Skip to content
Masca logo
MASCAmalaysian students' council
Responsible data

Data protection & PDPA

MASCA Australia follows practical data protection principles designed for a student-led organisation operating across Australia and engaging with Malaysia.

Our approach

MASCA aims to manage personal information openly, fairly and securely. Our privacy policy describes our website practices. This statement sets out the broader principles we use when making day-to-day decisions about data.

Depending on the activity and the people involved, Australian privacy requirements or Malaysia's Personal Data Protection Act 2010 (PDPA) may apply differently. We use these principles as a practical baseline and do not suggest that every law applies to every MASCA activity.

Principles we follow

  1. Accountability and transparency. We identify who is responsible for systems and explain our data practices in clear language.
  2. Notice and choice. We explain why information is requested and provide meaningful choices where appropriate.
  3. Purpose limitation and minimisation. We collect only what is reasonably needed and avoid reusing it for unrelated purposes without a suitable basis.
  4. Accuracy. We take reasonable steps to keep important records current and allow people to request corrections.
  5. Security and access control. Access is limited to people who need it for MASCA responsibilities, supported by managed infrastructure and account controls.
  6. Retention and disposal. Information is kept only as long as reasonably needed, then deleted or de-identified where practicable.
  7. Responsible disclosure and overseas processing. We consider the purpose, safeguards and location before sharing data with another team or provider.
  8. Access and correction. We provide a clear route for people to ask about their information and respond within a reasonable period.

Committee responsibilities

Committee members with access to personal information should use it only for authorised MASCA work, avoid unnecessary copies, protect accounts and devices, and remove access when roles change. Public committee profiles and photographs should be published with the person's knowledge and kept accurate during the relevant term.

Data incidents

Suspected loss, unauthorised access or disclosure should be reported promptly to MASCA. We will work to contain the issue, preserve relevant information, assess the likely impact, reduce further harm and notify affected people or authorities where required.

Requests and complaints

Contact [email protected] to request access or correction, ask how information was handled, or make a complaint. Include a concise description and relevant dates. We may verify your identity before releasing information and will explain the outcome of our review.

If a concern is not resolved, you may be able to contact the Office of the Australian Information Commissioner or Malaysia's Personal Data Protection Commissioner, depending on which framework applies.