NEW ERA UNIVERSITY COLLEGE
EMPLOYEE & JOB APPLICANT
PERSONAL DATA SECURITY POLICY
1. Policy Statement
This Employee & Job Applicant Personal Data Security Policy (“Policy”) is issued as an extension of Clause 7, Security of Personal Data, in the New Era University College (“NEUC”) Employee & Job Applicant Privacy Policy.
At New Era University College (“NEUC”, the University College, “we”, “our”, or “us”), a private higher education institution fully owned by New Era Edu Sdn. Bhd., we are committed to protecting the personal data of employees and job applicants in accordance with the Personal Data Protection Act 2010 (“PDPA”), its amendments, regulations, guidelines, codes of practice, and other applicable legal or regulatory requirements.
As the data controller, we shall implement appropriate technical, administrative, and physical security measures to safeguard employees’ and job applicants’ personal data against loss, misuse, unauthorised access, unauthorised disclosure, alteration, modification, destruction, accidental exposure, and cybersecurity threats.
This Policy supports and should be read together with the NEUC Employee & Job Applicant Privacy Policy. It explains the security measures, procedures, and responsibilities adopted by NEUC to protect personal data processed in electronic and non-electronic forms.
2. Purpose
The purpose of this Policy is to:
- protect the confidentiality, integrity, and availability of employees’ and job applicants’ personal data;
- support NEUC’s compliance with the PDPA and applicable personal data protection requirements;
- provide practical security measures for the protection of employment-related and recruitment-related personal data;
- define the responsibilities of employees, job applicants, staff, contractors, vendors, service providers, data processors, and authorised users in safeguarding personal data;
- prevent unauthorised access, misuse, disclosure, loss, alteration, destruction, or accidental exposure of personal data;
- support proper detection, reporting, investigation, containment, and mitigation of data breaches and security incidents;
- protect employment, payroll, recruitment, performance, disciplinary, health, statutory, and other confidential HR-related records; and
- promote responsible data governance, cybersecurity awareness, and confidentiality within NEUC.
3. Scope
This Policy applies to:
- full-time and part-time employees of NEUC;
- academic, administrative, management, and support staff;
- contract employees, temporary employees, interns, trainees, secondees, and other personnel engaged by NEUC;
- job applicants, recruitment candidates, interview candidates, and prospective employees;
- former employees, where their personal data continues to be retained or processed by NEUC;
- Human Resource personnel and other authorised staff handling employee or job applicant personal data;
- heads of departments, supervisors, interview panel members, recruitment committees, and authorised personnel involved in employment or recruitment processes;
- contractors, consultants, vendors, service providers, background screening providers, payroll providers, insurance providers, statutory service providers, cloud providers, system providers, and data processors handling employee or job applicant personal data on behalf of NEUC; and
- all systems, applications, databases, devices, storage media, physical files, forms, registers, personnel files, payroll records, recruitment records, CCTV systems, access control systems, and communication records containing employee or job applicant personal data.
This Policy covers personal data processed electronically, physically, internally, externally, through authorised third-party service providers, or through approved cloud or digital platforms.
4. Types of Personal Data
Employee and job applicant personal data protected under this Policy may include, but is not limited to:
- identification details, including name, NRIC number, passport number, date of birth, gender, and nationality;
- contact information, including residential address, correspondence address, email address, and phone number;
- employment-related information, including position, department, job title, employment status, employment history, contract details, salary, allowances, benefits, leave records, and other HR records;
- academic and professional qualifications, including educational institutions attended, academic transcripts, certificates, grades obtained, professional memberships, licences, and training records;
- recruitment and selection information, including application forms, curriculum vitae, resumes, interview records, assessment results, referee reports, recommendation letters, background screening results, and recruitment communications;
- performance records, appraisal reports, promotion records, training records, disciplinary records, grievance records, investigation records, and related correspondence;
- attendance records, working hour records, access logs, system usage records, and workplace access control records;
- payroll, banking, tax, statutory contribution, EPF, SOCSO, income tax, insurance, reimbursement, claims, and financial administration records;
- emergency contact details, including information of family members, dependents, next-of-kin, or other emergency contacts where relevant;
- marital status, dependent information, and languages spoken, where relevant to employment administration;
- images, audio recordings, video recordings, CCTV footage, event documentation, online meeting recordings, and video interview records;
- driver’s licence details, vehicle-related information, or travel-related records where applicable;
- health, medical, occupational safety, workplace accommodation, insurance, or benefit-related information where applicable;
- biometric data or access control data where applicable; and
- any other personal data voluntarily provided or required for recruitment, employment administration, post-employment administration, workplace safety, statutory compliance, or institutional operations.
