Personal Data Security Policy

Customer, Visitor & Donor Personal Data Security Policy

NEW ERA UNIVERSITY COLLEGE
CUSTOMER, VISITOR & DONOR
PERSONAL DATA SECURITY POLICY

 

1. Policy Statement

This Customer, Visitor & Donor Personal Data Security Policy (“Policy”) is issued as an extension of Clause 7, Security of Personal Data, in the New Era University College (“NEUC”) Customer, Visitor & Donor Privacy Policy.

At New Era University College (“NEUC”, the University College, “we”, “our”, or “us”), a private higher education institution fully owned by New Era Edu Sdn. Bhd., we are committed to protecting the personal data of customers, visitors, donors, and users of NEUC’s websites, online platforms, digital services, events, programmes, premises, donation channels, and related services in accordance with the Personal Data Protection Act 2010 (“PDPA”), its amendments, regulations, guidelines, codes of practice, and other applicable legal or regulatory requirements.

As the data controller, we shall implement appropriate technical, administrative, and physical security measures to safeguard customers’, visitors’ and donors’ personal data against loss, misuse, unauthorised access, unauthorised disclosure, alteration, destruction, accidental exposure, and cybersecurity threats.

This Policy supports and should be read together with the NEUC Customer, Visitor & Donor Privacy Policy. It explains the security measures, procedures, and responsibilities adopted by NEUC to protect personal data processed in electronic and non-electronic forms.

 

2. Purpose

The purpose of this Policy is to:

  1. protect the confidentiality, integrity, and availability of customers’, visitors’ and donors’ personal data;
  2. support NEUC’s compliance with the PDPA and applicable personal data protection requirements;
  3. prevent unauthorised access, misuse, disclosure, loss, alteration, destruction, or accidental exposure of personal data;
  4. support secure online and offline transactions, registrations, service engagements, donations, sponsorships, events, visits, and communications;
  5. define the responsibilities of staff, contractors, vendors, service providers, data processors, customers, visitors, donors, and authorised users in safeguarding personal data;
  6. support proper detection, reporting, investigation, containment, and mitigation of data breaches and security incidents; and
  7. promote responsible data governance, cybersecurity awareness, and confidentiality within NEUC.

 

3. Scope

This Policy applies to:

  1. customers who purchase courses, products, services, merchandise, or other offerings from NEUC, whether online or offline;
  2. visitors to NEUC’s premises, websites, online systems, events, programmes, activities, or digital platforms;
  3. donors, sponsors, contributors, benefactors, organisations, or individuals who make donations, sponsorships, endowments, philanthropic contributions, or other forms of support to NEUC;
  4. users registering accounts or submitting information through NEUC’s online platforms, websites, forms, donation channels, or service systems;
  5. NEUC staff, departments, faculties, centres, and units handling customer, visitor, or donor personal data;
  6. contractors, consultants, vendors, service providers, payment processors, cloud providers, verification providers, event service providers, and data processors processing personal data on behalf of NEUC; and
  7. all systems, applications, databases, devices, storage media, physical records, forms, registers, files, CCTV systems, donation records, transaction records, and communication records containing customer, visitor, or donor personal data.

This Policy covers personal data processed electronically, physically, internally, externally, through authorised third-party service providers, or through approved cloud or digital platforms.

 

4. Types of Personal Data Covered

Personal data protected under this Policy may include, but is not limited to:
 

4.1 Customer Personal Data

For customers who purchase courses, products, services, or otherwise engage with NEUC, personal data may include:

  1. identification details, such as name, identification card number, passport number, date of birth, gender, and nationality;
  2. contact information, such as address, email address, and phone number;
  3. transaction and payment information, such as billing details, payment records, invoices, receipts, purchase history, and refund information;
  4. service and registration information, such as course registration details, account records, service usage information, and customer support records;
  5. system and interaction data, such as website usage data, login records, platform activity records, IP addresses, and service interaction logs; and
  6. any other information voluntarily provided in connection with purchases, registrations, enquiries, feedback, or service engagement.
     

