Balance — Malaysia Country Annex
Effective date: 28 June 2026 Last updated: 28 June 2026
Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every Malaysian resident covered by this Annex; the Data Protection Officer ("DPO") for the purposes of Personal Data Protection Act 2010 (Act 709) ("PDPA") section 12A (introduced by the Personal Data Protection (Amendment) Act 2024 (Act A1709) — the "2024 Amendment Act" — gazetted on 17 October 2024 with phased commencement; section 12A is among the provisions in force from 1 June 2025 pursuant to the Personal Data Protection (Amendment) Act 2024 (Commencement) Order 2025 — § 18 versioning protocol covers any further phased commencement) read with the Personal Data Protection Commissioner Guideline on Appointment of Data Protection Officer (Reference No. JPDP-100-1/12/01-1, issued by the Pesuruhjaya Perlindungan Data Peribadi / Personal Data Protection Commissioner — the "PDP Commissioner" — on 29 May 2025, in operation from 1 June 2025), with business contact published as the publicly-accessible DPO contact required by PDPA section 12A(3) + the DPO Guideline § 5; the designated contact point for the Personal Data Protection Department (Bahasa Malaysia: Jabatan Perlindungan Data Peribadi, the "JPDP"), the Malaysian Communications and Multimedia Commission (Bahasa Malaysia: Suruhanjaya Komunikasi dan Multimedia Malaysia, the "MCMC"), the Royal Malaysia Police — Sexual Crimes, Children and Domestic Violence Investigation Division (D11) (Bahasa Malaysia: Polis Diraja Malaysia — Bahagian Siasatan Jenayah Seksual, Kanak-Kanak dan Keganasan Rumah Tangga (D11)), the Royal Malaysia Police — Cyber Crime and Multimedia Investigation Division (Bahasa Malaysia: Bahagian Siasatan Jenayah Komersil — Unit Siasatan Jenayah Siber dan Multimedia), the Department of Social Welfare (Bahasa Malaysia: Jabatan Kebajikan Masyarakat, the "JKM"), and CyberSecurity Malaysia (the national CERT) under their respective intake protocols.
Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to the Personal Data Protection Act 2010 (Act 709) ("PDPA") including the entry into force of any provision of the Personal Data Protection (Amendment) Act 2024 (Act A1709) (the "2024 Amendment Act") that is not yet operationally in force at the Effective date (the principal substantive provisions of the 2024 Amendment Act are in force from 1 June 2025 pursuant to the Personal Data Protection (Amendment) Act 2024 (Commencement) Order 2025 — including the section 12A mandatory DPO appointment + the section 12B mandatory data breach notification regime + the section 43A data portability right + the direct obligations on data processors at section 4 + the increased penalties at section 5 to greater of RM 1 million fine or 3 years imprisonment + the abolition of the s 130 whitelist transfer mechanism — but a set of subsidiary instruments under the 2024 Amendment Act remain to be issued; § 18 versioning protocol covers their issuance); (b) any amendment to the seven Personal Data Protection Principles at PDPA Part II (the "PDPPs") — PDPP 1 General Principle (s 6 lawful processing + consent + necessary-for-purpose) / PDPP 2 Notice and Choice Principle (s 7) / PDPP 3 Disclosure Principle (s 8) / PDPP 4 Security Principle (s 9) / PDPP 5 Retention Principle (s 10) / PDPP 6 Data Integrity Principle (s 11) / PDPP 7 Access Principle (s 12); (c) any Code of Practice, Guideline, Directive, or Determination issued by the PDP Commissioner under PDPA sections 23–28 — including the Guideline on Appointment of Data Protection Officer (29 May 2025), the Guideline on Notification of Personal Data Breach (29 May 2025), the Guideline on Cross-Border Personal Data Transfer (29 May 2025), the Guideline on Data Protection Impact Assessment (29 May 2025), the Guideline on Data Subject's Rights including Data Portability (29 May 2025), the Personal Data Protection Standards 2015 (the "PDP Standards 2015"), the Personal Data Protection Code of Practice for the Communications Sector + sectoral Codes of Practice for additional sectors, the Personal Data Protection (Class of Data Users) Order 2013 and the Personal Data Protection (Class of Data Users) (Amendment) Order 2016 (collectively, the "Class of Data Users Orders"), the Personal Data Protection (Compounding of Offences) Regulations 2013, the Personal Data Protection (Fees) Regulations 2013, and the Personal Data Protection Regulations 2013; (d) any decision of the Sessions Court, High Court, Court of Appeal, or Federal Court of Malaysia bearing on the PDPA, on Federal Constitution Article 5 read with Sivarasa Rasiah v Badan Peguam Malaysia [2010] 2 MLJ 333 (Federal Court of Malaysia — establishing that the right to life under Article 5 includes the right to privacy), or on the common-law privacy doctrines applied by Malaysian courts; (e) any amendment to the Child Act 2001 (Act 611) (the principal Malaysian child-welfare statute, in force from 1 August 2002, substantively amended by the Child (Amendment) Act 2016); (f) any amendment to the Sexual Offences Against Children Act 2017 (Act 792) ("SOACA") in force from 10 July 2017 — in particular sections 4 (child pornography offences), 5 (production and direction of child pornography), 6 (preparation of child pornography), 8 (using a child for child pornography), 10 (assault or use of criminal force on a child with sexual intent), 11 (sexual communication with a child + the principal online grooming offence), 12 (sexual extortion of a child), 13 (physical sexual assault on a child), 14 (non-physical sexual assault on a child), 15 (sexual assault on a child by person in a relationship of trust); (g) any amendment to the Penal Code (Act 574), in particular section 375 (rape) + section 375B (gang rape) + section 376 (punishment for rape) + section 376B (incest) + section 377A-377CA (carnal intercourse against the order of nature and related offences) + section 377D (gross indecency) + section 377E (incitement of child to act of gross indecency) + sections 509 (word or gesture intended to insult the modesty of any person); (h) any amendment to the Computer Crimes Act 1997 (Act 563), in particular section 3 (unauthorised access to computer material), section 4 (unauthorised access with intent to commit or facilitate further offences), section 5 (unauthorised modification of contents of any computer), and section 6 (wrongful communication); (i) any amendment to the Communications and Multimedia Act 1998 (Act 588), in particular section 211 (prohibition on provision of offensive content), section 233 (improper use of network facilities or network service), and Part X (powers of investigation); (j) any amendment to the Sedition Act 1948 (Act 15) or the Communications and Multimedia (Amendment) Act 2024 (the "CMA 2024 Amendment" — passed 11 December 2024 with phased commencement; introducing licensing for designated online platforms with 8 million Malaysian-resident users and child-safety obligations for relevant platforms — Balance is below the threshold and is not a designated platform); (k) any amendment to the Consumer Protection Act 1999 (Act 599), the Consumer Protection (Electronic Trade Transactions) Regulations 2012, the Contracts Act 1950 (Act 136), the Sale of Goods Act 1957 (Act 382), or the Age of Majority Act 1971 (Act 21) (collectively the principal Malaysian consumer-protection and contract-capacity statutes); (l) any amendment to the Communications and Multimedia (Anti-Spam) Regulations 2013 under the CMA 1998; (m) any amendment to a sub-processor's Malaysian data-handling posture under our sub-processor register; (n) the bringing into force of any post-Effective-date Malaysian regulation governing automated processing or related techniques (covered by the deliberate-silence carve-out in § 2 of this Annex); (o) Malaysia's accession to (or domestic implementation of) the Council of Europe Convention 108 / Convention 108+ (Malaysia is not currently a party) or the Convention on Cybercrime (Budapest Convention, Malaysia is not currently a party — § 18 versioning protocol covers any change in that status); (p) any amendment to the Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (Act 613) (AMLA) insofar as it engages production orders against data users; (q) any Federal Government Gazette notification by the Yang di-Pertuan Agong + Cabinet under PDPA section 130 regarding cross-border transfer mechanisms or Cabinet Order effecting the abolition of the legacy whitelist mechanism following the 2024 Amendment Act.
Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.
This Annex discharges the country-annex obligations referenced in:
- Privacy Policy § 18 (Country annexes — Malaysia row).
- Children's Privacy Notice § 14 (Country annexes — Malaysia row).
- Child Safety Standards § 13 (Country annexes — Malaysia row).
- Terms of Service § 19 (Malaysia consumer-protection carve-out under the Consumer Protection Act 1999 (Act 599) + the Consumer Protection (Electronic Trade Transactions) Regulations 2012 + the Contracts Act 1950 (Act 136) + the Sale of Goods Act 1957 (Act 382) — and the Age of Majority Act 1971 (Act 21) for parent contracting capacity).
- Subscription Terms § 20 (Malaysia consumer-rights overlay — Consumer Protection Act 1999 + Consumer Protection (Electronic Trade Transactions) Regulations 2012 + Sale of Goods Act 1957 + Contracts Act 1950; no statutory cooling-off period for general distance contracts but voluntary 14-day no-questions Google Play Billing refund as market-leading consumer-protection overlay).
- Data Retention & Deletion Policy § 14 (Malaysia PDP Commissioner complaint route).
- our breach-notification runbook § 9 (Malaysia mandatory data-breach-notification route under PDPA section 12B as introduced by the 2024 Amendment Act — 72 hours from awareness of a significant data breach, per the PDP Commissioner Guideline on Notification of Personal Data Breach of 29 May 2025).
- our international-transfer pack § 6 (PDPA section 129 cross-border-transfer mechanism + the PDP Commissioner Guideline on Cross-Border Personal Data Transfer of 29 May 2025).
This Annex is the canonical Malaysian-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants a Malaysian resident a right that the global Policy does not, this Annex governs. Where the global Policy grants a Malaysian resident a right that this Annex does not, the global Policy governs. The two are read together.
This Annex is drafted in English. The national language of the Federation of Malaysia under Federal Constitution Article 152(1) is Bahasa Malaysia (also known as Bahasa Melayu or Malay); English is permitted for any official purpose under Article 152(2)–(5) without prejudice to the national-language status of Bahasa Malaysia and is in practice widely used in commerce and law. Mandarin Chinese and Tamil are languages of significant Malaysian communities. Bahasa Malaysia translation of this Annex is queued for the Phase-2 locale rollout per our internal compliance tracker; the Mandarin Chinese and Tamil translations are queued in the same Phase-2 rollout. No translation is statutorily required at the Effective date for the English-language privacy notice to a Malaysian resident (the PDPA does not mandate multilingual notification; the PDP Commissioner's interpretive practice accepts notices in Bahasa Malaysia or English provided the notice is intelligible to the data subject in light of the context).
1. Scope and applicability
This Annex applies to every Balance user (parent or kid) whose country of residence is Malaysia — the federation comprising 13 States (Johor / Kedah / Kelantan / Melaka / Negeri Sembilan / Pahang / Pulau Pinang / Perak / Perlis / Sabah / Sarawak / Selangor / Terengganu) and 3 Federal Territories (Kuala Lumpur / Labuan / Putrajaya). There is no State-level data-protection sub-layer that derogates from the PDPA in respect of Balance's commercial processing (the PDPA at section 3(2) excludes the Federal Government and the State Governments as data users, but Balance is a commercial data user and the PDPA applies in full).
We determine country of residence at install/sign-up time by (a) the country the parent self-declares in the in-app onboarding flow, (b) the IP-geolocation read at sign-up (which we discard immediately after the residence decision — our internal data-flow map § 2.1 stores no IP after the authentication request closes), and (c) the Play Store account locale that Google Play passes to us at install. The residence determination is reviewable at any time by the parent at Settings → Account → Region.
Where any of the three signals identifies Malaysia as the country of residence, this Annex applies, even if the other signals are non-Malaysian. The most-protective-for-the-data-subject reading is the controlling reading per our internal compliance plan § 6.3.
The PDPA has explicit territorial reach defined at section 2(1) + section 3(1) of the PDPA: the PDPA applies to any person who processes (or has control over or authorises the processing of) any personal data in respect of commercial transactions where the data user is established in Malaysia or the data user is not established in Malaysia but uses equipment in Malaysia for processing the personal data otherwise than for the purposes of transit through Malaysia. The 2024 Amendment Act broadened the operational reach by tightening the equipment in Malaysia limb and by extending direct obligations to data processors at section 4 (formerly an indirect-via-data-user concept). Balance squarely targets Malaysian residents through Google Play Malaysia, through publication of this Annex at balance.babayagaprogram.com, and through delivery of the parental-control service to Malaysian-resident parents and kids; the PDPA applies in respect of all personal data Balance processes in connection with Malaysian-resident users.
