Personal Data Security Policy

Student Personal Data Security Policy

NEW ERA UNIVERSITY COLLEGE
STUDENT
PERSONAL DATA SECURITY POLICY

 

1. Policy Statement

This Student Personal Data Security Policy (“Policy”) is issued as an extension of Clause 7, Security of Personal Data, in the New Era University College (“NEUC”) Student Privacy Policy.

At New Era University College (“NEUC”, the University College, “we”, “our”, or “us”), a private higher education institution fully owned by New Era Edu Sdn. Bhd., we are committed to protecting students’ personal data in accordance with the Personal Data Protection Act 2010 (“PDPA”), its amendments, regulations, guidelines, codes of practice, and other applicable legal or regulatory requirements.

As the data controller, we shall implement appropriate technical, administrative, and physical security measures to protect students’ personal data against loss, misuse, unauthorised access, unauthorised disclosure, alteration, destruction, accidental exposure, and cybersecurity threats.

This Policy supports and should be read together with the NEUC Student Privacy Policy. It explains the security controls, responsibilities, and procedures adopted by NEUC to safeguard student personal data processed in electronic and non-electronic forms.

 

2. Purpose

The purpose of this Policy is to:

  1. protect the confidentiality, integrity, and availability of students’ personal data;
  2. support NEUC’s compliance with the PDPA and applicable personal data protection requirements;
  3. provide practical security measures for the protection of student personal data;
  4. define the responsibilities of students, staff, contractors, vendors, service providers, and other authorised persons who handle student personal data;
  5. prevent unauthorised access, misuse, disclosure, loss, alteration, destruction, or accidental exposure of student personal data;
  6. support proper detection, reporting, investigation, containment, and mitigation of data breaches and security incidents; and
  7. promote responsible data governance, cybersecurity awareness, and a culture of confidentiality within NEUC.

 

3. Scope

This Policy applies to:

  1. all students of NEUC;
  2. all academic, administrative, management, and support staff of NEUC;
  3. contractors, consultants, interns, temporary staff, vendors, service providers, and data processors who handle student personal data on behalf of NEUC;
  4. all departments, faculties, centres, units, systems, applications, databases, devices, storage media, physical files, and records containing student personal data; and
  5. all student personal data processed by NEUC, whether stored internally, physically, electronically, on approved cloud services, or through authorised third-party service providers.

This Policy covers personal data collected, used, stored, accessed, transferred, retained, archived, disclosed, or disposed of in connection with admission, enrolment, academic administration, student affairs, examinations, financial assistance, campus safety, disciplinary matters, alumni-related matters where applicable, and other lawful institutional purposes stated in the NEUC Student Privacy Policy.

 

4. Types of Personal Data

Student personal data protected under this Policy may include, but is not limited to:

  1. identification details, including name, NRIC number, passport number, date of birth, gender, nationality, and student ID number;
  2. contact details, including address, email address, and phone number;
  3. student-related information, including programme, faculty, enrolment status, academic records, examination records, attendance records, disciplinary records, and student affairs records;
  4. academic qualifications and educational information, including transcripts, certificates, grades, and records from previous educational institutions;
  5. scholarship, sponsorship, financial assistance, payment, billing, or refund-related information where applicable;
  6. emergency contact details, including information of parents, guardians, sponsors, or family members where relevant;
  7. images, audio recordings, video recordings, CCTV footage, event photographs, and online learning records;
  8. system access logs, student portal records, learning management system records, and online platform usage records;
  9. driver’s license or vehicle-related information where applicable; and
  10. sensitive personal data where applicable, including health or medical information, biometric data, religious belief information, financial information, or other sensitive personal data processed only where necessary and in accordance with the PDPA.

Sensitive personal data shall be subject to stricter access control, confidentiality, and security measures.

 

5. General Security Principles

NEUC shall implement reasonable, practical, and appropriate security measures by considering:

  1. the nature, category, and sensitivity of the personal data;
  2. the purpose for which the personal data is processed;
  3. the risk of harm arising from unauthorised access, disclosure, misuse, loss, alteration, or destruction;
  4. the location, method, and medium of storage;
  5. the security technologies, safeguards, and procedures available;
  6. the reliability, integrity, and authorization level of personnel handling the data;
  7. the security of data transmission, sharing, and transfer methods;
  8. the need for confidentiality, accountability, and auditability; and
  9. emerging cybersecurity threats, operational risks, and legal or regulatory changes.

