SOTON CNSP PRIVACY POLICY
1. INTRODUCTION
This Privacy Policy explains how the SOTON CNSP platform ("the Platform," "the System," or "CNSP") collects, uses, stores, and protects personal data submitted by users.
SOTON CNSP is a digital platform designed to support the administration and management of clubs, societies, and events associated with the University of Southampton Malaysia Student Association (UoSMSA).
This policy applies to all users of SOTON CNSP, including:
- Student leaders and committee members
- Club and society members
- Event organisers
- Event participants
- Administrative personnel
This policy is not intended to apply to other University of Southampton systems, services, or platforms. If you use other university systems, those systems have separate privacy policies.
2. WHO WE ARE
2.1 About SOTON CNSP
SOTON CNSP is the administrative platform for the University of Southampton Malaysia Student Association.
Important Clarification: The system was developed by Nilavarasen Subramaniam (Head of Operations & Systems, Term 25/26). Ownership of the system does not imply personal ownership of user data.
2.2 Data Controller / Responsible Entity
Currently, data appears to be processed under the responsibility of: UoSMSA (University of Southampton Malaysia Student Association), acting in its administrative capacity.
This point requires verification: Which legal entity is ultimately responsible for personal data processed through CNSP? Is it:
- The University of Southampton?
- UoSMSA as a registered student association?
- An individual or officer?
- A separate legal entity?
This must be clarified and confirmed before the policy is published.
2.3 Privacy Contact
Questions about data or privacy concerns?
Email: ns12n24@soton.ac.uk
Name: [TO BE CONFIRMED - Nilavarasen Subramaniam / Privacy Contact / Data Protection Officer]
[A dedicated privacy contact point should be established if this is a larger deployment]
3. SCOPE OF THIS PRIVACY POLICY
This policy covers personal data processed through SOTON CNSP, including:
- Data you voluntarily submit through forms
- Data generated when you use the Platform (e.g., login timestamps, submissions)
- Data you upload as supporting documentation
- Information about other people you provide through the Platform
This policy does NOT cover:
- Other University of Southampton systems or services
- Email communications sent outside CNSP
- University directories or public records
- Data managed by external service providers independently of CNSP
- Third-party social media or external platforms
4. PERSONAL DATA WE COLLECT
4.1 Information You Provide Directly
4.1.1 Account & Authentication
- Full name
- University email address
- User account credentials / authentication identifiers
- Role (Student, Club Leader, Committee Member, Administrator, etc.)
- Club or society affiliation
- Contact information (if different from university email)
4.1.2 Club & Society Information
- Club/society name and code
- Committee member names and positions
- Officer contact information
- Committee responsibilities
- Membership records (if tracked)
- Organisational objectives and descriptions
4.1.3 Event Information
When you propose or review an event, you may provide:
- Event name and description
- Event date, time, and duration
- Venue or location
- Event objectives and purpose
- Expected attendance/participant numbers
- External participant information (if applicable)
- VIP or guest information (if applicable)
- Event budget or financial information
- Risk assessment or safety documentation
- Supporting documents or attachments
4.1.4 Financial Information
When using cash declaration or financial forms:
- Expense descriptions
- Amounts and currency
- Revenue/income information
- Financial approvals or status
- Supporting receipts or invoices
- Funding source information
- Bank account details [IF AND ONLY IF the system actually requires these - to be confirmed]
4.1.5 Administrative & Compliance Information
- Semester checkpoint submissions
- Room booking requests
- Attendance records (if applicable)
- Approval workflows and status
- Administrative communications
- Supporting evidence or documentation
4.1.6 Event Photography & Media
- Event photographs or videos
- Images of participants
- Event documentation media
- Links to external media repositories
- Photo permissions or consent records
4.1.7 Other Information You Submit
Any other personal information you voluntarily provide through forms, uploads, or submissions.
