Compliance basis: Malaysia — Personal Data Protection Act 2010 (Act 709), as amended by the Personal Data Protection (Amendment) Act 2024 (Act A1727); aligned to international good practice (EU GDPR). Data controller: Mizuha Eco Solutions Sdn Bhd, Petaling Jaya, Selangor, Malaysia. Classification: Internal — Governance · Version: 1.0 · Effective date: 8 June 2026 · Next review: 8 June 2027.
This Policy is Mizuha's internal governance backbone for personal-data processing. It is given outward effect by Mizuha's external Privacy Notice (PDPA 2010, s.7; GDPR Arts. 13/14). Bracketed items marked "to be assigned/confirmed" are operational values Mizuha must populate before publication (e.g. DPO identity and contact, registered office address).
Table of Contents
- 1. Document Control
- 2. Introduction & Purpose
- 3. Scope & Application
- 4. Definitions
- 5. Legal & Regulatory Framework
- 6. Data Protection Principles
- 7. Categories of Personal Data We Process
- 8. Purposes & Lawful Basis of Processing
- 9. Consent Management
- 10. Privacy Notice (s.7 Notice & Choice)
- 11. Data Subject Rights
- 12. Data Subject Request Handling Procedure
- 13. Direct Marketing & Cookies
- 14. Security Measures
- 15. Data Retention & Disposal
- 16. Personal Data Breach Management & Notification
- 17. Data Processors & Third Parties
- 18. Cross-Border Data Transfers
- 19. Data Protection Officer (DPO)
- 20. Roles & Responsibilities
- 21. Training & Awareness
- 22. Monitoring, Audit & Accountability
- 23. Complaints & Regulatory Enforcement
- 24. Consequences of Non-Compliance
- 25. Review & Amendment
- Appendix A — Records of Processing Activities (ROPA)
- Appendix B — Data Subject Access Request (DSAR) Form & Procedure
- Appendix C — Consent Record Template
- Appendix D — Personal Data Breach Register & Commissioner Notification Template
- Appendix E — Data Retention Schedule (consolidated)
- Appendix F — Cookie & Tracking Table
- Appendix G — Data Protection Impact Assessment (DPIA) Template & Trigger Criteria
1. Document Control
| Field | Detail |
|---|---|
| Document title | Mizuha Eco Solutions Sdn Bhd — Personal Data Protection Policy |
| Document owner | Designated Privacy Owner (acting as Data Protection Officer if/when appointed), Mizuha Eco Solutions Sdn Bhd |
| Author | Designated Privacy Owner (acting as DPO if/when appointed) |
| Approved by | Board of Directors, Mizuha Eco Solutions Sdn Bhd [approving authority — to be confirmed] |
| Classification | Internal — Governance |
| Effective date | 8 June 2026 |
| Next scheduled review | 8 June 2027 (annual review cycle, or earlier upon material change in law, business model, or processing activities) |
Version history
| Version | Date | Author / Owner | Approver | Summary of change |
|---|---|---|---|---|
| 1.0 | 8 June 2026 | Designated Privacy Owner (acting as DPO if/when appointed) | Board of Directors | Initial issue. Establishes the enterprise Personal Data Protection Policy aligned to the Personal Data Protection Act 2010 (Act 709), the Personal Data Protection (Amendment) Act 2024 (Act A1727), and good international practice (EU GDPR). |
Review trigger note: Notwithstanding the fixed annual cycle, this Policy must be re-reviewed without waiting for the next scheduled date upon any of the following: (a) commencement or amendment of JPDP guidelines (e.g. the forthcoming Data Portability Guideline); (b) launch of e-commerce / online payments (a future commercial-stage expansion, distinct from the statutory commencement phases in §5.1); (c) crossing of a Data Protection Officer appointment threshold (see §19, Data Protection Officer); or (d) any reportable personal data breach.
2. Introduction & Purpose
Mizuha Eco Solutions Sdn Bhd ("Mizuha", "we", "us", or "our") is a Malaysian-incorporated company based in Petaling Jaya, Selangor, and the producer of Mizuha — Malaysia's locally-canned drinking water brand. In the ordinary course of our business — a predominantly business-to-business (B2B) operation serving HORECA, hospital corporate supply and custom-print clients, supported by a marketing website and direct-marketing activity, and expanding into premium retail and online commerce in later phases — we collect and process personal data relating to consumers, prospects, business contacts, suppliers, and partners.
We regard the personal data entrusted to us as something we hold on trust. This Policy reflects our commitment to handling that data lawfully, fairly, securely and transparently.
Purpose. This Policy:
- Establishes Mizuha's binding internal standard for the processing of personal data, anchored to the seven data protection principles under the Personal Data Protection Act 2010 (PDPA 2010, s.5(1)).
- Implements the obligations introduced by the Personal Data Protection (Amendment) Act 2024 — including direct processor security duties, mandatory breach notification, data portability, the renamed "data controller" role, and the revised cross-border transfer regime (Amendment Act 2024).
- Demonstrates accountability — that is, evidences that Mizuha not only complies but can show it complies (GDPR Art. 5(2); PDPA 2010, ss.6–12).
- Sets out the roles, responsibilities and procedures by which all personnel and processors must give effect to these obligations.
- Voluntarily aligns Mizuha's practices with good international data-protection practice, including the principles and data-subject rights of the EU General Data Protection Regulation (GDPR), so far as relevant to our processing.
This Policy is the governance backbone of Mizuha's data-protection programme. It operates alongside, and is given outward effect by, Mizuha's external-facing Privacy Notice (issued under PDPA 2010, s.7 and GDPR Arts. 13/14) and the supporting procedures and registers referenced throughout (Records of Processing, DSAR procedure, breach register, retention schedule, consent records, and cookie register).
Cause statement. Where this Policy or any associated notice refers to Mizuha's donation to the National Cancer Society Malaysia (NCSM) of RM0.20 per can (audited annually), that reference describes a charitable donation only. It is not, and must not be presented as, a medical, health or disease-prevention claim.
3. Scope & Application
3.1 Material scope (what this Policy covers)
This Policy applies to all processing of personal data carried out by or on behalf of Mizuha, in any format (electronic, paper, or otherwise) and at any stage of the data lifecycle (collection, recording, holding, use, disclosure, transfer, storage, and destruction). Without limitation, it covers personal data processed through:
- The Mizuha marketing website — including consumer waitlist sign-ups, contact-form enquiries, B2B sample-request / wholesale enquiry forms, and website analytics and cookies.
- Direct marketing — newsletters and product/trade communications, and the consent and opt-out mechanisms that govern them.
- B2B operations — lead qualification, sampling, quotation, customer relationship management (CRM), and fulfilment coordination, including named business contacts, which are personal data under both the PDPA and GDPR and are fully in scope.
- Supplier, partner and third-party relationships — including the NCSM donation reporting and annual audit, to the extent any personal data is involved.
- Future e-commerce and online payments (a future commercial-stage expansion) — order processing, fulfilment, and payment handling, once launched.
3.2 Personal scope (who must comply)
This Policy is binding on:
- All directors, officers and employees of Mizuha, whether permanent, temporary or part-time;
- All interns, secondees, contractors and consultants acting for or on behalf of Mizuha; and
- All data processors and other third parties that process personal data on Mizuha's behalf or under Mizuha's instructions (e.g. email service providers, analytics, CRM and cloud-hosting providers, and any future payment processors and couriers), who are bound through written contract and, since 1 April 2025, also bear direct statutory security obligations (Amendment Act 2024).
3.3 Territorial scope
Mizuha is a Malaysian-incorporated entity processing personal data in Malaysia, and is therefore squarely within the scope of the PDPA 2010 (PDPA 2010, s.2). Where Mizuha's processing reaches individuals in the EU/EEA (for example, EU-based hotel groups or visitors who join the waitlist), the EU GDPR may apply on an extraterritorial basis (GDPR Art. 3(2)); in such cases Mizuha applies the relevant GDPR standards in addition to the PDPA.
3.4 Relationship to other documents
This Policy prevails over any conflicting internal guidance on data protection. It does not override mandatory law: where any provision conflicts with the PDPA 2010, the Amendment Act 2024, or binding JPDP guidance, the law prevails and this Policy is to be read and applied accordingly.
4. Definitions
In this Policy, the following terms have the meanings set out below. Definitions are anchored to the PDPA 2010 (as amended by the Amendment Act 2024), with the nearest GDPR equivalent noted for alignment.
| Term | Meaning |
|---|---|
| Personal data | Any information that relates directly or indirectly to a data subject who is identified or identifiable from that information (or from that and other information in Mizuha's possession), including any expression of opinion about the individual. It covers names, email addresses, telephone numbers, online identifiers, and named B2B contacts. Information about a company or other entity is not personal data, but information about a named individual within it is (PDPA 2010, s.4; cf. GDPR Art. 4(1)). |
| Sensitive personal data | Personal data consisting of information as to a data subject's physical or mental health or condition, political opinions, religious or other beliefs of a similar nature, the commission or alleged commission of any offence, and biometric data (added by the Amendment Act 2024). Processing requires the data subject's explicit consent (PDPA 2010, s.40; cf. GDPR Arts. 4(13)–(14), 9). Mizuha's standing position is not to collect sensitive or biometric data. |
| Data subject | The individual who is the subject of the personal data (PDPA 2010, s.4; cf. GDPR "data subject", Art. 4(1)). |
| Data controller (formerly "data user") | The person who, either alone or jointly or in common with others, determines the purposes and means of the processing of personal data. The Amendment Act 2024 renamed "data user" to "data controller" (effective 1 April 2025). Mizuha is a data controller in respect of the processing described in this Policy (PDPA 2010, s.4 as amended; cf. GDPR "controller", Art. 4(7)). |
| Data processor | Any person, other than an employee of the data controller, who processes personal data solely on behalf of the data controller and does not process it for any of their own purposes. Since 1 April 2025, processors bear direct statutory obligations, in particular compliance with the Security Principle (PDPA 2010, s.4; s.5(1A) and s.9 as amended; cf. GDPR "processor", Arts. 4(8), 28). |
| Processing | Any operation performed on personal data, including collecting, recording, holding, storing, organising, using, disclosing, transferring, combining, correcting, erasing or destroying it (PDPA 2010, s.4; cf. GDPR Art. 4(2)). |
| Consent | A freely given, specific and informed indication by the data subject signifying agreement to the processing of their personal data. Under the PDPA, consent must be capable of being recorded and maintained (PDPA 2010, s.6; Personal Data Protection Regulations 2013, Reg. 3). Mizuha uses unticked opt-in and does not bundle consents; direct marketing requires a separate, distinct opt-in (cf. GDPR Arts. 4(11), 7). |
| Data Protection Officer (DPO) | The individual designated to oversee Mizuha's data-protection compliance and to act as the primary contact point for data subjects and for the Commissioner. Appointment is mandatory on a threshold basis under the DPO Appointment Guideline (effective 1 June 2025); where not yet legally mandatory, Mizuha designates a responsible privacy owner. The DPO must be proficient in Malay and English, be resident in or easily contactable in Malaysia, and be notified to the Commissioner within 21 days of appointment (Amendment Act 2024; DPO Appointment Guideline; cf. GDPR Arts. 37–39). |
| Personal data breach | A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data processed by or on behalf of Mizuha. A breach may be reportable to the Commissioner and, where it causes or is likely to cause significant harm, to affected data subjects (Amendment Act 2024; Data Breach Notification Guideline; cf. GDPR Arts. 4(12), 33–34). |
| Cross-border transfer | Any transfer of personal data to a place outside Malaysia. Such transfers are permitted only on a lawful basis under the revised regime — where the destination has a substantially similar law or ensures an adequate, at-least-equivalent level of protection, or where another enumerated basis applies (PDPA 2010, s.129 as amended; Cross-Border Personal Data Transfer Guideline No. 3/2025; cf. GDPR Chapter V). |
| The Commissioner / JPDP | The Personal Data Protection Commissioner (PDPA 2010, s.47), heading the Department of Personal Data Protection (Jabatan Perlindungan Data Peribadi, "JPDP") under the Ministry of Digital. The Commissioner is the regulator responsible for registration, complaints, investigations, Codes of Practice, DPO registration and breach notification (cf. GDPR "supervisory authority", Art. 51). |
5. Legal & Regulatory Framework
5.1 Governing law
Mizuha's processing of personal data is governed primarily by Malaysian law:
- Personal Data Protection Act 2010 (Act 709) — Malaysia's base statute regulating the processing of personal data in commercial transactions, in force since 15 November 2013. It establishes the seven data protection principles (PDPA 2010, s.5(1), defined in ss.6–12), the Section 7 notice obligation, data-subject rights, and the registration regime.
