SlideShare a Scribd company logo
1 of 15
Download to read offline
Malaysia: Personal
Data Protection Act
(PDPA) 2010
Hairul Hafiz B Hasbullah
Data Protection (Part 3)
Implementation of security to
protect data
Where Are We? : Stage 2
• Awareness program on PDPA 2010
• Establish a data protection task force
• Conduct a Privacy Impact Assessment
• Obtain Consent for use of personal data
• Prepare standard data protection notice and
clause in Agreement
Where Are We? : Stage 2
(After Briefing on 12-13 April 2017)
• Review plan established during Stage 1
• Establish procedures and forms to handle
data protection complaints
• Establish processes for training of relevant
staff
• Implementation of security to protect data
(a) physical access
(b) electronic access
Action Plan : Stage 3
• Implementation of security to protect data
(a) Electronic access
(b) Non-electronic access
(c) Retention standard
(d) Data Integrity standard
NO DESCRIPTIONS Person In-
charge
(PIC)/Depart
1 Register all employees involved in the processing of
personal data
BE/MME/HR
2 Terminate an employee’s access rights to personal
data after his/her resignation, termination, termination
of contract or agreement, or adjustment in accordance
with changes in MyCEB
HR/IT
3 Control and limit employees’ access to personal data
system for the purpose of collecting, processing and
storing of personal data
BE/MME/HR/IT
4 Provide user ID and password for authorised
employees to access personal data
BE/MME/HR/IT
A Establishment of the Security Standard for
Personal Data Processed for Electronic
NO DESCRIPTIONS Person In-
charge
(PIC)/Depart
5 Terminate user ID and password immediately when an
employee who is authorised access to personal data
is no longer handling the data
BE/MME/HR
6 Establish physical security procedures as follows:
i. Control the movement in an out of the data storage
site
ii. Storage personal data in an appropriate location
which is unexposed and safe from physical or
natural threats
IT
7 Update the Back up/ Recovery system and anti-virus
to prevent personal data intrusion and such
IT
Establishment of the Security Standard for
Personal Data Processed for Electronic
NO DESCRIPTIONS Person In-
charge
(PIC)/Depart
8 Safeguard the computer system from malware threats
to prevent attacks on personal data
IT
9 The transfer of personal data through removable
media device and cloud computing service is not
permitted unless with written consent by an officer
authorised by the management of the MyCEB data
user
BE/MME
10 Record any transfer of data through removable media
device and cloud computing service
BE/MME/HR
Establishment of the Security Standard for
Personal Data Processed for Electronic
NO DESCRIPTIONS Person In-
charge
(PIC)/Depart
11 Personal data transfer through cloud computing
service must comply with the personal data protection
principles in Malaysia, as well as with personal data
protection laws of other countries.
LEGAL
12 Ensure that all employees involved in processing
personal data always protect the confidentiality of the
data subject’s personal data.
BE/MME/HR
13 Bind an appointed third party by the data user with a
contract for operating and carrying out personal data
processing activities. This is to ensure the safety of
personal data from loss, misuse, modification,
unauthorised access and disclosure.
LEGAL
Establishment of the Security Standard for
Personal Data Processed for Electronic
NO DESCRIPTIONS Person In-
charge
(PIC)/Depart
1 Register employees handling personal data into a
system/registration book before allowed access to
personal data
BE/MME/HR
2 Terminate an employee’s access rights to personal
data after his/her resignation, termination, termination
of contract or agreement, or adjustment in accordance
with changes in MyCEB
BE/MME/HR/IT
3 Control and limit employees’ access to personal data
system for the purpose of collecting, processing and
storing of personal data
BE/MME/HR
B Establishment of the security standard for
personal data processed for non -electronic
NO DESCRIPTIONS Person In-
charge
(PIC)/Depart
4 Establish physical security procedures as follows:
i. Store all personal data orderly in files; and
ii. Store all files containing personal data in a locked
place
BE/MME/HR
5 Maintain a proper record access to personal data
periodically and make such record the confidentiality
of the data subject’s personal data
BE/MME/HR
6 Record personal data transferred conventionally such
as through mail, delivery, fax and etc
BE/MME/HR
Establishment of the security standard for
personal data processed for non -electronic
NO DESCRIPTIONS Person In-
charge
(PIC)/Depart
7 Ensure that all used papers, printed documents or
other documents exhibiting personal data are
destroyed thoroughly and efficiently by using
shredding machine or other appropriate methods
BE/MME/HR
8 Conduct awareness programmes to all employees on
the responsibility to protect personal data
LEGAL
Establishment of the security standard for
personal data processed for non -electronic
NO DESCRIPTIONS Person In-
charge
(PIC)/Depart
1 Determine the retention period relating to the
processing and retention personal data are fulfilled
before destroying the data ( normal practice is within 6
years)
BE/MME/HR
2 Keep personal data no longer than necessary unless
there are requirements by other legal provisions
BE/MME/HR
3 Maintain a proper record of personal data disposal
periodically
BE/MME/HR
C Establishment of the Retention Standard
NO DESCRIPTIONS Person In-
charge
(PIC)/Depart
4 Dispose personal data collection forms used in
commercial transactions within the period not
exceeding 14 days, except if the forms carry legal
values in relation to the commercial transaction
BE/MME/HR
5 Review and dispose all unwanted personal data in the
database (eg MyCEB CRM)
BE/MME/HR
6 Prepare a personal data disposal schedule for inactive
data with a 24 month period.
BE/MME/HR
7 The use of removable media device for storing
personal data is not permitted without written approval
from MyCEB management.
BE/MME/HR/IT
Establishment of the Retention Standard
NO DESCRIPTIONS Person In-
charge
(PIC)/Depart
1 Provide personal data update form for data subjects,
either via online or conventional
LEGAL
2 Update personal data immediately once data
correction notice is received from data subject
BE/MME/HR
3 Ensure that all relevant legislation is fulfilled in
determining the type of documents required to support
the validity of the data subject’s personal data
LEGAL
4 Notify on personal data updates either through the
portal or notice at premises or by other appropriate
methods
MARCOM
D Establishment of the Data Integrity Standard
CONGRATULATIONS!
You have just completed Privacy and Personal
data (Part 1) under MyCEB Personal Data Protection
2010
THANK YOU