2. Statutory framework — what applies
The Malaysian personal-data-protection regime is dominated by the Personal Data Protection Act 2010 (Act 709) ("PDPA"), in force from 15 November 2013 for the principal substantive provisions, and substantively modernised by the Personal Data Protection (Amendment) Act 2024 (Act A1709) (the "2024 Amendment Act") gazetted 17 October 2024 with phased commencement (the principal substantive provisions are in force from 1 June 2025). The PDPA is supplemented by the Personal Data Protection Regulations 2013, the Personal Data Protection (Class of Data Users) Order 2013 + Amendment Order 2016, the Personal Data Protection (Compounding of Offences) Regulations 2013, the Personal Data Protection (Fees) Regulations 2013, the Personal Data Protection Standards 2015 (PDP Standards 2015), the PDP Commissioner's Guidelines and Codes of Practice, and the body of PDP Commissioner Determinations. Adjacent layers: the Federal Constitution of Malaysia Article 5 read with Sivarasa Rasiah v Badan Peguam Malaysia [2010] 2 MLJ 333 (Federal Court of Malaysia); the Child Act 2001 (Act 611); the Sexual Offences Against Children Act 2017 (Act 792); the Penal Code (Act 574); the Computer Crimes Act 1997 (Act 563); the Communications and Multimedia Act 1998 (Act 588); the Communications and Multimedia (Anti-Spam) Regulations 2013; the Consumer Protection Act 1999 (Act 599); the Consumer Protection (Electronic Trade Transactions) Regulations 2012; the Contracts Act 1950 (Act 136); the Sale of Goods Act 1957 (Act 382); the Age of Majority Act 1971 (Act 21).
| Instrument | Short cite | What it does | Balance's posture |
|---|---|---|---|
| Federal Constitution of Malaysia | Federal Constitution — the supreme law of the Federation under Article 4(1). Article 5 "No person shall be deprived of his life or personal liberty save in accordance with law" — interpreted by the Federal Court of Malaysia in Sivarasa Rasiah v Badan Peguam Malaysia [2010] 2 MLJ 333 (Federal Court) + Lee Kwan Woh v PP [2009] 5 MLJ 301 (Federal Court) + Maria Chin Abdullah v Ketua Pengarah Imigresen Malaysia & Anor [2021] 1 MLJ 750 (Federal Court) to include the right to privacy as part of life; Article 8 equality before the law; Article 10 freedom of speech and expression (subject to permitted restrictions); Article 121 the judicial power vested in the Superior Courts; Article 152 Bahasa Malaysia as the national language with English permitted for any official purpose. | The constitutional anchor. The right to privacy in Malaysia is constitutional (Article 5 via Sivarasa Rasiah) AND statutory (PDPA + adjacent regimes). | Applies as the constitutional layer. Treatment in §§ 3, 6, 13 below. |
| Personal Data Protection Act 2010 (Act 709) | PDPA — published in the Federal Government Gazette on 10 June 2010; principal substantive provisions in force from 15 November 2013; substantively modernised by the Personal Data Protection (Amendment) Act 2024 (Act A1709) gazetted 17 October 2024 with principal substantive provisions in force from 1 June 2025 pursuant to the Personal Data Protection (Amendment) Act 2024 (Commencement) Order 2025. Part I Preliminary (s 1 short title + extent + commencement; s 2 interpretation; s 3 application — does not apply to Federal/State Government in their data user capacity; s 3(1) territorial application: PDPA applies to processing of personal data in respect of commercial transactions where (a) data user established in Malaysia OR (b) data user not established in Malaysia but uses equipment in Malaysia for processing otherwise than for transit). Part II Personal Data Protection Principles (PDPPs) — seven principles operative: s 6 PDPP 1 General Principle (personal data shall not be processed without the consent of the data subject given for a specific and lawful purpose; carve-outs for performance of contract / legal obligation / vital interest of data subject / administration of justice / functions of public nature); s 7 PDPP 2 Notice and Choice Principle (data user must give written notice to data subject of identified purposes + categories of personal data + sources + recipients + data subject's rights including access and correction + obligations); s 8 PDPP 3 Disclosure Principle (no disclosure for any purpose other than purpose of collection or directly-related purpose without prior consent of data subject; no disclosure to third parties other than as identified in notice without consent); s 9 PDPP 4 Security Principle (practical steps to protect personal data from loss / misuse / modification / unauthorised or accidental access or disclosure / alteration / destruction); s 10 PDPP 5 Retention Principle (no longer than necessary); s 11 PDPP 6 Data Integrity Principle (accuracy + completeness + not misleading + up to date for purpose); s 12 PDPP 7 Access Principle (data subject right of access + correction). Part II ALSO contains section 12A — mandatory Data Protection Officer appointment (introduced by the 2024 Amendment Act, in force from 1 June 2025 — data user must appoint a DPO where the data user's processing involves (i) substantial volume of personal data based on thresholds prescribed in subsidiary instruments + (ii) sensitive personal data processed as a core activity + (iii) regular and systematic monitoring of data subjects + (iv) processing of personal data of children); section 12A(3) — DPO contact details must be publicly available — and the DPO Guideline of 29 May 2025 + section 12B — mandatory data breach notification introduced by 2024 Amendment Act — PDP Commissioner notification within 72 hours from awareness of significant data breach + affected-individual notification as soon as practicable on harm-likelihood threshold; section 43A — right to data portability introduced by 2024 Amendment Act in force from 1 June 2025. Part III Registration of Data Users (ss 13–20 — registered data user classes prescribed by the Class of Data Users Orders; Balance's class — commercial data users dealing with personal data of children + provision of digital services — engages the Class of Data Users Order 2013 registration obligation; foreign data users without permanent Malaysian establishment are NOT required to register per JPDP interpretive practice; § 8.3 below). Part IV Sensitive Personal Data (s 40 — heightened processing rules; sensitive personal data defined at s 4 as physical or mental health / political opinions / religious beliefs or other beliefs of a similar nature / commission or alleged commission of any offence; Balance does NOT process sensitive personal data in respect of Malaysian residents). Part V Rights of Data Subject ss 30–43A — s 30 right of access (data access request) + s 35 right of correction (data correction request) + s 38 right to withdraw consent + s 42 right to prevent processing causing damage or distress + s 43 right to prevent processing for direct marketing + s 43A right to data portability (post-2024-Amendment). Part VI Personal Data Protection Commissioner (ss 47–58 — establishment + appointment + functions + powers). Part VII Notification of Personal Data Breach ss 12B-12D (post-2024-Amendment): s 12B notification triggers + 72-hour PDP Commissioner deadline + s 12C minimum content + s 12D affected-individual notification on harm-likelihood threshold + s 12E offences for failure to notify. Part VIII Codes of Practice (ss 23–28). Part IX Enforcement — administrative enforcement notices ss 90–92 + investigations ss 110–122 + offences and penalties at section 5 of the 2024 Amendment Act (general non-compliance fines up to RM 1 million + imprisonment up to 3 years; aggravated offences up to RM 500,000 + 2 years for individual officers in default). Part X Inspection ss 101–109. Part XI Appeals Process and Personal Data Protection Appeal Tribunal (ss 83–93 — Appeal Tribunal jurisdiction + appeal to High Court). Part XII Miscellaneous including section 129 transfer of personal data to places outside Malaysia — the 2024 Amendment Act abolished the pre-existing whitelist mechanism + replaced it with a more flexible accountability-based mechanism with the operational anchor at the PDP Commissioner Guideline on Cross-Border Personal Data Transfer of 29 May 2025; in force from 1 June 2025. Part XIII Provisions Affecting Other Written Laws ss 130–134. | The principal statute. Applies in full to Balance as a data user established outside Malaysia that targets services to Malaysian residents (with the territorial reach via the equipment in Malaysia limb at s 3(1) interpreted broadly under JPDP practice post-2024-Amendment). Treatment in §§ 3, 4, 6, 7, 8, 11, 13 below. | |
| Personal Data Protection (Amendment) Act 2024 (Act A1709) — "the 2024 Amendment Act" | 2024 Amendment Act — gazetted Warta Kerajaan Persekutuan on 17 October 2024 with phased commencement. Principal substantive provisions in force from 1 June 2025 per Personal Data Protection (Amendment) Act 2024 (Commencement) Order 2025. Headline changes: (i) replaces data user with data controller terminology (with the 2024-Amendment subsection clarifying that the change is purely terminological — substantive obligations carry through); (ii) introduces direct obligations on data processors at section 4 + s 9 security obligations; (iii) introduces section 12A mandatory DPO appointment; (iv) introduces section 12B mandatory data breach notification with 72-hour PDP Commissioner deadline + affected-individual notification on harm-likelihood threshold; (v) introduces section 43A right to data portability; (vi) abolishes the whitelist-based cross-border transfer mechanism at the pre-amendment section 129 and replaces it with an accountability-based mechanism with the PDP Commissioner Guideline on Cross-Border Personal Data Transfer (29 May 2025) as the operational anchor; (vii) increases penalties — general non-compliance up to RM 1 million + 3 years imprisonment; aggravated up to RM 500,000 + 2 years; PDPA Part IX restated; (viii) introduces a biometric data expanded definition within the sensitive-personal-data Part IV regime (Balance does NOT process biometric data); (ix) clarifies the processing of personal data of children as a category engaging the s 12A DPO obligation + the s 12B breach-notification threshold + DPIA expectations under the s 23 Codes of Practice framework. | Applies as the modernising overlay. Treatment in §§ 3, 4, 6, 8, 11 below. | |
| Personal Data Protection Regulations 2013 | PDP Regulations 2013 — gazetted 14 November 2013; in force 15 November 2013. Operationalise the PDPPs (Regulations 3–9), the data access request procedure (Regulation 4 + Schedule), the data correction request procedure (Regulation 5), the registration procedure under Part III of the PDPA (Regulations 6–9), and the maintenance of records requirements. The PDP Standards 2015 supplement the PDPP 4 Security Principle. | Applies in full. The operational implementation of the PDPA. Treatment in §§ 6, 11 below. | |
| Personal Data Protection Standards 2015 (PDP Standards 2015) | PDP Standards 2015 — issued by the PDP Commissioner under PDPA section 134(2) and effective from 23 December 2015. Personal Data Protection Standard 2015 — security standards mandatory for all data users dealing with personal data + Personal Data Protection Retention Standard + Personal Data Protection Data Integrity Standard. Sets the operative technical and organisational baselines for PDPP 4 Security + PDPP 5 Retention + PDPP 6 Data Integrity. | Applies in full. Balance's posture: PDP Standards 2015 implemented; further reinforced by the Personal Data Protection Code of Practice for the Communications Sector applied by analogy to Balance's operations. Treatment in § 11 below. | |
| Personal Data Protection (Class of Data Users) Order 2013 + Amendment Order 2016 | Class of Data Users Orders — gazetted 14 November 2013 (principal) + 23 December 2016 (amendment). Specify the classes of data users required to register with the PDP Commissioner under PDPA Part III. The 2013 Order designates eleven sectoral classes: communications / banking and financial institutions / insurance / health / tourism and hospitalities / transportation / education / direct selling / services / real estate / utilities. The 2016 Amendment Order added pawnbrokers and money-lenders. Balance's commercial offering is on the services sector + the communications sector overlap. Foreign data users without permanent Malaysian establishment are NOT required to register per JPDP interpretive practice — see § 8.3 below. | Applies. Treatment in § 8 below. | |