- Personal Data Protection (Amendment) Act 2024 (Act A1727) — the substantive overhaul of Act 709. It was assented on 9 October 2024, with the commencement notification gazetted on 24 December 2024, and was brought into force in three phases across 2025:
| Phase | Effective date | Key changes brought into force |
|---|---|---|
| Phase 1 | 1 January 2025 | Administrative and ancillary provisions only (e.g. electronic service of notices). No new substantive obligations. |
| Phase 2 | 1 April 2025 | Renaming of "data user" to "data controller"; addition of biometric data to sensitive personal data; extension of the Security Principle directly to data processors; increased penalties for breach of the principles; and the revised cross-border transfer regime (s.129 whitelist removed). |
| Phase 3 | 1 June 2025 | Mandatory (threshold-based) DPO appointment; mandatory data breach notification; and the new data portability right (PDPA 2010, s.43A). |
Citation note: The amending Act is cited here as Act A1727, consistent with the primary source published by JPDP. Some commentary refers to it as "Act A1726"; the short citation will be confirmed before external publication.
- Subsidiary instruments and guidance, including the Personal Data Protection Regulations 2013 (incl. Reg. 3 on recording consent), the Class of Data Users Orders 2013 and 2016, the Cross-Border Personal Data Transfer Guideline No. 3/2025 (launched 29 April 2025), the Guideline on the Appointment of a Data Protection Officer (effective 1 June 2025), and the Guideline on Data Breach Notification (effective 1 June 2025). The Data Portability Guideline is expected from JPDP and will be incorporated upon issue [Guideline status — to be confirmed at next review].
5.2 The regulator
The Personal Data Protection Commissioner (PDPA 2010, s.47), heading the Department of Personal Data Protection (Jabatan Perlindungan Data Peribadi, "JPDP") under the Ministry of Digital, is Mizuha's regulator for all matters under the PDPA. The Commissioner is responsible for registration, complaints, investigations, Codes of Practice and, following the Amendment Act 2024, DPO registration and breach notification. Mizuha will cooperate fully and promptly with the Commissioner and JPDP.
5.3 Voluntary alignment to GDPR and good international practice
In addition to its mandatory PDPA obligations, Mizuha voluntarily aligns its data-protection practices with the principles and data-subject rights of the EU General Data Protection Regulation (GDPR Art. 5) and with good international practice. This alignment supports consistency for international clients and visitors and reinforces our accountability posture.
Mizuha may accurately describe itself as "compliant with Malaysia's PDPA (as amended 2024)" and as "aligned with international data-protection standards, including the EU GDPR." Mizuha will not claim to be "GDPR-certified" (no such certification exists), "fully GDPR-compliant," or "EU-adequate" (Malaysia has no EU adequacy decision). Where Mizuha processes the personal data of individuals in the EU/EEA, the relevant GDPR obligations apply directly (GDPR Art. 3(2)) and are honoured alongside the PDPA. Mizuha recognises that, notwithstanding broad alignment, the PDPA and GDPR diverge in certain respects (for example, the PDPA is consent-centric and has no general "legitimate interests" basis), and will apply the stricter applicable standard where its processing falls within both regimes.
6. Data Protection Principles
Mizuha Eco Solutions Sdn Bhd processes personal data in accordance with the seven Personal Data Protection Principles set out in the Personal Data Protection Act 2010 (PDPA 2010, s.5(1); defined in ss.6–12). These principles bind Mizuha as a data controller (term substituted by the Amendment Act 2024, in force 1 April 2025) and, in respect of the Security Principle, bind our data processors directly (PDPA 2010, s.5(1A), as inserted by the Amendment Act 2024). Each principle below is stated together with how Mizuha applies it in practice. Breach of these principles is an offence carrying a maximum fine of RM1,000,000 and/or imprisonment up to 3 years (Amendment Act 2024).
6.1 General Principle (PDPA 2010, s.6)
- Mizuha does not process personal data unless the data subject has consented, or unless a specific exception under s.6(2) applies (e.g. performance of a contract to which the data subject is a party, compliance with a legal obligation, or protection of the data subject's vital interests).
- All processing must be for a lawful purpose directly related to an activity of Mizuha — namely, marketing, supplying and fulfilling orders for Mizuha canned drinking water, managing B2B/HORECA relationships, and operating our marketing website.
- Processing must be necessary for, and not excessive in relation to, that purpose. Mizuha applies data minimisation at every collection point: our consumer waitlist collects only an email address; our forms collect only the business-contact details needed to respond.
- Consent is obtained as an unticked, affirmative opt-in; it is never bundled with unrelated purposes. Consent records are created and maintained (Personal Data Protection Regulations 2013, Reg. 3). See §9.
- Mizuha does not collect sensitive personal data or biometric data (the latter added to the sensitive category by the Amendment Act 2024). Where any sensitive personal data is inadvertently supplied (e.g. in a free-text message), it is minimised, and explicit consent (s.40) would be required for any further processing.
6.2 Notice and Choice Principle (PDPA 2010, s.7)
- Mizuha issues a written privacy notice containing all items prescribed by s.7(1) — including the description of data processed, the purposes, the classes of third-party recipients, the choices/means to limit processing, and whether supply is obligatory or voluntary — at every point of collection (waitlist, contact form, wholesale/sample-request form, and the website footer).
- The notice is provided as soon as practicable (s.7(2)) — at or before the point of collection.
- In keeping with Mizuha's bilingual brand promise, the notice is provided in both Bahasa Malaysia and English (s.7(3)).
- Each collection point offers the data subject a genuine choice, including a separate marketing opt-in and a working unsubscribe mechanism (see §9).
6.3 Disclosure Principle (PDPA 2010, s.8)
- Mizuha does not disclose personal data for any purpose other than the purpose notified at collection, nor to any third party outside the classes of recipients disclosed in our privacy notice, without the data subject's consent.
- The classes of recipients Mizuha relies on are limited to: our email/marketing service provider, website analytics provider, CRM provider, cloud hosting provider, (in future) payment processor and courier, and — for the charitable cause — the National Cancer Society Malaysia (NCSM) and our external auditor. The NCSM relationship concerns a charitable donation only and involves predominantly aggregate, non-personal data.
- There is no undisclosed third-party sharing and no sale of personal data.
6.4 Security Principle (PDPA 2010, s.9)
- Mizuha takes practical technical and organisational steps to protect personal data against loss, misuse, and unauthorised access, modification, or disclosure — including HTTPS/TLS across the website, role-based access controls, encryption of data in transit and at rest where supported, and secure credential management.
- Mizuha engages only vetted processors and imposes written security terms on each (s.9 read with the Personal Data Protection Regulations 2013).
- Following the Amendment Act 2024 (in force 1 April 2025), each processor is directly obliged to comply with the Security Principle and must be able to evidence that compliance independently of Mizuha's contractual flow-down (s.5(1A)). See §12 (Processor Management).
- Mizuha maintains a breach register and breach-response procedure aligned to the 72-hour Commissioner notification duty. See §11 (Breach Response).
6.5 Retention Principle (PDPA 2010, s.10)
- Mizuha does not retain personal data longer than necessary for the purpose for which it was collected, and permanently deletes or anonymises data once that purpose is fulfilled.
- Documented retention periods apply per processing activity (see the Retention Schedule, Appendix E) — for example, dormant marketing/lead data is suppressed or deleted after approximately 24 months of inactivity, while transaction, tax, and audit records are kept for approximately 7 years in line with Malaysian accounting and tax requirements.
- Backups are purged on a defined cycle (approximately 30–90 days) so that they do not outlive the primary retention period.
6.6 Data Integrity Principle (PDPA 2010, s.11)
- Mizuha takes reasonable steps to ensure that personal data is accurate, complete, not misleading, and kept up to date having regard to its purpose.
- Data subjects may correct their data at any time (s.34); B2B contact records are reviewed and refreshed through ordinary CRM hygiene, and bounced/undeliverable marketing addresses are suppressed.
6.7 Access Principle (PDPA 2010, s.12)
- Mizuha gives data subjects the right to access their personal data and to request correction, operationalised through ss.30 (access) and 34 (correction).
- Access and correction requests are handled within the statutory 21-day window (Personal Data Protection Regulations) via the contact channel published in our privacy notice. See §8/§9 and the rights-handling procedure (Appendix B).
6.8 Mapping to GDPR Article 5 principles
| PDPA 2010 Principle | Section | Nearest GDPR Art. 5 principle |
|---|---|---|
| General | s.6 | Lawfulness, fairness and transparency; data minimisation (Art. 5(1)(a),(c)) |
| Notice and Choice | s.7 | Lawfulness, fairness and transparency (Art. 5(1)(a); Arts. 13–14) |
| Disclosure | s.8 | Purpose limitation (Art. 5(1)(b)) |
| Security | s.9 | Integrity and confidentiality (Art. 5(1)(f); Art. 32) |
| Retention | s.10 | Storage limitation (Art. 5(1)(e)) |
| Data Integrity | s.11 | Accuracy (Art. 5(1)(d)) |
| Access | s.12 | (Operationalises data-subject rights, Arts. 15–16; underpinned by accountability, Art. 5(2)) |
Note on divergence: the PDPA is consent-centric and has no general "legitimate interests" basis equivalent to GDPR Art. 6(1)(f). Where this policy maps a GDPR basis, it does so only for cases where Mizuha reaches EU/EEA data subjects; the controlling regime for Mizuha remains the PDPA 2010 (as amended 2024).
