SlideShare a Scribd company logo
1 of 30
Download to read offline
HALF-DAY PUBLIC SEMINAR ON
              MALAYSIAN PERSONAL DATA
             PROTECTION ACT (PDPA) 2010

                   25 July 2011, Monday, 9.30 am โ€“ 12 pm
             Legal Training Room, Menara SSM @ Sentral



                                            By Noriswadi Ismail
                                            Quotient Consulting




7/23/2011                 (c) 2011 Quotient Consulting, Information Is Invaluable
Vignette 1

    Harimau Malaya, Malaysian, holds a Malaysian
    ID, passport, driving license, 3 Malaysian bank
    accounts, 2 mobile accounts and 5 loyalty
    membership cards. His details are also
    registered in 2 private clinics, 1 government
    hospital and 2 insurance companies. He has 1
    bank account in London and Hong Kong
    respectively. He travels frequently for business
    and golfing. He is a director of 3 companies in
    Malaysia, London and Hong Kong. Also, an avid
    golfer of 3 golf clubs (Malaysia, Indonesia and
    Scotland).
7/23/2011                   (c) 2011 Quotient Consulting, Information Is Invaluable
Executive Summary
    Q: What is PDPA 2010?
    Q: Why we need to comply with PDPA 2010?
    Q: What are the 7 data protection principles?
    Q: Will PDPA 2010 kill my business operations?
    Q: To what extend PDPA 2010 affects your business operations?
    Q: We are a start-up and a semi medium sized company, how
    should we strategise?
    Q: When should we start?
    Q: Is there any additional compliance cost for this purpose?
    Q: How about formality and enforcement?
    Q: Whatโ€™s next and the must-to-do list?
    Q: How to ensure such data protection & privacy management
    sustainable?

7/23/2011                           (c) 2011 Quotient Consulting, Information Is Invaluable
What is PDPA 2010?
    ::: An Informational privacy legislation

    ::: 10 Parts (Preliminary, Personal Data Protection Principles,
    Registration, Data user forum and Code of practice, Rights of
    data subject, Exemption, Personal data Protection Fund,
    Personal Data Protection Advisory Committee, Appeal Tribunal,
    Inspection,   Complaint    and    Investigation,    Enforcement,
    Miscellaneous, Savings and Transitional Provisions)

    ::: 146 Sections

    ::: Jurisdiction: Malaysia




7/23/2011                                (c) 2011 Quotient Consulting, Information Is Invaluable
What is PDPA 2010?
     ::: Received Royal Assent on 2 June 2010, and gazetted a week
     later

     ::: Compliance commences: 3 months from the date of
     enforcement

     ::: Application: To commercial transactions only, not applicable
     to Federal and State Governments

     ::: Cross reference to: Electronic Commerce Act 2006โ€™s definition
     on commercial transactions โ€œโ€ฆany transaction of a commercial
     nature, whether contractual or not, which includes any matters
     relating to the supply or exchange of goods or services, agency,
     investments, financing, banking, insurance, but does not include
     a credit reporting business carried out by a credit reporting
     agencyโ€ฆโ€

7/23/2011                              (c) 2011 Quotient Consulting, Information is Invaluable.
What is PDPA 2010?
            โ€ข An authorised                                          โ€ข Oversees and
              person who                                               enforces the Laws
              processes data on                                      โ€ข Fund: Personal
              behalf of the data                                       Data Protection
              user                                                     Fund


                                      Data
                                                Regulator*
                                    Processor




                                      Data
                                                Data User
                                     Subject

            โ€ข Individual who is                                      โ€ข A person / legal
              the subject of the                                       person who
              personal data                                            controls /
                                                                       authorises the
                                                                       processing of data


7/23/2011                                       (c) 2011 Quotient Consulting, Information Is Invaluable
What is PDPA 2010?
                          *Regulator

                 Minister

             Data Protection
              Commissioner
              Personal Data                Data User Forum
            Protection Advisory
                Committee

             Appeal Tribunal




7/23/2011                         (c) 2011 Quotient Consulting, Information Is Invaluable
What is PDPA 2010?




                                           Question:
               Question:
                                          What about
               What about
                                         Government to
            Government Linked
                                         Governmentโ€™s
            Companies (GLCs)?
                                         engagements?




7/23/2011                       (c) 2011 Quotient Consulting, Information Is Invaluable
What is PDPA 2010?




                                             Question:
                  Question:                  What about
                                        transactions between
            What about transborder      government and non-
                  data flow?                governments?




7/23/2011                            (c) 2011 Quotient Consulting, Information Is Invaluable
Why We need to comply
                         with PDPA 2010?

                                    Recognition of privacy
                                    (informational) as one of the
                                    fundamental human rights




            Protection of invaluable data
            that are sensitive, being
            commoditised and having the
            vast potentials to being
            commoditised

7/23/2011                                   (c) 2011 Quotient Consulting, Information Is Invaluable
What are the 7 data protection
                        principles?

   P1: General Principles โ€“ Consent,          Sections 6(1) โ€“ (3)
   Lawful Purpose, Necessary, Adequate
   and Not Excessive
   P2 : Notice and Choice Principle           Section 7 (1)
   P3: Disclosure Principle                   Section 8, cross reference
                                              to Section 39
   P4: Security Principle                     Section 9(1) & (2)
   P5: Retention Principle                    Section 10
   P6: Data Integrity Principle               Section 11
   P7: Access Principle                       Section 12




7/23/2011                             (c) 2011 Quotient Consulting, Information Is Invaluable
Will PDPA 2010 kill my business operations?
    ::: Yes, if, your business operations are inconsistent and non
    compliance with the PDPA 2010โ€™s 7 data protection principles;

    ::: Yes, if, your business operations do not have the necessary
    framework, control, management and monitoring of the 7 data
    protection principlesโ€™ requirements;

    ::: No, as PDPA 2010 enhances trust, value and reputation of
    your business; and

    ::: No, as PDPA 2010 seeks to safeguard all of your data




7/23/2011                             (c) 2011 Quotient Consulting, Information Is Invaluable
To what extend PDPA 2010 affects
               your business operations?


                   Corporate Office
                                       Marketing &
                      (HR, Legal,
                                        Business
                   Finance, Audit &
                                       Development
                   Administration)




                      Business            Local &
                     Partners &        International
                     Contractors       engagements




7/23/2011                             (c) 2011 Quotient Consulting, Information Is Invaluable
To what extend PDPA 2010 affects
               your business operations?


