CNSP / PRIVACY POLICY
person
SOTON CNSP COMPLIANCE • DRAFT FOR REVIEW

SOTON CNSP PRIVACY POLICY

EFFECTIVE DATE [TO BE CONFIRMED]
LAST UPDATED [TO BE CONFIRMED]
POLICY VERSION 1.0 (Draft for Review)
CLAUSE 01

1. INTRODUCTION

This Privacy Policy explains how the SOTON CNSP platform ("the Platform," "the System," or "CNSP") collects, uses, stores, and protects personal data submitted by users.

SOTON CNSP is a digital platform designed to support the administration and management of clubs, societies, and events associated with the University of Southampton Malaysia Student Association (UoSMSA).

This policy applies to all users of SOTON CNSP, including:

  • Student leaders and committee members
  • Club and society members
  • Event organisers
  • Event participants
  • Administrative personnel

This policy is not intended to apply to other University of Southampton systems, services, or platforms. If you use other university systems, those systems have separate privacy policies.

CLAUSE 02

2. WHO WE ARE

2.1 About SOTON CNSP

SOTON CNSP is the administrative platform for the University of Southampton Malaysia Student Association.

Important Clarification: The system was developed by Nilavarasen Subramaniam (Head of Operations & Systems, Term 25/26). Ownership of the system does not imply personal ownership of user data.

2.2 Data Controller / Responsible Entity

[LEGAL ENTITY AND DATA CONTROLLER STATUS TO BE CONFIRMED BEFORE PUBLICATION]

Currently, data appears to be processed under the responsibility of: UoSMSA (University of Southampton Malaysia Student Association), acting in its administrative capacity.

This point requires verification: Which legal entity is ultimately responsible for personal data processed through CNSP? Is it:

  • The University of Southampton?
  • UoSMSA as a registered student association?
  • An individual or officer?
  • A separate legal entity?

This must be clarified and confirmed before the policy is published.

2.3 Privacy Contact

Questions about data or privacy concerns?

Email: ns12n24@soton.ac.uk

Name: [TO BE CONFIRMED - Nilavarasen Subramaniam / Privacy Contact / Data Protection Officer]

[A dedicated privacy contact point should be established if this is a larger deployment]

CLAUSE 03

3. SCOPE OF THIS PRIVACY POLICY

This policy covers personal data processed through SOTON CNSP, including:

  • Data you voluntarily submit through forms
  • Data generated when you use the Platform (e.g., login timestamps, submissions)
  • Data you upload as supporting documentation
  • Information about other people you provide through the Platform

This policy does NOT cover:

  • Other University of Southampton systems or services
  • Email communications sent outside CNSP
  • University directories or public records
  • Data managed by external service providers independently of CNSP
  • Third-party social media or external platforms
CLAUSE 04

4. PERSONAL DATA WE COLLECT

4.1 Information You Provide Directly

4.1.1 Account & Authentication

  • Full name
  • University email address
  • User account credentials / authentication identifiers
  • Role (Student, Club Leader, Committee Member, Administrator, etc.)
  • Club or society affiliation
  • Contact information (if different from university email)

4.1.2 Club & Society Information

  • Club/society name and code
  • Committee member names and positions
  • Officer contact information
  • Committee responsibilities
  • Membership records (if tracked)
  • Organisational objectives and descriptions

4.1.3 Event Information

When you propose or review an event, you may provide:

  • Event name and description
  • Event date, time, and duration
  • Venue or location
  • Event objectives and purpose
  • Expected attendance/participant numbers
  • External participant information (if applicable)
  • VIP or guest information (if applicable)
  • Event budget or financial information
  • Risk assessment or safety documentation
  • Supporting documents or attachments

4.1.4 Financial Information

When using cash declaration or financial forms:

  • Expense descriptions
  • Amounts and currency
  • Revenue/income information
  • Financial approvals or status
  • Supporting receipts or invoices
  • Funding source information
  • Bank account details [IF AND ONLY IF the system actually requires these - to be confirmed]

4.1.5 Administrative & Compliance Information

  • Semester checkpoint submissions
  • Room booking requests
  • Attendance records (if applicable)
  • Approval workflows and status
  • Administrative communications
  • Supporting evidence or documentation

4.1.6 Event Photography & Media

  • Event photographs or videos
  • Images of participants
  • Event documentation media
  • Links to external media repositories
  • Photo permissions or consent records

4.1.7 Other Information You Submit

Any other personal information you voluntarily provide through forms, uploads, or submissions.

4.2 Information We Collect Automatically

4.2.1 Usage Information

When you access SOTON CNSP, we may automatically collect:

  • Login timestamps: When you log in and out of the system
  • Submission timestamps: When you submit forms or documents
  • Audit information: Records of administrative actions and approvals
  • Browser information: The type of browser and device you use [if automatically logged]
  • IP address: Your internet connection identifier [if logged by the system]
  • Session information: Duration of your use of CNSP

Clarification: Not all of the above are necessarily collected. Only information actually logged by CNSP is stored.