| PDP Commissioner Guidelines (29 May 2025 series) | PDP Commissioner Guidelines — a series of binding interpretive instruments issued by the PDP Commissioner on 29 May 2025 + in operation from 1 June 2025, operationalising the 2024 Amendment Act. Most directly relevant: Guideline on Appointment of Data Protection Officer (Reference No. JPDP-100-1/12/01-1; sets out triggers for s 12A DPO appointment, DPO qualifications, DPO functions, DPO public-contact requirement under s 12A(3)); Guideline on Notification of Personal Data Breach (Reference No. JPDP-100-1/12/02-1; sets out triggers for s 12B notification, the 72-hour PDP Commissioner notification deadline from awareness, the significant data breach threshold, the minimum-content schedule under s 12C, the affected-individual notification on harm-likelihood under s 12D); Guideline on Cross-Border Personal Data Transfer (Reference No. JPDP-100-1/12/03-1; operational anchor for s 129 post-2024-Amendment — sets out the accountability-based mechanism + recommended-form contractual clauses); Guideline on Data Protection Impact Assessment (Reference No. JPDP-100-1/12/04-1; sets out DPIA triggers and methodology — Balance's DPIA at our Data Protection Impact Assessment); Guideline on Data Subject's Rights including Data Portability (Reference No. JPDP-100-1/12/05-1; operationalises s 30 + s 35 + s 38 + s 42 + s 43 + s 43A). | Sets the PDP Commissioner's binding interpretive layer on the PDPA. Applies in full. | |
| Child Act 2001 (Act 611) | Child Act 2001 — gazetted on 25 January 2001 + in force 1 August 2002. Substantively amended by the Child (Amendment) Act 2016 (Act A1511) in force 7 July 2017. Section 2 definitions — child means a person under the age of 18 years; parent + guardian defined; Child Protector under section 8 + Probation Officer. Part II Child Care + Protection Council (s 3); Part III Court for Children jurisdiction; Part IV Persons in need of protection — ss 17–29 including s 27 mandatory reporting by medical officer, family member, child care provider, or any person of physical / sexual / emotional injury to a child; Part V Adoption, fostering and place of safety; Part VI Children in conflict with the law; Part VII–XI sentencing and aftercare; Part XIII Offences in respect of children (s 31 child abuse / s 32 ill-treatment / s 33 abandonment / s 36 employing or causing a child to beg). The principal Malaysian child-welfare statute. | The principal child-welfare statute. Applies. Treatment in § 5 + § 14 below. | |
| Sexual Offences Against Children Act 2017 (Act 792) (SOACA) | SOACA — gazetted on 6 July 2017 + in force 10 July 2017. The principal Malaysian CSAE statute. Section 4 — child pornography offences (possession + access + distribution; fine + imprisonment up to 20 years); Section 5 — production and direction of child pornography (imprisonment up to 30 years + whipping not less than 6 strokes); Section 6 — preparation of child pornography; Section 7 — exploitation of child for pornography (imprisonment up to 30 years + whipping); Section 8 — using a child in production of child pornography (imprisonment up to 20 years + whipping); Section 10 — assault or use of criminal force on a child with sexual intent (imprisonment up to 20 years + whipping); Section 11 — sexual communication with a child — the principal online grooming offence in Malaysian law (any person who by any means including by communicating (oral / electronic / via a computer network) with a child for the purpose of engaging the child in sexual activity / sexual communication / sending sexually explicit material is guilty of an offence; imprisonment up to 10 years + fine up to RM 20,000); Section 12 — sexual extortion of a child; Section 13 — physical sexual assault on a child (imprisonment up to 20 years + whipping); Section 14 — non-physical sexual assault on a child (imprisonment up to 10 years + fine up to RM 20,000); Section 15 — sexual assault on a child by person in a relationship of trust (heightened penalty); Section 16 — failure to report sexual offences against a child + mandatory reporting by any person + immunity from civil and criminal action for reporting in good faith; Section 17 — extraterritorial application to offences by Malaysian citizens/PRs against children outside Malaysia. | The principal Malaysian CSAE statute. Applies. Treatment in § 14 below. | |
| Penal Code (Act 574) | Penal Code — the principal general criminal statute, in force 1 April 1976 (as the post-Merdeka consolidation of the pre-existing Federation of Malaya Penal Code). Substantive sections relevant to Balance's child-safety + lawful-access posture: s 354 assault or use of criminal force on a person with intent to outrage modesty; s 375 rape — including statutory rape elements at s 375(g) and (h) for unmarried girl under 16 + s 375(f) under-16 wife; s 375A husband-rape; s 375B gang rape (mandatory minimum 20 years + whipping); s 376 punishment for rape; s 376A incest; s 376B punishment for incest; s 377A–s 377CA carnal intercourse against the order of nature and related offences; s 377D gross indecency; s 377E incitement of child to act of gross indecency; s 509 word or gesture intended to insult the modesty of any person. | Applies. Treatment in § 14 below. | |
| Computer Crimes Act 1997 (Act 563) | Computer Crimes Act 1997 — in force from 1 June 2000. Section 3 unauthorised access to computer material; Section 4 unauthorised access with intent to commit or facilitate further offences; Section 5 unauthorised modification of contents of any computer; Section 6 wrongful communication; Section 7 abetment + attempts; Section 8 investigations and procedure. | The principal cybercrime statute. Applies. Treatment in § 13 below. | |
| Communications and Multimedia Act 1998 (Act 588) (CMA) | CMA — in force from 1 April 1999. Part I Preliminary; Part II establishment of MCMC; Part III licensing of network facilities providers / network service providers / applications service providers / content applications service providers (Balance is not a licensee — Balance is below the threshold and the parental-control service is not within the licensee categories); Part IV Spectrum; Part V Numbering and electronic addressing; Part VI Universal Service; Part VII Content (s 211 prohibition on provision of indecent / obscene / false / menacing / offensive content + s 233 improper use of network facilities or network service — fine up to RM 50,000 + imprisonment up to 1 year + further fine RM 1,000 per day); Part VIII–X Powers of Minister + investigations; the Communications and Multimedia (Anti-Spam) Regulations 2013 under CMA s 211 supplement the position on unsolicited commercial messages. Communications and Multimedia (Amendment) Act 2024 (the "CMA 2024 Amendment") — passed 11 December 2024 with phased commencement; introduces licensing for designated online platforms with at least 8 million Malaysian-resident users + child-safety obligations for relevant platforms (Balance is below the 8-million threshold and is not a designated platform). | Applies in respect of any improper-use-of-network-facilities offences; CMA 2024 Amendment is a context-setting fact (Balance below 8M threshold). Treatment in § 12 + § 13 below. | |
| Communications and Multimedia (Anti-Spam) Regulations 2013 | Anti-Spam Regulations 2013 — gazetted under CMA s 211; in force from 1 January 2014. Prohibit the provision of unsolicited commercial electronic message without prior consent + identification + unsubscribe mechanism. Civil penalties + criminal offences. | Applies. Balance does NOT send commercial electronic messages to Malaysian residents within the meaning of the Regulations. Treatment in § 12 below. | |
| Consumer Protection Act 1999 (Act 599) | CPA 1999 — in force from 15 November 1999. Part I Preliminary; Part II Misleading or deceptive conduct, false representations and unfair practices; Part IIIA Unfair contract terms (introduced by the Consumer Protection (Amendment) Act 2010 in force 1 July 2010); Part V Safety of goods and services; Part VI Rights against suppliers in respect of guarantees in the supply of goods; Part VII Rights against manufacturers in respect of guarantees in the supply of goods; Part VIII Rights of consumers in respect of services; Part IX Rights against suppliers in respect of guarantees in the supply of services — non-excludable guarantees of reasonable care and skill (s 53) + fitness for particular purpose (s 54) + reasonable time (s 55) + reasonable price (s 56); Part XII Tribunal for Consumer Claims (small claims up to RM 50,000); enforced by the Ministry of Domestic Trade and Cost of Living (KPDN) + the Tribunal for Consumer Claims. | The principal Malaysian consumer-protection statute. Applies in full. Treatment in § 16 below. | |
| Consumer Protection (Electronic Trade Transactions) Regulations 2012 | Electronic Trade Transactions Regulations 2012 — gazetted 31 July 2012 + in force 1 July 2013. Regulation 3 + Schedule prescribe minimum information disclosure for online marketplace operators + Schedule requirements for suppliers in distance-selling transactions including identity + nature of goods/services + price + delivery + cancellation/refund/exchange policy. Applies to electronic trade transactions including online subscription supply. | Applies. Treatment in § 16 below. | |
| Contracts Act 1950 (Act 136) | Contracts Act 1950 — the general statute of contract law, in force 1 January 1951. Section 11 capacity to contract (a minor cannot make a binding contract — Mohori Bibee v Dharmodas Ghose [1903] LR 30 IA 114 applied in Malaysia + Tan Hee Juan v Teh Boon Keat [1934] MLJ 96); Section 16 consent (free consent + undue influence); Section 17 fraud; Section 18 misrepresentation; Section 19 voidability for coercion / undue influence / fraud / misrepresentation; Sections 24–30 legality of consideration and object; Section 73 restitution of advantage gained from contract that becomes void. | Applies. Treatment in § 16 below. | |
| Sale of Goods Act 1957 (Act 382) | Sale of Goods Act 1957 — the principal sale-of-goods statute. Section 16 implied condition of merchantable quality; Section 16(1)(a) implied condition of fitness for purpose where the buyer makes known to the seller the particular purpose. | Applies. Treatment in § 16 below. | |
| Age of Majority Act 1971 (Act 21) | Age of Majority Act 1971 — in force from 1 January 1972. Section 2 sets the age of majority at 18 years. Subject to certain religious-personal-law overlays for matters governed by Islamic law (which do not engage Balance's commercial contracting). | Applies. Confirms that the parent contracting with Balance is an adult (the subscription contract is between Balance and the parent, not the kid). Treatment in § 16 below. | |
| EU adequacy | None. Malaysia does not hold an EU adequacy decision under GDPR Article 45 at the Effective date. EU/EEA → Malaysia transfers are governed by EU SCCs + Transfer Impact Assessment. | Cross-reference in EU / EEA annex § 8. | The absence of EU adequacy does not affect Balance's posture because Balance has no Malaysian data residency (the backend is in the US — see § 9 below). |
| Convention 108 / Convention 108+ | Not applicable. Malaysia is not a party to the Council of Europe Convention 108 or Convention 108+. | Applies as a context-setting fact. Treatment in § 8 below. | |
| APEC Cross-Border Privacy Rules (CBPR) | Malaysia has been an APEC participating economy since the founding of APEC in 1989; Malaysia formally joined the operational APEC CBPR system + the APEC PRP (Privacy Recognition for Processors) on 12 May 2022 as a participating economy with an Accountability Agent designation; the operational accountability agent designation for Malaysia is administered through the JPDP. | Applies as a context-setting fact. Treatment in § 8 below — the APEC CBPR participation provides an additional contractual-protection overlay route for Malaysia-to-third-country transfers but the operational mechanism for Balance is the PDPA section 129 framework + the PDP Commissioner Guideline on Cross-Border Personal Data Transfer (29 May 2025). | |
| ASEAN Framework on Personal Data Protection (2016) | The ASEAN Framework on Personal Data Protection adopted by the ASEAN Telecommunications and IT Ministers in November 2016 + the ASEAN Data Management Framework + the ASEAN Model Contractual Clauses for Cross Border Data Flows (January 2021). Malaysia is a signatory and supportive member. | Applies as a context-setting fact. The ASEAN Model Contractual Clauses provide an alternative contractual-protection overlay route used in this Annex's transfer pack at § 8 below. | |
| Budapest Convention on Cybercrime | Not applicable at the Effective date. Malaysia is not a party to the Convention on Cybercrime (Budapest Convention). | Applies as a context-setting fact. Cross-border lawful-access for Malaysia is via the Mutual Assistance in Criminal Matters Act 2002 (Act 621) + bilateral MLATs. |
(Any prospective Malaysian regulation governing automated processing, algorithmic decisions, or related techniques — including any post-Effective-date PDP Commissioner Guideline in that area, the National AI Roadmap 2021–2025 + the AI-RMF Malaysia: Artificial Intelligence Governance and Ethics Guidelines (issued by the Ministry of Science, Technology and Innovation in September 2024, voluntary best-practice guidance only), the National Artificial Intelligence Office (NAIO) initiatives, any future Malaysian primary legislation on artificial intelligence before the Dewan Rakyat, and any successor instrument — is intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such Malaysian regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence on the topic is deliberate and is not to be read as an implicit statement either way.)
