NEW ERA UNIVERSITY COLLEGE
VENDOR AND DATA PROCESSOR
PERSONAL DATA SECURITY POLICY
1. Policy Statement
This Vendor and Data Processor Personal Data Security Policy (“Policy”) is issued as an extension of Clause 7, Security of Personal Data, in the New Era University College (“NEUC”) Vendor Privacy Policy.
At New Era University College (“NEUC”, the University College, “we”, “our”, or “us”), a private higher education institution fully owned by New Era Edu Sdn. Bhd., we are committed to ensuring that all vendors, contractors, consultants, cloud providers, service providers, outsourced service providers, and other third parties processing personal data on behalf of NEUC implement appropriate personal data protection and security measures.
This Policy applies to vendors and individuals acting on behalf of or associated with vendors (“vendor representatives”), including external parties who process, access, store, transmit, host, support, maintain, or otherwise handle personal data for or on behalf of NEUC.
As the data controller, NEUC is responsible for personal data under its control, including personal data processed by vendors or data processors on its behalf. Vendors and data processors are required to implement appropriate technical, administrative, organisational, and physical security measures to safeguard personal data against loss, misuse, unauthorised access, unauthorised disclosure, alteration, modification, destruction, accidental exposure, and cybersecurity threats.
This Policy supports and should be read together with the NEUC Vendor Privacy Policy, applicable contracts, procurement documents, data processing agreements, service agreements, confidentiality undertakings, and other applicable NEUC policies or procedures.
2. Purpose
The purpose of this Policy is to:
- establish minimum security requirements for vendors and data processors handling personal data on behalf of NEUC;
- protect the confidentiality, integrity, and availability of personal data processed by vendors and data processors;
- support NEUC’s compliance with the Personal Data Protection Act 2010 (“PDPA”), its amendments, regulations, guidelines, codes of practice, and other applicable legal or regulatory requirements;
- ensure vendors and data processors process personal data only for authorised, lawful, contractual, operational, and documented purposes;
- define the responsibilities of vendors, vendor representatives, contractors, consultants, service providers, data processors, subprocessors, and authorised personnel;
- reduce legal, operational, reputational, contractual, cybersecurity, and data breach risks;
- support secure vendor onboarding, procurement, contract administration, service delivery, payment processing, access control, and vendor management; and
- ensure proper detection, reporting, investigation, containment, mitigation, retention, return, deletion, or disposal of personal data.
3. Scope
This Policy applies to all external parties that process, access, receive, store, transmit, host, maintain, support, or otherwise handle personal data for or on behalf of NEUC, including but not limited to:
- vendors and suppliers;
- vendor representatives and authorised contact persons;
- contractors and consultants;
- IT vendors, system vendors, software providers, and cloud service providers;
- outsourced service providers;
- maintenance, support, and facilities service providers;
- payment, finance, audit, legal, insurance, payroll, background screening, verification, courier, delivery, event, recruitment, and professional service providers;
- research partners or project partners handling personal data on behalf of NEUC;
- data processors and approved subprocessors; and
- any third-party handling NEUC personal data or personal data collected, processed, or maintained for NEUC.
This Policy covers:
- personal data processed electronically;
- physical and non-electronic records;
- personal data stored internally, externally, in cloud systems, in vendor systems, or on portable media;
- personal data accessed remotely or on-site;
- personal data transferred within or outside Malaysia; and
- personal data retained, archived, returned, deleted, or disposed of by vendors or data processors.
4. Types of Personal Data Covered
Personal data protected under this Policy may include, but is not limited to:
- personal data of students, employees, job applicants, customers, visitors, donors, alumni, vendors, vendor representatives, and other data subjects whose personal data is processed by or on behalf of NEUC;
- identification details, including name, NRIC number, passport number, staff ID, student ID, vendor representative details, designation, signature, and authorisation records;
- contact information, including address, email address, phone number, and business contact details;
- business, company, procurement, and operational data, including company information, registration number, date of incorporation, contractual records, purchase orders, invoices, payment records, bank account details, tax-related information, and transaction records;
- service performance records, due diligence records, vendor evaluation records, communication records, service reports, and operational coordination records;
- system or operational access logs, user account records, support records, remote access records, security logs, and audit records;
- site access records, access control records, vehicle records, CCTV footage, visitor logs, and safety-related records where applicable;
- documents, databases, files, images, recordings, emails, forms, reports, or other records containing personal data; and
- sensitive personal data where applicable, including biometric data, financial information, health or safety-related information, and other sensitive personal data required strictly for site access, safety, biometric access systems, statutory declarations, financial due diligence, legal compliance, or other authorised purposes.