4.2.2 Local Browser Storage

SOTON CNSP uses browser localStorage to store limited information on your device:

  • Your username (for display purposes)
  • Session/authentication tokens
  • User preferences or settings

What this means: This information is stored locally on your computer or device, not automatically transmitted to CNSP servers. Clearing your browser data will remove this information.

4.2.3 Cookies

[TO BE CONFIRMED: Does CNSP use cookies?]

If cookies are used, they are likely for:

  • User authentication and session management
  • Remembering user preferences
  • Essential functionality

To be verified: Are non-essential cookies used for analytics, tracking, or advertising? The existing policy suggests not, but this should be confirmed.

CLAUSE 05

5. HOW WE COLLECT PERSONAL DATA

5.1 Direct Submission

You directly provide most personal data when you:

  • Create a user account
  • Complete event proposal forms
  • Submit event reviews
  • Request room bookings
  • Submit financial declarations
  • Upload supporting documents
  • Update committee information
  • Submit checkpoint or semester reports

5.2 Automatic Collection

Some information is automatically collected:

  • Login and submission timestamps
  • System audit information
  • Browser and device identifiers (if logged)
  • Session information

5.3 Information About Other People

When you submit information about other people (e.g., committee members, event participants, guests), you are responsible for:

  • Having appropriate authority to share their information
  • Ensuring they understand their information will be processed
  • Not sharing sensitive personal information unnecessarily
  • Providing accurate and current information
Example: Do not submit someone's NRIC (identification) number, passport number, or personal phone number unless absolutely required for the specific CNSP function.
CLAUSE 06

6. HOW WE USE PERSONAL DATA

6.1 Essential Platform Functions

User Authentication & Account Management

  • Creating and maintaining your CNSP account
  • Authenticating you as an authorised user
  • Managing your access level and permissions
  • Identifying you and your organisation

Event Administration & Workflow

  • Processing your event proposals
  • Managing approval workflows
  • Reviewing and evaluating events
  • Maintaining event records
  • Communicating about event status

Room Booking & Resources

  • Processing room booking requests
  • Managing venue allocation
  • Scheduling and coordination
  • Recording booking history

Financial Management

  • Processing financial declarations
  • Recording expense submissions
  • Managing financial approvals
  • Supporting audits and compliance

Administrative Coordination

  • Processing semester checkpoints
  • Managing committee information
  • Coordinating club/society activities
  • Maintaining organisational records

6.2 Legitimate Administrative Purposes

Accountability & Transparency

  • Maintaining audit trails
  • Recording who submitted what and when
  • Tracking approvals and decisions
  • Supporting accountability requirements

Risk Management & Safety

  • Identifying risk-related information
  • Managing event safety assessments
  • Recording risk mitigation measures
  • Supporting incident investigation if needed

Support & Troubleshooting

  • Responding to user questions or issues
  • Troubleshooting technical problems
  • Providing assistance with CNSP features
  • Improving platform functionality

System Security & Maintenance

  • Detecting and preventing unauthorised access
  • Maintaining system security
  • Preventing misuse or fraud
  • Updating and maintaining CNSP

6.3 Institutional & Legal Requirements

Depending on how CNSP is configured, data may be processed to:

  • Comply with institutional governance requirements
  • Support institutional audit functions
  • Meet institutional compliance obligations
  • Respond to legal requests from authorities
  • Protecting legitimate organisational interests

6.4 Uses We Do NOT Undertake

SOTON CNSP does NOT use your personal data for:

  • Commercial marketing or advertising
  • Selling or renting personal data to third parties
  • Profiling or automated decision-making [Unless this occurs - to be confirmed]
  • Creating psychological or financial profiles
  • Harassment or spam
  • Any purpose you have not explicitly authorised
CLAUSE 07

7. DISCLOSURE OF PERSONAL DATA

7.1 Who May Access Your Information

Personal data submitted through SOTON CNSP may be visible to:

7.1.1 Authorised Personnel

  • UoSMSA officers and administrators
  • Club/society committee members (for information about their club)
  • Approval authorities (for event proposals, financial declarations, etc.)
  • System administrators (for technical maintenance)

Access is limited to what is necessary. A financial approver should not see information unrelated to financial approvals.

7.1.2 Supporting Service Providers

  • Google Firebase (data storage and authentication provider)
  • IT/technical support personnel
  • Cloud infrastructure providers
  • Authentication service providers

These providers process data on behalf of CNSP, not for their own purposes.

7.1.3 Legal & Safety Situations

Your information may be disclosed if:

  • Required by law or court order
  • Requested by regulatory or governmental authorities
  • Necessary to prevent fraud, illegal activity, or harm
  • Necessary to protect the safety of individuals
  • Required by legitimate institutional governance

We will provide notice of such disclosures where legally possible.

