• Home
  • News
    • Press Statements
    • Speeches
    • Bar News
    • AGMs and EGMs
    • In Memoriam
    • Legal and General News
    • Court Judgments
  • Members
    • Circulars
    • Sijil Annual and Payments
    • Benefits
    • Peer Support Network
    • Practice Management
    • Professional Development
    • Opportunities for Practice
    • Mentor-Mentee Programmes
    • Laws, BC Rulings and Practice Directions
    • Resources
    • Become a Member
  • Find
    • Legal Directories
    • BC Legal Aid Centres
    • State Bar Committees
    • Law Firms | Areas of Practice
    • Jobs
    • Useful forms
  • About Us
    • Malaysian Bar and Bar Council
    • President's Corner
    • Committees
    • Previous Committees
    • Contacts
    • Advertising
  • Public
    • Complaints
    • Legal Aid
    • Notices
    • Compensation Fund
  • Search
  • Login
Search for

New login method: If first-time login, the password is your NRIC No. Call 20502191 for help.

 
Lost your password? Remember Me

 
No User ID/Password for firm? Click here for more information. Forgot Firm Username/Password?

Set a new password

If you have lost your password, you must set a new password. To begin this process, please key in your 12-digit NRIC No. below.

Forgot Firm Username/ Password?

Please enter name of firm or registered email address, indicate whether you want to retrieve your firm's username or password, and click "Submit".

Username Password
 
Access to Member Portal

Please key in your membership number, and click "GO"

BC
Resume Practice Request

Please key in your membership number, and click "GO"

BC
Newly-Called Request

Please key in your pupil code, and click "Submit"

Pupil Code

Change Password


Please enter your Password and Confirm Password then click on the Change Password button.
You will receive a new password shortly. Use this new password to access the site.

Password:
Confirm Password:
 
Change Password


Shortcut
  • Legal Directory
  • Find a Job
  • CPD
  • Online Shop
  • e-Library
  • Payments
  • Complaints
  • Committees

Search the site

  • Search Me
Member Login
  • BC Online Facilities
  • Login Type 2
  • Login Type 3
  • Login Type 4
  • News
  • Legal and General News
  • Legal News
News
Press Statements
  • Press Statements
Speeches
  • Speeches
Bar News
  • Notices
  • News
AGMs and EGMs
  • Resolutions
In Memoriam
  • In Memoriam
Legal and General News
  • General News
  • Members' Opinions
  • Legal News
Court Judgments
  • Judgments
  • Go back to list
What you need to know about the PDPA 31 Dec 2012 12:00 am

©The Star (Used by permission)


A freelance journalist from Penang was already coping with the pain from a haemorrhoids surgery when she had to endure another hurtful experience she discovered that her surgeon had taken photographs of her private parts without her consent when she was under.

When she confronted him, she was told that it was “normal procedure” and a common practice for “medical purposes”. Outraged that her privacy had been violated, she sued the doctor.

This is one of the many cases of personal data breaches and privacy violations in the country. Hence, the enforcement of the Personal Data Protection Act (PDPA) this New Year is much lauded. In fact, it is long awaited for some, over a decade long.

However, while pictures of one's private parts may constitute as personal data, the aggrieved patient would not be able to take action under the Act our PDPA only regulates commercial transactions. (The freelance journalist, however, won RM25,000 in damages in her civil court case.)

Here are some of the facts you need to know about the PDPA:

> What is the scope of the PDPA?

The Act regulates the processing of personal data in commercial transactions. The Act applies to any person who processes personal data for commercial transactions (data user). This includes those who control and authorise the processing of personal data for commercial transactions. If you have a list of customers with their contact details for your part–time cupcake–making enterprise, for example, you may be subjected to the Act.

> What is “personal data”?

Personal data is defined as information that relates directly to a person or consumer in a commercial transaction (data subject).

It is personal data if the information can identify the person and includes any expression of opinion about him or her. It includes: name, address, MyKad number, passport number, health record, e–mail address, photographs, images from CCTV recording, information in personal file, bank account details and credit card details.

> What are “commercial transactions”?

Commercial transactions mean any transaction of a commercial nature, regardless of whether it is contractual. This includes the collection of personal data of potential customers.

> What is “processing” of personal data?

Processing personal data is the act of collecting, recording, holding or storing personal data. The data can be stored offline or online, including in paper files, paper stacks, computer database, e–mail, instant messenger, USB sticks, external hard disks, Cloud computing system or other storage systems on the Internet.

> What are your rights as a data subject (a person whose data is processed)?

As a data subject, you have a right to seven protection principles under the PDPA.

General Principle: Any processing of your personal data requires your consent.

Notice and Choice Principle: Data users are required to notify you of the purpose for which your personal data is collected and about the right to request access and correction of your personal data.

Disclosure Principle: The data user is not allowed to disclose your personal data to any third party without your consent.

Security Principle: A data user needs to take practical steps to protect your personal data from any loss, misuse, modification, unauthorised or accidental access or disclosure, alteration or destruction.

Retention Principle: Your personal data cannot be kept longer than is necessary to fulfil the original purpose it was obtained for by the data user.

Data Integrity Principle: A data user needs to take reasonable steps to ensure the accuracy and currency of your personal data in their “keep”.

Access Principle: You should be given access to your personal data and shall be able to make corrections where it is inaccurate or incomplete.

Source: JPDP and Dr Sonny Zulhuda, International Islamic University Malaysia.

> For enquiries or to lodge your personal data complaint, call 03–8911 5000/7901 or e–mail jpdp@kpkk.gov.my

© Copyright Reserved 2023. Bar Council Malaysia.
 

I'm a

 
 
 
 
 

I'm a