Tokio Marine Life. Questions in relation to objectives and principles of proposed DP framework:
|
|
|
- Ruby Hodge
- 9 years ago
- Views:
Transcription
1 1 PUBLIC CONSULTATION ISSUED BY MINISTRY OF INFORMATION, COMMUNICATIONS AND THE ARTS ON PROPOSED CONSUMER DATA PROTECTION REGIME FOR SINGAPORE COMMENTS OF LIA MEMBERS Summary of Returns: Comments (8) No Comments (8) Aviva AIA Friends Provident AXA Life Great Eastern Life & OAC Generali Manulife HSBC Insurance NTUC Income Royal Skandia Prudential Swiss Life Zurich Transamerica Tokio Marine Life PART III: PROPOSED CONSUMER DATA PROTECTION FRAMEWORK A) Key Objectives and Principles Questions in relation to objectives and principles of proposed DP framework: Question 1: Do you have any views / comments on the impact of the proposed DP law on specific sectors? Do you have any suggestions on measures to mitigate this or any other anticipated impact? Question 2: With reference to paragraph 3.8, do you have any views / comments on the concurrent application of the DP law with existing sectoral regulations? Question 2 - We agree with the concurrent application of DP law with existing sectoral regulations. We would like to clarify on which are the existing sectoral regulations on DP that are more stringent as compared to the proposed DP law. Please advise. - Will the stricter standard apply whether under the sectoral regulations or under the DP law? Question 1 An overly restrictive DP law might hinder trade and business. It is proposed that the DP laws only sets out the principle of DP, and for industry associations to set out specific restrictions / regulations after consultation with the DP Commissioner. B) Scope of Coverage Types of Data Covered Questions in relation to the definition of personal data : Question 3: Do you have any views / comments on the proposed definition of personal data outlined at paragraphs 3.9 to 3.11? Question 4: With reference to paragraphs 3.15 to 3.16, do you have any views / comments as to whether the proposed DP law should cover the personal data of the deceased? If it should,
2 2 do you have any views / comments on the proposed approach to the protection of personal data of the deceased? Question 3 The proposed definition is too general and it would be preferable if certain types of personal data are specifically identified as personal data: e.g. NRIC No / passport number, residential address although guidelines can be issued for less common forms of personal data. Question 4 The proposed DP law should protect the personal data of deceased persons but propose that the period be reduced from less than 20 years to less than 7 years. Question 3 Then proposed definition of personal data is too wide. Under the proposed definition, any information pertaining to an individual would be deemed personal data. For example, information is often communicated to employees through the head of department / the employee s manager. Such information could include information particular to that employee such as remuneration, performance reviews, test scores etc. Given the definition of personal data, such communication will no longer be possible unless prior consent for disclosure to the head of department / manager is obtained from employees. Question 4 It is proposed that DP only covers specific and restricted data of a deceased person. This is because there could be administrative duties to be performed after the demised of a person, and thus personal data might need to be revealed. E.g. family members / law firms checking if a deceased person holds any insurance policy with an insurer, or if the deceased person has any bank account with a bank. In addition, the proposed protection of deceased person s data of up to 20 years is onerous and could be administratively laborious. It is proposed that the personal data to be retained and tenure of retention be determined by the organisations based on its needs and requirements. Zurich: Question 4 We are of the view that the proposed DP law should not cover personal data of the deceased due to administrative complexity which would lead to higher cost and effort. For industries with access to relatively higher sensitive personal data (e.g. banks), there are already sectoral regulations in place to protect personal data. Types of Organisations and Activities Covered Questions in relation to the organisations and activities covered by the DP law: Question 5: Do you have any views / comments on the proposed organisations covered by the DP law? Question 6: With reference to paragraphs 3.20 to 3.22, do you have any views / comments as to whether the DP law should extend to organisations located outside Singapore, so long as they engage in personal data collection or processing activities in Singapore? Do you have any suggestions as to how the DP law could be implemented if it should apply to such organisations? Friends Provident: Question 6 In relation to paragraph 3.22, we believe Singapore s data protection law should cover only data collection and processing activities carried out by organisations in Singapore, to reduce the possibility of conflicts with similar law in other jurisdictions. NTUC Income: Question 6 MICA should consider a fair framework applying to offshore organisations calling customers in Singapore so that there is a level playing field for all organisations, regardless where they are located.