Sensitive personal data shall only be processed where necessary, with explicit consent where required by the PDPA, and shall be subject to enhanced protection and restricted access controls.
5. General Security Principles
Vendors and data processors shall implement reasonable, practical, and appropriate security measures by considering:
- the nature, category, and sensitivity of the personal data;
- the purpose and scope of processing authorised by NEUC;
- the risk of harm arising from unauthorised access, disclosure, misuse, loss, alteration, destruction, or accidental exposure;
- the location, method, and medium of storage;
- the security technologies, safeguards, and procedures available;
- the reliability, integrity, and authorisation level of personnel handling personal data;
- the security of data transmission, sharing, and transfer methods;
- the involvement of subcontractors, subprocessors, cloud providers, or other third parties;
- applicable contractual, legal, regulatory, audit, and institutional requirements; and
- emerging cybersecurity threats, operational risks, and legal or regulatory changes.
Vendors and data processors shall process personal data only in accordance with NEUC’s documented instructions, approved purposes, contracts, data processing agreements, and applicable laws.
6. Vendor Due Diligence and Onboarding
Before engaging or onboarding a vendor or data processor that may process personal data on behalf of NEUC, NEUC may request and review relevant information to assess the vendor’s suitability, including where appropriate:
- the vendor’s data protection, privacy, cybersecurity, or information security policies;
- technical, administrative, organisational, and physical security controls;
- data processing locations and cross-border transfer arrangements;
- use of subcontractors or subprocessors;
- incident response and breach notification procedures;
- retention, return, deletion, and secure disposal practices;
- certifications, audit reports, compliance documents, or security questionnaires;
- business continuity, backup, and disaster recovery arrangements; and
- any other information reasonably required for procurement, due diligence, compliance, audit, or risk management purposes.
NEUC may decline, suspend, or terminate engagement with vendors that do not meet NEUC’s personal data protection or security requirements.
7. Data Processing Agreement and Contractual Controls
All vendors and data processors that process personal data on behalf of NEUC shall be subject to appropriate contractual terms, confidentiality obligations, and, where necessary, a Data Processing Agreement (“DPA”) or equivalent written arrangement before accessing or processing NEUC personal data.
Such agreement or arrangement may include:
- the purpose, scope, nature, and duration of processing;
- the categories of personal data and data subjects involved;
- confidentiality obligations;
- technical, administrative, organisational, and physical security requirements;
- access control and personnel security requirements;
- data breach and security incident notification obligations;
- audit, inspection, and compliance review rights;
- data retention, return, deletion, and destruction requirements;
- cross-border transfer restrictions and safeguards;
- subprocessor appointment restrictions and approval requirements;
- cooperation obligations in relation to data subject requests, investigations, audits, and regulatory enquiries;
- restrictions on unauthorised disclosure, reuse, sale, sharing, or secondary use of personal data; and
- NEUC’s right to suspend access, require remediation, terminate services, or seek remedies for non-compliance.
No vendor or data processor shall process NEUC personal data except as authorised by NEUC and subject to appropriate contractual or written obligations.
8. Security Measures for Electronically Processed Data
8.1 Access Control
Vendors and data processors shall:
- restrict access to personal data to authorised personnel only;
- apply role-based access and the principle of least privilege;
- maintain records of personnel or user groups authorised to access personal data;
- review access rights periodically;
- immediately amend, suspend, or revoke access when personnel resign, transfer, change role, complete engagement, or no longer require access;
- restrict administrator, privileged, remote, and support access to authorised personnel only;
- prevent shared, generic, or uncontrolled accounts unless technically necessary and approved with compensating controls; and
- ensure access to NEUC systems, vendor systems, cloud systems, databases, and support tools is properly controlled.
8.2 User Authentication
Vendors and data processors shall:
- assign unique user IDs and secure passwords to authorised users where applicable;
- require users to keep login credentials confidential;
- prohibit password sharing and credential misuse;
- enforce strong password or secure authentication requirements;
- implement multi-factor authentication for privileged access, remote access, cloud systems, and higher-risk systems where appropriate; and
- monitor suspicious or abnormal login activities where reasonably practicable.