More Related Content

What's hot

Data Protection Act
Data Protection ActData Protection Act
Data Protection Actmrmwood
 
Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)Russell_Kennedy
 
Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Andrew Sharpe
 
Impact of ict on privacy and personal data
Impact of ict on privacy and personal dataImpact of ict on privacy and personal data
Impact of ict on privacy and personal datamohd kamal
 
Personal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochurePersonal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochureJean Luc Creppy
 
Highlights of the Singapore Personal Data Protection Act 2012
Highlights of the Singapore Personal Data Protection Act 2012Highlights of the Singapore Personal Data Protection Act 2012
Highlights of the Singapore Personal Data Protection Act 2012Fuji Xerox Singapore
 
Data Protection Guidelines
Data Protection GuidelinesData Protection Guidelines
Data Protection GuidelinesDavid Scanlon
 
A quick look at gdpr
A quick look at gdprA quick look at gdpr
A quick look at gdprCookieYes
 
General data protection
General data protectionGeneral data protection
General data protectionBrijeshR3
 
Merit Event - Understanding and Managing Data Protection
Merit Event - Understanding and Managing Data ProtectionMerit Event - Understanding and Managing Data Protection
Merit Event - Understanding and Managing Data Protectionmeritnorthwest
 
Data protection act
Data protection act Data protection act
Data protection act Iqbal Bocus
 
Intercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkitIntercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkitjoshquarrie
 
Data protection ppt
Data protection pptData protection ppt
Data protection pptgrahamwell
 
Safety And Security Of Data 4
Safety And Security Of Data 4Safety And Security Of Data 4
Safety And Security Of Data 4Wynthorpe
 
Applying the Personal Data Protection Act (Singapore)
Applying the Personal Data Protection Act (Singapore)Applying the Personal Data Protection Act (Singapore)
Applying the Personal Data Protection Act (Singapore)Benjamin Ang
 
Data Privacy in India and data theft
Data Privacy in India and data theftData Privacy in India and data theft
Data Privacy in India and data theftAmber Gupta
 
PDPA Compliance Preparation
PDPA Compliance PreparationPDPA Compliance Preparation
PDPA Compliance PreparationLawPlus Ltd.
 