7.2 Who We Do NOT Disclose To

SOTON CNSP does not share personal data with:

  • External commercial companies (beyond essential service providers)
  • Marketing or advertising partners
  • Social media platforms
  • Third-party data brokers
  • Entities unrelated to UoSMSA administration
  • Your data is not sold or rented
CLAUSE 08

8. THIRD-PARTY SERVICE PROVIDERS

8.1 Google Firebase

Service: Cloud-based data storage, authentication, and backend infrastructure

What they process: Personal data stored in CNSP, authentication information, session data

Purpose: Hosting and running SOTON CNSP

Location: [FIREBASE LOCATION TO BE CONFIRMED - likely United States]

Data Processing Agreement: [TO BE CONFIRMED - Should exist]

What this means: Your personal data is stored on Google's servers. Google is bound by contractual obligations to use this data only to provide CNSP services and not for other purposes.

8.2 Google Fonts & Material Symbols

Service: Typography and icon delivery
What they may collect: Your IP address, page you accessed, browser type (standard web server information)
Purpose: Delivering fonts and icons to your browser
Your control: If you want to limit this, you can disable web fonts in your browser settings

8.3 Tailwind CSS & External CDN Services

Service: Providing styling and design framework
What they may collect: Limited technical information if delivered via CDN
Purpose: Delivering web design resources

8.4 Other Service Providers [TO BE CONFIRMED]

The following should be verified and added if applicable:

  • [ ] Email delivery service (if CNSP sends emails)
  • [ ] Analytics services (if traffic/usage is monitored)
  • [ ] Document storage service (if used beyond Firebase)
  • [ ] Payment processing (if financial features are integrated)
  • [ ] Backup/disaster recovery providers
  • [ ] Security monitoring services
CLAUSE 09

9. INTERNATIONAL & CROSS-BORDER DATA TRANSFERS

9.1 Data Location

Important: While SOTON CNSP operates in Malaysia, personal data may be transferred to and processed in other countries, primarily through Google Firebase.

9.2 Google Firebase Location

Google Firebase is a US-based service. This means your personal data:

  • Is stored on servers in the United States (likely)
  • Is subject to US data security laws
  • May be subject to US government requests for information
  • Is processed by a US company

Malaysian Legal Context: The Personal Data Protection Act 2010 permits transfers of personal data outside Malaysia where:

  • Appropriate safeguards are in place
  • The recipient country provides adequate protection
  • Contractual safeguards are established
  • Specific legal exceptions apply

Status: The relationship between Malaysia's PDPA and US data protection is complex and evolving. [This should be reviewed with Malaysian legal counsel]

9.3 Your Rights Regarding Transfers

Under Malaysian law, you may have the right to:

  • Know where your data is transferred
  • Request information about safeguards
  • Understand the implications of cross-border transfer

This should be explained and verified by Malaysian legal counsel before publication.

CLAUSE 10

10. DATA SECURITY

10.1 Security Measures Implemented

SOTON CNSP implements the following safeguards:

Authentication & Access Control

  • Firebase Authentication (industry-standard authentication service)
  • Role-Based Access Control (RBAC) — different users have different permission levels
  • Secure credentials handling

Data Protection

  • Encrypted transmission (HTTPS/TLS encryption while data travels between your browser and servers)
  • Data stored securely on Firebase infrastructure
  • Access restricted to authorised personnel

System Monitoring

  • Audit logs of important actions
  • Monitoring for unauthorised access attempts
  • System logging of submissions and approvals

10.2 Important Limitations

Security is not absolute.

While SOTON CNSP uses industry-standard security measures, no digital system can guarantee 100% security. Potential risks include:

  • Unauthorised access by hackers or malicious actors
  • Compromise of cloud infrastructure
  • Human error or insider threats
  • Undetected vulnerabilities in software
  • Physical theft or loss of devices

10.3 Your Responsibility for Security

You are responsible for:

  • Keeping your password confidential
  • Not sharing your CNSP login credentials
  • Logging out after using shared computers
  • Protecting your device from malware
  • Reporting suspected security breaches
  • Clearing browser storage if using a shared device
CLAUSE 11

11. DATA RETENTION

11.1 Retention Principles

Personal data should not be retained indefinitely. SOTON CNSP retains information only as long as necessary for:

  • The purpose for which it was collected
  • Legal or institutional requirements
  • Audit or compliance purposes
  • Resolution of disputes or claims
  • Legitimate record-keeping

11.2 Retention by Category

[The following retention periods are TO BE CONFIRMED based on actual system design]
Data Category Retention Period Rationale
User Account Information Duration of CNSP use + [period] after account closure Account identification and audit
Event Proposals & Reviews End of academic year + [period] Institutional records and audit
Financial Declarations [Period per institutional requirement] Compliance, audit, financial records
Room Booking Records [Period per venue policy] Facility management and scheduling
Committee Information [Period per institutional requirement] Organisational continuity
Audit Logs & Timestamps [Period per security/audit policy] Security and accountability
Supporting Documents [Varies by document type] As required for associated processes
Event Photographs [To be confirmed] Depends on purpose (admin vs. promotional)

Status: Exact retention periods must be determined and documented before publication.