8.3 System and Network Security
Vendors and data processors shall implement appropriate system and network security controls, including where applicable:
- antivirus, anti-malware, endpoint detection, or endpoint protection measures;
- firewalls and network security controls;
- regular software updates and security patches;
- vulnerability management and remediation practices;
- secure configuration of systems, applications, databases, cloud services, and network services;
- protection against malware, ransomware, phishing, unauthorised access, and other cyber threats;
- monitoring of systems and networks for suspicious or unauthorised activities;
- segregation of environments where appropriate, including production, testing, and development environments; and
- restriction of unauthorised software, unauthorised tools, and insecure services.
8.4 Data Protection, Storage, and Backup
Vendors and data processors shall ensure that personal data is:
- protected against unauthorised access, use, disclosure, alteration, loss, or destruction;
- stored only in approved systems, locations, environments, or platforms;
- encrypted during transmission where appropriate;
- encrypted, masked, pseudonymised, or otherwise protected during storage where appropriate, especially for sensitive personal data;
- backed up securely where necessary for service continuity;
- protected against unauthorised access to backup data;
- subject to backup verification or recovery testing where appropriate; and
- not duplicated, downloaded, exported, or retained unnecessarily.
8.5 Data Transfer Security
Vendors and data processors shall:
- use secure and authorised methods when transferring personal data;
- restrict the use of removable media, personal email, unauthorised cloud services, public file-sharing services, or unapproved communication channels;
- apply encryption, password protection, secure links, access restrictions, or other safeguards where appropriate;
- verify recipients before disclosing or transferring personal data;
- maintain records of significant or higher-risk data transfers where necessary;
- transfer personal data only to locations, recipients, systems, or subprocessors authorised by NEUC; and
- promptly notify NEUC of any misdirected, unauthorised, failed, suspicious, or compromised transfer involving personal data.
8.6 Logging and Monitoring
Vendors and data processors shall, where appropriate:
- maintain logs of access to personal data, critical systems, and administrative activities;
- monitor unauthorised access attempts, abnormal activities, and security alerts;
- retain logs for audit, investigation, compliance, and security purposes;
- protect logs against unauthorised alteration or deletion; and
- provide relevant logs or reports to NEUC upon request for investigation, audit, or compliance review.
8.7 Workstation, Device, and Remote Access Security
Vendor personnel handling NEUC personal data shall:
- use secured workstations, laptops, mobile devices, and portable storage media;
- lock or log off devices when unattended;
- use password-protected screen locking mechanisms;
- prevent unauthorised persons from viewing confidential information;
- avoid storing NEUC personal data on unauthorised personal devices, personal email accounts, messaging applications, or unapproved cloud storage;
- secure laptops and portable devices containing personal data;
- protect remote access with appropriate security controls; and
- promptly report lost, stolen, compromised, or suspected compromised devices containing NEUC personal data.
9. Physical and Non-Electronic Data Security
Where vendors and data processors handle physical records containing personal data, they shall implement appropriate safeguards.
9.1 Physical Access Control
Vendors and data processors shall:
- restrict access to physical records containing personal data to authorised personnel only;
- store records in locked cabinets, secure rooms, restricted areas, or other controlled locations where appropriate;
- maintain access records where appropriate;
- protect storage areas from theft, unauthorised access, fire, flood, water damage, and other physical risks where reasonably practicable; and
- ensure unauthorised persons do not access restricted storage or work areas.
9.2 Clean Desk and Secure Handling
Vendor personnel shall:
- handle physical records containing personal data securely;
- prevent unauthorised viewing, copying, photographing, removal, or disclosure of records;
- avoid leaving confidential documents unattended in public, shared, or unsecured areas;
- clear confidential documents from desks, counters, meeting rooms, printers, photocopiers, scanners, and shared workspaces after use;
- keep printed records to the minimum necessary; and
- return records to secure storage after use.
9.3 Printing, Copying, and Scanning
When printing, copying, or scanning personal data, vendors and data processors shall:
- collect printed documents promptly;
- check printers, photocopiers, and scanners to ensure no confidential documents are left behind;
- avoid unnecessary printing or duplication;
- ensure scanned copies are stored in approved locations; and
- securely dispose of unwanted or duplicate copies.
9.4 Physical Transfer of Records
Where personal data is transferred physically by hand, mail, courier, delivery service, internal dispatch, or other authorised methods, vendors and data processors shall take reasonable steps to:
- package and label documents securely;
- verify the intended recipient and delivery address;
- use reliable delivery methods where appropriate;
- maintain records of significant or sensitive physical transfers where necessary; and
- promptly investigate and report missing, delayed, damaged, wrongly delivered, or compromised records.
