← All legal documents · Privacy Policy · Children's Privacy Notice

Balance — Malaysia Country Annex

Effective date: 28 June 2026 Last updated: 28 June 2026

Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every Malaysian resident covered by this Annex; the Data Protection Officer ("DPO") for the purposes of Personal Data Protection Act 2010 (Act 709) ("PDPA") section 12A (introduced by the Personal Data Protection (Amendment) Act 2024 (Act A1709) — the "2024 Amendment Act" — gazetted on 17 October 2024 with phased commencement; section 12A is among the provisions in force from 1 June 2025 pursuant to the Personal Data Protection (Amendment) Act 2024 (Commencement) Order 2025 — § 18 versioning protocol covers any further phased commencement) read with the Personal Data Protection Commissioner Guideline on Appointment of Data Protection Officer (Reference No. JPDP-100-1/12/01-1, issued by the Pesuruhjaya Perlindungan Data Peribadi / Personal Data Protection Commissioner — the "PDP Commissioner" — on 29 May 2025, in operation from 1 June 2025), with business contact published as the publicly-accessible DPO contact required by PDPA section 12A(3) + the DPO Guideline § 5; the designated contact point for the Personal Data Protection Department (Bahasa Malaysia: Jabatan Perlindungan Data Peribadi, the "JPDP"), the Malaysian Communications and Multimedia Commission (Bahasa Malaysia: Suruhanjaya Komunikasi dan Multimedia Malaysia, the "MCMC"), the Royal Malaysia Police — Sexual Crimes, Children and Domestic Violence Investigation Division (D11) (Bahasa Malaysia: Polis Diraja Malaysia — Bahagian Siasatan Jenayah Seksual, Kanak-Kanak dan Keganasan Rumah Tangga (D11)), the Royal Malaysia Police — Cyber Crime and Multimedia Investigation Division (Bahasa Malaysia: Bahagian Siasatan Jenayah Komersil — Unit Siasatan Jenayah Siber dan Multimedia), the Department of Social Welfare (Bahasa Malaysia: Jabatan Kebajikan Masyarakat, the "JKM"), and CyberSecurity Malaysia (the national CERT) under their respective intake protocols. Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to the Personal Data Protection Act 2010 (Act 709) ("PDPA") including the entry into force of any provision of the Personal Data Protection (Amendment) Act 2024 (Act A1709) (the "2024 Amendment Act") that is not yet operationally in force at the Effective date (the principal substantive provisions of the 2024 Amendment Act are in force from 1 June 2025 pursuant to the Personal Data Protection (Amendment) Act 2024 (Commencement) Order 2025 — including the section 12A mandatory DPO appointment + the section 12B mandatory data breach notification regime + the section 43A data portability right + the direct obligations on data processors at section 4 + the increased penalties at section 5 to greater of RM 1 million fine or 3 years imprisonment + the abolition of the s 130 whitelist transfer mechanism — but a set of subsidiary instruments under the 2024 Amendment Act remain to be issued; § 18 versioning protocol covers their issuance); (b) any amendment to the seven Personal Data Protection Principles at PDPA Part II (the "PDPPs") — PDPP 1 General Principle (s 6 lawful processing + consent + necessary-for-purpose) / PDPP 2 Notice and Choice Principle (s 7) / PDPP 3 Disclosure Principle (s 8) / PDPP 4 Security Principle (s 9) / PDPP 5 Retention Principle (s 10) / PDPP 6 Data Integrity Principle (s 11) / PDPP 7 Access Principle (s 12); (c) any Code of Practice, Guideline, Directive, or Determination issued by the PDP Commissioner under PDPA sections 23–28 — including the Guideline on Appointment of Data Protection Officer (29 May 2025), the Guideline on Notification of Personal Data Breach (29 May 2025), the Guideline on Cross-Border Personal Data Transfer (29 May 2025), the Guideline on Data Protection Impact Assessment (29 May 2025), the Guideline on Data Subject's Rights including Data Portability (29 May 2025), the Personal Data Protection Standards 2015 (the "PDP Standards 2015"), the Personal Data Protection Code of Practice for the Communications Sector + sectoral Codes of Practice for additional sectors, the Personal Data Protection (Class of Data Users) Order 2013 and the Personal Data Protection (Class of Data Users) (Amendment) Order 2016 (collectively, the "Class of Data Users Orders"), the Personal Data Protection (Compounding of Offences) Regulations 2013, the Personal Data Protection (Fees) Regulations 2013, and the Personal Data Protection Regulations 2013; (d) any decision of the Sessions Court, High Court, Court of Appeal, or Federal Court of Malaysia bearing on the PDPA, on Federal Constitution Article 5 read with Sivarasa Rasiah v Badan Peguam Malaysia [2010] 2 MLJ 333 (Federal Court of Malaysia — establishing that the right to life under Article 5 includes the right to privacy), or on the common-law privacy doctrines applied by Malaysian courts; (e) any amendment to the Child Act 2001 (Act 611) (the principal Malaysian child-welfare statute, in force from 1 August 2002, substantively amended by the Child (Amendment) Act 2016); (f) any amendment to the Sexual Offences Against Children Act 2017 (Act 792) ("SOACA") in force from 10 July 2017 — in particular sections 4 (child pornography offences), 5 (production and direction of child pornography), 6 (preparation of child pornography), 8 (using a child for child pornography), 10 (assault or use of criminal force on a child with sexual intent), 11 (sexual communication with a child + the principal online grooming offence), 12 (sexual extortion of a child), 13 (physical sexual assault on a child), 14 (non-physical sexual assault on a child), 15 (sexual assault on a child by person in a relationship of trust); (g) any amendment to the Penal Code (Act 574), in particular section 375 (rape) + section 375B (gang rape) + section 376 (punishment for rape) + section 376B (incest) + section 377A-377CA (carnal intercourse against the order of nature and related offences) + section 377D (gross indecency) + section 377E (incitement of child to act of gross indecency) + sections 509 (word or gesture intended to insult the modesty of any person); (h) any amendment to the Computer Crimes Act 1997 (Act 563), in particular section 3 (unauthorised access to computer material), section 4 (unauthorised access with intent to commit or facilitate further offences), section 5 (unauthorised modification of contents of any computer), and section 6 (wrongful communication); (i) any amendment to the Communications and Multimedia Act 1998 (Act 588), in particular section 211 (prohibition on provision of offensive content), section 233 (improper use of network facilities or network service), and Part X (powers of investigation); (j) any amendment to the Sedition Act 1948 (Act 15) or the Communications and Multimedia (Amendment) Act 2024 (the "CMA 2024 Amendment" — passed 11 December 2024 with phased commencement; introducing licensing for designated online platforms with 8 million Malaysian-resident users and child-safety obligations for relevant platforms — Balance is below the threshold and is not a designated platform); (k) any amendment to the Consumer Protection Act 1999 (Act 599), the Consumer Protection (Electronic Trade Transactions) Regulations 2012, the Contracts Act 1950 (Act 136), the Sale of Goods Act 1957 (Act 382), or the Age of Majority Act 1971 (Act 21) (collectively the principal Malaysian consumer-protection and contract-capacity statutes); (l) any amendment to the Communications and Multimedia (Anti-Spam) Regulations 2013 under the CMA 1998; (m) any amendment to a sub-processor's Malaysian data-handling posture under our sub-processor register; (n) the bringing into force of any post-Effective-date Malaysian regulation governing automated processing or related techniques (covered by the deliberate-silence carve-out in § 2 of this Annex); (o) Malaysia's accession to (or domestic implementation of) the Council of Europe Convention 108 / Convention 108+ (Malaysia is not currently a party) or the Convention on Cybercrime (Budapest Convention, Malaysia is not currently a party — § 18 versioning protocol covers any change in that status); (p) any amendment to the Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (Act 613) (AMLA) insofar as it engages production orders against data users; (q) any Federal Government Gazette notification by the Yang di-Pertuan Agong + Cabinet under PDPA section 130 regarding cross-border transfer mechanisms or Cabinet Order effecting the abolition of the legacy whitelist mechanism following the 2024 Amendment Act. Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.

This Annex discharges the country-annex obligations referenced in:

This Annex is the canonical Malaysian-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants a Malaysian resident a right that the global Policy does not, this Annex governs. Where the global Policy grants a Malaysian resident a right that this Annex does not, the global Policy governs. The two are read together.

This Annex is drafted in English. The national language of the Federation of Malaysia under Federal Constitution Article 152(1) is Bahasa Malaysia (also known as Bahasa Melayu or Malay); English is permitted for any official purpose under Article 152(2)–(5) without prejudice to the national-language status of Bahasa Malaysia and is in practice widely used in commerce and law. Mandarin Chinese and Tamil are languages of significant Malaysian communities. Bahasa Malaysia translation of this Annex is queued for the Phase-2 locale rollout per our internal compliance tracker; the Mandarin Chinese and Tamil translations are queued in the same Phase-2 rollout. No translation is statutorily required at the Effective date for the English-language privacy notice to a Malaysian resident (the PDPA does not mandate multilingual notification; the PDP Commissioner's interpretive practice accepts notices in Bahasa Malaysia or English provided the notice is intelligible to the data subject in light of the context).


1. Scope and applicability

This Annex applies to every Balance user (parent or kid) whose country of residence is Malaysia — the federation comprising 13 States (Johor / Kedah / Kelantan / Melaka / Negeri Sembilan / Pahang / Pulau Pinang / Perak / Perlis / Sabah / Sarawak / Selangor / Terengganu) and 3 Federal Territories (Kuala Lumpur / Labuan / Putrajaya). There is no State-level data-protection sub-layer that derogates from the PDPA in respect of Balance's commercial processing (the PDPA at section 3(2) excludes the Federal Government and the State Governments as data users, but Balance is a commercial data user and the PDPA applies in full).