                                      Documentation
                   Categorisation        (Forms,
                      of data         Agreements &
                                        Policies)




                   ICT deployment      Human capital
                                          (skills &
                    (Data security)      trainings)




7/23/2011                             (c) 2011 Quotient Consulting, Information Is Invaluable
We are a start-up and a semi medium sized
          company, how should we strategise?
                          Controls &
                           Systems
                          Planning &
                          Execution
              Partial                           Back-to-Back
            Outsourcing                         Arrangement
              Route                             & Execution



                          Adequacy




7/23/2011                       (c) 2011 Quotient Consulting, Information Is Invaluable
We are a start-up and a semi medium sized
          company, how should we strategise?

                             Cost


            Resources &                            Culture &
               Skills                             Awareness




                          Limitations




7/23/2011                        (c) 2011 Quotient Consulting, Information Is Invaluable
When should we start?
             Assumption 1     If the date of enforcement is
                              within Quarter 2 of 2012, itโ€™s
                              recommended to start the
                              planning & execution by Quarter
                              4 of 2011 โ€“ Quarter 1 of 2012
             Assumption 2     If the date of enforcement is
                              within Quarter 1 of 2012, itโ€™s
                              recommended to start the
                              planning & execution NOW
            Key Assumption    The proposed Malaysian Data
                              Protection Commissioner will be
                              established in Quarter 1 of 2012




7/23/2011                      (c) 2011 Quotient Consulting, Information Is Invaluable
Vignette 2
       Keranamu is a Government Consultant who
       advises on strategic acquisition of certain
       stakes in Company 76, a public listed
       company, incorporated in Hong Kong. The
       proposed acquisition is channeled through a
       leading    Government     Investment   arm.
       Company 76 appoints an European-based
       consultant to act on their behalf in the
       negotiations.




7/23/2011                   (c) 2011 Quotient Consulting, Information Is Invaluable
Is there any additional compliance cost
                       for this purpose?

       ::: Yes, subject to the budget, resource
       planning & business plans

       ::: No, if it has been anticipated




7/23/2011                       (c) 2011 Quotient Consulting, Information Is Invaluable
How about formality and enforcement?

            Registration of Data
                                                                      Power of
             User โ€“ Certificate     Report, complaint
                                                                    investigation,
                (Renewal,          and investigation by
                                                                   search & seizure
              Revocation &           Commissioner
                                                                     with warrant
                Surrender)




              Notification &
                                   Enforcement Notice               Power of arrest
             Access Request




              Inspection of            Variation or
              Personal Data          cancellation of                  Prosecution
                 System            Enforcement Notice




7/23/2011                                      (c) 2011 Quotient Consulting, Information Is Invaluable
How about formality and enforcement?

                                   Offences by body                 Jurisdiction:
                 Register
                                       corporate                   Sessions Court




            Transfer of personal
                                    Compounding of                  Protection of
               data to places
                                       offences                      Informers
              outside Malaysia




                                      Abetment and                Protection against
            Unlawful collecting
                                   attempt punishable               suit and legal
             of personal data
                                       as offences                   proceedings




7/23/2011                                     (c) 2011 Quotient Consulting, Information Is Invaluable
Vignette 3


       Truly Asia Travels & Tours has been appointed
       by some governmental agencies and private
       companies as their exclusive travel agent. The
       terms of reference include managing such
       flight, hotel, travel itinerary and related
       bookings. The amount of data processing of
       data subjects, transfers and sharing are done
       globally.




7/23/2011                     (c) 2011 Quotient Consulting, Information Is Invaluable
Whatโ€™s next and the to-do-list?


       ::: Strategic planning

       ::: Resource planning

       ::: Dissemination planning




7/23/2011                       (c) 2011 Quotient Consulting, Information Is Invaluable
Whatโ€™s next and the to-do-list?
    ::: Strategic planning

            Board Leadership    DPP as part and parcel of
                                organisation/companyโ€™s Key
                                Performance Indicators (KPIs)
            Senior Management   Driving DPP across the whole
                                spectrum of organisation/company
              Managers &        Overseeing & monitoring the
              Working Team      required affected portfolios that
                                intersect with PDPA 2010




7/23/2011                        (c) 2011 Quotient Consulting, Information Is Invaluable
Whatโ€™s next and the to-do-list?
    ::: Resource Planning

            Portfolio & Reporting     Subject to the setting of the
             creation/structure       Corporate Officeโ€™s structure
     Skills & knowledge enhancement Training, Consultation &
                                    Certification




7/23/2011                              (c) 2011 Quotient Consulting, Information Is Invaluable
Whatโ€™s next and the to-do-list?
    ::: Dissemination Planning

            Data Protection & Privacy   Across the organisation / company
                   Campaign
        Worldโ€™s Data Protection Day     28th January (of the year)
                   Event




7/23/2011                                (c) 2011 Quotient Consulting, Information Is Invaluable
How to ensure such data protection & privacy
              management sustainable?




                                            Trust
                         Monitored
                         compliance,
               Culture   controls and
                         execution



7/23/2011                    (c) 2011 Quotient Consulting, Information Is Invaluable
Vignette 4



       Hospitals A1, A2 & A3 are government
       hospitals. These hospitals deal with patients
       who mostly consist the public and engage with
       local and international consultants.




7/23/2011                    (c) 2011 Quotient Consulting, Information Is Invaluable
Vignette 5



       Universities B1, B2 & B3 are public
       universities. These universities engage with
       local and international students, consultants,
       international academics and universities
       globally.