3. Supervisory authorities
3.1 PDP Commissioner — Pesuruhjaya Perlindungan Data Peribadi
The principal supervisory authority is the Personal Data Protection Commissioner (Bahasa Malaysia: Pesuruhjaya Perlindungan Data Peribadi, the "PDP Commissioner"), the head of the Personal Data Protection Department (Jabatan Perlindungan Data Peribadi, "JPDP"), an authority within the Ministry of Digital (Bahasa Malaysia: Kementerian Digital; established on 12 December 2023 by the splitting of the former Ministry of Communications and Digital into the Ministry of Communications and the Ministry of Digital). The PDP Commissioner is appointed under PDPA section 47 + section 48 by the responsible Minister with the consent of the Yang di-Pertuan Agong (the King of Malaysia). The PDP Commissioner has investigative + enforcement + regulatory + recommendatory powers. The PDP Commissioner's decisions are appealable to the Personal Data Protection Appeal Tribunal under PDPA Part XI ss 83–93 and onwards to the High Court of Malaya + the Court of Appeal + the Federal Court of Malaysia.
| Field | Value |
|---|---|
| Name | Personal Data Protection Department (Jabatan Perlindungan Data Peribadi, JPDP) |
| Parent ministry | Ministry of Digital (Kementerian Digital) |
| Headquarters | Aras 6, Kompleks Kementerian Komunikasi dan Digital, Lot 4G9, Persiaran Perdana, Presint 4, 62100 Putrajaya, Malaysia |
| Website | https://www.pdp.gov.my/ (Bahasa Malaysia) / https://www.pdp.gov.my/?lang=en (English) |
| Complaint channel | JPDP online complaint portal at https://aduan.pdp.gov.my/; email aduan@pdp.gov.my |
| Phone | +60 3 8911 7000 |
| Data-Breach-Notification channel | JPDP online Personal Data Breach Notification portal per PDPA section 12B + the PDP Commissioner Guideline on Notification of Personal Data Breach of 29 May 2025 — 72-hour notification from awareness of significant personal data breach. |
| Personal Data Protection Commissioner | At the Effective date — published at https://www.pdp.gov.my/ |
The PDP Commissioner is the first-line forum for any PDPA-grounded complaint from any Malaysian resident. A Malaysian resident may petition the PDP Commissioner after first raising the matter with Balance (the JPDP's Aduan Portal complaint procedure recommends raising the matter with the data user first, but the JPDP also accepts direct complaints). We accept all data subject access / privacy enquiries at (named individual: , in his capacity as the DPO under PDPA section 12A + the PDP Commissioner Guideline on Appointment of Data Protection Officer of 29 May 2025) and respond within the PDPA timelines (see § 6 below).
A Malaysian resident may also pursue private remedies via (i) the PDPA section 42 right to prevent processing causing damage or distress + the PDPA Part IX civil remedies under the s 5 enforcement-quantum framework; (ii) common-law privacy doctrine as recognised by Malaysian courts in Lee Ewe Poh v Dr Lim Teik Man & Anor [2011] 1 MLJ 835 (High Court) + subsequent decisions; (iii) the Federal Constitution Article 5 constitutional-rights cause of action read with Sivarasa Rasiah v Badan Peguam Malaysia [2010] 2 MLJ 333 (Federal Court); (iv) the PDPA section 18 complaint route to a sectoral Code of Practice where applicable; (v) the PDPA Part VII offences which may be the subject of criminal complaint to the Public Prosecutor under PDPA section 138 + the Criminal Procedure Code (Act 593).
3.2 Ministry of Digital — JPDP parent ministry
The Ministry of Digital (Kementerian Digital) is the parent ministry of the JPDP. The Minister of Digital is the responsible minister for the PDPA and for the issuance of subsidiary instruments under PDPA section 134.
| Field | Value |
|---|---|
| Name | Ministry of Digital (Kementerian Digital, KD) |
| Headquarters | Aras 1, 2, 3 dan 4, Blok B, Kompleks Kementerian Komunikasi dan Digital, Lot 4G9, Persiaran Perdana, Presint 4, 62100 Putrajaya, Malaysia |
| Website | https://www.digital.gov.my/ |
| Phone | +60 3 8000 8000 |
3.3 Other regulatory bodies
| Body | Subject matter | URL |
|---|---|---|
| Malaysian Communications and Multimedia Commission (MCMC) — Suruhanjaya Komunikasi dan Multimedia Malaysia | Communications and Multimedia Act 1998 enforcement; spam; CMA 2024 Amendment designated-platform regulation | https://www.mcmc.gov.my/ — Hotline: 1-800-188-030 |
| Royal Malaysia Police (PDRM) — Sexual Crimes, Children and Domestic Violence Investigation Division (D11) — Polis Diraja Malaysia — Bahagian Siasatan Jenayah Seksual, Kanak-Kanak dan Keganasan Rumah Tangga | Sexual offences against children + CSAE investigation | https://www.rmp.gov.my/ — Emergency 999 |
| PDRM — Cyber Crime and Multimedia Investigation Division (D5(6)) | Cybercrime investigation including online CSAE | https://www.rmp.gov.my/ |
| PDRM — Anti-Trafficking in Persons and Anti-Smuggling of Migrants Division (D7) | Anti-Trafficking in Persons and Anti-Smuggling of Migrants Act 2007 | https://www.rmp.gov.my/ |
| Department of Social Welfare (JKM) — Jabatan Kebajikan Masyarakat | Child Act 2001 — child-protection lead agency; Talian Kasih 15999 general welfare hotline | https://www.jkm.gov.my/ |
| Department of Women Development (JPW) — Jabatan Pembangunan Wanita | Women + gender-based-violence services | https://www.jpw.gov.my/ |
| Ministry of Women, Family and Community Development (KPWKM) | JKM + JPW parent ministry; SOACA implementing ministry; Talian Kasih 15999 | https://www.kpwkm.gov.my/ |
| Ministry of Domestic Trade and Cost of Living (KPDN) — Kementerian Perdagangan Dalam Negeri dan Kos Sara Hidup | Consumer Protection Act 1999 + Electronic Trade Transactions Regulations + Tribunal for Consumer Claims | https://www.kpdn.gov.my/ — Hotline: 1-800-886-800 |
| Tribunal for Consumer Claims — Tribunal Tuntutan Pengguna Malaysia (TTPM) | Small consumer claims up to RM 50,000 | https://ttpm.kpdn.gov.my/ |
| CyberSecurity Malaysia (CSM) | National CERT; MyCERT for cyber-incident handling | https://www.cybersecurity.my/ + https://www.mycert.org.my/ |
| Attorney General's Chambers — Jabatan Peguam Negara | Public prosecution; SOACA + Penal Code prosecutions | https://www.agc.gov.my/ |
| Personal Data Protection Appeal Tribunal | Appeals from PDP Commissioner decisions under PDPA Part XI | via JPDP https://www.pdp.gov.my/ |
| Children's Commissioner — Suruhanjaya Hak Asasi Manusia Malaysia (SUHAKAM) — Children's Commissioner | Independent child-rights advocacy | https://www.suhakam.org.my/ |
| National Council for Child Welfare — Majlis Kebajikan Kanak-Kanak Malaysia | Federal child-welfare coordination body under Child Act 2001 s 3 | via JKM |
| Talian Kasih 15999 — KPWKM Hotline | 24/7 child-protection + women-protection + family-violence hotline | dial 15999 |
| Childline Foundation Malaysia | Children's helpline NGO | https://www.childlinefoundation.org.my/ — 15999 (via Talian Kasih) |
| Protect and Save the Children (PS) Malaysia | Children's protection NGO | https://psthechildren.org.my/ |
| PEMBELA — Persatuan Mencegah Buli, Eksploitasi, Layanan Buruk dan Aniaya | Children's protection NGO | via PS the Children |
| WAO — Women's Aid Organisation | Women + child sexual-violence services | https://wao.org.my/ |
| Befrienders Kuala Lumpur | 24-hour emotional support hotline | https://www.befrienders.org.my/ — 03-7956 8145 |
| MIASA — Mental Illness Awareness and Support Association | Mental health crisis support | https://miasa.org.my/ |
| CyberSAFE Malaysia | CSM-operated online-safety awareness initiative | https://www.cybersafe.my/ |
3.4 The DPO
PDPA section 12A (introduced by the 2024 Amendment Act, in force from 1 June 2025) + the PDP Commissioner Guideline on Appointment of Data Protection Officer of 29 May 2025 require every data user falling within the section 12A criteria to appoint a Data Protection Officer (DPO). The criteria include (iv) processing of personal data of children. Balance's processing of children's personal data of Malaysian-resident kids engages s 12A(1)(iv) and Balance accordingly appoints a DPO. The DPO must be readily accessible, must be reachable by data subjects and by the PDP Commissioner, and the DPO's contact details must be publicly available under s 12A(3).
The Balance DPO is:
- , Director, BabaYaga Program, TOO —
.
The DPO's business contact is published in this Annex, in the global Privacy Policy (Privacy Policy § 1), and at balance.babayagaprogram.com — satisfying PDPA s 12A(3) + the PDP Commissioner Guideline on Appointment of Data Protection Officer of 29 May 2025. The DPO is the contact point for the PDP Commissioner on any regulatory matter and for data subjects on rights-exercise matters. The DPO need not be a Malaysian citizen or resident but must be readily accessible during Malaysian business hours per the DPO Guideline § 6.3.
4. Lawful bases — PDPA section 6 (PDPP 1) + section 8 (PDPP 3) + sensitive-data carve-out
The PDPA is a consent-and-purpose-limitation regime modulated by the PDPP 1 general principle + the section 6 carve-outs (performance of contract / legal obligation / vital interest / administration of justice / functions of public nature). Balance processes personal data of Malaysian residents on the following PDPA mapping:
| Processing purpose | PDPA basis | Cross-reference |
|---|---|---|
| Run the parental-control service the parent signed up for (account creation, family configuration, kid profile, limits, schedules, tasks, earned-time ledger, end-to-end-encrypted proof media) | PDPA section 6 PDPP 1 — parent's consent given for the specific and lawful purpose + performance-of-contract carve-out at s 6(2)(b) (the processing is necessary for the performance of a contract to which the data subject is a party) + PDPP 2 notice and choice at s 7 + PDPP 3 disclosure at s 8 + PDPP 4 security at s 9 | H1 § 4; H7 PA-01 through PA-08; § 7 of this Annex |
| Process the kid's personal data | PDPA section 6 — parent's consent given on behalf of the kid under the Age of Majority Act 1971 (kid is a minor; parent is the legal guardian) + Child Act 2001 framework + Contracts Act 1950 s 11 minor-capacity doctrine + Hindu/Muslim/Christian/customary parental-authority overlays as applicable per personal-law jurisdiction + the PDP Commissioner Guideline on Appointment of Data Protection Officer + DPP 1/3/4 | § 7 of this Annex; our Data Protection Impact Assessment § 6 |
| Deliver operational alerts | PDPA section 6 + section 7 (primary purpose) | H1 § 4; H7 PA-09; M3 |
| Detect, prevent, and respond to security incidents, abuse, fraud, and unauthorised access | PDPA section 9 PDPP 4 security obligation + PDP Standards 2015 + section 6(2)(d) (necessary for any legal proceedings) + section 6(2)(e) (necessary to protect vital interest) + section 39 carve-outs for crime prevention | H7 PA-15; § 13 below |
| Comply with legal, regulatory, and supervisory obligations | PDPA section 6(2)(c) (necessary to comply with any legal obligation to which the data user is the subject) + s 39 carve-outs | § 13 below; M1; § 14 below |
| Process Verifiable Parental Consent for the kid's data | PDPA section 6 PDPP 1 + section 7 PDPP 2 — collection of the parent's personal data for the primary purpose of obtaining VPC | § 7 of this Annex; A-US § 5 |
| Process the parent's billing / subscription data | PDPA section 6(2)(b) performance-of-contract necessity; CPA 1999 + Consumer Protection (Electronic Trade Transactions) Regulations 2012 + Sale of Goods Act 1957 + Contracts Act 1950 consumer-protection overlay in § 16 below | H4; § 16 below |
Balance does not process sensitive personal data under PDPA section 40 (post-2024-Amendment expanded definition at section 4 — physical or mental health / political opinions / religious beliefs or other beliefs of a similar nature / commission or alleged commission of any offence / biometric data) in respect of any Malaysian resident.
Balance does not collect any Malaysian national or government-issued identification number — neither the MyKad number (the Malaysian Identity Card number issued under the National Registration Regulations 1990) nor the MyKid number (issued to under-12 Malaysian citizens) nor the passport number (issued under the Passports Act 1966) nor the driver's licence number. PDPA section 4 sensitive-data-equivalent treatment + the JPDP's interpretive practice on the collection of MyKad numbers impose strict purpose-limitation on the collection of such numbers; Balance's posture aligns: none collected.