4.2 Visitor Personal Data

For visitors to NEUC’s premises, websites, events, programmes, or activities, personal data may include:

  1. identification details, such as name, identification card number, passport number, and nationality;
  2. contact information, such as phone number and email address, where required for registration, access, communication, or safety purposes;
  3. visitor and access records, including entry and exit records, visitor registration logs, vehicle registration numbers, and access control records;
  4. event registration and attendance information;
  5. images, audio recordings, video recordings, CCTV footage, event photography, livestreaming recordings, and institutional documentation;
  6. emergency contact details, where provided for safety or security purposes; and
  7. any other information voluntarily provided during visits, registrations, events, programmes, or activities.
     

4.3 Donor Personal Data

For donors, sponsors, contributors, benefactors, organisations, or individuals who make donations, sponsorships, endowments, philanthropic contributions, or other forms of support to NEUC, personal data may include:

  1. identification details, such as name, identification card number, passport number, nationality, organisation name, and organisation registration number, where applicable;
  2. contact information, such as address, email address, and phone number;
  3. donation and contribution records, such as donation amount, sponsorship amount, contribution details, donation purpose, payment records, transaction references, invoices, receipts, and donation history;
  4. tax and compliance information, such as tax identification numbers and supporting documentation, where applicable;
  5. communication records relating to donations, sponsorships, acknowledgements, campaigns, fundraising, reporting, or donor relations; and
  6. any other information voluntarily provided in connection with donations, sponsorships, endowments, philanthropic activities, or institutional contributions.
     

4.4 Sensitive Personal Data

Sensitive personal data may include information relating to physical or mental health, religious beliefs, biometric data, financial information, or other sensitive data, where applicable.

Sensitive personal data shall only be processed where necessary, with explicit consent where required by the PDPA, and shall be subject to enhanced protection and restricted access controls.

 

5. General Security Principles

NEUC shall implement reasonable, practical, and appropriate security measures by considering:

  1. the nature, category, and sensitivity of the personal data;
  2. the purpose for which the personal data is processed;
  3. the risk of harm arising from unauthorised access, disclosure, misuse, loss, alteration, or destruction;
  4. the location, method, and medium of storage;
  5. the security technologies, safeguards, and procedures available;
  6. the reliability, integrity, and authorization level of personnel handling the data;
  7. the security of data transmission, sharing, and transfer methods;
  8. the need for confidentiality, accountability, and auditability;
  9. the involvement of payment processors, donation platforms, delivery providers, event vendors, cloud providers, or other third-party service providers; and
  10. emerging cybersecurity threats, operational risks, and legal or regulatory changes.

NEUC shall periodically review and improve its security measures to ensure continued protection of customers’, visitors’ and donors’ personal data.

 

6. Administrative Security Measures
 

6.1 Governance and Accountability

NEUC shall assign appropriate responsibility for personal data protection and security, including oversight by the Data Protection Officer (“DPO”) and relevant departments.

The DPO and relevant departments shall support the implementation of this Policy by:

  1. advising on PDPA compliance and personal data protection practices;
  2. supporting the handling of data access, correction, withdrawal of consent, and related requests;
  3. coordinating responses to suspected or confirmed data breaches;
  4. reviewing security practices where necessary; and
  5. promoting awareness of personal data protection obligations.
     

6.2 Authorised Processing

Customers’, visitors’ and donors’ personal data shall only be accessed, used, disclosed, transferred, retained, or processed by authorised persons for legitimate operational, administrative, transactional, service-related, safety, security, donation-related, legal, regulatory, audit, institutional, or consented purposes.

Staff and authorised users shall not access, copy, download, disclose, transfer, or use customer, visitor, or donor personal data for personal, unauthorised, or unrelated purposes.
 

6.3 Confidentiality Obligations

All staff, contractors, vendors, service providers, data processors, volunteers, or authorised persons who handle customer, visitor, or donor personal data shall maintain confidentiality and comply with applicable data protection and security obligations.

Confidentiality obligations shall continue after the end of employment, appointment, contract, engagement, or service arrangement, where applicable.
 

6.4 Training and Awareness

NEUC shall promote awareness of personal data protection and cybersecurity through appropriate training, reminders, guidance, or internal communications.