NEUC shall periodically review and improve its security controls to ensure continued protection of students’ personal data.

 

6. Security Measures for Electronically Processed Data

NEUC shall implement appropriate technical and organisational security measures for electronically processed student personal data.
 

6.1 Access Control

NEUC shall:

  1. restrict access to student personal data to authorised personnel only;
  2. apply role-based access and the principle of least privilege;
  3. maintain records of personnel or user groups authorised to access student personal data where appropriate;
  4. review access rights where appropriate;
  5. amend, suspend, or revoke access when a user changes role, transfers department, resigns, graduates, or no longer requires access;
  6. restrict administrator or privileged access to authorised personnel only; and
  7. prevent unauthorised access to student systems, databases, records, and applications.
     

6.2 User Authentication

NEUC shall:

  1. assign unique user IDs and passwords to authorised users where applicable;
  2. require users to keep login credentials confidential;
  3. prohibit password sharing and credential misuse;
  4. require strong passwords or secure authentication methods where appropriate;
  5. implement multi-factor authentication (MFA) for selected systems or higher-risk access where appropriate; and
  6. monitor suspicious or abnormal login activities where reasonably practicable.
     

6.3 Workstation & Device Security

Authorised personnel handling student personal data shall:

  1. lock or log off workstations when unattended;
  2. not leave devices displaying student personal data unattended in public or shared areas;
  3. use password-protected screen locking mechanisms;
  4. take reasonable steps to prevent unauthorised persons from viewing confidential information;
  5. ensure confidential documents or printed records are not left unattended;
  6. secure laptops, portable devices, and storage media containing student personal data;
  7. avoid storing student personal data in unauthorised personal devices, personal email accounts, messaging applications, or unapproved cloud storage; and
  8. promptly report lost, stolen, compromised, or suspected compromised devices containing student personal data.
     

6.4 System & Network Security

NEUC shall implement reasonable system and network security controls, including where appropriate:

  1. antivirus, anti-malware, and endpoint protection;
  2. firewalls and network security controls;
  3. regular software updates and security patches;
  4. monitoring of systems and networks for unauthorised or suspicious activities;
  5. protection against malware, ransomware, phishing, and other cyber threats;
  6. restriction of unauthorised software installation; and
  7. secure configuration of systems, applications, and network services.
     

6.5 Data Storage & Backup

NEUC shall:

  1. store student personal data in secure and controlled environments;
  2. restrict access to storage locations, databases, folders, and backup systems;
  3. maintain secure backup and disaster recovery arrangements where appropriate;
  4. conduct backup verification or recovery testing periodically where practicable;
  5. apply encryption, masking, or other protection measures for sensitive data where appropriate;
  6. avoid unnecessary duplication of student personal data; and
  7. ensure backup data is protected against unauthorised access, loss, or corruption.
     

6.6 Data Transfer Security

NEUC shall

  1. use secure and authorised methods when transferring student personal data electronically;
  2. restrict the use of removable media, personal email, unauthorised cloud services, or unapproved file-sharing platforms;
  3. apply encryption, password protection, access restriction, or secure links where appropriate;
  4. verify recipients before disclosing or transferring student personal data;
  5. maintain records of significant or higher-risk data transfers where necessary; and
  6. ensure that cloud service providers, vendors, or data processors provide appropriate protection for student personal data.
     

6.7 Logging & Monitoring

NEUC shall, where appropriate:

  1. maintain logs of access to critical systems and student personal data;
  2. monitor unauthorised access attempts, abnormal activities, and security alerts;
  3. retain logs for audit, investigation, security, and compliance purposes; and
  4. review logs or reports where necessary to support incident detection and investigation.
     

6.8 Email, Online Platform, and Communication Security

When using email, online platforms, learning management systems, student portals, or other digital communication channels, NEUC staff and authorised users shall:

  1. verify recipients before sending student personal data;
  2. avoid sending unnecessary personal data;
  3. use password protection or encryption for sensitive attachments where appropriate;
  4. avoid disclosing student personal data through unauthorised messaging applications or public platforms;
  5. use official or approved communication channels where possible; and
  6. report misdirected emails or accidental disclosures promptly.
     

