-
Introduction
- Net Onboard Sdn Bhd is committed to full compliance with Malaysian laws, industry regulations, and international best practices to ensure ethical business conduct, legal risk mitigation, and regulatory adherence.
- This Regulatory Compliance & Legal Risk Policy outlines the frameworks, obligations, and enforcement mechanisms applicable to our cloud computing, managed IT, cybersecurity, and digital solutions services.
-
This policy aligns with:
- Malaysia’s Communications and Multimedia Act (CMA) 1998
- Malaysia’s Personal Data Protection Act (PDPA) 2010
- Sales and Service Tax (SST) Act 2018
- Anti-Money Laundering Act (AMLA) 2001
- Competition Act 2010
- ISO 27001 & NIST Cybersecurity Standards
- By using Net Onboard’s services, you acknowledge and agree to comply with this Regulatory Compliance & Legal Risk Policy.
-
Compliance Framework & Legal Obligations
-
Compliance Objectives:
- To uphold legal and regulatory standards for cloud computing and IT services.
- To prevent legal risks related to data protection, taxation, anti-fraud, and competition laws.
- To ensure business operations are ethical, transparent, and legally sound.
-
Regulatory Bodies & Reporting Obligations:
- Malaysian Communications and Multimedia Commission (MCMC) – Oversees digital service compliance.
- Bank Negara Malaysia (BNM) – Regulates financial transactions, fraud prevention, and AMLA compliance.
- Royal Malaysian Customs Department – Administers SST compliance.
- Personal Data Protection Commissioner (JPDP) – Enforces data protection laws.
-
Compliance Objectives:
-
Data Protection & Privacy Compliance
-
Personal Data Protection Act (PDPA) 2010 Compliance:
- All personal and corporate data is processed in compliance with PDPA 2010.
- Explicit consent is required before collecting or processing personal data.
- Users have the right to access, correct, or delete their personal data.
-
Data Sovereignty & Storage:
- Personal data is stored in Malaysia unless international transfer is necessary for service fulfillment.
- Cross-border data transfers are subject to the Cross-Border Data Transfer Policy.
-
Personal Data Protection Act (PDPA) 2010 Compliance:
-
Anti-Money Laundering & Financial Compliance
-
Compliance with AMLA 2001:
- Transactions are monitored for unusual patterns (e.g., rapid high-value transactions).
- Know Your Customer (KYC) verification is required for high-risk transactions.
- Suspicious transactions will be reported to Bank Negara Malaysia (BNM).
-
Sales & Service Tax (SST) Compliance:
- All taxable services are subject to 8% SST under the Sales and Service Tax (SST) Act 2018.
- Customers will receive tax invoices for all applicable charges.
-
Compliance with AMLA 2001:
-
Competition & Fair Business Practices
-
Adherence to the Competition Act 2010:
- Net Onboard does not engage in anti-competitive practices, price fixing, or market monopolization.
- Third-party partnerships and vendor agreements are conducted fairly and transparently.
-
Intellectual Property & Copyright Compliance:
- Users must not host, distribute, or promote pirated software, counterfeit goods, or copyright-infringing materials.
- Net Onboard enforces strict IP protection measures under the Intellectual Property (IP) & Copyright Policy.
-
Adherence to the Competition Act 2010:
-
Cybersecurity & IT Risk Compliance
-
ISO 27001 & NIST Cybersecurity Compliance:
- All IT systems are secured using ISO 27001-compliant security controls.
- Regular penetration testing, vulnerability assessments, and security monitoring are conducted.
- Users must adhere to the Acceptable Use Policy (AUP) and Cybersecurity Policy.
-
Incident Response & Breach Notification:
- In the event of a data breach, affected users will be notified within 72 hours, as per PDPA & GDPR.
- Security incidents are managed under the Incident Response Policy.
-
ISO 27001 & NIST Cybersecurity Compliance:
-
Legal Risk Mitigation Strategies
-
Contractual Safeguards:
- All business engagements are governed by legally binding contracts.
- Liability limitations and dispute resolution clauses are incorporated into customer agreements.
-
Compliance Audits & Monitoring:
- Net Onboard conducts internal audits to identify and mitigate compliance risks.
- Regulatory updates are monitored, and policies are adjusted accordingly.
-
Legal & Regulatory Training:
- Employees undergo mandatory training on data protection, AMLA, and cybersecurity compliance.
- Key compliance personnel are designated to oversee risk management processes.
-
Contractual Safeguards:
-
Enforcement & Penalties for Non-Compliance
-
Violations of this Policy May Result In:
- Warnings or compliance notices for minor infractions.
- Suspension or termination of services for serious breaches.
- Legal action if violations involve fraud, regulatory breaches, or cybersecurity threats.
-
Regulatory Reporting Obligations:
- Serious legal violations will be reported to the appropriate Malaysian authorities.
-
Violations of this Policy May Result In:
-
Governing Law & Dispute Resolution
- This policy is governed by the laws of Malaysia.
- Any disputes related to regulatory compliance or legal risks will be resolved through negotiation and mediation before arbitration or litigation.
-
Amendments & Updates
- Net Onboard reserves the right to update this Regulatory Compliance & Legal Risk Policy at any time.
- Users will be notified of any material changes via email or system notifications.
For compliance-related inquiries, contact [email protected].