3 3 Question 5 It should be clarified as to what extend a person acting in a personal capacity or domestic capacity need not be covered under the DP law. E.g. in the life insurance context, will the provision of a prospect s name and contact details by an individual to an insurance representative be deemed as acting in a personal capacity or domestic capacity? It is not clear on how much is regarded as a low annual turnover as described under paragraph C) Rules and Exclusions General Rules Questions in relation to the general exclusions from the DP law: Question 10: Do you have any views / comments on the proposed general rules under the DP law? Question 11: With reference to paragraph 3.35, do you have any views / comments as to whether individuals should be deemed to have given consent for organisations to collect, use or disclose their personal data if they are notified and given reasonable time to opt out but do not? Question 10 Are we able to use the information provided in the proposal forms for other purposes such as blast, SMS broadcast to policyholders and servicing life insurance representatives and also to conduct satisfaction survey? These are part of the services that we make available to policyholders and servicing life insurance representatives in order to address their enquiries and to understand from the customer, the service standards that we are providing. In the insurance context, personal and policy information is restricted to the policyholder, servicing life insurance representatives and internal staff. If the policyholder had signed an authorisation letter to release such information, are we in compliant with the proposed DP law if we were to release such information to the authorised third party? Currently, we have reservations in doing so with the exception of power of attorney cases as policy information can be sensitive. Disclosure of personal and policy information will also be made to proper claimants provided that proof of relationship and death certificate is given. We would like to ask if such procedures and requirements are sufficient or if additional measures be required to safeguard the information of the deceased party? Question 11 If it is clearly provided under the proposed DP law, consumers will not be disadvantaged and organisations will incur much less costs. Question 10 It is proposed that general / blanket consent be obtained for all purpose relating to or incidental with the business of ABC rather than specific consent be obtained individually for each purpose relating to the business. A restrictive consent or a need for individual specific consent would result in confusion over the type of consent given. In addition, operationally it will be very challenging to segregate between deemed consent and fresh consent for existing customers. Question 11 It is proposed that consent be under the opt out arrangement so as not to hinder trade / business and at the same time render protection for data of individuals. In addition, it is unclear as to what constitutes to a reasonable time. As such, it is proposed that a statutory
4 4 timeline be provided as relying on reasonable time would be subjective in each scenario and does not provide a level of comfort for businesses to use such data. Please also clarify the lead time given for organisations to execute customers' instructions to withdraw his consent for use of his personal data. For marketing campaigns (such as direct mail, or SMS, though non-exhaustive), data would be cut as at a certain date while the execution of the campaign is 2-3 weeks thereafter. Customers may write in to withdraw their consent during the window period and it may not be possible to stop the mail / / SMS in time. Rules on the Collection, Use and Disclosure of Personal Data Questions in relation to the proposed rules on collection, use and disclosure of personal data: Question 12: Do you have any views / comments on the proposed rules on collection, use and disclosure of personal data? Question 13: Do you have any views / comments on the proposed exceptions to the rules on collection, use and disclosure? Should an exception be provided for organisations to collect, use and disclose an individual s personal data for the purposes of identifying him or her as a member, or for circulation within the organisation? Are there any other exceptions that should be provided? Question 14: Do you agree with the proposed approach to the transfer of personal data outside Singapore outlined at paragraphs 3.60 to 3.61? Friends Provident: Question 12 In relation to paragraph 3.41, we believe that a specified contact information of the organisation would serve the purpose better than that of a contact information of an officer or employee. A valid group mailbox which is maintained and accessed by a number employees in the organisation means the concerns of the individuals will be looked upon and managed even if a specific employee is absent from the organisation. In relation to that point, it is onerous to have to designate one or more individuals to be responsible for the DP Act as stated in paragraph Not all Acts or subsidiary legislations require designation of persons responsible, and it is challenging why the DP Act should receive priority above others. We agree that the organisation, as the legal person, should be responsible for the DP Act. Question 12 For paragraph 3.41, before collecting an individual's personal data, an organisation shall disclose to the individual, verbally or in writing the purposes for collection of the personal data. As such, when customer provides personal data in the proposal forms, is it necessary to have additional disclosures / declarations statement in proposal & application forms to inform or obtain agreement from the customer for the collection of data? Would we need to extent this to feedback and survey forms, where information is collected mainly for feedback on our services and personal data disclosed is merely for identification purposes? Question 13 Collection, use and disclosure of an employee's personal data would be acceptable for the purpose of identifying him as an employee of the organisation, an exception to the general rule would be acceptable. What is the retention period for the insurance industry to maintain policy records necessary for business or legal purposes? For policy and customer records, we would suggest to follow the retention period as required by the industry. For other such as feedback or survey forms, perhaps a time frame of 3 to 4 years will be sufficient. Question 14 No objections as financial institutions are already bound by the MAS Outsourcing Guidelines to protect the personal information of the customers if such information is required to be provided to service providers in an outsourcing arrangement.
5 5 NTUC Income: Question 12 MICA should clarify if insurance companies are able to circulate personal particulars of insurance policyholders within the insurance industry when a policyholder submits a claim or during a policy application to their insurer. Currently, it is a common practice in the insurance industry to share insurance policy information to enable insurance companies to verify what was declared in the insurance claims or insurance policy application form. We would therefore appreciate if MICA can define the word investigation in Paragraph 3.42 more clearly, to explain whether this would include investigating an insurance claim that is being submitted or a new insurance application submitted by an applicant. If yes, does that mean that insurers can share information about the claimant or applicant without first seeking his consent (i.e. Paragraph 3.41). E.g. Mr Tan files a claim with Insurer A. Insurer A checks with Insurer B and C to find out if Mr Tan has submitted a claim as well with them and the details of any medical reports already obtained by Insurer B & C. Must Insurer B & C seek Mr Tan s consent before releasing such information to Insurer A? Question 12 Similar to our response to Question 10 - It needs to be clarified if transfer of data between related companies is allowed or would constitute to a breach under the DP law, taking also into consideration that certain related companies might be outside of Singapore. - The legislation should also exclude from the framework data that is shared amongst group companies and professional advisers on strict confidentiality basis. Question 13 See our response to Question 12 - To consider the sharing of information specific / necessary for specific industry (e.g. LIA centralize database, GIA database etc). - It is proposed that the exception of DP laws to employee extends in the same manner to insurance representatives as well. Question 14 Yes Rules on Accuracy, Protection and Retention of Personal Data Questions in relation to the proposed rules on accuracy, protection and retention of personal data: Question 14: Do you have any views / comments on the proposed requirements for the accuracy, protection and retention of personal data outlined at paragraphs 3.62 to 3.67? Question 15: With reference to paragraph 3.67, do you have any views / comments as to whether organisations should be required to specify the retention period when collecting personal data? Question 14 Given that the personal information is directly provided by our customers, would insurance companies not be required to ensure that the personal data of customers is reasonably accurate and complete? As for retention of personal data of policyholders, given the nature of the insurance policies especially life policies, we would need the personal data of the policies as long as the policies are still in force which could be for a few decades. Question 15 Given the nature of life insurance policies, it would be natural and reasonable for policyholders to assume that the personal data given by them to insurance companies would be retained for as long as they remain as a customer of the insurance company. Hence, we do not see the need to specify a retention period for purchasers of insurance policies.