We determine country of residence at install/sign-up time by (a) the country the parent self-declares in the in-app onboarding flow, (b) the IP-geolocation read at sign-up (which we discard immediately after the residence decision — our internal data-flow map § 2.1 stores no IP after the authentication request closes), and (c) the Play Store account locale that Google Play passes to us at install. The residence determination is reviewable at any time by the parent at Settings → Account → Region.

Where any of the three signals identifies Malaysia as the country of residence, this Annex applies, even if the other signals are non-Malaysian. The most-protective-for-the-data-subject reading is the controlling reading per our internal compliance plan § 6.3.

The PDPA has explicit territorial reach defined at section 2(1) + section 3(1) of the PDPA: the PDPA applies to any person who processes (or has control over or authorises the processing of) any personal data in respect of commercial transactions where the data user is established in Malaysia or the data user is not established in Malaysia but uses equipment in Malaysia for processing the personal data otherwise than for the purposes of transit through Malaysia. The 2024 Amendment Act broadened the operational reach by tightening the equipment in Malaysia limb and by extending direct obligations to data processors at section 4 (formerly an indirect-via-data-user concept). Balance squarely targets Malaysian residents through Google Play Malaysia, through publication of this Annex at balance.babayagaprogram.com, and through delivery of the parental-control service to Malaysian-resident parents and kids; the PDPA applies in respect of all personal data Balance processes in connection with Malaysian-resident users.


2. Statutory framework — what applies

The Malaysian personal-data-protection regime is dominated by the Personal Data Protection Act 2010 (Act 709) ("PDPA"), in force from 15 November 2013 for the principal substantive provisions, and substantively modernised by the Personal Data Protection (Amendment) Act 2024 (Act A1709) (the "2024 Amendment Act") gazetted 17 October 2024 with phased commencement (the principal substantive provisions are in force from 1 June 2025). The PDPA is supplemented by the Personal Data Protection Regulations 2013, the Personal Data Protection (Class of Data Users) Order 2013 + Amendment Order 2016, the Personal Data Protection (Compounding of Offences) Regulations 2013, the Personal Data Protection (Fees) Regulations 2013, the Personal Data Protection Standards 2015 (PDP Standards 2015), the PDP Commissioner's Guidelines and Codes of Practice, and the body of PDP Commissioner Determinations. Adjacent layers: the Federal Constitution of Malaysia Article 5 read with Sivarasa Rasiah v Badan Peguam Malaysia [2010] 2 MLJ 333 (Federal Court of Malaysia); the Child Act 2001 (Act 611); the Sexual Offences Against Children Act 2017 (Act 792); the Penal Code (Act 574); the Computer Crimes Act 1997 (Act 563); the Communications and Multimedia Act 1998 (Act 588); the Communications and Multimedia (Anti-Spam) Regulations 2013; the Consumer Protection Act 1999 (Act 599); the Consumer Protection (Electronic Trade Transactions) Regulations 2012; the Contracts Act 1950 (Act 136); the Sale of Goods Act 1957 (Act 382); the Age of Majority Act 1971 (Act 21).