HOW TO PROCESS DATA IN VARIOUS GEO'S A COMPARATIVE ANALYSIS BY SANJEEV SINGH...
HOW TO PROCESS DATA IN VARIOUS GEO'S A  COMPARATIVE ANALYSIS BY SANJEEV SINGH...HOW TO PROCESS DATA IN VARIOUS GEO'S A  COMPARATIVE ANALYSIS BY SANJEEV SINGH...
HOW TO PROCESS DATA IN VARIOUS GEO'S A COMPARATIVE ANALYSIS BY SANJEEV SINGH...Sanjeev Bharwan
 
GDPR and WHOIS Compliance - Impact on Indian Stakeholders
GDPR and WHOIS Compliance - Impact on Indian StakeholdersGDPR and WHOIS Compliance - Impact on Indian Stakeholders
GDPR and WHOIS Compliance - Impact on Indian StakeholdersServerGuy
 

What's hot (20)

Data Protection Act
Data Protection ActData Protection Act
Data Protection Act
 
Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)
 
Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)
 
Impact of ict on privacy and personal data
Impact of ict on privacy and personal dataImpact of ict on privacy and personal data
Impact of ict on privacy and personal data
 
Personal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochurePersonal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochure
 
Highlights of the Singapore Personal Data Protection Act 2012
Highlights of the Singapore Personal Data Protection Act 2012Highlights of the Singapore Personal Data Protection Act 2012
Highlights of the Singapore Personal Data Protection Act 2012
 
Data Protection Guidelines
Data Protection GuidelinesData Protection Guidelines
Data Protection Guidelines
 
A quick look at gdpr
A quick look at gdprA quick look at gdpr
A quick look at gdpr
 
General data protection
General data protectionGeneral data protection
General data protection
 
Merit Event - Understanding and Managing Data Protection
Merit Event - Understanding and Managing Data ProtectionMerit Event - Understanding and Managing Data Protection
Merit Event - Understanding and Managing Data Protection
 
Data protection act
Data protection act Data protection act
Data protection act
 
Intercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkitIntercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkit
 
Popi act presentation
Popi act presentationPopi act presentation
Popi act presentation
 
Data protection ppt
Data protection pptData protection ppt
Data protection ppt
 
Safety And Security Of Data 4
Safety And Security Of Data 4Safety And Security Of Data 4
Safety And Security Of Data 4
 
Applying the Personal Data Protection Act (Singapore)
Applying the Personal Data Protection Act (Singapore)Applying the Personal Data Protection Act (Singapore)
Applying the Personal Data Protection Act (Singapore)
 
Data Privacy in India and data theft
Data Privacy in India and data theftData Privacy in India and data theft
Data Privacy in India and data theft
 
PDPA Compliance Preparation
PDPA Compliance PreparationPDPA Compliance Preparation
PDPA Compliance Preparation
 
HOW TO PROCESS DATA IN VARIOUS GEO'S A COMPARATIVE ANALYSIS BY SANJEEV SINGH...
HOW TO PROCESS DATA IN VARIOUS GEO'S A  COMPARATIVE ANALYSIS BY SANJEEV SINGH...HOW TO PROCESS DATA IN VARIOUS GEO'S A  COMPARATIVE ANALYSIS BY SANJEEV SINGH...
HOW TO PROCESS DATA IN VARIOUS GEO'S A COMPARATIVE ANALYSIS BY SANJEEV SINGH...
 
