Legal
Privacy policy
How MSDI collects, uses, protects and retains your personal data under the Personal Data Protection Act 2010.
Last updated 10 June 2026
This policy is a working draft prepared for review by legal counsel before launch. The practices described reflect how the platform is built today.
1. Who we are and what this policy covers
MSDI is a Malaysian training and credentialing provider. This policy explains how we handle personal data when you browse this website, enquire about a programme, enrol, study with us, apply for Recognition of Prior Experiential Learning (RPEL), or verify a credential. It is written to meet the requirements of the Personal Data Protection Act 2010 (PDPA) and applies to learners, enquirers, employer and sponsor contacts, trainers, agents and website visitors.
2. The personal data we collect
- Identity and contact data: name, email address, phone number, and, for enrolled learners, identification details required for accredited awards and credential issuance.
- Enquiry data: the topic, programme of interest and message you send through our contact form, together with your consent record.
- Learning records: enrolments, attendance, assessment outcomes, completion status and issued credentials.
- RPEL evidence: portfolios, employment history and supporting documents you submit for APEL assessment.
- Sponsorship data: employer details, HRD Corp registration information and levy claim documentation for sponsored training.
- Payment data: invoicing details and payment status. Card and banking credentials are processed by our licensed payment gateway and are not stored on MSDI systems.
- Technical data: device, browser and usage information needed to keep the platform secure and working, as described in the cookie policy.
3. How we collect it
Most personal data comes directly from you: forms you submit, documents you upload and programmes you enrol in. When your employer sponsors your training, we receive your enrolment details from your employer. Limited technical data is collected automatically when you use the site.
4. Why we process your personal data
- Responding to enquiries and processing applications and enrolments.
- Delivering training, assessment and learner support.
- Issuing credentials and operating the public credential verification service.
- Preparing and managing HRD Corp grant applications and claims for sponsors.
- Billing, payment processing and accounting in RM.
- Meeting accreditation, audit and statutory obligations.
- Service communications about your enrolment, such as intake reminders.
- Marketing communications, only where you have consented, and you may withdraw that consent at any time.
5. The PDPA principles we follow
We apply the seven PDPA principles: the General Principle (processing with consent and for lawful purposes), Notice and Choice (this policy and consent checkboxes at the point of collection), Disclosure (no use beyond the stated purposes), Security (safeguards described below), Retention (no longer than necessary), Data Integrity (keeping records accurate and current) and Access (your right to access and correct your data).
6. Who we share personal data with
We never sell personal data. We disclose it only to:
- Service providers: our cloud database and hosting provider (Supabase) and our payment gateway, each bound to process data only on our instructions.
- HRD Corp: attendance, assessment and invoice records required to process levy claims for sponsored learners.
- Your sponsor: enrolment and completion status for training your employer pays for.
- Accreditation and audit bodies: records required to maintain accreditation and statutory compliance.
- Authorities: where disclosure is required by Malaysian law.
The public verification page shows only the minimum needed to confirm a credential: holder name, award title and status. It never exposes contact details, assessment records or documents.
7. International transfers
Our cloud infrastructure may store data on servers located outside Malaysia. Where that happens, we use providers with recognised security certifications and contractual safeguards consistent with the PDPA.
8. How we keep it secure
Data is encrypted in transit, access is restricted by role with row-level security in the database, and administrative access follows least privilege. Public forms accept submissions only with your explicit consent recorded, and our systems cannot read contact submissions back out through the public website.
9. How long we keep it
We keep personal data only as long as needed for the purpose it was collected. Credential records are retained long term so that verification keeps working for the life of the award. Financial records are retained for the period required by Malaysian tax law. Enquiry records that do not become enrolments are deleted on a routine cycle.
10. Your rights
- Request access to the personal data we hold about you.
- Request correction of inaccurate or outdated data.
- Withdraw consent to processing, including marketing, at any time.
- Limit processing of your data where the PDPA provides for it.
To exercise any right, reach us through the contact page. We respond within 21 days as required by the PDPA. A nominal fee may apply to formal access requests, as the Act permits. If you are unsatisfied with our response, you may complain to the Personal Data Protection Department (JPDP) Malaysia.
11. Language
The PDPA requires privacy notices in both Bahasa Malaysia and English. The Bahasa Malaysia version of this notice is being prepared and will be published on this page; contact us if you need it sooner.
12. Children
Our services are designed for working adults. We do not knowingly collect personal data from anyone under 18 except where a sponsored programme expressly provides for it with guardian consent.
13. Changes to this policy
We update this policy when our practices change and revise the date at the top of the page. Material changes affecting your rights will be notified to enrolled learners by email.