Skip to main content

Personal Data Protection Policy - Malaysia & Singapore

Written by Edward Au

Malaysia (PDPA 2010) & Singapore (PDPA 2012)

Version: 19 September 2025

1. Introduction

Eber is committed to protecting the privacy and personal data of all individuals we interact with, including customers, employees, vendors, and business partners. This Personal Data Protection Policy ("Policy") sets out how Eber collects, uses, discloses, and manages personal data in accordance with:

  • The Personal Data Protection Act 2010 (Malaysia) ("Malaysia PDPA")

  • The Personal Data Protection Act 2012 (Singapore) ("Singapore PDPA")

This Policy applies to all entities operating under the Eber brand, and to all employees, contractors, and third-party processors who handle personal data on behalf of Eber.

2. Scope of This Policy

This Policy applies to:

  • All personal data collected, processed, or stored by Eber in Malaysia and Singapore

  • Personal data processed in connection with Eber's products, services, and operations

  • All business units, departments, employees, and third-party vendors acting on behalf of Eber

This Policy covers personal data processed in both digital and physical formats.

3. Definitions

Term

Definition

Personal Data

Any information that relates to an identified or identifiable individual, directly or indirectly.

Sensitive Personal Data

Data relating to health, biometrics, political opinions, religious beliefs, or criminal records.

Data Subject

An individual whose personal data is collected or processed by Eber.

Data Processor

A party that processes personal data on behalf of Eber.

Data User

Eber, in its capacity as the entity that controls and processes personal data.

Processing

Any operation performed on personal data including collection, storage, use, disclosure, or deletion.

DPO

Data Protection Officer — the designated person responsible for overseeing data protection compliance.

Consent

A freely given, specific, informed, and unambiguous indication of agreement to process personal data.

4. Types of Personal Data Collected

4.1 General Personal Data

  • Full name, NRIC/Passport number, date of birth

  • Contact information: email address, phone number, mailing address

  • Account credentials and authentication data

  • Transaction and payment records

  • Usage data and behavioural analytics from Eber's platform

  • Device information, IP addresses, and location data

4.2 Sensitive Personal Data

Eber may collect personal data, including sensitive personal data where necessary and permitted under applicable law, solely for legitimate business, legal, or regulatory purposes. All data collection and processing will be conducted in accordance with our internal data governance policies and in accordance with:

  • The Personal Data Protection Act 2010 (Malaysia) ("Malaysia PDPA")

  • The Personal Data Protection Act 2012 (Singapore) ("Singapore PDPA")

5. Principles of Data Collection

5.1 Lawful Basis and Consent

Eber collects personal data on one or more of the following lawful bases:

  • Consent: The data subject has given clear consent for processing

  • Contract: Processing is necessary for the performance of a contract

  • Legal Obligation: Processing is required to comply with a legal obligation

  • Legitimate Interests: Processing is necessary for Eber's legitimate business interests

Where consent is relied upon, Eber ensures it is:

  • Freely given, specific, informed, and unambiguous

  • Obtained prior to collection through clear opt-in mechanisms

  • Documented and capable of being withdrawn at any time

5.2 Collection Directly from Data Subjects

Eber generally collects personal data directly from data subjects through registration forms, platform usage, customer support interactions, or contractual agreements.


5.3 Collection from Third Parties

Where personal data is obtained from third parties (e.g., business partners or referrals), Eber verifies that such third parties have the appropriate authority to share the data and that data subjects have been duly notified.


6. Purpose of Data Processing

Eber processes personal data for the following purposes:

Purpose

Basis

Account registration and management

Contract / Consent

Provision of Eber's products and services

Contract

Processing payments and transactions

Contract / Legal Obligation

Customer support and communications

Contract / Legitimate Interest

Fraud prevention and security monitoring

Legal Obligation / Legitimate Interest

Regulatory and legal compliance (KYC, AML)

Legal Obligation

Marketing and promotional communications (opt-in)

Consent

Product improvement and analytics

Legitimate Interest

Employment administration (for employees)

Contract / Legal Obligation

Personal data will not be processed for any purpose that is incompatible with the original purpose of collection without additional consent.


