Legal

Privacy policy

How MSDI collects, uses, discloses, stores and protects your personal data under Malaysia's Personal Data Protection Act 2010.

Effective 24 August 2026. Last updated 24 August 2026.

In short

MSDI collects the personal data needed to enrol you in a programme, assess you, issue your certificate and support a HRD Corp claim. We do not sell or rent personal data. We share it only with the bodies that fund, examine or accredit your programme, and with service providers acting on our instructions. You may access, correct or ask us to stop using your data at any time by emailing msdinstitute.my@gmail.com.

1. Introduction

Malaysia Strategic Development Institute (“MSDI”, “we”, “us”, “our”) is committed to protecting the privacy and security of your personal data.

This policy explains how we handle personal data when you:

  • visit or use our website at msdi.edu.my (the “Website”);
  • submit an enquiry, registration or booking form;
  • make a payment through our online payment facility;
  • create or access an account on our learner portal or learning management system (the “Portal”);
  • subscribe to our newsletter, email updates or WhatsApp broadcast list;
  • attend, enrol in or complete any of our training programmes, courses, certifications or assessments; or
  • otherwise deal or communicate with us.

This policy is issued in accordance with the Personal Data Protection Act 2010 (the “PDPA”), as amended by the Personal Data Protection (Amendment) Act 2024, and the guidelines and regulations issued by the Personal Data Protection Commissioner of Malaysia.

By using the Website, submitting your personal data to us, or enrolling in any of our programmes, you acknowledge that you have read and understood this policy.

2. Who we are

For the purposes of the PDPA, the data controller is:

Details of our Data Protection Officer are set out in Section 16.

3. What we mean by personal data

Personal data means any information that relates to you and can identify you, directly or indirectly, and which is processed in connection with a commercial transaction.

Sensitive personal data means personal data consisting of information as to your physical or mental health or condition, political opinions, religious beliefs or other beliefs of a similar nature, biometric data, the commission or alleged commission of any offence, or any other data as may be determined by the Minister.

4. Personal data we collect

4.1 Information you provide directly

Enquiry and registration data. Full name as per NRIC or passport, NRIC or passport number, date of birth, gender, nationality, email address, mobile number, correspondence address, employer name, job title, department, employer address, employer HRD Corp registration details where applicable, academic and professional qualifications, work experience, CV, the programmes you are interested in, preferred dates and delivery mode, and emergency contact details where a physical programme requires them.

Payment data. Billing name, billing address, email and contact number, invoice, purchase order and local order (LO/PO) details, transaction reference numbers, payment method and payment status, and bank or company details for refunds and reconciliation.

We do not collect or store your full card number, CVV or online banking credentials. All card and banking details are entered directly into the systems of our appointed payment gateway provider.

Portal and learner account data. Username, email address and encrypted password, any profile information you choose to add, course enrolment records, attendance, progress and completion status, assignment and assessment submissions, marks, results and feedback, certificates, credentials, digital badges and post-nominal awards, and support tickets and correspondence with our team.

Marketing subscription data. Name, email address and mobile number, your consent preferences and subscription status, and the interests or programme categories you select.

Other information you may provide. Photographs or video recordings taken during training sessions where you have been notified, feedback forms, surveys, testimonials and course evaluations, and any information you volunteer in emails, calls or WhatsApp messages.

4.2 Sensitive personal data

In limited circumstances we may collect sensitive personal data, for example:

  • Health information, where you disclose dietary requirements, allergies, medical conditions, mobility needs or accessibility requirements so that we can make reasonable arrangements for your participation;
  • Religious observance information, where it is relevant to prayer arrangements or meal provision at a venue.

We will only process sensitive personal data with your explicit consent, or where the processing is otherwise permitted under the PDPA. You are not obliged to provide this information, but we may be unable to accommodate specific requirements without it.