GDPR and WHOIS Compliance - Impact on Indian Stakeholders
GDPR and WHOIS Compliance - Impact on Indian StakeholdersGDPR and WHOIS Compliance - Impact on Indian Stakeholders
GDPR and WHOIS Compliance - Impact on Indian Stakeholders
 

Similar to PDPA 2010 (Part 4) by Hairul Hafiz Hasbullah

Data privacy team meeting
Data privacy team meetingData privacy team meeting
Data privacy team meetingrrosas0731
 
Managing Data Protection guide powerpoint presentation
Managing Data Protection guide powerpoint presentationManaging Data Protection guide powerpoint presentation
Managing Data Protection guide powerpoint presentationsilvereyez11
 
IAPP Canada Privacy Symposium- "Data Retention Is a Team Sport: How to Get It...
IAPP Canada Privacy Symposium- "Data Retention Is a Team Sport: How to Get It...IAPP Canada Privacy Symposium- "Data Retention Is a Team Sport: How to Get It...
IAPP Canada Privacy Symposium- "Data Retention Is a Team Sport: How to Get It...Blancco
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Qualsys Ltd
 
GDPR Benefits and a Technical Overview
GDPR  Benefits and a Technical OverviewGDPR  Benefits and a Technical Overview
GDPR Benefits and a Technical OverviewErnest Staats
 
Data protection process information
Data protection process informationData protection process information
Data protection process informationyourlegalconsultants
 
Compliance audit under the Information Technology Act, 2000
Compliance audit under the Information Technology Act, 2000Compliance audit under the Information Technology Act, 2000
Compliance audit under the Information Technology Act, 2000Sagar Rahurkar
 
Security Industry Association Privacy Framework
Security Industry Association Privacy FrameworkSecurity Industry Association Privacy Framework
Security Industry Association Privacy Framework- Mark - Fullbright
 
DATA PROTECTION IMPACT ASSESSMENT TEMPLATE (ODPC).docx
DATA PROTECTION IMPACT ASSESSMENT TEMPLATE (ODPC).docxDATA PROTECTION IMPACT ASSESSMENT TEMPLATE (ODPC).docx
DATA PROTECTION IMPACT ASSESSMENT TEMPLATE (ODPC).docxSteveNgigi2
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceCobweb
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion
 
Personal Data Protection in Indonesia
Personal Data Protection in IndonesiaPersonal Data Protection in Indonesia
Personal Data Protection in IndonesiaEryk Budi Pratama
 
Mass Information Security Requirements January 2010
Mass Information Security Requirements January 2010Mass Information Security Requirements January 2010
Mass Information Security Requirements January 2010madamseane
 
Consent form for TESDA
Consent form for TESDAConsent form for TESDA
Consent form for TESDAGieKo
 
Compliance poster
Compliance posterCompliance poster
Compliance posterRui Gomes
 
Data protection training emea new joiners. mandatory quiz
Data protection training emea new joiners. mandatory quizData protection training emea new joiners. mandatory quiz
Data protection training emea new joiners. mandatory quizDeborahchiesa
 

Similar to PDPA 2010 (Part 4) by Hairul Hafiz Hasbullah (20)

Data privacy team meeting
Data privacy team meetingData privacy team meeting
Data privacy team meeting
 
Managing Data Protection guide powerpoint presentation
Managing Data Protection guide powerpoint presentationManaging Data Protection guide powerpoint presentation
Managing Data Protection guide powerpoint presentation
 
Group 10 - PDPA II.pptx
Group 10 - PDPA II.pptxGroup 10 - PDPA II.pptx
Group 10 - PDPA II.pptx
 
IAPP Canada Privacy Symposium- "Data Retention Is a Team Sport: How to Get It...
IAPP Canada Privacy Symposium- "Data Retention Is a Team Sport: How to Get It...IAPP Canada Privacy Symposium- "Data Retention Is a Team Sport: How to Get It...
IAPP Canada Privacy Symposium- "Data Retention Is a Team Sport: How to Get It...
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
 
GDPR Benefits and a Technical Overview
GDPR  Benefits and a Technical OverviewGDPR  Benefits and a Technical Overview
GDPR Benefits and a Technical Overview
 
Data protection process information
Data protection process informationData protection process information
Data protection process information
 
Compliance audit under the Information Technology Act, 2000
Compliance audit under the Information Technology Act, 2000Compliance audit under the Information Technology Act, 2000
Compliance audit under the Information Technology Act, 2000
 
