Personal Data Protection Policy
We, Nationwide Express Courier Services Berhad (Company No. 133096-M), and our subsidiaries ("Nationwide Express Group of Companies"), respect the privacy of all individuals with whom we have a contractual relationship. We are committed in protecting all Personal Data kept by us.
For this reason, Nationwide Express Group of Companies have adopted this Personal Data Protection Policy ("this Policy") in compliance with the Personal Data Protection Act 2010 of Malaysia ("PDP Act").
Definitions
-
"Consent"
the free, informed and prior agreement given by the Data Subject for the processing of his/her Personal Data.
-
"Personal Data"
any information relating to an identified or identifiable natural person. An identifiable person is someone who can be identified, directly or indirectly, in particular by reference to an identification number or the person's physical, physiological, mental, economic, cultural or social characteristics. Personal data may relate to any natural persons, including employees, customers, clients, investors, suppliers, contractors or other individuals.
-
"Processing"
collecting, recording, holding or storing the Personal Data or carrying out any operation or set of operations on the Personal Data, including:-
- the organization, adaptation or alteration of Personal Data;
- the retrieval, consultation or use of Personal Data;
- the disclosure of personal data by transmission, transfer, dissemination or otherwise making available; or
- the alignment, combination, correction, erasure or destruction of personal data;
-
"Data Subject"
a natural person, a private individual about whom information is collected, stored or processed.
-
"Minister"
refers to the Minister of Information, Communications & Culture.
-
"Sensitive Personal Data"
comprises information as to:-
- the physical or mental health or condition of Data Subject;
- the political opinions of Data Subject;
- the religious beliefs or other beliefs of a similar nature of Data Subject;
- the commission or alleged commission of any offence by Data Subject; or
- any other Personal Data determined by the Minister.
-
"Third parties"
a person or a company who is not a party to a contract or a transaction with Nationwide Express Group of Companies, but excluding Nationwide Express' subsidiaries, contractors, sub-contractors, authorized agents, vendors and professional advisors.
1. Scope
This Policy applies to all operations and business units of Nationwide Express Group of Companies. To the extent any operations or business unit of Nationwide Express Group of Companies already has a data protection policy in place; this Policy shall supersede and replace any such policy.2. Responsibility
Legal and Compliance Division of Nationwide Express Group of Companies is responsible for the administration of this Policy and monitoring enterprise wide compliance.3. Effective Date
This policy is effective as at 15 November 2013.4. Personal Data Protection Principles
4.1 | General Principle:- | ||
(a) | Nationwide Express Group of Companies will only process Personal Data in the manner set out below:- | ||
(i) | processing of Personal Data will be for a lawful purpose directly related to the activity of Nationwide Express Group of Companies; | ||
(ii) | processing of Personal Data must be necessary for or directly related to that purpose; | ||
(iii) | the Personal Data is adequate but not excessive in relation to that purpose; and | ||
(iv) | the Consent of the Data Subject must be obtained. | ||
(b) | Nationwide Express Group of Companies is not responsible to obtain the Consent of the Data Subject where the Processing Personal Data is necessary: - | ||
(i) | for the performance of a contract to which the Data Subject is a party; | ||
(ii) | at the request of the Data Subject with a view to entering into a contract with the Data Subject; | ||
(iii) | for compliance with any legal obligation to which Nationwide Express Group of Companies is subject, other than an obligation imposed by a contract; | ||
(iv) | to protect the vital interests of the Data Subject;. | ||
(v) | for the administration of justice; or | ||
(vi) | for the exercise of any functions conferred on any person by or under any law. | ||
(c) | Nationwide Express Group of Companies will only process Sensitive Personal Data:- | ||
(i) | with the consent of the Data Subject; | ||
(ii) |
where Processing is necessary for any of the following purposes:-
|
||
(d) | The Data Subject may withdraw his/her consent at any time and may attach any condition or limitation he/she believes to be appropriate. | ||
(e) | It is Nationwide Express Group of Companies' policy that Personal Data must be processed fairly and lawfully. Nationwide Express Group of Companies is responsible for collecting Personal Data only for specific, lawful, explicit and legitimate purposes, and for further processing of Personal Data consistent with those purposes. | ||