11.3 Deletion Upon Request

Upon request and subject to institutional approval, personal data may be deleted if:

  • No longer needed for the original purpose
  • No legal or institutional reason to retain it
  • Not part of an ongoing audit or investigation
  • The individual requesting deletion is authorised
CLAUSE 12

12. PERSONAL DATA RIGHTS & ACCESS

12.1 Access to Your Personal Data

Under Malaysian personal data protection law, you have the right to:

Request access to your personal data

  • You can request what personal data CNSP holds about you
  • We will provide this information in a clear format
  • There may be reasonable processing time
  • We may require verification of your identity

How to request: Email ns12n24@soton.ac.uk with your request

Exceptions: We may be unable to provide information if:

  • Disclosure would harm the privacy of others
  • Legal or institutional restrictions apply
  • The information is part of an active investigation

12.2 Correction of Inaccurate Data

You have the right to request correction if personal data held about you is:

  • Inaccurate or incomplete
  • Outdated or no longer relevant
  • Misleading or incorrect

How to request: Contact ns12n24@soton.ac.uk with details of the inaccurate information

We will:

  • Review your correction request
  • Make corrections where appropriate
  • Notify you of the outcome
  • Update audit records to reflect corrections

12.3 Withdrawal of Consent

Where CNSP processing is based on your consent, you may withdraw that consent by:

  • Notifying ns12n24@soton.ac.uk in writing
  • Requesting deletion of your account

Important: Withdrawal of consent does not apply retroactively. Information already processed may continue to be retained where legally required.

12.4 Other Possible Rights

Depending on final Malaysian legal analysis, you may have rights regarding:

  • Requesting information about how your data is used
  • Requesting restrictions on how your data is processed
  • Objecting to certain types of processing
  • Understanding automated decision-making (if used)

Status: These rights require confirmation of current Malaysian law applicability. [Malaysian legal review required]

CLAUSE 13

13. CHILDREN & MINORS

13.1 University Student Users

SOTON CNSP is designed for university students and student leaders, typically aged 18+.

However, some users may be under 18:

  • International foundation students
  • Early-entry students
  • Students with special circumstances

13.2 Event Participants Under 18

Events organised through CNSP may involve participants under 18, including:

  • School visitors or guests
  • Younger siblings at family events
  • Minors attending public university events

13.3 Data Protection for Minors

If personal data of minors is submitted through CNSP:

  • Such information should be submitted only where necessary
  • Additional safeguards apply to sensitive information
  • Parents/guardians should be informed where appropriate
  • Consent requirements may differ for minors
Example: Avoid submitting a minor's NRIC number, passport number, or personal phone number unless absolutely required.

13.4 Parental or Guardian Consent

[To be confirmed: Does CNSP require parental consent for minors' data? If so, what is the process?]

If your event involves minors, you may need to:

  • Collect parental consent for data processing
  • Provide parents with privacy information
  • Maintain consent documentation
CLAUSE 14

14. EVENT PHOTOGRAPHS, VIDEOS & MEDIA

14.1 Event Documentation Photography

Event photos may be submitted as part of:

  • Event review submissions
  • Event documentation
  • Proof of event completion
  • Record-keeping purposes

14.2 Use of Event Photos

Important distinction:

  • Administrative use: Photos submitted for event review/record-keeping are for internal CNSP use
  • Promotional use: Using photos for marketing, social media, or public publication is separate

If you submit a photo for event review documentation, you are NOT automatically giving permission for public promotion.

14.3 Photos Involving Other People

If your event photos include other people:

  • You should have obtained their permission to include them in CNSP submissions
  • Do not submit photos of people without their knowledge or consent
  • Be particularly careful with photos of minors
  • Consider the privacy of individuals in the background

14.4 Promotional Use of Photos

[To be confirmed: Does CNSP have a separate process for promotional photos?]

If CNSP (or UoSMSA) wants to use event photos for marketing, promotion, or public publicity:

  • Separate, explicit consent should be obtained
  • Individuals should know their image will be used publicly
  • This is separate from administrative documentation

Do not assume: Event documentation photos can be automatically used for promotional purposes.

14.5 Minors in Photographs

Special care applies to photographs containing minors:

  • Parental consent may be required
  • Consider the minor's privacy and dignity
  • Be cautious about identifying minors by name and photo together
  • Follow institutional guidance on minor photography
CLAUSE 15

15. COOKIES, LOCAL STORAGE & BROWSER TECHNOLOGIES

15.1 What These Technologies Do

Cookies: Small files stored on your computer by websites you visit
Local Storage: Information stored in your browser that websites can access
Session Storage: Temporary information cleared when you close your browser

15.2 How SOTON CNSP Uses These

Local Storage:
CNSP uses browser localStorage to store:

  • Your username (for displaying your name)
  • Authentication/session tokens
  • User preferences or settings

This information is stored on your device, not automatically transmitted to CNSP servers.