7/23/2011                     (c) 2011 Quotient Consulting, Information Is Invaluable
THANK YOU



                                              QC          TM




                               London. Kuala Lumpur. Jakarta

            Data Diagnosis | Privacy Impact Assessment | Data Protection & Privacy Strategy
            Training | Data Protection & Privacy Certification | Public & Private Consultations



                                     <noriswadi@googlemail.com>




7/23/2011                                             (c) 2011 Quotient Consulting, Information Is Invaluable

More Related Content

What's hot

Personal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochurePersonal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochureJean Luc Creppy
ย 
Pdpa(kewal)
Pdpa(kewal)Pdpa(kewal)
Pdpa(kewal)Kewal Pradhan
ย 
The Personal Data Protection Act challenge in Singapore
The Personal Data Protection Act challenge in SingaporeThe Personal Data Protection Act challenge in Singapore
The Personal Data Protection Act challenge in SingaporeJean Luc Creppy
ย 
Saying "I Don't": the requirement of data subject consent for purposes of dat...
Saying "I Don't": the requirement of data subject consent for purposes of dat...Saying "I Don't": the requirement of data subject consent for purposes of dat...
Saying "I Don't": the requirement of data subject consent for purposes of dat...Werksmans Attorneys
ย 
Data Protection Act
Data Protection ActData Protection Act
Data Protection ActYizi
ย 
Personal data protection bill
Personal data protection bill Personal data protection bill
Personal data protection bill Mathew Chacko
ย 
Practical steps to take in preparation for the Protection of Personal Informa...
Practical steps to take in preparation for the Protection of Personal Informa...Practical steps to take in preparation for the Protection of Personal Informa...
Practical steps to take in preparation for the Protection of Personal Informa...Werksmans Attorneys
ย 
Startups - data protection
Startups  - data protectionStartups  - data protection
Startups - data protectionMathew Chacko
ย 
Personal Data Protection Bill 2018
Personal Data Protection Bill 2018Personal Data Protection Bill 2018
Personal Data Protection Bill 2018Nanda Mohan Shenoy
ย 
Put your left leg in, put your left leg out: the exclusions and exemptions of...
Put your left leg in, put your left leg out: the exclusions and exemptions of...Put your left leg in, put your left leg out: the exclusions and exemptions of...
Put your left leg in, put your left leg out: the exclusions and exemptions of...Werksmans Attorneys
ย 
Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Robert MacLean
ย 
Popi act presentation
Popi act presentationPopi act presentation
Popi act presentationKholisile Mazaza
ย 
The Data Protection Act
The Data Protection ActThe Data Protection Act
The Data Protection ActSaimaRafiq
ย 
The Data Protection Act What You Need To Know
The Data Protection Act   What You Need To KnowThe Data Protection Act   What You Need To Know
The Data Protection Act What You Need To KnowEamonnORagh
ย 
The Protection of Personal Information Act: A Presentation
The Protection of Personal Information Act: A PresentationThe Protection of Personal Information Act: A Presentation
The Protection of Personal Information Act: A PresentationEndcode_org
ย 
Documents, documents and more documents - is it time to spring clean? - Ahmor...
Documents, documents and more documents - is it time to spring clean? - Ahmor...Documents, documents and more documents - is it time to spring clean? - Ahmor...
Documents, documents and more documents - is it time to spring clean? - Ahmor...Werksmans Attorneys
ย 
Complying with Singapore Personal Data Protection Act - A Practical Guide
Complying with Singapore Personal Data Protection Act - A Practical GuideComplying with Singapore Personal Data Protection Act - A Practical Guide
Complying with Singapore Personal Data Protection Act - A Practical GuideDaniel Li
ย 
Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)Russell_Kennedy
ย 
The Protection of Personal Information Act 4 of 2013
The Protection of Personal Information Act 4 of 2013The Protection of Personal Information Act 4 of 2013
The Protection of Personal Information Act 4 of 2013Myron Duncan Burton Betshanger
ย 

What's hot (20)

Personal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochurePersonal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochure
ย 
Pdpa(kewal)
Pdpa(kewal)Pdpa(kewal)
Pdpa(kewal)
ย 
The Personal Data Protection Act challenge in Singapore
The Personal Data Protection Act challenge in SingaporeThe Personal Data Protection Act challenge in Singapore
The Personal Data Protection Act challenge in Singapore
ย 
Saying "I Don't": the requirement of data subject consent for purposes of dat...
Saying "I Don't": the requirement of data subject consent for purposes of dat...Saying "I Don't": the requirement of data subject consent for purposes of dat...
Saying "I Don't": the requirement of data subject consent for purposes of dat...
ย 
Data Protection Act
Data Protection ActData Protection Act
Data Protection Act
ย 
Personal data protection bill
Personal data protection bill Personal data protection bill
Personal data protection bill
ย 
Practical steps to take in preparation for the Protection of Personal Informa...
Practical steps to take in preparation for the Protection of Personal Informa...Practical steps to take in preparation for the Protection of Personal Informa...
Practical steps to take in preparation for the Protection of Personal Informa...
ย 
Startups - data protection
Startups  - data protectionStartups  - data protection
Startups - data protection
ย 
Personal Data Protection Bill 2018
Personal Data Protection Bill 2018Personal Data Protection Bill 2018
Personal Data Protection Bill 2018
ย 
Put your left leg in, put your left leg out: the exclusions and exemptions of...
Put your left leg in, put your left leg out: the exclusions and exemptions of...Put your left leg in, put your left leg out: the exclusions and exemptions of...
Put your left leg in, put your left leg out: the exclusions and exemptions of...
ย 
POPI
POPI POPI
POPI
ย 
Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)
ย 
Popi act presentation
Popi act presentationPopi act presentation
Popi act presentation
ย 
The Data Protection Act
The Data Protection ActThe Data Protection Act
The Data Protection Act
ย 
The Data Protection Act What You Need To Know
The Data Protection Act   What You Need To KnowThe Data Protection Act   What You Need To Know
The Data Protection Act What You Need To Know
ย 
The Protection of Personal Information Act: A Presentation
The Protection of Personal Information Act: A PresentationThe Protection of Personal Information Act: A Presentation
The Protection of Personal Information Act: A Presentation
ย 
Documents, documents and more documents - is it time to spring clean? - Ahmor...
Documents, documents and more documents - is it time to spring clean? - Ahmor...Documents, documents and more documents - is it time to spring clean? - Ahmor...
Documents, documents and more documents - is it time to spring clean? - Ahmor...
ย 
Complying with Singapore Personal Data Protection Act - A Practical Guide
Complying with Singapore Personal Data Protection Act - A Practical GuideComplying with Singapore Personal Data Protection Act - A Practical Guide
Complying with Singapore Personal Data Protection Act - A Practical Guide
ย 
Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)
ย 
The Protection of Personal Information Act 4 of 2013
The Protection of Personal Information Act 4 of 2013The Protection of Personal Information Act 4 of 2013
The Protection of Personal Information Act 4 of 2013
ย 