6 6 Question 14 The requirement to ensure data is accurate should not apply in events where a prospective policyholder makes an offer to the insurer for the application of an insurance policy. The onus to provide accurate data should lie on the policyholder since insurance is a contract of utmost good faith. Question 15 It is proposed that the personal data to be retained and tenure of retention be determined by the institution based on its needs and requirements and organisations need not specify the retention period when collecting personal data. As such, it is proposed that the disclosure of the retention period should be in a broad and generic term, rather than a specific timeline. In the case of long term contracts, the personal data provided could be relied upon as evidences in future and thus having a restrictive retention period might not be feasible. Zurich: Question 15 We are of the view to not want to specify the retention period at the point of collecting the data. Different industries may need to comply with other data retention legislation / regulations apart from the DP law. If these legislation / regulations change in future, it would then cause additional administrative cost and effort to update the existing clients if we have already disclosed a different retention period to them. From a client perspective, most would not be overly interested in knowing the retention period as long as they have the assurance that their personal data is protected under the necessary legislation / regulations. Rules on Access to and Correction of Personal Data Questions in relation to the proposed rules on access to and correction of personal data: Question 16: Do you have any views / comments on the proposed rules on access to and correction of personal data? We have no objections to charging a reasonable fee to customers who wish to correct their personal data although currently we do not charge a fee. It might be administratively laborious to inform third parties of the change in personal data and the third parties might not require such updates. In the case of bancassurance model for example, a customer might wish to keep separate correspondence addresses for his banking and insurance needs. In addition, it is proposed that the type of data that are assessable to individual and subject to amendment by the individuals under paragraph 3.69 be defined. Accordingly, it is proposed that nonmaterial information should not be covered under the DP law. PART IV: IMPLEMENTATION A) Penalty and Enforcement Regime Questions in relation to the proposed penalty and enforcement regime: Question 17: Do you have any views / comments on the proposed enforcement powers of the DPC or the proposed appeals mechanism?
7 7 Question 18: Do you have any views / comments on the proposed penalties for contravention of the DP law outlined at paragraphs 4.4 to 4.5? Do you have any views / comments on the criteria for breaches that would warrant financial penalties? Question 18 As long as the criteria for breaches is very clear, we have no objections to the proposed penalties for contravention of the proposed DP law as long as mere negligence and unintended inadvertence in breaching the proposed DP is not punished with monetary penalties. C) Transitional Arrangements Sunrise period Questions in relation to transitional arrangements: Question 19: Do you have any suggestions on specific guidelines that the DPC should provide to help organisations achieve compliance with the DP law? Industrial associations should self regulate on DP regulations, rather than relying on strict DP laws, which could impede trade and businesses. Existing personal data Questions in relation to transitional arrangements: Question 20: With reference to paragraphs 4.11 to 4.14, do you have any views / comments as to whether a one to two year sunrise period would be appropriate? Question 21: With reference to paragraphs 4.15 to 4.19, do you have any views / comments on the proposed treatment of existing personal data? Question 22: Are there certain organisations that may require different transitional arrangements? Aviva: Question 20 Sunrise period of 2 years would be appropriate. Question 21 For existing customers, Company should be given a right to call unless client specifically states otherwise or client included in the Do-Not-Call (DNC) register. Question 20 It would be preferable to have at the very least a 2 year "sunrise" period to enable organisations to comply with the proposed DP law. Question 20 Sunrise period should be at least 2 years or longer. Question 21 It is proposed that all activities incidental to the business should be regarded as deemed consent for such activities to be carried out. Accordingly, consent should not be overly restrictive. Further, individuals whose personal data has already been collected should be deemed to have consented to the use of such data, even for new purposes, once the proposed legislation is in place. An op-out exercise should apply to such cases.
8 8 PART V: NATIONAL DO-NOT-CALL REGISTRY Questions in relation to proposed National Do-Not-Call registry: Question 23: Do you have any views / comments as to whether a National Do-Not-Call registry should be set up in Singapore? Aviva: Yes, there should be a National Do-Not-Call (DNC) registry in Singapore. Consumer should be able to self-register to the DNC Register on a renewable term basis (e.g. 24 months) with a choice of DNC to be imposed on specific industries. Friends Provident: In relation to paragraph 5.5, a national DNC registry will cause compliance cost to be significantly higher because there has to be constant referencing to the national registry before advertisements are sent to individuals. If an organisation already maintains its own DNC registry and protection is given to how personal data is obtained and used, then a national DNC registry may be duplicating the protection given by these measures. Hence we would urge a rethink of having a national DNC registry. Manulife: With reference to Part V, Manulife is of the opinion that the Registry should operate in the same way as the UK model -- when a member of the public request that they want to opt out of any kind of unsolicited calls their names will not be included on any list sold to a tele sales company or in our case to agents. The onus is on the companies selling the lists to make sure that the lists do not contain names that have been registered with the national system. Secondly this will not preclude us from contacting existing clients or those who are introduced to us by referral. Thirdly, we need to address the issue of registrants changing phone numbers and the impact of recirculated numbers as practiced by telcos in Singapore. NTUC Income: On registering under the National DNC registry, we would like to highlight the following points: (a) It does not make commercial sense for the national DNC registry to apply to organisations if they have a business relationship with the individuals concerned. It is common practice for organisations to contact their customers on a periodic basis to provide them with product or information update. If the customers do not wish to be contacted, they would already have requested to be registered under the individual company s DNC list. (b) MICA must consider giving individuals the option to select the sector / industry which they do not wish to receive information from. It does not make commercial sense for the registry to apply across all sectors. Given that all telemarketing operations of general insurers are guided by MAS Notice 211, telemarketing activities conducted by the organisations comply with the MAS regulatory requirements on Fit & Proper Criteria. It thus seems harsh to penalise some industries for bad conduct of other industries. (c) We suggest there must be a cost effective and hassle free of downloading the DNC registry. We must be aware that there is a lead time between the date of registration and the date of calling. Organisations should not be penalised if violations occur during this period. A National Do-Not-Call registry is good but there are considerations such as how fast would the registry be updated to reflect the latest Do-Not-Call list. It would also be important to know if a DNC list covers all purpose of a call, or if it only applies to specific category of calls or specific sectors, such as not to be contacted for unsolicited calls. A company should be able to continue calling the number if the holder of such number is an existing customer of an organisation and calling such customer is necessary. In addition, would consent given would be superseded by subsequent inclusion under the Do-No-Call Registry?