(f) | It is Nationwide Express Group of Companies' policy that Personal Data is adequate, relevant and not excessive to the purpose for which they are collected or further processed. Nationwide Express Group of Companies is responsible for making every reasonable effort to maintain such data accurately, provide reasonable means to correct, delete, or rectify any inaccurate data, and store such data for periods no longer than is necessary. | ||
4.2 | Notice and Choice Principle:- | ||
(a) | Nationwide Express Group of Companies will inform the Data Subject of the following by a written notice as soon as practical:- | ||
(i) | that the Personal Data is being processed; | ||
(ii) | a description of the Personal Data; | ||
(iii) | the purpose of the collection of the Personal Data; | ||
(iv) | the source of the Personal Data; | ||
(v) | the right of the Data Subject to request access and correction of the Personal Data; | ||
(vi) | classes of third parties to whom the Personal Data is / may be disclosed; | ||
(vii) | the choice and means of limiting the processing of Personal Data; | ||
(viii) | whether the supply of the Personal Data is obligatory or voluntary; and | ||
(ix) | the consequences of the Data Subject's failure to supply the Personal Data. | ||
4.3 | Disclosure Principle:- | ||
(a) | Nationwide Express Group of Companies will only disclose Personal Data:- | ||
(i) | to comply with any government agency notification requirements; and/or | ||
(ii) | for the purpose for which the Personal Data is processed. | ||
(b) | Nationwide Express Group of Companies will not disclose the Personal Data for other purpose and to third parties unless with the Consent of the Data Subject. | ||
4.4 | Security Principle:- | ||
(a) | Nationwide Express Group of Companies is responsible for taking prudent steps to safeguard the confidentiality and security of all Personal Data, including appropriate procedural, organizational and technical steps to protect personal data from accidental or unlawful destruction or accidental loss, alteration or disclosure. These steps include entering into written agreements with subcontractors who process Personal Data in accordance with Nationwide Express Group of Companies' instructions and incorporating Nationwide Express Group of Companies' own data protection standards as a minimum. | ||
(b) | Nationwide Express Group of Companies has reasonable security policies and procedures in place to protect personal information from unauthorized loss, misuse, alteration, or destruction. Despite Nationwide Express Group of Companies' best efforts, however, security cannot be absolutely guaranteed against all threats. To the best of Nationwide Express Group of Companies' ability, access to Data Subject's Personal Data is limited to those who have a need to know. Those individuals who have access to the Personal Data are required to maintain the confidentiality of such information. | ||
4.5 | Retention Principle:- | ||
(a) | Nationwide Express Group of Companies shall take all reasonable steps to ensure that:- | ||
(i) | Personal Data are retained only for so long as the information is necessary to comply with a Data Subject's request or until that Data Subject request that the information be deleted according to Nationwide Express Group of Companies' internal procedures; and | ||
(ii) | the Personal Data is destroyed or permanently deleted, where possible, after the purpose is served. | ||
4.6 | Data Integrity Principle:- | ||
Nationwide Express Group of Companies will ensure that the Personal Data is accurate, complete, not misleading and kept up-to-date, having regard to the purpose the data was collected and further processed. | |||
4.7 | Access Principle:- | ||
(a) | Nationwide Express Group of Companies recognizes the right of Data Subjects to obtain without constraint at reasonable intervals and without excessive delay or expense:- | ||
(i) | confirmation concerning whether Nationwide Express Group of Companies, any representative or agent is holding or processing Personal Data relating to him or her; | ||
(ii) | information on the purpose(s) of the processing, the categories of data concerned, and the recipients or categories of recipients; | ||
(iii) | information in an intelligible form concerning the data relating to him or her being processed and the source of such data; and | ||
(iv) | information, as appropriate, concerning the logic underlying the data processing. | ||
(b) | Further, Nationwide Express Group of Companies recognizes the Data Subject's right to require, as appropriate, the correction, erasure or blocking of data whenever the processing of such data does not comply with applicable laws and regulations. Nationwide Express Group of Companies will alert, to the extent practicable, third parties to whom the Personal Data has been disclosed of any such correction, erasure or blocking. | ||
(c) | A Data subject will be entitled to access his/her Personal Data that is being used by Nationwide Express Group of Companies by making a request in writing which will be complied within 21 days from date of receipt of such request. |
5. Data Collection, Transfer & Processing