7. Data Accuracy

Eber takes reasonable steps to ensure that personal data held is accurate, complete, and up to date. Data subjects are encouraged to notify Eber of any changes to their personal data. Eber will make corrections within a reasonable timeframe upon verified request.


8. Data Retention and Deletion

Any of your Personal Data provided to Eber is retained for as long as the purposes for which the Personal Data was collected continues; your Personal Data is then destroyed from our records and system in accordance with our retention policy in the event your Personal Data is no longer required for the said purposes unless its further retention is required to satisfy a longer retention period to meet our operational, legal, regulatory, tax or accounting requirements.


9. Disclosure of Personal Data

9.1 Third-Party Disclosure

Eber may disclose personal data to third parties in the following circumstances:

  • Service providers and data processors engaged to support Eber's operations (e.g., cloud hosting, payment processors, analytics providers)

  • Business partners where disclosure is required to deliver contracted services

  • Regulatory authorities, law enforcement, or courts as required by law

  • Auditors, legal advisors, and professional consultants under confidentiality obligations

9.2 Conditions of Disclosure

All third-party processors are required to:

  • Enter into a Data Processing Agreement with Eber

  • Implement appropriate technical and organisational security measures

  • Process personal data only on Eber's documented instructions

  • Notify Eber promptly of any personal data breach

9.3 Cross-Border Data Transfers

Eber may transfer personal data outside Malaysia or Singapore where necessary. Such transfers are conducted in compliance with:

  • Malaysia PDPA: Transfers are made only to countries with adequate data protection standards, or subject to contractual safeguards approved by the Minister

  • Singapore PDPA: Transfers are subject to contractual protection obligations equivalent to Singapore PDPA standards

10. Data Subject Rights

Eber respects and upholds the rights of data subjects. Data subjects in both Malaysia and Singapore have the following rights:

Right

Description

Applicable Jurisdiction

Right of Access

Request access to personal data held about you

Malaysia & Singapore

Right of Correction

Request correction of inaccurate or incomplete data

Malaysia & Singapore

Right to Withdraw Consent

Withdraw consent for processing at any time

Malaysia & Singapore

Right to Data Portability

Request personal data in a machine-readable format

Singapore

Right to Erasure

Request deletion of personal data (subject to legal obligations)

Singapore

Right to Object to Processing

Object to processing based on legitimate interests

Singapore

Right to Restrict Processing

Request restriction on how data is used

Singapore

To exercise any of the above rights, data subjects may submit a written request to the Data Protection Officer using the contact details in Section 14. Eber will respond within:

  • Malaysia: 21 days (or as extended under Malaysia PDPA)

  • Singapore: 10 business days to acknowledge; 30 calendar days to respond

11. Data Security

11.1 Technical Safeguards

  • Encryption of personal data in transit (TLS 1.2+) and at rest (AES-256)

  • Role-based access controls and the principle of least privilege

  • Multi-factor authentication for systems handling personal data

  • Regular vulnerability assessments and penetration testing

  • Secure software development lifecycle (SDLC) practices

11.2 Organisational Safeguards

  • Regular data protection training for all employees

  • Background screening for staff in sensitive data roles

  • Data Protection Impact Assessments (DPIAs) for high-risk processing activities

  • Internal audit programme to assess policy compliance

11.3 ISO 27001 Alignment

Eber's security measures are aligned with ISO/IEC 27001 requirements. The following ISO 27001 policies directly support PDPA compliance:

PDPA Requirement

ISO 27001 Policy Reference

Data protection procedures

Information Security Policy

Access controls

Access Control Policy

Breach response

Incident Response Policy

Vendor management

Supplier Security Policy

Data retention and deletion

Asset Management Policy

Staff training

Security Awareness Training Programme

12. Personal Data Breach Notification

12.1 Internal Response

Upon discovery of a personal data breach, Eber will:

  • Immediately contain the breach and preserve evidence

  • Convene an incident response team within 2 hours

  • Conduct an initial assessment of the breach scope and severity

  • Document the incident in the Breach Register

12.2 Regulatory Notification

  • Malaysia: Eber will notify the Personal Data Protection Commissioner as soon as practicable where a breach is likely to cause significant harm to data subjects.