4.2 Information We Collect Automatically
4.2.1 Usage Information
When you access SOTON CNSP, we may automatically collect:
- Login timestamps: When you log in and out of the system
- Submission timestamps: When you submit forms or documents
- Audit information: Records of administrative actions and approvals
- Browser information: The type of browser and device you use [if automatically logged]
- IP address: Your internet connection identifier [if logged by the system]
- Session information: Duration of your use of CNSP
Clarification: Not all of the above are necessarily collected. Only information actually logged by CNSP is stored.
4.2.2 Local Browser Storage
SOTON CNSP uses browser localStorage to store limited information on your device:
- Your username (for display purposes)
- Session/authentication tokens
- User preferences or settings
What this means: This information is stored locally on your computer or device, not automatically transmitted to CNSP servers. Clearing your browser data will remove this information.
4.2.3 Cookies
[TO BE CONFIRMED: Does CNSP use cookies?]If cookies are used, they are likely for:
- User authentication and session management
- Remembering user preferences
- Essential functionality
To be verified: Are non-essential cookies used for analytics, tracking, or advertising? The existing policy suggests not, but this should be confirmed.
5. HOW WE COLLECT PERSONAL DATA
5.1 Direct Submission
You directly provide most personal data when you:
- Create a user account
- Complete event proposal forms
- Submit event reviews
- Request room bookings
- Submit financial declarations
- Upload supporting documents
- Update committee information
- Submit checkpoint or semester reports
5.2 Automatic Collection
Some information is automatically collected:
- Login and submission timestamps
- System audit information
- Browser and device identifiers (if logged)
- Session information
5.3 Information About Other People
When you submit information about other people (e.g., committee members, event participants, guests), you are responsible for:
- Having appropriate authority to share their information
- Ensuring they understand their information will be processed
- Not sharing sensitive personal information unnecessarily
- Providing accurate and current information
6. HOW WE USE PERSONAL DATA
6.1 Essential Platform Functions
User Authentication & Account Management
- Creating and maintaining your CNSP account
- Authenticating you as an authorised user
- Managing your access level and permissions
- Identifying you and your organisation
Event Administration & Workflow
- Processing your event proposals
- Managing approval workflows
- Reviewing and evaluating events
- Maintaining event records
- Communicating about event status
Room Booking & Resources
- Processing room booking requests
- Managing venue allocation
- Scheduling and coordination
- Recording booking history
Financial Management
- Processing financial declarations
- Recording expense submissions
- Managing financial approvals
- Supporting audits and compliance
Administrative Coordination
- Processing semester checkpoints
- Managing committee information
- Coordinating club/society activities
- Maintaining organisational records
6.2 Legitimate Administrative Purposes
Accountability & Transparency
- Maintaining audit trails
- Recording who submitted what and when
- Tracking approvals and decisions
- Supporting accountability requirements
Risk Management & Safety
- Identifying risk-related information
- Managing event safety assessments
- Recording risk mitigation measures
- Supporting incident investigation if needed
Support & Troubleshooting
- Responding to user questions or issues
- Troubleshooting technical problems
- Providing assistance with CNSP features
- Improving platform functionality
System Security & Maintenance
- Detecting and preventing unauthorised access
- Maintaining system security
- Preventing misuse or fraud
- Updating and maintaining CNSP
6.3 Institutional & Legal Requirements
Depending on how CNSP is configured, data may be processed to:
- Comply with institutional governance requirements
- Support institutional audit functions
- Meet institutional compliance obligations
- Respond to legal requests from authorities
- Protecting legitimate organisational interests
6.4 Uses We Do NOT Undertake
SOTON CNSP does NOT use your personal data for:
- Commercial marketing or advertising
- Selling or renting personal data to third parties
- Profiling or automated decision-making [Unless this occurs - to be confirmed]
- Creating psychological or financial profiles
- Harassment or spam
- Any purpose you have not explicitly authorised
7. DISCLOSURE OF PERSONAL DATA
7.1 Who May Access Your Information
Personal data submitted through SOTON CNSP may be visible to:
7.1.1 Authorised Personnel
- UoSMSA officers and administrators
- Club/society committee members (for information about their club)
- Approval authorities (for event proposals, financial declarations, etc.)
