disclose your Personal Data to, to protect the confidentiality and security of your Personal Data. Depending on the state of the art, the costs of implementation and the nature of the data/information to be protected, we have put in place physical, technical and organisational measures to prevent risks such as unauthorised access, collection, use, disclosure, copying, modification, disposal or loss.
- If you have any reason to believe that your interaction with us is no longer secure, please contact us (contact details provided below).
- How can you contact us for choices available to you?
- With respect to Processing of your Personal Data, upon successful verification of your identity, you may:
- obtain information on the Processing of your Personal Data over the past one year, subject to applicable fee(s) related to the costs of processing your access request;
- request to update or correct your Personal Data, provided we are satisfied on reasonable grounds that such a correction should be made; and/or
- withdraw your consent to use of your Personal Data. Please note that your request may affect the products and services we are able to offer to you;
- If you have any inquiries, requests, feedback or complaints in relation to protecting your Personal Data, please contact the Data Protection Office via the following channels:
- Call: +65 6307 7880
- Email: [email protected]
- Written communication mailed to: Data Protection Officer, IHH Healthcare Singapore, 1 HarbourFront Place, #03-02 HarbourFront Tower One, Singapore 098633.
- We will do our best to respond to you within a reasonable time and no longer than 30 days from the date we receive your inquiry, request, feedback or complaint.
- With respect to Processing of your Personal Data, upon successful verification of your identity, you may:
- Updates to Notice
- We may revise this Notice from time to time. Any changes will become effective as on the Effective Date, when we post the revised Notice on our website. You are strongly advised to review this Notice periodically for any changes
Appendix 1: Personal Data which may be collected
Types of Personal Data | Examples (Non-exhaustive) |
---|---|
Personal identification information (personal particulars, demographic and contact information) | Name, NRIC, travel and permit document (passport, employment pass, VISA details), gender, date of birth, country of birth, country of residence, nationality, citizenship, marital status, Relatives5 , race, ethnicity, religion, contact number(s), email address(es). |
Health and medical information | Topics of interest, medical history and records including, but not limited to, drug prescriptions, tests and scan results or clinical images, therapies and procedures, consultations, reports and reviews. |
Account and profile information | Account login information, health and medical information, benefits entitlement, accreditation, appointments, admissions, bills, purchases and/or payments information, insurance claims, transactions records, subscriptions, registrations, applications, enquiries, feedback, comments, ratings, reviews and testimonials via our communication and feedback touchpoints, channels and/or platforms. |
Network traffic and other related data | Identification numbers, location data, online identifiers, IP address, cookies, web beacons, device identification details, language settings. |
Images and/or videos from which you may be identified, images captured on security systems, including CCTV and key card entry systems | Pictures uploaded into our accounts, social media or services otherwise provided to us by you, CCTV images, log files. |
Compensation and payroll | Bank account information, salary, bonus, payroll deductions including insurance. |
Job, position, and organisation data. | Department, supervisor, office address, work location, permit details, hire date, job title, designation, business unit, part-time or full time position, work history, termination date and reason, retirement eligibility, promotions and disciplinary records, date of transfers, reporting manager(s), other details of employment contract. |
Performance and benefits data | Performance reviews and ratings, incentives, awards, retirement, benefits data of family members/dependents such as names and date of birth. |
Tax Data | Tax number, contribution rates, tax preferences. |
Data resulting from internal or external communications | Contents of email, records of communication through bots, messaging tools, mobile communications. |
Information that you decide to voluntarily share with us | Feedback, opinions, reviews, comments, and any information you may share with us on our social media platform, internal communication platforms and websites. |
Appendix 2: Purposes for which Personal Data is Processed
Purposes for Processing Personal Data | Examples |
---|---|
Provision of Medical Services Purpose | Assessment for provision of medical treatment and other related services: If you are referred to our facility by your doctor / medical professional, and you have previously attended any IHH Healthcare Singapore facility6 , we may use the personal data (such as your address and contact details) we hold from your previous registration or admission to streamline the referral process in our system to assess you for your medical treatment. Such previous registration or admission is regardless of whether the assessment is conducted by our or a third party medical professional and entered into our system. i. Processing your Personal Data that is collected by other IHH Healthcare entities in order to deliver shared services (e.g., HR, IT, Finance and internal audit functions) within IHH Healthcare Singapore; ii. Where an IHH Healthcare Singapore entity performs group management function collects and uses the Personal Data collected by other affiliates for its reporting purposes (e.g., Board reporting or to compile statistics for the necessary reporting); iii. Where an IHH Healthcare Singapore entity uses the same IT systems and database to process its data (including your Personal Data) (e.g., SAP system or any applicable medical records systems); and iv. consolidating your Personal Data collected from an IHH Healthcare Singapore facility or entity into one database for use by another IHH Healthcare Singapore facility or entity in order to facilitate the delivery of medical services to you. Contracted services with government agencies: We may provide health services to groups such as individuals under contracts with government. Where you receive services from us under such arrangements, we will provide your Personal Data (which in some cases may include a copy o your medical record for the relevant admission) to those government agencies as required under those contracts. Clinical trial invitation and participation: At times, we may become aware of clinical trials which may be relevant to your medical attention. Any participation in such trials is voluntary and we will seek your consent before enrolling you into such trials. We may use your personal data to assess your suitability for participation in the clinical trial in order to provide you with initial information about such clinical trial. Other common uses: We may also collect, use, disclose or Process your personal data where necessary for: i. Liaising with third party administrators (TPAs), insurance companies or parties authorising the payment of medical services for review and management of your case and claims of medical fees in relation to any medical services recommended or provided to you; ii. Liaising with your medical saving scheme administrator (e.g., Medisave, MediShield) and, where required, provide information to your medical saving scheme administrator to verify treatment provided to you, as applicable and as necessary; iii. The purpose of contacting you or your appointed primary contact person in relation to billing updates, post-discharge updates/follow-ups, emergency contact or other medical related purposes, and readiness of your medical reports or other documents, by call, text message or email to the number or mailing address which you have provided to us; and iv. Communicating important information to you regarding your medical saving scheme and any financial or management implications in relation to your care at our facility. |