9 9 CONTACT PERSONS Aviva Friends Provident Great Eastern Life & OAC Manulife NTUC Income Prudential Zurich Stanley Yeo Lawrence Ong Adeline Long Margaret Ho Peter Teo Tee Swee Vien Max Ng or Paul Ballam Submitted through Life Insurance Association, Singapore 19 October 2011
PERSONAL DATA PROTECTION COMMISSION (PDPC) CONSULTATION ON PROPOSED REGULATIONS AND ADVISORY GUIDELINES FOR PERSONAL DATA PROTECTION ACT (PDPA)
1 PERSONAL DATA PROTECTION COMMISSION (PDPC) CONSULTATION ON PROPOSED REGULATIONS AND ADVISORY GUIDELINES FOR PERSONAL DATA PROTECTION ACT (PDPA) Comments (10) No comments (9) AXA Life Aviva HSBC Insurance
ADVISORY GUIDELINES FOR THE HEALTHCARE SECTOR 11 SEPTEMBER 2014
ADVISORY GUIDELINES FOR THE HEALTHCARE SECTOR 11 SEPTEMBER 2014 1 PART I... 4 1 Introduction... 4 PART II: APPLICATION OF THE DATA PROTECTION PROVISIONS TO SCENARIOS FACED IN THE HEALTHCARE SECTOR... 5
WHEN BUSINESS GETS PERSONAL A QUICK GUIDE TO THE PERSONAL DATA PROTECTION ACT 2012 FOR ORGANISATIONS PERSONAL DATA PROTECTION COMMISSION
WHEN BUSINESS GETS PERSONAL A QUICK GUIDE TO THE PERSONAL DATA PROTECTION ACT 2012 FOR ORGANISATIONS PERSONAL DATA PROTECTION COMMISSION S I N G A P O R E www.pdpc.gov.sg Introduction Organisations today
To this end ERCI fully endorses and adheres to the Principles of Personal Data Protection Act (2012). 1. The Purpose:
Data Protection Policy: Policy Statement: ERC Institute (ERCI) collects and uses information about people with whom it communicates. As stipulated by the Personal Data Protection Act (2012) (hereinafter
CODE OF CONDUCT FOR FINANCIAL ADVISERS
CODE OF CONDUCT FOR FINANCIAL ADVISERS 1 The Code of Conduct for Financial Advisers Contents The Principles of Conduct of Finance Business... 3 1. Introduction... 5 2. Interpretation... 6 3. General principles...
STATUTORY INSTRUMENTS. S.I. No. 336 of 2011
STATUTORY INSTRUMENTS. S.I. No. 336 of 2011 EUROPEAN COMMUNITIES (ELECTRONIC COMMUNICATIONS NETWORKS AND SERVICES) (PRIVACY AND ELECTRONIC COMMUNICATIONS) REGULATIONS 2011 (Prn. A11/1165) 2 [336] S.I.
Mortgage Brokerages, Lenders and Administrators Act, 2006. Additional Draft Regulations for Consultation
Mortgage Brokerages, Lenders and Administrators Act, 2006 Additional Draft Regulations for Consultation Proposed by the Ministry of Finance January, 2008 Mortgage Brokerages, Lenders and Administrators
Insurance Law Reforms and Requirements for Direct Offshore Foreign Insurers ("DOFIs")
Insurance Law Reforms and Requirements for Direct Offshore Foreign Insurers ("DOFIs") The Clayton Utz contact for this document is Fred Hawke, Partner Clayton Utz Lawyers Level 18 333 Collins Street Melbourne
PERSONAL DATA PROTECTION CHECKLIST FOR ORGANISATIONS
PERSONAL DATA PROTECTION CHECKLIST FOR ORGANISATIONS How well does your organisation protect personal data? This self-assessment checklist is based on the nine personal data protection obligations underlying
Exercising Your Right of Consent to and Opt-out from Direct Marketing Activities under the Personal Data (Privacy) Ordinance 1
Exercising Your Right of Consent to and Opt-out from Direct Marketing Activities under the Personal Data (Privacy) Ordinance 1 It is common for members of the public to receive unsolicited telephone calls,
CONSULTATION PAPER NO 2. 2004
CONSULTATION PAPER NO 2. 2004 REGULATION OF GENERAL INSURANCE MEDIATION BUSINESS This consultation paper explains the need for the Island to regulate general insurance mediation business and examines the
Critical Illness Claim
The Certificate sets out the exclusions on the policy. In this regard, please note the following : (a) Illness in the Certificate has a defined meaning and will exclude pre-existing conditions. Please
TERMS OF BUSINESS AGREEMENT
Insurance and Reinsurance Brokers Iris Insurance Brokers Ltd 7 th Floor, New London House 6 London Street, London, EC3R 7LP United Kingdom. Tel: +44 (0)20 3178 7872 Fax: +44 (0)1702 431 644 Email: [email protected]
Taking care of what s important to you
A v i v a C a n a d a I n c. P r i v a c y P o l i c y Taking care of what s important to you Table of Contents Introduction Privacy in Canada Definition of Personal Information Privacy Policy: the ten
Hong Leong Asia Ltd.