Similar to Half day public-seminar_on_pdpa_2010_-_250711

Half day public seminar on pdpa 2010 - 250711
Half day public seminar on pdpa 2010 - 250711Half day public seminar on pdpa 2010 - 250711
Half day public seminar on pdpa 2010 - 250711Quotient Consulting
ย 
Ethics In DW &amp; DM
Ethics In DW &amp; DMEthics In DW &amp; DM
Ethics In DW &amp; DMabethan
ย 
Oracle big data and rtd v5
Oracle big data and rtd v5Oracle big data and rtd v5
Oracle big data and rtd v5techsuda
ย 
Computational Intelligence Unconference Jul 2014 Data to Knowledge
Computational Intelligence Unconference Jul 2014 Data to Knowledge Computational Intelligence Unconference Jul 2014 Data to Knowledge
Computational Intelligence Unconference Jul 2014 Data to Knowledge John Morton
ย 
Regulation and Compliance in the Data Driven Enterprise
Regulation and Compliance in the Data Driven EnterpriseRegulation and Compliance in the Data Driven Enterprise
Regulation and Compliance in the Data Driven EnterpriseDenodo
ย 
6. thurs 345 430 steier - consuming and interacting with analytics
6. thurs 345 430 steier - consuming and interacting with analytics6. thurs 345 430 steier - consuming and interacting with analytics
6. thurs 345 430 steier - consuming and interacting with analyticsJon Hedlund
ย 
Compliance and Deliverability Workshop
Compliance and Deliverability WorkshopCompliance and Deliverability Workshop
Compliance and Deliverability WorkshopMatt Vernhout
ย 
Mobile Devices and Internet of Things
Mobile Devices and Internet of ThingsMobile Devices and Internet of Things
Mobile Devices and Internet of ThingsPaul Hastings
ย 
The top trends changing the landscape of Information Management
The top trends changing the landscape of Information ManagementThe top trends changing the landscape of Information Management
The top trends changing the landscape of Information ManagementVelrada
ย 
Healthcare Cyber Security Webinar
Healthcare Cyber Security WebinarHealthcare Cyber Security Webinar
Healthcare Cyber Security WebinarHealthCareManagement
ย 
Data Pioneers - Roland Haeve (Atos Nederland) - Big data in organisaties
Data Pioneers - Roland Haeve (Atos Nederland) - Big data in organisatiesData Pioneers - Roland Haeve (Atos Nederland) - Big data in organisaties
Data Pioneers - Roland Haeve (Atos Nederland) - Big data in organisatiesMultiscope
ย 
What is CT- DPO.pdf
What is CT- DPO.pdfWhat is CT- DPO.pdf
What is CT- DPO.pdftsaaroacademy
ย 
All the Change in the World: BCBSNC outsources IT infrastructure and changes ...
All the Change in the World: BCBSNC outsources IT infrastructure and changes ...All the Change in the World: BCBSNC outsources IT infrastructure and changes ...
All the Change in the World: BCBSNC outsources IT infrastructure and changes ...Information Services Group (ISG)
ย 
Enabling Interoperability through Standards & Architecture
Enabling Interoperability through Standards & ArchitectureEnabling Interoperability through Standards & Architecture
Enabling Interoperability through Standards & ArchitectureHealth Informatics New Zealand
ย 
Bitcoin wednesday (1) deloitte
Bitcoin wednesday (1) deloitteBitcoin wednesday (1) deloitte
Bitcoin wednesday (1) deloitteBitcoin Wednesday
ย 
Big data analytics for life insurers
Big data analytics for life insurersBig data analytics for life insurers
Big data analytics for life insurersdipak sahoo
ย 
Big_data_analytics_for_life_insurers_published
Big_data_analytics_for_life_insurers_publishedBig_data_analytics_for_life_insurers_published
Big_data_analytics_for_life_insurers_publishedShradha Verma
ย 
The Future of Data.docx
The Future of Data.docxThe Future of Data.docx
The Future of Data.docxUK Data Provider
ย 
IGNITION: Winning data strategies for publishers by Todd Teresi/Quantcast
IGNITION: Winning data strategies for publishers by Todd Teresi/Quantcast IGNITION: Winning data strategies for publishers by Todd Teresi/Quantcast
IGNITION: Winning data strategies for publishers by Todd Teresi/Quantcast Babbel
ย 
Who changed my data? Need for data governance and provenance in a streaming w...
Who changed my data? Need for data governance and provenance in a streaming w...Who changed my data? Need for data governance and provenance in a streaming w...
Who changed my data? Need for data governance and provenance in a streaming w...DataWorks Summit
ย 

Similar to Half day public-seminar_on_pdpa_2010_-_250711 (20)

