PERSONAL DATA PROTECTION NOTICE AND CHOICE PRINCIPLE
NOTIFICATION AND CONSENT
Pursuant to sections 7 and 6, respectively, of the Personal Data Protection Act 2010
We hereby inform you that we, CPP Malaysia Sdn. Bhd. (“CPP”, “Company”, “we”:, “our” or “us”)) and our related corporations (as the term is defined in the Companies Act 2016), affiliates, and associated companies (whether or not controlled by us), are committed to safeguarding your privacy and pledge to observe the requirements of the relevant data protection and privacy law applicable to Malaysia. As data users, as the term is defined in the Personal Data Protection Act 2010 (“PDPA”), when you visit https://malaysia.cppdirect.com/ (the “Website”) we have or will collect, record, hold, store, use, disclose and / or process (collectively referred to as “Process”) personally identifiable information from you as set out in this Privacy Statement.
When you visit this Website, we will not collect any personally identifiable information from you other than as set out in the ‘Type of Personal Data Collected’ section below.
Except as specified in the “Purposes of Collection” section below, CPP will not disclose any of your personally identifiable information except when we have your permission or under special circumstances. CPP will take all reasonable steps to ensure the security in respect of personal data transmitted to and held by us.
If you have any queries in relation to this notification, please feel free to contact our Privacy Compliance Officer, whose contact details are set out in the ‘Privacy Compliance Officer – Contact Details’ section below.
Type of Personal Data Collected
We may collect and process the following data about you:
- Information you give us. This is information about you that you give us by filling in forms on our Website or by corresponding with us by phone, e-mail or otherwise. It includes information you provide if you use the ‘Contact Us’ form on the Website and/or if you register your interest via the Website in relation to a product that we offer. The information you give us may include your name, phone number and email address, as well as any such information we deem necessary or appropriate from time to time in connection with your commercial relationship with us.
To the extent that you wilfully and voluntarily disclose to us any personal information and/or personal data of another individual, we shall assume, without independent verification, that you have obtained such individual’s consent for the disclosure of such information and / or personal data as well as the processing of the same in accordance with the terms of this Privacy Statement.
Sources of Information
Your personal data has and / or will be obtained from the following sources or such other sources which we may see fit from time to time, where applicable,:
(a) information provided or submitted by you as set out in the ‘Type of Personal Data Collected’ section above;
(b) information collected by us as set out in the ‘Type of Personal Data Collected’ section above;
(c) as applicable, publicly available or publicly accessible information.
As the accuracy of your personal data depends largely on the information you provide to us, kindly inform us as soon as practicable if there are any errors in your personal data or if there have been any changes to your personal data.
Purposes of Processing
We may collect and Process personal data from users of this Website for any of the following purposes:
- to communicate with you via telephone, mail, e-mail, facsimile and/or any other communication means to respond to any communication you send to us via the ‘Contact Us’ form and/or when you register your interest on the Website in relation to products that we offer;
- for the facilitation of transactions / contractual dealings you have or may have with us;
- conducting direct marketing and promotional activities in connection with our services and related products for us, our vendors and business partners and other selected companies;
- complying with any requirements to make disclosures under any laws and regulations and other regulatory requirements binding on us or any of our group companies and affiliated companies;
- to administer the Website and for internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes;
- to improve the Website to ensure that content is presented in the most effective manner for you and for your computer;
- in order to fulfil any purpose directly related to the purposes above.
Disclosure of Personal Data
Your personal information will be shared with authorised third party service providers, whether within or out of Malaysia, who perform services on our behalf (e.g. providing IT support and maintenance). These service providers may have access to personal information needed to perform their services, but are not permitted to share or to use this for any other purpose. Your personal information may also be disclosed to: (i) other entities within the CPP group and may be transferred out of Malaysia for purposes of data storage and managing your information more securely and efficiently at group level; and (ii) to any government authorities or to any person to whom we are compelled or required to do so under law.
In accordance with the requirements of the PDPA, we will honor an individual’s request not to use his or her personal data for the purposes of direct marketing. Should you wish not to receive direct marketing material from us, please address this request to CPP’s Compliance Officer, whose contact details are stipulated below. Any such request should clearly be supported by sufficient information in relation to the request being made.
Unless otherwise instructed as per the above, we may use any personal data collected in the normal course of business for marketing purposes.
Impact resulting from failure to supply Personal Data
Except for personal data collected or processed for direct marketing purposes, it is obligatory for you to provide all of the categories of personal data which we request from you on the ‘Contact Us’ form and/or when you register your interest in relation to products we offer. Failure to supply personal data in this regard will result in us being unable to provide you with the information, and / or services requested.
Access and Correction of Personal Data
Users of this Website have the right to request access to and/or correction of their personal data held by us. In accordance with the Personal Information Collection Statement and subject only to you paying us a reasonable fee for making such a request, you have the right to:
(i) check whether we hold personal data about you and, if so, obtain a copy of such personal data;
(ii) request that we correct any personal data relating to you that is inaccurate, incomplete or out-of -date;
(iii) ascertain our policies and practices in relation to personal data and to be informed of the kind of personal data held by us; and
(iv)request that we limit the manner in which we process your personal data.
We will, upon satisfying ourselves of the authenticity and validity of the correction request, make every endeavour to comply with and respond to the request within the period set by the PDPA.
Security of Personal Data
Physical records containing personal data are securely stored in locked areas and/or containers when not in use.
Access to records and personal data without appropriate management authorization are strictly prohibited. Authorizations are granted to authorised personnel only on a “need to know” basis that is commensurate with the individual’s responsibilities and their training.
Records we hold are under the control of assigned information officers who are responsible to ensure the transfer of or access to information is legitimate and complies with the PDPA. Audit records may be produced to validate data modifications in order to verify the data’s integrity.
There may be violations logging processes for investigation of any unauthorized attempt to access information. Encryption technology, such as SSL, may be employed for the transmission of data collected online
Privacy Compliance Officer – Contact Details
All enquiries regarding our compliance with our obligations under the PDPA and / or requests to access or correct any personal data thereof should be addressed to:
The Compliance Manager, CPP Malaysia Sdn. Bhd., Level 27, (Penthouse), Centrepoint South, The Boulevard Mid Valley City Lingkaran Syed Putra, 59200 Kuala Lumpur, at email@example.com, Tel :+603 20969577 Fax : +603 2096 9797