The Personal Data Protection Act 2010 (the “PDPA”) establishes a new general data protection law in Malaysia which governs the collection, use and disclosure of individuals’ personal data by organisations. The Personal Data Protection Commissioner (the “Commissioner”) is appointed by the Minister of Information Communications and Culture under the PDPA with the key functions, amongst others, of promoting awareness of data protection in Malaysia and administering and enforcing the PDPA.
Citylimo Leasing (M) Sdn Bhd is committed to safeguarding the personal information entrusted to us by our customers. We manage your personal information in accordance with the obligations guided by Personal Data Protection Commission Malaysia. This policy outlines the principles and practices we follow in protecting your personal information. This policy also applies to any person providing services on our behalf.
WHAT PERSONAL DATA DO WE COLLECT?
We collect only the personal data that we need for the purposes of providing services to our customers, including personal data needed to:
- Open and manage an account
- Meet regulatory requirements
- Grant credit
- Deliver requested products and support services
- Provide after-sales services
- Contact customers about appointments
- Follow up with customers to determine satisfaction of our products and services
- Notify customers of upcoming events of interests
We normally collect customer data directly from customers. We may collect your data from other persons with your consent or as authorised by law.
We inform our customers, before or at the time of collecting personal data, of the purposes for which we are collecting the data. However, we do not provide this notification when a customer volunteers information for an obvious purpose such as producing a credit card for a purchase payment when the data will only be used to process the payment.
We ask for consent to collect, use or disclose customer personal data, except in specific circumstances where collection, use or disclosure without consent is authorised or required by law. We may assume consent in cases where you volunteer information for an obvious purpose.
In cases where we collected personal data before 1 December 2016, we assume your consent for the purposes for which the personal data was collected, unless the individual has withdrawn consent. If there is a fresh purpose for the use of the personal data, consent will be obtained anew.
Our customers may withdraw consent to the use and disclosure of personal data at any time, unless the personal data is necessary for us to fulfill our legal obligations. We will respect your decision, but we may not be able to provide you with certain products and services if we do not have the necessary personal information.
HOW DO WE USE AND DISCLOSE PERSONAL DATA?
We use and disclose customer personal data only for the purposes for which the information was collected, except as authorised by law. For example, we may use customer contact information to deliver our products and provide our services.
HOW DO WE SAFEGUARD PERSONAL DATA?
We make every reasonable effort to ensure that customer data is accurate and complete. We rely on our customers to notify us if there is a change to their personal data that may affect their relationship with our organisation. If you are aware of an error in our information about you, please let us know and we will correct it on request wherever possible.
We protect customer data in a manner appropriate for the sensitivity of the information. We make every reasonable effort to prevent any loss, misuse, disclosure or modification of personal data, as well as any unauthorized access to personal data.
We will notify the Personal Data Protection Commission of Malaysia, immediately, of a security breach affecting personal data if it creates a real risk of significant harm to individuals.
We retain customer data only for as long as is reasonable to fulfill the purposes for which the data was collected or for legal or business purposes.
We adopt appropriate security measures when destroying customer personal data including shredding paper records and permanently deleting electronic records.
ACCESS TO RECORDS CONTAINING PERSONAL DATA
Customers of Citylimo Leasing (M) Sdn Bhd have access rights to their own personal data in a record that is in our custody or under our control, subject to some exceptions. For example, organizations are required under the Personal Data Protection Act to refuse to provide access to information that would reveal personal data about another individual. Organisations are authorised under the Act to refuse access to personal data if disclosure would reveal confidential information. Access may also be denied if the information is privileged or contained in mediation records.
If we denied a request in whole or part, we will provide the reasons for the refusal. In some cases where exceptions to access apply, we may withhold that information and provide you with the remainder of the record.
You may request for access to your personal data by writing to our Personal Data Protection Officer designated to ensure compliance with PDPA. You must provide sufficient information in your request to allow us to identify the information you are seeking.
You may also request information about our use of your personal data and any disclosure of that information to persons outside our organisation. For personal data collected before 1 December 2016, if we do not have record of disclosures, we will provide information about any disclosure of your information that is likely to have occurred.
You may also request a correction of an error or omission in your personal data. We will respond to your request within 30 calendar days, unless an extension is granted. We may charge a reasonable fee to provide information, but not to make correction. We will advise you of any fees that may apply before processing your request.
QUESTIONS AND COMPLAINTS
If you have a question or concern about any collection, use or disclosure of personal data by Citylimo Leasing (M) Sdn Bhd, or about a request for access to your own personal data, please contact our Personal Data Protection Officer:
Personal Protection Data Officer
Citylimo Leasing (M) Sdn Bhd
No.10, SS13/6, Subang Jaya Industrial Estate
47500 Subang Jaya, Selangor, Malaysia
Main Line: (+60) 3 5638 1818
Fax: (+60) 3 5638 1881
REVIEW OF THE POLICY
We will review the Policy from time to time and amend it where necessary to ensure continued compliance with the PDPA.
1st December 2016