Malaysia (PDPA 2010) & Singapore (PDPA 2012)
Version: 19 September 2025
1. Introduction
Eber is committed to protecting the privacy and personal data of all individuals we interact with, including customers, employees, vendors, and business partners. This Personal Data Protection Policy ("Policy") sets out how Eber collects, uses, discloses, and manages personal data in accordance with:
The Personal Data Protection Act 2010 (Malaysia) ("Malaysia PDPA")
The Personal Data Protection Act 2012 (Singapore) ("Singapore PDPA")
This Policy applies to all entities operating under the Eber brand, and to all employees, contractors, and third-party processors who handle personal data on behalf of Eber.
2. Scope of This Policy
This Policy applies to:
All personal data collected, processed, or stored by Eber in Malaysia and Singapore
Personal data processed in connection with Eber's products, services, and operations
All business units, departments, employees, and third-party vendors acting on behalf of Eber
This Policy covers personal data processed in both digital and physical formats.
3. Definitions
Term | Definition |
Personal Data | Any information that relates to an identified or identifiable individual, directly or indirectly. |
Sensitive Personal Data | Data relating to health, biometrics, political opinions, religious beliefs, or criminal records. |
Data Subject | An individual whose personal data is collected or processed by Eber. |
Data Processor | A party that processes personal data on behalf of Eber. |
Data User | Eber, in its capacity as the entity that controls and processes personal data. |
Processing | Any operation performed on personal data including collection, storage, use, disclosure, or deletion. |
DPO | Data Protection Officer — the designated person responsible for overseeing data protection compliance. |
Consent | A freely given, specific, informed, and unambiguous indication of agreement to process personal data. |
4. Types of Personal Data Collected
4.1 General Personal Data
Full name, NRIC/Passport number, date of birth
Contact information: email address, phone number, mailing address
Account credentials and authentication data
Transaction and payment records
Usage data and behavioural analytics from Eber's platform
Device information, IP addresses, and location data
4.2 Sensitive Personal Data
Eber may collect personal data, including sensitive personal data where necessary and permitted under applicable law, solely for legitimate business, legal, or regulatory purposes. All data collection and processing will be conducted in accordance with our internal data governance policies and in accordance with:
The Personal Data Protection Act 2010 (Malaysia) ("Malaysia PDPA")
The Personal Data Protection Act 2012 (Singapore) ("Singapore PDPA")
5. Principles of Data Collection
5.1 Lawful Basis and Consent
Eber collects personal data on one or more of the following lawful bases:
Consent: The data subject has given clear consent for processing
Contract: Processing is necessary for the performance of a contract
Legal Obligation: Processing is required to comply with a legal obligation
Legitimate Interests: Processing is necessary for Eber's legitimate business interests
Where consent is relied upon, Eber ensures it is:
Freely given, specific, informed, and unambiguous
Obtained prior to collection through clear opt-in mechanisms
Documented and capable of being withdrawn at any time
5.2 Collection Directly from Data Subjects
Eber generally collects personal data directly from data subjects through registration forms, platform usage, customer support interactions, or contractual agreements.
5.3 Collection from Third Parties
Where personal data is obtained from third parties (e.g., business partners or referrals), Eber verifies that such third parties have the appropriate authority to share the data and that data subjects have been duly notified.
6. Purpose of Data Processing
Eber processes personal data for the following purposes:
Purpose | Basis |
Account registration and management | Contract / Consent |
Provision of Eber's products and services | Contract |
Processing payments and transactions | Contract / Legal Obligation |
Customer support and communications | Contract / Legitimate Interest |
Fraud prevention and security monitoring | Legal Obligation / Legitimate Interest |
Regulatory and legal compliance (KYC, AML) | Legal Obligation |
Marketing and promotional communications (opt-in) | Consent |
Product improvement and analytics | Legitimate Interest |
Employment administration (for employees) | Contract / Legal Obligation |
Personal data will not be processed for any purpose that is incompatible with the original purpose of collection without additional consent.
7. Data Accuracy
Eber takes reasonable steps to ensure that personal data held is accurate, complete, and up to date. Data subjects are encouraged to notify Eber of any changes to their personal data. Eber will make corrections within a reasonable timeframe upon verified request.
8. Data Retention and Deletion
Any of your Personal Data provided to Eber is retained for as long as the purposes for which the Personal Data was collected continues; your Personal Data is then destroyed from our records and system in accordance with our retention policy in the event your Personal Data is no longer required for the said purposes unless its further retention is required to satisfy a longer retention period to meet our operational, legal, regulatory, tax or accounting requirements.