Hong Leong Asia Ltd. Personal Data Protection Policy The protection of your Personal Data is important to us. This Personal Data Protection Policy ( PDP Policy ) outlines how we manage your personal data,
The Cloud and Cross-Border Risks - Singapore
The Cloud and Cross-Border Risks - Singapore February 2011 What is the objective of the paper? Macquarie Telecom has commissioned this paper by international law firm Freshfields Bruckhaus Deringer in
Copy of the Life Insured s/payor s (for Payor Benefit)/ Child (For Serious Illness of a Child Benefit)) Identity Card/Birth Certificate/ Passport
Dear Claimant We are sorry to learn of your illness/ injury. In order for us to process the claim, we require the following: 1. Critical Illness Form 2. Attending Physician s Statement 3. Copy of the Life
Claims Management Services Regulation. Conduct of Authorised Persons Rules 2013 (2)
Claims Management Services Regulation Conduct of Authorised Persons Rules 2013 (2) Effective from 8 July 2013 Contents Introduction 1 Definitions 1 General Rules Principles 2 Conduct of Business 2 Professional
INSURANCE INTERMEDIARIES (GENERAL BUSINESS) REGULATIONS 1999
INSURANCE INTERMEDIARIES (GENERAL BUSINESS) REGULATIONS 1999 Incorporating amendments to 1 st April 2010 ARRANGEMENT OF REGULATIONS 1. Citation and commencement. 2. Interpretation. 3. [Revoked] 4. Register
CONCEPT PAPER ON REGULATION OF INVESTMENT ADVISORS
1. Background CONCEPT PAPER ON REGULATION OF INVESTMENT ADVISORS 1.1 Section 11 (2)(b) of SEBI Act empowers SEBI to register and regulate working of Investment Advisors and such other intermediaries who
NOTICE TO BANKS MONETARY AUTHORITY OF SINGAPORE ACT, CAP. 186 PREVENTION OF MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM - BANKS
MAS 626 2 July 2007 Last revised on 1 July 2014 (Refer to endnotes for history of amendments) NOTICE TO BANKS MONETARY AUTHORITY OF SINGAPORE ACT, CAP. 186 PREVENTION OF MONEY LAUNDERING AND COUNTERING
HIPAA Privacy FAQ s. 3. Generally, what does the HIPAA Privacy Rule require the average provider or health plan to do?
HIPAA Privacy FAQ s 1. What is the HIPAA privacy regulation? Until Congress passed HIPAA in 1996, personal health information (PHI) was protected by a patchwork of federal and state laws. Patients health
Leads may be resubmitted within 4 months of the leads license renewal date.
1. LEAD GENERATION SERVICES (a) IBP agrees to collect and provide School with Leads as further specified herein and as described in the Lead Payment Schedule as may be executed by the parties from time
Insurance Prudential Rules. ICR Intermediary Conduct. Non-Bank Financial Institutions Regulatory Authority
Insurance Prudential Rules Intermediary Conduct Non-Bank Financial Institutions Regulatory Authority January 2014 Contents 1. Introduction... 3 1.1. Insurance Prudential Rules... 3 1.2. Purpose... 3 2.
This TEPL Data Protection Policy is effective from 2 July 2014. Updated on 31 Jul 2015
Telecom Equipment Pte Ltd ( TEPL ) Data Protection Policy Dash is a mobile money service created by Singtel and Standard Chartered. Payment services are provided by Telecom Equipment Pte Ltd ( TEPL ) and
Key Rules for General Insurance Brokers
Key Rules for General Insurance Brokers Contents 1. Introduction 3 2. Principles for businesses 6 3. Conduct of business rules 7 Financial promotion 7 Initial disclosure 9 Arranging and suitable advice
NASAA Recordkeeping Requirements For Investment Advisers Model Rule 203(a)-2 Adopted 9/3/87, amended 5/3/99, 4/18/04, 9/11/05; Amended 9/11/2011
NASAA Recordkeeping Requirements For Investment Advisers Model Rule 203(a)-2 Adopted 9/3/87, amended 5/3/99, 4/18/04, 9/11/05; Amended 9/11/2011 NOTE: Italicized information is explanatory and not intended
QUEENSLAND COUNTRY HEALTH FUND. privacy policy. Queensland Country Health Fund Ltd ABN 18 085 048 237. better health cover shouldn t hurt
QUEENSLAND COUNTRY HEALTH FUND privacy policy Queensland Country Health Fund Ltd ABN 18 085 048 237 better health cover shouldn t hurt 1 2 contents 1. Introduction 4 2. National Privacy Principles 5 3.