- System administrators (for technical maintenance)
Access is limited to what is necessary. A financial approver should not see information unrelated to financial approvals.
7.1.2 Supporting Service Providers
- Google Firebase (data storage and authentication provider)
- IT/technical support personnel
- Cloud infrastructure providers
- Authentication service providers
These providers process data on behalf of CNSP, not for their own purposes.
7.1.3 Legal & Safety Situations
Your information may be disclosed if:
- Required by law or court order
- Requested by regulatory or governmental authorities
- Necessary to prevent fraud, illegal activity, or harm
- Necessary to protect the safety of individuals
- Required by legitimate institutional governance
We will provide notice of such disclosures where legally possible.
7.2 Who We Do NOT Disclose To
SOTON CNSP does not share personal data with:
- External commercial companies (beyond essential service providers)
- Marketing or advertising partners
- Social media platforms
- Third-party data brokers
- Entities unrelated to UoSMSA administration
- Your data is not sold or rented
8. THIRD-PARTY SERVICE PROVIDERS
8.1 Google Firebase
Service: Cloud-based data storage, authentication, and backend infrastructure
What they process: Personal data stored in CNSP, authentication information, session data
Purpose: Hosting and running SOTON CNSP
Location: [FIREBASE LOCATION TO BE CONFIRMED - likely United States]
Data Processing Agreement: [TO BE CONFIRMED - Should exist]
What this means: Your personal data is stored on Google's servers. Google is bound by contractual obligations to use this data only to provide CNSP services and not for other purposes.
8.2 Google Fonts & Material Symbols
Service: Typography and icon delivery
What they may collect: Your IP address, page you accessed, browser type (standard web server information)
Purpose: Delivering fonts and icons to your browser
Your control: If you want to limit this, you can disable web fonts in your browser settings
8.3 Tailwind CSS & External CDN Services
Service: Providing styling and design framework
What they may collect: Limited technical information if delivered via CDN
Purpose: Delivering web design resources
8.4 Other Service Providers [TO BE CONFIRMED]
The following should be verified and added if applicable:
- [ ] Email delivery service (if CNSP sends emails)
- [ ] Analytics services (if traffic/usage is monitored)
- [ ] Document storage service (if used beyond Firebase)
- [ ] Payment processing (if financial features are integrated)
- [ ] Backup/disaster recovery providers
- [ ] Security monitoring services
9. INTERNATIONAL & CROSS-BORDER DATA TRANSFERS
9.1 Data Location
Important: While SOTON CNSP operates in Malaysia, personal data may be transferred to and processed in other countries, primarily through Google Firebase.
9.2 Google Firebase Location
Google Firebase is a US-based service. This means your personal data:
- Is stored on servers in the United States (likely)
- Is subject to US data security laws
- May be subject to US government requests for information
- Is processed by a US company
Malaysian Legal Context: The Personal Data Protection Act 2010 permits transfers of personal data outside Malaysia where:
- Appropriate safeguards are in place
- The recipient country provides adequate protection
- Contractual safeguards are established
- Specific legal exceptions apply
Status: The relationship between Malaysia's PDPA and US data protection is complex and evolving. [This should be reviewed with Malaysian legal counsel]
9.3 Your Rights Regarding Transfers
Under Malaysian law, you may have the right to:
- Know where your data is transferred
- Request information about safeguards
- Understand the implications of cross-border transfer
This should be explained and verified by Malaysian legal counsel before publication.