5. Children's rights overlay
Malaysia does not have a children-specific data-protection statute equivalent to COPPA (US), GDPR Art 8, or Quebec Private Sector Act s 8.1, at the Effective date. The children's regime is built up from (i) the PDPA + the 2024 Amendment Act's recognition of processing of personal data of children as a triggering category at s 12A(1)(iv) + the PDP Commissioner Guideline on Appointment of Data Protection Officer (29 May 2025) and Guideline on Notification of Personal Data Breach (29 May 2025); (ii) the Federal Constitution Article 5 read with Sivarasa Rasiah; (iii) the Child Act 2001 (Act 611); (iv) the Sexual Offences Against Children Act 2017 (Act 792) + the Penal Code (Act 574) sexual-offences chapter; (v) the Age of Majority Act 1971 age 18; (vi) the Contracts Act 1950 s 11 minor-incapacity doctrine; (vii) the UN Convention on the Rights of the Child (Malaysia acceded with reservations on 17 February 1995, principal reservations on Arts 2 + 7 + 14 + 28(1)(a) + 37 withdrawn or modified in subsequent declarations).
5.1 Definitions
For the purposes of this Annex:
- Child (under Child Act 2001): a person who has not attained the age of 18 years (Child Act 2001 s 2).
- Child for the purposes of SOACA (Sexual Offences Against Children Act 2017): a person under the age of 18 years (SOACA s 2).
- Minor (under Age of Majority Act 1971 + Contracts Act 1950): a person who has not attained the age of 18 years.
- Age of sexual consent (per Penal Code s 375(g)): 16 years (an unmarried girl under 16 — statutory rape elements engage regardless of consent).
- Age of digital consent under PDPA: the PDPA does not set a numerical age of digital consent. The PDP Commissioner Guideline on Appointment of Data Protection Officer treats processing of personal data of children (under 18) as a triggering category for the DPO mandate at s 12A(1)(iv); the broader interpretive practice treats persons below 18 as requiring parental consent for the processing of their personal data for online services directed at minors, subject to maturity-based exceptions for older adolescents. Balance applies the most-protective reading and obtains parental consent regardless of the child's age.
5.2 Verifiable Parental Consent (VPC) for Malaysian kids
Balance applies the most-protective reading and obtains Verifiable Parental Consent for every Malaysian kid regardless of age, using the VPC mechanism in United States annex § 5 (email-verified parent account creation + payment-method capture at subscription time + parent's affirmative in-app action of creating the kid profile and pairing the kid's device). The VPC screen for Malaysian residents itemises the categories of personal data being processed, the purposes for which it is being processed, the third parties to whom it may be disclosed (sub-processors), and the data subject's rights under the PDPA + Federal Constitution Article 5 + the common-law privacy doctrine.
5.3 No kid-self-serve consent path
Balance does not provide a kid-self-serve consent path inside the app. The parent always consents on behalf of the kid; the kid app's UI is designed for the kid to see their own limits, schedules, tasks, and earned-time ledger, and to request changes through the in-app "request change" affordance, which is forwarded to the parent device for the parent's decision. This is the most-protective reading of the PDPA + the PDP Commissioner Guideline on Appointment of Data Protection Officer + the Contracts Act 1950 s 11 minor-incapacity doctrine + the Age of Majority Act 1971 + the Child Act 2001.
5.4 No advertising directed at children
Balance does not display advertising to any user (parent or kid), does not allow any third party to display advertising in Balance, and does not build a behavioural-advertising data file of any user. This is consistent with: (i) the PDPA section 43 right to prevent processing for direct marketing; (ii) the Communications and Multimedia (Anti-Spam) Regulations 2013; (iii) the CPA 1999 Part II prohibition on misleading or deceptive conduct + Part IIIA unfair contract terms; (iv) the MCMC Code on Advertising + the MCMC Code of Conduct (Industry Code) for the Communications and Multimedia Industry Malaysia. Cross-references: the Play Console Data Safety form § 2 (Contains ads: No); the Play Console Child Safety Standards declaration § 3 ATTESTATION-D.
5.5 Cooperation routes
The principal Malaysian child-protection bodies are: (i) the Department of Social Welfare (JKM) — the principal child-welfare lead agency under Child Act 2001 + Talian Kasih 15999 24/7 hotline; (ii) the Royal Malaysia Police — Sexual Crimes, Children and Domestic Violence Investigation Division (D11) + the PDRM Cyber Crime and Multimedia Investigation Division; (iii) the Ministry of Women, Family and Community Development (KPWKM) — the SOACA implementing ministry; (iv) CyberSecurity Malaysia (CSM) — national CERT for cyber-incident coordination; (v) SUHAKAM Children's Commissioner; (vi) the National Council for Child Welfare under Child Act 2001 s 3; (vii) NGO partners — Childline Foundation Malaysia, Protect and Save the Children (PS) Malaysia, PEMBELA, WAO (Women's Aid Organisation), Befrienders KL 03-7956 8145, MIASA, CyberSAFE Malaysia. Balance cooperates with each on incidents involving Malaysian kids — see § 14 below.
6. PDPA rights catalogue
6.1 The rights catalogue
A Malaysian resident has the following rights under the PDPA + the 2024 Amendment Act + the PDP Commissioner Guidelines (29 May 2025 series) as in force at the Effective date.
- PDPA s 7 PDPP 2 — Right to be informed. Notice and choice principle. Honored at the privacy notice in this Annex + at
+ in-app at sign-up. - PDPA s 30 — Data Access Request. A data subject may request the data user to inform him of the personal data held by the data user that is being processed by or on behalf of the data user and to provide him with a copy of that personal data. Honored in-app at Settings → Family → [kid name] → "Export this kid's data". Format: machine-readable JSON archive, with a plain-language English summary; Bahasa Malaysia summary queued for Phase-2 locale rollout. Response window: 21 days under PDPA s 31 + extendable by a further 14 days on written notice.
- PDPA s 35 — Data Correction Request. A data subject may request the data user to correct inaccurate / incomplete / misleading / not-up-to-date personal data. Response window: 21 days under PDPA s 36 + extendable by a further 14 days.
- PDPA s 38 — Right to withdraw consent. Honored in-app at Settings → Account → "Delete account" + via
. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal. - PDPA s 42 — Right to prevent processing causing damage or distress. A data subject may give written notice to the data user requiring the data user to cease processing his personal data on the ground that the processing is causing or is likely to cause unwarranted damage or distress to him. Honored at
. - PDPA s 43 — Right to prevent processing for direct marketing. (n/a — Balance does not direct-market.)
- PDPA s 43A — Right to data portability (introduced by the 2024 Amendment Act in force from 1 June 2025). A data subject may request the data user to transmit personal data which the data subject has provided to the data user to another data user in a structured, commonly used, and machine-readable format. Honored at
. - PDPA s 110 PDP Commissioner complaint route. A data subject may file a complaint with the PDP Commissioner at the JPDP Aduan Portal or by email at
aduan@pdp.gov.my. The PDP Commissioner may open an investigation, issue an enforcement notice, or refer the matter to the Public Prosecutor for criminal action. - PDPA s 42 + s 43 + s 43A + Part IX civil remedies + common-law breach-of-confidence (per Lee Ewe Poh v Dr Lim Teik Man [2011] 1 MLJ 835 (High Court) + subsequent decisions).
- Federal Constitution Article 5 constitutional-rights remedy (judicial review + appropriate declaratory relief; cause of action sustainable per Sivarasa Rasiah + Lee Kwan Woh).
6.2 Timeline
- PDPA s 31 access: 21 days from receipt of the data access request, extendible by a further 14 days on written notice.
- PDPA s 36 correction: 21 days from receipt of the data correction request, extendible by a further 14 days.
- PDPA s 38 withdrawal of consent: as soon as practicable, in any event within 30 days.
- PDPA s 42 prevent processing causing damage or distress: the data user must give the data subject a written response within 21 days stating whether the data user has complied or intends to comply with the notice.
- PDPA s 43A data portability: Balance gives effect to a data portability request within 30 days, per the PDP Commissioner Guideline on Data Subject's Rights including Data Portability (29 May 2025).
- PDP Commissioner complaint: the JPDP's published target is to conduct an initial assessment within 30 days + an in-depth investigation thereafter; complex matters may take longer.
Where the data-access carve-outs at PDPA section 32 apply (national security / prevention or detection of crime / regulatory enforcement / professional confidentialities / mental-health-of-data-subject), Balance may decline to provide access and explain the reasons.
6.3 Identity verification
Where there is reasonable doubt about the identity of the natural person making the request, Balance may request additional information necessary to confirm the identity. The identity-verification protocol uses the parent's existing authentication credential.
6.4 Fees
Under PDPA section 28(2) + the Personal Data Protection (Fees) Regulations 2013, a data user may charge a prescribed fee for processing a data access request (the prescribed fee is RM 10 for the first request and RM 50 per request for subsequent requests in the same 12-month period, subject to upward adjustment in the data user's reasonable discretion). Balance does not charge for access in practice.
6.5 Language
A request may be submitted in Bahasa Malaysia or English. The JPDP accepts complaints in Bahasa Malaysia and English.
7. Children's data — PDPA + Child Act 2001 + Contracts Act 1950 + Age of Majority Act 1971
Balance processes personal data of Malaysian kids under the following layered framework:
- PDPA section 6 + section 7 + section 12A(1)(iv) recognition of processing of personal data of children as a triggering category read with the PDP Commissioner Guideline on Appointment of Data Protection Officer of 29 May 2025 + the Guideline on Data Subject's Rights including Data Portability of 29 May 2025 — for any minor under 18, the data user should obtain consent from the parent or guardian.
- Child Act 2001 (Act 611) — child-protection framework including the mandatory-reporting regime at section 27.
- Sexual Offences Against Children Act 2017 (Act 792) — sexual offences against minors + the online-grooming offence at section 11.
- Contracts Act 1950 (Act 136) section 11 — minor-incapacity doctrine; the parent contracts on behalf of the kid.
- Age of Majority Act 1971 (Act 21) — age of majority 18.
- UN Convention on the Rights of the Child (Malaysia acceded with reservations on 17 February 1995; principal reservations on Arts 2 + 7 + 14 + 28(1)(a) + 37 withdrawn or modified in subsequent declarations) — internalised through Malaysia's child-welfare statutes.
For Balance:
- Verifiable Parental Consent. Identical mechanism to A-US § 5. The VPC screen is in English (Bahasa Malaysia queued for Phase 2 locale rollout; Mandarin Chinese and Tamil queued in the same Phase 2 rollout).
- No kid-self-serve consent path. Per § 5.3 above.
A parent may revoke consent at any time at Settings → Family → [kid name] → "Delete this kid" (or by email to ). Revocation triggers the cascade documented in Data Retention & Deletion Policy § 7. Revocation does not affect the lawfulness of processing carried out before the revocation.
8. International data transfers from Malaysia — PDPA s 129 + PDP Commissioner Guideline on Cross-Border Personal Data Transfer (29 May 2025)
The controller (BabaYaga Program, TOO) is established in Kazakhstan. The backend (Emergent Labs Inc.) is hosted in the United States. Proof-media storage (Google Cloud Storage) is in the United States. Push (Firebase Cloud Messaging), sign-in (Google Sign-In), and billing (Google Play Billing) are operated by Google LLC and dispatched from the United States. Transactional email (Resend) is dispatched from the United States. Accordingly, every Malaysian resident's personal data leaves Malaysia at the point of being uploaded to the Balance backend.
8.1 The Malaysia-to-US transfer mechanism — PDPA section 129 (post-2024-Amendment) + the PDP Commissioner Guideline on Cross-Border Personal Data Transfer
PDPA section 129 as amended by the 2024 Amendment Act is the operative cross-border-transfer provision. The 2024 Amendment Act abolished the pre-existing whitelist mechanism (under which the pre-amendment section 129(1) listed jurisdictions to which transfer was authorised, with a long-standing operational anomaly that no Federal Government Gazette had ever specified the whitelist) and replaced it with a more flexible accountability-based mechanism with the PDP Commissioner Guideline on Cross-Border Personal Data Transfer of 29 May 2025 as the operational anchor.
