s 27 Obligation of subscribers, etc.
(1) Any subscriber or other person, including a person providing services to a credit reporting agency, who has access to the credit information processed by the credit reporting agency shall take appropriate measures to safeguard the credit information against any unauthorized or improper access, use, modification or disclosure, includingβ (a) developing written policies and procedures to be followed by its employees, agents and contractors; (b) establishing controls, includingβ (i) the use of passwords, credential tokens, digital signatures or other mechanisms; and (ii) user identification; (c) providing information and training to ensure compliance with the policies, procedures and controls; (d) monitoring usage and regularly checking compliance with the policies, procedures and controls; (e) taking appropriate action in relation to identified breaches of the policies, procedures and controls; and (f) maintenance of logs of all accesses, amendments and audit trails to the credit information provided to it by the credit reporting agency. (2) A person who contravenes subsection (1) commits an offence and shall, upon conviction, be liable to a fine not exceeding two hundred thousand ringgit or to imprisonment for a term not exceeding two years or to both.