Instrument Short cite What it does Balance's posture
Federal Constitution of Malaysia Federal Constitution — the supreme law of the Federation under Article 4(1). Article 5 "No person shall be deprived of his life or personal liberty save in accordance with law" — interpreted by the Federal Court of Malaysia in Sivarasa Rasiah v Badan Peguam Malaysia [2010] 2 MLJ 333 (Federal Court) + Lee Kwan Woh v PP [2009] 5 MLJ 301 (Federal Court) + Maria Chin Abdullah v Ketua Pengarah Imigresen Malaysia & Anor [2021] 1 MLJ 750 (Federal Court) to include the right to privacy as part of life; Article 8 equality before the law; Article 10 freedom of speech and expression (subject to permitted restrictions); Article 121 the judicial power vested in the Superior Courts; Article 152 Bahasa Malaysia as the national language with English permitted for any official purpose. The constitutional anchor. The right to privacy in Malaysia is constitutional (Article 5 via Sivarasa Rasiah) AND statutory (PDPA + adjacent regimes). Applies as the constitutional layer. Treatment in §§ 3, 6, 13 below.
Personal Data Protection Act 2010 (Act 709) PDPA — published in the Federal Government Gazette on 10 June 2010; principal substantive provisions in force from 15 November 2013; substantively modernised by the Personal Data Protection (Amendment) Act 2024 (Act A1709) gazetted 17 October 2024 with principal substantive provisions in force from 1 June 2025 pursuant to the Personal Data Protection (Amendment) Act 2024 (Commencement) Order 2025. Part I Preliminary (s 1 short title + extent + commencement; s 2 interpretation; s 3 application — does not apply to Federal/State Government in their data user capacity; s 3(1) territorial application: PDPA applies to processing of personal data in respect of commercial transactions where (a) data user established in Malaysia OR (b) data user not established in Malaysia but uses equipment in Malaysia for processing otherwise than for transit). Part II Personal Data Protection Principles (PDPPs) — seven principles operative: s 6 PDPP 1 General Principle (personal data shall not be processed without the consent of the data subject given for a specific and lawful purpose; carve-outs for performance of contract / legal obligation / vital interest of data subject / administration of justice / functions of public nature); s 7 PDPP 2 Notice and Choice Principle (data user must give written notice to data subject of identified purposes + categories of personal data + sources + recipients + data subject's rights including access and correction + obligations); s 8 PDPP 3 Disclosure Principle (no disclosure for any purpose other than purpose of collection or directly-related purpose without prior consent of data subject; no disclosure to third parties other than as identified in notice without consent); s 9 PDPP 4 Security Principle (practical steps to protect personal data from loss / misuse / modification / unauthorised or accidental access or disclosure / alteration / destruction); s 10 PDPP 5 Retention Principle (no longer than necessary); s 11 PDPP 6 Data Integrity Principle (accuracy + completeness + not misleading + up to date for purpose); s 12 PDPP 7 Access Principle (data subject right of access + correction). Part II ALSO contains section 12A — mandatory Data Protection Officer appointment (introduced by the 2024 Amendment Act, in force from 1 June 2025 — data user must appoint a DPO where the data user's processing involves (i) substantial volume of personal data based on thresholds prescribed in subsidiary instruments + (ii) sensitive personal data processed as a core activity + (iii) regular and systematic monitoring of data subjects + (iv) processing of personal data of children); section 12A(3) — DPO contact details must be publicly available — and the DPO Guideline of 29 May 2025 + section 12B — mandatory data breach notification introduced by 2024 Amendment Act — PDP Commissioner notification within 72 hours from awareness of significant data breach + affected-individual notification as soon as practicable on harm-likelihood threshold; section 43A — right to data portability introduced by 2024 Amendment Act in force from 1 June 2025. Part III Registration of Data Users (ss 13–20 — registered data user classes prescribed by the Class of Data Users Orders; Balance's class — commercial data users dealing with personal data of children + provision of digital services — engages the Class of Data Users Order 2013 registration obligation; foreign data users without permanent Malaysian establishment are NOT required to register per JPDP interpretive practice; § 8.3 below). Part IV Sensitive Personal Data (s 40 — heightened processing rules; sensitive personal data defined at s 4 as physical or mental health / political opinions / religious beliefs or other beliefs of a similar nature / commission or alleged commission of any offence; Balance does NOT process sensitive personal data in respect of Malaysian residents). Part V Rights of Data Subject ss 30–43A — s 30 right of access (data access request) + s 35 right of correction (data correction request) + s 38 right to withdraw consent + s 42 right to prevent processing causing damage or distress + s 43 right to prevent processing for direct marketing + s 43A right to data portability (post-2024-Amendment). Part VI Personal Data Protection Commissioner (ss 47–58 — establishment + appointment + functions + powers). Part VII Notification of Personal Data Breach ss 12B-12D (post-2024-Amendment): s 12B notification triggers + 72-hour PDP Commissioner deadline + s 12C minimum content + s 12D affected-individual notification on harm-likelihood threshold + s 12E offences for failure to notify. Part VIII Codes of Practice (ss 23–28). Part IX Enforcement — administrative enforcement notices ss 90–92 + investigations ss 110–122 + offences and penalties at section 5 of the 2024 Amendment Act (general non-compliance fines up to RM 1 million + imprisonment up to 3 years; aggravated offences up to RM 500,000 + 2 years for individual officers in default). Part X Inspection ss 101–109. Part XI Appeals Process and Personal Data Protection Appeal Tribunal (ss 83–93 — Appeal Tribunal jurisdiction + appeal to High Court). Part XII Miscellaneous including section 129 transfer of personal data to places outside Malaysia — the 2024 Amendment Act abolished the pre-existing whitelist mechanism + replaced it with a more flexible accountability-based mechanism with the operational anchor at the PDP Commissioner Guideline on Cross-Border Personal Data Transfer of 29 May 2025; in force from 1 June 2025. Part XIII Provisions Affecting Other Written Laws ss 130–134. The principal statute. Applies in full to Balance as a data user established outside Malaysia that targets services to Malaysian residents (with the territorial reach via the equipment in Malaysia limb at s 3(1) interpreted broadly under JPDP practice post-2024-Amendment). Treatment in §§ 3, 4, 6, 7, 8, 11, 13 below.
Personal Data Protection (Amendment) Act 2024 (Act A1709) — "the 2024 Amendment Act" 2024 Amendment Act — gazetted Warta Kerajaan Persekutuan on 17 October 2024 with phased commencement. Principal substantive provisions in force from 1 June 2025 per Personal Data Protection (Amendment) Act 2024 (Commencement) Order 2025. Headline changes: (i) replaces data user with data controller terminology (with the 2024-Amendment subsection clarifying that the change is purely terminological — substantive obligations carry through); (ii) introduces direct obligations on data processors at section 4 + s 9 security obligations; (iii) introduces section 12A mandatory DPO appointment; (iv) introduces section 12B mandatory data breach notification with 72-hour PDP Commissioner deadline + affected-individual notification on harm-likelihood threshold; (v) introduces section 43A right to data portability; (vi) abolishes the whitelist-based cross-border transfer mechanism at the pre-amendment section 129 and replaces it with an accountability-based mechanism with the PDP Commissioner Guideline on Cross-Border Personal Data Transfer (29 May 2025) as the operational anchor; (vii) increases penalties — general non-compliance up to RM 1 million + 3 years imprisonment; aggravated up to RM 500,000 + 2 years; PDPA Part IX restated; (viii) introduces a biometric data expanded definition within the sensitive-personal-data Part IV regime (Balance does NOT process biometric data); (ix) clarifies the processing of personal data of children as a category engaging the s 12A DPO obligation + the s 12B breach-notification threshold + DPIA expectations under the s 23 Codes of Practice framework. Applies as the modernising overlay. Treatment in §§ 3, 4, 6, 8, 11 below.
Personal Data Protection Regulations 2013 PDP Regulations 2013 — gazetted 14 November 2013; in force 15 November 2013. Operationalise the PDPPs (Regulations 3–9), the data access request procedure (Regulation 4 + Schedule), the data correction request procedure (Regulation 5), the registration procedure under Part III of the PDPA (Regulations 6–9), and the maintenance of records requirements. The PDP Standards 2015 supplement the PDPP 4 Security Principle. Applies in full. The operational implementation of the PDPA. Treatment in §§ 6, 11 below.
Personal Data Protection Standards 2015 (PDP Standards 2015) PDP Standards 2015 — issued by the PDP Commissioner under PDPA section 134(2) and effective from 23 December 2015. Personal Data Protection Standard 2015 — security standards mandatory for all data users dealing with personal data + Personal Data Protection Retention Standard + Personal Data Protection Data Integrity Standard. Sets the operative technical and organisational baselines for PDPP 4 Security + PDPP 5 Retention + PDPP 6 Data Integrity. Applies in full. Balance's posture: PDP Standards 2015 implemented; further reinforced by the Personal Data Protection Code of Practice for the Communications Sector applied by analogy to Balance's operations. Treatment in § 11 below.
Personal Data Protection (Class of Data Users) Order 2013 + Amendment Order 2016 Class of Data Users Orders — gazetted 14 November 2013 (principal) + 23 December 2016 (amendment). Specify the classes of data users required to register with the PDP Commissioner under PDPA Part III. The 2013 Order designates eleven sectoral classes: communications / banking and financial institutions / insurance / health / tourism and hospitalities / transportation / education / direct selling / services / real estate / utilities. The 2016 Amendment Order added pawnbrokers and money-lenders. Balance's commercial offering is on the services sector + the communications sector overlap. Foreign data users without permanent Malaysian establishment are NOT required to register per JPDP interpretive practice — see § 8.3 below. Applies. Treatment in § 8 below.
PDP Commissioner Guidelines (29 May 2025 series) PDP Commissioner Guidelines — a series of binding interpretive instruments issued by the PDP Commissioner on 29 May 2025 + in operation from 1 June 2025, operationalising the 2024 Amendment Act. Most directly relevant: Guideline on Appointment of Data Protection Officer (Reference No. JPDP-100-1/12/01-1; sets out triggers for s 12A DPO appointment, DPO qualifications, DPO functions, DPO public-contact requirement under s 12A(3)); Guideline on Notification of Personal Data Breach (Reference No. JPDP-100-1/12/02-1; sets out triggers for s 12B notification, the 72-hour PDP Commissioner notification deadline from awareness, the significant data breach threshold, the minimum-content schedule under s 12C, the affected-individual notification on harm-likelihood under s 12D); Guideline on Cross-Border Personal Data Transfer (Reference No. JPDP-100-1/12/03-1; operational anchor for s 129 post-2024-Amendment — sets out the accountability-based mechanism + recommended-form contractual clauses); Guideline on Data Protection Impact Assessment (Reference No. JPDP-100-1/12/04-1; sets out DPIA triggers and methodology — Balance's DPIA at our Data Protection Impact Assessment); Guideline on Data Subject's Rights including Data Portability (Reference No. JPDP-100-1/12/05-1; operationalises s 30 + s 35 + s 38 + s 42 + s 43 + s 43A). Sets the PDP Commissioner's binding interpretive layer on the PDPA. Applies in full.
Child Act 2001 (Act 611) Child Act 2001 — gazetted on 25 January 2001 + in force 1 August 2002. Substantively amended by the Child (Amendment) Act 2016 (Act A1511) in force 7 July 2017. Section 2 definitionschild means a person under the age of 18 years; parent + guardian defined; Child Protector under section 8 + Probation Officer. Part II Child Care + Protection Council (s 3); Part III Court for Children jurisdiction; Part IV Persons in need of protection — ss 17–29 including s 27 mandatory reporting by medical officer, family member, child care provider, or any person of physical / sexual / emotional injury to a child; Part V Adoption, fostering and place of safety; Part VI Children in conflict with the law; Part VII–XI sentencing and aftercare; Part XIII Offences in respect of children (s 31 child abuse / s 32 ill-treatment / s 33 abandonment / s 36 employing or causing a child to beg). The principal Malaysian child-welfare statute. The principal child-welfare statute. Applies. Treatment in § 5 + § 14 below.
Sexual Offences Against Children Act 2017 (Act 792) (SOACA) SOACA — gazetted on 6 July 2017 + in force 10 July 2017. The principal Malaysian CSAE statute. Section 4 — child pornography offences (possession + access + distribution; fine + imprisonment up to 20 years); Section 5 — production and direction of child pornography (imprisonment up to 30 years + whipping not less than 6 strokes); Section 6 — preparation of child pornography; Section 7 — exploitation of child for pornography (imprisonment up to 30 years + whipping); Section 8 — using a child in production of child pornography (imprisonment up to 20 years + whipping); Section 10 — assault or use of criminal force on a child with sexual intent (imprisonment up to 20 years + whipping); Section 11 — sexual communication with a child — the principal online grooming offence in Malaysian law (any person who by any means including by communicating (oral / electronic / via a computer network) with a child for the purpose of engaging the child in sexual activity / sexual communication / sending sexually explicit material is guilty of an offence; imprisonment up to 10 years + fine up to RM 20,000); Section 12 — sexual extortion of a child; Section 13 — physical sexual assault on a child (imprisonment up to 20 years + whipping); Section 14 — non-physical sexual assault on a child (imprisonment up to 10 years + fine up to RM 20,000); Section 15 — sexual assault on a child by person in a relationship of trust (heightened penalty); Section 16 — failure to report sexual offences against a child + mandatory reporting by any person + immunity from civil and criminal action for reporting in good faith; Section 17 — extraterritorial application to offences by Malaysian citizens/PRs against children outside Malaysia. The principal Malaysian CSAE statute. Applies. Treatment in § 14 below.
Penal Code (Act 574) Penal Code — the principal general criminal statute, in force 1 April 1976 (as the post-Merdeka consolidation of the pre-existing Federation of Malaya Penal Code). Substantive sections relevant to Balance's child-safety + lawful-access posture: s 354 assault or use of criminal force on a person with intent to outrage modesty; s 375 rape — including statutory rape elements at s 375(g) and (h) for unmarried girl under 16 + s 375(f) under-16 wife; s 375A husband-rape; s 375B gang rape (mandatory minimum 20 years + whipping); s 376 punishment for rape; s 376A incest; s 376B punishment for incest; s 377A–s 377CA carnal intercourse against the order of nature and related offences; s 377D gross indecency; s 377E incitement of child to act of gross indecency; s 509 word or gesture intended to insult the modesty of any person. Applies. Treatment in § 14 below.
Computer Crimes Act 1997 (Act 563) Computer Crimes Act 1997 — in force from 1 June 2000. Section 3 unauthorised access to computer material; Section 4 unauthorised access with intent to commit or facilitate further offences; Section 5 unauthorised modification of contents of any computer; Section 6 wrongful communication; Section 7 abetment + attempts; Section 8 investigations and procedure. The principal cybercrime statute. Applies. Treatment in § 13 below.
Communications and Multimedia Act 1998 (Act 588) (CMA) CMA — in force from 1 April 1999. Part I Preliminary; Part II establishment of MCMC; Part III licensing of network facilities providers / network service providers / applications service providers / content applications service providers (Balance is not a licensee — Balance is below the threshold and the parental-control service is not within the licensee categories); Part IV Spectrum; Part V Numbering and electronic addressing; Part VI Universal Service; Part VII Content (s 211 prohibition on provision of indecent / obscene / false / menacing / offensive content + s 233 improper use of network facilities or network service — fine up to RM 50,000 + imprisonment up to 1 year + further fine RM 1,000 per day); Part VIII–X Powers of Minister + investigations; the Communications and Multimedia (Anti-Spam) Regulations 2013 under CMA s 211 supplement the position on unsolicited commercial messages. Communications and Multimedia (Amendment) Act 2024 (the "CMA 2024 Amendment") — passed 11 December 2024 with phased commencement; introduces licensing for designated online platforms with at least 8 million Malaysian-resident users + child-safety obligations for relevant platforms (Balance is below the 8-million threshold and is not a designated platform). Applies in respect of any improper-use-of-network-facilities offences; CMA 2024 Amendment is a context-setting fact (Balance below 8M threshold). Treatment in § 12 + § 13 below.
Communications and Multimedia (Anti-Spam) Regulations 2013 Anti-Spam Regulations 2013 — gazetted under CMA s 211; in force from 1 January 2014. Prohibit the provision of unsolicited commercial electronic message without prior consent + identification + unsubscribe mechanism. Civil penalties + criminal offences. Applies. Balance does NOT send commercial electronic messages to Malaysian residents within the meaning of the Regulations. Treatment in § 12 below.
Consumer Protection Act 1999 (Act 599) CPA 1999 — in force from 15 November 1999. Part I Preliminary; Part II Misleading or deceptive conduct, false representations and unfair practices; Part IIIA Unfair contract terms (introduced by the Consumer Protection (Amendment) Act 2010 in force 1 July 2010); Part V Safety of goods and services; Part VI Rights against suppliers in respect of guarantees in the supply of goods; Part VII Rights against manufacturers in respect of guarantees in the supply of goods; Part VIII Rights of consumers in respect of services; Part IX Rights against suppliers in respect of guarantees in the supply of services — non-excludable guarantees of reasonable care and skill (s 53) + fitness for particular purpose (s 54) + reasonable time (s 55) + reasonable price (s 56); Part XII Tribunal for Consumer Claims (small claims up to RM 50,000); enforced by the Ministry of Domestic Trade and Cost of Living (KPDN) + the Tribunal for Consumer Claims. The principal Malaysian consumer-protection statute. Applies in full. Treatment in § 16 below.
Consumer Protection (Electronic Trade Transactions) Regulations 2012 Electronic Trade Transactions Regulations 2012 — gazetted 31 July 2012 + in force 1 July 2013. Regulation 3 + Schedule prescribe minimum information disclosure for online marketplace operators + Schedule requirements for suppliers in distance-selling transactions including identity + nature of goods/services + price + delivery + cancellation/refund/exchange policy. Applies to electronic trade transactions including online subscription supply. Applies. Treatment in § 16 below.
Contracts Act 1950 (Act 136) Contracts Act 1950 — the general statute of contract law, in force 1 January 1951. Section 11 capacity to contract (a minor cannot make a binding contract — Mohori Bibee v Dharmodas Ghose [1903] LR 30 IA 114 applied in Malaysia + Tan Hee Juan v Teh Boon Keat [1934] MLJ 96); Section 16 consent (free consent + undue influence); Section 17 fraud; Section 18 misrepresentation; Section 19 voidability for coercion / undue influence / fraud / misrepresentation; Sections 24–30 legality of consideration and object; Section 73 restitution of advantage gained from contract that becomes void. Applies. Treatment in § 16 below.
Sale of Goods Act 1957 (Act 382) Sale of Goods Act 1957 — the principal sale-of-goods statute. Section 16 implied condition of merchantable quality; Section 16(1)(a) implied condition of fitness for purpose where the buyer makes known to the seller the particular purpose. Applies. Treatment in § 16 below.
Age of Majority Act 1971 (Act 21) Age of Majority Act 1971 — in force from 1 January 1972. Section 2 sets the age of majority at 18 years. Subject to certain religious-personal-law overlays for matters governed by Islamic law (which do not engage Balance's commercial contracting). Applies. Confirms that the parent contracting with Balance is an adult (the subscription contract is between Balance and the parent, not the kid). Treatment in § 16 below.
EU adequacy None. Malaysia does not hold an EU adequacy decision under GDPR Article 45 at the Effective date. EU/EEA → Malaysia transfers are governed by EU SCCs + Transfer Impact Assessment. Cross-reference in EU / EEA annex § 8. The absence of EU adequacy does not affect Balance's posture because Balance has no Malaysian data residency (the backend is in the US — see § 9 below).
Convention 108 / Convention 108+ Not applicable. Malaysia is not a party to the Council of Europe Convention 108 or Convention 108+. Applies as a context-setting fact. Treatment in § 8 below.
APEC Cross-Border Privacy Rules (CBPR) Malaysia has been an APEC participating economy since the founding of APEC in 1989; Malaysia formally joined the operational APEC CBPR system + the APEC PRP (Privacy Recognition for Processors) on 12 May 2022 as a participating economy with an Accountability Agent designation; the operational accountability agent designation for Malaysia is administered through the JPDP. Applies as a context-setting fact. Treatment in § 8 below — the APEC CBPR participation provides an additional contractual-protection overlay route for Malaysia-to-third-country transfers but the operational mechanism for Balance is the PDPA section 129 framework + the PDP Commissioner Guideline on Cross-Border Personal Data Transfer (29 May 2025).
ASEAN Framework on Personal Data Protection (2016) The ASEAN Framework on Personal Data Protection adopted by the ASEAN Telecommunications and IT Ministers in November 2016 + the ASEAN Data Management Framework + the ASEAN Model Contractual Clauses for Cross Border Data Flows (January 2021). Malaysia is a signatory and supportive member. Applies as a context-setting fact. The ASEAN Model Contractual Clauses provide an alternative contractual-protection overlay route used in this Annex's transfer pack at § 8 below.
Budapest Convention on Cybercrime Not applicable at the Effective date. Malaysia is not a party to the Convention on Cybercrime (Budapest Convention). Applies as a context-setting fact. Cross-border lawful-access for Malaysia is via the Mutual Assistance in Criminal Matters Act 2002 (Act 621) + bilateral MLATs.