6.9 Use of Artificial Intelligence Tools and Online Large Language Models

Where artificial intelligence tools, generative AI tools, online large language models, automated processing tools, or similar digital technologies (“AI Tools”) are used in connection with NEUC’s academic, administrative, operational, customer service, visitor management, donation, communication, or institutional activities, NEUC shall ensure that such use is subject to appropriate personal data protection and security controls.

Staff, authorised users, contractors, vendors, and service providers shall not upload, enter, paste, share, or submit students’ personal data, sensitive personal data, confidential academic records, identification documents, admission records, enrolment records, attendance records, examination results, assessment records, disciplinary records, scholarship or financial assistance records, counselling or health-related information, student portal records, CCTV footage, images, audio recordings, video recordings, access logs, correspondence, or other non-public information into public or unauthorised AI Tools, unless prior approval has been obtained and appropriate safeguards are in place.

Where AI Tools are used, NEUC shall take reasonable steps to ensure that:

  1. the AI Tool has been approved or assessed by NEUC before use for work-related purposes;
  2. the use of AI Tools is limited to lawful, authorised, necessary, and relevant purposes;
  3. personal data is anonymized, pseudonymized, masked, redacted, or minimized before being entered into an AI Tool, where practicable;
  4. sensitive personal data is not processed using AI Tools unless necessary, authorised, and protected by appropriate safeguards;
  5. confidential or restricted records are not uploaded to public AI platforms or personal AI accounts;
  6. AI outputs are reviewed by authorised personnel before being used for decision-making, communication, publication, or record purposes;
  7. AI Tools are not used as the sole basis for decisions that may significantly affect the rights, interests, access, participation, benefits, services, donations, transactions, or treatment of any data subject, unless permitted by applicable law and subject to appropriate review;
  8. contracts, terms of service, data processing terms, retention practices, security measures, and cross-border transfer implications of AI Tool providers are reviewed where necessary;
  9. access to approved AI Tools is controlled, monitored, and limited to authorised users where appropriate;
  10. prompts, uploaded files, generated outputs, and AI-assisted records containing personal data are stored, retained, deleted, or archived securely in accordance with NEUC’s retention and disposal requirements; and
  11. any suspected unauthorised disclosure, accidental upload, misuse, or exposure of personal data through AI Tools is reported immediately as a data breach or security incident.

Students are encouraged not to submit unnecessary personal data, sensitive personal data, confidential documents, identification documents, academic records, examination materials, login credentials, third-party personal data, or NEUC’s non-public information into public AI Tools when using AI platforms for study, research, assignments, communication, or other NEUC-related purposes.

The use of AI Tools shall not reduce NEUC’s responsibility to protect student personal data under the PDPA, the NEUC Student Privacy Policy, this Policy, and any applicable internal procedures.

 

7. Security Measures for Physical and Non-Electronic Data

NEUC shall implement appropriate safeguards for physical records containing student personal data.
 

7.1 Physical Access Control

NEUC shall:

  1. restrict access to physical records containing student personal data to authorised personnel only;
  2. store records in locked cabinets, secure rooms, restricted areas, or other controlled locations where appropriate;
  3. maintain access records where appropriate;
  4. protect storage areas from theft, unauthorised access, fire, flood, water damage, and other physical risks where reasonably practicable; and
  5. ensure that visitors or unauthorised persons do not access restricted record storage areas.
     

7.2 Clean Desk and Secure Handling

Staff and authorised users shall:

  1. handle physical records containing student personal data securely;
  2. prevent unauthorised viewing, copying, photographing, removal, or disclosure of records;
  3. avoid leaving confidential documents unattended in public, shared, or unsecured areas;
  4. clear confidential documents from desks, counters, meeting rooms, classrooms, printers, photocopiers, and shared workspaces after use;
  5. keep printed records to the minimum necessary; and
  6. return files and documents to secure storage after use
      

7.3 Printing, Copying, and Scanning

When printing, copying, or scanning student personal data, staff and authorised users shall:

  1. collect printed documents promptly;
  2. check printers, photocopiers, and scanners to ensure no confidential documents are left behind;
  3. avoid unnecessary printing or duplication;
  4. ensure scanned copies are stored in approved locations; and
  5. securely dispose of unwanted or duplicate copies.
     