7. Categories of Personal Data We Process
The table below describes the categories of personal data Mizuha processes, derived from our Record of Processing Activities (ROPA, Appendix A). Mizuha does not intentionally collect sensitive personal data or biometric data (PDPA 2010, s.4; Amendment Act 2024).
| Data category | Examples | Data subjects | Source |
|---|---|---|---|
| Consumer contact data | Email address; consent record; signup timestamp | Consumers and prospects (including possible EU/EEA tourists) | Directly from the data subject (waitlist signup, index.html) |
| Enquiry / contact data | Name, email, organisation, enquiry topic, free-text message | Business contacts, press, general enquirers | Directly from the data subject (contact form, contact.html) |
| B2B lead & business-contact data | Name, company, role/title, work email, phone, business segment, estimated volume / tier (Bronze–Platinum), custom-print interest (MOQ ~30,000), shipping address (if a sample is shipped) | Named employees/contacts of partner venues (HORECA, hospitals, retail) — personal data even though acting in a business capacity | Directly from the data subject (wholesale / sample-request form, wholesale.html) |
| Marketing & engagement data | Email, name (optional), segment/preferences, email opens and clicks | Opted-in consumers and business contacts | Directly from the data subject (marketing opt-in) and generated by our email platform |
| Technical, usage & cookie data | IP address, device/browser identifiers, cookie identifiers, pages viewed, referrer/UTM parameters, approximate location, session behaviour | All website visitors | Generated automatically via the website and analytics/cookie technologies (with consent for non-essential cookies) |
| CRM relationship data | Consolidated name, company, role, work email, phone, enquiry/sample history, pipeline stage, communications log, account notes | Business contacts; later, customer-account contacts | Derived/consolidated from the above sources within the CRM |
| Transaction & payment data (future e-commerce) | Name, billing/shipping address, email, phone, order history, account credentials (if accounts offered). Card data is tokenised and is not stored by Mizuha (PCI-DSS scope reduction). | Consumer and trade purchasers | Directly from the data subject at checkout; payment data via the payment processor |
| Cause / audit contact data | Names and business contact details of Mizuha, NCSM, and external auditor personnel (donation reporting is predominantly aggregate/financial and largely non-personal) | Mizuha, NCSM, and auditor personnel | Generated through the donation-reporting and annual-audit process |
8. Purposes & Lawful Basis of Processing
Mizuha relies on the lawful bases set out below. The PDPA 2010 is consent-centric: processing requires consent unless a narrow s.6(2) exception (such as contractual necessity or a legal obligation) applies. The GDPR column is provided only where Mizuha may reach EU/EEA data subjects (GDPR Art. 3(2)); it is not the controlling basis for Mizuha.
| Processing activity | Purpose | PDPA 2010 lawful basis | GDPR lawful basis |
|---|---|---|---|
| Consumer waitlist | Register interest, send launch notice, build a pre-launch audience | Consent (s.6) — the signup is the consent act | Consent (Art. 6(1)(a)) |
| Contact / enquiry handling | Respond to enquiries from press, business and general contacts | Consent + processing necessary to respond (s.6) | Pre-contractual / contract (Art. 6(1)(b)); otherwise legitimate interests (Art. 6(1)(f)) |
| B2B sample / wholesale enquiry | Qualify and respond to leads; arrange sampling and quotations | Pre-contractual / contractual necessity + consent (s.6) | Contract (Art. 6(1)(b)); legitimate interests for B2B prospecting (Art. 6(1)(f)) |
| Newsletter / direct marketing | Send product and trade news; ongoing direct marketing | Consent (s.6); s.43 opt-out must always operate | Consent (Art. 6(1)(a)); soft opt-in only for existing/similar customers |
| Website analytics & cookies | Measure traffic, optimise the site, attribute referrals, maintain security | Consent for non-essential cookies (s.6); strictly-necessary cookies as a legitimate operation | Consent for non-essential cookies (ePrivacy + Art. 6(1)(a)); Art. 6(1)(f) for strictly necessary |
| B2B CRM / pipeline management | Manage sales pipeline, accounts, fulfilment coordination and reporting | Pre-contractual / contractual necessity + consent for any marketing layer (s.6) | Contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
| Future e-commerce / order fulfilment | Process orders, take payment, fulfil and handle returns, prevent fraud | Contractual necessity (s.6(2)); legal obligation for tax/accounting records (s.6(2)) | Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)); legitimate interests for fraud prevention (Art. 6(1)(f)) |
| NCSM donation reporting & annual audit | Substantiate and report the RM0.20/can charitable donation; support the annual audit and cause transparency | Legal obligation / legitimate interest for audit (s.6(2)); consent only if any donor is individually named | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |
| Vendor / cloud-hosting processor layer | Host the website, store form data, run email/CRM/analytics, maintain backups and security | The underlying activity's basis carries; Mizuha imposes s.9 security terms by written contract; processors are directly bound (s.5(1A)) | Underlying basis carries; Art. 28 processor contract required |
The NCSM tie is referenced here solely as a charitable donation that is audited annually. It is not a medical, health, or disease-prevention claim, and nothing in this policy should be read as making such a claim.
9. Consent Management
Where Mizuha relies on consent (PDPA 2010, s.6; Personal Data Protection Regulations 2013, Reg. 3), that consent is obtained, recorded, and capable of withdrawal as set out below.
9.1 How consent is obtained
- Consent is affirmative and unbundled: it is given through a clear, deliberate action (e.g. submitting the waitlist form, or ticking a separate marketing checkbox). Mizuha does not use pre-ticked boxes, and does not bundle consent for unrelated purposes (s.6).
- Each collection point is accompanied by the bilingual s.7 privacy notice, so consent is informed — the data subject is told what data is collected, the purpose, the classes of recipients, and how to limit processing, before consenting (s.7(1)).
- For sensitive personal data, explicit consent would be required (s.40). Mizuha avoids collecting sensitive or biometric data and configures forms accordingly.
9.2 Granular marketing consent
- Direct-marketing consent is separate and distinct from the consent given to join the waitlist or to make a B2B enquiry. Mizuha does not reuse waitlist or enquiry email addresses for marketing without a fresh, dedicated marketing opt-in.
- Where offered, a preference centre lets data subjects choose the types of communications they receive (e.g. consumer launch news vs. B2B/trade updates).
- Every marketing communication includes a working unsubscribe mechanism. Mizuha gives effect to any direct-marketing opt-out (s.43); failure to do so is an offence carrying a fine of up to RM200,000 and/or 2 years' imprisonment.
9.3 How consent is recorded
- Mizuha creates and maintains a record of each consent (Reg. 3), capturing — at minimum — the data subject's identifier (e.g. email), the date/time, the collection source (e.g. signup page/UTM), the version of the notice shown, and the specific purpose(s) consented to.
- Consent records are retained for as long as the related processing continues and for a reasonable period thereafter to evidence compliance, then deleted in line with the consent-record retention rules (Appendix C — Consent Record Template).
9.4 How consent is withdrawn
- A data subject may withdraw consent at any time by written notice or by using the unsubscribe/preference controls. On receipt, Mizuha ceases the relevant processing (s.38); ignoring a withdrawal is an offence carrying a fine of up to RM100,000 and/or 1 year's imprisonment.
- Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and does not affect processing Mizuha must continue under another lawful basis (e.g. retaining transaction/tax records under a legal obligation).
- Withdrawal requests are actioned promptly and, in any event, consistently with the 21-day response window applicable to data-subject requests.
9.5 Bilingual (English / Bahasa Malaysia) notices
- Consistent with s.7(3) and Mizuha's bilingual brand promise, all consent prompts and privacy notices are presented in both English and Bahasa Malaysia.
- The two language versions carry the same meaning and the same scope of consent; neither version narrows or expands the other. Consent prompts are written in plain, calm, factual language in keeping with Mizuha's brand voice.
10. Privacy Notice (s.7 Notice & Choice)
Under the Notice and Choice Principle (PDPA 2010, s.7), Mizuha Eco Solutions Sdn Bhd must inform every data subject — at or before the point their personal data is collected — what is being collected, why, and what control they retain. This notice is also Mizuha's mechanism for meeting the equivalent GDPR Arts. 13–14 transparency duties where EU/EEA data subjects (e.g. EU hotel groups or tourists joining the waitlist) are reached.
10.1 Mandatory contents of the Mizuha Privacy Notice (s.7(1))
Every Mizuha privacy notice — published on the website and surfaced at each collection point — shall state, as required by PDPA 2010, s.7(1):
- (a) Fact and description of processing — that personal data is being or will be processed by Mizuha Eco Solutions Sdn Bhd as data controller, with a description of the data concerned (e.g. email for the consumer waitlist; name, company, role, phone and work email for B2B sample/wholesale enquiries).
- (b) Purposes — the purpose(s) for which the data is collected and further processed (e.g. registering launch interest, responding to enquiries, qualifying B2B leads, direct marketing where separately consented).
- (c) Source — any information available to Mizuha as to the source of the data, where it was not collected directly from the data subject.
- (d) Access and correction rights — the data subject's right to request access to and correction of their personal data, and the contact details of the office handling such requests (see §11.5).
- (e) Classes of third parties — the class(es) of third parties to whom Mizuha may disclose the data: email service provider (ESP), website analytics provider, customer relationship management (CRM) platform, cloud hosting provider, future payment processor and courier, and — for the charitable cause — the National Cancer Society Malaysia (NCSM) and Mizuha's external auditor.
- (f) Choices and means to limit — the choices and means Mizuha offers the data subject to limit the processing of their data (e.g. opting out of marketing, adjusting cookie preferences, withdrawing consent).
- (g) Obligatory or voluntary supply — whether it is obligatory or voluntary for the data subject to supply the data, and where obligatory, the consequences of failing to supply it.
Mizuha's website data collection is voluntary in every case (waitlist, contact, sample/wholesale enquiry). The notice shall state this plainly, and that declining to provide data simply means Mizuha cannot, for example, add the person to the waitlist or respond to their enquiry.
10.2 Bilingual requirement (s.7(3))
The notice shall be issued in both the national language (Bahasa Malaysia) and English (PDPA 2010, s.7(3)). Both language versions shall be:
- Materially identical in meaning and equally accessible (e.g. a language toggle, or both versions linked from every collection point).
- Written in Mizuha's consumer-facing voice — quiet, exact, calm, factual, plain language — with no hype.
This aligns with Mizuha's bilingual brand promise and is a legal requirement, not an optional courtesy. A placeholder BM translation is not acceptable for publication; the BM version shall be a faithful, reviewed translation. [BM translation — to be finalised and legally reviewed before publication.]
10.3 Timing — "as soon as practicable" (s.7(2))
The notice shall be given as soon as practicable (PDPA 2010, s.7(2)) — in practice, at or before the point of collection. Concretely, Mizuha shall:
- Place a short, layered notice (a one-line summary plus a link to the full notice) immediately adjacent to every form: the consumer waitlist (
index.html), the contact form (contact.html), and the B2B sample/wholesale enquiry form (wholesale.html). - Link the full Privacy Notice from the website footer on every page.
- Pair the notice with the cookie consent banner (see §13) so that cookie/tracking disclosure is given before non-essential tags fire.
10.4 Layered notice structure
To keep collection points uncluttered while remaining complete, Mizuha shall use a layered notice:
| Layer | Where it appears | What it contains |
|---|---|---|
| Layer 1 — Short notice | Inline at each form, beside the submit button | One or two plain sentences: who is collecting, the single main purpose, a link to the full notice, and (for marketing) a separate unticked opt-in. |
| Layer 2 — Full Privacy Notice | Dedicated page, linked from footer and every Layer-1 notice | All s.7(1) contents (§10.1), cross-border transfer disclosure (§13 / s.129), retention periods, the full rights set (§11), complaint routes, and the cookie table. |
10.5 Consent must not be bundled into the notice
Acknowledging the notice is not consent to marketing. Under the General Principle (PDPA 2010, s.6), any marketing consent shall be a separate, unticked opt-in collected alongside — but distinct from — the notice (see §13.1). The notice informs; consent is a deliberate, recorded act by the data subject.
11. Data Subject Rights
Mizuha recognises and will give effect to the rights conferred on data subjects by the PDPA 2010 (as amended 2024), and — as a matter of good practice and GDPR alignment — offers the additional GDPR-style rights set out below to all data subjects, regardless of location.