Sensitive personal data, including health information, religious belief information, political opinion information, biometric data, financial information, or other sensitive personal data, shall only be processed where necessary, with explicit consent where required by the PDPA, and shall be subject to enhanced protection and restricted access controls.
5. General Security Principles
NEUC shall implement reasonable, practical, and appropriate security measures by considering:
- the nature, category, and sensitivity of the personal data;
- the purpose for which the personal data is processed;
- the risk of harm arising from unauthorised access, disclosure, misuse, loss, alteration, or destruction;
- the location, method, and medium of storage;
- the security technologies, safeguards, and procedures available;
- the reliability, integrity, and authorisation level of personnel handling the data;
- the security of data transmission, sharing, and transfer methods;
- the need for confidentiality, accountability, and auditability;
- the involvement of payroll providers, insurance providers, statutory bodies, background screening providers, recruitment platforms, cloud providers, or other third-party service providers; and
- emerging cybersecurity threats, operational risks, and legal or regulatory changes.
NEUC shall periodically review and improve its security measures to ensure continued protection of employees’ and job applicants’ personal data.
6. Security Measures for Electronically Processed Data
NEUC shall implement appropriate technical and organisational measures to protect electronically processed employee and job applicant personal data.
6.1 Access Control
NEUC shall:
- restrict access to employee and job applicant personal data to authorised personnel only;
- apply role-based access and the principle of least privilege;
- maintain records of personnel or user groups authorised to access personal data where appropriate;
- review access rights periodically;
- amend, suspend, or revoke access when a user changes role, transfers department, resigns, is terminated, completes engagement, or no longer requires access;
- restrict administrator or privileged access to authorised personnel only; and
- prevent unauthorised access to HR systems, payroll systems, recruitment platforms, personnel records, performance records, disciplinary records, statutory records, and related databases.
6.2 User Authentication
NEUC shall:
- assign unique user IDs and passwords to authorised users where applicable;
- require users to keep login credentials confidential;
- prohibit password sharing and credential misuse;
- require strong passwords or secure authentication methods where appropriate;
- implement multi-factor authentication for selected systems or higher-risk access where appropriate; and
- monitor suspicious or abnormal login activities where reasonably practicable.
6.3 Workstation and Device Security
Employees and authorised personnel handling employee or job applicant personal data shall:
- lock or log off workstations when unattended;
- not leave devices displaying personal data unattended in public or shared areas;
- use password-protected screen locking mechanisms;
- take reasonable steps to prevent unauthorised persons from viewing confidential information;
- ensure confidential documents or printed records are not left unattended;
- secure laptops, portable devices, and storage media containing personal data;
- avoid storing personal data in unauthorised personal devices, personal email accounts, messaging applications, or unapproved cloud storage; and
- promptly report lost, stolen, compromised, or suspected compromised devices containing employee or job applicant personal data.
6.4 System and Network Security
NEUC shall implement reasonable system and network security controls, including where appropriate:
- antivirus, anti-malware, and endpoint protection;
- firewalls and network security controls;
- regular software updates and security patches;
- monitoring of systems and networks for unauthorised or suspicious activities;
- protection against malware, ransomware, phishing, and other cyber threats;
- restriction of unauthorised software installation; and
- secure configuration of HR systems, payroll systems, recruitment platforms, employee portals, databases, and network services.