(Any prospective Malaysian regulation governing automated processing, algorithmic decisions, or related techniques — including any post-Effective-date PDP Commissioner Guideline in that area, the National AI Roadmap 2021–2025 + the AI-RMF Malaysia: Artificial Intelligence Governance and Ethics Guidelines (issued by the Ministry of Science, Technology and Innovation in September 2024, voluntary best-practice guidance only), the National Artificial Intelligence Office (NAIO) initiatives, any future Malaysian primary legislation on artificial intelligence before the Dewan Rakyat, and any successor instrument — is intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such Malaysian regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence on the topic is deliberate and is not to be read as an implicit statement either way.)


3. Supervisory authorities

3.1 PDP Commissioner — Pesuruhjaya Perlindungan Data Peribadi

The principal supervisory authority is the Personal Data Protection Commissioner (Bahasa Malaysia: Pesuruhjaya Perlindungan Data Peribadi, the "PDP Commissioner"), the head of the Personal Data Protection Department (Jabatan Perlindungan Data Peribadi, "JPDP"), an authority within the Ministry of Digital (Bahasa Malaysia: Kementerian Digital; established on 12 December 2023 by the splitting of the former Ministry of Communications and Digital into the Ministry of Communications and the Ministry of Digital). The PDP Commissioner is appointed under PDPA section 47 + section 48 by the responsible Minister with the consent of the Yang di-Pertuan Agong (the King of Malaysia). The PDP Commissioner has investigative + enforcement + regulatory + recommendatory powers. The PDP Commissioner's decisions are appealable to the Personal Data Protection Appeal Tribunal under PDPA Part XI ss 83–93 and onwards to the High Court of Malaya + the Court of Appeal + the Federal Court of Malaysia.

Field Value
Name Personal Data Protection Department (Jabatan Perlindungan Data Peribadi, JPDP)
Parent ministry Ministry of Digital (Kementerian Digital)
Headquarters Aras 6, Kompleks Kementerian Komunikasi dan Digital, Lot 4G9, Persiaran Perdana, Presint 4, 62100 Putrajaya, Malaysia
Website https://www.pdp.gov.my/ (Bahasa Malaysia) / https://www.pdp.gov.my/?lang=en (English)
Complaint channel JPDP online complaint portal at https://aduan.pdp.gov.my/; email aduan@pdp.gov.my
Phone +60 3 8911 7000
Data-Breach-Notification channel JPDP online Personal Data Breach Notification portal per PDPA section 12B + the PDP Commissioner Guideline on Notification of Personal Data Breach of 29 May 2025 — 72-hour notification from awareness of significant personal data breach.
Personal Data Protection Commissioner At the Effective date — published at https://www.pdp.gov.my/

The PDP Commissioner is the first-line forum for any PDPA-grounded complaint from any Malaysian resident. A Malaysian resident may petition the PDP Commissioner after first raising the matter with Balance (the JPDP's Aduan Portal complaint procedure recommends raising the matter with the data user first, but the JPDP also accepts direct complaints). We accept all data subject access / privacy enquiries at (named individual: , in his capacity as the DPO under PDPA section 12A + the PDP Commissioner Guideline on Appointment of Data Protection Officer of 29 May 2025) and respond within the PDPA timelines (see § 6 below).

A Malaysian resident may also pursue private remedies via (i) the PDPA section 42 right to prevent processing causing damage or distress + the PDPA Part IX civil remedies under the s 5 enforcement-quantum framework; (ii) common-law privacy doctrine as recognised by Malaysian courts in Lee Ewe Poh v Dr Lim Teik Man & Anor [2011] 1 MLJ 835 (High Court) + subsequent decisions; (iii) the Federal Constitution Article 5 constitutional-rights cause of action read with Sivarasa Rasiah v Badan Peguam Malaysia [2010] 2 MLJ 333 (Federal Court); (iv) the PDPA section 18 complaint route to a sectoral Code of Practice where applicable; (v) the PDPA Part VII offences which may be the subject of criminal complaint to the Public Prosecutor under PDPA section 138 + the Criminal Procedure Code (Act 593).