11.1 Rights matrix
| # | Right | Governing law | What the data subject may do | Mizuha's response commitment |
|---|---|---|---|---|
| 1 | Access | PDPA 2010, s.30 | Request confirmation that Mizuha processes their data, and a copy of that data with its purposes and recipients. | Confirm and provide within 21 days (statutory). |
| 2 | Correction | PDPA 2010, s.34 | Request correction of data that is inaccurate, incomplete, misleading or out of date. | Correct (or explain refusal) within 21 days (statutory). |
| 3 | Withdraw consent | PDPA 2010, s.38 | Withdraw consent to processing by written notice. | Cease the relevant processing on receipt; confirm action within 21 days. (Offence to continue: fine up to RM100,000 and/or 1 year.) |
| 4 | Prevent direct marketing | PDPA 2010, s.43 | By written notice, require Mizuha to stop processing their data for direct marketing. | Stop direct marketing without delay; honour every unsubscribe. (Offence to ignore: fine up to RM200,000 and/or 2 years.) |
| 5 | Data portability | PDPA 2010, s.43A (Amendment Act 2024) | Request that their personal data be transmitted directly to another data controller, subject to technical feasibility and compatibility of data format. | Action within 21 days where feasible; explain any technical-feasibility limit. Mechanics to follow forthcoming JPDP guidance. [Data Portability Guideline — confirm status before publication.] |
| 6 | Erasure (good practice) | Offered voluntarily; aligns with GDPR Art. 17 | Request deletion of their data where Mizuha has no lawful basis or ongoing need to retain it. | Delete within 21 days unless a legal retention duty applies (e.g. 7-year tax/audit records), in which case Mizuha explains the basis for retention. |
| 7 | Restriction of processing (good practice) | Offered voluntarily; aligns with GDPR Art. 18 | Ask Mizuha to suspend processing (e.g. while a correction dispute is resolved). | Apply restriction within 21 days; flag the affected records. |
| 8 | Objection (good practice) | Offered voluntarily; aligns with GDPR Art. 21 | Object to processing based on Mizuha's legitimate interests (e.g. B2B prospecting). | Review and respond within 21 days; stop unless compelling grounds exist. |
Scope note: The PDPA does not contain a general "right to be forgotten" or a standalone restriction/objection right; rights 6–8 are offered by Mizuha as voluntary good practice and GDPR alignment, not as statutory PDPA entitlements. Where an EU/EEA data subject's data is in scope, rights 6–8 are honoured as legal GDPR obligations.
11.2 Response timeline Mizuha commits to
Mizuha commits to the statutory 21-day window (PDPA Regulations) for access and correction requests, and applies the same 21-day target to all other request types listed above for consistency. Where a request is complex or the data subject's identity cannot be readily verified, Mizuha will acknowledge the request promptly and may extend, explaining the reason and the expected timeframe before the 21 days expire. For EU/EEA data subjects, the GDPR one-month timeframe (Art. 12(3)) is also met, since 21 days is shorter.
11.3 No general charge for rights requests
Mizuha will not charge a fee for routine access, correction, consent-withdrawal, marketing-opt-out, portability, erasure, restriction or objection requests. A reasonable, cost-based fee may be applied only for manifestly unfounded, excessive, or repetitive requests, or for additional copies — and the basis will be explained to the data subject before any charge. (This mirrors GDPR Art. 12(5) and keeps Mizuha's practice simple and trustworthy.)
11.4 Limits and refusals
Mizuha may decline or partially fulfil a request only on lawful grounds — for example, where complying would adversely affect another person's rights, where a legal retention obligation overrides an erasure request, or where the request is manifestly unfounded. Any refusal will be communicated in writing with reasons and with information on how to complain (see §11.6).
11.5 How to make a request — channel
Data subjects may exercise any right by contacting Mizuha's privacy function:
- Email: [DPO / privacy contact email — to be assigned, e.g. privacy@mizuha.com.my]
- Postal: Mizuha Eco Solutions Sdn Bhd, [registered office address — Petaling Jaya, Selangor — to be inserted], for the attention of the Data Protection / Privacy Officer.
- Web: an online rights-request form linked from the Privacy Notice. [Form — to be built.]
Requests may be made in Bahasa Malaysia or English.
11.6 Complaints
If a data subject is dissatisfied with how Mizuha handles their data or a request, they may complain to Mizuha's privacy function in the first instance, and thereafter to the Personal Data Protection Commissioner, Department of Personal Data Protection (Jabatan Perlindungan Data Peribadi, JPDP), Ministry of Digital, Malaysia (PDPA 2010, s.47).
12. Data Subject Request Handling Procedure
This procedure ensures every data subject request ("DSR") is logged, verified, actioned and closed within the statutory window, and that Mizuha can evidence its handling (an accountability requirement under PDPA s.5 and GDPR Art. 5(2)).
12.1 Step-by-step procedure
- Receipt & logging. On arrival via any channel (email, post, web form), the request is logged in the DSR Register with: a unique reference, date received, requester identity, channel, right(s) invoked, and the 21-day due date calculated from receipt. The clock starts on the date of receipt.
- Acknowledgement. Mizuha acknowledges the request to the data subject within 3 working days, stating the reference and expected response date.
- Identity verification. Before disclosing or changing any data, Mizuha verifies the requester is the data subject (or an authorised agent), using proportionate means — e.g. confirming control of the email address on record, or a minimal identity check. Mizuha will not collect more identity data than necessary. If verification is needed, the 21-day clock is treated as paused only for the period reasonably required to verify, and the data subject is told this.
- Triage & routing. The privacy owner classifies the request (access / correction / withdrawal / marketing opt-out / portability / erasure / restriction / objection) and routes data retrieval to the relevant system owners (ESP, CRM, analytics, cloud host) — including instructing any processor to act, since processors now carry direct duties (PDPA s.5(1A), Amendment Act 2024).
- Action.
- Access (s.30): compile the data, purposes and recipient classes; provide a copy in an intelligible form.
- Correction (s.34): correct across all systems and notify relevant processors.
- Withdraw consent (s.38): stop the consented processing immediately; suppress, do not silently retain.
- Direct-marketing opt-out (s.43): add to the suppression list across ESP and CRM; never delete the suppression record itself (it evidences the opt-out).
- Portability (s.43A): where technically feasible, transmit in a structured, commonly used format; otherwise explain the limit.
- Erasure / restriction / objection (good practice): action unless a lawful retention duty applies; document the outcome.
- Review & approval. The privacy owner reviews the response for completeness and for any third-party data that must be redacted, then approves release.
- Response to data subject. Mizuha responds within 21 days of receipt, in the requester's chosen language (BM or English), confirming what was done or giving written reasons for any refusal and complaint routes (§11.6).
- Closure & record. The DSR Register entry is closed with the action taken, date completed, and any documents issued. Records of DSRs are retained as evidence of compliance.
12.2 Statutory timeline
| Milestone | Target |
|---|---|
| Acknowledge request | Within 3 working days of receipt |
| Substantive response (all request types) | Within 21 days of receipt (PDPA Regulations) |
| Permitted extension (complex/voluminous) | Notified before day 21, with reasons and a revised date |
| GDPR cross-check (EU/EEA subjects) | Within 1 month (Art. 12(3)) — met by the 21-day target |
12.3 Fees
Routine requests are handled free of charge (§11.3). A reasonable, cost-based fee may be charged only for manifestly unfounded, excessive or repetitive requests, or additional copies; the fee and its basis are communicated before any work proceeds, and the data subject may withdraw or narrow the request to avoid it.
12.4 Roles
The Data Protection / Privacy Officer (or, until a DPO is formally appointed, the designated privacy owner — see §19 (Data Protection Officer)) is accountable for the DSR process. All staff receiving a request must forward it to the privacy function the same working day and must not action it independently.
13. Direct Marketing & Cookies
13.1 Waitlist and newsletter consent
Mizuha operates on a consent-centric basis (PDPA 2010, s.6). The following rules are mandatory:
- Separate, specific consent for marketing. Joining the consumer waitlist, submitting a contact form, or making a B2B sample/wholesale enquiry does not, by itself, authorise ongoing direct marketing. Any newsletter or direct-marketing use requires a distinct, separate, unticked opt-in at the point of collection.
- No bundled or pre-ticked consent. Consent boxes shall never be pre-ticked and shall not be bundled with the privacy-notice acknowledgement or with the act of submitting a form (s.6; GDPR Art. 7).
- Recorded and maintained. Every marketing consent shall be recorded with the date, time, source/form, IP and the exact wording consented to, and maintained for as long as the consent is relied on (PDPA Regulations 2013, Reg. 3).
- No repurposing of enquiry emails. Emails collected for waitlist registration, enquiry response, or B2B lead qualification shall not be added to a marketing list without a fresh, separate marketing consent.
- B2B contacts are in scope. A named B2B contact's work email is personal data (PDPA s.4). B2B prospecting is therefore subject to the same consent and opt-out discipline; Mizuha will not assume B2B contacts are exempt.
13.2 Opt-out of direct marketing (s.43)
- Every marketing email shall contain a clear, working unsubscribe link and an unambiguous sender identity.
- On receiving a marketing opt-out — whether via unsubscribe link or written notice — Mizuha shall cease direct-marketing processing without delay (PDPA 2010, s.43). Ignoring a valid opt-out is an offence carrying a fine up to RM200,000 and/or 2 years' imprisonment.
- Opt-outs are recorded on a suppression list retained across the ESP and CRM; the suppression record itself is kept (not deleted) to ensure the person is not re-contacted.
- A preference centre shall let subscribers adjust frequency and topic, or withdraw entirely, without having to email Mizuha.
13.3 Cause messaging guard
Where any marketing or notice references the NCSM donation (RM0.20/can, audited annually), it shall be described strictly as a charitable donation. Mizuha shall never frame the cause — in any marketing, notice, or consent text — as a medical, health, or disease-prevention claim.
13.4 Website cookies and analytics
Mizuha's website uses cookies and similar technologies for traffic measurement, optimisation, attribution and security. Governance:
| Cookie / tag category | Examples | Consent basis | Behaviour |
|---|---|---|---|
| Strictly necessary | Session, security, load-balancing, consent-state storage | No consent required (essential to deliver the service) | Always active. |
| Analytics / performance | Website analytics, page/referrer/UTM measurement | Prior consent required | Blocked until the visitor consents. |
| Marketing / tracking | Ad pixels, cross-site/attribution tags | Prior consent required | Blocked until the visitor consents. |
13.5 Consent banner requirements
- Block before consent (top priority). Non-essential cookies and tags (analytics, marketing pixels) shall not fire before the visitor gives consent. Tags loading before consent is the single highest cookie-compliance risk and is prohibited in Mizuha's setup.
- Genuine choice. The banner shall offer "Accept all" and "Reject all" with equal prominence, plus a granular "Manage preferences" option (aligning with EU ePrivacy expectations for any EU/EEA visitors).
- Informed. The banner shall briefly state what cookies do and link to the full cookie table and Privacy Notice, in Bahasa Malaysia and English.
- Withdrawable. Visitors shall be able to change or withdraw their cookie choices at any time, as easily as they gave them (e.g. a persistent "Cookie settings" link in the footer).
- Recorded. The consent management platform shall log the choice, scope, timestamp and banner version for each visitor as evidence of valid consent.
- Cross-border note. Because analytics/CDN identifiers are typically processed outside Malaysia, the cookie disclosure shall connect to Mizuha's cross-border transfer governance (PDPA s.129; CBPDT Guideline 3/2025) so visitors understand their data may leave Malaysia.
14. Security Measures
Mizuha Eco Solutions Sdn Bhd implements technical and organisational measures to protect personal data against loss, misuse, and unauthorised access, modification, or disclosure, in accordance with the Security Principle (PDPA 2010, s.9) and aligned to GDPR Art. 32. Following the Amendment Act 2024, the Security Principle now binds data processors directly (s.5(1A), effective 1 April 2025), so every vendor handling Mizuha data must independently implement and evidence equivalent security.
14.1 Technical Measures
- Encryption in transit. All personal data transmitted to or from the Mizuha website (waitlist signups, contact forms, B2B sample/wholesale enquiries) and between Mizuha and its processors is protected using TLS 1.2 or higher (HTTPS enforced site-wide, with HTTP-to-HTTPS redirection and HSTS).