  • Singapore: Eber will notify the Personal Data Protection Commission (PDPC) within 3 calendar days where a breach affects 500 or more individuals, or is likely to cause significant harm.

12.3 Individual Notification

Where a breach is likely to result in significant harm to affected data subjects, Eber will notify affected individuals as soon as reasonably practicable, providing:

  • A description of the breach and data affected

  • Steps taken to mitigate the breach

  • Recommended actions for affected individuals to protect themselves

  • Contact details for further enquiries

13. Data Protection Officer (DPO)

Eber has appointed a Data Protection Officer responsible for:

  • Monitoring compliance with this Policy and applicable PDPA legislation

  • Serving as the primary point of contact for data protection matters

  • Conducting and reviewing Data Protection Impact Assessments

  • Liaising with regulatory authorities in Malaysia and Singapore

  • Providing data protection guidance and training to staff

The appointment of a DPO reflects Eber's commitment to embedding data protection into its operations and culture.


14. Contact Details

For all data protection enquiries, access/correction requests, or complaints, please contact:

Details

Data Protection Officer

Eber

Email

Malaysia Correspondence

Eber Pte Ltd

Edward Au

380 Jalan Besar, Arc 380 #07-06, Singapore 209000

Singapore Correspondence

Ebertech Sdn Bhd

Suet Yee

D-33A-3, Menara Suezcap 1, KL Gateway, No.2 Jalan Kerinchi, Gerbang Kerinchi Lestari, 59200 Kuala Lumpur

Eber will endeavour to resolve all complaints promptly and fairly. Where data subjects remain unsatisfied, they may lodge a complaint with:

15. Cookies and Tracking Technologies

Eber uses cookies and similar tracking technologies on its digital platforms. These may include:

  • Essential cookies (required for platform functionality — no consent required)

  • Analytics cookies (to understand usage patterns — consent required)

  • Marketing cookies (for targeted advertising — consent required)

Users may manage cookie preferences through the cookie consent banner or browser settings. Detailed information is available in Eber's Cookie Policy.


16. Direct Marketing

Eber may send marketing communications about its products and services where a data subject has expressly opted in, or where Eber has an existing customer relationship and the data subject has not opted out. Data subjects may opt out of marketing communications at any time by:

  • Clicking the "Unsubscribe" link in any marketing email

  • Updating preferences within the Eber platform

17. Children's Personal Data

Eber's services are not directed at children under the age of 18. Eber does not knowingly collect personal data from minors without verifiable parental or guardian consent. If Eber becomes aware that personal data of a minor has been collected without appropriate consent, such data will be promptly deleted.


18. Policy Review and Updates

This Policy is reviewed at least annually, or whenever there is a material change to Eber's data processing activities or applicable legislation. Updates will be communicated to data subjects through Eber's website and, where appropriate, via direct notification.

The current version of this Policy is always available at: www.eber.com/privacy-policy


19. Governing Law

This Policy is governed by and construed in accordance with applicable law in each respective jurisdiction:

  • Malaysia: Personal Data Protection Act 2010 (Act 709) and its subsidiary legislation

  • Singapore: Personal Data Protection Act 2012 (No. 26 of 2012), as amended, and PDPC Advisory Guidelines

In the event of any inconsistency between this Policy and applicable law, the law prevails.

Did this answer your question?