4.3 Information collected automatically

When you visit the Website, our servers and hosting provider may automatically record limited technical information: IP address and the approximate location derived from it, browser type and version, device type and operating system, the date and time of access, pages requested and referring URL, and error and security event logs. This information is used for security, fraud prevention, troubleshooting and keeping the Website available.

4.4 Information from third parties

We may receive your personal data from:

  • your employer or sponsoring organisation, where they register you for a programme or submit a training grant application on your behalf;
  • HRD Corp and other funding or government bodies, in connection with grant approvals, claims and verification;
  • awarding and certification bodies, in connection with registration, assessment results and credential issuance;
  • referrals, where an existing participant or partner introduces you to us with your knowledge.

5. Why we process your personal data

Programme delivery and administration. Responding to enquiries and providing quotations, processing registrations, enrolments, deferments and cancellations, verifying eligibility for a programme, exemption or funded initiative, managing attendance, class logistics, venue, materials and catering, conducting assessments and issuing results, certificates and credentials, and providing learner support and handling complaints.

Payment, funding and compliance. Issuing invoices and receipts, processing payments and refunds, preparing and submitting HRD Corp grant applications and claim documents, meeting the reporting, audit and verification requirements of the Department of Skills Development (JPK), HRD Corp and other regulators, maintaining accounting records and complying with tax and statutory obligations, and detecting and preventing fraud, misuse or non-payment.

Certification and accreditation. Registering candidates with awarding bodies and examination partners, submitting assessment evidence, portfolios and results for external verification, arranging membership, designations and post-nominal awards, and maintaining a register of certified individuals so credentials can be verified on request.

Communication and marketing. Sending programme confirmations, joining instructions, reminders and administrative notices, sending newsletters, course announcements, promotions and event invitations where you have consented, sending WhatsApp broadcast messages where you have opted in, and conducting satisfaction surveys and collecting feedback.

Improvement, security and legal. Improving our programmes, curriculum, service quality and Website, producing internal, anonymised or aggregated statistics and reports, protecting the security and integrity of our systems and records, and establishing, exercising or defending legal claims and complying with any court order, law or lawful request by a regulator.

5.1 Legal basis

We process personal data on the basis of:

  • your consent, which you may withdraw at any time;
  • the performance of a contract with you, or steps taken at your request before entering into a contract;
  • compliance with a legal or regulatory obligation to which we are subject;
  • the legitimate interests pursued by us or a third party, where these are not overridden by your interests or fundamental rights.

5.2 If you do not provide personal data

Certain personal data is mandatory. If you do not provide it, we may be unable to:

  • register you for a programme or examination;
  • process a payment, invoice or refund;
  • submit or support a HRD Corp grant or claim application;
  • issue a certificate, credential or professional designation;
  • verify your identity for assessment or fraud prevention purposes.

Mandatory fields are marked on our forms.

6. Disclosure of your personal data

We do not sell, rent or trade your personal data. We may disclose it to the following recipients, and only so far as is necessary for the purposes set out in Section 5.

Government, regulatory and funding bodies. The Human Resource Development Corporation (HRD Corp) for grant applications, claims, attendance verification and audits; Jabatan Pembangunan Kemahiran (JPK) and the Ministry of Human Resources for accreditation, certification and audit purposes; and any other government agency, statutory body, ministry or regulator where required by law, or where you have applied for a funded or subsidised programme.

Awarding, certification and examination bodies. The Chartered Management Institute (CMI), United Kingdom, for registration, assessment, membership and chartered designation purposes; Pearson VUE and Certiport for examination scheduling, delivery, identity verification and results; and other awarding bodies, professional institutes or accreditation partners associated with the programme you enrol in.

Payment and finance providers. Our appointed payment gateway provider for card and online banking transactions, our banks for collection, reconciliation and refunds, and our accountants, auditors and tax agents for bookkeeping, audit and statutory filing.