- Encryption at rest. Personal data stored in databases, the CRM, the email/marketing platform, and cloud backups is encrypted at rest using AES-256 (or the provider's equivalent industry-standard cipher).
- Access control. Access to personal data is granted on a least-privilege, need-to-know basis, governed by role-based access controls. Administrative access requires multi-factor authentication (MFA). Credentials are never shared, and default/vendor credentials are changed on provisioning.
- Network and application security. Production systems sit behind a firewall and, where applicable, a Web Application Firewall (WAF) and CDN-level protection. Software, dependencies, and CMS components are kept patched and updated.
- Logging and monitoring. Server access logs, authentication events, and administrative actions are logged and monitored to detect anomalous or unauthorised activity.
- Pseudonymisation and minimisation. Where analytics or operational needs allow, identifiers are pseudonymised or aggregated, and only data necessary for the stated purpose is collected (PDPA 2010, s.6 — not excessive).
- Secure disposal. Personal data is securely deleted or rendered irrecoverable at end of its retention period (see §15).
14.2 Organisational Measures
- Privacy ownership. A designated privacy owner (or DPO, where appointed — see §19, Data Protection Officer) oversees the implementation and review of these measures.
- Access governance. Access rights are reviewed periodically and revoked promptly upon role change or departure of personnel or contractors.
- Staff awareness. Personnel and contractors who handle personal data receive data-protection and security-awareness briefings, including secure handling of B2B lead data and avoidance of routing personal data through unsecured personal channels.
- Secure collection points. Personal data is captured only through secured (HTTPS) forms; free-text fields (e.g. contact-form messages) are monitored to avoid inadvertent capture of sensitive personal data.
- Vendor security terms. Written security obligations reflecting s.9 are imposed on every processor (see §17), and each processor's compliance is verified given their now-direct statutory duty (Amendment Act 2024, s.5(1A)).
- Periodic review. Security measures are reviewed at least annually and on any material change to systems, vendors, or the business model (notably before any e-commerce/payments launch).
14.3 Payment Data (Future E-commerce)
When Mizuha introduces online payments, card data will be processed by a PCI-DSS-compliant payment gateway and tokenised — never stored on Mizuha's own systems — to minimise PCI-DSS scope. A DPIA-equivalent assessment will be completed before launch (see §16 on breach management and Appendix G — Data Protection Impact Assessment (DPIA) Template & Trigger Criteria).
15. Data Retention & Disposal
In accordance with the Retention Principle (PDPA 2010, s.10) and GDPR Art. 5(1)(e), Mizuha does not retain personal data longer than necessary for the purpose for which it was collected. When data is no longer required, it is securely destroyed or permanently deleted. The periods below are Mizuha's default schedule; final values are to be confirmed by the privacy owner.
| Data category (source) | Retention period | Trigger / basis | Disposal method |
|---|---|---|---|
| Consumer waitlist (email + signup metadata) | Until product launch + active use, then suppress/delete after [24 months — to confirm] of inactivity, or immediately on unsubscribe/withdrawal (s.38) | Consent (s.6); purpose exhausted at launch | Permanent deletion from ESP and backups; suppression-list hash only for opt-out honouring |
| Contact-form enquiries | Duration of enquiry + [12–24 months — to confirm] | Necessary to respond, then purpose exhausted | Deletion from email platform / CRM / helpdesk |
| B2B leads (sample/wholesale enquiries) | Active engagement + [24–36 months — to confirm]; longer only if converted to a contract | Pre-contractual/consent; dormant leads purged | CRM record deletion; secure erasure of attachments |
| Customer/partner contracts & related records | Contract term + statutory limitation/tax tail, commonly up to 7 years | Legal obligation (tax/accounting); limitation period | Secure deletion/archival destruction after tail expires |
| Payment & transaction records (future e-commerce) | 7 years (Malaysian accounting/tax retention) | Legal obligation (s.6(2)) | Secure deletion; card data not stored (tokenised) |
| Website analytics & cookie identifiers | Raw identifiers [14 months — to confirm]; aggregate/non-personal data may be kept longer | Consent (non-essential cookies) | Automatic expiry/deletion at provider; cookie expiry |
| Newsletter / direct-marketing data | Until consent withdrawn (s.43); re-permission or suppress after [18–24 months — to confirm] inactivity | Consent | Deletion from ESP; suppression record retained to honour opt-out |
| NCSM donation reporting & audit records | 7 years (audit/financial) — predominantly aggregate, minimal personal data | Legal obligation / audit | Secure archival destruction after retention |
| Backups | Rolling cycle, purged within [30–90 days — to confirm] | Operational continuity | Automatic backup rotation/overwrite |
Disposal principles: (1) deletion must extend to backups, processor systems, and any cached copies within the backup cycle; (2) where immediate deletion of a single record from a backup is not technically feasible, the record is put beyond use and deleted on the next backup rotation; (3) deletion is irreversible (overwriting, cryptographic erasure, or provider-confirmed permanent deletion); (4) where data must be retained for a legal/limitation purpose, it is archived with restricted access rather than kept in active systems.
16. Personal Data Breach Management & Notification
16.1 Definition
A personal data breach is any breach of security leading to the accidental or unlawful loss, destruction, alteration, unauthorised disclosure of, or access to, personal data processed by Mizuha or any of its processors. This expressly includes breaches occurring at a vendor/processor (e.g. ESP, CRM, analytics, cloud host), which are reportable by Mizuha (Amendment Act 2024).
16.2 Internal Escalation
- Any employee, contractor, or processor who becomes aware of, or suspects, a breach must report it immediately to the privacy owner/DPO at [DPO/privacy email — to be assigned].
- The privacy owner promptly assesses: the nature and scope of the data involved, the number of data subjects affected, the likely consequences, and whether the breach is likely to cause significant harm.
- Containment, recovery, and remediation steps are initiated without delay, in coordination with the relevant processor where the breach originated on their systems.
- The assessment, decisions, and timestamps are recorded in the breach register (§16.5).
16.3 Notification to the Commissioner (Mandatory)
Where Mizuha has reason to believe a personal data breach has occurred, it shall notify the Personal Data Protection Commissioner (JPDP) as soon as practicable and in any event within 72 hours of the occurrence of the breach (Amendment Act 2024; Data Breach Notification Guideline, effective 1 June 2025). The 72-hour clock runs from the occurrence of / reason to believe in the breach, not from any later "significant harm" determination. Where full information is not available within 72 hours, an initial notification is made and supplemented as details emerge.
16.4 Notification to Affected Data Subjects
Where a breach causes or is likely to cause significant harm to affected data subjects, Mizuha shall notify those data subjects without unnecessary delay and in any event within 7 days of notifying the Commissioner (Data Breach Notification Guideline; aligned to GDPR Art. 34). "Significant harm" includes risk of physical harm, financial loss, negative effect on a credit record, damage to or loss of property, misuse for unlawful purposes, identity fraud, the involvement of sensitive personal data, or a breach of significant scale (affecting or likely to affect more than 1,000 data subjects). Notification to data subjects describes the breach, likely consequences, measures taken, and steps individuals can take to protect themselves.
16.5 Breach Register
Mizuha maintains a breach register recording every personal data breach (including those not meeting the notification threshold): date and time of occurrence and discovery, description and cause, data categories and number of data subjects affected, the significant-harm assessment, remediation actions, and notification decisions and timestamps. A standard internal notification template covers both Commissioner and data-subject notifications and is structured to handle vendor/processor breaches.
17. Data Processors & Third Parties
Mizuha relies on third-party processors — including its email/marketing platform (ESP), CRM, website analytics, cloud hosting/CDN, future payment gateway and courier — and discloses limited data to third parties such as the National Cancer Society Malaysia (NCSM) and external auditors. All such relationships are governed to satisfy the Security Principle (PDPA 2010, s.9) and the Disclosure Principle (s.8).
17.1 Processors' Direct Obligations (Post-2024)
Following the Amendment Act 2024 (s.5(1A), effective 1 April 2025), data processors bear direct statutory obligations, in particular direct compliance with the Security Principle, with criminal liability independent of Mizuha's contractual flow-down. Each processor must therefore implement and be able to evidence its own security compliance.
17.2 Data Processing Agreement (DPA) Requirements
- Every processor must be bound by a written data processing agreement before any personal data is shared (s.9; aligned to GDPR Art. 28).
- The DPA shall require the processor to: (a) process data only on Mizuha's documented instructions and only for the notified purpose; (b) implement technical and organisational security measures reflecting s.9; (c) notify Mizuha of any breach without undue delay to enable Mizuha's 72-hour reporting (§16); (d) impose equivalent terms on any sub-processor and disclose sub-processors; (e) assist with data-subject rights requests; (f) on termination, delete or return personal data; and (g) disclose data residency and any cross-border transfer (§18).
17.3 Due Diligence
Before engaging a processor, Mizuha assesses its security posture, data residency, certifications (e.g. ISO/IEC 27001/27701), sub-processor chain, and breach history. Vendors are re-assessed periodically and on material change. A record of approved processors and their data-residency locations is maintained (seeded from the ROPA).
17.4 NCSM Donation-Reporting Relationship
The donation to NCSM (RM0.20 per can, audited annually) is reported predominantly as aggregate, financial data (cans sold × RM0.20), which is largely non-personal. Mizuha applies data minimisation: customer-level personal data is not shared with NCSM or the auditor where aggregate figures suffice; personal data shared is limited to Mizuha/NCSM/auditor contact personnel. NCSM is a third party, and the relationship is a charitable donation — it is never reported or framed as a medical, health, or disease-prevention claim.
18. Cross-Border Data Transfers
Because most of Mizuha's processors (ESP, analytics/CDN, CRM, cloud host, and any future payment gateway) are SaaS providers likely hosted outside Malaysia (typically the US, EU, or Singapore), cross-border transfer governance is a primary compliance focus.
18.1 The Post-2024 Transfer Regime
The previous "whitelist" mechanism has been repealed; Mizuha places no reliance on it. Under the substituted regime (PDPA 2010, s.129, as amended by the Amendment Act 2024, effective 1 April 2025) and the Cross-Border Personal Data Transfer Guideline No. 3/2025 (29 April 2025), Mizuha may transfer personal data outside Malaysia only where a lawful basis applies:
- the destination jurisdiction has in force a law substantially similar to the PDPA, or ensures an adequate level of protection at least equivalent to the PDPA;
- the data subject has given explicit consent to the transfer (after being informed of the risks);
- the transfer is necessary for the performance of a contract with, or in the interest of, the data subject, or to protect vital interests;
- the transfer is necessary for legal proceedings or obtaining legal advice; or
- Mizuha has taken reasonable precautions and exercised due diligence to ensure the data will be protected (operationalised through contractual clauses, binding corporate rules, or certification).
18.2 Safeguards for Cloud / SaaS Vendors
- Mizuha maps the data residency of each processor and documents the lawful transfer basis relied on for each (recorded in the ROPA).
- A Transfer Impact Assessment is conducted for material transfers, particularly any involving higher-risk data (e.g. future payment data).
- Transfer obligations and security terms are embedded in each DPA (§17.2), and transfers occur only over encrypted channels (§14).
18.3 GDPR Note (EU-Origin Data)
Malaysia has no EU adequacy decision. Where Mizuha receives personal data originating in the EU/EEA (e.g. EU hotel groups or EU tourists on the waitlist), transfers into Malaysia require an appropriate GDPR Chapter V safeguard — typically Standard Contractual Clauses (SCCs) or binding corporate rules (GDPR Arts. 44–46). Mizuha does not claim EU-adequate status and relies on SCC-style contractual safeguards for any such inbound EU-origin data.