Claims Management Regulation. Marketing and Advertising Guidance Note
Claims Management Regulation Marketing and Advertising Guidance Note July 2013 Contents Introduction 1 Telemarketing 2 Making telesales calls 2 Data and third party compliance 4 Content of telesales calls
SUBSIDIARY LEGISLATION 104.01 MOTOR VEHICLES INSURANCE REGULATIONS
MOTOR VEHICLES INSURANCE [S.L.104.01 1 SUBSIDIARY LEGISLATION 104.01 MOTOR VEHICLES INSURANCE REGULATIONS 1st August, 1947 GOVERNMENT NOTICE 611 of 1939, as amended by Government Notice 221 of 1947 and
the Financing of Terrorism
CONSULTATION PAPER Obligations of Financial Institutions under the Personal Data Protection Act 2012 - P005-2014 June 2014 Amendments to Notices on Prevention of Money Laundering and Countering the Financing
PERSONAL DATA PROTECTION POLICY RELATING TO CIGNA EUROPE INSURANCE COMPANY S.A.-N.V. SINGAPORE BRANCH
PERSONAL DATA PROTECTION POLICY RELATING TO CIGNA EUROPE INSURANCE COMPANY S.A.-N.V. SINGAPORE BRANCH Personal data protection in Singapore is regulated by the Personal Data Protection Act 2012 (the PDPA
NOBLE TRUST COMPANY LTD. GENERAL TERMS OF BUSINESS. The following definitions and rules of interpretation shall apply:
NOBLE TRUST COMPANY LTD. GENERAL TERMS OF BUSINESS 1. Definitions and interpretation The following definitions and rules of interpretation shall apply: 1.1 Agent means any person appointed by a Client
Should you have any questions please do not hesitate to contact the NIG Broker Support on 0845 600 8408* or by email to brokersupport@nig-uk.
Dear Broker Principal, RE: Access to the NIG Extranet (including The Hub). U K Insurance Limited, trading as NIG ( NIG/we/us ), has received an application from a member of staff at your organisation (
Principles of Best Practice applicable to the distribution of Life Insurance Products on a Cross-border Basis within the EU or a Third Country
2015 Principles of Best Practice applicable to the distribution of Life Insurance Products on a Cross-border Basis within the EU or a Third Country 1 Principles of Best Practice applicable to the distribution
Statement of Guidance: Outsourcing All Regulated Entities
Statement of Guidance: Outsourcing All Regulated Entities 1. STATEMENT OF OBJECTIVES 1.1. 1.2. 1.3. 1.4. This Statement of Guidance ( Guidance ) is intended to provide guidance to regulated entities on
MEMBI PRIVACY POLICY
MEMBI 1 PURPOSE OF OUR POLICY 1.1 Membi Limited (Company Number 09775238) of 396a Kingston Road, Kingston Road, London SW20 8LL, United Kingdom (Membi, we, us or our) provides the services offered on the
NATIONAL PARTNERSHIP AGREEMENT ON E-HEALTH
NATIONAL PARTNERSHIP AGREEMENT ON E-HEALTH Council of Australian Governments An agreement between the Commonwealth of Australia and the States and Territories, being: The State of New South Wales The State
Identity Cards Act 2006
Identity Cards Act 2006 CHAPTER 15 Explanatory Notes have been produced to assist in the understanding of this Act and are available separately 6 50 Identity Cards Act 2006 CHAPTER 15 CONTENTS Registration
TERMS OF SERVICE TELEPORT REQUEST RECEIVERS
TERMS OF SERVICE These terms of service and the documents referred to in them ( Terms ) govern your access to and use of our services, including our website teleportapp.co ( our site ), applications, buttons,
POLICY FRAMEWORK AND STANDARDS INFORMATION SHARING BETWEEN GOVERNMENT AGENCIES
POLICY FRAMEWORK AND STANDARDS INFORMATION SHARING BETWEEN GOVERNMENT AGENCIES January 2003 CONTENTS Page 1. POLICY FRAMEWORK 1.1 Introduction 1 1.2 Policy Statement 1 1.3 Aims of the Policy 1 1.4 Principles
Firm Registration Form
Firm Registration Form Firm Registration Form This registration form should be completed by firms who are authorised and regulated by the Financial Conduct Authority. All sections of this form are mandatory.
[To All Financial Institutions Exempt from Holding Capital Markets Services Licence]
Circular No.: CMI 01/2011 7 February 2011 [To All Holders of Capital Markets Services Licence] [To All Holders of Financial Advisers Licence] [To All Financial Institutions Exempt from Holding Capital
TPS Corporate Services Personal Data Protection Policy
TPS Corporate Services Personal Data Protection Policy In this policy, we, us, our means and all its related companies (collectively known as TPS ), you, your or yours means the persons to whom this policy
Updated HIPAA Regulations What Optometrists Need to Know Now. HIPAA Overview
Updated HIPAA Regulations What Optometrists Need to Know Now The U.S. Department of Health & Human Services Office for Civil Rights recently released updated regulations regarding the Health Insurance
2015 No. 0000 FINANCIAL SERVICES AND MARKETS. The Small and Medium Sized Business (Finance Platforms) Regulations 2015
Draft Regulations to illustrate the Treasury s current intention as to the exercise of powers under clause 5 of the Small Business, Enterprise and Employment Bill. D R A F T S T A T U T O R Y I N S T R
[email protected]
APPLICATION FORM INVICTUS SICAVp.l.c. INVICTUS MACRO FUND This Form duly completed should be sent to the Company at the offices of the Administrator or through any duly authorised intermediary at the following
computer to identify you as a unique user and to take into account your personal preferences and technical information. We use:
BMS CONSULTING WEBSITE TERMS AND RULES OF USE www.bms-consulting.com This site and associated websites referenced by links (collectively, the Site) provide information on services, projects, solutions
THE PUBLIC RELATIONS CONSULTANTS ASSOCIATION. Find A PR agency Terms and Conditions for Clients
THE PUBLIC RELATIONS CONSULTANTS ASSOCIATION Find A PR agency Terms and Conditions for Clients 1 Introduction 1.1 Find A PR agency is the PRCA s impartial search and referral service for organisations
RESPONSE TO FEEDBACK RECEIVED CONSULTATION PAPER ON REVIEW OF PARTICIPATING LIFE INSURANCE BUSINESS
RESPONSE TO FEEDBACK RECEIVED CONSULTATION PAPER ON REVIEW OF PARTICIPATING LIFE INSURANCE BUSINESS 1 INTRODUCTION 1.1 On 22 February 2005, MAS issued a consultation paper on proposals to enhance the management
THE GENERAL INSURANCE BROKERS CODE OF PRACTICE