6.5 Data Storage and Backup
NEUC shall:
- store employee and job applicant personal data in secure and controlled environments;
- restrict access to storage locations, databases, folders, and backup systems;
- maintain secure backup and disaster recovery arrangements where appropriate;
- conduct backup verification or recovery testing periodically where practicable;
- apply encryption, masking, or other protection measures for sensitive data where appropriate;
- avoid unnecessary duplication of personal data; and
- ensure backup data is protected against unauthorised access, loss, or corruption.
6.6 Data Transfer Security
NEUC shall:
- use secure and authorised methods when transferring employee or job applicant personal data electronically;
- restrict the use of removable media, personal email, unauthorised cloud services, or unapproved file-sharing platforms;
- apply encryption, password protection, access restriction, secure links, or other safeguards where appropriate;
- verify recipients before disclosing or transferring personal data;
- maintain records of significant or higher-risk data transfers where necessary; and
- ensure that cloud service providers, payroll providers, recruitment platforms, insurance providers, statutory service providers, background screening providers, or data processors provide appropriate protection for personal data.
6.7 Logging and Monitoring
NEUC shall, where appropriate:
- maintain logs of access to critical systems and personal data;
- monitor unauthorised access attempts, abnormal activities, and security alerts;
- retain logs for audit, investigation, security, and compliance purposes; and
- review logs or reports where necessary to support incident detection and investigation.
6.8 Vendor and Data Processor Security
Where third-party vendors, service providers, contractors, consultants, payroll providers, insurance providers, background screening providers, recruitment platform providers, statutory service providers, cloud providers, or data processors process employee or job applicant personal data on behalf of NEUC, NEUC shall take reasonable steps to ensure that such parties provide a comparable level of protection for personal data.
NEUC shall, where appropriate:
- conduct reasonable assessment or due diligence before engaging vendors or data processors;
- require appropriate contractual terms, confidentiality obligations, or data processing agreements;
- require vendors and data processors to process personal data only according to NEUC’s instructions and for authorised purposes;
- require adequate technical, administrative, and physical security measures;
- restrict unauthorised onward disclosure or transfer of personal data;
- require prompt reporting of actual or suspected data breaches or security incidents;
- require secure return, deletion, or destruction of personal data upon completion or termination of services, where applicable; and
- monitor or review vendor compliance where necessary.
6.9 Email, Online Platform, and Communication Security
When using email, HR systems, recruitment platforms, employee portals, online forms, cloud systems, video interview platforms, online meeting platforms, or other digital communication channels, NEUC staff and authorised users shall:
- verify recipients before sending employee or job applicant personal data;
- avoid sending unnecessary personal data;
- use password protection, encryption, secure links, or access restrictions for sensitive attachments where appropriate;
- avoid disclosing personal data through unauthorised messaging applications or public platforms;
- use official or approved communication channels where possible;
- ensure that video interviews, online meetings, and recordings containing personal data are stored and shared securely; and
- report misdirected emails, accidental disclosures, or suspected unauthorised sharing promptly.
6.10 Use of Artificial Intelligence Tools and Online Large Language Models
Where artificial intelligence tools, generative AI tools, online large language models, automated processing tools, AI-assisted transcription tools, translation tools, image generation tools, recruitment screening tools, analytics tools, or similar digital technologies (“AI Tools”) are used in connection with NEUC’s recruitment, employment administration, HR management, performance management, training, communication, workplace operations, investigation, or institutional activities, NEUC shall ensure that such use is subject to appropriate personal data protection and security controls.
Staff, authorised users, contractors, vendors, service providers, and data processors shall not upload, enter, paste, share, or submit employees’ or job applicants’ personal data, sensitive personal data, confidential HR records, identification documents, employment contracts, salary records, payroll records, bank account details, EPF records, SOCSO records, income tax records, medical records, recruitment records, interview notes, referee reports, background screening records, performance appraisal records, disciplinary records, investigation records, attendance records, access logs, CCTV footage, images, audio recordings, video recordings, online meeting recordings, correspondence, or other non-public information into public or unauthorised AI Tools, unless prior approval has been obtained and appropriate safeguards are in place.