9. Disclosure of Personal Data
9.1 Third-Party Disclosure
Eber may disclose personal data to third parties in the following circumstances:
Service providers and data processors engaged to support Eber's operations (e.g., cloud hosting, payment processors, analytics providers)
Business partners where disclosure is required to deliver contracted services
Regulatory authorities, law enforcement, or courts as required by law
Auditors, legal advisors, and professional consultants under confidentiality obligations
9.2 Conditions of Disclosure
All third-party processors are required to:
Enter into a Data Processing Agreement with Eber
Implement appropriate technical and organisational security measures
Process personal data only on Eber's documented instructions
Notify Eber promptly of any personal data breach
9.3 Cross-Border Data Transfers
Eber may transfer personal data outside Malaysia or Singapore where necessary. Such transfers are conducted in compliance with:
Malaysia PDPA: Transfers are made only to countries with adequate data protection standards, or subject to contractual safeguards approved by the Minister
Singapore PDPA: Transfers are subject to contractual protection obligations equivalent to Singapore PDPA standards
10. Data Subject Rights
Eber respects and upholds the rights of data subjects. Data subjects in both Malaysia and Singapore have the following rights:
Right | Description | Applicable Jurisdiction |
Right of Access | Request access to personal data held about you | Malaysia & Singapore |
Right of Correction | Request correction of inaccurate or incomplete data | Malaysia & Singapore |
Right to Withdraw Consent | Withdraw consent for processing at any time | Malaysia & Singapore |
Right to Data Portability | Request personal data in a machine-readable format | Singapore |
Right to Erasure | Request deletion of personal data (subject to legal obligations) | Singapore |
Right to Object to Processing | Object to processing based on legitimate interests | Singapore |
Right to Restrict Processing | Request restriction on how data is used | Singapore |
To exercise any of the above rights, data subjects may submit a written request to the Data Protection Officer using the contact details in Section 14. Eber will respond within:
Malaysia: 21 days (or as extended under Malaysia PDPA)
Singapore: 10 business days to acknowledge; 30 calendar days to respond
11. Data Security
11.1 Technical Safeguards
Encryption of personal data in transit (TLS 1.2+) and at rest (AES-256)
Role-based access controls and the principle of least privilege
Multi-factor authentication for systems handling personal data
Regular vulnerability assessments and penetration testing
Secure software development lifecycle (SDLC) practices
11.2 Organisational Safeguards
Regular data protection training for all employees
Background screening for staff in sensitive data roles
Data Protection Impact Assessments (DPIAs) for high-risk processing activities
Internal audit programme to assess policy compliance
11.3 ISO 27001 Alignment
Eber's security measures are aligned with ISO/IEC 27001 requirements. The following ISO 27001 policies directly support PDPA compliance:
PDPA Requirement | ISO 27001 Policy Reference |
Data protection procedures | Information Security Policy |
Access controls | Access Control Policy |
Breach response | Incident Response Policy |
Vendor management | Supplier Security Policy |
Data retention and deletion | Asset Management Policy |
Staff training | Security Awareness Training Programme |
12. Personal Data Breach Notification
12.1 Internal Response
Upon discovery of a personal data breach, Eber will:
Immediately contain the breach and preserve evidence
Convene an incident response team within 2 hours
Conduct an initial assessment of the breach scope and severity
Document the incident in the Breach Register
12.2 Regulatory Notification
Malaysia: Eber will notify the Personal Data Protection Commissioner as soon as practicable where a breach is likely to cause significant harm to data subjects.
Singapore: Eber will notify the Personal Data Protection Commission (PDPC) within 3 calendar days where a breach affects 500 or more individuals, or is likely to cause significant harm.
12.3 Individual Notification
Where a breach is likely to result in significant harm to affected data subjects, Eber will notify affected individuals as soon as reasonably practicable, providing:
A description of the breach and data affected
Steps taken to mitigate the breach
Recommended actions for affected individuals to protect themselves
Contact details for further enquiries
13. Data Protection Officer (DPO)
Eber has appointed a Data Protection Officer responsible for:
Monitoring compliance with this Policy and applicable PDPA legislation
Serving as the primary point of contact for data protection matters
Conducting and reviewing Data Protection Impact Assessments
Liaising with regulatory authorities in Malaysia and Singapore
Providing data protection guidance and training to staff
The appointment of a DPO reflects Eber's commitment to embedding data protection into its operations and culture.
14. Contact Details
For all data protection enquiries, access/correction requests, or complaints, please contact:
Details |
|
Data Protection Officer | Eber |
Malaysia Correspondence | Eber Pte Ltd Edward Au 380 Jalan Besar, Arc 380 #07-06, Singapore 209000 |
Singapore Correspondence | Ebertech Sdn Bhd Suet Yee D-33A-3, Menara Suezcap 1, KL Gateway, No.2 Jalan Kerinchi, Gerbang Kerinchi Lestari, 59200 Kuala Lumpur |
Eber will endeavour to resolve all complaints promptly and fairly. Where data subjects remain unsatisfied, they may lodge a complaint with:
Malaysia: Personal Data Protection Commissioner (www.pdp.gov.my)
Singapore: Personal Data Protection Commission (www.pdpc.gov.sg)
15. Cookies and Tracking Technologies
Eber uses cookies and similar tracking technologies on its digital platforms. These may include:
Essential cookies (required for platform functionality — no consent required)
Analytics cookies (to understand usage patterns — consent required)
Marketing cookies (for targeted advertising — consent required)
Users may manage cookie preferences through the cookie consent banner or browser settings. Detailed information is available in Eber's Cookie Policy.
16. Direct Marketing
Eber may send marketing communications about its products and services where a data subject has expressly opted in, or where Eber has an existing customer relationship and the data subject has not opted out. Data subjects may opt out of marketing communications at any time by:
Clicking the "Unsubscribe" link in any marketing email
Updating preferences within the Eber platform
17. Children's Personal Data
Eber's services are not directed at children under the age of 18. Eber does not knowingly collect personal data from minors without verifiable parental or guardian consent. If Eber becomes aware that personal data of a minor has been collected without appropriate consent, such data will be promptly deleted.
18. Policy Review and Updates
This Policy is reviewed at least annually, or whenever there is a material change to Eber's data processing activities or applicable legislation. Updates will be communicated to data subjects through Eber's website and, where appropriate, via direct notification.
The current version of this Policy is always available at: www.eber.com/privacy-policy
19. Governing Law
This Policy is governed by and construed in accordance with applicable law in each respective jurisdiction:
Malaysia: Personal Data Protection Act 2010 (Act 709) and its subsidiary legislation
Singapore: Personal Data Protection Act 2012 (No. 26 of 2012), as amended, and PDPC Advisory Guidelines
In the event of any inconsistency between this Policy and applicable law, the law prevails.