Staff handling customer, visitor, or donor personal data shall be made aware of their responsibilities, including secure handling, confidentiality, incident reporting, and compliance with this Policy and related procedures.

 

7. Security Measures for Electronically Processed Data

NEUC shall implement appropriate technical and organisational measures to protect electronically processed customer, visitor, and donor personal data.
 

7.1 Access Control

NEUC shall:

  1. restrict access to customer, visitor, and donor personal data to authorised personnel only;
  2. apply role-based access and the principle of least privilege;
  3. maintain records of personnel or user groups authorised to access personal data where appropriate;
  4. review access rights where appropriate;
  5. amend, suspend, or revoke access when a user changes role, transfers department, resigns, or no longer requires access;
  6. restrict administrator or privileged access to authorised personnel only; and
  7. prevent unauthorised access to websites, online shop systems, donation systems, payment records, visitor systems, event registration systems, databases, and related applications.
     

7.2 User Authentication

NEUC shall:

  1. assign unique user IDs and passwords to authorised users where applicable;
  2. require users to keep login credentials confidential;
  3. prohibit password sharing and credential misuse;
  4. require strong passwords or secure authentication methods where appropriate;
  5. implement multi-factor authentication for selected systems or higher-risk access where appropriate; and
  6. monitor suspicious or abnormal login activities where reasonably practicable.
     

7.3 Workstation and Device Security

Authorised personnel handling customer, visitor, or donor personal data shall:

  1. lock or log off workstations when unattended;
  2. not leave devices displaying personal data unattended in public or shared areas;
  3. use password-protected screen locking mechanisms;
  4. take reasonable steps to prevent unauthorised persons from viewing confidential information;
  5. ensure confidential documents or printed records are not left unattended;
  6. secure laptops, portable devices, and storage media containing personal data;
  7. avoid storing personal data in unauthorised personal devices, personal email accounts, messaging applications, or unapproved cloud storage; and
  8. promptly report lost, stolen, compromised, or suspected compromised devices containing customer, visitor, or donor personal data.
      

7.4 System and Network Security

NEUC shall implement reasonable system and network security controls, including where appropriate:

  1. antivirus, anti-malware, and endpoint protection;
  2. firewalls and network security controls;
  3. regular software updates and security patches;
  4. monitoring of systems and networks for unauthorised or suspicious activities;
  5. protection against malware, ransomware, phishing, and other cyber threats;
  6. restriction of unauthorised software installation; and
  7. secure configuration of websites, online shop systems, donation systems, event registration platforms, payment-related systems, databases, and network services.
     

7.5 Online Payment, Donation, and Transaction Security

Where NEUC processes online payments, purchases, registrations, donations, sponsorships, contributions, or related transactions, NEUC shall:

  1. use secure and authorised payment gateways, donation platforms, banking channels, or transaction methods;
  2. protect payment, donation, receipt, invoice, and transaction information from unauthorised access;
  3. restrict access to payment and donation records to authorised personnel only;
  4. avoid collecting or storing payment card details unless necessary and properly secured;
  5. use encryption, secure connections, or other appropriate safeguards for online transactions;
  6. monitor transaction-related systems for suspicious activities where practicable;
  7. ensure payment processors, donation platform providers, and relevant service providers maintain appropriate security and confidentiality measures; and
  8. maintain transaction and donation records securely for legal, financial, audit, tax, administrative, and institutional purposes.
     

7.6 Data Storage and Backup

NEUC shall where appropriate:

  1. store customer, visitor, and donor personal data in secure and controlled environments;
  2. restrict access to storage locations, databases, folders, and backup systems;
  3. maintain secure backup and disaster recovery arrangements where appropriate;
  4. conduct backup verification or recovery testing periodically where practicable;
  5. apply encryption, masking, or other protection measures for sensitive data where appropriate;
  6. avoid unnecessary duplication of personal data; and
  7. ensure backup data is protected against unauthorised access, loss, or corruption.
     

