NGO Reg PPM-001-14-02011979
1124
Legal · Compliance

Privacy Policy

Effective date: 1 January 2026 · EWRF Malaysia (Reg. PPM-001-14-02011979)

1. Introduction

The Educational, Welfare and Research Foundation Malaysia ("EWRF", "we", "us") is committed to protecting the personal data of donors, volunteers, beneficiaries, programme participants, and every visitor to this website. This Privacy Policy sets out how we collect, store, use and disclose personal data in compliance with the Personal Data Protection Act 2010 (Act 709) of Malaysia ("PDPA"), relevant provisions of the Communications and Multimedia Act 1998, the Computer Crimes Act 1997, and — for our international donors — the EU General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, and equivalent standards under Singapore's PDPA 2012.

2. Data We Collect

  • Identity data: name, IC/passport (for donation receipts under Section 44(6)), age, gender.
  • Contact data: address, email, phone, WhatsApp number.
  • Financial data: donation amount, payment method reference (no full card numbers are stored — payments handled by Stripe/DuitNow/iPay88).
  • Volunteer & programme data: qualifications, availability, health information (only when relevant to programme participation).
  • Technical data: IP address, browser type, device type, referring URL, pages visited, cookies (see §7).

3. Lawful Basis & Purpose

We process personal data on one or more of these lawful bases:

  • Consent — freely given, specific, informed, unambiguous (e.g. newsletter sign-up).
  • Contract — to fulfil donation receipts, volunteer agreements, event registration.
  • Legal obligation — LHDN tax-exemption reporting under Section 44(6), Registrar of Societies filings.
  • Legitimate interest — impact reporting, fraud prevention, cybersecurity monitoring.

4. Your Rights (PDPA & GDPR)

You have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Withdraw consent at any time
  • Object to direct marketing communications
  • Request deletion (subject to retention obligations under LHDN / ROS regulations)
  • Data portability (GDPR / UK DPA donors)
  • Lodge a complaint with Malaysia's Department of Personal Data Protection (JPDP) or your local supervisory authority

5. Data Sharing & International Transfers

We do not sell your data. We share only what's necessary with:

  • Payment processors (Stripe Inc. / iPay88 Sdn Bhd / DuitNow) — for donation processing.
  • Cloud infrastructure providers (bounded by data processing agreements with equivalent safeguards).
  • Regulatory bodies where required by Malaysian law (LHDN, ROS, PDRM cybercrime unit).
  • Programme partners — only for joint programmes and only with prior consent.

International transfers to non-adequate jurisdictions occur only with Standard Contractual Clauses (SCCs) or your explicit consent, per PDPA §129 and GDPR Chapter V.

6. Cybersecurity & Data Retention

We employ industry-standard safeguards — TLS 1.3 encryption in transit, encrypted-at-rest databases, principle of least privilege, and periodic access reviews — in line with ISO/IEC 27001:2022 guidance and Malaysia's Cyber Security Act 2024. Personal data is retained only as long as necessary for the purpose collected or as required by law (donation records: 7 years per LHDN; volunteer records: 5 years post-service). Any confirmed data breach affecting personal data will be notified to affected individuals and the relevant authority within 72 hours, in line with GDPR Article 33 and PDPA best practice.

7. Cookies & Analytics

We use essential cookies to run the site (session, CSRF tokens) and privacy-friendly analytics to measure traffic. We do not use cross-site advertising trackers. You may block cookies in your browser settings — the donation flow may not function without essential cookies.

8. Contact & Complaints

Send data access, correction, or deletion requests to admin@ewrf.org.my or by post to: EWRF Malaysia, 4B, Persiaran Zaaba, Taman Tun Dr Ismail, 60000 Kuala Lumpur. We will respond within 21 days. Unresolved complaints may be escalated to the Department of Personal Data Protection Malaysia (JPDP).

This policy is reviewed annually. Substantial changes will be communicated via the website and, where applicable, to affected data subjects directly.

See also: Terms & Conditions