9.5 Secure Disposal of Physical Records
Vendors and data processors shall securely dispose of physical records containing personal data when they are no longer required and where disposal is authorised by NEUC.
Secure disposal methods may include shredding, pulping, secure destruction, or other approved disposal methods that prevent reconstruction, recovery, or unauthorised use of the records.
Vendors and data processors shall provide destruction confirmation to NEUC upon request.
10. Personnel and Confidentiality
Vendors and data processors shall ensure that:
- only authorised personnel handle NEUC personal data;
- personnel access personal data only on a need-to-know basis;
- personnel are subject to confidentiality obligations before accessing personal data;
- confidentiality obligations continue after the end of employment, appointment, contract, or engagement where applicable;
- personnel receive appropriate PDPA, privacy, confidentiality, and cybersecurity awareness training;
- personnel are instructed not to use personal data for unauthorised, personal, unrelated, or secondary purposes;
- personnel promptly report actual or suspected data breaches, security incidents, unauthorised access, loss, theft, or accidental disclosure; and
- personnel comply with this Policy, applicable contracts, data processing agreements, and NEUC’s instructions.
11. Subprocessors and Third Parties
Vendors and data processors shall not appoint, replace, or allow any subcontractor, subprocessor, related company, cloud provider, outsourced provider, or other third party to process NEUC personal data without NEUC’s prior written approval, unless otherwise authorised in writing.
Where NEUC approves the use of a subprocessor, the vendor or data processor shall ensure that:
- the subprocessor is subject to equivalent personal data protection, confidentiality, and security obligations;
- the subprocessor processes personal data only for authorised purposes;
- the subprocessor does not further disclose, transfer, or appoint another subprocessor without appropriate authorisation;
- appropriate security safeguards are implemented;
- breach notification obligations are imposed on the subprocessor;
- cross-border transfer restrictions are complied with; and
- the vendor or data processor remains responsible to NEUC for the acts and omissions of its subprocessors.
12. Cross-Border Transfer of Personal Data
Vendors and data processors shall not transfer, store, access, host, or process NEUC personal data outside Malaysia without NEUC’s prior written approval, unless such transfer has been expressly authorised under the applicable contract or data processing agreement.
Where cross-border transfer is authorised, vendors and data processors shall ensure that:
- the transfer complies with applicable PDPA requirements;
- a comparable level of protection is provided for the personal data;
- appropriate contractual, technical, organisational, and security safeguards are implemented;
- the location of processing, hosting, storage, access, or support is disclosed to NEUC where required;
- subprocessors or overseas recipients are subject to equivalent obligations; and
- NEUC is promptly informed of any material change affecting cross-border processing arrangements.
13. Data Breach and Security Incident Management
Vendors and data processors shall immediately notify NEUC of any actual or suspected personal data breach or security incident involving NEUC personal data.
A personal data breach or security incident may include:
- unauthorised access to personal data;
- unauthorised disclosure, sharing, or transfer of personal data;
- loss or theft of files, devices, storage media, documents, or systems containing personal data;
- accidental sending of personal data to the wrong recipient;
- malware, ransomware, phishing, system compromise, or cyberattack involving personal data;
- unauthorised alteration, deletion, or destruction of personal data;
- unauthorised access to cloud systems, databases, user accounts, logs, or support tools;
- breach involving a subprocessor or third party; or
- any other incident that may affect the confidentiality, integrity, or availability of personal data.
Upon becoming aware of an actual or suspected breach or incident, the vendor or data processor shall:
- notify NEUC without undue delay and, where contractually required, within the specified notification timeframe;
- contain and mitigate the incident promptly;
- preserve relevant evidence, logs, records, and affected materials;
- investigate the cause, scope, timeline, affected data, affected systems, and potential impact;
- provide NEUC with relevant information required for assessment, investigation, notification, remediation, and reporting;
- cooperate fully with NEUC, the DPO, auditors, regulators, and authorised investigators;
- not notify data subjects, regulators, media, or third parties on behalf of NEUC unless authorised by NEUC or required by law;
- implement corrective and preventive measures; and
- provide incident reports, root cause analysis, remediation plans, and closure reports where requested.
