PDPA - Notis Perlindungan Data Peribadi​

PDPA, this Data Protection Notice (“Notice”) sets out the basis which Khidmat Guaman (“we”, “us”, or “our”) may collect, use, disclose or otherwise process personal data of our customers in accordance with the Personal Data Protection Act (“PDPA”). This Notice applies to personal data in our possession or under our control, including personal data in the possession of organisations which we have engaged to collect, use, disclose or process personal data for our purposes.

Personal Data Protection Notice

Definitions

As used in this Notice:

  1. Customer: An individual who:

    • (a) has contacted us through any means to find out more about any goods or services we provide, or
    • (b) may, or has, entered into a contract with us for the supply of any goods or services by us.
  2. Personal Data: Data, whether true or not, about a customer who can be identified:

    • (a) from that data; or
    • (b) from that data and other information to which we have or are likely to have access.

Depending on the nature of your interaction with us, some examples of personal data we may collect include name, residential address, email address, telephone number, nationality, and gender. Other terms used in this Notice shall have the meanings given to them in the Personal Data Protection Act (PDPA) where the context so permits.


Collection, Use, and Disclosure of Personal Data

  1. Collection:

    • We generally do not collect your personal data unless:
      • (a) it is provided voluntarily by you or your authorised representative after being notified of the purposes, and written consent is provided; or
      • (b) collection and use without consent are permitted or required by the PDPA or other laws.
    • We will seek your consent before collecting additional personal data or using your data for purposes not previously notified.
  2. Purposes:

    • Verifying your identity.
    • Responding to queries, requests, applications, complaints, and feedback.
    • Managing your relationship with us.
    • Complying with legal and regulatory requirements.
    • Transmitting data to third parties (e.g., service providers, agents, or governmental authorities).
    • Other incidental business purposes.
  3. Disclosure:

    • We may disclose your personal data:
      • (a) to perform obligations related to goods and services requested by you; or
      • (b) to third-party service providers, agents, and organisations engaged by us for the above purposes.

Deemed Consent by Notification

  • We may collect, use, or disclose personal data for secondary purposes differing from the primary purpose by notifying you via appropriate communication channels.
  • Example: Advertisements.
  • You will have a reasonable period to opt out of this collection, use, or disclosure.
  • After the opt-out period, you may still withdraw consent by notifying us.


Reliance on the Legitimate Interests Exception

  • We may collect, use, or disclose your personal data without consent for our legitimate interests or those of others, after assessing and balancing adverse effects.

Examples:

  • Network analysis to prevent fraud and financial crime.
  • Data loss prevention on company-issued devices.

These purposes may apply even after your relationship with us has ended, for a reasonable period.



Withdrawing Your Consent

  • You may withdraw consent by submitting a written request or email to our Data Protection Officer (DPO).
  • Processing time: Up to 30 business days.
  • Withdrawal may affect our ability to provide goods or services. You will be notified of the implications before processing is complete.
  • Withdrawal does not affect our right to continue collecting, using, or disclosing data where permitted or required by law.


Access to and Correction of Personal Data

  • Requests for access or correction can be made in writing or via email to our DPO.
  • Access requests may incur a reasonable fee (informed before processing).
  • Response time: Within 30 business days or as informed if an extension is required.


Protection of Personal Data

We implement safeguards such as:

  • Authentication and access controls.
  • Encryption, data anonymisation, and antivirus protection.
  • Regular security reviews, patches, and testing.

While security measures are robust, no method is entirely secure. We continually enhance our security practices.



Accuracy of Personal Data

  • To ensure accuracy, please update us if your personal data changes by notifying our DPO in writing or via email.


Retention of Personal Data

  • Personal data is retained as long as necessary for its purpose or as required by law.
  • Data no longer needed will be securely deleted or anonymised.


Transfers of Personal Data Outside of Malaysia

  • We generally do not transfer personal data outside Malaysia. If such transfers are necessary, we will obtain your consent and ensure equivalent data protection standards.


Data Protection Officer

For enquiries, feedback, or requests, please contact:

Reference: https://www.pdp.gov.my/
Applies to the entire website: https://khidmatguaman.my



Effect of Notice and Changes to Notice

  • This Notice complements other notices, contractual terms, and consents related to personal data.
  • We may revise this Notice without prior notice. Changes will be updated with a revision date. Continued use of our services indicates acknowledgment and acceptance of changes.