Data Protection & Cybersecurity Policy

Newvest Recoveries Sdn Bhd

Last updated: April 2026

1. Purpose of This Policy

This Data Protection & Cyber Security Policy explains the measures adopted by Newvest Recoveries Sdn Bhd (“Newvest”, “we”, “our” or “us”) to safeguard personal data and protect information systems used in connection with our website and debt recovery operations.

This Policy is intended to provide transparency on our security governance and demonstrates our commitment to protecting information in accordance with applicable Malaysian laws and regulatory expectations.


2. Scope

This Policy applies to:

  • Personal data processed through or in connection with the Newvest website;
  • Information systems, platforms and digital tools used for debt recovery activities; and
  • Employees, contractors and authorised representatives who access or process data on behalf of Newvest.

This Policy should be read together with the Privacy Notice, which explains how personal data is collected, used and disclosed.


3. Regulatory Framework

Newvest’s data protection and security practices are designed to align with:

  • The Personal Data Protection Act 2010 (PDPA);
  • Principles and guidance issued by the Jabatan Perlindungan Data Peribadi (JPDP); and
  • Industry-appropriate information security standards commonly expected of entities operating within the financial services and debt recovery ecosystem.

4. Information Security Governance

Data protection and cyber security are overseen by Newvest’s management and compliance functions and are embedded within our operational controls.

Responsibilities include:

  • Establishing internal data protection and security policies;
  • Promoting awareness and accountability among personnel;
  • Monitoring compliance with legal and contractual obligations; and
  • Reviewing risks associated with information handling and system access.

5. Security Measures

Newvest adopts a layered approach to information security, which includes technical, organisational and physical safeguards appropriate to the nature of our operations.

(a) Technical Safeguards

These include, where appropriate:

  • Controlled system access based on job roles;
  • Authentication measures for authorised users;
  • Monitoring of system activity to detect unauthorised access or misuse.

(b) Organisational Safeguards

  • Confidentiality obligations imposed on employees and contractors;
  • Training and awareness on responsible data handling;
  • Segregation of duties and supervision to reduce misuse risk.

(c) Physical Safeguards

  • Controlled access to offices and equipment;
  • Secure storage of physical records and devices.

Specific security configurations are not publicly disclosed to preserve system integrity.


6. Data Access and Use Controls

Access to personal data and systems is limited to authorised individuals who require such access for legitimate business purposes.

Newvest applies the principle of least privilege, ensuring that access rights are proportionate to role and responsibility and are reviewed periodically.


7. Third-Party Risk and Data Sharing

Where Newvest engages third-party service providers (such as IT service providers or authorised recovery agents):

  • Sharing of information is limited to what is necessary;
  • Appropriate contractual and confidentiality obligations are imposed; and
  • Third parties are expected to implement adequate security measures.

8. Incident and Breach Management

Newvest maintains internal procedures to identify, assess and respond to suspected or actual information security incidents, including personal data breaches.

Where required by law, contractual obligation or regulatory expectation, appropriate notifications and corrective actions will be taken in a timely manner.


9. Retention and Secure Disposal

Information is retained only for as long as necessary for operational, legal and regulatory purposes.

When data is no longer required, it is securely disposed of or destroyed using methods appropriate to the format and sensitivity of the information.


10. Continuous Review and Improvement

Data protection and cyber security risks evolve over time.
Newvest therefore reviews this Policy and related controls periodically to ensure they remain effective, relevant and aligned with regulatory expectations and operational needs.


11. Transparency and Updates

This Policy may be updated from time to time to reflect changes in law, technology or business operations.
The most current version will be made available on our website.


12. Contact and Queries

For queries relating to data protection or information security practices, please contact:

Newvest Recoveries Sdn Bhd
Attention: IT & Compliance Function