NEUC’s DPO will record, investigate, implement or coordinate security measures, assess whether notification to the Personal Data Protection Commissioner, Jabatan Perlindungan Data Peribadi (“JPDP”), is required where necessary, and notify affected data subjects and reporters where applicable.
14. Data Retention, Return, Deletion, and Disposal
Vendors and data processors shall retain NEUC personal data only for the approved duration, authorised purpose, and contractual or legal requirement.
Upon completion, expiry, termination, or written request by NEUC, vendors and data processors shall, according to NEUC’s instructions:
- return personal data to NEUC;
- securely delete or destroy personal data;
- anonymise personal data where authorised;
- securely dispose of physical records and electronic records;
- delete personal data from live systems, storage locations, backup systems, portable devices, and user accounts where practicable and authorised;
- ensure deleted data cannot be reconstructed or recovered through ordinary means; and
- provide written confirmation or evidence of deletion, destruction, return, or disposal upon request by NEUC.
Vendors and data processors shall not retain copies of NEUC personal data after completion or termination of services unless retention is required by law or expressly authorised by NEUC.
15. Audit, Compliance Review, and Cooperation
NEUC reserves the right to conduct or request audits, compliance reviews, security assessments, questionnaires, inspections, evidence reviews, or investigations relating to the vendor’s or data processor’s processing of personal data.
Vendors and data processors shall:
- cooperate with NEUC’s audits, investigations, compliance reviews, and security assessments;
- provide reasonable evidence of compliance upon request;
- provide relevant policies, procedures, certifications, reports, logs, or control evidence where appropriate;
- remediate identified weaknesses, gaps, or non-compliance within a reasonable timeframe agreed with NEUC;
- notify NEUC of material changes affecting personal data processing or security controls; and
- support NEUC in responding to data subject requests, regulatory enquiries, audits, investigations, or legal obligations.
16. Use of Artificial Intelligence Tools and Online Large Language Models
Where artificial intelligence tools, generative AI tools, online large language models, automated processing tools, AI-assisted transcription tools, translation tools, image generation tools, analytics tools, or similar digital technologies (“AI Tools”) are used by vendors or data processors in connection with services provided to NEUC, such use shall be subject to appropriate personal data protection and security controls.
Vendors, data processors, subprocessors, and their personnel shall not upload, enter, paste, share, or submit NEUC personal data, sensitive personal data, confidential records, identification documents, student records, employee records, customer records, visitor records, donor records, vendor records, payment records, bank account details, invoices, contracts, access logs, CCTV footage, images, audio recordings, video recordings, system logs, support tickets, correspondence, or other non-public NEUC information into public or unauthorised AI Tools, unless prior written approval has been obtained from NEUC and appropriate safeguards are in place.
Where AI Tools are used, vendors and data processors shall ensure that:
- the AI Tool has been reviewed and approved for the relevant purpose before use;
- the use of AI Tools is limited to lawful, authorised, necessary, and contractually permitted purposes;
- personal data is anonymised, pseudonymised, masked, redacted, or minimised before being entered into an AI Tool, where practicable;
- sensitive personal data is not processed using AI Tools unless necessary, authorised, and protected by appropriate safeguards;
- confidential or restricted NEUC records are not uploaded to public AI platforms, personal AI accounts, unauthorised browser extensions, or unapproved third-party tools;
- AI-generated outputs are reviewed by authorised personnel before being used for service delivery, reporting, communication, publication, decision-making, or record purposes;
- contracts, terms of service, data processing terms, retention practices, security measures, confidentiality commitments, and cross-border transfer implications of AI Tool providers are reviewed where necessary;
- prompts, uploaded files, transcripts, summaries, generated outputs, and AI-assisted records containing NEUC personal data are stored, retained, deleted, or archived securely in accordance with NEUC’s instructions and applicable retention requirements;
- AI Tools are not used to bypass NEUC’s approved systems, access controls, procurement procedures, contractual obligations, confidentiality obligations, or personal data protection requirements; and
- any suspected unauthorised disclosure, accidental upload, misuse, loss, or exposure of personal data through AI Tools is reported immediately as a data breach or security incident.
The use of AI Tools shall not reduce the vendor’s or data processor’s responsibility to protect personal data under the PDPA, this Policy, the NEUC Vendor Privacy Policy, applicable contracts, and any data processing agreement.