THE GENERAL INSURANCE BROKERS CODE OF PRACTICE CONTENTS 1 Introduction Outline of the Code...3 Objectives of the Code...3 Principles of the Code...3 Monitoring of the Code...3 Review and development of
GUIDELINES ON COMPLIANCE FUNCTION FOR FUND MANAGEMENT COMPANIES
GUIDELINES ON COMPLIANCE FUNCTION FOR FUND MANAGEMENT COMPANIES Issued: 15 March 2005 Revised: 25 April 2014 1 P a g e List of Revision Revision Effective Date 1 st Revision 23 May 2011 2 nd Revision 16
Consultation on Review of Participating Fund Business for Life Insurers
CONSULTATION PAPER P004-2005 February 2005 Consultation on Review of Participating Fund Business for Life Insurers PREFACE The Participating (Par) Fund Review Workgroup, comprising representatives from
THOMSON REUTERS (TAX & ACCOUNTING) INC. FOREIGN NATIONAL INFORMATION SYSTEM TERMS OF USE
THOMSON REUTERS (TAX & ACCOUNTING) INC. FOREIGN NATIONAL INFORMATION SYSTEM TERMS OF USE 1. License and Permitted Use The Foreign National Information System (FNIS) is licensed, not sold. Subject to the
PRIVACY POLICY. What Information Is Collected
PRIVACY POLICY This Privacy Policy applies to Web.com Group, Inc. (along with all subsidiaries, affiliates, successors and assigns thereof, referred to hereinafter collectively as Web.com, "we", "our"
COMPLIANCE FRAMEWORK AND REPORTING GUIDELINES
COMPLIANCE FRAMEWORK AND REPORTING GUIDELINES DRAFT FOR CONSULTATION June 2015 38 Cavenagh Street DARWIN NT 0800 Postal Address GPO Box 915 DARWIN NT 0801 Email: [email protected] Website:
Appendix : Business Associate Agreement
I. Authority: Pursuant to 45 C.F.R. 164.502(e), the Indian Health Service (IHS), as a covered entity, is required to enter into an agreement with a business associate, as defined by 45 C.F.R. 160.103,
HIPAA BUSINESS ASSOCIATE AGREEMENT
HIPAA BUSINESS ASSOCIATE AGREEMENT THIS BUSINESS ASSOCIATE AGREEMENT (hereinafter Agreement ) is between COVERED ENTITY NAME (hereinafter Covered Entity ) and BUSINESS ASSOCIATE NAME (hereinafter Business
Conditions for transfer of personal data overseas
19 The Transfer Limitation Obligation 19.1 Section 26 of the PDPA limits the ability of an organisation to transfer personal data outside Singapore. In particular, section 26(1) provides that an organisation
SECURITIES AND FUTURES ACT (CAP. 289)
Monetary Authority of Singapore SECURITIES AND FUTURES ACT (CAP. 289) FREQUENTLY ASKED QUESTIONS (FAQs) ON THE LICENSING AND REGISTRATION OF FUND MANAGEMENT COMPANIES Disclaimer: These FAQs are meant to
North American Electric Reliability Corporation. Compliance Monitoring and Enforcement Program. December 19, 2008
116-390 Village Boulevard Princeton, New Jersey 08540-5721 North American Electric Reliability Corporation Compliance Monitoring and Enforcement Program December 19, 2008 APPENDIX 4C TO THE RULES OF PROCEDURE
G&T Brokers Limited. Terms of Business Agreement ( TOBA )
Terms of Business Agreement ( TOBA ) The purpose of this document is to describe our professional relationship and the services we will provide to you. You should read this document carefully for as well
Name of Other Party: Address of Other Party: Effective Date: Reference Number as applicable:
PLEASE NOTE: THIS DOCUMENT IS SUBMITTED AS A SAMPLE, FOR INFORMATIONAL PURPOSES ONLY TO ABC ORGANIZATION. HIPAA SOLUTIONS LC IS NOT ENGAGED IN THE PRACTICE OF LAW IN ANY STATE, JURISDICTION, OR VENUE OF
Maybank Kim Eng Securities Pte Ltd Terms and Conditions
Maybank Kim Eng Securities Pte Ltd Terms and Conditions for Financial Advisory Services Telephone Email Website : (65) 6432 1888 (Singapore and Overseas) : [email protected] : www.maybank-ke.com.sg
Investment Structures Insurance Solutions (ISIS)
Investment Structures Insurance Solutions (ISIS) Directors and Officers Liability Entities Securities Professional Liability Crime Proposal form Instructions to applicant Completing the Proposal Form Please
Disclaimer: Template Business Associate Agreement (45 C.F.R. 164.308)
HIPAA Business Associate Agreement Sample Notice Disclaimer: Template Business Associate Agreement (45 C.F.R. 164.308) The information provided in this document does not constitute, and is no substitute
May 28, 1997. All Title Insurance Companies, Title Insurance Agencies, and Title Insurance Agents Licensed in Virginia
May 28, 1997 Administrative Letter 1997-5 TO: RE: All Title Insurance Companies, Title Insurance Agencies, and Title Insurance Agents Licensed in Virginia Senate Bill No. 1104 (The Consumer Real Estate
GymSports NZ Incorporated. Membership Data Regulation. Commencement Date 23 January 2009. Issued 23 January 2009
GymSports NZ Incorporated Membership Data Regulation Commencement Date 23 January 2009 Issued 23 January 2009 GymSports NZ, 2008 GymSports New Zealand Incorporated Membership Data Regulation 1. Purpose
FUND MANAGER CODE OF CONDUCT
FUND MANAGER CODE OF CONDUCT First Edition pursuant to the Securities and Futures Ordinance (Cap. 571) April 2003 Securities and Futures Commission Hong Kong TABLE OF CONTENTS Page INTRODUCTION 1 I. ORGANISATION
Merthyr Tydfil County Borough Council. Data Protection Policy
Merthyr Tydfil County Borough Council Data Protection Policy 2014 Cyfarthfa High School is a Rights Respecting School, we recognise the importance of ensuring that the United Nations Convention of the
Appendix 11 - Swiss Data Protection Act
GLEIF- LOU Restricted Appendix 11 - Swiss Data Protection Act GLEIF Revision Version: 1.0 2015-09-23 Master Copy page 2 of 11 Applicable Provisions of the Swiss Data Protection Act (DPA) including the
RESPONSE TO FEEDBACK RECEIVED CONSULTATION ON ANTI- MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM (AML/CFT) NOTICES AND GUIDELINES
RESPONSE TO FEEDBACK RECEIVED CONSULTATION ON ANTI- MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM (AML/CFT) NOTICES AND GUIDELINES Introduction 1 In August 2006, MAS released a consultation
IRDA/ADMN/GDL/MISC/059/04/2011 Dt. 05/04/2011. Guidelines on Distance Marketing of Insurance Products
IRDA/ADMN/GDL/MISC/059/04/2011 Dt. 05/04/2011 Guidelines on Distance Marketing of Insurance Products These Guidelines are issued in exercise of the powers conferred upon the Authority under Section 14(1)
13-25a-101. Title. This chapter is known as the "Telephone and Facsimile Solicitation Act."