Security Industry Association Privacy Framework
Security Industry Association Privacy FrameworkSecurity Industry Association Privacy Framework
Security Industry Association Privacy Framework
 
DATA PROTECTION IMPACT ASSESSMENT TEMPLATE (ODPC).docx
DATA PROTECTION IMPACT ASSESSMENT TEMPLATE (ODPC).docxDATA PROTECTION IMPACT ASSESSMENT TEMPLATE (ODPC).docx
DATA PROTECTION IMPACT ASSESSMENT TEMPLATE (ODPC).docx
 
GDPR, Data Privacy.
GDPR, Data Privacy.GDPR, Data Privacy.
GDPR, Data Privacy.
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
Living with gdpr
Living with gdprLiving with gdpr
Living with gdpr
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
 
GDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
GDPR: 3 Months On | Guest Speaker: Data Protection CommissionersGDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
GDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
 
Personal Data Protection in Indonesia
Personal Data Protection in IndonesiaPersonal Data Protection in Indonesia
Personal Data Protection in Indonesia
 
Mass Information Security Requirements January 2010
Mass Information Security Requirements January 2010Mass Information Security Requirements January 2010
Mass Information Security Requirements January 2010
 
Consent form for TESDA
Consent form for TESDAConsent form for TESDA
Consent form for TESDA
 
Compliance poster
Compliance posterCompliance poster
Compliance poster
 
Data protection training emea new joiners. mandatory quiz
Data protection training emea new joiners. mandatory quizData protection training emea new joiners. mandatory quiz
Data protection training emea new joiners. mandatory quiz
 

Recently uploaded

Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126Oishi8
 
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书Fir L
 
How You Can Get a Turkish Digital Nomad Visa
How You Can Get a Turkish Digital Nomad VisaHow You Can Get a Turkish Digital Nomad Visa
How You Can Get a Turkish Digital Nomad VisaBridgeWest.eu
 
定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一
定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一
定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一st Las
 
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...Dr. Oliver Massmann
 
如何办理(KPU毕业证书)加拿大昆特兰理工大学毕业证学位证书
 如何办理(KPU毕业证书)加拿大昆特兰理工大学毕业证学位证书 如何办理(KPU毕业证书)加拿大昆特兰理工大学毕业证学位证书
如何办理(KPU毕业证书)加拿大昆特兰理工大学毕业证学位证书Fir sss
 
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝soniya singh
 
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一jr6r07mb
 
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书Fs Las
 
一比一原版旧金山州立大学毕业证学位证书
 一比一原版旧金山州立大学毕业证学位证书 一比一原版旧金山州立大学毕业证学位证书
一比一原版旧金山州立大学毕业证学位证书SS A
 
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书FS LS
 
POLICE ACT, 1861 the details about police system.pptx
POLICE ACT, 1861 the details about police system.pptxPOLICE ACT, 1861 the details about police system.pptx
POLICE ACT, 1861 the details about police system.pptxAbhishekchatterjee248859
 
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书Fs Las
 
Offences against property (TRESPASS, BREAKING
Offences against property (TRESPASS, BREAKINGOffences against property (TRESPASS, BREAKING
Offences against property (TRESPASS, BREAKINGPRAKHARGUPTA419620
 
Test Identification Parade & Dying Declaration.pptx
Test Identification Parade & Dying Declaration.pptxTest Identification Parade & Dying Declaration.pptx
Test Identification Parade & Dying Declaration.pptxsrikarna235
 
Key Factors That Influence Property Tax Rates
Key Factors That Influence Property Tax RatesKey Factors That Influence Property Tax Rates
Key Factors That Influence Property Tax RatesHome Tax Saver
 
如何办理(Rice毕业证书)莱斯大学毕业证学位证书
如何办理(Rice毕业证书)莱斯大学毕业证学位证书如何办理(Rice毕业证书)莱斯大学毕业证学位证书
如何办理(Rice毕业证书)莱斯大学毕业证学位证书SD DS
 
Trial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 seditionTrial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 seditionNilamPadekar1
 

Recently uploaded (20)

Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126
 
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
 
How You Can Get a Turkish Digital Nomad Visa
How You Can Get a Turkish Digital Nomad VisaHow You Can Get a Turkish Digital Nomad Visa
How You Can Get a Turkish Digital Nomad Visa
 
Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...
Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...
Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...
 