7.5 Physical Transfer of Records

Where student personal data is transferred physically by hand, mail, courier, delivery service, or other authorised methods, NEUC shall take reasonable steps to:

  1. package and label documents securely;
  2. verify the intended recipient and delivery address;
  3. use reliable delivery methods where appropriate;
  4. maintain records of significant or sensitive physical transfers where necessary; and
  5. promptly investigate missing, delayed, damaged, or wrongly delivered records.
     

7.6 Secure Disposal of Physical Records

NEUC shall securely dispose of physical records containing student personal data when they are no longer required, subject to applicable retention requirements.

Secure disposal methods may include shredding, pulping, secure destruction, or other approved disposal methods that prevent reconstruction, recovery, or unauthorised use of the records.

 

8. Vendor and Data Processor Security

Where third-party vendors, service providers, contractors, consultants, or data processors process student personal data on behalf of NEUC, NEUC shall take reasonable steps to ensure that such parties provide a comparable level of protection for student personal data.

NEUC shall, where appropriate:

  1. conduct reasonable assessment or due diligence before engaging vendors or data processors;
  2. require appropriate contractual terms, confidentiality obligations, or data processing agreements;
  3. require vendors and data processors to process student personal data only according to NEUC’s instructions and for authorised purposes;
  4. require adequate technical, administrative, and physical security measures;
  5. restrict unauthorised onward disclosure or transfer of student personal data;
  6. require prompt reporting of actual or suspected data breaches or security incidents;
  7. require secure return, deletion, or destruction of student personal data upon completion or termination of services, where applicable; and
  8. monitor or review vendor compliance where necessary.

 

9. Responsibilities of Students

Students play an important role in protecting their own personal data and the security of NEUC systems.

Students are responsible for:

  1. protecting their student portal, email, learning platform, and system login credentials;
  2. not sharing accounts, passwords, access tokens, or verification codes with others;
  3. using NEUC systems and online platforms responsibly;
  4. reporting suspected unauthorised access, suspicious activities, phishing attempts, or compromised accounts promptly;
  5. ensuring that personal devices used to access NEUC systems are reasonably secured;
  6. providing accurate, complete, and updated personal information to NEUC; and
  7. complying with applicable student rules, IT policies, and acceptable use requirements.
     

Students must not:

  1. access personal data, systems, files, or accounts without authorization;
  2. share confidential information belonging to other students, staff, or NEUC;
  3. misuse NEUC systems, applications, databases, or networks;
  4. attempt to bypass, disable, or compromise security controls;
  5. impersonate another user or use another person’s login credentials; or
  6. upload, distribute, or use malicious software, unauthorised tools, or harmful content on NEUC systems.

 

10. Responsibilities of Staff and Authorised Users

All staff and authorised users handling student personal data shall:

  1. access student personal data only for authorised and legitimate purposes;
  2. maintain the confidentiality of student information;
  3. comply with this Policy, the NEUC Student Privacy Policy, applicable procedures, and PDPA requirements;
  4. process only the minimum personal data necessary for the relevant purpose;
  5. ensure student personal data is accurate and updated where they are responsible for maintaining such records;
  6. handle electronic and physical records securely;
  7. attend relevant PDPA, privacy, information security, or cybersecurity training where required;
  8. report actual or suspected data breaches, security incidents, unauthorised access, loss, theft, or accidental disclosure immediately; and
  9. cooperate with investigations, audits, corrective actions, and security improvement measures.

 

11. Data Breach and Security Incident Management

NEUC shall establish and maintain procedures to manage actual or suspected personal data breaches and security incidents involving student personal data.

A personal data breach or security incident may include:

  1. unauthorised access to student personal data;
  2. unauthorised disclosure or sharing of student personal data;
  3. loss or theft of files, devices, storage media, or documents containing student personal data;
  4. accidental sending of student personal data to the wrong recipient;
  5. malware, ransomware, phishing, system compromise, or cyberattack involving student personal data;
  6. unauthorised alteration, deletion, or destruction of student personal data; or
  7. any other incident that may affect the confidentiality, integrity, or availability of student personal data.
     