Where AI Tools are used, NEUC shall take reasonable steps to ensure that:
- the AI Tool has been reviewed or approved by NEUC before being used for work-related purposes involving employee or job applicant personal data;
- the use of AI Tools is limited to lawful, authorised, necessary, and relevant recruitment, employment, administrative, operational, or institutional purposes;
- employee and job applicant personal data is anonymised, pseudonymised, masked, redacted, or minimised before being entered into an AI Tool, where practicable;
- sensitive personal data, including health information, biometric data, religious belief information, political opinion information, financial information, payroll information, statutory contribution information, or other sensitive records, is not processed using AI Tools unless necessary, authorised, and protected by appropriate safeguards;
- confidential or restricted HR, payroll, recruitment, disciplinary, investigation, performance, medical, or employment records are not uploaded to public AI platforms, personal AI accounts, unauthorised browser extensions, or unapproved third-party tools;
- AI Tools are not used to screen, rank, reject, shortlist, evaluate, discipline, profile, monitor, or make decisions about employees or job applicants in a way that may significantly affect their recruitment outcome, employment, promotion, appraisal, benefits, disciplinary outcome, workplace access, rights, or interests, unless such use is authorised, lawful, transparent, and subject to appropriate human review;
- AI-generated outputs are reviewed by authorised personnel before being used for recruitment decisions, employment decisions, HR communications, performance management, disciplinary management, investigation, publication, reporting, or record purposes;
- contracts, terms of service, data processing terms, retention practices, security measures, confidentiality commitments, and cross-border transfer implications of AI Tool providers are reviewed where necessary;
- access to approved AI Tools is controlled, limited to authorised users, and monitored where appropriate;
- prompts, uploaded files, transcripts, summaries, generated outputs, and AI-assisted records containing employee or job applicant personal data are stored, retained, deleted, or archived securely in accordance with NEUC’s retention and disposal requirements;
- AI Tools are not used to bypass NEUC’s approved systems, access controls, recruitment procedures, HR procedures, payroll procedures, confidentiality obligations, or personal data protection requirements; and
- any suspected unauthorised disclosure, accidental upload, misuse, loss, or exposure of employee or job applicant personal data through AI Tools is reported immediately as a data breach or security incident.
Employees and job applicants are encouraged not to submit unnecessary personal data, sensitive personal data, confidential documents, identification documents, employment records, recruitment records, salary information, medical information, third-party personal data, login credentials, or NEUC’s non-public information into public AI Tools when communicating with NEUC, applying for employment, performing work duties, or engaging with NEUC-related systems and services.
The use of AI Tools shall not reduce NEUC’s responsibility to protect employee and job applicant personal data under the PDPA, the NEUC Employee & Job Applicant Privacy Policy, this Policy, and any applicable internal procedures.
7. Security Measures for Physical and Non-Electronic Data
NEUC shall implement appropriate safeguards for physical records containing employee or job applicant personal data.
7.1 Physical Access Control
NEUC shall:
- restrict access to physical records containing personal data to authorised personnel only;
- store records in locked cabinets, secure rooms, restricted areas, or other controlled locations where appropriate;
- maintain access records where appropriate;
- protect storage areas from theft, unauthorised access, fire, flood, water damage, and other physical risks where reasonably practicable; and
- ensure that visitors or unauthorised persons do not access restricted HR, payroll, recruitment, or personnel record storage areas.
7.2 Clean Desk and Secure Handling
Employees and authorised users shall:
- handle physical records containing employee or job applicant personal data securely;
- prevent unauthorised viewing, copying, photographing, removal, or disclosure of records;
- avoid leaving confidential documents unattended in public, shared, or unsecured areas;
- clear confidential documents from desks, counters, interview rooms, meeting rooms, printers, photocopiers, and shared workspaces after use;
- keep printed records to the minimum necessary; and
- return personnel files, recruitment files, payroll records, interview notes, disciplinary records, investigation records, and other confidential documents to secure storage after use.