10. DATA SECURITY
10.1 Security Measures Implemented
SOTON CNSP implements the following safeguards:
Authentication & Access Control
- Firebase Authentication (industry-standard authentication service)
- Role-Based Access Control (RBAC) — different users have different permission levels
- Secure credentials handling
Data Protection
- Encrypted transmission (HTTPS/TLS encryption while data travels between your browser and servers)
- Data stored securely on Firebase infrastructure
- Access restricted to authorised personnel
System Monitoring
- Audit logs of important actions
- Monitoring for unauthorised access attempts
- System logging of submissions and approvals
10.2 Important Limitations
Security is not absolute.
While SOTON CNSP uses industry-standard security measures, no digital system can guarantee 100% security. Potential risks include:
- Unauthorised access by hackers or malicious actors
- Compromise of cloud infrastructure
- Human error or insider threats
- Undetected vulnerabilities in software
- Physical theft or loss of devices
10.3 Your Responsibility for Security
You are responsible for:
- Keeping your password confidential
- Not sharing your CNSP login credentials
- Logging out after using shared computers
- Protecting your device from malware
- Reporting suspected security breaches
- Clearing browser storage if using a shared device
11. DATA RETENTION
11.1 Retention Principles
Personal data should not be retained indefinitely. SOTON CNSP retains information only as long as necessary for:
- The purpose for which it was collected
- Legal or institutional requirements
- Audit or compliance purposes
- Resolution of disputes or claims
- Legitimate record-keeping
11.2 Retention by Category
[The following retention periods are TO BE CONFIRMED based on actual system design]| Data Category | Retention Period | Rationale |
|---|---|---|
| User Account Information | Duration of CNSP use + [period] after account closure | Account identification and audit |
| Event Proposals & Reviews | End of academic year + [period] | Institutional records and audit |
| Financial Declarations | [Period per institutional requirement] | Compliance, audit, financial records |
| Room Booking Records | [Period per venue policy] | Facility management and scheduling |
| Committee Information | [Period per institutional requirement] | Organisational continuity |
| Audit Logs & Timestamps | [Period per security/audit policy] | Security and accountability |
| Supporting Documents | [Varies by document type] | As required for associated processes |
| Event Photographs | [To be confirmed] | Depends on purpose (admin vs. promotional) |
Status: Exact retention periods must be determined and documented before publication.
11.3 Deletion Upon Request
Upon request and subject to institutional approval, personal data may be deleted if:
- No longer needed for the original purpose
- No legal or institutional reason to retain it
- Not part of an ongoing audit or investigation
- The individual requesting deletion is authorised
12. PERSONAL DATA RIGHTS & ACCESS
12.1 Access to Your Personal Data
Under Malaysian personal data protection law, you have the right to:
Request access to your personal data
- You can request what personal data CNSP holds about you
- We will provide this information in a clear format
- There may be reasonable processing time
- We may require verification of your identity
How to request: Email ns12n24@soton.ac.uk with your request
Exceptions: We may be unable to provide information if:
- Disclosure would harm the privacy of others
- Legal or institutional restrictions apply
- The information is part of an active investigation
12.2 Correction of Inaccurate Data
You have the right to request correction if personal data held about you is:
- Inaccurate or incomplete
- Outdated or no longer relevant
- Misleading or incorrect
How to request: Contact ns12n24@soton.ac.uk with details of the inaccurate information
We will:
- Review your correction request
- Make corrections where appropriate
- Notify you of the outcome
- Update audit records to reflect corrections
12.3 Withdrawal of Consent
Where CNSP processing is based on your consent, you may withdraw that consent by:
- Notifying ns12n24@soton.ac.uk in writing
- Requesting deletion of your account
Important: Withdrawal of consent does not apply retroactively. Information already processed may continue to be retained where legally required.
12.4 Other Possible Rights
Depending on final Malaysian legal analysis, you may have rights regarding:
- Requesting information about how your data is used
- Requesting restrictions on how your data is processed
- Objecting to certain types of processing
- Understanding automated decision-making (if used)
Status: These rights require confirmation of current Malaysian law applicability. [Malaysian legal review required]
13. CHILDREN & MINORS
13.1 University Student Users
SOTON CNSP is designed for university students and student leaders, typically aged 18+.