3.2 Ministry of Digital — JPDP parent ministry

The Ministry of Digital (Kementerian Digital) is the parent ministry of the JPDP. The Minister of Digital is the responsible minister for the PDPA and for the issuance of subsidiary instruments under PDPA section 134.

Field Value
Name Ministry of Digital (Kementerian Digital, KD)
Headquarters Aras 1, 2, 3 dan 4, Blok B, Kompleks Kementerian Komunikasi dan Digital, Lot 4G9, Persiaran Perdana, Presint 4, 62100 Putrajaya, Malaysia
Website https://www.digital.gov.my/
Phone +60 3 8000 8000

3.3 Other regulatory bodies

Body Subject matter URL
Malaysian Communications and Multimedia Commission (MCMC)Suruhanjaya Komunikasi dan Multimedia Malaysia Communications and Multimedia Act 1998 enforcement; spam; CMA 2024 Amendment designated-platform regulation https://www.mcmc.gov.my/ — Hotline: 1-800-188-030
Royal Malaysia Police (PDRM) — Sexual Crimes, Children and Domestic Violence Investigation Division (D11)Polis Diraja Malaysia — Bahagian Siasatan Jenayah Seksual, Kanak-Kanak dan Keganasan Rumah Tangga Sexual offences against children + CSAE investigation https://www.rmp.gov.my/ — Emergency 999
PDRM — Cyber Crime and Multimedia Investigation Division (D5(6)) Cybercrime investigation including online CSAE https://www.rmp.gov.my/
PDRM — Anti-Trafficking in Persons and Anti-Smuggling of Migrants Division (D7) Anti-Trafficking in Persons and Anti-Smuggling of Migrants Act 2007 https://www.rmp.gov.my/
Department of Social Welfare (JKM)Jabatan Kebajikan Masyarakat Child Act 2001 — child-protection lead agency; Talian Kasih 15999 general welfare hotline https://www.jkm.gov.my/
Department of Women Development (JPW)Jabatan Pembangunan Wanita Women + gender-based-violence services https://www.jpw.gov.my/
Ministry of Women, Family and Community Development (KPWKM) JKM + JPW parent ministry; SOACA implementing ministry; Talian Kasih 15999 https://www.kpwkm.gov.my/
Ministry of Domestic Trade and Cost of Living (KPDN)Kementerian Perdagangan Dalam Negeri dan Kos Sara Hidup Consumer Protection Act 1999 + Electronic Trade Transactions Regulations + Tribunal for Consumer Claims https://www.kpdn.gov.my/ — Hotline: 1-800-886-800
Tribunal for Consumer ClaimsTribunal Tuntutan Pengguna Malaysia (TTPM) Small consumer claims up to RM 50,000 https://ttpm.kpdn.gov.my/
CyberSecurity Malaysia (CSM) National CERT; MyCERT for cyber-incident handling https://www.cybersecurity.my/ + https://www.mycert.org.my/
Attorney General's ChambersJabatan Peguam Negara Public prosecution; SOACA + Penal Code prosecutions https://www.agc.gov.my/
Personal Data Protection Appeal Tribunal Appeals from PDP Commissioner decisions under PDPA Part XI via JPDP https://www.pdp.gov.my/
Children's CommissionerSuruhanjaya Hak Asasi Manusia Malaysia (SUHAKAM) — Children's Commissioner Independent child-rights advocacy https://www.suhakam.org.my/
National Council for Child WelfareMajlis Kebajikan Kanak-Kanak Malaysia Federal child-welfare coordination body under Child Act 2001 s 3 via JKM
Talian Kasih 15999 — KPWKM Hotline 24/7 child-protection + women-protection + family-violence hotline dial 15999
Childline Foundation Malaysia Children's helpline NGO https://www.childlinefoundation.org.my/ — 15999 (via Talian Kasih)
Protect and Save the Children (PS) Malaysia Children's protection NGO https://psthechildren.org.my/
PEMBELAPersatuan Mencegah Buli, Eksploitasi, Layanan Buruk dan Aniaya Children's protection NGO via PS the Children
WAOWomen's Aid Organisation Women + child sexual-violence services https://wao.org.my/
Befrienders Kuala Lumpur 24-hour emotional support hotline https://www.befrienders.org.my/ — 03-7956 8145
MIASA — Mental Illness Awareness and Support Association Mental health crisis support https://miasa.org.my/
CyberSAFE Malaysia CSM-operated online-safety awareness initiative https://www.cybersafe.my/

3.4 The DPO

PDPA section 12A (introduced by the 2024 Amendment Act, in force from 1 June 2025) + the PDP Commissioner Guideline on Appointment of Data Protection Officer of 29 May 2025 require every data user falling within the section 12A criteria to appoint a Data Protection Officer (DPO). The criteria include (iv) processing of personal data of children. Balance's processing of children's personal data of Malaysian-resident kids engages s 12A(1)(iv) and Balance accordingly appoints a DPO. The DPO must be readily accessible, must be reachable by data subjects and by the PDP Commissioner, and the DPO's contact details must be publicly available under s 12A(3).

The Balance DPO is:

The DPO's business contact is published in this Annex, in the global Privacy Policy (Privacy Policy § 1), and at balance.babayagaprogram.com — satisfying PDPA s 12A(3) + the PDP Commissioner Guideline on Appointment of Data Protection Officer of 29 May 2025. The DPO is the contact point for the PDP Commissioner on any regulatory matter and for data subjects on rights-exercise matters. The DPO need not be a Malaysian citizen or resident but must be readily accessible during Malaysian business hours per the DPO Guideline § 6.3.


4. Lawful bases — PDPA section 6 (PDPP 1) + section 8 (PDPP 3) + sensitive-data carve-out

The PDPA is a consent-and-purpose-limitation regime modulated by the PDPP 1 general principle + the section 6 carve-outs (performance of contract / legal obligation / vital interest / administration of justice / functions of public nature). Balance processes personal data of Malaysian residents on the following PDPA mapping:

Processing purpose PDPA basis Cross-reference
Run the parental-control service the parent signed up for (account creation, family configuration, kid profile, limits, schedules, tasks, earned-time ledger, end-to-end-encrypted proof media) PDPA section 6 PDPP 1 — parent's consent given for the specific and lawful purpose + performance-of-contract carve-out at s 6(2)(b) (the processing is necessary for the performance of a contract to which the data subject is a party) + PDPP 2 notice and choice at s 7 + PDPP 3 disclosure at s 8 + PDPP 4 security at s 9 H1 § 4; H7 PA-01 through PA-08; § 7 of this Annex
Process the kid's personal data PDPA section 6 — parent's consent given on behalf of the kid under the Age of Majority Act 1971 (kid is a minor; parent is the legal guardian) + Child Act 2001 framework + Contracts Act 1950 s 11 minor-capacity doctrine + Hindu/Muslim/Christian/customary parental-authority overlays as applicable per personal-law jurisdiction + the PDP Commissioner Guideline on Appointment of Data Protection Officer + DPP 1/3/4 § 7 of this Annex; our Data Protection Impact Assessment § 6
Deliver operational alerts PDPA section 6 + section 7 (primary purpose) H1 § 4; H7 PA-09; M3
Detect, prevent, and respond to security incidents, abuse, fraud, and unauthorised access PDPA section 9 PDPP 4 security obligation + PDP Standards 2015 + section 6(2)(d) (necessary for any legal proceedings) + section 6(2)(e) (necessary to protect vital interest) + section 39 carve-outs for crime prevention H7 PA-15; § 13 below
Comply with legal, regulatory, and supervisory obligations PDPA section 6(2)(c) (necessary to comply with any legal obligation to which the data user is the subject) + s 39 carve-outs § 13 below; M1; § 14 below
Process Verifiable Parental Consent for the kid's data PDPA section 6 PDPP 1 + section 7 PDPP 2 — collection of the parent's personal data for the primary purpose of obtaining VPC § 7 of this Annex; A-US § 5
Process the parent's billing / subscription data PDPA section 6(2)(b) performance-of-contract necessity; CPA 1999 + Consumer Protection (Electronic Trade Transactions) Regulations 2012 + Sale of Goods Act 1957 + Contracts Act 1950 consumer-protection overlay in § 16 below H4; § 16 below

Balance does not process sensitive personal data under PDPA section 40 (post-2024-Amendment expanded definition at section 4 — physical or mental health / political opinions / religious beliefs or other beliefs of a similar nature / commission or alleged commission of any offence / biometric data) in respect of any Malaysian resident.

Balance does not collect any Malaysian national or government-issued identification number — neither the MyKad number (the Malaysian Identity Card number issued under the National Registration Regulations 1990) nor the MyKid number (issued to under-12 Malaysian citizens) nor the passport number (issued under the Passports Act 1966) nor the driver's licence number. PDPA section 4 sensitive-data-equivalent treatment + the JPDP's interpretive practice on the collection of MyKad numbers impose strict purpose-limitation on the collection of such numbers; Balance's posture aligns: none collected.


