1.1 This Personal Data Protection Notice (“Notice”) is revised on [1st November 2023] (“Effective Date”)
1.2 Pantai Holdings Sdn Bhd and/or its related corporations, including but not limited to its Affiliates (“we”, “us”, “our”, “company” or “IHH MY”) is committed to protecting
Data Subject’s (“your”, “you” and “yours”) personal data, responsibly and in compliance with applicable data protection related laws.
1.3 This Notice addresses how we Process your personal data by us when you interact with us.
1.4 This Notice may, however, be replaced or supplemented due to local requirements or to provide you additional information. We strongly encourage you to read this
2.1 For purposes of this Notice, Personal Data means any information or combination of information, relating, directly or indirectly to an identified or identifiable natural
2.2 Depending on the nature of your interaction with us, Personal Data may include your name, identification number, passport number, telephone number(s), mailing
address, email address, network traffic data, online identifiers and/or any other information which have been provided to us or we may have access to, in the course of
your interaction with us.
2.3 We may Process certain Personal Data about your Relatives but only when there is a legitimate business purpose related to your relationship with us, for instance, to
administer employee benefits or in case of an emergency.
2.4 For certain reasons, it may be necessary for us to Process special categories of Personal Data (including “sensitive” Personal Data) (“Sensitive Personal Data”). We only
Process Sensitive Personal Data where it is required or authorised under law (employment, social security, social protection or other applicable data protection related
laws), or in case of legal claims. Sensitive Personal Data may include religious or philosophical beliefs, information about disabilities, medical history, racial or ethnic
data and/or criminal data (behavior, records or proceedings regarding criminal or unlawful behavior).
What Personal Data do we collect?
We collect Personal Data from you in the following ways:
- when you create an account, register with us and/or submit any form to provide us or benefit from our services;
- when you disclose Personal Data in face-to-face meetings, email messages, telephone conversations with our teams such as marketing or customer service officers;
- when you volunteer and consent to participate in any research conducted by us;
- when you sign up for our marketing and promotional communications and/or any initiatives;
- when you give your feedback, comments, questions, ratings and reviews on our website, social media or to our customer service officers;
- when you interact or communicate with us via our websites or on social media channels, pages, promotions and/or blogs;
- when you contact us and/or enter into an agreement to provide us services;
- when you visit and/or are within our premises and your images are captured by us via CCTV cameras, photographs or videos taken by us or our representatives when you attend any of our events;
- when you submit an employment application; and/or
- when you make available your Personal Data to us for any other reason;
3.2 indirectly, from other data sources:
- when we seek and receive your Personal Data in connection with your relationship with us (including for our product and services or job applications). Example: business partners, public agencies, your ex-employer, referral intermediaries and the relevant authorities;
- if you act as an intermediary or are supplying us with information regarding a third-party/other individual (such as a Relative, friend, a colleague, an employee etc.), you undertake that you have obtained all necessary consents from such third-party/other individual for Processing of their Personal Data by us;
- as we are collecting third-party or other individual’s Personal Data from you, you undertake to make such third-party or other individual aware of all matters listed in this Notice by referring them to our website or informing them of the contents of this Notice; and/or
- any other information which we may collect from other sources.
3.3 Personal Data of Vulnerable Persons
- It is, our intention and policy to comply with law when it requires parent, guardian or legal representative’s permission before collecting, using or disclosing Personal Data of Vulnerable Persons.
- If a parent, guardian or legal representative becomes aware that Personal Data of a child or ward has been provided by that child or ward without the consent of the relevant parent, guardian or legal representative, please contact us (contact details provided below). Such Personal Data will be disposed of from our records.
For more details on Personal Data which may be collected, please refer to Appendix 1.
4.1 Business Purposes: These are legitimate purposes as appropriate to conduct our business. These purposes address Processing of Personal Data necessary for
activities such as:
- conclusion and execution of agreements with Data Subjects;
- marketing, sales, and promotions;
- account management of Data Subjects;
- customer service and support;
- finance and accounting;
- research and development, for instance, analytics to provide better products and services;
- purchasing/availing of our services;
- internal management, communications and controls;
- management of investor relations;
- government and legal affairs;
- alliances, ventures, mergers, acquisitions, and divestitures;
- Intellectual property and standards management;
- any other activity that is reasonably connected to the foregoing.