Upon becoming aware of an actual or suspected personal data breach or security incident, NEUC shall take reasonable steps to:

  1. record the incident;
  2. contain and mitigate the incident promptly;
  3. investigate the cause and scope of the incident;
  4. assess the risk and potential impact on affected students and other relevant persons;
  5. implement corrective and preventive measures;
  6. assess whether notification to the Personal Data Protection Commissioner, Jabatan Perlindungan Data Peribadi (“JPDP”), is required;
  7. notify affected data subjects and relevant reporters where applicable; and
  8. maintain appropriate records of the incident, investigation, decision, notification, and remedial actions.

Students, staff, vendors, and authorised users shall report actual or suspected breaches or security incidents involving student personal data immediately to the DPO or relevant department.

 

12.Data Retention, Archiving and Disposal

NEUC shall retain student personal data only for as long as necessary for lawful, academic, administrative, operational, legal, regulatory, audit, historical, or institutional purposes.

When student personal data is no longer required and is not subject to any legal, regulatory, audit, dispute, or operational retention requirement, NEUC shall take reasonable steps to securely dispose of, delete, anonymize, or archive such personal data.

Secure disposal shall apply to both electronic and physical records, including databases, backup media, files, paper records, scanned documents, and storage devices where applicable.

 

13. Cross-Border Transfer of Personal Data

Where student personal data is transferred, stored, accessed, or processed outside Malaysia by NEUC’s authorised vendors, experts, service providers, cloud providers, or data processors, NEUC shall take reasonable steps to ensure that such personal data is protected in accordance with the PDPA and that a comparable level of protection is provided.

Such measures may include contractual safeguards, security requirements, access restrictions, confidentiality obligations, encryption, due diligence, or other appropriate controls.

 

14. Compliance and Non-Compliance

Compliance with this Policy is mandatory for all persons to whom this Policy applies.

Failure to comply with this Policy may result in appropriate action, including:

  1. reminder, warning, or retraining;
  2. restriction, suspension, or termination of system access;
  3. disciplinary action in accordance with applicable NEUC rules or procedures;
  4. contractual remedies against vendors, contractors, or service providers; and
  5. legal, regulatory, or enforcement action where applicable.

 

15. Policy Review

NEUC shall review this Policy periodically or whenever necessary due to:

  1. changes in the PDPA or other applicable legal or regulatory requirements;
  2. changes to the NEUC Student Privacy Policy;
  3. changes in NEUC’s operations, systems, technologies, or data processing activities;
  4. emerging cybersecurity threats or operational risks;
  5. audit findings, security assessments, or compliance reviews; or
  6. significant data breaches or security incidents.

NEUC reserves the right to amend this Policy from time to time. The latest version should be read together with the latest NEUC Student Privacy Policy.

 

16. Contact Information

For matters relating to this Policy or the protection of personal data, please contact: 

Data Protection Officer (DPO)
New Era University College

Address:
Blocks B & C, Lot 5, Seksyen 10, Jalan Bukit,
43000 Kajang, Selangor, Malaysia

Tel: 603-8740 6392/8210 3709

Email:

For PDPA-related enquiries: dpo@newera.edu.my

For local student-related enquiries:

  1. registration, enrolment, academic records, etc.: registrar@newera.edu.my
  2. student affairs: student@newera.edu.my

For international student-related enquiries: iie@newera.edu.my

 

 

(Revised and Approved by Administration Meeting on 20th May 2026)

Quick Access

NEUC STUDENT
NEUC STAFF
CONVOCATION
VISITORS

address

Blok B&C, Lot 5, Seksyen 10, Jalan Bukit,
43000 Kajang, Selangor.

phone

03-8210 3709 (Main Line)
03-8740 6392 (Main Line)
03-8740 4392
03-8741 8192
03-8741 4923
03-8741 4924
03-8740 6925
03-8737 9292

email

neuc@newera.edu.my

OFFICE HOURS

Monday to Friday: 8:30am - 5:00pm
(Off on Saturday, Sunday and Public Holidays)