Service providers acting on our instructions. Website hosting, cloud storage, email and communication platforms; learning management system and examination platform providers; customer relationship management, e-invoicing and marketing platform providers; appointed trainers, assessors, verifiers and moderators bound by confidentiality obligations; and venue operators, where required for access control, catering or safety.

Others. Your employer or sponsoring organisation, where they have registered or funded your participation, limited to attendance, progress, results and certification status; professional advisers such as lawyers and insurers where necessary; and any party to whom we are required or permitted to disclose by law, court order or regulatory request.

All service providers are engaged under written terms requiring them to process personal data only on our instructions and to apply appropriate security safeguards.

7. Transfers outside Malaysia

Some of the recipients listed in Section 6 are located outside Malaysia:

  • CMI (United Kingdom), for candidate registration, assessment and chartered status;
  • Pearson VUE and Certiport, whose systems and support operations may be located in the United States or elsewhere;
  • certain cloud hosting, email and software providers whose servers may be located outside Malaysia.

Where we transfer personal data outside Malaysia, we do so in accordance with the cross-border transfer requirements of the PDPA. We transfer only where the receiving jurisdiction has in force a law substantially similar to the PDPA or ensures an adequate level of protection at least equivalent to it; or you have consented to the transfer; or the transfer is necessary for the performance of a contract with you, or for the conclusion or performance of a contract concluded in your interest; or another exception under the PDPA applies. Where required, we assess the risks of the transfer and put contractual safeguards in place with the recipient.

8. Retention of personal data

We keep personal data only for as long as necessary to fulfil the purposes it was collected for, or as required by law.

CategoryRetention period
Enquiries that do not result in enrolmentUp to 24 months from last contact
Enrolment, attendance and assessment recordsAt least 7 years from programme completion, or longer where an awarding body or regulator requires it
Certification and credential recordsKept on a permanent register so your credential can be verified for life
HRD Corp grant and claim documentationAt least 7 years, in line with HRD Corp and audit requirements
Accounting, invoicing and tax recordsAt least 7 years, in line with the Income Tax Act 1967 and the Companies Act 2016
Portal account and login recordsFor the life of the account, plus up to 24 months after deactivation
Marketing subscription recordsUntil you withdraw consent, plus a suppression record to honour your opt-out
Server and security logsUp to 12 months

When personal data is no longer required, we take reasonable steps to securely destroy, delete or permanently anonymise it.

9. Security of your personal data

We apply practical and appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, modification, disclosure or destruction. These include encryption of the Website using HTTPS and TLS, password hashing and access controls on the Portal, role-based access so staff reach only the data their role requires, confidentiality obligations in employment and trainer contracts, restricted access to physical records and secure disposal of hard copies, regular software updates, backups and access reviews, and due diligence and written terms with service providers.

No method of transmission or storage is completely secure. While we take reasonable steps to protect your personal data, we cannot guarantee absolute security. You are responsible for keeping your Portal password confidential and for telling us immediately if you suspect unauthorised access to your account.

10. Personal data breach notification

If we have reason to believe a personal data breach has occurred, we will:

  1. assess and contain the breach without undue delay;
  2. notify the Personal Data Protection Commissioner as soon as practicable, and in any event within the timeframe prescribed under the PDPA; and
  3. notify affected individuals without unnecessary delay where the breach is likely to cause them significant harm, together with information on the nature of the breach and the steps they can take.

We keep internal records of personal data breaches and the remedial action taken.

11. Your rights

Subject to the PDPA and any applicable exemptions, you have the right to:

  • access the personal data we hold about you, and be told how it is being processed;
  • correct personal data that is inaccurate, incomplete, misleading or out of date;
  • withdraw consent to the processing of your personal data at any time;
  • limit processing, including requiring us to stop using your personal data for direct marketing;
  • prevent processing that is likely to cause you unwarranted substantial damage or distress;
  • data portability, meaning you may ask us to transmit your personal data directly to another data controller where that is technically feasible and the data formats are compatible.