5.1 | Nationwide Express Group of Companies is responsible for collecting, processing and transferring Personal Data in compliance with the PDP Act. | ||
5.2 | It is Nationwide Express Group of Companies' policy that except as allowed or required by the PDP Act, Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union memberships, health or sex life or alleged commission of any offense not be processed and the collection and storage of such Sensitive Personal Data be particularly safeguarded. The Processing of the Sensitive Personal Data by Nationwide Express Group of Companies will be in the manner set out in Clause 4.1(c) of this Policy. | ||
5.3 | For Personal Data obtained directly from the Data Subject, Nationwide Express Group of Companies is responsible for informing the Data Subject of the identity of those controlling the Personal Data, the purpose for which the Personal Data is being collected and processed and any further information the Data Subject may need for fair processing. This same standard applies to Personal Data not obtained directly from the Data Subject, except as allowed by law for statistical purposes. | ||
5.4 | Nationwide Express Group of Companies is responsible for informing the Data Subject prior to any initial transfer or Processing of Personal Data for direct marketing purposes and, upon request, for blocking such action. | ||
5.5 | It is Nationwide Express Group of Companies' policy not to transfer Personal Data to any entity, individual, or organization, particularly entities within third countries without adequate data protections, which does not meet the standards established by this policy without ensuring that:- | ||
(a) | the Data Subject has given his/her unambiguous consent; | ||
(b) | the transfers are needed for the performance of a contract between the Data Subject and the third party or to implement a pre-contractual commitment made at the request of the Data Subject; | ||
(c) | the transfers are needed for the conclusion or performance of a contract concluded in the interest of the Data Subject with a third party; | ||
(d) | the transfers are needed to protect the vital interests of the Data Subject; or | ||
(e) | the transfers are made from a register established pursuant to laws and regulations as being open for consultation by members of the general public or by any person who can demonstrate a legitimate interest./td> |
6. Use of Cookies And Web Beacons
6.1 | From time to time when a Data Subject visit Nationwide Express Group of Companies' website, information may be placed on his/her computer to allow Nationwide Express Group of Companies to recognize Data Subject's computer in the form of a text file known as a "cookie". Nationwide Express Group of Companies' use of cookies is intended to provide benefits Data Subject, such as eliminating the need for Data Subject to enter his/her password frequently during a session. Cookies are also used for website traffic analysis and anonymous demographic profiling so that Nationwide Express Group of Companies may improve its services. | ||
6.2 | Nationwide Express Group of Companies may use so called web beacons (or "pixel tags") in connection with some websites. However, Nationwide Express Group of Companies do not use them to identify individual users personally. Web beacons are typically graphic images that are placed on a website and they are used to count visitors to a website and/or to access certain cookies. This information is used to improve Nationwide Express Group of Companies' services. Web beacons do not typically collect any other information than what Data Subject browser provides Nationwide Express Group of Companies with as a standard part of any internet communication. If Data Subject turn off cookies, the web beacon will no longer be able to track Data Subject specific activity. The web beacon may, however, continue to collect information of visits from Data Subject's IP-address, but such information will no longer be unique. | ||
6.3 | If Data Subject does not wish to receive cookies, or wants to be notified before he/she is placed, Data Subject may set his/her web browser to do so, if his/her browser so permits. Once the cookies are turned off, Data Subject may not be able to view certain parts of Nationwide Express Group of Companies' site that may enhance Data Subject's visit. Some of Nationwide Express Group of Companies' business partners whose content is linked to or from Nationwide Express Group of Companies' website may also use cookies or web beacons. However, Nationwide Express Group of Companies has no access to or control over these cookies. |
- Kementerian Komunikasi dan Multimedia (KKMM)
- Jabatan Perlindungan Data Peribadi
* Nationwide Express Group of Companies is committed in protecting the Personal Data of any Data Subject. If you have questions or comments about Nationwide Express Group of Companies' administration of Personal Data, please contact us at pdpa@nationwide2u.com . You may also use this address to communicate any concerns you may have regarding compliance with this Policy.