5. Children's rights overlay

Malaysia does not have a children-specific data-protection statute equivalent to COPPA (US), GDPR Art 8, or Quebec Private Sector Act s 8.1, at the Effective date. The children's regime is built up from (i) the PDPA + the 2024 Amendment Act's recognition of processing of personal data of children as a triggering category at s 12A(1)(iv) + the PDP Commissioner Guideline on Appointment of Data Protection Officer (29 May 2025) and Guideline on Notification of Personal Data Breach (29 May 2025); (ii) the Federal Constitution Article 5 read with Sivarasa Rasiah; (iii) the Child Act 2001 (Act 611); (iv) the Sexual Offences Against Children Act 2017 (Act 792) + the Penal Code (Act 574) sexual-offences chapter; (v) the Age of Majority Act 1971 age 18; (vi) the Contracts Act 1950 s 11 minor-incapacity doctrine; (vii) the UN Convention on the Rights of the Child (Malaysia acceded with reservations on 17 February 1995, principal reservations on Arts 2 + 7 + 14 + 28(1)(a) + 37 withdrawn or modified in subsequent declarations).

5.1 Definitions

For the purposes of this Annex:

Balance applies the most-protective reading and obtains Verifiable Parental Consent for every Malaysian kid regardless of age, using the VPC mechanism in United States annex § 5 (email-verified parent account creation + payment-method capture at subscription time + parent's affirmative in-app action of creating the kid profile and pairing the kid's device). The VPC screen for Malaysian residents itemises the categories of personal data being processed, the purposes for which it is being processed, the third parties to whom it may be disclosed (sub-processors), and the data subject's rights under the PDPA + Federal Constitution Article 5 + the common-law privacy doctrine.

Balance does not provide a kid-self-serve consent path inside the app. The parent always consents on behalf of the kid; the kid app's UI is designed for the kid to see their own limits, schedules, tasks, and earned-time ledger, and to request changes through the in-app "request change" affordance, which is forwarded to the parent device for the parent's decision. This is the most-protective reading of the PDPA + the PDP Commissioner Guideline on Appointment of Data Protection Officer + the Contracts Act 1950 s 11 minor-incapacity doctrine + the Age of Majority Act 1971 + the Child Act 2001.

5.4 No advertising directed at children

Balance does not display advertising to any user (parent or kid), does not allow any third party to display advertising in Balance, and does not build a behavioural-advertising data file of any user. This is consistent with: (i) the PDPA section 43 right to prevent processing for direct marketing; (ii) the Communications and Multimedia (Anti-Spam) Regulations 2013; (iii) the CPA 1999 Part II prohibition on misleading or deceptive conduct + Part IIIA unfair contract terms; (iv) the MCMC Code on Advertising + the MCMC Code of Conduct (Industry Code) for the Communications and Multimedia Industry Malaysia. Cross-references: the Play Console Data Safety form § 2 (Contains ads: No); the Play Console Child Safety Standards declaration § 3 ATTESTATION-D.

5.5 Cooperation routes

The principal Malaysian child-protection bodies are: (i) the Department of Social Welfare (JKM) — the principal child-welfare lead agency under Child Act 2001 + Talian Kasih 15999 24/7 hotline; (ii) the Royal Malaysia Police — Sexual Crimes, Children and Domestic Violence Investigation Division (D11) + the PDRM Cyber Crime and Multimedia Investigation Division; (iii) the Ministry of Women, Family and Community Development (KPWKM) — the SOACA implementing ministry; (iv) CyberSecurity Malaysia (CSM) — national CERT for cyber-incident coordination; (v) SUHAKAM Children's Commissioner; (vi) the National Council for Child Welfare under Child Act 2001 s 3; (vii) NGO partners — Childline Foundation Malaysia, Protect and Save the Children (PS) Malaysia, PEMBELA, WAO (Women's Aid Organisation), Befrienders KL 03-7956 8145, MIASA, CyberSAFE Malaysia. Balance cooperates with each on incidents involving Malaysian kids — see § 14 below.


6. PDPA rights catalogue

6.1 The rights catalogue

A Malaysian resident has the following rights under the PDPA + the 2024 Amendment Act + the PDP Commissioner Guidelines (29 May 2025 series) as in force at the Effective date.

6.2 Timeline

Where the data-access carve-outs at PDPA section 32 apply (national security / prevention or detection of crime / regulatory enforcement / professional confidentialities / mental-health-of-data-subject), Balance may decline to provide access and explain the reasons.

6.3 Identity verification

Where there is reasonable doubt about the identity of the natural person making the request, Balance may request additional information necessary to confirm the identity. The identity-verification protocol uses the parent's existing authentication credential.

6.4 Fees

Under PDPA section 28(2) + the Personal Data Protection (Fees) Regulations 2013, a data user may charge a prescribed fee for processing a data access request (the prescribed fee is RM 10 for the first request and RM 50 per request for subsequent requests in the same 12-month period, subject to upward adjustment in the data user's reasonable discretion). Balance does not charge for access in practice.

6.5 Language

A request may be submitted in Bahasa Malaysia or English. The JPDP accepts complaints in Bahasa Malaysia and English.


7. Children's data — PDPA + Child Act 2001 + Contracts Act 1950 + Age of Majority Act 1971

Balance processes personal data of Malaysian kids under the following layered framework:

For Balance:

A parent may revoke consent at any time at Settings → Family → [kid name] → "Delete this kid" (or by email to ). Revocation triggers the cascade documented in Data Retention & Deletion Policy § 7. Revocation does not affect the lawfulness of processing carried out before the revocation.


8. International data transfers from Malaysia — PDPA s 129 + PDP Commissioner Guideline on Cross-Border Personal Data Transfer (29 May 2025)

The controller (BabaYaga Program, TOO) is established in Kazakhstan. The backend (Emergent Labs Inc.) is hosted in the United States. Proof-media storage (Google Cloud Storage) is in the United States. Push (Firebase Cloud Messaging), sign-in (Google Sign-In), and billing (Google Play Billing) are operated by Google LLC and dispatched from the United States. Transactional email (Resend) is dispatched from the United States. Accordingly, every Malaysian resident's personal data leaves Malaysia at the point of being uploaded to the Balance backend.

8.1 The Malaysia-to-US transfer mechanism — PDPA section 129 (post-2024-Amendment) + the PDP Commissioner Guideline on Cross-Border Personal Data Transfer

PDPA section 129 as amended by the 2024 Amendment Act is the operative cross-border-transfer provision. The 2024 Amendment Act abolished the pre-existing whitelist mechanism (under which the pre-amendment section 129(1) listed jurisdictions to which transfer was authorised, with a long-standing operational anomaly that no Federal Government Gazette had ever specified the whitelist) and replaced it with a more flexible accountability-based mechanism with the PDP Commissioner Guideline on Cross-Border Personal Data Transfer of 29 May 2025 as the operational anchor.

Under the post-2024-Amendment section 129 + the Guideline, a data user may transfer personal data to a place outside Malaysia where the data user has taken reasonable steps to ensure that the personal data will not be processed in any manner that contravenes the PDPA. The Guideline identifies the following operational mechanisms as satisfying the reasonable steps test:

Balance relies on the following stack to satisfy PDPA s 129 + the Guideline:

8.2 The Malaysia-to-KZ axis (controller administrative access)

The controller's personnel in Kazakhstan have administrative access to the US-hosted backend for operational purposes. Because Kazakhstan is a third country, the Malaysia-KZ axis is covered by the PDPA s 129 limb (b) written contracts with safeguards equivalent to the PDPA + limb (d) parent's consent overlay + limb (e) performance-of-contract necessity — written processor agreements signed between Emergent Labs (as processor) and BabaYaga Program, TOO (as controller) in inverse, with EU-SCC substance + ASEAN Model Contractual Clauses substance preserved. The transfer-impact analysis for the KZ leg is in our international-transfer pack § 7.

8.3 PDPA Part III data-user registration

PDPA Part III (ss 13–20) + the Class of Data Users Order 2013 + Amendment Order 2016 require data users within prescribed classes to register with the PDP Commissioner. The JPDP's interpretive practice for foreign data users without permanent Malaysian establishment is documented in JPDP guidance: foreign data users are not required to register their data-user activity but remain subject to the PDPA's substantive obligations including the PDPP framework, the section 12A DPO obligation, and the section 12B breach-notification obligation. Balance accordingly does not register as a data user with the JPDP at the Effective date and tracks this in the placeholder tracker. Should the JPDP's interpretive practice change or should Balance establish a permanent Malaysian presence, registration will follow via the JPDP's data-user-registration portal.

8.4 APEC CBPR overlay (context-setting)

Malaysia formally joined the operational APEC CBPR system + the APEC PRP (Privacy Recognition for Processors) on 12 May 2022. The APEC CBPR system provides a complementary accountability framework for cross-border data transfers within the APEC region (which includes Malaysia, Singapore, the Philippines, the United States, Canada, Japan, the Republic of Korea, Mexico, Taiwan, and Australia at the Effective date). Balance's principal operational mechanism remains the PDPA s 129 limb (b) written contracts framework + the Guideline on Cross-Border Personal Data Transfer; the APEC CBPR + PRP framework is a context-setting overlay.

8.5 ASEAN Model Contractual Clauses for Cross Border Data Flows (January 2021)

Malaysia is an ASEAN Member State + a signatory to the ASEAN Framework on Personal Data Protection (2016) + the ASEAN Data Management Framework. The ASEAN Model Contractual Clauses for Cross Border Data Flows (January 2021) provide a recommended-form contractual-clauses template usable across ASEAN Member States. Balance's sub-processor agreements incorporate the substance of the ASEAN Model Contractual Clauses as a substantive overlay (see our international-transfer pack § 6).