4.2 Human resources and personnel management: This includes Processing necessary for the performance of an employment or other contract with an employee (or to
take necessary steps at the request of an employee prior to entering into a contract), or for managing the employment-at-will relationship, e.g. management and
administration of recruiting and outplacement, compensation and benefits, payments, tax issues, career and talent development, performance evaluations, training, travel
and expenses, and employee communications;
4.3 Business process execution and internal management: This includes Processing necessary for activities such as scheduling work, recording time, managing company
assets, conducting internal audits and investigations, implementing business controls, managing and using customer database/employee directories;
4.4 Health, safety and security: Activities such as those involving occupational safety and health, the protection of our assets, your verification and your access rights and
4.5 Organisational analysis and development and management reporting: Conducting surveys, managing mergers, acquisitions and divestitures, and Processing data for
management reporting and analysis;
4.6 Compliance with legal obligations: For Processing necessary for compliance with a legal obligation to which we are subject;
4.7 Vital interests: For Processing necessary to protect your vital interests, for instance, situations that require us to protect your life or you from harm;
4.8 Sensitive Personal Data: Sensitive Personal Data may be Processed under one or more of the following circumstances
- where you have explicitly consented to the Processing;
- where Sensitive Data are Processed in connection with the purchase of our service;
- where you voluntarily participate in a research project or product test;
- as required by or allowed under applicable data protection related laws;
- to establish, exercise or defend a legal claim;
- with regard to racial or ethnic data: to safeguard our assets, for site access and security reasons, and for the authentication/verification of your access rights, we may Process photos and video images (in some countries photo and video images of individuals qualify as racial or ethnic data);
- to prevent, detect or prosecute (including cooperating with public authorities) suspected fraud, contract breaches, violations of law, or other breaches of the terms of access to our sites or assets;
- to protect your vital interest, but only where it is impossible to obtain your consent first; and/or
- where necessary to comply with an obligation of international public law (e.g. Treaties).
4.9 Direct Marketing: We may, when Processing Personal Data for making direct marketing communications, either:
- obtain your consent; and/or
- offer you opportunity to choose not to receive such communications.
In every subsequent direct marketing communication that is made to you, you shall be offered the opportunity to opt-out of further marketing communication.
If you object to receiving marketing communications from us, or withdraw consent to receive such materials, we will take steps to refrain from sending further
marketing materials as specifically requested you. We will do so within the time-period required by applicable data protection related laws;
4.10 Secondary Purposes: Processing of Personal Data (including previously collected data) for secondary purposes such as:
- Maintaining the security of the Personal Data Processed;
- transferring the Personal Data to an Archive;
- conducting internal audits or investigations;
- implementing business controls;
- conducting statistical, historical or scientific research as required for our business operations;
- preparing or engaging in dispute resolution;
- using legal or business consulting services;
- managing insurance or other benefits related issues; and/or
- creating de-identified, aggregated and/or anonymised data from Personal Data from which relevant Data Subjects would not be identifiable, through removal of identifiable components, obfuscation, pseudonymisation, anonymisation, or any other means for purposes including, but not limited to (a) enhancing security; and/or (b) for further processing, aggregation, analysis (of the anonymised data that no longer contains your Personal Data only), for optimisation of patient care and improvement of healthcare services, products and research and developments which may include transferring such anonymised data to our affiliates and business partners in IHH MY or abroad, for such purposes.”
4.11 Any other purpose necessary to fulfil or achieve any other purposes stated in this Notice.
For more details on purposes for which Personal Data is Processed, please refer to Appendix 2.
4.12 Exceptions: Some of our obligations under this Notice may be overridden if, under the specific circumstances at issue, a pressing legitimate need exists that
outweighs your interest. Such a situation exists if there is a need to:
a) protect our Business Interests including:
4.12.1. the health, security or safety of individuals;
4.12.2. our intellectual property rights, trade secrets or reputation;
4.12.3. the continuity of our business operations;
4.12.4. the preservation of confidentiality in a proposed sale;
4.12.5. merger or acquisition of a business; and/or
4.12.6. the involvement of authorised advisors or consultants for business, legal, tax, or insurance purposes.
b) prevent or investigate suspected or actual violations of
4.12.1. law (including cooperating with law enforcement);
4.12.2. contracts; and/or
4.12.3. or our policies.
c) otherwise protect or defend us, our personnel’s or other individual’s rights or freedoms.
5.1 Automated tools may be used by us to Process your Personal Data and/or make decisions about you. Some extent of human intervention may be involved in the
5.2 Where permissible under law, we may undertake automated decision-making if:
- the decision is made by us for purposes of entering or performing a contract provided that the underlying request leading to a decision by us was made by you;
- you have provided explicit consent; and/or
- the use of automated tools is otherwise required.
5.3 We are mindful of safeguarding your rights and legitimate interests. To request a manual decision-making process, express your opinion or contest our decision based
on automated processing, including profiling, please contact us (contact details provided below).