Under the post-2024-Amendment section 129 + the Guideline, a data user may transfer personal data to a place outside Malaysia where the data user has taken reasonable steps to ensure that the personal data will not be processed in any manner that contravenes the PDPA. The Guideline identifies the following operational mechanisms as satisfying the reasonable steps test:
- (a) the recipient is subject to a law in the receiving country that is substantially similar to the PDPA, or that serves the same purposes as the PDPA, with comparable rules / oversight / enforcement;
- (b) the data user has entered into a written contract with the recipient containing safeguards equivalent to the PDPA — the principal operational mechanism for Balance — using a recommended-form contractual-clauses template published by the PDP Commissioner or substantively-equivalent contractual clauses including the ASEAN Model Contractual Clauses for Cross Border Data Flows (January 2021) + the APEC CBPR contractual-clauses overlay;
- (c) the recipient is a member of a binding corporate-rules group or a binding inter-corporate-rules framework approved by the PDP Commissioner;
- (d) the data subject has given consent to the transfer with explicit notice of the implications;
- (e) the transfer is necessary for the performance of a contract between the data subject and the data user (or pre-contractual steps);
- (f) the transfer is necessary for the conclusion or performance of a contract between the data user and a third party which is entered into at the request of the data subject or is in the interests of the data subject;
- (g) the transfer is necessary for any legal proceedings or for obtaining legal advice or for establishing, exercising or defending legal rights;
- (h) the transfer is necessary to protect the vital interest of the data subject; or
- (i) the data user has reasonable grounds to believe that in all the circumstances of the case the transfer is for the avoidance or mitigation of adverse action against the data subject.
Balance relies on the following stack to satisfy PDPA s 129 + the Guideline:
- Limb (b) written contracts with safeguards equivalent to the PDPA — principal mechanism. Each US sub-processor (Emergent Labs Inc.; Google LLC for GCS, FCM, Sign-In, and Play Billing; Resend, Inc.) is bound by a written processor agreement that includes a binding undertaking to maintain the personal data in accordance with the PDPA + PDPP 4 security + PDPP 5 retention + PDPP 6 data integrity. The clauses incorporate the substance of the EU SCC + UK IDTA + APP-aligned + Quebec-Private-Sector-Act-aligned + ASEAN Model Contractual Clauses substance as substantive overlays. The full transfer pack is in our international-transfer pack § 6.
- Limb (d) parent's consent overlay — belt-and-braces. The parent's sign-up consent prominently and expressly discloses the cross-border transfer to the United States, expressly states that the US recipient has given a written undertaking to maintain the personal data in accordance with the PDPA, identifies the country of destination and the categories of recipients, and informs the parent of any risk arising from the transfer.
- Limb (e) performance-of-contract necessity. The transfer is also necessary for the performance of the subscription contract between Balance and the parent and for the operation of the parental-control service.
- Supplementary measures — most importantly, the end-to-end encryption of proof media documented in our encryption-posture record. The E2EE is the principal supplementary measure ensuring that even a compelled-production scenario in the US yields only opaque ciphertext, not plaintext media.
- Onward-transfer restrictions — every sub-processor's processor agreement forbids onward transfer of Malaysian-resident personal data to a third country outside the PDPA s 129 framework without the controller's prior written authorisation.
8.2 The Malaysia-to-KZ axis (controller administrative access)
The controller's personnel in Kazakhstan have administrative access to the US-hosted backend for operational purposes. Because Kazakhstan is a third country, the Malaysia-KZ axis is covered by the PDPA s 129 limb (b) written contracts with safeguards equivalent to the PDPA + limb (d) parent's consent overlay + limb (e) performance-of-contract necessity — written processor agreements signed between Emergent Labs (as processor) and BabaYaga Program, TOO (as controller) in inverse, with EU-SCC substance + ASEAN Model Contractual Clauses substance preserved. The transfer-impact analysis for the KZ leg is in our international-transfer pack § 7.
8.3 PDPA Part III data-user registration
PDPA Part III (ss 13–20) + the Class of Data Users Order 2013 + Amendment Order 2016 require data users within prescribed classes to register with the PDP Commissioner. The JPDP's interpretive practice for foreign data users without permanent Malaysian establishment is documented in JPDP guidance: foreign data users are not required to register their data-user activity but remain subject to the PDPA's substantive obligations including the PDPP framework, the section 12A DPO obligation, and the section 12B breach-notification obligation. Balance accordingly does not register as a data user with the JPDP at the Effective date and tracks this in the placeholder tracker. Should the JPDP's interpretive practice change or should Balance establish a permanent Malaysian presence, registration will follow via the JPDP's data-user-registration portal.
8.4 APEC CBPR overlay (context-setting)
Malaysia formally joined the operational APEC CBPR system + the APEC PRP (Privacy Recognition for Processors) on 12 May 2022. The APEC CBPR system provides a complementary accountability framework for cross-border data transfers within the APEC region (which includes Malaysia, Singapore, the Philippines, the United States, Canada, Japan, the Republic of Korea, Mexico, Taiwan, and Australia at the Effective date). Balance's principal operational mechanism remains the PDPA s 129 limb (b) written contracts framework + the Guideline on Cross-Border Personal Data Transfer; the APEC CBPR + PRP framework is a context-setting overlay.
8.5 ASEAN Model Contractual Clauses for Cross Border Data Flows (January 2021)
Malaysia is an ASEAN Member State + a signatory to the ASEAN Framework on Personal Data Protection (2016) + the ASEAN Data Management Framework. The ASEAN Model Contractual Clauses for Cross Border Data Flows (January 2021) provide a recommended-form contractual-clauses template usable across ASEAN Member States. Balance's sub-processor agreements incorporate the substance of the ASEAN Model Contractual Clauses as a substantive overlay (see our international-transfer pack § 6).
9. Data residency for Malaysian residents
| Question | Answer |
|---|---|
| Where is the backend hosted? | United States. Emergent Labs Inc. (Delaware) on US infrastructure. |
| Where is the MongoDB database located? | United States. |
| Where is the proof-media storage located? | United States — Google Cloud Storage us multi-region. |
| Where are push notifications dispatched from? | United States — Firebase Cloud Messaging. |
| Is any Malaysian resident's personal data held in Malaysia? | No. Every Malaysian resident's personal data is held in the United States. The PDPA s 129 limb (b) written contracts + limb (d) parent's consent + limb (e) performance-of-contract necessity stack in § 8 above is the legal basis for the transfer. |
| Where is the controller? | Kazakhstan (BabaYaga Program, TOO). The controller has administrative access to the US-hosted backend via written processor agreements. |
| Is there a Malaysian establishment? | No. Balance has no permanent establishment in Malaysia. The PDPA's territorial reach (s 3(1) equipment in Malaysia limb, broadened by the 2024 Amendment Act) is the basis for Balance's PDPA compliance. |
| Where is the supervisory authority? | Malaysia — JPDP + Ministry of Digital + the regulatory bodies in § 3.3 above. |
The decision to centralise on a US-only backend is documented in our internal compliance plan § 6. Malaysia does not impose a comprehensive data-localisation mandate on parental-control services at the Effective date, with the exception of certain sector-specific regimes (e.g., the Bank Negara Malaysia directives on outsourcing by Malaysian banks — not applicable to Balance; the Securities Commission Malaysia directives — not applicable to Balance; certain Health Ministry directives on healthcare data localisation — not applicable to Balance).
10. Sub-processors touching Malaysian-resident data
| Sub-processor | Role | Location of processing | Malaysian transfer paperwork |
|---|---|---|---|
| Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (MongoDB, Inc., US) for the production database; relationship governed by Emergent ToS (22 Dec 2025) + Privacy Policy (28 May 2026) as the GDPR Art 28(3) "other legal act" (no standalone DPA available outside Enterprise per Emergent final position 2026-06-10; full handling in our internal vendor-handling plan); MongoDB Atlas Customer DPA + EU SCCs Module 2 + UK IDTA Addendum at https://www.mongodb.com/legal/dpa cover the storage layer | Hosts the FastAPI backend + MongoDB cluster | United States | PDPA s 129 limb (b) written processor agreement with PDPA-equivalent safeguards + limb (d) parent's consent on file per our international-transfer pack § 6; E2EE supplementary measure for proof media; ASEAN Model Contractual Clauses substance. |
| Google LLC — Google Cloud Storage (USA) | Stores end-to-end-encrypted proof-media ciphertext | United States (us multi-region) |
PDPA s 129 limb (b) written processor agreement (Google Cloud Data Processing Addendum) + limb (d) consent; ciphertext-only handling. |
| Google LLC via Google Cloud (USA) | Periodic (daily) backups of our operational database | United States (us multi-region) |
PDPA s 129 limb (b) written processor agreement (Google Cloud Data Processing Addendum) + limb (d) consent; the backup archive holds the operational data we hold about the resident (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens), other than the items that never reach our backend in readable form (the kid's proof media and the media-encryption keys); retained on a 30-day rolling window, then automatically deleted. |
| Google LLC — Firebase Cloud Messaging | Delivers push notifications to Malaysian kid + parent devices | United States | PDPA s 129 limb (b) + limb (d) as above; push body deliberately free of sensitive content (cross-reference: the just-in-time permission disclosures). |
| Google LLC — Google Sign-In | Authenticates parent Google identity (when used) | United States | PDPA s 129 limb (b) + limb (d) as above. |
| Google LLC — Google Play Billing | Processes subscription purchases | United States | PDPA s 129 limb (b) + limb (d) + Google Play Developer Distribution Agreement. |
| Resend, Inc. (San Francisco, CA, USA) | Delivers transactional email to Malaysian parent users | United States | PDPA s 129 limb (b) + limb (d). |
Every sub-processor is bound by a written data-processing agreement that forbids processing of any data we transmit for any purpose other than performing the service we engaged them for, and that incorporates the security and confidentiality controls in our Records of Processing Activities (Article 30) § 7 + PDPA s 9 PDPP 4 + PDP Standards 2015. The full sub-processor list, with each row's processor-agreement status, is at our sub-processor register.
11. Breach notification — PDPA section 12B (2024 Amendment Act) + PDP Commissioner Guideline on Notification of Personal Data Breach (29 May 2025)
PDPA section 12B (introduced by the 2024 Amendment Act, in force from 1 June 2025) + the PDP Commissioner Guideline on Notification of Personal Data Breach of 29 May 2025 is the principal breach-notification regime. The Malaysian regime requires 72-hour PDP Commissioner notification from awareness of a significant personal data breach:
| Audience | Trigger | Deadline | Channel |
|---|---|---|---|
| PDP Commissioner | A significant personal data breach has occurred — defined by PDPA s 12B + the Guideline on Notification of Personal Data Breach as a breach of the PDPP 4 security obligation that involves (a) personal data of a significant number of data subjects (the Guideline references a threshold of approximately 1,000 data subjects as the operational anchor + scaled to the data user's normal processing volume) OR (b) sensitive personal data OR (c) data that is likely to cause significant harm to the data subjects OR (d) circumstances of significant operational complexity. | 72 hours from awareness of the significant data breach. Awareness is the time at which the data user has a reasonable degree of certainty that a personal data breach has occurred. Balance internal anchor: as soon as practicable but no later than 72 hours from initial discovery. | JPDP Personal Data Breach Notification portal + by email to aduan@pdp.gov.my |
| Affected individuals | A significant personal data breach as above where, on the harm-likelihood analysis under PDPA s 12D + the Guideline, affected-individual notification is warranted to allow the affected individuals to take protective measures. | As soon as practicable after PDP Commissioner notification, with carve-outs in the Guideline (where the data has been rendered unintelligible — e.g., the E2EE ciphertext case — affected-individual notification may not be warranted; where the PDP Commissioner directs otherwise). | Direct email to the affected parent on file; in-app banner where the parent is logged in; out-of-app contact via the public-website incident page if email is no longer deliverable. The notification is in English, with a Bahasa Malaysia version queued for the Phase-2 locale rollout. |
| CSAE-specific | An incident with a CSAE component. | Per § 14 below + the internal runbook (M1). | PDRM D11 + JKM + KPWKM + CSM. |
The internal breach-decision SLA is at our breach-notification runbook § 5.4 + § 9: preliminary classification within one business day, formal assessment under PDPA s 12B + Guideline completed within 48 hours of discovery for significant-data-breach escalation, PDP Commissioner notification within the 72-hour statutory window, affected-individual notification per the harm-likelihood analysis.
11.1 Minimum content of the PDP Commissioner notification (PDPA s 12C + PDP Commissioner Guideline on Notification of Personal Data Breach)
The PDP Commissioner notification states:
- the nature of the significant personal data breach, the description of how the breach occurred, the personal data possibly involved, the chronology of the events leading up to the loss of control of the personal data;
- the categories and approximate number of data subjects involved (or the best estimate);
- the description of the likely consequences of the breach;
- the measures taken or proposed to be taken to address the breach (including measures to mitigate possible harm or negative consequences);
- the name and contact details of the DPO (, named individual: ) — the contact from whom the affected data subjects may obtain additional information.
The English-language template lives in our breach-notification runbook § 8.1. A Bahasa Malaysia version is queued for Phase 2 locale rollout.
