Data Privacy & PDPA Compliance

Malaysia: Personal Data Protection Act 2010 (Act 709)

Select country

Review how this page describes privacy-law coverage for your school jurisdiction.

Last reviewed: March 2026

Our Commitment

River SIS processes personal data for school management operations including student administration, staff records, and school activities. For Malaysia schools, this page summarises how our operational privacy practices align to the Personal Data Protection Act 2010 (Act 709), which regulates personal data processed in commercial transactions, and to its seven Personal Data Protection Principles: General, Notice and Choice, Disclosure, Security, Retention, Data Integrity, and Access.


Data Classification
ClassificationDescriptionExamples
PIIPersonally identifiable informationDatabase records, user profile images
ConfidentialSensitive operational dataApp configuration, environment secrets
AuditAccess and activity recordsDatabase audit logs, admin activity
InternalNon-personal operational dataApplication logs, container images

Security Measures
Encryption at Rest
  • DocumentDB: KMS encryption at cluster level
  • S3 buckets: AWS KMS server-side encryption
  • CloudWatch Log Groups: KMS encryption
  • Container registry (ECR): KMS encryption
Encryption in Transit
  • HTTPS only; TLS 1.2 minimum, TLS 1.3 preferred
  • Application to database: TLS enforced, plaintext rejected

Data Retention
Data CategoryStorageRetentionDeletion
Customer images (current)S3IndefiniteManual on request
Customer images (superseded)S330 daysAutomatic (S3 Lifecycle)
Database backupsDocumentDB30 daysAutomatic
Application logsCloudWatch7 daysAutomatic
Database audit logsCloudWatch90 daysAutomatic

Your Data Rights
Access Requests

Malaysia's PDPA includes an access principle and supports requests to access personal data and correct inaccuracies, subject to applicable exceptions. We support verified access requests through customer administrators and internal review controls.

Retention and Deletion

Malaysia's PDPA emphasises retention limitation rather than a broad standalone erasure right. We therefore assess deletion requests against the purpose of processing, customer requirements, legal obligations, and retention controls already applied to the service.

Data Integrity and Correction

The Data Integrity Principle requires reasonable steps to ensure personal data is accurate, complete, not misleading, and kept up to date where necessary. Customer-facing correction workflows and administrative review support this obligation.

Notice, Choice, and Exports

Malaysia's PDPA is principle-based and does not mirror every portability right found in some other regimes. Where appropriate and technically feasible, we can support structured exports while focusing primarily on notice, disclosure control, and access rights under Act 709.

Disclosure, Security, and Objections

For Malaysia coverage, we focus on disclosure controls, security safeguards, retention discipline, and handling verified requests or objections through the customer relationship and applicable legal requirements.


Governance Schedule
Monthly

Review data classification, retention settings, access permissions, and operational changes that may affect privacy risk.

Quarterly

Conduct least-privilege access reviews, verify key security controls, and document material changes to processing activities or vendor arrangements.

Annually

Perform a fuller review of data inventories, test data-rights handling and deletion workflows, review incident-response readiness, and update this document.


Exercise Your Data Rights

To exercise any of your data rights or for privacy-related enquiries, please contact SchoolHero.io OÜ at info@riversis.com or by post at Harju maakond, Kuusalu vald, Pudisoo küla, Männimäe, 74626, Estonia.