Half day public seminar on pdpa 2010 - 250711
Half day public seminar on pdpa 2010 - 250711Half day public seminar on pdpa 2010 - 250711
Half day public seminar on pdpa 2010 - 250711
ย 
Ethics In DW &amp; DM
Ethics In DW &amp; DMEthics In DW &amp; DM
Ethics In DW &amp; DM
ย 
Oracle big data and rtd v5
Oracle big data and rtd v5Oracle big data and rtd v5
Oracle big data and rtd v5
ย 
Computational Intelligence Unconference Jul 2014 Data to Knowledge
Computational Intelligence Unconference Jul 2014 Data to Knowledge Computational Intelligence Unconference Jul 2014 Data to Knowledge
Computational Intelligence Unconference Jul 2014 Data to Knowledge
ย 
Regulation and Compliance in the Data Driven Enterprise
Regulation and Compliance in the Data Driven EnterpriseRegulation and Compliance in the Data Driven Enterprise
Regulation and Compliance in the Data Driven Enterprise
ย 
6. thurs 345 430 steier - consuming and interacting with analytics
6. thurs 345 430 steier - consuming and interacting with analytics6. thurs 345 430 steier - consuming and interacting with analytics
6. thurs 345 430 steier - consuming and interacting with analytics
ย 
Compliance and Deliverability Workshop
Compliance and Deliverability WorkshopCompliance and Deliverability Workshop
Compliance and Deliverability Workshop
ย 
Mobile Devices and Internet of Things
Mobile Devices and Internet of ThingsMobile Devices and Internet of Things
Mobile Devices and Internet of Things
ย 
The top trends changing the landscape of Information Management
The top trends changing the landscape of Information ManagementThe top trends changing the landscape of Information Management
The top trends changing the landscape of Information Management
ย 
Healthcare Cyber Security Webinar
Healthcare Cyber Security WebinarHealthcare Cyber Security Webinar
Healthcare Cyber Security Webinar
ย 
Data Pioneers - Roland Haeve (Atos Nederland) - Big data in organisaties
Data Pioneers - Roland Haeve (Atos Nederland) - Big data in organisatiesData Pioneers - Roland Haeve (Atos Nederland) - Big data in organisaties
Data Pioneers - Roland Haeve (Atos Nederland) - Big data in organisaties
ย 
What is CT- DPO.pdf
What is CT- DPO.pdfWhat is CT- DPO.pdf
What is CT- DPO.pdf
ย 
All the Change in the World: BCBSNC outsources IT infrastructure and changes ...
All the Change in the World: BCBSNC outsources IT infrastructure and changes ...All the Change in the World: BCBSNC outsources IT infrastructure and changes ...
All the Change in the World: BCBSNC outsources IT infrastructure and changes ...
ย 
Enabling Interoperability through Standards & Architecture
Enabling Interoperability through Standards & ArchitectureEnabling Interoperability through Standards & Architecture
Enabling Interoperability through Standards & Architecture
ย 
Bitcoin wednesday (1) deloitte
Bitcoin wednesday (1) deloitteBitcoin wednesday (1) deloitte
Bitcoin wednesday (1) deloitte
ย 
Big data analytics for life insurers
Big data analytics for life insurersBig data analytics for life insurers
Big data analytics for life insurers
ย 
Big_data_analytics_for_life_insurers_published
Big_data_analytics_for_life_insurers_publishedBig_data_analytics_for_life_insurers_published
Big_data_analytics_for_life_insurers_published
ย 
The Future of Data.docx
The Future of Data.docxThe Future of Data.docx
The Future of Data.docx
ย 
IGNITION: Winning data strategies for publishers by Todd Teresi/Quantcast
IGNITION: Winning data strategies for publishers by Todd Teresi/Quantcast IGNITION: Winning data strategies for publishers by Todd Teresi/Quantcast
IGNITION: Winning data strategies for publishers by Todd Teresi/Quantcast
ย 
Who changed my data? Need for data governance and provenance in a streaming w...
Who changed my data? Need for data governance and provenance in a streaming w...Who changed my data? Need for data governance and provenance in a streaming w...
Who changed my data? Need for data governance and provenance in a streaming w...
ย 

Recently uploaded

Booking open Available Pune Call Girls Talegaon Dabhade 6297143586 Call Hot ...
Booking open Available Pune Call Girls Talegaon Dabhade  6297143586 Call Hot ...Booking open Available Pune Call Girls Talegaon Dabhade  6297143586 Call Hot ...
Booking open Available Pune Call Girls Talegaon Dabhade 6297143586 Call Hot ...Call Girls in Nagpur High Profile
ย 
( Jasmin ) Top VIP Escorts Service Dindigul ๐Ÿ’ง 7737669865 ๐Ÿ’ง by Dindigul Call G...
( Jasmin ) Top VIP Escorts Service Dindigul ๐Ÿ’ง 7737669865 ๐Ÿ’ง by Dindigul Call G...( Jasmin ) Top VIP Escorts Service Dindigul ๐Ÿ’ง 7737669865 ๐Ÿ’ง by Dindigul Call G...
( Jasmin ) Top VIP Escorts Service Dindigul ๐Ÿ’ง 7737669865 ๐Ÿ’ง by Dindigul Call G...dipikadinghjn ( Why You Choose Us? ) Escorts
ย 
VIP Independent Call Girls in Andheri ๐ŸŒน 9920725232 ( Call Me ) Mumbai Escorts...