7.3 Printing, Copying, and Scanning
When printing, copying, or scanning employee or job applicant personal data, employees and authorised users shall:
- collect printed documents promptly;
- check printers, photocopiers, and scanners to ensure no confidential documents are left behind;
- avoid unnecessary printing or duplication;
- ensure scanned copies are stored in approved locations; and
- securely dispose of unwanted or duplicate copies.
7.4 Physical Transfer of Records
Where employee or job applicant personal data is transferred physically by hand, mail, courier, delivery service, internal dispatch, or other authorised methods, NEUC shall take reasonable steps to:
- package and label documents securely;
- verify the intended recipient and delivery address;
- use reliable delivery methods where appropriate;
- maintain records of significant or sensitive physical transfers where necessary; and
- promptly investigate missing, delayed, damaged, or wrongly delivered records.
7.5 Secure Disposal of Physical Records
NEUC shall securely dispose of physical records containing employee or job applicant personal data when they are no longer required, subject to applicable retention requirements.
Secure disposal methods may include shredding, pulping, secure destruction, or other approved disposal methods that prevent reconstruction, recovery, or unauthorised use of the records.
8. Responsibilities of Employees
All employees handling personal data shall:
- access personal data only for authorised and legitimate purposes;
- maintain the confidentiality of personal data;
- comply with this Policy, the NEUC Employee & Job Applicant Privacy Policy, applicable procedures, and PDPA requirements;
- process only the minimum personal data necessary for the relevant purpose;
- ensure personal data is accurate and updated where they are responsible for maintaining such records;
- handle electronic and physical records securely;
- protect passwords, login credentials, access cards, and system access rights;
- lock or log off workstations when unattended;
- store portable devices and storage media securely when not in use;
- avoid storing personal data in unauthorised devices, locations, applications, or accounts;
- attend relevant PDPA, privacy, information security, or cybersecurity training where required;
- report actual or suspected data breaches, security incidents, unauthorised access, loss, theft, or accidental disclosure immediately; and
- cooperate with investigations, audits, corrective actions, and security improvement measures.
Employees shall not:
- access personal data without authorisation;
- share confidential information with unauthorised persons;
- misuse NEUC systems, databases, applications, or records;
- disable, bypass, or interfere with security controls or monitoring systems;
- disclose personal data through unauthorised channels;
- leave computers, systems, portable devices, or documents containing personal data unattended without appropriate security protection; or
- use personal data for personal, unrelated, or unauthorised purposes.
9. Responsibilities of Job Applicants
Job applicants shall:
- provide accurate, complete, and updated personal information to NEUC;
- protect recruitment portal login credentials, verification codes, and account details where applicable;
- submit personal data through official or authorised recruitment channels where possible;
- avoid submitting unnecessary sensitive personal data unless requested or required for the recruitment process;
- report suspicious activities, unauthorised access, phishing attempts, or suspected misuse involving their personal data; and
- avoid submitting false, misleading, or unauthorised third-party personal data.
Job applicants’ personal data shall only be used for recruitment, selection, employment evaluation, onboarding, compliance, and related lawful purposes, unless otherwise permitted by law or consented to by the job applicant.
10. Data Breach and Security Incident Management
NEUC shall establish and maintain procedures to manage actual or suspected personal data breaches and security incidents involving employee or job applicant personal data.
A personal data breach or security incident may include:
- unauthorised access to employee or job applicant personal data;
- unauthorised disclosure or sharing of personal data;
- loss or theft of personnel files, recruitment files, payroll records, devices, storage media, or documents containing personal data;
- accidental sending of personal data to the wrong recipient;
- malware, ransomware, phishing, system compromise, or cyberattack involving personal data;
- unauthorised alteration, deletion, or destruction of personal data;
- unauthorised access to HR, payroll, recruitment, performance, disciplinary, medical, or statutory records; or
- any other incident that may affect the confidentiality, integrity, or availability of personal data.