11.2 Non-compliance — PDPA Part IX + Part VII offences
- PDPA s 12E offence — failure to notify a significant personal data breach to the PDP Commissioner — fine up to RM 250,000 + imprisonment up to 2 years.
- PDPA general non-compliance penalties (2024 Amendment Act s 5 quantum) — up to RM 1 million + imprisonment up to 3 years.
- PDPA s 5(3) aggravated offence by officer in default — additional individual liability up to RM 500,000 + imprisonment up to 2 years.
11.3 Concurrent CMA-1998 notification
For incidents involving network facilities or network services, the Communications and Multimedia (Anti-Spam) Regulations 2013 + the MCMC operational guidance on cyber-incident handling may require concurrent MCMC notification. Balance is not a CMA licensee and the concurrent-MCMC-notification pathway is unlikely to be engaged for ordinary breach scenarios.
12. Cookies, spam, and electronic direct marketing
Malaysia does not have a dedicated ePrivacy / cookies statute. The substantive position on cookies and electronic direct marketing is derived from: (i) PDPA s 6 + s 7 + s 8 for any cookie that processes personal data; (ii) the PDP Commissioner's interpretive position on cookies in the Guideline on Data Subject's Rights including Data Portability of 29 May 2025 and broader interpretive practice; (iii) the Communications and Multimedia (Anti-Spam) Regulations 2013 for commercial electronic messages; (iv) PDPA section 43 right to prevent processing for direct marketing.
12.1 In-app — strictly-necessary storage only
The Balance app (parent and kid) does not deploy any cookie-equivalent storage that is not strictly necessary for the service. The strictly-necessary storage Balance uses (authentication tokens in Android SecureStore; the device-pairing key wrap; the kid app's earned-time cache) is operationally necessary and is covered by the parent's sign-up consent.
12.2 Public legal-documents site — no analytics, no advertising, no tracking
The public legal-documents site (balance.babayagaprogram.com) uses only strictly-necessary cookies; no analytics cookies; no advertising cookies; no third-party trackers; no fingerprinting; no embedded social plugins.
12.3 Electronic direct marketing — not sent
Balance does not send commercial electronic messages within the meaning of the Communications and Multimedia (Anti-Spam) Regulations 2013 to Malaysian residents. The only email Balance sends to Malaysian parent users is transactional — account creation, password reset, subscription receipts, security alerts, and parent-action notifications. The Anti-Spam Regulations commercial electronic message definition requires the message to promote or solicit the supply of goods or services for a commercial purpose; transactional messages are outside the definition. If Balance ever introduces a marketing channel, we will comply with the Anti-Spam Regulations: (i) prior consent from the recipient (opt-in); (ii) clear identification of the sender; (iii) a clearly-identified opt-out mechanism in the body; (iv) honour an opt-out request within a reasonable time. We will also comply with PDPA section 43 right to prevent processing for direct marketing.
12.4 No telemarketing
Balance does not place telemarketing voice calls, SMS, or messaging-app outreach to Malaysian residents.
13. Lawful-access requests and the encryption posture
Malaysian authorities may serve a lawful-access request on Balance via:
- A judicial search warrant under the Criminal Procedure Code (Act 593) sections 54 + 55 + 116A — the principal mechanism for compelling production of stored personal data in connection with a criminal investigation.
- A production order under the Computer Crimes Act 1997 (Act 563) + the Communications and Multimedia Act 1998 (Act 588) Part X powers of investigation.
- A judicial interception order under the Criminal Procedure Code section 116C + the Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (Act 613) (AMLA) Part IV intercept regime.
- A Sexual Offences Against Children Act 2017 section 18 order for the production of communications data + electronic content + child-pornography material — for SOACA investigations.
- A PDP Commissioner enforcement notice under PDPA section 90 + PDP Commissioner investigation power under PDPA section 101 + section 110.
- An ordinary civil-court production order or subpoena under the Rules of Court 2012.
- A Mutual Assistance in Criminal Matters Act 2002 (Act 621) request channelled through the Attorney General's Chambers — for foreign-state cooperation.
- The Communications and Multimedia (Amendment) Act 2024 designated-platform regime — Balance is not a designated platform (below 8M Malaysian-resident user threshold).
- A prerogative-writ application under the Specific Relief Act 1950 (Act 137) + the Rules of Court 2012 + the Courts of Judicature Act 1964 (Act 91) + the Federal Constitution Article 121 + Article 125 for judicial review of executive action.
The Balance architectural posture interacts with these mechanisms as follows:
- Proof media is end-to-end encrypted. The kid's device generates a fresh per-file file-encryption key, encrypts the proof file with XChaCha20-Poly1305, wraps the file-encryption key to each authorised parent device's X25519 public key, and uploads only the resulting ciphertext + the recipient-wrap envelopes. We do not retain a master key, a backdoor, or any other means by which we could ourselves decrypt the proof media. PDPA s 9 PDPP 4 security obligation + PDP Standards 2015 + the Computer Crimes Act 1997 section 5 prohibition on unauthorised modification + the Criminal Procedure Code section 116C judicial-order requirement for interception all reinforce the design choice.
- No assistance with bulk plaintext interception. Balance does not perform bulk plaintext content scanning. Balance does not deploy a server-side content-moderation engine on the proof-media payload. There is no plaintext on our side to be intercepted.
- Response protocol. On receipt of a lawful-access request directed at proof media, we will: 1. acknowledge receipt within one business day; 2. engage Malaysian counsel to assess the validity of the request and the appropriate response under PDPA s 39 carve-outs + PDPA s 6(2)(c) legal-obligation basis + the relevant lawful-access statute + the Federal Constitution Article 5 proportionality screen; 3. preserve the relevant ciphertext for the period the request requires (subject to our retention rules); 4. inform the requesting authority that the proof media is end-to-end encrypted and that plaintext is not available from us; 5. cooperate in identifying and serving the lawful-process route to the parent — who holds the decryption key — if that is the appropriate channel.
- CSAE-cooperation overlay. Notwithstanding the encryption posture, Balance cooperates fully with the PDRM D11, the PDRM Cyber Crime and Multimedia Investigation Division, the KPWKM-administered SOACA enforcement bodies, the JKM, and CyberSecurity Malaysia on any CSAE-related referral, via the routes in § 14 below.
- Notification of the data subject. Where the lawful-access request is not accompanied by a non-disclosure obligation, we will inform the affected parent of the request (PDPA s 7 PDPP 2 + the PDP Commissioner interpretive practice on transparency in lawful-access matters). Where the request is accompanied by a statutory non-disclosure obligation (e.g., under the Criminal Procedure Code section 116D non-disclosure orders or the Security Offences (Special Measures) Act 2012 (Act 747) (SOSMA) framework), we will comply with the order and inform the parent as soon as the order permits.
The full encryption posture is in our encryption-posture record.
14. CSAE reporting routes — Malaysia
A Malaysian resident (parent, kid, or third party) who wishes to report a CSAE concern about Balance, about a third party encountered outside Balance, or about a Balance user, may use any of the following routes:
- Balance Designated Child Safety Officer:
(named individual: ). Acknowledgement within one business day, in English. - Royal Malaysia Police — emergency 999 (Bahasa Malaysia: Polis 999); non-emergency 03-2266 2222 for general police enquiries.
- PDRM Sexual Crimes, Children and Domestic Violence Investigation Division (D11) — for sexual offences against children + SOACA enforcement. Via 999 + via the PDRM website at
https://www.rmp.gov.my/. - PDRM Cyber Crime and Multimedia Investigation Division (D5(6)) — for online CSAE + cyber-crime investigation. Online reporting at
https://www.rmp.gov.my/+ via the CyberCrime Alert System athttps://ccid.rmp.gov.my/. - Talian Kasih 15999 — KPWKM/JKM 24/7 hotline — the principal Malaysian child-protection + family-violence hotline. Dial 15999 (toll-free).
- Cyber999 Help Centre — CyberSecurity Malaysia (CSM) / MyCERT — for cyber-incident reporting + CSAE technical incident handling. Phone 1-300-88-2999 + online at
https://www.mycert.org.my/portal/index.html. - CyberSAFE Malaysia — CSM-operated online-safety awareness initiative + CSAE technical-incident routing. Online at
https://www.cybersafe.my/. - Ministry of Women, Family and Community Development (KPWKM) — SOACA implementing ministry. Online at
https://www.kpwkm.gov.my/. - Department of Social Welfare (JKM) — Child Act 2001 child-protection lead agency. Online at
https://www.jkm.gov.my/+ via Talian Kasih 15999. - SUHAKAM Children's Commissioner — independent child-rights advocacy. Online at
https://www.suhakam.org.my/+ Hotline +60 3 2612 5600. - Childline Foundation Malaysia — children's helpline NGO via Talian Kasih 15999.
- Protect and Save the Children (PS) Malaysia — children's protection NGO. Online at
https://psthechildren.org.my/. - WAO — Women's Aid Organisation — for women + child sexual-violence services. Hotline +60 3 3000 8858 + SMS / WhatsApp TINA at +60 18 988 8058 + online at
https://wao.org.my/. - Befrienders Kuala Lumpur — 24-hour emotional-support hotline. Phone +60 3-7956 8145 + online at
https://www.befrienders.org.my/. - MIASA — Mental Illness Awareness and Support Association — mental health crisis support. Online at
https://miasa.org.my/. - ICMEC — International Centre for Missing & Exploited Children —
https://www.icmec.org/. Malaysia coordination via INTERPOL Kuala Lumpur Sub-Bureau. - INHOPE — Malaysia does not currently have a domestic INHOPE-member hotline at the Effective date. Cross-border CSAM reports flow through PDRM D11 + PDRM Cyber Crime + INTERPOL Kuala Lumpur + the international INHOPE network.
The full CSAE Country Routing Table is in Child Safety Standards § 8.6.
15. Complaint routes (summary)
A Malaysian resident who is dissatisfied with Balance's handling of a privacy enquiry or a child-safety concern may complain to any of the following authorities:
| Authority | Subject matter | Address / URL |
|---|---|---|
| Personal Data Protection Department (JPDP) | PDPA | Aras 6, Kompleks Kementerian Komunikasi dan Digital, Lot 4G9, Persiaran Perdana, Presint 4, 62100 Putrajaya; https://www.pdp.gov.my/; +60 3 8911 7000; aduan@pdp.gov.my |
| Ministry of Digital | JPDP parent ministry | Aras 1-4, Blok B, Kompleks Kementerian Komunikasi dan Digital, Lot 4G9, Persiaran Perdana, Presint 4, 62100 Putrajaya; https://www.digital.gov.my/ |
| Personal Data Protection Appeal Tribunal | Appeals from PDP Commissioner decisions under PDPA Part XI | via JPDP |
| Malaysian Communications and Multimedia Commission (MCMC) | CMA 1998 + Anti-Spam Regulations | https://www.mcmc.gov.my/; 1-800-188-030 |
| Royal Malaysia Police — D11 + Cyber Crime Division | CSAE + cybercrime | https://www.rmp.gov.my/; emergency 999; non-emergency 03-2266 2222 |
| Ministry of Women, Family and Community Development (KPWKM) | SOACA implementing ministry; Talian Kasih 15999 | https://www.kpwkm.gov.my/ |
| Department of Social Welfare (JKM) | Child Act 2001 child-protection | https://www.jkm.gov.my/; Talian Kasih 15999 |
| Ministry of Domestic Trade and Cost of Living (KPDN) | Consumer Protection Act + Electronic Trade Transactions Regulations | https://www.kpdn.gov.my/; 1-800-886-800 |
| Tribunal for Consumer Claims (TTPM) | Small consumer claims up to RM 50,000 | https://ttpm.kpdn.gov.my/ |
| CyberSecurity Malaysia (CSM) / MyCERT | Cyber-incident handling | https://www.cybersecurity.my/; Cyber999 Help Centre 1-300-88-2999 |
| SUHAKAM | Independent human-rights advocacy + Children's Commissioner | https://www.suhakam.org.my/; +60 3 2612 5600 |
| Sessions Court | PDPA Part IX civil action up to RM 250,000; SOACA + Child Act 2001 prosecutions | via https://www.kehakiman.gov.my/ |
| High Court of Malaya / High Court of Sabah and Sarawak | PDPA Part IX civil action above Sessions Court limits; judicial review; PDP Commissioner + Appeal Tribunal appeals | via https://www.kehakiman.gov.my/ |
| Court of Appeal | Appellate review | via https://www.kehakiman.gov.my/ |
| Federal Court of Malaysia | Final appellate review on points of law; constitutional matters | https://www.kehakiman.gov.my/ |
A Malaysian resident may always first raise the matter with us at (data access; named individual: , in his capacity as the DPO under PDPA s 12A + the PDP Commissioner Guideline on Appointment of Data Protection Officer of 29 May 2025). We will respond within the PDPA timelines. The JPDP's published policy recommends raising the matter with the data user first but the JPDP also accepts direct complaints where the data subject demonstrates that internal-remedy exhaustion is impracticable or where the complaint involves a serious matter warranting immediate JPDP action.