VIP Independent Call Girls in Andheri ๐ŸŒน 9920725232 ( Call Me ) Mumbai Escorts...VIP Independent Call Girls in Andheri ๐ŸŒน 9920725232 ( Call Me ) Mumbai Escorts...
VIP Independent Call Girls in Andheri ๐ŸŒน 9920725232 ( Call Me ) Mumbai Escorts...dipikadinghjn ( Why You Choose Us? ) Escorts
ย 
Vip Call US ๐Ÿ“ž 7738631006 โœ…Call Girls In Sakinaka ( Mumbai )
Vip Call US ๐Ÿ“ž 7738631006 โœ…Call Girls In Sakinaka ( Mumbai )Vip Call US ๐Ÿ“ž 7738631006 โœ…Call Girls In Sakinaka ( Mumbai )
Vip Call US ๐Ÿ“ž 7738631006 โœ…Call Girls In Sakinaka ( Mumbai )Pooja Nehwal
ย 
Gurley shaw Theory of Monetary Economics.
Gurley shaw Theory of Monetary Economics.Gurley shaw Theory of Monetary Economics.
Gurley shaw Theory of Monetary Economics.Vinodha Devi
ย 
Indore Real Estate Market Trends Report.pdf
Indore Real Estate Market Trends Report.pdfIndore Real Estate Market Trends Report.pdf
Indore Real Estate Market Trends Report.pdfSaviRakhecha1
ย 
Top Rated Pune Call Girls Dighi โŸŸ 6297143586 โŸŸ Call Me For Genuine Sex Servi...
Top Rated  Pune Call Girls Dighi โŸŸ 6297143586 โŸŸ Call Me For Genuine Sex Servi...Top Rated  Pune Call Girls Dighi โŸŸ 6297143586 โŸŸ Call Me For Genuine Sex Servi...
Top Rated Pune Call Girls Dighi โŸŸ 6297143586 โŸŸ Call Me For Genuine Sex Servi...Call Girls in Nagpur High Profile
ย 
Business Principles, Tools, and Techniques in Participating in Various Types...
Business Principles, Tools, and Techniques  in Participating in Various Types...Business Principles, Tools, and Techniques  in Participating in Various Types...
Business Principles, Tools, and Techniques in Participating in Various Types...jeffreytingson
ย 
Mira Road Awesome 100% Independent Call Girls NUmber-9833754194-Dahisar Inter...
Mira Road Awesome 100% Independent Call Girls NUmber-9833754194-Dahisar Inter...Mira Road Awesome 100% Independent Call Girls NUmber-9833754194-Dahisar Inter...
Mira Road Awesome 100% Independent Call Girls NUmber-9833754194-Dahisar Inter...priyasharma62062
ย 
Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...
Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...
Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...ssifa0344
ย 
VIP Call Girl in Thane ๐Ÿ’ง 9920725232 ( Call Me ) Get A New Crush Everyday With...
VIP Call Girl in Thane ๐Ÿ’ง 9920725232 ( Call Me ) Get A New Crush Everyday With...VIP Call Girl in Thane ๐Ÿ’ง 9920725232 ( Call Me ) Get A New Crush Everyday With...
VIP Call Girl in Thane ๐Ÿ’ง 9920725232 ( Call Me ) Get A New Crush Everyday With...dipikadinghjn ( Why You Choose Us? ) Escorts
ย 
Mira Road Memorable Call Grls Number-9833754194-Bhayandar Speciallty Call Gir...
Mira Road Memorable Call Grls Number-9833754194-Bhayandar Speciallty Call Gir...Mira Road Memorable Call Grls Number-9833754194-Bhayandar Speciallty Call Gir...
Mira Road Memorable Call Grls Number-9833754194-Bhayandar Speciallty Call Gir...priyasharma62062
ย 
TEST BANK For Corporate Finance, 13th Edition By Stephen Ross, Randolph Weste...
TEST BANK For Corporate Finance, 13th Edition By Stephen Ross, Randolph Weste...TEST BANK For Corporate Finance, 13th Edition By Stephen Ross, Randolph Weste...
TEST BANK For Corporate Finance, 13th Edition By Stephen Ross, Randolph Weste...ssifa0344
ย 
falcon-invoice-discounting-unlocking-prime-investment-opportunities
falcon-invoice-discounting-unlocking-prime-investment-opportunitiesfalcon-invoice-discounting-unlocking-prime-investment-opportunities
falcon-invoice-discounting-unlocking-prime-investment-opportunitiesFalcon Invoice Discounting
ย 
VIP Independent Call Girls in Mumbai ๐ŸŒน 9920725232 ( Call Me ) Mumbai Escorts ...
VIP Independent Call Girls in Mumbai ๐ŸŒน 9920725232 ( Call Me ) Mumbai Escorts ...VIP Independent Call Girls in Mumbai ๐ŸŒน 9920725232 ( Call Me ) Mumbai Escorts ...
VIP Independent Call Girls in Mumbai ๐ŸŒน 9920725232 ( Call Me ) Mumbai Escorts ...dipikadinghjn ( Why You Choose Us? ) Escorts
ย 
WhatsApp ๐Ÿ“ž Call : 9892124323 โœ…Call Girls In Chembur ( Mumbai ) secure service
WhatsApp ๐Ÿ“ž Call : 9892124323  โœ…Call Girls In Chembur ( Mumbai ) secure serviceWhatsApp ๐Ÿ“ž Call : 9892124323  โœ…Call Girls In Chembur ( Mumbai ) secure service
WhatsApp ๐Ÿ“ž Call : 9892124323 โœ…Call Girls In Chembur ( Mumbai ) secure servicePooja Nehwal
ย 
Call Girls Koregaon Park Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Koregaon Park Call Me 7737669865 Budget Friendly No Advance BookingCall Girls Koregaon Park Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Koregaon Park Call Me 7737669865 Budget Friendly No Advance Bookingroncy bisnoi
ย 
Webinar on E-Invoicing for Fintech Belgium
Webinar on E-Invoicing for Fintech BelgiumWebinar on E-Invoicing for Fintech Belgium
Webinar on E-Invoicing for Fintech BelgiumFinTech Belgium
ย 