13-25a-101. Title. This chapter is known as the "Telephone and Facsimile Solicitation Act." Enacted by Chapter 26, 1996 General Session 13-25a-102. Definitions. As used in this chapter: (1) "Advertisement"
SWEDBANK AS TERMS AND CONDITIONS FOR PAYMENT CARDS SERVICING Valid from 01.12.2014
SWEDBANK AS TERMS AND CONDITIONS FOR PAYMENT CARDS SERVICING Valid from 01.12.2014 1. TERMS AND DEFINITIONS 1.1 Account is a current account of the Merchant specified in the Agreement. 1.2 Agreement is
Keystone Financial Planning, Inc.
Keystone Financial Planning, Inc. 7261 Engle Road Suite 308 Middleburg Heights, Ohio 44130 Telephone: 440.234.6323 Facsimile: 440.234.6844 Website: www.keystonefin.com February 10, 2014 FORM ADV PART 2
Communication between the Auditor and the Insurance Authority
PN 620.2 Revised February 2013 Practice Note 620.2 Communication between the Auditor and the Insurance Authority PRACTICE NOTE 620.2 COMMUNICATION BETWEEN THE AUDITOR AND THE INSURANCE AUTHORITY (Issued
These TERMS AND CONDICTIONS (this Agreement ) are agreed to between InfluencersAtWork,
TERMS AND CONDITIONS INFLUENCERS AT WORK These TERMS AND CONDICTIONS (this Agreement ) are agreed to between InfluencersAtWork, Ltd. ( InfluencerAtWork ) and you, or if you represent a company or other
DISCUSSION PAPER SUBJECT: TYING AND BUNDLING INSURANCE POLICIES WITH OTHER SERVICES AND GOODS
1 P a g e INSURANCE REGULATORY AND DEVELOPMENT AUTHORITY DISCUSSION PAPER SUBJECT: TYING AND BUNDLING INSURANCE POLICIES WITH OTHER SERVICES AND GOODS I. Objective: This paper seeks to discuss issues relating
2015 No. 1945 FINANCIAL SERVICES AND MARKETS. The Small and Medium Sized Business (Credit Information) Regulations 2015
S T A T U T O R Y I N S T R U M E N T S 2015 No. 1945 FINANCIAL SERVICES AND MARKETS The Small and Medium Sized Business (Credit Information) Regulations 2015 Made - - - - 26th November 2015 Coming into
PRIVACY POLICY Personal information and sensitive information Information we request from you
PRIVACY POLICY Business Chicks Pty Ltd A.C.N. 121 566 934 (we, us, our, or Business Chicks) recognises and values the protection of your privacy. We also understand that you want clarity about how we manage
COLLECTIVE INVESTMENT SCHEMES ACT 2008 COLLECTIVE INVESTMENT SCHEMES (REGULATED FUND) REGULATIONS 2010
Statutory Document No. 161/10 COLLECTIVE INVESTMENT SCHEMES ACT 2008 COLLECTIVE INVESTMENT SCHEMES (REGULATED FUND) REGULATIONS 2010 1 Title 2 Commencement 3 Interpretation INDEX THE GOVERNING BODY 4 Composition
Terms and Conditions
Terms and Conditions The use of angieavardturnerlaw.com, including all materials online and all services provided by Angie Avard Turner Law, LLC (hereafter Angie Avard Turner Law), is subject to the following
Bond Form Commentary and Comparison
Bond Form Commentary and Comparison AIA Document A310 2010, Bid Bond, and AIA Document A312 2010, Performance Bond and Payment Bond INTRODUCTION Since the first publication of The Standard Form of Bond
TERMS AND CONDITIONS GOVERNING THE USE OF NBADS ONLINE TRADING
TERMS AND CONDITIONS GOVERNING THE USE OF NBADS ONLINE TRADING In this document, the following words and phrases shall have the meanings set out below unless indicated otherwise. You should read every
ii. sold, licensed, transferred or assigned to no other party for a period of thirty (30) days;
Tymax Media Vendor Operating Agreement Tymax Media Vendor Operating Agreement (the "Agreement") is made and entered into by and between Tymax Media ("Tymax Media," us or "we"), and you, ("you" or "Vendor")