How to exercise your rights

Send your request to our Data Protection Officer using the details in Section 16, including your full name and contact details, the nature of your request, enough detail for us to locate the relevant records, and a copy of your NRIC or passport so we can verify your identity.

We will respond within 21 days. If we need longer, we will tell you in writing before that period expires and respond within a further period as permitted under the PDPA. A prescribed fee may apply to a data access request.

Withdrawing consent or asking us to delete data may affect our ability to deliver a programme, issue a certificate or process a funding claim. We may also be required to keep certain records to meet legal, audit or accreditation obligations.

12. Direct marketing and how to opt out

We will only send you marketing communications where you have opted in, or where you are an existing customer and the communication relates to similar programmes.

Every marketing email includes an unsubscribe link. For WhatsApp broadcasts you may reply STOP, or message us directly to be removed. You may also email us at any time to opt out of all direct marketing.

Opting out of marketing does not stop transactional and administrative messages such as booking confirmations, joining instructions, invoices, results and certificate notifications.

13. Cookies and tracking

The Website uses only strictly necessary cookies required for the Website and Portal to function: session cookies that keep you signed in to the Portal, security cookies that protect against cross-site request forgery, and cookies that remember your form inputs and preferences during a session.

We do not currently use analytics, advertising, retargeting or third-party tracking cookies on the Website. If that changes, we will update this policy and, where required, ask for your consent through a cookie notice before any non-essential cookies are set.

You can control or delete cookies through your browser settings. Disabling strictly necessary cookies may stop parts of the Website or Portal from working. See our cookie policy for more detail.

14. Minors

Some of our programmes are open to participants below the age of 18.

Where a participant is under 18, we require the consent of a parent or legal guardian before collecting or processing their personal data, and registration forms for those programmes include a parent or guardian consent section.

We do not knowingly collect personal data from a person under 18 through the Website without that consent. If you believe we have, please contact our Data Protection Officer and we will take steps to delete it.

15. Third-party websites and platforms

The Website may link to third-party websites, social media pages, payment pages, examination platforms and awarding body portals. This policy does not apply to them. We are not responsible for their content or privacy practices, and we encourage you to read their privacy policies before giving them personal data.

16. Data Protection Officer

We have appointed a Data Protection Officer responsible for overseeing our compliance with the PDPA and for handling your queries and requests. You can reach them at:

  • The Data Protection Officer
  • Email: msdinstitute.my@gmail.com
  • Telephone: 012-879 3311
  • Address: Wisma MSDI, 22 Jalan Empayar Kawasan 17, KU/1, 41150 Klang, Selangor, marked “Attention: Data Protection Officer”

17. Complaints

If you are not satisfied with how we have handled your personal data or your request, please contact our Data Protection Officer first so that we have the chance to put it right.

You also have the right to complain to:

Jabatan Perlindungan Data Peribadi (Department of Personal Data Protection), Ministry of Digital, Malaysia. www.pdp.gov.my

18. Changes to this policy

We may update this policy from time to time to reflect changes in our practices, technology, or legal and regulatory requirements. The revised version will be posted on this page with an updated date.

Where the changes are material, we will take reasonable steps to notify you, for example by email or by a notice on the Website. Continuing to use the Website or our services after the changes take effect means you accept the revised policy.

19. Language

This policy is issued in both Bahasa Malaysia and English in accordance with the PDPA. If there is any inconsistency or conflict between the two versions, the Bahasa Malaysia version prevails.

20. Contact us

For any question about this policy or how we handle your personal data:

  • Malaysia Strategic Development Institute (MSDI)
  • Wisma MSDI, 22 Jalan Empayar Kawasan 17, KU/1, 41150 Klang, Selangor
  • Email: msdinstitute.my@gmail.com
  • Telephone: 012-879 3311
  • Website: msdi.edu.my

See also our terms of service, cookie policy and refund policy.