16. Consumer rights — the CPA 1999 + Electronic Trade Transactions Regulations + Sale of Goods Act 1957 + Contracts Act 1950 overlay
The Consumer Protection Act 1999 (Act 599) (the "CPA 1999"), the Consumer Protection (Electronic Trade Transactions) Regulations 2012 (the "ETT Regulations 2012"), the Sale of Goods Act 1957 (Act 382) ("SGA 1957"), and the Contracts Act 1950 (Act 136) apply to Balance's subscription flow as a consumer transaction (the parent is a consumer within the CPA 1999 s 3 definition — using goods or services ordinarily acquired for personal, domestic or household purposes). Treatment is implemented in Subscription Terms § 20.
16.1 CPA 1999 Part II — misleading or deceptive conduct + false representations + unfair practices
CPA 1999 section 9 prohibits misleading or deceptive conduct in trade in relation to goods or services. CPA 1999 section 10 prohibits false or misleading representations. CPA 1999 sections 11–18 prohibit specific unfair practices. The Balance Terms of Service (Terms of Service) and the in-app subscription flow are drafted to avoid each section 9–18 risk.
16.2 CPA 1999 Part IIIA — unfair contract terms
CPA 1999 Part IIIA (introduced by the Consumer Protection (Amendment) Act 2010 in force 1 July 2010) prohibits unfair contract terms in consumer contracts: - s 24A definition of unfair contract terms (procedurally unfair / substantively unfair) — drawn broadly with detailed indicia at ss 24C–24E. - s 24C procedural unfairness factors (relative bargaining position + extent of negotiation + extent of understanding + standard-form character). - s 24D substantive unfairness factors (against good faith / good conscience / equity / community standards of fairness). - s 24E other relevant matters. - s 24G — Tribunal for Consumer Claims and the Court have power to declare any contract term to be unfair + to refuse to enforce + to limit or modify.
Balance's Terms of Service and Subscription Terms are drafted to comply with CPA 1999 Part IIIA. Choice-of-law clauses or jurisdiction clauses that would deprive the Malaysian consumer of mandatory protection are subject to CPA 1999 s 24A + s 24D + the public policy doctrine in Cap n° 4 Allwood Ltd v Yong Sek Choo [2017] MLJU 678.
16.3 Consumer Protection (Electronic Trade Transactions) Regulations 2012 — supplier disclosure
The ETT Regulations 2012 require the supplier in an electronic trade transaction to disclose, in a prominently displayed manner: (i) the supplier's name + business address + means of contact (Reg 3(1)(a)); (ii) the nature of the goods or services (Reg 3(1)(b)); (iii) the price including taxes + the delivery and payment terms (Reg 3(1)(c)); (iv) the cancellation and refund policy (Reg 3(1)(d)); (v) the delivery method and time (Reg 3(1)(e)); (vi) terms of supply (Reg 3(1)(f)); (vii) the consumer's privacy rights and the supplier's policies on data protection (Reg 3(1)(g)). Balance's pre-contract subscription screen + the in-app subscription terms + the Subscription Terms document (Subscription Terms) implement each disclosure.
16.4 CPA 1999 Part IX — non-excludable services guarantees
CPA 1999 Part IX prescribes non-excludable guarantees in the supply of services: - s 53 guarantee as to reasonable care and skill; - s 54 guarantee as to fitness for particular purpose; - s 55 guarantee as to reasonable time; - s 56 guarantee as to reasonable price.
Applied to Balance's subscription supply as the supply of services to a consumer; reasonable care + skill + fitness + reasonable time + reasonable price are non-excludable guarantees of the subscription contract. Section 64 prohibits contracting out of the Part IX guarantees in any consumer contract.
16.5 No statutory cooling-off period under Malaysian general law for online subscription contracts
Malaysian general consumer-protection law does not include a statutory cooling-off period for distance-selling contracts (in contrast with the SG CPFTA, the IL Consumer Protection Law s 14C 14-day cooling-off, the AR CDC 10-business-day botón de arrepentimiento, the EU Consumer Rights Directive 14-day right of withdrawal, and similar regimes). Specific sector-specific cooling-off rules apply to certain product categories (e.g., direct-sales contracts under the Direct Sales and Anti-Pyramid Scheme Act 1993 (Act 500) + the Direct Sales (Door-to-Door Sales)(Conduct) Regulations 1993 — n/a to Balance because Balance is not a direct seller). Balance honors a voluntary 14-day no-questions refund window via Google Play Billing, exceeding the Malaysian general-consumer-protection minimum.
16.6 Refunds and the Malaysian subscription posture
Balance honors a voluntary 14-day no-questions refund window via Google Play Billing, exceeding the Malaysian consumer-protection minimum. The 14-day refund window is documented at Subscription Terms § 20.
16.7 Contracts Act 1950 — capacity-of-minors framework + Age of Majority Act 1971
Under Contracts Act 1950 s 11 + Age of Majority Act 1971 s 2, a kid (under 18) cannot enter into a binding contract. The subscription contract is between Balance and the parent (who is 18+ — the Age of Majority Act 1971 confirms the age of majority). The kid is a beneficiary of the service supplied to the parent. Balance does not contract directly with kids.
16.8 Forum and choice of law
The Balance Terms of Service preserve the consumer's domicile forum (see Terms of Service § 19); choice-of-law clauses that would displace CPA 1999 to the prejudice of the Malaysian consumer are subject to CPA 1999 s 64 (no contracting out) + CPA 1999 Part IIIA unfair-contract-terms screen + the public policy doctrine.
17. Cross-references
- Global Privacy Policy: Privacy Policy (H1).
- Children's Privacy Notice: Children's Privacy Notice (H2).
- Terms of Service: Terms of Service (H3).
- Subscription Terms: Subscription Terms (H4).
- Child Safety Standards: Child Safety Standards (H5).
- Retention Policy: Data Retention & Deletion Policy (H6).
- Records of Processing: our Records of Processing Activities (Article 30) (H7).
- DPIA + LIA: our Data Protection Impact Assessment (H8).
- Breach Runbook: our breach-notification runbook (M1).
- Transfer Pack: our international-transfer pack (M2) — PDPA s 129 limb (b) written processor agreements with PDPA-equivalent safeguards + limb (d) parent's consent + ASEAN Model Contractual Clauses substance on file.
- JIT Permission Disclosures: the just-in-time permission disclosures (M3).
- Play Console Permission Declarations: the Play Console permission declarations (M4).
- Play Console Data Safety: the Play Console Data Safety form (M5).
- Play Console Child Safety Standards Declaration: the Play Console Child Safety Standards declaration (M6).
- Play Console Target Audience + IARC: the Play Console Target Audience form (M7).
- US Country Annex: United States annex (A-US).
- UK Country Annex: United Kingdom annex (A-UK).
- EU/EEA Country Annex: EU / EEA annex (A-EU-EEA).
- Argentina Country Annex: Argentina annex (A-AR).
- Chile Country Annex: Chile annex (A-CL).
- Colombia Country Annex: Colombia annex (A-CO).
- Peru Country Annex: Peru annex (A-PE).
- Uruguay Country Annex: Uruguay annex (A-UY).
- Canada Country Annex: Canada annex (A-CA).
- Australia Country Annex: Australia annex (A-AU).
- New Zealand Country Annex: New Zealand annex (A-NZ).
- Singapore Country Annex: Singapore annex (A-SG).
- Philippines Country Annex: Philippines annex (A-PH).
- Israel Country Annex: Israel annex (A-IL).
- Hong Kong Country Annex: Hong Kong annex (A-HK).
- App Classification: our country classification table.
- Sub-processor list: our sub-processor register.
- Android Permissions Register: our permissions register.
- Encryption Posture: our encryption-posture record.
- Data Flow / Inventory Map: our internal data-flow map.
- Phase-2 Placeholder Tracker: our internal compliance tracker.
- Compliance Plan: our internal compliance plan.
18. Versioning and review
This Annex follows the same strict versioning protocol as the rest of the Phase-1 bundle:
- Every change to a substantive row in §§ 2–16 bumps the Last updated date at the top of this file and triggers a re-publication at Privacy Policy and Children's Privacy Notice.
- A material amendment to the PDPA (Act 709) — including the bringing into force of any provision of the Personal Data Protection (Amendment) Act 2024 (Act A1709) that is not yet operationally in force at the Effective date (the principal substantive provisions are in force from 1 June 2025; subsidiary instruments under the 2024 Amendment Act remain to be issued in part) — triggers an off-cycle rewrite of §§ 2, 4, 6, 8, and 11.
- A new or amended PDP Commissioner Guideline, Code of Practice, Directive, or Determination — including any revision to the Guideline on Appointment of Data Protection Officer (29 May 2025), the Guideline on Notification of Personal Data Breach (29 May 2025), the Guideline on Cross-Border Personal Data Transfer (29 May 2025), the Guideline on Data Protection Impact Assessment (29 May 2025), the Guideline on Data Subject's Rights including Data Portability (29 May 2025), the Personal Data Protection Standards 2015, or the body of PDP Commissioner Codes of Practice — triggers an off-cycle update.
- A material amendment to the Child Act 2001 (Act 611), the Sexual Offences Against Children Act 2017 (Act 792), or the Penal Code (Act 574), in particular SOACA section 11 online-grooming + Penal Code Chapter XVI sexual offences against children, triggers an off-cycle update to §§ 5, 13, 14.
- A material amendment to the Computer Crimes Act 1997 (Act 563), the Communications and Multimedia Act 1998 (Act 588) + the Communications and Multimedia (Amendment) Act 2024, the Criminal Procedure Code (Act 593) section 116A + 116C, the Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (Act 613), or the Mutual Assistance in Criminal Matters Act 2002 (Act 621) triggers an off-cycle update to § 13.
- A material amendment to the Consumer Protection Act 1999 (Act 599), the Consumer Protection (Electronic Trade Transactions) Regulations 2012, the Sale of Goods Act 1957 (Act 382), the Contracts Act 1950 (Act 136), or the Age of Majority Act 1971 (Act 21) triggers an off-cycle update to § 16 + Subscription Terms.
- A material amendment to the Communications and Multimedia (Anti-Spam) Regulations 2013 triggers an off-cycle update to § 12.
- A material decision of the Personal Data Protection Appeal Tribunal under PDPA Part XI, of the Sessions Court / High Court / Court of Appeal / Federal Court of Malaysia bearing on the PDPA, on Federal Constitution Article 5 read with Sivarasa Rasiah, or on the common-law privacy doctrine of Malaysia per Lee Ewe Poh v Dr Lim Teik Man [2011] 1 MLJ 835 (High Court), triggers an off-cycle update.
- Malaysia's accession to (or domestic implementation of) the Council of Europe Convention 108 / 108+ or the Convention on Cybercrime (Budapest Convention) triggers an off-cycle update to § 2 + § 8 + § 13.
- A new EU adequacy decision for Malaysia (currently none at the Effective date) triggers an off-cycle update to § 8 + § 9.
- A change to Malaysia's APEC CBPR participation status or the operational designation of the JPDP as APEC CBPR Accountability Agent triggers an off-cycle update to § 8.
- The issuance of subsidiary instruments under the 2024 Amendment Act not yet issued at the Effective date triggers an off-cycle update.
- A material change to a sub-processor's PDPA-equivalent-safeguards status triggers an off-cycle update to § 8 + § 10 + our sub-processor register.
- The annual review is by 9 June. The DPO signs the review off; the Designated Child Safety Officer co-signs any change to § 3 (supervisory authorities), § 5 (children's rights), § 11 (breach), § 13 (lawful-access), or § 14 (CSAE routes).
- This Annex is republished alongside H1 and H2 at the public legal-documents site (Privacy Policy and Children's Privacy Notice) and is incorporated by reference. The Bahasa Malaysia translation is queued for the Phase-2 locale rollout per our internal compliance tracker; the Mandarin Chinese and Tamil translations are queued in the same Phase-2 rollout.
End of Malaysia Country Annex.