This Data Processing Agreement ("DPA") is between ("Controller") and REDTEAM ("Processor") and forms part of the Master Service Agreement for the engagement.
In performing the services, the Processor may process personal data on behalf of the Controller. This DPA sets out the terms governing that processing, in compliance with the Personal Data Protection Act 2010 (Malaysia) ("PDPA") and any successor legislation.
| Field | Details |
|---|---|
| Purpose | |
| Categories of data | |
| Data subjects | |
| Retention |
The Processor maintains, at minimum: access controls (least privilege); encryption in transit and at rest where feasible; secure storage and transmission of evidence; logging of access to personal data; and a process for testing and evaluating the effectiveness of security measures.
The Processor assists the Controller, to the extent required by law and using commercially reasonable efforts, in responding to data subject requests under the PDPA, including access, correction, and complaints. The Processor notifies the Controller if it receives a direct request from a data subject concerning the Controller's data.
The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting Controller data, providing sufficient detail for the Controller to assess the breach and meet its legal notification obligations. The Processor cooperates with the Controller's investigation and remediation.
Personal data is not transferred outside Malaysia without the Controller's written consent or a lawful basis under the PDPA. Where transfer occurs, appropriate safeguards are applied and documented.
Personal data is retained only for the period necessary for the services and the agreed retention period, then securely deleted or returned to the Controller at its direction, unless retention is required by law.
The Controller may, on reasonable notice and no more than once per year (or as agreed), audit the Processor's compliance with this DPA through documented assessments, information requests, or an independent auditor bound by confidentiality.
Liability under this DPA follows the liability provisions of the MSA. Each Party remains liable for its own breaches of the PDPA.
This DPA takes effect on the Effective Date and continues while the Processor processes personal data on behalf of the Controller, surviving termination of the MSA until all data is returned or destroyed.
This DPA is governed by the laws of Malaysia.
COMPANY STAMP