17. Prohibited Activities
Vendors, data processors, subprocessors, and their personnel shall not:
- process personal data for unauthorised purposes;
- use personal data for their own commercial, marketing, analytics, training, profiling, product development, or unrelated purposes without NEUC’s written authorisation;
- disclose personal data to unauthorised persons or third parties;
- appoint subprocessors without required approval;
- transfer personal data outside Malaysia without required approval;
- store personal data in unapproved systems, locations, devices, or platforms;
- share user accounts, passwords, or access credentials;
- disable, bypass, or interfere with security controls, monitoring, logging, or audit functions;
- copy, download, export, retain, or print personal data unnecessarily;
- combine NEUC personal data with other datasets except where authorised;
- use personal data for AI training, machine learning, testing, or model improvement without NEUC’s written authorisation; or
- retain personal data after completion or termination of services unless authorised or required by law.
18. Responsibilities of Vendor Representatives
Vendor representatives and authorised personnel shall:
- provide accurate, complete, and updated personal data to NEUC where required for vendor registration, onboarding, access, payment, due diligence, safety, or compliance purposes;
- maintain confidentiality of NEUC personal data and confidential information;
- access personal data only for authorised purposes;
- comply with this Policy, the NEUC Vendor Privacy Policy, applicable contracts, data processing agreements, and NEUC’s instructions;
- protect passwords, access credentials, devices, files, and records;
- report suspected unauthorised access, data breaches, security incidents, loss, theft, or accidental disclosure immediately;
- cooperate with NEUC’s investigations, audits, compliance reviews, and corrective actions; and
- ensure that their personnel, agents, contractors, and approved subprocessors comply with equivalent obligations.
19. Non-Compliance
Failure to comply with this Policy may result in appropriate action, including:
- requirement to remedy or improve security controls;
- suspension or restriction of access to NEUC systems, premises, records, or personal data;
- suspension of procurement, onboarding, payment, or service activities where appropriate;
- contract termination;
- removal or replacement of vendor personnel;
- claims for losses, damages, costs, penalties, or liabilities;
- reporting to relevant authorities where required; and
- legal, regulatory, contractual, or enforcement action where applicable.
20. Template Contract Clause
Where appropriate, the following clause may be included in contracts, purchase orders, service agreements, data processing agreements, or other vendor documents:
“The Vendor/Data Processor shall implement appropriate technical, administrative, organisational, and physical security measures to protect personal data from unauthorised access, disclosure, loss, misuse, alteration, destruction, accidental exposure, and cybersecurity threats. The Vendor/Data Processor shall process personal data only for authorised purposes and in accordance with NEUC’s documented instructions, the Personal Data Protection Act 2010, its amendments, applicable regulations, this Policy, and any applicable data processing agreement.
The Vendor/Data Processor shall ensure that all employees, representatives, contractors, agents, and approved subprocessors handling personal data are bound by confidentiality and equivalent data protection obligations. The Vendor/Data Processor shall not disclose, transfer, store, process, or provide access to personal data to any third party or outside Malaysia without NEUC’s prior written approval, unless otherwise authorised in writing.
The Vendor/Data Processor shall immediately notify NEUC of any actual or suspected personal data breach or security incident, cooperate fully with NEUC’s investigation, provide relevant information and evidence, and implement corrective and preventive measures. Upon completion, expiry, termination, or request by NEUC, the Vendor/Data Processor shall return or securely delete/destroy all personal data and provide confirmation upon request. NEUC reserves the right to audit or review the Vendor/Data Processor’s compliance with these obligations.”
21. Policy Review
NEUC shall review this Policy periodically or whenever necessary due to:
- changes in the PDPA or other applicable legal or regulatory requirements;
- changes to the NEUC Vendor Privacy Policy;
- changes in NEUC’s procurement, vendor management, systems, technologies, operations, contracts, or data processing activities;
- emerging cybersecurity threats or operational risks;
- audit findings, security assessments, due diligence findings, or compliance reviews; or
- significant data breaches or security incidents.
NEUC reserves the right to amend this Policy from time to time. The latest version should be read together with the latest NEUC Vendor Privacy Policy.
22. Contact Information
For matters relating to this Policy or the protection of personal data, please contact:
Data Protection Officer (DPO)
New Era University College
Address:
Blocks B & C, Lot 5, Seksyen 10, Jalan Bukit,
43000 Kajang, Selangor, Malaysia
Tel: 603-8740 6392/8210 3709
Email:
For PDPA-related enquiries: dpo@newera.edu.my
For vendor-related enquiries: general@newera.edu.my
(Revised and Approved by Administration Meeting on 20th May 2026)