9. Data residency for Malaysian residents

Question Answer
Where is the backend hosted? United States. Emergent Labs Inc. (Delaware) on US infrastructure.
Where is the MongoDB database located? United States.
Where is the proof-media storage located? United States — Google Cloud Storage us multi-region.
Where are push notifications dispatched from? United States — Firebase Cloud Messaging.
Is any Malaysian resident's personal data held in Malaysia? No. Every Malaysian resident's personal data is held in the United States. The PDPA s 129 limb (b) written contracts + limb (d) parent's consent + limb (e) performance-of-contract necessity stack in § 8 above is the legal basis for the transfer.
Where is the controller? Kazakhstan (BabaYaga Program, TOO). The controller has administrative access to the US-hosted backend via written processor agreements.
Is there a Malaysian establishment? No. Balance has no permanent establishment in Malaysia. The PDPA's territorial reach (s 3(1) equipment in Malaysia limb, broadened by the 2024 Amendment Act) is the basis for Balance's PDPA compliance.
Where is the supervisory authority? Malaysia — JPDP + Ministry of Digital + the regulatory bodies in § 3.3 above.

The decision to centralise on a US-only backend is documented in our internal compliance plan § 6. Malaysia does not impose a comprehensive data-localisation mandate on parental-control services at the Effective date, with the exception of certain sector-specific regimes (e.g., the Bank Negara Malaysia directives on outsourcing by Malaysian banks — not applicable to Balance; the Securities Commission Malaysia directives — not applicable to Balance; certain Health Ministry directives on healthcare data localisation — not applicable to Balance).


10. Sub-processors touching Malaysian-resident data

Sub-processor Role Location of processing Malaysian transfer paperwork
Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (MongoDB, Inc., US) for the production database; relationship governed by Emergent ToS (22 Dec 2025) + Privacy Policy (28 May 2026) as the GDPR Art 28(3) "other legal act" (no standalone DPA available outside Enterprise per Emergent final position 2026-06-10; full handling in our internal vendor-handling plan); MongoDB Atlas Customer DPA + EU SCCs Module 2 + UK IDTA Addendum at https://www.mongodb.com/legal/dpa cover the storage layer Hosts the FastAPI backend + MongoDB cluster United States PDPA s 129 limb (b) written processor agreement with PDPA-equivalent safeguards + limb (d) parent's consent on file per our international-transfer pack § 6; E2EE supplementary measure for proof media; ASEAN Model Contractual Clauses substance.
Google LLC — Google Cloud Storage (USA) Stores end-to-end-encrypted proof-media ciphertext United States (us multi-region) PDPA s 129 limb (b) written processor agreement (Google Cloud Data Processing Addendum) + limb (d) consent; ciphertext-only handling.
Google LLC via Google Cloud (USA) Periodic (daily) backups of our operational database United States (us multi-region) PDPA s 129 limb (b) written processor agreement (Google Cloud Data Processing Addendum) + limb (d) consent; the backup archive holds the operational data we hold about the resident (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens), other than the items that never reach our backend in readable form (the kid's proof media and the media-encryption keys); retained on a 30-day rolling window, then automatically deleted.
Google LLC — Firebase Cloud Messaging Delivers push notifications to Malaysian kid + parent devices United States PDPA s 129 limb (b) + limb (d) as above; push body deliberately free of sensitive content (cross-reference: the just-in-time permission disclosures).
Google LLC — Google Sign-In Authenticates parent Google identity (when used) United States PDPA s 129 limb (b) + limb (d) as above.
Google LLC — Google Play Billing Processes subscription purchases United States PDPA s 129 limb (b) + limb (d) + Google Play Developer Distribution Agreement.
Resend, Inc. (San Francisco, CA, USA) Delivers transactional email to Malaysian parent users United States PDPA s 129 limb (b) + limb (d).

Every sub-processor is bound by a written data-processing agreement that forbids processing of any data we transmit for any purpose other than performing the service we engaged them for, and that incorporates the security and confidentiality controls in our Records of Processing Activities (Article 30) § 7 + PDPA s 9 PDPP 4 + PDP Standards 2015. The full sub-processor list, with each row's processor-agreement status, is at our sub-processor register.


11. Breach notification — PDPA section 12B (2024 Amendment Act) + PDP Commissioner Guideline on Notification of Personal Data Breach (29 May 2025)

PDPA section 12B (introduced by the 2024 Amendment Act, in force from 1 June 2025) + the PDP Commissioner Guideline on Notification of Personal Data Breach of 29 May 2025 is the principal breach-notification regime. The Malaysian regime requires 72-hour PDP Commissioner notification from awareness of a significant personal data breach:

Audience Trigger Deadline Channel
PDP Commissioner A significant personal data breach has occurred — defined by PDPA s 12B + the Guideline on Notification of Personal Data Breach as a breach of the PDPP 4 security obligation that involves (a) personal data of a significant number of data subjects (the Guideline references a threshold of approximately 1,000 data subjects as the operational anchor + scaled to the data user's normal processing volume) OR (b) sensitive personal data OR (c) data that is likely to cause significant harm to the data subjects OR (d) circumstances of significant operational complexity. 72 hours from awareness of the significant data breach. Awareness is the time at which the data user has a reasonable degree of certainty that a personal data breach has occurred. Balance internal anchor: as soon as practicable but no later than 72 hours from initial discovery. JPDP Personal Data Breach Notification portal + by email to aduan@pdp.gov.my
Affected individuals A significant personal data breach as above where, on the harm-likelihood analysis under PDPA s 12D + the Guideline, affected-individual notification is warranted to allow the affected individuals to take protective measures. As soon as practicable after PDP Commissioner notification, with carve-outs in the Guideline (where the data has been rendered unintelligible — e.g., the E2EE ciphertext case — affected-individual notification may not be warranted; where the PDP Commissioner directs otherwise). Direct email to the affected parent on file; in-app banner where the parent is logged in; out-of-app contact via the public-website incident page if email is no longer deliverable. The notification is in English, with a Bahasa Malaysia version queued for the Phase-2 locale rollout.
CSAE-specific An incident with a CSAE component. Per § 14 below + the internal runbook (M1). PDRM D11 + JKM + KPWKM + CSM.

The internal breach-decision SLA is at our breach-notification runbook § 5.4 + § 9: preliminary classification within one business day, formal assessment under PDPA s 12B + Guideline completed within 48 hours of discovery for significant-data-breach escalation, PDP Commissioner notification within the 72-hour statutory window, affected-individual notification per the harm-likelihood analysis.

11.1 Minimum content of the PDP Commissioner notification (PDPA s 12C + PDP Commissioner Guideline on Notification of Personal Data Breach)

The PDP Commissioner notification states: - the nature of the significant personal data breach, the description of how the breach occurred, the personal data possibly involved, the chronology of the events leading up to the loss of control of the personal data; - the categories and approximate number of data subjects involved (or the best estimate); - the description of the likely consequences of the breach; - the measures taken or proposed to be taken to address the breach (including measures to mitigate possible harm or negative consequences); - the name and contact details of the DPO (, named individual: ) — the contact from whom the affected data subjects may obtain additional information.

The English-language template lives in our breach-notification runbook § 8.1. A Bahasa Malaysia version is queued for Phase 2 locale rollout.

11.2 Non-compliance — PDPA Part IX + Part VII offences

11.3 Concurrent CMA-1998 notification

For incidents involving network facilities or network services, the Communications and Multimedia (Anti-Spam) Regulations 2013 + the MCMC operational guidance on cyber-incident handling may require concurrent MCMC notification. Balance is not a CMA licensee and the concurrent-MCMC-notification pathway is unlikely to be engaged for ordinary breach scenarios.


12. Cookies, spam, and electronic direct marketing

Malaysia does not have a dedicated ePrivacy / cookies statute. The substantive position on cookies and electronic direct marketing is derived from: (i) PDPA s 6 + s 7 + s 8 for any cookie that processes personal data; (ii) the PDP Commissioner's interpretive position on cookies in the Guideline on Data Subject's Rights including Data Portability of 29 May 2025 and broader interpretive practice; (iii) the Communications and Multimedia (Anti-Spam) Regulations 2013 for commercial electronic messages; (iv) PDPA section 43 right to prevent processing for direct marketing.

12.1 In-app — strictly-necessary storage only

The Balance app (parent and kid) does not deploy any cookie-equivalent storage that is not strictly necessary for the service. The strictly-necessary storage Balance uses (authentication tokens in Android SecureStore; the device-pairing key wrap; the kid app's earned-time cache) is operationally necessary and is covered by the parent's sign-up consent.

The public legal-documents site (balance.babayagaprogram.com) uses only strictly-necessary cookies; no analytics cookies; no advertising cookies; no third-party trackers; no fingerprinting; no embedded social plugins.

12.3 Electronic direct marketing — not sent

Balance does not send commercial electronic messages within the meaning of the Communications and Multimedia (Anti-Spam) Regulations 2013 to Malaysian residents. The only email Balance sends to Malaysian parent users is transactional — account creation, password reset, subscription receipts, security alerts, and parent-action notifications. The Anti-Spam Regulations commercial electronic message definition requires the message to promote or solicit the supply of goods or services for a commercial purpose; transactional messages are outside the definition. If Balance ever introduces a marketing channel, we will comply with the Anti-Spam Regulations: (i) prior consent from the recipient (opt-in); (ii) clear identification of the sender; (iii) a clearly-identified opt-out mechanism in the body; (iv) honour an opt-out request within a reasonable time. We will also comply with PDPA section 43 right to prevent processing for direct marketing.