Recently uploaded (20)

Booking open Available Pune Call Girls Talegaon Dabhade 6297143586 Call Hot ...
Booking open Available Pune Call Girls Talegaon Dabhade  6297143586 Call Hot ...Booking open Available Pune Call Girls Talegaon Dabhade  6297143586 Call Hot ...
Booking open Available Pune Call Girls Talegaon Dabhade 6297143586 Call Hot ...
ย 
( Jasmin ) Top VIP Escorts Service Dindigul ๐Ÿ’ง 7737669865 ๐Ÿ’ง by Dindigul Call G...
( Jasmin ) Top VIP Escorts Service Dindigul ๐Ÿ’ง 7737669865 ๐Ÿ’ง by Dindigul Call G...( Jasmin ) Top VIP Escorts Service Dindigul ๐Ÿ’ง 7737669865 ๐Ÿ’ง by Dindigul Call G...
( Jasmin ) Top VIP Escorts Service Dindigul ๐Ÿ’ง 7737669865 ๐Ÿ’ง by Dindigul Call G...
ย 
VIP Independent Call Girls in Andheri ๐ŸŒน 9920725232 ( Call Me ) Mumbai Escorts...
VIP Independent Call Girls in Andheri ๐ŸŒน 9920725232 ( Call Me ) Mumbai Escorts...VIP Independent Call Girls in Andheri ๐ŸŒน 9920725232 ( Call Me ) Mumbai Escorts...
VIP Independent Call Girls in Andheri ๐ŸŒน 9920725232 ( Call Me ) Mumbai Escorts...
ย 
Vip Call US ๐Ÿ“ž 7738631006 โœ…Call Girls In Sakinaka ( Mumbai )
Vip Call US ๐Ÿ“ž 7738631006 โœ…Call Girls In Sakinaka ( Mumbai )Vip Call US ๐Ÿ“ž 7738631006 โœ…Call Girls In Sakinaka ( Mumbai )
Vip Call US ๐Ÿ“ž 7738631006 โœ…Call Girls In Sakinaka ( Mumbai )
ย 
Gurley shaw Theory of Monetary Economics.
Gurley shaw Theory of Monetary Economics.Gurley shaw Theory of Monetary Economics.
Gurley shaw Theory of Monetary Economics.
ย 
Indore Real Estate Market Trends Report.pdf
Indore Real Estate Market Trends Report.pdfIndore Real Estate Market Trends Report.pdf
Indore Real Estate Market Trends Report.pdf
ย 
Top Rated Pune Call Girls Dighi โŸŸ 6297143586 โŸŸ Call Me For Genuine Sex Servi...
Top Rated  Pune Call Girls Dighi โŸŸ 6297143586 โŸŸ Call Me For Genuine Sex Servi...Top Rated  Pune Call Girls Dighi โŸŸ 6297143586 โŸŸ Call Me For Genuine Sex Servi...
Top Rated Pune Call Girls Dighi โŸŸ 6297143586 โŸŸ Call Me For Genuine Sex Servi...
ย 
Business Principles, Tools, and Techniques in Participating in Various Types...
Business Principles, Tools, and Techniques  in Participating in Various Types...Business Principles, Tools, and Techniques  in Participating in Various Types...
Business Principles, Tools, and Techniques in Participating in Various Types...
ย 
From Luxury Escort Service Kamathipura : 9352852248 Make on-demand Arrangemen...
From Luxury Escort Service Kamathipura : 9352852248 Make on-demand Arrangemen...From Luxury Escort Service Kamathipura : 9352852248 Make on-demand Arrangemen...
From Luxury Escort Service Kamathipura : 9352852248 Make on-demand Arrangemen...
ย 
(INDIRA) Call Girl Mumbai Call Now 8250077686 Mumbai Escorts 24x7
(INDIRA) Call Girl Mumbai Call Now 8250077686 Mumbai Escorts 24x7(INDIRA) Call Girl Mumbai Call Now 8250077686 Mumbai Escorts 24x7
(INDIRA) Call Girl Mumbai Call Now 8250077686 Mumbai Escorts 24x7
ย 
Mira Road Awesome 100% Independent Call Girls NUmber-9833754194-Dahisar Inter...
Mira Road Awesome 100% Independent Call Girls NUmber-9833754194-Dahisar Inter...Mira Road Awesome 100% Independent Call Girls NUmber-9833754194-Dahisar Inter...
Mira Road Awesome 100% Independent Call Girls NUmber-9833754194-Dahisar Inter...
ย 
Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...
Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...
Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...
ย 
VIP Call Girl in Thane ๐Ÿ’ง 9920725232 ( Call Me ) Get A New Crush Everyday With...
VIP Call Girl in Thane ๐Ÿ’ง 9920725232 ( Call Me ) Get A New Crush Everyday With...VIP Call Girl in Thane ๐Ÿ’ง 9920725232 ( Call Me ) Get A New Crush Everyday With...
VIP Call Girl in Thane ๐Ÿ’ง 9920725232 ( Call Me ) Get A New Crush Everyday With...
ย 
Mira Road Memorable Call Grls Number-9833754194-Bhayandar Speciallty Call Gir...
Mira Road Memorable Call Grls Number-9833754194-Bhayandar Speciallty Call Gir...Mira Road Memorable Call Grls Number-9833754194-Bhayandar Speciallty Call Gir...
Mira Road Memorable Call Grls Number-9833754194-Bhayandar Speciallty Call Gir...
ย 
TEST BANK For Corporate Finance, 13th Edition By Stephen Ross, Randolph Weste...
TEST BANK For Corporate Finance, 13th Edition By Stephen Ross, Randolph Weste...TEST BANK For Corporate Finance, 13th Edition By Stephen Ross, Randolph Weste...
TEST BANK For Corporate Finance, 13th Edition By Stephen Ross, Randolph Weste...
ย 
falcon-invoice-discounting-unlocking-prime-investment-opportunities
falcon-invoice-discounting-unlocking-prime-investment-opportunitiesfalcon-invoice-discounting-unlocking-prime-investment-opportunities
falcon-invoice-discounting-unlocking-prime-investment-opportunities
ย 
VIP Independent Call Girls in Mumbai ๐ŸŒน 9920725232 ( Call Me ) Mumbai Escorts ...
VIP Independent Call Girls in Mumbai ๐ŸŒน 9920725232 ( Call Me ) Mumbai Escorts ...VIP Independent Call Girls in Mumbai ๐ŸŒน 9920725232 ( Call Me ) Mumbai Escorts ...
VIP Independent Call Girls in Mumbai ๐ŸŒน 9920725232 ( Call Me ) Mumbai Escorts ...
ย 
WhatsApp ๐Ÿ“ž Call : 9892124323 โœ…Call Girls In Chembur ( Mumbai ) secure service
WhatsApp ๐Ÿ“ž Call : 9892124323  โœ…Call Girls In Chembur ( Mumbai ) secure serviceWhatsApp ๐Ÿ“ž Call : 9892124323  โœ…Call Girls In Chembur ( Mumbai ) secure service
WhatsApp ๐Ÿ“ž Call : 9892124323 โœ…Call Girls In Chembur ( Mumbai ) secure service
ย 
Call Girls Koregaon Park Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Koregaon Park Call Me 7737669865 Budget Friendly No Advance BookingCall Girls Koregaon Park Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Koregaon Park Call Me 7737669865 Budget Friendly No Advance Booking
ย 
Webinar on E-Invoicing for Fintech Belgium
Webinar on E-Invoicing for Fintech BelgiumWebinar on E-Invoicing for Fintech Belgium
Webinar on E-Invoicing for Fintech Belgium
ย 