7.7 Data Transfer Security

NEUC shall:

  1. use secure and authorised methods when transferring customer, visitor, or donor personal data electronically;
  2. restrict the use of removable media, personal email, unauthorised cloud services, or unapproved file-sharing platforms;
  3. apply encryption, password protection, access restriction, secure links, or other safeguards where appropriate;
  4. verify recipients before disclosing or transferring personal data;
  5. maintain records of significant or higher-risk data transfers where necessary; and
  6. ensure that cloud service providers, payment processors, event vendors, delivery providers, donation platforms, or data processors provide appropriate protection for personal data.
     

7.8 Logging and Monitoring

NEUC shall, where appropriate:

  1. maintain logs of access to critical systems and personal data;
  2. monitor unauthorised access attempts, abnormal activities, and security alerts;
  3. retain logs for audit, investigation, security, and compliance purposes; and
  4. review logs or reports where necessary to support incident detection and investigation.
      

7.9 Email, Online Platform, and Communication Security

When using email, websites, online forms, event platforms, donation platforms, customer service systems, or other digital communication channels, NEUC staff and authorised users shall:

  1. verify recipients before sending customer, visitor, or donor personal data;
  2. avoid sending unnecessary personal data;
  3. use password protection, encryption, or secure links for sensitive attachments where appropriate;
  4. avoid disclosing personal data through unauthorised messaging applications or public platforms;
  5. use official or approved communication channels where possible; and
  6. report misdirected emails, accidental disclosures, or suspected unauthorised sharing promptly.
     

7.10 Use of Artificial Intelligence Tools and Online Large Language Models

Where artificial intelligence tools, generative AI tools, online large language models, automated processing tools, AI-assisted transcription tools, translation tools, image generation tools, analytics tools, or similar digital technologies (“AI Tools”) are used in connection with NEUC’s customer service, visitor management, event administration, donation management, communication, marketing, administrative, operational, or institutional activities, NEUC shall ensure that such use is subject to appropriate personal data protection and security controls.

Staff, authorised users, contractors, vendors, service providers, and data processors shall not upload, enter, paste, share, or submit customers’, visitors’ or donors’ personal data, sensitive personal data, confidential records, identification documents, payment records, transaction records, invoices, receipts, donation records, sponsorship records, tax or compliance documents, visitor registration records, access logs, CCTV footage, event photographs, audio recordings, video recordings, livestream recordings, customer enquiries, donor communications, correspondence, or other non-public information into public or unauthorised AI Tools, unless prior approval has been obtained and appropriate safeguards are in place. 

Where AI Tools are used, NEUC shall take reasonable steps to ensure that:

  1. the AI Tool has been reviewed or approved by NEUC before being used for work-related purposes involving customer, visitor or donor personal data;
  2. the use of AI Tools is limited to lawful, authorised, necessary, and relevant customer service, visitor management, event administration, donation management, operational, communication, or institutional purposes;
  3. customer, visitor and donor personal data is anonymized, pseudonymized, masked, redacted, or minimized before being entered into an AI Tool, where practicable;
  4. sensitive personal data, including health information, biometric data, financial information, payment-related information, tax information, or other sensitive records, is not processed using AI Tools unless necessary, authorised, and protected by appropriate safeguards;
  5. confidential or restricted customer, visitor, donor, payment, transaction, donation, sponsorship, event, access control, or CCTV records are not uploaded to public AI platforms, personal AI accounts, unauthorised browser extensions, or unapproved third-party tools;
  6. AI Tools are not used to profile, evaluate, rank, exclude, approve, reject, or make decisions about customers, visitors, donors, sponsors, contributors, or event participants in a way that may significantly affect their access to NEUC’s services, events, premises, donation arrangements, transactions, benefits, recognition, rights, or interests, unless such use is authorised, lawful, transparent, and subject to appropriate human review;
  7. AI-generated outputs are reviewed by authorised personnel before being used for customer communication, visitor communication, donor communication, service response, event administration, publication, marketing, publicity, fundraising, reporting, or record purposes;
  8. contracts, terms of service, data processing terms, retention practices, security measures, confidentiality commitments, and cross-border transfer implications of AI Tool providers are reviewed where necessary;
  9. access to approved AI Tools is controlled, limited to authorised users, and monitored where appropriate;
  10. prompts, uploaded files, transcripts, summaries, generated outputs, and AI-assisted records containing customer, visitor or donor personal data are stored, retained, deleted, or archived securely in accordance with NEUC’s retention and disposal requirements;
  11. AI Tools are not used to bypass NEUC’s approved systems, access controls, payment controls, donation management procedures, visitor registration procedures, event administration procedures, confidentiality obligations, or personal data protection requirements; and
  12. any suspected unauthorised disclosure, accidental upload, misuse, loss, or exposure of customer, visitor or donor personal data through AI Tools is reported immediately as a data breach or security incident.

