Personal Data Protection Policy (“Policy”)
In view of the implementation of the Personal Data Protection Act 2010 ("Act"), E-IONS Corporation Sdn. Bhd. ("E-IONS") recognize the need to process all personal data obtained in a lawful and appropriate manner. E-IONS is committed to protecting the personal data supplied by a data subject to ensure compliance with the legal and regulatory requirements in accordance with the Act. This Policy covers the processing of all personal data and sensitive personal data which use is controlled by E-IONS.
As a principle, collection, use, or disclosure of the personal data is prohibited for any purpose unless otherwise with the approval of the head of the relevant business units and the compliance officer.
B. Policy Status
This Policy is applicable to all employees of E-IONS. For the purposes of this Policy, the term "employees" herein refers to all members of E-IONS, including sales representatives and members of E-IONS. Failure to comply with this Policy may result in disciplinary action.
Any query regarding this Policy may be directed to the compliance officers of E-IONS at [email protected]
In the event of any discrepancy, contradiction, and/or differences between any part of this Policy and that of any current policies adopted by E-IONS, by the portion of the relevant policy which imposes a higher standard of data protection shall apply and supersede the other.
C. Roles and Responsibilities
The legal responsibility for compliance with the Act lies with E-IONS who is the "data user" under the Act and is registered as such with the Personal Data Protection Commission. Notwithstanding, compliance with this Policy and the Act is the responsibility of all employees of E-IONS.
D. Data Collected & Purposes
During the course of E-IONS's business and activities, E-IONS may be required to process information of a data subject, including but not limited to the name of the individual, address, phone number and email address. Such information includes information which may identify an individual when in combination with other information, even if such information cannot identify such individual on its own. All these information may also be collected online or offline.
The personal data collected by E-IONS may be used among other things for the following purpose:
Providing customer care and enhancing customer satisfaction, including but not limited to, resolving complaints, dealing with and/or responding to requests and enquiries, warranty, returns and other after sales services;
Promoting, advertising and enhancing our products and services;
Human resources, employment and recruitment purposes;
Training of staff;
Storing and processing of personal data relating to the clients of E-IONS in the data storage systems;
Updating and managing the accuracy of the E-IONS's internal record, including but not limited to administration, processing and matching any personal data held which relates to you for any of the purposes listed herein;
Billing, taxation and/or auditing purposes;
Information and security purposes, including but not limited to managing and administrating e-mail, handling and investigating any security related issues, vulnerability, and/or incidents;
Facilitating business transactions (which may extend to any merges, acquisitions or assets sales) invoicing any of the related corporations or affiliates of E-IONS;
Legal purposes (including but not limited to obtaining legal advice and dispute resolution);
Disclosing personal data to the government authorities and/or authorized third party as required by law and/or within the responsibility of E-IONS; and
As reasonably contemplated by the nature of any transaction.
E. Data Processing
As and when E-IONS is required to collect personal data, E-IONS and its employees must abide by the requirements of this Policy and the Act. In the context of the Act, "processing" is defined to include collecting, recording, holding or storing personal data which includes NRIC numbers, home address, contact details, etc.
E-IONS will be responsible for ensuring that any personal data processed in relation to the E-IONS's clients and/or another individual is accurate, complete, not misleading and kept up-to-date. The personal data will be reviewed periodically to ensure that they are up-to-date and to determine whether retention of such personal data is necessary.
F. Consent of Individual
E-IONS may only process personal data with the consent of the data subject whom the personal data concerns and/or if the processing of the personal data is for the performance of a contract by E-IONS to which the data subject is a party.
G. Disclosure of Information
E-IONS requires all employees to be vigilant and exercise reasonable caution when asked to provide any personal data to a third party. In particular, E-IONS must ensure that personal data is not disclosed either orally or in writing to any unauthorized employee without express prior consent of the compliance officer and/or authorized individual (as the case), and/or if disclosure is not for any of the purposes stipulated in Paragraph 6.
However, as and when it is reasonably required, the personal data in the possession of E-IONS may only be disclosed to the following third parties:
Authorized agents, contractors and third party service providers who provide services to E-IONS for any of the purposes contemplated at Paragraph 6;
External professional advisers and auditors; and/or
Governmental departments and authorities.
Personal data will not be transferred outside E-IONS to a country outside of Malaysia unless consent from the data subject is obtained.
H. Data Security
E-IONS will ensure that any personal data which is collected, stored and processed, is stored securely and the practical steps are adopted to ensure the following:
Source documents are well kept in accordance with applicable laws;
Paper-based records must not be left where unauthorized employees can gain access to them and must be kept in accordance with applicable laws;
Computerize personal data is protected by passwords; and
Individual passwords are kept confidential and not disclosed or shared with other employees to enable login under any other employee's personal username and password.
When physical files or any forms relating to the data subject are no longer required, they will be shredded or bagged and destroyed securely, and the hard drives consisting of those records will be erased off via secure electronic deletion pursuant to such standard procedure by the administration department.
Any employee of E-IONS must not process any personal data belonging to any data subject, whether in soft copy or hard copy, outside of the premises of E-IONS unless prior approval is provided by the compliance officer or any authorized person.
I. Data Retention
Personal data obtained should not be kept longer than it is required for its purposes. E-IONS has an obligation to ensure that the personal data of the data subject are destroyed and/or permanently deleted after a specified period of time. All employees are required to contact the compliance officer and/or any authorized officer should the need to dispose of any personal data arises.
Personal and sensitive data will be disposed of by means as listed in Paragraph 14. Appropriate measures will and must be taken by E-IONS to ensure the personal data destroyed are not reconstructed or processed by any third party.
J. Rights of Data Subject
A data subject has the following rights under the Act:
Request for access to personal data held on the individual, the purpose for which the personal data is being used and those to whom it has, or can be disclosed to;
Prevent data processing that is likely to cause distress or damage;
Take reasonable action to stop the use of, rectify, erase, and/or dispose of inaccurate personal data; and
Limit the processing of their personal data and/or withdraw their consent given to E-IONS.
Any individual who intends to exercise the above-mentioned rights shall make a written request to E-IONS together with the prescribed fee as applicable. For purposes of I, II, and III under paragraph 18, E-IONS shall, subject to any exceptions provided under law, comply with the request not later than 21 days from the date of receipt of such request. For purposes of IV under paragraph 18, E-IONS shall, upon receiving such request, cease the processing of such personal data as soon as practicable.