Half day public-seminar_on_pdpa_2010_-_250711

  • 1. HALF-DAY PUBLIC SEMINAR ON MALAYSIAN PERSONAL DATA PROTECTION ACT (PDPA) 2010 25 July 2011, Monday, 9.30 am โ€“ 12 pm Legal Training Room, Menara SSM @ Sentral By Noriswadi Ismail Quotient Consulting 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 2. Vignette 1 Harimau Malaya, Malaysian, holds a Malaysian ID, passport, driving license, 3 Malaysian bank accounts, 2 mobile accounts and 5 loyalty membership cards. His details are also registered in 2 private clinics, 1 government hospital and 2 insurance companies. He has 1 bank account in London and Hong Kong respectively. He travels frequently for business and golfing. He is a director of 3 companies in Malaysia, London and Hong Kong. Also, an avid golfer of 3 golf clubs (Malaysia, Indonesia and Scotland). 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 3. Executive Summary Q: What is PDPA 2010? Q: Why we need to comply with PDPA 2010? Q: What are the 7 data protection principles? Q: Will PDPA 2010 kill my business operations? Q: To what extend PDPA 2010 affects your business operations? Q: We are a start-up and a semi medium sized company, how should we strategise? Q: When should we start? Q: Is there any additional compliance cost for this purpose? Q: How about formality and enforcement? Q: Whatโ€™s next and the must-to-do list? Q: How to ensure such data protection & privacy management sustainable? 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 4. What is PDPA 2010? ::: An Informational privacy legislation ::: 10 Parts (Preliminary, Personal Data Protection Principles, Registration, Data user forum and Code of practice, Rights of data subject, Exemption, Personal data Protection Fund, Personal Data Protection Advisory Committee, Appeal Tribunal, Inspection, Complaint and Investigation, Enforcement, Miscellaneous, Savings and Transitional Provisions) ::: 146 Sections ::: Jurisdiction: Malaysia 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 5. What is PDPA 2010? ::: Received Royal Assent on 2 June 2010, and gazetted a week later ::: Compliance commences: 3 months from the date of enforcement ::: Application: To commercial transactions only, not applicable to Federal and State Governments ::: Cross reference to: Electronic Commerce Act 2006โ€™s definition on commercial transactions โ€œโ€ฆany transaction of a commercial nature, whether contractual or not, which includes any matters relating to the supply or exchange of goods or services, agency, investments, financing, banking, insurance, but does not include a credit reporting business carried out by a credit reporting agencyโ€ฆโ€ 7/23/2011 (c) 2011 Quotient Consulting, Information is Invaluable.
  • 6. What is PDPA 2010? โ€ข An authorised โ€ข Oversees and person who enforces the Laws processes data on โ€ข Fund: Personal behalf of the data Data Protection user Fund Data Regulator* Processor Data Data User Subject โ€ข Individual who is โ€ข A person / legal the subject of the person who personal data controls / authorises the processing of data 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 7. What is PDPA 2010? *Regulator Minister Data Protection Commissioner Personal Data Data User Forum Protection Advisory Committee Appeal Tribunal 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 8. What is PDPA 2010? Question: Question: What about What about Government to Government Linked Governmentโ€™s Companies (GLCs)? engagements? 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 9. What is PDPA 2010? Question: Question: What about transactions between What about transborder government and non- data flow? governments? 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 10. Why We need to comply with PDPA 2010? Recognition of privacy (informational) as one of the fundamental human rights Protection of invaluable data that are sensitive, being commoditised and having the vast potentials to being commoditised 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 11. What are the 7 data protection principles? P1: General Principles โ€“ Consent, Sections 6(1) โ€“ (3) Lawful Purpose, Necessary, Adequate and Not Excessive P2 : Notice and Choice Principle Section 7 (1) P3: Disclosure Principle Section 8, cross reference to Section 39 P4: Security Principle Section 9(1) & (2) P5: Retention Principle Section 10 P6: Data Integrity Principle Section 11 P7: Access Principle Section 12 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 12. Will PDPA 2010 kill my business operations? ::: Yes, if, your business operations are inconsistent and non compliance with the PDPA 2010โ€™s 7 data protection principles; ::: Yes, if, your business operations do not have the necessary framework, control, management and monitoring of the 7 data protection principlesโ€™ requirements; ::: No, as PDPA 2010 enhances trust, value and reputation of your business; and ::: No, as PDPA 2010 seeks to safeguard all of your data 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 13. To what extend PDPA 2010 affects your business operations? Corporate Office Marketing & (HR, Legal, Business Finance, Audit & Development Administration) Business Local & Partners & International Contractors engagements 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 14. To what extend PDPA 2010 affects your business operations? Documentation Categorisation (Forms, of data Agreements & Policies) ICT deployment Human capital (skills & (Data security) trainings) 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 15. We are a start-up and a semi medium sized company, how should we strategise? Controls & Systems Planning & Execution Partial Back-to-Back Outsourcing Arrangement Route & Execution Adequacy 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 16. We are a start-up and a semi medium sized company, how should we strategise? Cost Resources & Culture & Skills Awareness Limitations 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 17. When should we start? Assumption 1 If the date of enforcement is within Quarter 2 of 2012, itโ€™s recommended to start the planning & execution by Quarter 4 of 2011 โ€“ Quarter 1 of 2012 Assumption 2 If the date of enforcement is within Quarter 1 of 2012, itโ€™s recommended to start the planning & execution NOW Key Assumption The proposed Malaysian Data Protection Commissioner will be established in Quarter 1 of 2012 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 18. Vignette 2 Keranamu is a Government Consultant who advises on strategic acquisition of certain stakes in Company 76, a public listed company, incorporated in Hong Kong. The proposed acquisition is channeled through a leading Government Investment arm. Company 76 appoints an European-based consultant to act on their behalf in the negotiations. 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 19. Is there any additional compliance cost for this purpose? ::: Yes, subject to the budget, resource planning & business plans ::: No, if it has been anticipated 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 20. How about formality and enforcement? Registration of Data Power of User โ€“ Certificate Report, complaint investigation, (Renewal, and investigation by search & seizure Revocation & Commissioner with warrant Surrender) Notification & Enforcement Notice Power of arrest Access Request Inspection of Variation or Personal Data cancellation of Prosecution System Enforcement Notice 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 21. How about formality and enforcement? Offences by body Jurisdiction: Register corporate Sessions Court Transfer of personal Compounding of Protection of data to places offences Informers outside Malaysia Abetment and Protection against Unlawful collecting attempt punishable suit and legal of personal data as offences proceedings 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 22. Vignette 3 Truly Asia Travels & Tours has been appointed by some governmental agencies and private companies as their exclusive travel agent. The terms of reference include managing such flight, hotel, travel itinerary and related bookings. The amount of data processing of data subjects, transfers and sharing are done globally. 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 23. Whatโ€™s next and the to-do-list? ::: Strategic planning ::: Resource planning ::: Dissemination planning 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 24. Whatโ€™s next and the to-do-list? ::: Strategic planning Board Leadership DPP as part and parcel of organisation/companyโ€™s Key Performance Indicators (KPIs) Senior Management Driving DPP across the whole spectrum of organisation/company Managers & Overseeing & monitoring the Working Team required affected portfolios that intersect with PDPA 2010 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 25. Whatโ€™s next and the to-do-list? ::: Resource Planning Portfolio & Reporting Subject to the setting of the creation/structure Corporate Officeโ€™s structure Skills & knowledge enhancement Training, Consultation & Certification 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 26. Whatโ€™s next and the to-do-list? ::: Dissemination Planning Data Protection & Privacy Across the organisation / company Campaign Worldโ€™s Data Protection Day 28th January (of the year) Event 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 27. How to ensure such data protection & privacy management sustainable? Trust Monitored compliance, Culture controls and execution 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 28. Vignette 4 Hospitals A1, A2 & A3 are government hospitals. These hospitals deal with patients who mostly consist the public and engage with local and international consultants. 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 29. Vignette 5 Universities B1, B2 & B3 are public universities. These universities engage with local and international students, consultants, international academics and universities globally. 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable
  • 30. THANK YOU QC TM London. Kuala Lumpur. Jakarta Data Diagnosis | Privacy Impact Assessment | Data Protection & Privacy Strategy Training | Data Protection & Privacy Certification | Public & Private Consultations <noriswadi@googlemail.com> 7/23/2011 (c) 2011 Quotient Consulting, Information Is Invaluable