REDTEAM
RT-DPA-- ·
Data Processing Agreement

Personal Data Processing (PDPA)

Client: Effective: Confidential

1 · Parties

This Data Processing Agreement ("DPA") is between ("Controller") and REDTEAM ("Processor") and forms part of the Master Service Agreement for the engagement.

2 · Background

In performing the services, the Processor may process personal data on behalf of the Controller. This DPA sets out the terms governing that processing, in compliance with the Personal Data Protection Act 2010 (Malaysia) ("PDPA") and any successor legislation.

3 · Definitions

4 · Processing Details

FieldDetails
Purpose 
Categories of data 
Data subjects 
Retention 

5 · Controller Obligations

6 · Processor Obligations

7 · Security Measures

The Processor maintains, at minimum: access controls (least privilege); encryption in transit and at rest where feasible; secure storage and transmission of evidence; logging of access to personal data; and a process for testing and evaluating the effectiveness of security measures.

8 · Sub-Processing

9 · Data Subject Requests

The Processor assists the Controller, to the extent required by law and using commercially reasonable efforts, in responding to data subject requests under the PDPA, including access, correction, and complaints. The Processor notifies the Controller if it receives a direct request from a data subject concerning the Controller's data.

10 · Personal Data Breach

The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting Controller data, providing sufficient detail for the Controller to assess the breach and meet its legal notification obligations. The Processor cooperates with the Controller's investigation and remediation.

11 · Cross-Border Transfer

Personal data is not transferred outside Malaysia without the Controller's written consent or a lawful basis under the PDPA. Where transfer occurs, appropriate safeguards are applied and documented.

12 · Retention & Deletion

Personal data is retained only for the period necessary for the services and the agreed retention period, then securely deleted or returned to the Controller at its direction, unless retention is required by law.

13 · Audit

The Controller may, on reasonable notice and no more than once per year (or as agreed), audit the Processor's compliance with this DPA through documented assessments, information requests, or an independent auditor bound by confidentiality.

14 · Liability

Liability under this DPA follows the liability provisions of the MSA. Each Party remains liable for its own breaches of the PDPA.

15 · Term

This DPA takes effect on the Effective Date and continues while the Processor processes personal data on behalf of the Controller, surviving termination of the MSA until all data is returned or destroyed.

16 · Governing Law

This DPA is governed by the laws of Malaysia.

For the Controller (Client)
Name: ______________________
Title: ______________________
Date: ______________________
For REDTEAM (Processor)
Name: ______________________
Title: ______________________
Date: ______________________

COMPANY STAMP

REDTEAM · redteam.alesa.my · redteam@alesa.myTemplate RT-DPA v1.0 ·