19. Data Protection Officer (DPO)
19.1 Position under the Amendment Act 2024
The Personal Data Protection (Amendment) Act 2024 (Act A1727) introduced a statutory obligation, effective 1 June 2025, to appoint at least one Data Protection Officer (DPO) where prescribed thresholds are met. Under the Guideline on the Appointment of a Data Protection Officer (effective 1 June 2025), appointment is mandatory where Mizuha Eco Solutions Sdn Bhd, acting as a data controller or processor:
- processes the personal data of more than 20,000 data subjects; or
- processes sensitive personal data (including financial data) of more than 10,000 data subjects; or
- carries out core activities requiring regular and systematic monitoring of personal data.
19.2 Mizuha's current position and standing commitment
At Mizuha's pre-launch and early-growth stage, the combined consumer waitlist and B2B CRM are not expected to exceed 20,000 data subjects, and Mizuha deliberately avoids collecting sensitive or biometric data (s.40). On that basis, a DPO appointment may not yet be legally mandatory. Notwithstanding this:
- Mizuha appoints a Privacy Owner (a designated, accountable individual) from the outset as best practice and as a GDPR-alignment signal, irrespective of the statutory threshold.
- Mizuha monitors the total distinct count of data subjects across all processing activities (ROPA activities 1–6) and re-assesses the threshold at every material expansion — in particular before the e-commerce / online-payments launch (a future commercial-stage expansion), at which point thresholds may be crossed quickly.
- On crossing any threshold in §19.1, Mizuha will formally appoint a DPO and complete registration with the Commissioner within the statutory window (§19.4).
19.3 DPO responsibilities
The DPO (or, pending mandatory appointment, the Privacy Owner) is responsible for:
- advising Mizuha and its staff on PDPA 2010 (as amended 2024) and GDPR-aligned obligations;
- monitoring compliance with this Policy, the seven data protection principles (PDPA 2010, s.5(1)), and the external Privacy Notice (s.7);
- maintaining the Record of Processing Activities (ROPA), consent records, and the retention schedule;
- acting as the primary contact point for data subjects exercising their rights (ss.30, 34, 38, 43, 43A) and for the Personal Data Protection Commissioner (JPDP);
- overseeing data-subject rights requests within the 21-day PDPA response window;
- coordinating breach response, the breach register, and notifications to the Commissioner (within 72 hours of occurrence) and to affected data subjects where significant harm arises (within 7 days of notifying the Commissioner) (§16, Personal Data Breach Management & Notification);
- overseeing processor/vendor due diligence, written security agreements (s.9), and cross-border transfer assessments (s.129; CBPDT Guideline 3/2025);
- championing a Data Protection Impact Assessment (DPIA) before high-risk processing, mandatorily before the e-commerce/payments launch;
- delivering or commissioning staff training (§21) and reporting on compliance to the Board (§20, §22).
19.4 Qualifications and registration with JPDP
Where appointment becomes mandatory, the DPO must:
- possess the prescribed skills and expertise in personal data protection;
- be proficient in both Bahasa Malaysia and English;
- be resident in Malaysia or otherwise easily contactable;
- be free of conflicts of interest with the DPO function.
Mizuha must register/notify the DPO's business contact details to the Commissioner within 21 days of appointment (per the DPO Appointment Guideline, effective 1 June 2025). The DPO's details must also be published in Mizuha's external Privacy Notice (s.7(1)(d)).
19.5 Contact
| Field | Detail |
|---|---|
| Role | Data Protection Officer / Privacy Owner |
| Name | [DPO / Privacy Owner name — to be assigned] |
| [DPO email — to be assigned, e.g. dpo@mizuha.com.my] | |
| Postal address | Mizuha Eco Solutions Sdn Bhd, [registered office address, Petaling Jaya, Selangor — to be confirmed] |
| Languages | Bahasa Malaysia and English |
20. Roles & Responsibilities
Accountability for data protection is shared across the organisation. The matrix below uses RACI conventions: R = Responsible (does the work), A = Accountable (ultimately answerable), C = Consulted, I = Informed.
| Activity / Obligation | Board / Directors | DPO / Privacy Owner | Department Heads | All Staff | Processors / Vendors |
|---|---|---|---|---|---|
| Approve this Policy and the data protection strategy | A | C | I | I | — |
| Provide resources and authority for compliance | A/R | C | I | I | — |
| Maintain ROPA, consent and retention records | I | A/R | C | I | I |
| Issue and maintain the s.7 Privacy Notice (bilingual) | I | A/R | C | I | — |
| Handle data-subject rights requests (21-day window) | I | A | R | R | C |
| Embed data protection in departmental processes | I | C | A/R | R | I |
| Day-to-day lawful, secure handling of personal data | I | C | A | R | R |
| Implement Security Principle measures (s.9) | I | A | R | R | R (direct duty, §§14, 17) |
| Breach detection, escalation and reporting | I | A | R | R (report immediately) | R (report to Mizuha) |
| Vendor due diligence and written DPAs | I | A/R | C | I | C |
| Cross-border transfer assessments (s.129) | I | A/R | C | I | C |
| Complete mandatory training | A | R | R | R | I |
20.1 Specific responsibilities
- Board / Directors — hold ultimate accountability (GDPR Art. 5(2), 24); approve this Policy and the privacy budget; ensure a Privacy Owner/DPO is designated; review compliance reporting at least annually (§22).
- DPO / Privacy Owner — as set out in §19.3; the central coordinating and advisory function.
- Department Heads (Sales/B2B, Marketing, Operations, Finance, IT) — accountable for compliance within their function; ensure forms, CRM use, marketing consent, and vendor engagements follow this Policy; escalate risks and breaches to the DPO.
- All Staff — process personal data only for authorised purposes and under instruction; apply security practices; report any suspected breach to the DPO immediately (and in any event without delay, to support the 72-hour clock); never route personal data to unsanctioned personal accounts (e.g. personal Gmail) or unsecured channels.
- Processors / Vendors (ESP, analytics/CDN, CRM, cloud host, future payment gateway, couriers) — bound by written processor/security agreements; under the 2024 amendments must directly comply with the Security Principle (s.9) and are subject to criminal liability under s.5(1A); must evidence their own compliance and report any breach to Mizuha without delay.
21. Training & Awareness
- Induction. Every new employee, contractor, and intern who may handle personal data receives data protection training as part of onboarding, before being granted access to personal data systems.
- Annual refresher. All staff complete refresher training at least annually, and additional ad-hoc training whenever the law, this Policy, or key processing activities change materially (e.g. e-commerce launch).
- Role-specific training. Higher-exposure functions — Sales/B2B (CRM, B2B lead handling), Marketing (consent and s.43 marketing opt-outs), Operations and IT (security, breach response), Finance (transaction/tax retention) — receive targeted, role-specific modules.
- Content. Training covers the seven PDPA principles (s.5(1)), lawful basis and consent recordkeeping, the s.7 Notice, data-subject rights and the 21-day window, secure handling, breach recognition and immediate escalation, and the cross-border and processor obligations introduced in 2024.
- Brand-compliance point. Training reinforces that the NCSM tie is a charitable donation only and must never be framed in any notice, marketing, or data communication as a medical, health, or disease-prevention claim.
- Records. The DPO maintains a training register (attendee, date, module, completion) as accountability evidence (GDPR Art. 5(2)).
- Awareness. Periodic reminders, updated quick-reference guidance, and phishing/security awareness are issued to keep data protection front-of-mind.
22. Monitoring, Audit & Accountability
- Accountability principle. Mizuha must not only comply but be able to demonstrate compliance (GDPR Art. 5(2), 24; the PDPA Security and Retention principles). This Policy, the ROPA, consent records, the retention schedule, the breach register, and the training register together form the accountability evidence base.
- Ongoing monitoring. The DPO monitors compliance continuously, including: cookie/tag behaviour (non-essential tags must not fire before consent), working unsubscribe links (s.43), consent capture quality (unticked opt-in, not bundled), and the running data-subject count against the DPO threshold (§19.1).
- Periodic audit. Mizuha conducts an internal data protection audit at least annually, reviewing each ROPA activity against its stated lawful basis, retention period, recipients, and cross-border basis (s.129; CBPDT Guideline 3/2025), and verifying that written processor/security agreements remain in place and current.
- DPIA. A DPIA-equivalent is conducted before any high-risk processing and is mandatory before the e-commerce / online-payments launch; DPIA outcomes are tracked to closure.
- Vendor assurance. Processors are reviewed for evidence of independent Security-Principle compliance (§14), data residency, and sub-processor changes.
- Reporting. The DPO reports compliance status, audit findings, incidents, and open remediation items to the Board at least annually and on any material incident.
23. Complaints & Regulatory Enforcement
23.1 Complaining to Mizuha first
Data subjects are encouraged to raise any concern about how Mizuha handles their personal data — or to exercise their rights of access (s.30), correction (s.34), consent withdrawal (s.38), prevention of direct marketing (s.43), or data portability (s.43A) — directly with Mizuha in the first instance:
| Channel | Detail |
|---|---|
| [DPO email — to be assigned, e.g. dpo@mizuha.com.my] | |
| Post | Data Protection Officer, Mizuha Eco Solutions Sdn Bhd, [registered office address, Petaling Jaya, Selangor — to be confirmed] |
- Mizuha acknowledges complaints promptly and responds to rights requests within the 21-day PDPA window, extending only where lawfully permitted and with notice to the data subject.
- Complaints and their resolution are logged by the DPO for accountability.
23.2 Complaining to the Commissioner (JPDP)
If a data subject is dissatisfied with Mizuha's response, they may complain to the regulator:
| Field | Detail |
|---|---|
| Regulator | Personal Data Protection Commissioner (PDPA 2010, s.47), Department of Personal Data Protection (Jabatan Perlindungan Data Peribadi, JPDP), Ministry of Digital |
| Functions | Receives and investigates complaints, conducts investigations, and enforces the Act |
| Contact | Via the official JPDP channels — website www.pdp.gov.my; Department of Personal Data Protection (JPDP), Ministry of Digital, Putrajaya (confirm current postal address and complaint hotline at publication via pdp.gov.my) |
23.3 Cooperation with the regulator
Mizuha cooperates fully with any inquiry, investigation, or direction of the Commissioner, and treats the DPO as the designated liaison for all regulatory correspondence.
24. Consequences of Non-Compliance
24.1 Statutory penalties (PDPA 2010, as amended by Act A1727 2024)
Non-compliance exposes Mizuha — and, where applicable, its processors — to criminal liability. The principal penalties are:
| Contravention | Section | Maximum penalty |
|---|---|---|
| Breach of the data protection principles | s.5(1) (and s.5(1A) for processors breaching the Security Principle) | Fine up to RM1,000,000 and/or imprisonment up to 3 years |
| Failure to notify a data breach | s.12B (breach notification) | Reported as a fine up to RM250,000 and/or imprisonment up to 2 years [VERIFY against gazetted section text — medium confidence] |
| Processing after consent withdrawal | s.38 | Fine up to RM100,000 and/or imprisonment up to 1 year |
| Ignoring a direct-marketing opt-out | s.43 | Fine up to RM200,000 and/or imprisonment up to 2 years |
| Processing without registration where registration is required | s.14 | Fine up to RM500,000 and/or imprisonment up to 3 years |
The principles-breach penalty under s.5(1) was raised by the 2024 amendments from RM300,000 to RM1,000,000, and maximum imprisonment from 2 years to 3 years. It now attaches directly to a data controller and, newly, to a data processor who breaches the Security Principle (s.5(1A)).