Customers, visitors and donors are encouraged not to submit unnecessary personal data, sensitive personal data, confidential documents, identification documents, payment information, donation records, tax documents, third-party personal data, login credentials, or NEUC’s non-public information into public AI Tools when communicating with NEUC, participating in NEUC events, making purchases, submitting enquiries, making donations, or engaging with NEUC-related services.

The use of AI Tools shall not reduce NEUC’s responsibility to protect customer, visitor and donor personal data under the PDPA, the NEUC Customer, Visitor & Donor Privacy Policy, this Policy, and any applicable internal procedures.

 

8. Security Measures for Physical and Non-Electronic Data

NEUC shall implement appropriate safeguards for physical records containing customer, visitor, or donor personal data.
 

8.1 Physical Access Control

NEUC shall:

  1. restrict access to physical records containing personal data to authorised personnel only;
  2. store records in locked cabinets, secure rooms, restricted areas, or other controlled locations where appropriate;
  3. maintain access records where appropriate;
  4. protect storage areas from theft, unauthorised access, fire, flood, water damage, and other physical risks where reasonably practicable; and
  5. ensure that visitors or unauthorised persons do not access restricted record storage areas.
     

8.2 Clean Desk and Secure Handling

Staff and authorised users shall:

  1. handle physical records containing customer, visitor, or donor personal data securely;
  2. prevent unauthorised viewing, copying, photographing, removal, or disclosure of records;
  3. avoid leaving confidential documents unattended in public, shared, or unsecured areas;
  4. clear confidential documents from desks, counters, event registration areas, donation counters, meeting rooms, printers, photocopiers, and shared workspaces after use;
  5. keep printed records to the minimum necessary; and
  6. return files, donation records, visitor logs, receipts, registration forms, and transaction documents to secure storage after use.
     

8.3 Printing, Copying, and Scanning

When printing, copying, or scanning customer, visitor, or donor personal data, staff and authorised users shall:

  1. collect printed documents promptly;
  2. check printers, photocopiers, and scanners to ensure no confidential documents are left behind;
  3. avoid unnecessary printing or duplication;
  4. ensure scanned copies are stored in approved locations; and
  5. securely dispose of unwanted or duplicate copies.
     

8.4 Physical Transfer of Records

Where customer, visitor, or donor personal data is transferred physically by hand, mail, courier, delivery service, internal dispatch, or other authorised methods, NEUC shall take reasonable steps to:

  1. package and label documents securely;
  2. verify the intended recipient and delivery address;
  3. use reliable delivery methods where appropriate;
  4. maintain records of significant or sensitive physical transfers where necessary; and
  5. promptly investigate missing, delayed, damaged, or wrongly delivered records.
     

8.5 Secure Disposal of Physical Records

NEUC shall securely dispose of physical records containing customer, visitor, or donor personal data when they are no longer required, subject to applicable retention requirements.

Secure disposal methods may include shredding, pulping, secure destruction, or other approved disposal methods that prevent reconstruction, recovery, or unauthorised use of the records.

 

9. Vendor and Data Processor Security

Where third-party vendors, service providers, contractors, consultants, payment processors, delivery providers, event service providers, donation platform providers, cloud providers, verification providers, or data processors process customer, visitor, or donor personal data on behalf of NEUC, NEUC shall take reasonable steps to ensure that such parties provide a comparable level of protection for personal data.

NEUC shall, where appropriate:

  1. conduct reasonable assessment or due diligence before engaging vendors or data processors;
  2. require appropriate contractual terms, confidentiality obligations, or data processing agreements;
  3. require vendors and data processors to process personal data only according to NEUC’s instructions and for authorised purposes;
  4. require adequate technical, administrative, and physical security measures;
  5. restrict unauthorised onward disclosure or transfer of personal data;
  6. require prompt reporting of actual or suspected data breaches or security incidents;
  7. require secure return, deletion, or destruction of personal data upon completion or termination of services, where applicable; and
  8. monitor or review vendor compliance where necessary.

