Legal Documents
Privacy Policy
Last Updated: 15 March 2025 | Effective: 15 March 2025
Suria Legal is committed to protecting the personal data of our clients and website visitors. This policy explains what information we collect, why we collect it, how we use it, and what rights you have in relation to it. It is written in plain language so that you can make informed decisions about sharing your information with us.
1. Who We Are
Suria Legal is an immigration law advisory practice registered in Malaysia, with principal offices at Level 28, Menara Maxis, Kuala Lumpur City Centre, 50088 Kuala Lumpur. We are the data controller in respect of personal data collected through our website and as part of our advisory engagements.
For data-related enquiries, contact us at: [email protected]
2. Personal Data We Collect
Information you provide directly
- Full name, email address, and phone number (provided via contact forms or enquiries)
- Passport details and nationality information (provided during advisory engagements)
- Employment and income information (required for pass eligibility assessments)
- Financial statements and documentation (for MM2H or business visa engagements)
- Family member details (for dependant application tracks)
Information collected automatically
- Browser type, operating system, and device information
- Pages visited and time spent on the website
- IP address and approximate geographic location
- Cookie preferences and interaction data (subject to your consent)
3. Legal Basis for Processing
We process personal data on the following legal bases under the Personal Data Protection Act 2010 (PDPA) of Malaysia:
- Consent: Where you have given us explicit consent to process your data, including for marketing communications.
- Contract: Where processing is necessary for the performance of an advisory engagement you have entered into with us.
- Legitimate interests: Where processing is necessary for our legitimate business interests, such as improving our services or maintaining security.
- Legal obligation: Where we are required to process data to comply with a legal or regulatory obligation.
4. How We Use Your Data
- Responding to enquiries and providing advisory services
- Preparing and submitting immigration applications on your behalf
- Communicating with the Immigration Department, ESD, or MDEC as required by your engagement
- Sending written milestone updates and engagement correspondence
- Improving the quality and relevance of our website content
- Complying with legal and regulatory obligations
We do not use your data for automated decision-making or profiling. We do not sell your personal data to third parties.
5. Data Sharing
We share personal data only where necessary:
- Government authorities: The Immigration Department of Malaysia, Expatriate Services Division (ESD), One Stop Centre, or MDEC — as required by the application process
- Service providers: Secure document management and IT service providers operating under confidentiality agreements
- Legal requirements: Where we are required by law to disclose information to a competent authority
All third parties with whom we share data are required to handle it with equivalent levels of care to those described in this policy.
6. Data Retention
We retain client engagement records for a period of seven years from the close of an engagement, in accordance with Malaysian legal professional standards. Website enquiry data is retained for twelve months from the date of initial contact if no engagement follows.
Cookie and analytics data is retained for the durations specified in our Cookie Policy.
7. Cookies
We use cookies on our website for essential functionality, analytics, and preference storage. Your cookie preferences are stored in your browser and can be adjusted at any time via our Cookie Policy page.
8. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or disclosure. These include:
- Secure file storage with access limited to the engagement team for each matter
- Encrypted email communication for sensitive document exchange
- Regular review of access rights and security practices
- Staff training on data handling obligations under the PDPA
In the event of a personal data breach that is likely to result in harm, we will notify affected individuals and, where required, the relevant authority in accordance with applicable law.
9. Your Rights
Under the Personal Data Protection Act 2010 (Malaysia), you have the following rights in respect of your personal data:
- Right of access: To request a copy of the personal data we hold about you
- Right to correction: To request correction of inaccurate or incomplete data
- Right to withdraw consent: Where processing is based on consent, to withdraw that consent at any time
- Right to restrict processing: To request that we limit how we use your data in certain circumstances
- Right to object: To object to processing for direct marketing purposes
To exercise any of these rights, contact us at [email protected]. We will respond within 21 days. We may need to verify your identity before processing a request.
You also have the right to lodge a complaint with the Personal Data Protection Commissioner of Malaysia if you believe your rights under the PDPA have been infringed.
10. Third-Party Links
Our website may contain links to the official Immigration Department website, MDEC, and other government resources. These sites have their own privacy policies, and we are not responsible for how they handle your data. We recommend reviewing their policies before providing any personal information.
11. Children's Privacy
Our services are directed at adults aged 18 and above. We do not knowingly collect personal data directly from children. Where minor dependants are included in an application, their data is provided by the adult applicant and processed solely for the purpose of the engagement.
12. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in law or our practices. Material changes will be communicated via our website. The date at the top of this page indicates when this version was last updated. Continued use of our website following an update constitutes acceptance of the revised policy.
13. Contact
For any questions about this policy or how we handle your personal data:
- Email: [email protected]
- Address: Level 28, Menara Maxis, KLCC, 50088 Kuala Lumpur, Malaysia
- Phone: +60 3 2386 9418