Business Purpose | Processing necessary for the performance of contractual obligations, invoicing, billing and account management of Individuals, customer service and support, finance and accounting, research and development, internal management and control, and any other reasonably related activities. |
Contractual obligations and necessity | Providing and administering medical care, health and wellness services including, but not limited to, ordering and providing medication, medical tests, scans, reports, reviews, consultations, therapy, procedures; liaising with third-party service providers, vendors, suppliers and business and collaboration partners for the provisions of such, and related, products and services; and maintaining related documentations and records. |
Account management of Individuals | Creating and maintaining account profiles and information including, but not limited to, health, medical, benefits entitlement, accreditation, transaction (enquiries and feedback, appointments, admissions, bills, purchases and/or payments, insurance claims, etc.) records; to enable the processing of requests including, but not limited to, subscriptions, registrations, applications, execution and conclusion of contracts, and providing customer service and support |
Customer service and support | Handling enquiries, feedback and complaints; arranging and facilitating bookings, registrations, applications; providing notifications and reminders; and providing support to deliver contractual obligations and other reasonably related account and relationship management requests and matters. |
Finance and accounting | Facilitate payments to, and receive payments from, Individuals, service providers, vendors, suppliers and business and collaboration partners; administering debt recovery and management; and other reasonably related matters |
Research and development | Review, study, analyse, perform analytics and/or aggregate information on product and service consumption, patterns and trends; Individual behavioural patterns, preferences; to improve operations, services, product offerings, personalise experiences; and other reasonably related activities and objectives. |
Internal management and control | Internal communications, scheduling work, recording time, managing and allocating company and employee assets and human resources, ensuring business continuity and crisis management; managing projects and costs, investor relations, alliances, ventures, mergers, acquisitions, divestitures, re-organisations or disposals and integration with purchaser; compilation of audit trails and other reporting tools, maintaining records relating to business activities, budgeting, financial management and reporting; intellectual property and standards management. |
Human resources and personnel management | Performing workforce analysis and planning including, but not limited to, internal surveys, performance evaluations, talent and career development, courses and trainings; grievances, disciplinary matters and terminations; maintaining internal employee directories and emergency contacts; management and administration of outplacement, eligibility for employment, initial hiring or rehiring; providing and verifying employment references and background checks; management of leave and other absences, compensation and benefits, taxes, loans, grants, business expenses and reimbursements, travel arrangements. |
Health, safety and security | Deploying and maintaining technical and organisational security measures, conducting internal audits and investigations, conducting assessments to verify conflict of interests, identifying and authenticating employees, managing network security and preventing data loss using automated technologies to identify malicious data on equipment or networks and to detect confidential information from leaving our perimeters or from unauthorised access to that information. Recording of your Personal Data through video or other digital, electronic, or wireless surveillance system or device to secure and maintain IT infrastructure, office equipment, facilities and other property, and to maintain the safety and security of our staff, patients, visitors and other attendees to our facilities. |
Compliance with legal and regulatory obligations | Disclosing Personal Data to government institutions or supervisory authorities as required by law or judicial authorisation for complying with tax and national insurance deductions, record-keeping and reporting obligations, conducting audits and investigations to prevent or detect fraud or corruption, compliance with government inspections and other requests from government or other public authorities, responding to legal process conducting investigations including employee reporting of allegations of wrongdoing, policy violations, fraud, or financial reporting concerns, complying with internal policies and procedures. Please also keep in mind that we may also use your data for security reasons and/or to protect our legitimate business interests or to prevent or investigate suspected or actual violations of law, breaches of the terms of employment or non-compliance with our policies. |
Defence of legal claims | Establishment, exercise or defence of legal claims to which we are subject, such as responding to legal processes such as subpoenas, pursuing legal rights and remedies, defending litigation and managing any internal complaints or claims (including any whistle-blower/ethics hotlines). |
Enhanced security and further processing for improved services | Creation of de-identified and/or anonymised data from your Personal Data (by removal of identifiable components, obfuscation, anonymisation, or any other means) to enhance security and for further processing, aggregation, analysis for optimisation of patient care and improvement of healthcare services, products, research and development which may include transferring anonymised data to our affiliates and business partners in foreign countries. |
2 “Individual” means a natural person, whether living or deceased
3 “Processing” is any operation or set of operations performed on the Personal Data including, but not limited to, collection, recording, holding, organisation, adaptation, alteration, retrieval, combination, transmission, storage, use, disclosure, transfer erasure or destruction.
4 “Vulnerable Persons” are persons deemed more vulnerable by applicable Singapore laws and regulations, and includes, but is not limited to, minors, elderly, persons with disabilities, and persons with diminished mental capacity.
5 “Relatives” include spouses, next of kin, dependents, children, and partners.
6 An IHH Healthcare Singapore facility includes but not limited to Mount Elizabeth Hospital, Mount Elizabeth Novena Hospital, Gleneagles Hospital, Parkway East Hospital, Parkway Cancer Centre, Parkway MediCentre, clinics operated by Shenton Medical Group and Shenton Family Medical Centre, Parkway Radiology clinics and Parkway Laboratory Services clinics.
7 Under a homecare service, medical services would be provided by us or a third party outside an IHH Healthcare Singapore facility.