Cookies: [To be confirmed: Does CNSP use cookies? If so, for what purposes?]

15.3 Essential vs. Non-Essential

Essential: Cookies or storage necessary for CNSP to function (authentication, session management)

Non-Essential: Cookies used for analytics, tracking, advertising, or user profiling

Current status: SOTON CNSP does not appear to use non-essential tracking cookies. [This should be confirmed]

15.4 Your Control

You can:

  • Delete stored data by clearing your browser cache/storage
  • Disable cookies in your browser settings
  • Use private/incognito browsing mode to prevent local storage

Note: Disabling these may prevent CNSP from functioning properly.

15.5 Third-Party Tracking

Google Fonts and Material Symbols may collect limited information when loading:

  • Your IP address
  • The page you accessed
  • Your browser type
  • Approximate loading time

This is standard web server information and does not personally identify you.

CLAUSE 16

16. USER RESPONSIBILITIES

16.1 Accuracy of Information

When you submit information through CNSP, you are responsible for:

  • Providing accurate and current information
  • Updating information if it changes
  • Notifying CNSP if information becomes outdated
  • Correcting errors you identify

Examples:

  • Committee member contact information
  • Event details and schedules
  • Financial information and receipts
  • Personal profile information

16.2 Authority to Submit Information

You should only submit:

  • Your own personal information
  • Information you are authorised to provide
  • Information you have legitimate reason to share

Do not submit:

  • Information about other people without permission
  • Sensitive information (NRIC, passport numbers) unnecessarily
  • Confidential institutional information
  • Information you are not authorised to share

16.3 Protecting Others' Privacy

When submitting information about other people (committee members, participants, guests), you should:

  • Only include information necessary for CNSP functions
  • Avoid unnecessary disclosure of sensitive details
  • Ensure individuals understand their information will be used
  • Protect the privacy and dignity of individuals
Example: Listing committee members is appropriate; disclosing their personal phone numbers without consent is not.

16.4 Handling Sensitive Information

Some information requires extra care:

  • Identity document numbers (NRIC, passport)
  • Medical or health information
  • Disability or accessibility information
  • Emergency contact information
  • Financial credentials or account numbers
  • Information about minors

Only include this information if absolutely required by the specific CNSP function.

CLAUSE 17

17. DATA BREACHES & SECURITY INCIDENTS

17.1 What Constitutes a Breach

A data breach or security incident might include:

  • Unauthorised access to CNSP
  • Accidental disclosure of personal data
  • Loss or theft of data
  • Ransomware or cyberattack
  • Insider threats or misuse
  • System compromise or hacking

17.2 Our Response

If a security incident occurs:

Investigation: CNSP administrators will investigate the incident to understand:

  • What happened
  • What data was affected
  • Who was responsible
  • How serious the impact is

Containment: We will work to:

  • Stop the attack or unauthorised access
  • Secure the system
  • Prevent further compromise
  • Recover affected data if possible

Remediation: We will:

  • Fix the underlying security issue
  • Restore systems to normal function
  • Document what happened

Notification: We will notify:

  • Affected individuals (where appropriate and where their data was at risk)
  • Relevant authorities (if required by law or institutional policy)
  • System administrators and oversight bodies

17.3 Reporting a Breach

If you discover a security incident or suspected breach:

  • Notify immediately: ns12n24@soton.ac.uk
  • Provide details: What happened, when, what data affected
  • Do not investigate: Leave investigation to administrators

17.4 Malaysian Notification Requirements

[To be confirmed: Are there Malaysian legal requirements for breach notification?]

The Personal Data Protection Act 2010 may require notification to affected individuals in certain breach scenarios. [This requires Malaysian legal review]

Current practice: CNSP will notify affected individuals and relevant authorities where legally required or institutionally appropriate.

CLAUSE 18

18. DATA ACCURACY & CORRECTION PROCEDURES

18.1 Request Process

To request correction of inaccurate personal data:

  1. Identify the inaccuracy: Be specific about what information is incorrect
  2. Contact CNSP: Email ns12n24@soton.ac.uk with:
    • Your name and CNSP user ID
    • Description of the inaccurate information
    • What the correct information should be
    • Reason for requesting correction
    • Supporting evidence if available
  3. Verification: CNSP will verify:
    • That you are authorised to request this correction
    • The correction is appropriate
    • No institutional reasons prevent the correction
  4. Response: You will receive notification of:
    • Whether correction has been made
    • Reasons for refusal (if applicable)
    • Timeline for correction

18.2 Timeframe

[TO BE CONFIRMED: What is the target timeframe for responding to correction requests?]

