Our
Policies
At ESG Malaysia, strong governance and ethical conduct are fundamental to how we operate and engage with our members, partners, and stakeholders. Our policies are designed to uphold transparency, accountability, inclusivity, and legal compliance, while reflecting Malaysia’s regulatory environment, cultural context, and international best practices.
Privacy Policy
Revision date: 15 May 2026
In accordance with Malaysia's Personal Data Protection Act (PDPA)
ESG Malaysia is committed to safeguarding personal data entrusted to the organisation. This Privacy Policy sets out the principles and procedures governing the collection, use, disclosure, retention, and protection of personal data. Personal data is processed lawfully, securely, and solely for legitimate organisational and operational purposes.
Purpose
This Privacy Policy sets out how ESG Malaysia collects, uses, discloses, stores, and protects personal data in the course of its operations. It reflects our commitment to transparency and accountability in all data handling activities.
Scope
This Policy applies to all personal data relating to members, partners, employees, contractors, event participants, and other stakeholders of ESG Malaysia — regardless of the form or medium in which the data is held.
Personal Data Management
ESG Malaysia processes personal data lawfully, fairly, and for legitimate purposes directly related to its activities. Personal data collected shall be adequate, relevant, and not excessive in relation to the purposes for which it is processed.
We do not use personal data for purposes that are incompatible with the original reason for which it was collected, without first obtaining the appropriate consent or lawful basis to do so.
Data Protection and Security
Reasonable technical and organisational measures are implemented to protect personal data against loss, misuse, unauthorised access, disclosure, alteration, or destruction. These measures are reviewed and updated periodically to reflect current best practices and applicable regulatory guidance.
Disclosure and Retention
Personal data shall not be disclosed to third parties without a lawful basis or the data subject's consent, except where disclosure is required or permitted by applicable law.
Personal data is retained only for as long as is necessary to fulfil its intended purpose or to comply with applicable legal or regulatory obligations, after which it is securely deleted or anonymised.
Rights of Data Subjects
In accordance with applicable laws and the PDPA, data subjects have the right to request access to their personal data, request correction of inaccurate or incomplete personal data, and request a limitation on the processing of their personal data where permitted by law.
To exercise any of these rights, please contact ESG Malaysia through the official channels listed on our website. We will respond to all requests within a reasonable timeframe.
