Privacy Statement – Control Union Malaysia Sdn. Bhd.
Last updated on: 1 January 2026
This Privacy Statement applies to individuals, organisations, and representatives who interact with Control Union Malaysia Sdn. Bhd. (“Control Union Malaysia”, “we”, “us” or “our”) and whose personal data are processed in Malaysia in accordance with the Personal Data Protection Act 2010 (PDPA) and its subsidiary legislation.
In this Privacy Statement, we explain how we collect, use, disclose, store, and protect personal data (“Data Protection”) obtained through our website, business activities, contractual engagements, and other interactions. We recommend that you read this statement carefully. In processing personal data, we comply with applicable data protection laws (especially the Malaysian Data Protection Act 2010) and principles, including that:
we clearly state the purposes for which personal data are processed;
we limit the collection of personal data to what is necessary for legitimate business and regulatory purposes;
we obtain consent where required under the PDPA;
we implement appropriate technical and organisational security measures to protect personal data; and
we respect your rights to access, correct, withdraw consent for, or limit the processing of your personal data.
If you have any questions or would like to seek further clarification on how your data is kept and processed, please contact us.
1. Purpose, personal data and retention period
We may collect or receive personal data for purposes connected with our business operations, including certification, inspection, testing, validation, verification, training, commercial, regulatory, and administrative activities.
1.1 Contact and business communications
Through phone, mail, email, meetings, and/or web forms
For this purpose, we may process the following personal data:
First and last name
Job title and organisation
Email address
Telephone or mobile number
Business address
IP address and basic website usage data
Legal basis for processing
Personal data are processed where it is necessary for:
the performance of a contract or pre-contractual steps;
compliance with legal, regulatory or accreditation obligations; and/or
our legitimate interests in conducting business, responding to enquiries, and maintaining professional relationships.
Retention period
Personal data are retained only for as long as necessary to fulfil the purpose for which they were collected, or as required by contractual, accreditation, or legal obligations.
1.2 Certification, inspection, testing, validation and verification activities
In the course of delivering our conformity assessment services, we may process personal data relating to:
client representatives and authorised contacts;
auditors, inspectors, reviewers, technical experts, and decision makers;
participants involved in audits, inspections, site visits, and assessments.
Such data may include names, professional credentials, contact details, employment history relevant to competence assessment, declarations of impartiality, and assessment-related records.
Legal basis for processing
Processing is necessary for the performance of contracts, compliance with accreditation standards, and compliance with applicable laws and regulatory requirements.
Retention period
Records are retained in accordance with accreditation rules, scheme requirements, contractual terms, laws and regulations and in adherence to the statutory limitation period.
2. Cookies
Our website uses cookies and similar technologies to ensure proper functionality, improve user experience, and analyse website performance.
For more information about the cookies we use and how you can manage your preferences, please refer to our Cookie Policy.
3. Disclosure practices
We treat personal data as confidential and do not disclose it to third parties except where necessary and permitted by law. Personal data may be disclosed:
where required by law, regulation, court order, or competent authority;
to accreditation bodies, regulators, or scheme owners in connection with accredited or recognised activities;
to professional advisers such as auditors, lawyers, or consultants;
to service providers and processors acting on our behalf under appropriate contractual safeguards; or
in connection with a corporate transaction such as a merger, acquisition, or restructuring.
Where applicable, we ensure that third parties processing personal data on our behalf are subject to appropriate confidentiality and data protection obligations.
4. Security
We are committed to the security of personal data. We implement appropriate administrative, technical, and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage.
Access to personal data is restricted to authorised personnel only, and our security measures are reviewed periodically to ensure ongoing effectiveness.
5. Third-party websites
This Privacy Statement does not apply to third-party websites that may be linked from our website. We are not responsible for the privacy practices or content of such external sites.
We recommend that you review the privacy statements of any third-party websites before providing personal data to them.
6. Amendments to this Privacy Statement
We reserve the right to amend this Privacy Statement from time to time to reflect changes in legal requirements, accreditation rules, or our business practices.
We encourage you to review this Privacy Statement periodically. Where appropriate, we will notify you of material changes.
7. Accessing, correcting, and limiting your personal data
Subject to the PDPA, you have the right to:
request access to your personal data held by us;
request correction of inaccurate, incomplete, or outdated personal data;
withdraw consent to the processing of personal data, where consent is the basis for processing;
request information on how your personal data are processed and retained; and
object to the processing of personal data for direct marketing purposes.
To protect your personal data, we may require verification of your identity before processing any request.
8. Submitting a complaint
If you are not satisfied with how we handle your personal data, you may contact us using the details below. You also have the right to lodge a complaint with the Personal Data Protection Commissioner of Malaysia.
SPDP – Sistem Perlindungan Data Peribadi
9. Contact details
Control Union Malaysia Sdn. Bhd.
Email: malaysia@controlunion.com
Address: Control Union Malaysia Sdn Bhd, Port Tech Tower, Level 17, Unit 1-7, Jalan Tiara 3, KU/1, Bandar Baru Klang, 41150 Klang, Selangor Darul Ehsan, Malaysia
- Industries
-
Services
Services
-
Certification & Assurance Services
Certification & Assurance Services
- Certification Programs
- Assurance Services
- General Process
- Certifications and Accreditations
- Publications
- Industrial Inspections
-
Commodity Inspections & Collateral Management
Commodity Inspections & Collateral Management Commodity Inspections & Collateral Management overview
- Laboratory Services
- Academy
-
Certification & Assurance Services
- About Us
- Careers
- Contact
-
Client Access
Client AccessIndustrial Inspections client portal
Efficient, and convenient access to your inspection status and updates.
Login to client portalICU - Textile Certification SystemClient platform for sustainable textile certification programs.
Log in to ICUCIS - Client Information SystemClient platform powering all non-textile certification programs.
Log in to CISCUCERT - Control Union Certification SystemNewly released certification platform for specific Aqua and Bio programs.
Log in to CUCERTNeed help?In order to request access to any of our platforms, please contact your local office
Find your local office - Search