Reasonable timeframe for response: typically within [X business days]

18.3 Record of Corrections

When corrections are made:

  • The accurate information is updated
  • The date of correction is recorded
  • Audit logs may retain historical records
  • Affected users may be notified (depending on sensitivity)
CLAUSE 19

19. COMPLAINTS & PRIVACY ENQUIRIES

19.1 Contact CNSP Privacy Team

For questions, concerns, or complaints about data handling:

Email: ns12n24@soton.ac.uk

Subject Line Examples:

• "Privacy Question: [Your question]"

• "Data Access Request"

• "Complaint: [Description]"

• "Correction Request: [Description]"

Response Target: We aim to respond within [X business days]

19.2 Information to Include

When contacting us, please provide:

  • Your full name and CNSP user ID
  • Clear description of your concern
  • Relevant dates or events
  • What outcome you're seeking
  • Supporting information if applicable

19.3 Escalation

If you are not satisfied with the response:

  • You may escalate within UoSMSA
  • Contact institutional data protection officers
  • Seek guidance from institutional administration
  • Consider advice from external privacy advocates

19.4 Malaysian Data Protection Commissioner

[To be confirmed: What is the process for complaints to the Malaysian DPA?]

If you believe CNSP is not complying with Malaysian personal data protection law, you may lodge a complaint with:

[Malaysian Data Protection Commissioner details to be added after verification]

CLAUSE 20

20. PRIVACY POLICY CHANGES

20.1 Updates to This Policy

SOTON CNSP may update this Privacy Policy to:

  • Reflect changes in how data is handled
  • Respond to new legal requirements
  • Improve clarity or accuracy
  • Address new features or functionality
  • Respond to security or privacy concerns

20.2 Notification of Changes

When material changes are made:

  • This page will be updated with the new version
  • The "Last Updated" date at the top will change
  • Users will be notified of significant changes [method to be confirmed]
  • Previous versions may be archived for reference

20.3 Your Rights Regarding Changes

Important: Continued use of CNSP after policy changes does not automatically mean you accept the new terms.

If new privacy practices are introduced that you do not accept:

  • You may discontinue use of CNSP
  • You may request deletion of your account
  • You may contact ns12n24@soton.ac.uk with concerns
CLAUSE 21

21. GOVERNING LAW & JURISDICTION

21.1 Applicable Law

This Privacy Policy and SOTON CNSP's data handling practices are governed by:

  • Personal Data Protection Act 2010 (Act 709) — Malaysia's primary personal data protection law
  • Other applicable Malaysian data protection regulations and guidance
  • Institutional policies of the University of Southampton Malaysia Student Association

21.2 Legal Framework

This policy has been prepared with reference to:

  • Malaysian personal data protection principles
  • Current regulatory guidance from Malaysian authorities
  • Best practices in personal data governance
  • Institutional administrative requirements

21.3 Disputes & Resolution

Any disputes regarding this policy or CNSP's handling of personal data should first be addressed through:

  1. Direct communication with ns12n24@soton.ac.uk
  2. Escalation through UoSMSA administrative channels
  3. Institutional grievance procedures if applicable
  4. Malaysian data protection authorities if legal compliance is at issue
CLAUSE 22

22. CONTACT INFORMATION

22.1 Privacy Questions

For questions about this Privacy Policy or CNSP data practices:

Email: ns12n24@soton.ac.uk

Name: Nilavarasen Subramaniam

Title: Head of Operations & Systems (Term 25/26)

Organisation: UoSMSA (University of Southampton Malaysia Student Association)

22.2 Data Access Requests

To request access to your personal data or make corrections:

Email ns12n24@soton.ac.uk with:

  • Subject: "Data Access Request" or "Correction Request"
  • Your full name and CNSP user ID
  • Clear description of what you're requesting

22.3 Support & Technical Issues

For technical support or reporting platform issues:

The contact email above can direct you to appropriate technical support or administrative channels.

22.4 Complaints

To file a complaint about CNSP's data handling:

Email ns12n24@soton.ac.uk with:

  • Subject: "Privacy Complaint"
  • Clear description of the issue
  • Dates and details
  • Your contact information
CLAUSE 23

23. ACKNOWLEDGMENTS & FINAL NOTES

This Privacy Policy is intended to:

  • Explain CNSP's data handling practices clearly
  • Comply with applicable Malaysian data protection law
  • Demonstrate responsible data governance
  • Be understandable to university students
  • Be transparent about limitations and unknowns

Important: This policy does not guarantee absolute security or privacy. It reflects current practices based on information available. Where practices change or new information becomes available, this policy will be updated.