However, some users may be under 18:
- International foundation students
- Early-entry students
- Students with special circumstances
13.2 Event Participants Under 18
Events organised through CNSP may involve participants under 18, including:
- School visitors or guests
- Younger siblings at family events
- Minors attending public university events
13.3 Data Protection for Minors
If personal data of minors is submitted through CNSP:
- Such information should be submitted only where necessary
- Additional safeguards apply to sensitive information
- Parents/guardians should be informed where appropriate
- Consent requirements may differ for minors
13.4 Parental or Guardian Consent
[To be confirmed: Does CNSP require parental consent for minors' data? If so, what is the process?]If your event involves minors, you may need to:
- Collect parental consent for data processing
- Provide parents with privacy information
- Maintain consent documentation
14. EVENT PHOTOGRAPHS, VIDEOS & MEDIA
14.1 Event Documentation Photography
Event photos may be submitted as part of:
- Event review submissions
- Event documentation
- Proof of event completion
- Record-keeping purposes
14.2 Use of Event Photos
Important distinction:
- Administrative use: Photos submitted for event review/record-keeping are for internal CNSP use
- Promotional use: Using photos for marketing, social media, or public publication is separate
If you submit a photo for event review documentation, you are NOT automatically giving permission for public promotion.
14.3 Photos Involving Other People
If your event photos include other people:
- You should have obtained their permission to include them in CNSP submissions
- Do not submit photos of people without their knowledge or consent
- Be particularly careful with photos of minors
- Consider the privacy of individuals in the background
14.4 Promotional Use of Photos
[To be confirmed: Does CNSP have a separate process for promotional photos?]If CNSP (or UoSMSA) wants to use event photos for marketing, promotion, or public publicity:
- Separate, explicit consent should be obtained
- Individuals should know their image will be used publicly
- This is separate from administrative documentation
Do not assume: Event documentation photos can be automatically used for promotional purposes.
14.5 Minors in Photographs
Special care applies to photographs containing minors:
- Parental consent may be required
- Consider the minor's privacy and dignity
- Be cautious about identifying minors by name and photo together
- Follow institutional guidance on minor photography
15. COOKIES, LOCAL STORAGE & BROWSER TECHNOLOGIES
15.1 What These Technologies Do
Cookies: Small files stored on your computer by websites you visit
Local Storage: Information stored in your browser that websites can access
Session Storage: Temporary information cleared when you close your browser
15.2 How SOTON CNSP Uses These
Local Storage:
CNSP uses browser localStorage to store:
- Your username (for displaying your name)
- Authentication/session tokens
- User preferences or settings
This information is stored on your device, not automatically transmitted to CNSP servers.
Cookies: [To be confirmed: Does CNSP use cookies? If so, for what purposes?]
15.3 Essential vs. Non-Essential
Essential: Cookies or storage necessary for CNSP to function (authentication, session management)
Non-Essential: Cookies used for analytics, tracking, advertising, or user profiling
Current status: SOTON CNSP does not appear to use non-essential tracking cookies. [This should be confirmed]
15.4 Your Control
You can:
- Delete stored data by clearing your browser cache/storage
- Disable cookies in your browser settings
- Use private/incognito browsing mode to prevent local storage
Note: Disabling these may prevent CNSP from functioning properly.
15.5 Third-Party Tracking
Google Fonts and Material Symbols may collect limited information when loading:
- Your IP address
- The page you accessed
- Your browser type
- Approximate loading time
This is standard web server information and does not personally identify you.
