PDPA Notice
The personal data protection act
PFPFA (Malaysia) Sdn. Bhd. (hereinafter referred to as ‘the Organization’) is committed to protecting the personal data of its clients, employees, partners, and other stakeholders. This notice sets out the Organization’s approach to ensuring compliance with PDPA 2010 (Act 709), PDPA Amendment Act 2024 (Act A1727), and guidelines issued by the Personal Data Protection Commissioner (PDPC).
This notice explains how we collect, use, disclose, and safeguard your personal data when you interact with us through our website, services, or other channels.
The General principle prohibits the processing of personal data without the consent of the data subject, except under specific permitted circumstances.
The Personal Data We Collect
We may collect the following categories of personal data:
• Identity data (e.g., name, NRIC/passport number)
• Contact data (e.g., email, phone number, address)
• Employment or financial data (if relevant to services)
• Any other information voluntarily provided to us
Purpose of Collection
Your personal data is collected for purposes including:
• Responding to inquiries or service requests
• Providing financial advisory and estate planning services
• Compliance with legal and regulatory obligations
• Internal operations and analytics
• Marketing and promotional communications (with consent)
Disclosure of Personal Data
We do not disclose your personal data to third parties without your consent, except:
• To authorized service providers under contractual safeguards
• To comply with legal obligations
• For purposes directly related to the original reason for collection
Cross-Border Transfers
Your personal data may be transferred outside Malaysia only where:
• The destination country has laws substantially similar to Malaysia’s PDPA, or
• Adequate safeguards are in place to protect your data
Data Security
Data Retention
Your Rights
You have the right to:
• Access and correct your personal data
• Withdraw consent at any time
• Object to processing for direct marketing or profiling
• Request data portability (where applicable)
• Lodge a complaint with the Personal Data Protection Commissioner