定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一
定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一
定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一
 
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
 
如何办理(KPU毕业证书)加拿大昆特兰理工大学毕业证学位证书
 如何办理(KPU毕业证书)加拿大昆特兰理工大学毕业证学位证书 如何办理(KPU毕业证书)加拿大昆特兰理工大学毕业证学位证书
如何办理(KPU毕业证书)加拿大昆特兰理工大学毕业证学位证书
 
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
 
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一
 
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
 
一比一原版旧金山州立大学毕业证学位证书
 一比一原版旧金山州立大学毕业证学位证书 一比一原版旧金山州立大学毕业证学位证书
一比一原版旧金山州立大学毕业证学位证书
 
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书
 
Vip Call Girls Greater Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Greater Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS LiveVip Call Girls Greater Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Greater Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
 
POLICE ACT, 1861 the details about police system.pptx
POLICE ACT, 1861 the details about police system.pptxPOLICE ACT, 1861 the details about police system.pptx
POLICE ACT, 1861 the details about police system.pptx
 
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
 
Offences against property (TRESPASS, BREAKING
Offences against property (TRESPASS, BREAKINGOffences against property (TRESPASS, BREAKING
Offences against property (TRESPASS, BREAKING
 
Test Identification Parade & Dying Declaration.pptx
Test Identification Parade & Dying Declaration.pptxTest Identification Parade & Dying Declaration.pptx
Test Identification Parade & Dying Declaration.pptx
 
Key Factors That Influence Property Tax Rates
Key Factors That Influence Property Tax RatesKey Factors That Influence Property Tax Rates
Key Factors That Influence Property Tax Rates
 
如何办理(Rice毕业证书)莱斯大学毕业证学位证书
如何办理(Rice毕业证书)莱斯大学毕业证学位证书如何办理(Rice毕业证书)莱斯大学毕业证学位证书
如何办理(Rice毕业证书)莱斯大学毕业证学位证书
 
Trial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 seditionTrial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 sedition
 

