Privacy Policy

This is OSBR's organisation-level commitment on personal data — the promise, made to the people whose data we hold, that stands behind everything else in this handbook. It is the counterpart of the Security Policy (which protects information assets) and the SHEQ Policy (which commits us on safety, health, environment, and quality): where those govern what we protect, this governs the trust of the person the data describes. It is a notice, not an engineering spec — the concrete technical controls that satisfy these commitments live in the Data Protection standard, and the legal judgement calls behind them in Legal Compliance. This document is the promise those pages keep.

OSBR is a Malaysian company, so our home law is Malaysia's Personal Data Protection Act 2010 (PDPA). Because we work with a Japanese parent studio and with clients elsewhere, Japan's APPI and, where a client brings us within their reach, the EU's GDPR and comparable US regimes also apply. These regimes rest on the same core duties, so the commitments below honour all of them.

Personal data is not ours. It belongs to the person it describes, and they lend it to us for a purpose. Be Nice: a person who can see what we hold, correct it, and ask us to stop is someone we have treated as a partner, not a resource. Be Kind: behind every record is a human being who trusted someone with it, and honouring that trust is the whole point. Be Strong: do the unglamorous work of collecting less, deleting on time, and telling a client plainly when a use of data exceeds what the person consented to — even when more data would be convenient.

How to read this policy

1. Goal

Every protection in this handbook exists so that OSBR can be trusted with a loan of personal data: that we take only what the purpose needs, use it only for what we said, guard it as if it were our own most sensitive secret, and hand it back, correct it, or stop using it the moment the person asks and the law allows.

OSBR commits to handling personal data lawfully and fairly: to obtain it only within the scope necessary for clearly stated business purposes and with consent; to give clear notice and a real choice; to use it only within those stated purposes, re-obtaining consent before exceeding them; to restrict disclosure to third parties without consent; to protect it with organizational, human, physical, and technical safeguards; to keep it accurate and no longer than needed; to supervise anyone we entrust it to; and to honour a person's rights of access, correction, and withdrawal as the law requires.

These commitments are the seven Personal Data Protection Principles of Malaysia's PDPAGeneral, Notice and Choice, Disclosure, Security, Retention, Data Integrity, and Access — as amended by the Personal Data Protection (Amendment) Act 2024. The same duties are named in Japan's 個人情報保護法 (APPI), the EU's GDPR, the OECD Privacy Guidelines, and the privacy-information-management system codified in ISO/IEC 27701. OSBR adopts them as commitments, not as a compliance chore.

2. Responsibility

Role Responsibility
OSBR (as a company) Owns this commitment. Provides the policies, training, and controls that make it real, and answers for it when it fails. Appoints a Data Protection Officer where the PDPA requires one.
Data Protection Officer (where required) The person accountable for personal-data compliance — that purposes are stated, consent is recorded, retention is bounded, breaches are notified, and access/correction/withdrawal requests are answered in time. Under the amended PDPA a DPO must be appointed above the prescribed thresholds and be ordinarily resident in Malaysia.
Every developer / collaborator Handles personal data only within the stated purpose and their granted access; raises the moment a design or request would collect more, use it differently, or send it somewhere new.
Contractors & data processors Bound by contract to protect personal data to the same standard, and supervised by OSBR for the life of the engagement (§3-5).
Client (often the data controller) Confirms the business facts that set the purpose and lawful basis, and co-owns the duties that are legally theirs as the controller.

Whether OSBR is the data controller (we set the purpose) or a data processor (we build and run it for a client who is the controller) depends on the engagement — the amended PDPA now places obligations directly on processors too, and we honour the same principles in either role. Genuinely legal judgement calls (does a given use exceed the stated purpose? is a transfer a "disclosure"?) are escalated per Legal Compliance; this policy makes sure the question gets asked in time.

3. Practices

Named, established practice, right-sized for an SME. The principles are universal; the ceremony is not — adopt the discipline of the reference regimes without importing a large enterprise's headcount.

3-1. Notice and choice: obtain only what the purpose needs, lawfully and fairly

We do not collect personal data because it might be useful someday. Collection is tied to a stated purpose and kept to the minimum that purpose requires — the PDPA's General and Notice and Choice principles, echoed by the APPI's duty to specify the purpose of use (利用目的), GDPR Art. 5(1)(c) data minimisation, and the OECD Collection Limitation principle.

The purpose stated at collection is a boundary, not a formality. This is purpose limitation — the PDPA General Principle, the APPI's rule that personal data may not be handled beyond the specified purpose without consent, GDPR Art. 5(1)(b), and the OECD Purpose Specification and Use Limitation principles.

Handing personal data to someone outside OSBR is the moment of highest risk and highest duty. The PDPA Disclosure Principle, the APPI's third-party-provision rule (第三者提供), and the GDPR's transfer safeguards all start from restriction.

3-4. Security: protect it with organizational, human, physical, and technical safeguards

OSBR commits to the four categories of safeguard that satisfy the PDPA Security Principle, the APPI's necessary-and-appropriate measures (安全管理措置), the controls of ISO/IEC 27701 / 27001, and the GDPR's Art. 32 security-of-processing duty:

Safeguard What OSBR commits to Where it is specified
Organizational A named owner per engagement, defined handling rules, access review, and an incident response path. Security Policy
Human Security and privacy training before joining a project; a culture where raising a concern is expected, not punished. Security Policy
Physical Device encryption, auto-lock, no work in public spaces, no uncontrolled removable media, remote-wipe. Security Policy
Technical Least-privilege access, MFA/passkeys, no long-lived credentials, encryption in transit and at rest, logging and monitoring. Data Protection

Breach notification. Under the amended PDPA, OSBR MUST notify the Personal Data Protection Commissioner of a personal-data breach as soon as practicable, and notify affected individuals where the breach is likely to cause significant harm — the same duty the APPI places toward the PPC and the GDPR toward the supervisory authority. The operational flow is the Incident Management standard.

3-5. Supervise everyone we entrust personal data to

When OSBR entrusts personal data to a data processor to carry out the stated purpose, the duty of care does not transfer with the data — it stays with us. This is part of the PDPA Security Principle (and the amended Act's direct obligations on processors), the APPI's duty to supervise a trustee (委託先の監督), and the GDPR's Art. 28 processor requirements.

3-6. Retention, integrity, and access: keep it right, no longer than needed, and honour the person's rights

Three PDPA principles meet here — Retention, Data Integrity, and Access — and this is where all of the above becomes real to the person.

4. Rules Summary (MUST / SHOULD)

6. References

OSBR is a Malaysian company serving clients worldwide. The commitments above rest on the duties common to the data-protection regimes below.

Malaysia

Japan

European Union

United States

International frameworks