12.4 No telemarketing

Balance does not place telemarketing voice calls, SMS, or messaging-app outreach to Malaysian residents.


13. Lawful-access requests and the encryption posture

Malaysian authorities may serve a lawful-access request on Balance via:

The Balance architectural posture interacts with these mechanisms as follows:

The full encryption posture is in our encryption-posture record.


14. CSAE reporting routes — Malaysia

A Malaysian resident (parent, kid, or third party) who wishes to report a CSAE concern about Balance, about a third party encountered outside Balance, or about a Balance user, may use any of the following routes:

The full CSAE Country Routing Table is in Child Safety Standards § 8.6.


15. Complaint routes (summary)

A Malaysian resident who is dissatisfied with Balance's handling of a privacy enquiry or a child-safety concern may complain to any of the following authorities:

Authority Subject matter Address / URL
Personal Data Protection Department (JPDP) PDPA Aras 6, Kompleks Kementerian Komunikasi dan Digital, Lot 4G9, Persiaran Perdana, Presint 4, 62100 Putrajaya; https://www.pdp.gov.my/; +60 3 8911 7000; aduan@pdp.gov.my
Ministry of Digital JPDP parent ministry Aras 1-4, Blok B, Kompleks Kementerian Komunikasi dan Digital, Lot 4G9, Persiaran Perdana, Presint 4, 62100 Putrajaya; https://www.digital.gov.my/
Personal Data Protection Appeal Tribunal Appeals from PDP Commissioner decisions under PDPA Part XI via JPDP
Malaysian Communications and Multimedia Commission (MCMC) CMA 1998 + Anti-Spam Regulations https://www.mcmc.gov.my/; 1-800-188-030
Royal Malaysia Police — D11 + Cyber Crime Division CSAE + cybercrime https://www.rmp.gov.my/; emergency 999; non-emergency 03-2266 2222
Ministry of Women, Family and Community Development (KPWKM) SOACA implementing ministry; Talian Kasih 15999 https://www.kpwkm.gov.my/
Department of Social Welfare (JKM) Child Act 2001 child-protection https://www.jkm.gov.my/; Talian Kasih 15999
Ministry of Domestic Trade and Cost of Living (KPDN) Consumer Protection Act + Electronic Trade Transactions Regulations https://www.kpdn.gov.my/; 1-800-886-800
Tribunal for Consumer Claims (TTPM) Small consumer claims up to RM 50,000 https://ttpm.kpdn.gov.my/
CyberSecurity Malaysia (CSM) / MyCERT Cyber-incident handling https://www.cybersecurity.my/; Cyber999 Help Centre 1-300-88-2999
SUHAKAM Independent human-rights advocacy + Children's Commissioner https://www.suhakam.org.my/; +60 3 2612 5600
Sessions Court PDPA Part IX civil action up to RM 250,000; SOACA + Child Act 2001 prosecutions via https://www.kehakiman.gov.my/
High Court of Malaya / High Court of Sabah and Sarawak PDPA Part IX civil action above Sessions Court limits; judicial review; PDP Commissioner + Appeal Tribunal appeals via https://www.kehakiman.gov.my/
Court of Appeal Appellate review via https://www.kehakiman.gov.my/
Federal Court of Malaysia Final appellate review on points of law; constitutional matters https://www.kehakiman.gov.my/

A Malaysian resident may always first raise the matter with us at (data access; named individual: , in his capacity as the DPO under PDPA s 12A + the PDP Commissioner Guideline on Appointment of Data Protection Officer of 29 May 2025). We will respond within the PDPA timelines. The JPDP's published policy recommends raising the matter with the data user first but the JPDP also accepts direct complaints where the data subject demonstrates that internal-remedy exhaustion is impracticable or where the complaint involves a serious matter warranting immediate JPDP action.


16. Consumer rights — the CPA 1999 + Electronic Trade Transactions Regulations + Sale of Goods Act 1957 + Contracts Act 1950 overlay

The Consumer Protection Act 1999 (Act 599) (the "CPA 1999"), the Consumer Protection (Electronic Trade Transactions) Regulations 2012 (the "ETT Regulations 2012"), the Sale of Goods Act 1957 (Act 382) ("SGA 1957"), and the Contracts Act 1950 (Act 136) apply to Balance's subscription flow as a consumer transaction (the parent is a consumer within the CPA 1999 s 3 definition — using goods or services ordinarily acquired for personal, domestic or household purposes). Treatment is implemented in Subscription Terms § 20.

16.1 CPA 1999 Part II — misleading or deceptive conduct + false representations + unfair practices

CPA 1999 section 9 prohibits misleading or deceptive conduct in trade in relation to goods or services. CPA 1999 section 10 prohibits false or misleading representations. CPA 1999 sections 11–18 prohibit specific unfair practices. The Balance Terms of Service (Terms of Service) and the in-app subscription flow are drafted to avoid each section 9–18 risk.

16.2 CPA 1999 Part IIIA — unfair contract terms

CPA 1999 Part IIIA (introduced by the Consumer Protection (Amendment) Act 2010 in force 1 July 2010) prohibits unfair contract terms in consumer contracts: - s 24A definition of unfair contract terms (procedurally unfair / substantively unfair) — drawn broadly with detailed indicia at ss 24C–24E. - s 24C procedural unfairness factors (relative bargaining position + extent of negotiation + extent of understanding + standard-form character). - s 24D substantive unfairness factors (against good faith / good conscience / equity / community standards of fairness). - s 24E other relevant matters. - s 24G — Tribunal for Consumer Claims and the Court have power to declare any contract term to be unfair + to refuse to enforce + to limit or modify.

Balance's Terms of Service and Subscription Terms are drafted to comply with CPA 1999 Part IIIA. Choice-of-law clauses or jurisdiction clauses that would deprive the Malaysian consumer of mandatory protection are subject to CPA 1999 s 24A + s 24D + the public policy doctrine in Cap n° 4 Allwood Ltd v Yong Sek Choo [2017] MLJU 678.

16.3 Consumer Protection (Electronic Trade Transactions) Regulations 2012 — supplier disclosure

The ETT Regulations 2012 require the supplier in an electronic trade transaction to disclose, in a prominently displayed manner: (i) the supplier's name + business address + means of contact (Reg 3(1)(a)); (ii) the nature of the goods or services (Reg 3(1)(b)); (iii) the price including taxes + the delivery and payment terms (Reg 3(1)(c)); (iv) the cancellation and refund policy (Reg 3(1)(d)); (v) the delivery method and time (Reg 3(1)(e)); (vi) terms of supply (Reg 3(1)(f)); (vii) the consumer's privacy rights and the supplier's policies on data protection (Reg 3(1)(g)). Balance's pre-contract subscription screen + the in-app subscription terms + the Subscription Terms document (Subscription Terms) implement each disclosure.

16.4 CPA 1999 Part IX — non-excludable services guarantees

CPA 1999 Part IX prescribes non-excludable guarantees in the supply of services: - s 53 guarantee as to reasonable care and skill; - s 54 guarantee as to fitness for particular purpose; - s 55 guarantee as to reasonable time; - s 56 guarantee as to reasonable price.

Applied to Balance's subscription supply as the supply of services to a consumer; reasonable care + skill + fitness + reasonable time + reasonable price are non-excludable guarantees of the subscription contract. Section 64 prohibits contracting out of the Part IX guarantees in any consumer contract.

16.5 No statutory cooling-off period under Malaysian general law for online subscription contracts

Malaysian general consumer-protection law does not include a statutory cooling-off period for distance-selling contracts (in contrast with the SG CPFTA, the IL Consumer Protection Law s 14C 14-day cooling-off, the AR CDC 10-business-day botón de arrepentimiento, the EU Consumer Rights Directive 14-day right of withdrawal, and similar regimes). Specific sector-specific cooling-off rules apply to certain product categories (e.g., direct-sales contracts under the Direct Sales and Anti-Pyramid Scheme Act 1993 (Act 500) + the Direct Sales (Door-to-Door Sales)(Conduct) Regulations 1993 — n/a to Balance because Balance is not a direct seller). Balance honors a voluntary 14-day no-questions refund window via Google Play Billing, exceeding the Malaysian general-consumer-protection minimum.

16.6 Refunds and the Malaysian subscription posture

Balance honors a voluntary 14-day no-questions refund window via Google Play Billing, exceeding the Malaysian consumer-protection minimum. The 14-day refund window is documented at Subscription Terms § 20.

16.7 Contracts Act 1950 — capacity-of-minors framework + Age of Majority Act 1971

Under Contracts Act 1950 s 11 + Age of Majority Act 1971 s 2, a kid (under 18) cannot enter into a binding contract. The subscription contract is between Balance and the parent (who is 18+ — the Age of Majority Act 1971 confirms the age of majority). The kid is a beneficiary of the service supplied to the parent. Balance does not contract directly with kids.

16.8 Forum and choice of law

The Balance Terms of Service preserve the consumer's domicile forum (see Terms of Service § 19); choice-of-law clauses that would displace CPA 1999 to the prejudice of the Malaysian consumer are subject to CPA 1999 s 64 (no contracting out) + CPA 1999 Part IIIA unfair-contract-terms screen + the public policy doctrine.


17. Cross-references


18. Versioning and review

This Annex follows the same strict versioning protocol as the rest of the Phase-1 bundle:


End of Malaysia Country Annex.

← Back to Privacy Policy · Children's Privacy Notice