 

10. Responsibilities of Customers, Visitors and Donors

Customers, visitors, and donors play an important role in protecting their own personal data and the security of NEUC’s systems, services, and platforms.

Customers, visitors, and donors are encouraged to:

  1. provide accurate, complete, and updated personal information to NEUC;
  2. protect their account passwords, login credentials, verification codes, and transaction details;
  3. avoid sharing account credentials or confidential transaction information with others;
  4. use secure internet connections when making online purchases, registrations, payments, donations, or submissions;
  5. notify NEUC promptly of suspicious or unauthorised account activities, transactions, donations, communications, or access;
  6. ensure that personal devices used to access NEUC systems are reasonably secured; and
  7. communicate with NEUC through official or trusted channels where possible.

Customers, visitors, and donors shall not:

  1. attempt unauthorised access to NEUC systems, websites, platforms, records, or accounts;
  2. misuse NEUC websites, online services, donation channels, or digital platforms;
  3. interfere with the security or operation of NEUC systems;
  4. impersonate another person or organisation;
  5. submit false, misleading, or unauthorised personal data; or
  6. upload, distribute, or use malicious software, unauthorised tools, or harmful content on NEUC systems.

 

11. Responsibilities of Staff and Authorised Users

All staff and authorised users handling customer, visitor, or donor personal data shall:

  1. access personal data only for authorised and legitimate purposes;
  2. maintain the confidentiality of personal data;
  3. comply with this Policy, the NEUC Customer, Visitor & Donor Privacy Policy, applicable procedures, and PDPA requirements;
  4. process only the minimum personal data necessary for the relevant purpose;
  5. ensure personal data is accurate and updated where they are responsible for maintaining such records;
  6. handle electronic and physical records securely;
  7. protect passwords, login credentials, and system access rights;
  8. lock or log off workstations when unattended;
  9. attend relevant PDPA, privacy, information security, or cybersecurity training where required;
  10. report actual or suspected data breaches, security incidents, unauthorised access, loss, theft, or accidental disclosure immediately; and
  11. cooperate with investigations, audits, corrective actions, and security improvement measures.

 

12. Data Breach and Security Incident Management

NEUC shall establish and maintain procedures to manage actual or suspected personal data breaches and security incidents involving customer, visitor, or donor personal data.

A personal data breach or security incident may include:

  1. unauthorised access to customer, visitor, or donor personal data;
  2. unauthorised disclosure or sharing of personal data;
  3. loss or theft of files, forms, receipts, donation records, devices, storage media, or documents containing personal data;
  4. accidental sending of personal data to the wrong recipient;
  5. malware, ransomware, phishing, system compromise, or cyberattack involving personal data;
  6. unauthorised alteration, deletion, or destruction of personal data;
  7. unauthorised access to payment, donation, transaction, or registration records; or
  8. any other incident that may affect the confidentiality, integrity, or availability of personal data.

Upon becoming aware of an actual or suspected personal data breach or security incident, NEUC shall take reasonable steps to:

  1. record the incident;
  2. contain and mitigate the incident promptly;
  3. investigate the cause and scope of the incident;
  4. assess the risk and potential impact on affected customers, visitors, donors, and other relevant persons;
  5. implement corrective and preventive measures;
  6. assess whether notification to the Personal Data Protection Commissioner, Jabatan Perlindungan Data Peribadi (“JPDP”), is required;
  7. notify affected data subjects and relevant reporters where applicable; and
  8. maintain appropriate records of the incident, investigation, decision, notification, and remedial actions.

Customers, visitors, donors, staff, vendors, and authorised users shall report actual or suspected breaches or security incidents involving personal data immediately to the DPO or relevant department.

 

13. Data Retention, Archiving and Disposal

NEUC shall retain customer, visitor, and donor personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required for legal, regulatory, audit, administrative, financial, tax, security, contractual, dispute-resolution, or institutional purposes.