24.2 Other consequences
Beyond statutory penalties, non-compliance may expose Mizuha to regulatory enforcement directions, civil claims, contractual liability to B2B partners, and reputational harm inconsistent with Mizuha's quiet, exact, factual brand.
24.3 Internal disciplinary consequences
- Compliance with this Policy is a condition of employment and engagement.
- Any breach of this Policy by an employee, contractor, or intern — including unauthorised processing, failure to report a suspected breach, or routing personal data through unsanctioned channels — may result in disciplinary action up to and including termination of employment or engagement, in accordance with Mizuha's disciplinary procedures and applicable employment law.
- Where conduct involves a criminal offence under the PDPA, Mizuha may refer the matter to the authorities.
- Vendors/processors in breach of their obligations (including the direct Security-Principle duty) may face suspension or termination of their contract and indemnity claims.
25. Review & Amendment
- Review cycle. This Policy is reviewed by the DPO and approved by the Board at least annually, and additionally whenever there is a material change in the law (e.g. issuance of the pending Data Portability Guideline), in Mizuha's processing activities (notably the e-commerce/payments launch or future retail expansion), or following a significant incident.
- Open items. Outstanding verification items (e.g. the short citation of the amending Act, the failure-to-notify penalty figure, the DPO threshold position at launch) are tracked to closure as part of each review.
- Approval and publication. Material amendments take effect on Board approval and are reflected in the bilingual (BM + English) external Privacy Notice where data-subject-facing.
- Change log.
| Version | Date | Author | Approved by | Summary of changes |
|---|---|---|---|---|
| 1.0 | 8 June 2026 | Designated Privacy Owner (acting as DPO if/when appointed) | Board of Directors | Initial issue of the Personal Data Protection Policy (PDPA 2010 as amended by Act A1727 2024; GDPR-aligned). |
| [next] | 8 June 2027 (scheduled) |
Policy owner: Data Protection Officer / Privacy Owner, Mizuha Eco Solutions Sdn Bhd. Next review due: 8 June 2027 (within 12 months of the effective date).
Appendix A — Records of Processing Activities (ROPA)
Document control: ROPA owner — [Privacy Owner / DPO — to be assigned] · Last reviewed: [date] · Review cycle: annual or on material change (e.g. e-commerce launch). Regime: Malaysia PDPA 2010 (Act 709, as amended by Act A1727 (2024)); GDPR bases mapped where EU/EEA data subjects may be reached (GDPR Art.30). Cross-cutting note: Most processors are SaaS hosted outside Malaysia — cross-border governance (PDPA 2010, s.129; CBPDT Guideline 3/2025) is the dominant control. Named B2B contacts are personal data (PDPA 2010, s.4) and are in scope. Recipients are described by category, not by vendor name.
| # | Activity (source) | Data categories | Data subjects | Purpose | Lawful basis — PDPA | Lawful basis — GDPR | Recipient classes | Cross-border | Retention | Key risks / controls |
|---|---|---|---|---|---|---|---|---|---|---|
| 1 | Consumer waitlist (index.html) |
Email; derived IP, timestamp, consent record, signup source/UTM | Consumers / prospects (incl. possible EU tourists) | Register launch interest; build pre-launch audience | Consent (s.6) — signup is the consent act | Art.6(1)(a) | ESP, cloud host | Yes (ESP/host likely US/EU/SG) | Until launch + [retention months — to be confirmed]; suppress/delete on unsubscribe or ~24 months inactivity | Missing opt-in record; purpose creep; absent unsubscribe → maintain consent log + working opt-out |
| 2 | Contact form (contact.html) |
Name, email, organisation, topic, free-text message | Business contacts, press, enquirers | Respond to enquiries | Consent + processing necessary to respond | Art.6(1)(b) pre-contractual, else 6(1)(f) | Email platform, CRM/helpdesk, cloud host | Yes | Live enquiry + ~12–24 months [to be confirmed] | Free-text may capture sensitive data (s.40); routing to personal inboxes outside a DPA → controlled mailbox + DPA |
| 3 | B2B sample / wholesale enquiry (wholesale.html) |
Work email; planned: name, company, role, phone, segment, est. volume / tier, custom-print interest (MOQ ~30,000), shipping address if sampled | Partner-venue employees (personal data) | Qualify/respond to leads; arrange sampling & quotes | Contractual / pre-contractual (s.6(2)) + consent | Art.6(1)(b); 6(1)(f) for B2B prospecting | CRM, ESP, cloud host, sampling/logistics | Yes | Active lead + ~24–36 months; longer if converts | "B2B = out of scope" error; unsolicited marketing without separate consent → separate marketing opt-in |
| 4 | Newsletter / direct marketing | Email, name (opt.), segment, engagement (opens/clicks), preferences | Opted-in consumers & business contacts | Direct marketing, product/trade news | Consent; s.43 opt-out must always work | Art.6(1)(a); soft opt-in for existing customers | ESP, analytics, cloud host | Yes | Until withdrawal; re-permission/suppress after ~18–24 months inactivity | Bundled consent (reusing waitlist emails); failed opt-out → preference centre + distinct opt-in |
| 5 | Website analytics & cookies | IP, device/browser, cookie IDs, pages, referrer/UTM, approx. location, session behaviour | All visitors | Traffic measurement, optimisation, attribution, security | Consent for non-essential cookies; legitimate-operations for strictly necessary | ePrivacy consent + Art.6(1)(a); 6(1)(f) strictly necessary | Analytics, tag/CDN, cloud host, possible ad pixels | Yes (US analytics/CDN; EU-visitor reach raises scrutiny) | Raw identifiers ~14 months; aggregate longer | Tags firing before consent (top risk) → CMP blocks non-essential tags until consent |
| 6 | B2B CRM | Name, company, role, work email, phone, enquiry/sample history, pipeline, notes, comms log | Business contacts; later account contacts | Sales pipeline, accounts, fulfilment coordination, reporting | Contractual / pre-contractual (s.6(2)) + consent for marketing layer | Art.6(1)(b); 6(1)(f) | CRM SaaS, ESP, cloud host, internal sales | Yes | Relationship + limitation tail (up to ~7 years for transaction-linked); purge dormant leads ~24–36 months | No DPA with vendor; over-broad access; subjective free-text notes → least-privilege + DPA |
| 7 | Future e-commerce / payments | Name, billing/shipping address, email, phone, order history; card data tokenised (not stored by Mizuha — PCI-DSS scope reduction); credentials if offered | Consumer & trade purchasers | Orders, payment, fulfilment, returns, fraud prevention | Contractual (s.6(2)); legal obligation for tax/accounting | Art.6(1)(b); 6(1)(c); 6(1)(f) fraud | Payment gateway, e-commerce platform, courier, accounting software, cloud host | Yes | Transaction/tax records ~7 years (MY tax); marketing-only data sooner | Card data in PCI scope; checkout marketing bundling → run DPIA-equivalent before launch |
| 8 | NCSM donation reporting & annual audit | Predominantly aggregate/financial (cans × RM0.20); personal data limited to Mizuha/NCSM/auditor contacts | Mizuha, NCSM, auditor personnel | Substantiate/report the charitable donation; support annual audit | Legal obligation / legitimate interest for audit; consent if a donor is named | Art.6(1)(c); 6(1)(f) | NCSM (third party), external auditor | Generally no (both Malaysian) | Audit/financial records ~7 years | Over-sharing customer-level data when aggregates suffice; report as a donation, never a medical/disease-prevention claim |
| 9 | Vendor / cloud hosting (processor layer) | Effectively all categories above (form data, logs, backups, server access logs w/ IPs) | All of the above | Host site, store form data, run email/CRM/analytics, backups, security | Processors on Mizuha's instructions; Mizuha retains basis + imposes s.9 security terms by written contract | Controller's basis carries; Art.28 processor contract required | Cloud/host, ESP, analytics, CRM, future payment processor, CDN | Yes — principal transfer vector | Per underlying activity + backup cycle (backups purged ~30–90 days) | No Art.28/PDPA processor agreement; unknown residency; sub-processor sprawl; vendor breach now reportable (s.12B) |
Appendix B — Data Subject Access Request (DSAR) Form & Procedure
This appendix operationalises the data-subject rights under PDPA 2010 — access (s.30), correction (s.34), withdrawal of consent (s.38), prevention of direct marketing (s.43), and data portability (s.43A) — and the equivalent GDPR rights (Arts.15–17, 20, 21) where applicable.
B.1 DSAR Request Form (data-subject-facing)
Mizuha Eco Solutions Sdn Bhd — Data Subject Request Form Submit to: [DPO / Privacy contact email — to be assigned] · Or by post to: Mizuha Eco Solutions Sdn Bhd, [registered address — to be confirmed], Petaling Jaya, Selangor.
| Field | Entry |
|---|---|
| Full name | |
| Email used with Mizuha | |
| Phone (optional) | |
| Relationship to Mizuha | ☐ Waitlist subscriber ☐ Contact-form enquirer ☐ B2B / wholesale contact ☐ Newsletter subscriber ☐ Customer ☐ Other: ___ |
| Type of request | ☐ Access (s.30) ☐ Correction (s.34) ☐ Withdraw consent (s.38) ☐ Stop direct marketing (s.43) ☐ Data portability (s.43A) ☐ Erasure/deletion (where applicable) |
| Details of request | |
| For corrections — what is inaccurate and what is the correct value | |
| Proof of identity attached | ☐ Yes (describe): ___ |
| Date / signature |
B.2 Handling procedure (obligations)
- Log the request in the DSAR register on receipt; record the receipt date (the clock start).
- Verify identity proportionately before disclosing any data; do not over-collect identity documents.
- Acknowledge to the requester promptly, confirming the request type and expected timeline.
- Respond within 21 days of receipt for access and correction requests (PDPA Regulations). For consent withdrawal (s.38) and direct-marketing opt-out (s.43), cease the relevant processing on receipt of the written notice.
- Search all in-scope systems (ESP, CRM, helpdesk, analytics, cloud storage, backups where reasonably retrievable) and, where the requester is an EU/EEA data subject, apply the GDPR one-month window if shorter is not already met.
- Apply exemptions narrowly (e.g. third-party data, legally privileged or investigatory material); record the basis for any redaction or refusal.
- Fulfil portability (s.43A) by transmitting data to another controller where technically feasible and the format is compatible; treat detailed mechanics as subject to forthcoming JPDP guidance.
- Confirm completion in writing and close the register entry. If refusing, state reasons and inform the requester of their right to complain to the Personal Data Protection Commissioner (JPDP).
- Escalate any request that reveals a possible breach to the breach procedure (Appendix D).
B.3 DSAR Register fields
Request ID · Date received · Requester name · Request type · Identity verified (Y/N) · Systems searched · Due date (21 days / GDPR 1 month) · Action taken · Outcome (fulfilled / partially / refused + reason) · Date closed · Handler.
Appendix C — Consent Record Template
Consent under PDPA 2010, s.6 must be recordable and maintained (PD Regulations 2013, Reg.3); marketing consent must be a distinct, unbundled, unticked opt-in (GDPR Art.7). Sensitive/biometric data requires explicit consent (s.40) — Mizuha avoids collecting such data.
C.1 Consent record fields (per data subject, per purpose)
| Field | Entry |
|---|---|
| Consent record ID | |
| Data subject identifier (email) | |
| Purpose consented to | ☐ Waitlist ☐ Newsletter / direct marketing ☐ B2B follow-up ☐ Cookies (non-essential) |
| Consent text / version shown | [version ID] |
| Method of capture | ☐ Web form (unticked checkbox) ☐ CMP banner ☐ Other |
| Timestamp | |
| Source page / UTM | |
| IP / device (where captured) | |
| Language shown | ☐ English ☐ Bahasa Malaysia |
| Withdrawal date (if any) | |
| Withdrawal method |
C.2 Bilingual marketing-consent wording (ready-to-use)
English: Yes, I would like to receive occasional emails from Mizuha Eco Solutions Sdn Bhd about Mizuha canned water, product launches and trade news. I understand I can unsubscribe at any time using the link in every email, or by contacting [DPO email — to be assigned]. My details are handled under Mizuha's Privacy Notice.