16. USER RESPONSIBILITIES
16.1 Accuracy of Information
When you submit information through CNSP, you are responsible for:
- Providing accurate and current information
- Updating information if it changes
- Notifying CNSP if information becomes outdated
- Correcting errors you identify
Examples:
- Committee member contact information
- Event details and schedules
- Financial information and receipts
- Personal profile information
16.2 Authority to Submit Information
You should only submit:
- Your own personal information
- Information you are authorised to provide
- Information you have legitimate reason to share
Do not submit:
- Information about other people without permission
- Sensitive information (NRIC, passport numbers) unnecessarily
- Confidential institutional information
- Information you are not authorised to share
16.3 Protecting Others' Privacy
When submitting information about other people (committee members, participants, guests), you should:
- Only include information necessary for CNSP functions
- Avoid unnecessary disclosure of sensitive details
- Ensure individuals understand their information will be used
- Protect the privacy and dignity of individuals
16.4 Handling Sensitive Information
Some information requires extra care:
- Identity document numbers (NRIC, passport)
- Medical or health information
- Disability or accessibility information
- Emergency contact information
- Financial credentials or account numbers
- Information about minors
Only include this information if absolutely required by the specific CNSP function.
17. DATA BREACHES & SECURITY INCIDENTS
17.1 What Constitutes a Breach
A data breach or security incident might include:
- Unauthorised access to CNSP
- Accidental disclosure of personal data
- Loss or theft of data
- Ransomware or cyberattack
- Insider threats or misuse
- System compromise or hacking
17.2 Our Response
If a security incident occurs:
Investigation: CNSP administrators will investigate the incident to understand:
- What happened
- What data was affected
- Who was responsible
- How serious the impact is
Containment: We will work to:
- Stop the attack or unauthorised access
- Secure the system
- Prevent further compromise
- Recover affected data if possible
Remediation: We will:
- Fix the underlying security issue
- Restore systems to normal function
- Document what happened
Notification: We will notify:
- Affected individuals (where appropriate and where their data was at risk)
- Relevant authorities (if required by law or institutional policy)
- System administrators and oversight bodies
17.3 Reporting a Breach
If you discover a security incident or suspected breach:
- Notify immediately: ns12n24@soton.ac.uk
- Provide details: What happened, when, what data affected
- Do not investigate: Leave investigation to administrators
17.4 Malaysian Notification Requirements
[To be confirmed: Are there Malaysian legal requirements for breach notification?]The Personal Data Protection Act 2010 may require notification to affected individuals in certain breach scenarios. [This requires Malaysian legal review]
Current practice: CNSP will notify affected individuals and relevant authorities where legally required or institutionally appropriate.
18. DATA ACCURACY & CORRECTION PROCEDURES
18.1 Request Process
To request correction of inaccurate personal data:
- Identify the inaccuracy: Be specific about what information is incorrect
- Contact CNSP: Email ns12n24@soton.ac.uk with:
- Your name and CNSP user ID
- Description of the inaccurate information
- What the correct information should be
- Reason for requesting correction
- Supporting evidence if available
- Verification: CNSP will verify:
- That you are authorised to request this correction
- The correction is appropriate
- No institutional reasons prevent the correction
- Response: You will receive notification of:
- Whether correction has been made
- Reasons for refusal (if applicable)
- Timeline for correction
18.2 Timeframe
[TO BE CONFIRMED: What is the target timeframe for responding to correction requests?]Reasonable timeframe for response: typically within [X business days]
18.3 Record of Corrections
When corrections are made:
- The accurate information is updated
- The date of correction is recorded
- Audit logs may retain historical records
- Affected users may be notified (depending on sensitivity)
19. COMPLAINTS & PRIVACY ENQUIRIES
19.1 Contact CNSP Privacy Team
For questions, concerns, or complaints about data handling:
Email: ns12n24@soton.ac.uk
Subject Line Examples:
• "Privacy Question: [Your question]"
• "Data Access Request"
• "Complaint: [Description]"
• "Correction Request: [Description]"
Response Target: We aim to respond within [X business days]
19.2 Information to Include
When contacting us, please provide:
- Your full name and CNSP user ID
- Clear description of your concern
- Relevant dates or events
- What outcome you're seeking
- Supporting information if applicable
19.3 Escalation
If you are not satisfied with the response:
- You may escalate within UoSMSA
- Contact institutional data protection officers
- Seek guidance from institutional administration
- Consider advice from external privacy advocates
19.4 Malaysian Data Protection Commissioner
[To be confirmed: What is the process for complaints to the Malaysian DPA?]If you believe CNSP is not complying with Malaysian personal data protection law, you may lodge a complaint with:
[Malaysian Data Protection Commissioner details to be added after verification]
20. PRIVACY POLICY CHANGES
20.1 Updates to This Policy
SOTON CNSP may update this Privacy Policy to:
- Reflect changes in how data is handled
- Respond to new legal requirements
- Improve clarity or accuracy
- Address new features or functionality
- Respond to security or privacy concerns
20.2 Notification of Changes
When material changes are made:
- This page will be updated with the new version
- The "Last Updated" date at the top will change
- Users will be notified of significant changes [method to be confirmed]
- Previous versions may be archived for reference
20.3 Your Rights Regarding Changes
Important: Continued use of CNSP after policy changes does not automatically mean you accept the new terms.