Where applicable, the retention period for personal data shall be determined in accordance with NEUC's Record Retention Schedule, Records Management Policy, or other approved internal retention requirements.

Where personal data is no longer required and is not subject to any legal, regulatory, audit, dispute, financial, tax, or operational retention requirement, NEUC shall take reasonable steps to securely delete, dispose of, anonymize, or archive such personal data.

Secure disposal shall apply to both electronic and physical records, including databases, backup media, forms, visitor logs, event records, donation records, invoices, receipts, transaction records, scanned documents, and storage devices where applicable.

 

14. Cross-Border Transfer of Personal Data

Where customer, visitor, or donor personal data is transferred, stored, accessed, or processed outside Malaysia by NEUC’s authorised vendors, experts, service providers, cloud providers, payment processors, donation platform providers, or data processors, NEUC shall take reasonable steps to ensure that such personal data is protected in accordance with the PDPA and that a comparable level of protection is provided.

Such measures may include contractual safeguards, security requirements, access restrictions, confidentiality obligations, encryption, due diligence, or other appropriate controls.

 

15. Marketing, Publicity and Promotional Use

Where customer, visitor, or donor personal data is used for marketing, communication, publicity, promotional, donor-recognition, institutional, or public relations purposes, NEUC shall apply appropriate safeguards to prevent unauthorised or excessive disclosure.

Such safeguards may include:

  1. using personal data only for authorised or consented purposes;
  2. limiting access to images, recordings, testimonials, donor names, event participation records, or contact details to authorised personnel;
  3. obtaining consent where required by applicable law;
  4. respecting opt-out or withdrawal requests, subject to legal, operational, or contractual limitations; and
  5. reviewing promotional materials before publication where necessary to reduce unnecessary disclosure of personal data.

 

16. Compliance and Non-Compliance

Compliance with this Policy is mandatory for all persons to whom this Policy applies. Failure to comply with this Policy may result in appropriate action, including:

  1. reminder, warning, or retraining;
  2. restriction, suspension, or termination of system access;
  3. disciplinary action in accordance with applicable NEUC rules or procedures;
  4. contractual remedies against vendors, contractors, or service providers; and
  5. legal, regulatory, or enforcement action where applicable.

 

17. Policy Review

NEUC shall review this Policy periodically or whenever necessary due to:

  1. changes in the PDPA or other applicable legal or regulatory requirements;
  2. changes to the Customer, Visitor & Donor Privacy Policy;
  3. changes in NEUC’s operations, systems, technologies, donation platforms, payment systems, or data processing activities;
  4. emerging cybersecurity threats or operational risks;
  5. audit findings, security assessments, or compliance reviews; or
  6. significant data breaches or security incidents.

NEUC reserves the right to amend this Policy from time to time. The latest version should be read together with the latest NEUC Customer, Visitor & Donor Privacy Policy.

 

18. Contact Information

For matters relating to this Policy or the protection of customer, visitor and donor personal data, please contact:

Data Protection Officer (DPO)
New Era University College 

Address:
Blocks B & C, Lot 5, Seksyen 10, Jalan Bukit,
43000 Kajang, Selangor, Malaysia

Tel: 603-8740 6392/8210 3709

Email:
For PDPA-related enquiries:        dpo@newera.edu.my
For customer-related enquiries:    publicity@newera.edu.my
For visitor-related enquiries:        general@newera.edu.my
For donor-related enquiries:         public@newera.edu.my

 

 

 

(Revised and Approved by Administration Meeting on 20th May 2026)

Quick Access

NEUC STUDENT
NEUC STAFF
CONVOCATION
VISITORS

address

Blok B&C, Lot 5, Seksyen 10, Jalan Bukit,
43000 Kajang, Selangor.

phone

03-8210 3709 (Main Line)
03-8740 6392 (Main Line)
03-8740 4392
03-8741 8192
03-8741 4923
03-8741 4924
03-8740 6925
03-8737 9292

email

neuc@newera.edu.my

OFFICE HOURS

Monday to Friday: 8:30am - 5:00pm
(Off on Saturday, Sunday and Public Holidays)