6.1 Your Personal Data may be shared with our Affiliates and the healthcare professional.
6.2 Access to Personal Data, will be limited to those who have a need to know the information for the purposes described in this Notice.
6.3 From time to time, we may need to share your Personal Data with authorised external parties, which may include the following:
- service providers, vendors, suppliers: we contract with authorised external parties or companies that provide products and services to us such as information technology security and support, customer survey, debt recovery, payroll and employee expense support, and benefits and rewards administration;
- public and governmental authorities: when required by law, or as necessary to protect our rights, we may share your Personal Data to public and governmental authorities that regulate or have jurisdiction over us;
- professional advisors and others: we work with and receive support from certain professional advisors such as banks, insurance companies, auditors, lawyers, accountants, and payroll advisors; and/or
- other parties in connection with corporate transactions: we may also, from time to time, share your Personal Data in the course of corporate transactions, such as during a sale of a business or a part of a business to another company, or any reorganisation, merger, joint venture, or other disposition of our business, assets, or stock.
6.4 As appropriate, we will contractually protect and safeguard your interests at a similar level of protection as provided by us.
7.1 Due to our international presence, your Personal Data may be transferred to or accessed by our Affiliates and authorised external parties from various countries around
the world in order for us fulfil the purposes described in this Notice.
7.2 As a result, we may transfer your Personal Data to countries located outside of your country of residence, which may have data protection related laws and rules that are
different from those of your country of residence.
7.3 Personal Data may be transferred to an authorised external party, located internationally only if, we believe it is necessary or appropriate to:
- ensure compliance with applicable data protection related laws which may include responding to requests from public and government authorities, cooperation with law enforcement agencies or other legal reasons; and/or
- satisfy purposes for which Personal Data has been collected by us or to enforce our terms and conditions.
8.1 We keep your Personal Data as long as we need to fulfil the purposes for which it has been collected. We retain Personal Data only:
8.1.1 for the period required to serve applicable Business Purpose;
8.1.2. to the extent necessary to comply with an applicable legal requirement; and/or
8.1.3 as advised by local laws.
8.2 Promptly after applicable retention period has ended, your Personal Data will be appropriately:
- de-identified (through removal of identifiable components, obfuscation, pseudonymisation, anonymisation, or any other means); and/or
- transferred to an archive (unless this is prohibited by applicable data protection related law).
9.1 We are committed to maintaining the security of the Personal Data processed and restrict the Processing of Personal Data to those data / information that are
reasonable, adequate for, and/or relevant to applicable Business Purpose.
9.2 To protect your Personal Data, we take appropriate measures, and we also require our external parties to protect the confidentiality and security of your Personal Data.
Depending on the state of the art, the costs of implementation and the nature of the data/information to be protected, we have put in place physical, technical and
organisational measures to prevent risks such as destruction, loss, misuse, alteration, and unauthorised disclosure of or access to your Personal Data.
9.3 If you have any reason to believe that your interaction with us is no longer secure, please contact us (contact details provided below).
10.1 We strive to maintain your Personal Data in a manner that is accurate, complete and up-to-date. Personal Data you provide us with must be accurate, complete and up-
to-date, and you must inform us of any significant changes to your Personal Data.
10.2 Furthermore, if you share Personal Data of other people with us (including your Relatives) please note that you need to ensure that this Personal Data is collected in
compliance with applicable data protection related laws. For example, you should inform such other people about contents of this Notice.
10.3 With respect to Processing of your Personal Data, you may:
- obtain information on the Processing of your Personal Data;
- ask questions about how we handle Personal Data;
- request to review, correct, update, supress, or restrict the use of your Personal Data;
- request your Personal Data to be removed;
- withdraw your consent to use of your Personal Data;
- object to the use of Personal Data for our legitimate business interests; and/or
- request to receive an electronic copy of your Personal Data for purposes of transferring it to another company.
10.4 If you have any inquiries, requests or comments in relation to this Notice, please contact the Data Protection Office via the following channels:
- Email: email@example.com
- Written communication mailed to:
Data Protection Officer, IHH Healthcare Malaysia Pantai Medical Centre Sdn Bhd, Level 6, Block A, Pantai Hospital Kuala Lumpur, 8, Jalan Bukit Pantai, 59100, Kuala Lumpur.
10.5. We will do our best to address your requests and concerns within reasonable time. Upon receipt of your request, we may ask you to verify your identity before we can act on your request.
11.1. We may revise this Notice from time to time. Any changes will become effective as on the Effective Date, when we post the revised Notice on our website. You are strongly advised to review this Notice periodically for any changes.
11.2. The English language version of this notice shall prevail in the event of any inconsistencies with any translated versions.