PERSONAL DATAPROTECTION NOTICE

Jerudong Park Medical Centre Sdn Bhd (JPMC) respects your privacy and is committed to protecting your personal data. This Notice explains how we collect, use, disclose, store, and safeguard personal data in accordance with the Personal Data Protection Order, 2025 (PDPO). It also outlines your rights in relation to your personal data and how you may contact us if you have any questions or requests regarding how your information is handled. JPMC may update this Notice from time to time to reflect changes in legal requirements or our data handling practices. The latest version will be available on our website.

This Notice applies to individuals whose personal data is in our possession or under our control, including but not limited to:

  • Patients
  • Next of kin or caregivers
  • Visitors
  • Insured members and payors
  • Employees, visiting consultants, students, and trainees
  • Vendors, contractors, and service providers

“Personal data” refers to data, whether true or not, about an individual who can be identified from that data, or from that data and other information to which an organisation has or is likely to have access.

Depending on your interaction with us, we may collect:

  • Identification details such as name, NRIC or passport number, date of birth, sex, and nationality
  • Contact details such as address, phone number, and email
  • Medical information needed for your care, including diagnoses, treatment records, test results, and medications
  • Clinical photographs taken for care, documentation, or teaching (not used for marketing unless separately consented)
  • Next-of-kin or caregiver details
  • Billing, payment, and insurance information
  • CCTV images within our premises for safety and security
  • Biometric or other sensitive data where permitted by law and necessary

If you provide personal data about another person, you confirm that you are authorised to do so.

We collect personal data directly from you or from relevant third parties when you:

  • Register, book appointments, are admitted, discharged, or receive care
  • Acquire clinical or non-clinical support services
  • Submit forms, make enquiries, provide feedback, or request medical reports
  • Make payments or insurance claims
  • Enter areas monitored by CCTV
  • Attend JPMC events where photos or recordings may be taken

We use personal data only where necessary to operate our hospital and provide safe, effective care.

This includes:

  • Ensuring patient, staff, and visitor safety
  • Maintaining accurate medical and administrative records
  • Providing medical treatment, care coordination, referrals, and follow-ups
  • Managing appointments, admissions, transfers, and discharges
  • Processing billing, payments, and insurance claims
  • Conducting audits, quality improvement, and accreditation activities
  • Supporting education and training of healthcare professionals
  • Conducting approved research in accordance with law and ethics requirements
  • Supporting public health reporting and safety initiatives
  • Communicating with you about JPMC services where permitted
  • Administration of hospital operations

If you prefer that students or trainees are not involved in your care, please inform your attending doctor.

We share personal data only on a need-to-know basis with:

  • Healthcare professionals and institutions involved in your care
  • Insurers, payors, or administrators for billing and claims
  • Service providers supporting hospital operations, under contractual safeguards
  • Regulatory or public authorities where required by law
  • Accreditation bodies, auditors, and inspection teams
  • Your authorised representatives/caregivers involved in your care
  • Courts or legal advisors where necessary to establish, exercise or defend legal claims

We collect, use, and disclose personal data where:

  • Required or permitted by law
  • Needed to provide medical care or ensure safety
  • With your consent, where required

Consent is limited to what is reasonable. It may be implied when you voluntarily provide information for a requested service.

Marketing communications are sent only with your consent, where required by law.

Withdrawal of Consent

You may withdraw consent for activities that are based on consent, subject to reasonable notice.

  • Withdrawal may affect non-essential services, like marketing
  • It does not apply to processing that is necessary for care, safety, or legal obligations
  • A request for withdrawal may not be acted upon immediately if records are in active clinical use
  • We will explain any important consequences

To withdraw consent, contact our Data Protection Officer with your name, contact details, the data/activity affected, and the consent you wish to withdraw.

Under the PDPO, you have the right to:

  • Be informed about how your personal data is used
  • Request access to your personal data
  • Request correction of inaccurate or incomplete data
  • Withdraw consent where processing is consent-based

Requests for access to medical records are managed by JPMC’s Health Information Management Department in accordance with hospital policy. Access requests may be refused in limited cases (e.g., unreasonable, threats to life/health, third‑party data).

Further information on accessing your medical records is available on ACCESSING YOUR MEDICAL HEALTH RECORDS | JPMC Brunei.

If you are dissatisfied with our response, you may raise your concern with the Authority for Info-communications Technology Industry of Brunei Darussalam (AITI).

We take reasonable steps to ensure that personal data is accurate and complete. Where you provide information directly to us, we rely on it as accurate unless informed otherwise.

We maintain technical, administrative and organizational safeguards to protect your personal data by ensuring it is kept confidential, accurate, and secure against unauthorized access, loss, or misuse.

If a notifiable data breach occur (e,g., likely to cause significant harm), we will assess the situation and notify affected individuals and the relevant authority as required by law.

We keep personal data only for as long as necessary to meet medical, legal, regulatory, and operational requirements. Data is securely deleted or anonymised when no longer needed.

If personal data is transferred outside Brunei Darussalam, we ensure it is protected to a standard comparable to the PDPO using appropriate safeguards.

Minors or individuals who cannot give consent, personal data is collected and used only with consent from a parent, legal guardian, or authorised representative. Processing of some personal data without consent may still occur if required for medical care or safety.

Contact Us​

If you have questions or wish to exercise your data protection rights, please contact:
Data Protection Officer
Email: [email protected]
Phone: +673 261 1433
Post: Jerudong Park Medical Centre, Jerudong BG3122, Brunei Darussalam

Last updated on 19th March 2026

Feedback Form

How JPMC Can Help You

We welcome patient feedback, to tell us what we are doing right now and what we can improve. We would like you to think about your recent experience with our service. How likely are you to recommend our practice to friends and family if they needed similar care or treatment?