Questions or concerns? Email ns12n24@soton.ac.uk

CLAUSE 24

24. DOCUMENT INFORMATION

Privacy Policy Version: 1.0 (Draft)

Effective Date: [TO BE CONFIRMED]

Last Updated: [TO BE CONFIRMED]

Next Review Date: [TO BE CONFIRMED]

Policy Owner: [TO BE CONFIRMED]

© SOTON CNSP | University of Southampton Malaysia Student Association

APPENDIX PART C

PART C — DATA INVENTORY TABLE

Data Category Examples Purpose Who May Access Retention Sensitive? Status
Account/Authentication Name, email, credentials, role User authentication, account management System, administrators Duration of account + [period] No (passwords encrypted) Confirmed
User Profile Display name, affiliation, contact info User identification, display User, authorised personnel Duration of account + [period] Low Confirmed
Club/Society Info Club name, members, officers Administrative records, organization Club leaders, administrators [PERIOD TBC] Low Confirmed
Event Proposals Event name, date, description, objectives Event approval workflow Event approvers, administrators End of year + [PERIOD TBC] Low Confirmed
Event Reviews Review content, attendance info, photos Post-event documentation Submitters, approvers, administrators [RETENTION TBC] Medium (if includes participant info) Confirmed
Financial Data Expenses, receipts, revenue, claims Financial management, audit Financial approvers, auditors [RETENTION TBC - per institutional requirement] High Confirmed
Room Bookings Venue, date, time, usage Facility management Booking approvers, venue staff [RETENTION TBC] Low Confirmed
Committee Info Names, positions, contact details, responsibilities Organizational governance Club leaders, administrators [RETENTION TBC] Medium Confirmed
Event Photos/Media Images, videos, documentation Event records, administrative use Submitters, administrators [RETENTION TBC] High (if includes minors or identifiable people) Confirmed
Audit Logs Timestamps, user actions, submissions, approvals Accountability, security, audit Administrators, security personnel [RETENTION TBC] Low Confirmed
Risk Documents Risk assessments, safety info, mitigation measures Risk management, event safety Event leaders, approvers, administrators [RETENTION TBC] High Confirmed
Semester Checkpoints Checkpoint submissions, status, approvals Semester reporting, oversight Submitters, approvers, administrators [RETENTION TBC] Low Confirmed

Key: [TBC] = To Be Confirmed before publication

APPENDIX PART D

PART D — LEGAL & COMPLIANCE NOTES

Sources of Policy Requirements

Malaysian Law

  • Personal Data Protection Act 2010 (Act 709) — Governing law for data protection in Malaysia
  • Principles: Principles for personal data protection include notice, choice, security, retention, integrity, access, and disclosure
  • Status: Current policy aligns with general PDPA principles, but requires formal legal review

Best Practices (Not Legal Requirements)

  • GDPR-inspired transparency (not GDPR compliance)
  • Data minimization principles
  • Purpose limitation
  • Storage limitation
  • Access controls and least privilege
  • Security by design
  • Incident response procedures

System-Specific Facts

  • Firebase as primary data storage (confirmed from HTML)
  • Firebase authentication (confirmed)
  • LocalStorage usage (confirmed)
  • Google Fonts CDN (confirmed)
  • Tailwind CSS (confirmed)
  • Role-based access control (confirmed)
  • Audit logging (inferred from interface)

Assumptions Requiring Verification

Before publication, the following must be confirmed:

  1. 1. Legal Entity Responsibility

    • Who is the "data user" under PDPA? UoSMSA? University of Southampton? Individual? What is the institutional arrangement?

  2. 2. Hosting & Data Location

    • Google Firebase location (likely US, but confirm). Whether Firebase is the only data processor. Whether data is backed up and where. Cross-border transfer implications under Malaysian law.

  3. 3. Security Controls

    • Whether encryption is implemented (claims must be verified). Whether backups are encrypted. Incident response procedures (must exist and be documented). Whether multi-factor authentication is used.

  4. 4. Financial Data Handling

    • Whether bank account numbers are actually stored. Whether payment cards are processed through CNSP. Relevant financial/payment security standards (PCI-DSS, etc.).

  5. 5. Event Photo Practices

    • Whether separate consent is needed for promotional use. Whether parents consent for minors' photos. Policy on photo retention and deletion.

  6. 6. Retention Schedules

    • Exact periods for each data category. Whether retention periods align with institutional requirements. Deletion/archival procedures.

  7. 7. Analytics & Tracking

    • Whether Google Analytics or similar is used. Whether any third-party tracking cookies are present. User consent mechanisms for non-essential tracking.

  8. 8. User Rights Procedures

    • How access requests are processed. How corrections are handled. Timelines for responses. Verification procedures.

  9. 9. Malaysian Law Compliance

    • Current requirements for breach notification. Specific PDPA principles that apply. Cross-border transfer safeguards. Rights of individuals under PDPA. Whether any sector-specific requirements apply.

  10. 10. Minors & Children

    • Whether under-18 data is processed. Parental consent requirements. Special safeguards for minors.

APPENDIX PART E

PART E — PRE-PUBLICATION COMPLIANCE CHECKLIST

DO NOT PUBLISH this Privacy Policy until all items are confirmed.