Bahasa Malaysia: Ya, saya ingin menerima e-mel sekali-sekala daripada Mizuha Eco Solutions Sdn Bhd mengenai air dalam tin Mizuha, pelancaran produk dan berita perdagangan. Saya faham bahawa saya boleh berhenti melanggan pada bila-bila masa melalui pautan dalam setiap e-mel, atau dengan menghubungi [e-mel DPO — akan ditetapkan]. Maklumat saya dikendalikan di bawah Notis Privasi Mizuha.
Implementation note: present as an unticked checkbox, separate from the waitlist or enquiry submission. Do not pre-tick. Do not reuse a waitlist or enquiry email for marketing without this fresh consent.
Appendix D — Personal Data Breach Register & Commissioner Notification Template
Under PDPA 2010, s.12B (in force 1 June 2025) Mizuha must notify the Commissioner as soon as practicable and in any event within 72 hours of the occurrence of (or reason to believe in) a personal data breach, and notify affected data subjects within 7 days of notifying the Commissioner where the breach causes or is likely to cause "significant harm" (incl. a breach of significant scale — more than 1,000 data subjects). A processor/vendor breach is reportable. Failing to notify is reported to attract a fine up to RM250,000 and/or 2 years' imprisonment [VERIFY against gazetted section text].
D.1 Breach register fields
Breach ID · Date/time of occurrence · Date/time Mizuha became aware · Source (internal / processor / external report) · Description · Personal data categories affected · Number of data subjects affected · Cross-border element (Y/N) · Significant-harm assessment + reasoning · Commissioner notified (Y/N, date/time, within 72h?) · Data subjects notified (Y/N, date, within 7 days?) · Containment & remediation actions · Root cause · Preventive measures · Status (open/closed) · Owner.
D.2 Commissioner notification template (fields to capture)
| Field | Entry |
|---|---|
| Notifying controller | Mizuha Eco Solutions Sdn Bhd, Petaling Jaya, Selangor |
| Controller contact / DPO | [DPO name & email — to be assigned] |
| Date/time of breach occurrence | |
| Date/time controller became aware | |
| Is this within 72 hours of occurrence? | ☐ Yes ☐ No (explain delay) |
| Nature of the breach | ☐ Confidentiality (unauthorised access/disclosure) ☐ Integrity (alteration) ☐ Availability (loss/destruction) |
| Affected activity (ref. ROPA Appendix A) | |
| Categories of personal data affected | |
| Approx. number of data subjects affected | |
| Was a processor/vendor involved? | ☐ Yes (name, role) ☐ No |
| Cross-border data involved? | ☐ Yes ☐ No |
| Likely consequences / significant-harm assessment | |
| Measures taken / proposed (containment, remediation) | |
| Have / will affected data subjects be notified? | ☐ Yes (date) ☐ No (reason) |
| Reporter name, role, date |
Appendix E — Data Retention Schedule (consolidated)
Per the Retention Principle (PDPA 2010, s.10) and GDPR Art.5(1)(e), personal data must not be kept longer than necessary. Bracketed periods are Mizuha's to confirm; seven-year periods follow Malaysian accounting/tax record-keeping practice.
| Data set | Source / ROPA ref | Retention period | Trigger to delete / review | Disposal method |
|---|---|---|---|---|
| Waitlist subscriber data | A-1 | Until launch + [retention months — to be confirmed]; max ~24 months inactivity | Unsubscribe, launch completion, or inactivity | Permanent deletion + ESP suppression |
| Contact-form enquiries | A-2 | Live enquiry + ~12–24 months [to be confirmed] | Enquiry resolved + period elapsed | Permanent deletion |
| B2B sample / wholesale leads (unconverted) | A-3, A-6 | Active lead + ~24–36 months | Lead dormant past period | Delete from CRM + ESP |
| B2B converted-customer records | A-6, A-7 | Relationship + limitation tail, up to ~7 years for transaction-linked records | End of relationship + statutory tail | Secure deletion |
| Newsletter / marketing data | A-4 | Until withdrawal; re-permission/suppress after ~18–24 months inactivity | Withdrawal or inactivity | Suppression then deletion |
| Analytics raw identifiers | A-5 | ~14 months (aggregate may be kept longer) | Retention period elapsed | Automated expiry in analytics tool |
| Cookie consent records | A-5, C | Duration of consent + reasonable evidentiary period [to be confirmed] | Consent withdrawn / re-prompt cycle | Deletion |
| E-commerce transaction & tax records | A-7 | ~7 years (Malaysian tax/accounting) | Statutory period elapsed | Secure deletion |
| NCSM donation / audit records | A-8 | ~7 years (financial/audit) | Statutory period elapsed | Secure deletion |
| Backups | A-9 | ~30–90 days rolling | Backup cycle rotation | Overwrite / automated purge |
| DSAR, consent & breach registers | B, C, D | Retain as accountability evidence for [period — to be confirmed, e.g. 6 years] | Period elapsed | Secure deletion |
Note: backups must not outlive primary-record retention; restore-and-purge procedures apply where a deletion request reaches backup media.
Appendix F — Cookie & Tracking Table
For EU/EEA visitors, non-essential cookies require prior, informed, freely-given, withdrawable consent with a genuine "reject all"; strictly-necessary cookies are exempt (ePrivacy/GDPR). Malaysia is moving toward consent-based cookie governance under the 2024 reforms. The consent management platform (CMP) must block non-essential tags until consent is given, and the notice must be bilingual (EN/BM).
| Cookie / tracker name | Category | Provider type | Purpose | Duration | Consent required |
|---|---|---|---|---|---|
| [session/security cookie — to be confirmed] | Strictly necessary | First-party / host | Session integrity, security, load balancing | Session | No (exempt) |
| [consent state cookie — to be confirmed] | Strictly necessary | CMP | Stores cookie-consent choices | [e.g. 6–12 months] | No (exempt) |
| [analytics cookie — to be confirmed] | Analytics / performance | Web analytics (likely US) | Traffic measurement, optimisation, attribution | [e.g. up to 14 months] | Yes |
| [analytics ID — to be confirmed] | Analytics / performance | Web analytics | Distinguish users / sessions | [e.g. 14 months] | Yes |
| [CDN/tag cookie — to be confirmed] | Functional / performance | CDN / tag manager | Content delivery, tag orchestration | [to be confirmed] | Yes (if non-essential) |
| [marketing pixel — to be confirmed, if used] | Marketing / targeting | Ad platform (likely US) | Campaign attribution, retargeting | [to be confirmed] | Yes |
Implementation notes: (1) confirm exact cookie names, providers and durations at build time and keep this table in sync with the live CMP; (2) any analytics/marketing tracker likely transfers data outside Malaysia — document a lawful transfer basis (PDPA 2010, s.129; CBPDT Guideline 3/2025); (3) provide an always-available link to re-open the CMP so visitors can withdraw consent.
Appendix G — Data Protection Impact Assessment (DPIA) Template & Trigger Criteria
A DPIA (also called a privacy impact assessment) is Mizuha's structured method for identifying and minimising the data-protection risks of a new or changed processing activity before it goes live. Although a DPIA is not separately mandated by the PDPA 2010, it is required as a matter of Mizuha policy (see §14.3, §19.3(8) and §22.4) and reflects the accountability expectation under GDPR Art. 35 and good international practice. The DPIA evidences that Mizuha assessed risk before processing — the core of accountability (§2, GDPR Art. 5(2)).
G.1 When a DPIA is mandatory (trigger criteria)
A DPIA must be completed and signed off by the Designated Privacy Owner (acting as DPO if/when appointed) before any of the following begins:
- Launch of e-commerce and/or online payments — collection of order, delivery and payment data from consumers (the single most significant planned expansion of Mizuha's processing).
- Any new processing of sensitive personal data or biometric data (PDPA 2010, s.4 as amended). Mizuha's standing position is to avoid such processing; if it cannot be avoided, a DPIA is mandatory.
- Large-scale or systematic processing — any activity expected to take Mizuha across, or near, the 1,000-data-subject threshold relevant to DPO appointment and "significant scale" breach assessment (§19.1, §16).
- New profiling, behavioural tracking, or automated decision-making — including advanced website analytics, ad-tech retargeting, or scoring of leads/customers that produces effects for the individual.
- A new cross-border transfer of personal data to a country or cloud region not already covered by an existing transfer assessment (§18).
- Engagement of a new category of data processor that will handle personal data at scale (e.g. a new payment gateway, marketing platform, or CRM).
- A material change to an existing activity that increases the volume, sensitivity, or risk of the personal data processed.
If it is unclear whether a DPIA is required, a short screening assessment (Part 1 below) is completed and the Privacy Owner decides.
G.2 DPIA template
Part 1 — Screening (always complete)
| Field | Entry |
|---|---|
| Project / activity name | |
| Project owner & department | |
| Date of screening | |
| Brief description of the processing | |
| Does any trigger in G.1 apply? (list which) | |
| Outcome | ☐ Full DPIA required ☐ No DPIA required (record reason) |
| Screening approved by (Privacy Owner) |
Part 2 — Describe the processing
| Field | Entry |
|---|---|
| Nature of processing (how data is collected, used, stored, deleted) | |
| Scope (data categories; volume; number/types of data subjects; geography; retention) | |
| Context (relationship with individuals; their expectations; novelty; relevant guidance) | |
| Purpose(s) and intended benefit | |
| Data subjects affected (consumers / business contacts / staff / other) | |
| Recipients & processors (by category) | |
| Cross-border transfers (destination, mechanism, safeguards — see §18) |
Part 3 — Necessity & proportionality
| Question | Assessment |
|---|---|
| Lawful basis under PDPA 2010 / GDPR (see §8) | |
| Is the processing necessary, relevant and not excessive for the purpose? (s.6) | |
| Could the purpose be achieved with less data or less intrusive means? | |
| How is the §7 notice given, and consent obtained/recorded where relied on? | |
| How are data-subject rights (§11) supported for this activity? | |
| How are accuracy (§s.11) and retention (§s.10 / Appendix E) handled? |
Part 4 — Risk assessment
| # | Risk to individuals | Likelihood (L/M/H) | Severity (L/M/H) | Overall (L/M/H) |
|---|---|---|---|---|
| 1 | ||||
| 2 | ||||
| 3 |
Part 5 — Measures to reduce risk
| Risk # | Mitigation / control | Residual risk (L/M/H) | Measure approved? |
|---|---|---|---|
| 1 | |||
| 2 |
Part 6 — Sign-off and outcome
| Field | Entry |
|---|---|
| Residual risk acceptable? | ☐ Yes — proceed ☐ Yes, with conditions ☐ No — do not proceed |
| Conditions / actions before go-live (with owners and dates) | |
| Privacy Owner / DPO sign-off (name, date) | |
| Approving authority (where high residual risk) | |
| Review date for this DPIA | |
| Linked records (ROPA entry — Appendix A; consent records — Appendix C; retention — Appendix E) |
G.3 Governance
- Completed DPIAs are retained by the Privacy Owner as part of Mizuha's accountability record and are made available to the Commissioner (JPDP) on request.
- Each DPIA is revisited when the underlying activity materially changes and at the Policy's annual review (§25).
- A DPIA that concludes with high residual risk that cannot be mitigated must be escalated to the Board before processing begins; consultation with the Commissioner should be considered.