PDPA 2010 (Part 4) by Hairul Hafiz Hasbullah

  • 1. Malaysia: Personal Data Protection Act (PDPA) 2010 Hairul Hafiz B Hasbullah Data Protection (Part 3) Implementation of security to protect data
  • 2. Where Are We? : Stage 2 • Awareness program on PDPA 2010 • Establish a data protection task force • Conduct a Privacy Impact Assessment • Obtain Consent for use of personal data • Prepare standard data protection notice and clause in Agreement
  • 3. Where Are We? : Stage 2 (After Briefing on 12-13 April 2017) • Review plan established during Stage 1 • Establish procedures and forms to handle data protection complaints • Establish processes for training of relevant staff • Implementation of security to protect data (a) physical access (b) electronic access
  • 4. Action Plan : Stage 3 • Implementation of security to protect data (a) Electronic access (b) Non-electronic access (c) Retention standard (d) Data Integrity standard
  • 5. NO DESCRIPTIONS Person In- charge (PIC)/Depart 1 Register all employees involved in the processing of personal data BE/MME/HR 2 Terminate an employee’s access rights to personal data after his/her resignation, termination, termination of contract or agreement, or adjustment in accordance with changes in MyCEB HR/IT 3 Control and limit employees’ access to personal data system for the purpose of collecting, processing and storing of personal data BE/MME/HR/IT 4 Provide user ID and password for authorised employees to access personal data BE/MME/HR/IT A Establishment of the Security Standard for Personal Data Processed for Electronic
  • 6. NO DESCRIPTIONS Person In- charge (PIC)/Depart 5 Terminate user ID and password immediately when an employee who is authorised access to personal data is no longer handling the data BE/MME/HR 6 Establish physical security procedures as follows: i. Control the movement in an out of the data storage site ii. Storage personal data in an appropriate location which is unexposed and safe from physical or natural threats IT 7 Update the Back up/ Recovery system and anti-virus to prevent personal data intrusion and such IT Establishment of the Security Standard for Personal Data Processed for Electronic
  • 7. NO DESCRIPTIONS Person In- charge (PIC)/Depart 8 Safeguard the computer system from malware threats to prevent attacks on personal data IT 9 The transfer of personal data through removable media device and cloud computing service is not permitted unless with written consent by an officer authorised by the management of the MyCEB data user BE/MME 10 Record any transfer of data through removable media device and cloud computing service BE/MME/HR Establishment of the Security Standard for Personal Data Processed for Electronic
  • 8. NO DESCRIPTIONS Person In- charge (PIC)/Depart 11 Personal data transfer through cloud computing service must comply with the personal data protection principles in Malaysia, as well as with personal data protection laws of other countries. LEGAL 12 Ensure that all employees involved in processing personal data always protect the confidentiality of the data subject’s personal data. BE/MME/HR 13 Bind an appointed third party by the data user with a contract for operating and carrying out personal data processing activities. This is to ensure the safety of personal data from loss, misuse, modification, unauthorised access and disclosure. LEGAL Establishment of the Security Standard for Personal Data Processed for Electronic
  • 9. NO DESCRIPTIONS Person In- charge (PIC)/Depart 1 Register employees handling personal data into a system/registration book before allowed access to personal data BE/MME/HR 2 Terminate an employee’s access rights to personal data after his/her resignation, termination, termination of contract or agreement, or adjustment in accordance with changes in MyCEB BE/MME/HR/IT 3 Control and limit employees’ access to personal data system for the purpose of collecting, processing and storing of personal data BE/MME/HR B Establishment of the security standard for personal data processed for non -electronic
  • 10. NO DESCRIPTIONS Person In- charge (PIC)/Depart 4 Establish physical security procedures as follows: i. Store all personal data orderly in files; and ii. Store all files containing personal data in a locked place BE/MME/HR 5 Maintain a proper record access to personal data periodically and make such record the confidentiality of the data subject’s personal data BE/MME/HR 6 Record personal data transferred conventionally such as through mail, delivery, fax and etc BE/MME/HR Establishment of the security standard for personal data processed for non -electronic
  • 11. NO DESCRIPTIONS Person In- charge (PIC)/Depart 7 Ensure that all used papers, printed documents or other documents exhibiting personal data are destroyed thoroughly and efficiently by using shredding machine or other appropriate methods BE/MME/HR 8 Conduct awareness programmes to all employees on the responsibility to protect personal data LEGAL Establishment of the security standard for personal data processed for non -electronic
  • 12. NO DESCRIPTIONS Person In- charge (PIC)/Depart 1 Determine the retention period relating to the processing and retention personal data are fulfilled before destroying the data ( normal practice is within 6 years) BE/MME/HR 2 Keep personal data no longer than necessary unless there are requirements by other legal provisions BE/MME/HR 3 Maintain a proper record of personal data disposal periodically BE/MME/HR C Establishment of the Retention Standard
  • 13. NO DESCRIPTIONS Person In- charge (PIC)/Depart 4 Dispose personal data collection forms used in commercial transactions within the period not exceeding 14 days, except if the forms carry legal values in relation to the commercial transaction BE/MME/HR 5 Review and dispose all unwanted personal data in the database (eg MyCEB CRM) BE/MME/HR 6 Prepare a personal data disposal schedule for inactive data with a 24 month period. BE/MME/HR 7 The use of removable media device for storing personal data is not permitted without written approval from MyCEB management. BE/MME/HR/IT Establishment of the Retention Standard
  • 14. NO DESCRIPTIONS Person In- charge (PIC)/Depart 1 Provide personal data update form for data subjects, either via online or conventional LEGAL 2 Update personal data immediately once data correction notice is received from data subject BE/MME/HR 3 Ensure that all relevant legislation is fulfilled in determining the type of documents required to support the validity of the data subject’s personal data LEGAL 4 Notify on personal data updates either through the portal or notice at premises or by other appropriate methods MARCOM D Establishment of the Data Integrity Standard
  • 15. CONGRATULATIONS! You have just completed Privacy and Personal data (Part 1) under MyCEB Personal Data Protection 2010 THANK YOU