PART E.1 — ORGANIZATIONAL & LEGAL REQUIREMENTS

  • Legal entity identity confirmed — Which organization is the data user/controller?
  • • UoSMSA registered as a student association?
  • • University of Southampton Malaysia (institutional entity)?
  • • Individual administrator?
  • • Separate legal entity?
  • Action Required: Confirm legal responsibility and update policy accordingly
  • Privacy officer or contact designated
  • • Who is the primary privacy contact?
  • • Is there a dedicated data protection officer?
  • • Backup contact if primary unavailable?
  • Current: ns12n24@soton.ac.uk (individual) — Should this be formalized?
  • Official registered address confirmed
  • • UoSMSA physical address? Office location? Mailing address for legal documents?
  • Institutional approval obtained
  • • UoSMSA leadership approval? University administration approval? Data protection sign-off?
  • Policy reviewed by qualified Malaysian legal/privacy counsel
  • • Expert review of Malaysian PDPA compliance? Retention periods under law? User rights verification? Cross-border transfer legality?

PART E.2 — DATA HANDLING & TECHNICAL REQUIREMENTS

  • Data storage confirmed (Google Firebase, server location, backup locations, encryption)
  • Authentication confirmed (Firebase Auth, MFA support, session timeouts, password rules)
  • Analytics & tracking verified (No tracking cookies, essential localstorage only)
  • User access controls verified (RBAC implemented, access logs maintained)
  • Audit logging confirmed (Log retention, access controls, logged events)

PART E.3 — THIRD-PARTY & VENDOR REQUIREMENTS

  • Google Firebase agreement confirmed (DPA in place, SLA documented)
  • Other third-party services identified & documented (Email delivery, document storage, CDN)
  • Processor responsibilities clarified (Data use restrictions documented)

PART E.4 — DATA RETENTION & DELETION REQUIREMENTS

  • Retention periods defined for each category (Account, Proposals, Financial, Bookings, Photos)
  • Deletion procedures documented (Secure deletion, backup purge, audit trails)
  • Institutional requirements verified (Academic records, financial audit requirements)

PART E.5 — SECURITY & INCIDENT RESPONSE

  • Security controls documented (RBAC, encryption, monitoring)
  • Incident response procedure established (Detection, containment, notification timeline)
  • Breach notification obligations verified (Malaysian PDPA timing and requirements)
  • Data loss / disaster recovery plan (Backup schedule, RTO/RPO objectives)

PART E.6 — USER RIGHTS & ACCESS PROCEDURES

  • Access request procedures established (Timeline, ID verification, data format)
  • Correction procedures established (Verification, timeline, update logging)
  • Consent management & PDPA rights verified

PART E.7 THROUGH E.10 — SPECIAL GOVERNANCE

  • Minors & Sensitive Data Handling Confirmed (Under-18 policies, photography rules)
  • Cross-Border Transfer Safeguards Verified (Firebase US location legal basis)
  • Policy Documentation & Publication Prepared (Archiving, change logs, multi-language)
  • Administrator & User Training Established

PART E.11 — FINAL LEGAL REVIEW SIGN-OFF

Reviewer Name: _________________________________

Reviewer Firm / Credentials: _________________________________

Review Date: _________________________________

Approval Status: [ ] Approved    [ ] Approved with modifications    [ ] Not approved

Institutional Approval: _________________________________ Date: _______________

Privacy Officer Sign-Off: _______________________________ Date: _______________

PART E.12 — PUBLICATION READINESS

  • All [TO BE CONFIRMED] items addressed (Verified or explicitly explained)
  • Policy is complete and accurate (No placeholder text remains)
  • Ready for publication (All legal reviews and approvals obtained)
TECHNICAL MEMORANDUM

FINAL IMPLEMENTATION NOTES

Critical Items Before Publication:

  1. Legal Entity Clarification: The policy assumes UoSMSA is responsible, but this must be formally confirmed.
  2. Malaysian Legal Review: Requires review by a qualified Malaysian data protection/privacy attorney. Key areas: PDPA requirements, cross-border transfer legality, user rights, breach notification obligations.
  3. Firebase Compliance: Confirm Google Firebase terms and DPA comply with Malaysian regulations.
  4. Retention Periods: Replace all [RETENTION TBC] items with actual institutional requirements.
  5. Security Controls: Verify every security claim before publishing. Do not claim unverified encryption or MFA.
  6. Contact Information: Verify ns12n24@soton.ac.uk is appropriate or designate a formal office.
  7. Minor's Data: Determine if special procedures are needed for under-18 users.
  8. Institutional Requirements: Verify retention periods comply with institutional record-keeping rules.

This policy is designed to be transparent, specific, and legally defensible for SOTON CNSP.

QUESTIONS REGARDING COMPLIANCE?

ns12n24@soton.ac.uk open_in_new