If new privacy practices are introduced that you do not accept:
- You may discontinue use of CNSP
- You may request deletion of your account
- You may contact ns12n24@soton.ac.uk with concerns
21. GOVERNING LAW & JURISDICTION
21.1 Applicable Law
This Privacy Policy and SOTON CNSP's data handling practices are governed by:
- Personal Data Protection Act 2010 (Act 709) — Malaysia's primary personal data protection law
- Other applicable Malaysian data protection regulations and guidance
- Institutional policies of the University of Southampton Malaysia Student Association
21.2 Legal Framework
This policy has been prepared with reference to:
- Malaysian personal data protection principles
- Current regulatory guidance from Malaysian authorities
- Best practices in personal data governance
- Institutional administrative requirements
21.3 Disputes & Resolution
Any disputes regarding this policy or CNSP's handling of personal data should first be addressed through:
- Direct communication with ns12n24@soton.ac.uk
- Escalation through UoSMSA administrative channels
- Institutional grievance procedures if applicable
- Malaysian data protection authorities if legal compliance is at issue
22. CONTACT INFORMATION
22.1 Privacy Questions
For questions about this Privacy Policy or CNSP data practices:
Email: ns12n24@soton.ac.uk
Name: Nilavarasen Subramaniam
Title: Head of Operations & Systems (Term 25/26)
Organisation: UoSMSA (University of Southampton Malaysia Student Association)
22.2 Data Access Requests
To request access to your personal data or make corrections:
Email ns12n24@soton.ac.uk with:
- Subject: "Data Access Request" or "Correction Request"
- Your full name and CNSP user ID
- Clear description of what you're requesting
22.3 Support & Technical Issues
For technical support or reporting platform issues:
The contact email above can direct you to appropriate technical support or administrative channels.
22.4 Complaints
To file a complaint about CNSP's data handling:
Email ns12n24@soton.ac.uk with:
- Subject: "Privacy Complaint"
- Clear description of the issue
- Dates and details
- Your contact information
23. ACKNOWLEDGMENTS & FINAL NOTES
This Privacy Policy is intended to:
- Explain CNSP's data handling practices clearly
- Comply with applicable Malaysian data protection law
- Demonstrate responsible data governance
- Be understandable to university students
- Be transparent about limitations and unknowns
Important: This policy does not guarantee absolute security or privacy. It reflects current practices based on information available. Where practices change or new information becomes available, this policy will be updated.
