20
Laws of Malaysia
ACT 709
(b) to any party other than a third party of the class of third
parties as specified in paragraph 7(1)(e).
Security Principle
9. (1) A data user shall, when processing personal data, take
practical steps to protect the personal data from any loss, misuse,
modification, unauthorized or accidental access or disclosure,
alteration or destruction by having regard—
(a) to the nature of the personal data and the harm that
would result from such loss, misuse, modification,
unauthorized or accidental access or disclosure, alteration
or destruction;
(b) to the place or location where the personal data is
stored;
(c) to any security measures incorporated into any equipment
in which the personal data is stored;
(d) to the measures taken for ensuring the reliability, integrity
and competence of personnel having access to the personal
data; and
(e) to the measures taken for ensuring the secure transfer of
the personal data.
(2) Where processing of personal data is carried out by a data
processor on behalf of the data user, the data user shall, for the
purpose of protecting the personal data from any loss, misuse,
modification, unauthorized or accidental access or disclosure,
alteration or destruction, ensure that the data processor—
(a) provides sufficient guarantees in respect of the technical
and organizational security measures governing the
processing to be carried out; and
(b) takes reasonable steps to ensure compliance with those
measures.
Retention Principle
10. (1) The personal data processed for any purpose shall
not be kept longer than is necessary for the fulfilment of that
purpose.