Upon becoming aware of an actual or suspected personal data breach or security incident, NEUC shall take reasonable steps to:
- record the incident;
- contain and mitigate the incident promptly;
- investigate the cause and scope of the incident;
- assess the risk and potential impact on affected employees, job applicants, and other relevant persons;
- implement corrective and preventive measures;
- assess whether notification to the Personal Data Protection Commissioner, Jabatan Perlindungan Data Peribadi (“JPDP”), is required;
- notify affected data subjects and relevant reporters where applicable; and
- maintain appropriate records of the incident, investigation, decision, notification, and remedial actions.
Employees, job applicants, staff, vendors, service providers, and authorised users shall report actual or suspected breaches or security incidents involving personal data immediately to the DPO, Human Resource Department, or relevant department.
11. Data Retention, Archiving and Disposal
NEUC shall retain employee and job applicant personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required for legal, regulatory, audit, administrative, financial, tax, employment, contractual, dispute-resolution, statutory, post-employment, or institutional purposes.
Where personal data is no longer required and is not subject to any legal, regulatory, audit, dispute, financial, tax, employment, statutory, or operational retention requirement, NEUC shall take reasonable steps to securely delete, dispose of, anonymise, or archive such personal data.
Recruitment records of unsuccessful job applicants shall be retained only for the period necessary for recruitment, future employment consideration where consented or permitted, legal compliance, audit, dispute management, or legitimate institutional purposes.
Secure disposal shall apply to both electronic and physical records, including databases, backup media, personnel files, recruitment files, payroll records, statutory records, medical records, disciplinary records, investigation records, scanned documents, and storage devices where applicable.
12. Cross-Border Transfer of Personal Data
Where employee or job applicant personal data is transferred, stored, accessed, or processed outside Malaysia by NEUC’s authorised vendors, experts, service providers, cloud providers, payroll providers, recruitment platform providers, background screening providers, or data processors, NEUC shall take reasonable steps to ensure that such personal data is protected in accordance with the PDPA and that a comparable level of protection is provided.
Such measures may include contractual safeguards, security requirements, access restrictions, confidentiality obligations, encryption, due diligence, or other appropriate controls.
13. Recruitment Updates and Communications
Where NEUC sends recruitment updates, employment opportunities, or relevant announcements to job applicants or prospective candidates who have opted in to receive such communications, NEUC shall ensure that:
- such communications are sent through authorised channels;
- contact details are used only for authorised or consented purposes;
- recipients are provided with a practical method to withdraw consent or opt out where applicable;
- recruitment mailing lists or candidate databases are protected against unauthorised access or disclosure; and
- withdrawal or opt-out requests are acted upon within a reasonable period, subject to applicable legal, operational, or contractual limitations.
14. Compliance and Non-Compliance
Compliance with this Policy is mandatory for all persons to whom this Policy applies.
Failure to comply with this Policy may result in appropriate action, including:
- reminder, warning, or retraining;
- restriction, suspension, or termination of system access;
- disciplinary action in accordance with applicable NEUC rules or procedures;
- contractual remedies against vendors, contractors, or service providers; and
- legal, regulatory, or enforcement action where applicable.
15. Policy Review
NEUC shall review this Policy periodically or whenever necessary due to:
- changes in the PDPA or other applicable legal or regulatory requirements;
- changes to the NEUC Employee & Job Applicant Privacy Policy;
- changes in NEUC’s operations, systems, technologies, HR systems, payroll systems, recruitment platforms, or data processing activities;
- emerging cybersecurity threats or operational risks;
- audit findings, security assessments, or compliance reviews; or
- significant data breaches or security incidents.
NEUC reserves the right to amend this Policy from time to time. The latest version should be read together with the latest NEUC Employee & Job Applicant Privacy Policy.
16. Contact Information
For matters relating to this Policy or the protection of employee and job applicant personal data, please contact:
Data Protection Officer (DPO)
New Era University College
Address:
Blocks B & C, Lot 5, Seksyen 10, Jalan Bukit,
43000 Kajang, Selangor, Malaysia
Tel: 603-8740 6392/8210 3709
Email:
For PDPA-related enquiries: dpo@newera.edu.my
For employment-related enquiries: hr@newera.edu.my
(Revised and Approved by Administration Meeting on 20th May 2026)