Questions or concerns? Email ns12n24@soton.ac.uk
24. DOCUMENT INFORMATION
Privacy Policy Version: 1.0 (Draft)
Effective Date: [TO BE CONFIRMED]
Last Updated: [TO BE CONFIRMED]
Next Review Date: [TO BE CONFIRMED]
Policy Owner: [TO BE CONFIRMED]
© SOTON CNSP | University of Southampton Malaysia Student Association
PART C — DATA INVENTORY TABLE
| Data Category | Examples | Purpose | Who May Access | Retention | Sensitive? | Status |
|---|---|---|---|---|---|---|
| Account/Authentication | Name, email, credentials, role | User authentication, account management | System, administrators | Duration of account + [period] | No (passwords encrypted) | Confirmed |
| User Profile | Display name, affiliation, contact info | User identification, display | User, authorised personnel | Duration of account + [period] | Low | Confirmed |
| Club/Society Info | Club name, members, officers | Administrative records, organization | Club leaders, administrators | [PERIOD TBC] | Low | Confirmed |
| Event Proposals | Event name, date, description, objectives | Event approval workflow | Event approvers, administrators | End of year + [PERIOD TBC] | Low | Confirmed |
| Event Reviews | Review content, attendance info, photos | Post-event documentation | Submitters, approvers, administrators | [RETENTION TBC] | Medium (if includes participant info) | Confirmed |
| Financial Data | Expenses, receipts, revenue, claims | Financial management, audit | Financial approvers, auditors | [RETENTION TBC - per institutional requirement] | High | Confirmed |
| Room Bookings | Venue, date, time, usage | Facility management | Booking approvers, venue staff | [RETENTION TBC] | Low | Confirmed |
| Committee Info | Names, positions, contact details, responsibilities | Organizational governance | Club leaders, administrators | [RETENTION TBC] | Medium | Confirmed |
| Event Photos/Media | Images, videos, documentation | Event records, administrative use | Submitters, administrators | [RETENTION TBC] | High (if includes minors or identifiable people) | Confirmed |
| Audit Logs | Timestamps, user actions, submissions, approvals | Accountability, security, audit | Administrators, security personnel | [RETENTION TBC] | Low | Confirmed |
| Risk Documents | Risk assessments, safety info, mitigation measures | Risk management, event safety | Event leaders, approvers, administrators | [RETENTION TBC] | High | Confirmed |
| Semester Checkpoints | Checkpoint submissions, status, approvals | Semester reporting, oversight | Submitters, approvers, administrators | [RETENTION TBC] | Low | Confirmed |
Key: [TBC] = To Be Confirmed before publication
PART D — LEGAL & COMPLIANCE NOTES
Sources of Policy Requirements
Malaysian Law
- Personal Data Protection Act 2010 (Act 709) — Governing law for data protection in Malaysia
- Principles: Principles for personal data protection include notice, choice, security, retention, integrity, access, and disclosure
- Status: Current policy aligns with general PDPA principles, but requires formal legal review
Best Practices (Not Legal Requirements)
- GDPR-inspired transparency (not GDPR compliance)
- Data minimization principles
- Purpose limitation
- Storage limitation
- Access controls and least privilege
- Security by design
- Incident response procedures
System-Specific Facts
- Firebase as primary data storage (confirmed from HTML)
- Firebase authentication (confirmed)
- LocalStorage usage (confirmed)
- Google Fonts CDN (confirmed)
- Tailwind CSS (confirmed)
- Role-based access control (confirmed)
- Audit logging (inferred from interface)
Assumptions Requiring Verification
Before publication, the following must be confirmed:
- 1. Legal Entity Responsibility
• Who is the "data user" under PDPA? UoSMSA? University of Southampton? Individual? What is the institutional arrangement?
- 2. Hosting & Data Location
• Google Firebase location (likely US, but confirm). Whether Firebase is the only data processor. Whether data is backed up and where. Cross-border transfer implications under Malaysian law.
- 3. Security Controls
• Whether encryption is implemented (claims must be verified). Whether backups are encrypted. Incident response procedures (must exist and be documented). Whether multi-factor authentication is used.
- 4. Financial Data Handling
• Whether bank account numbers are actually stored. Whether payment cards are processed through CNSP. Relevant financial/payment security standards (PCI-DSS, etc.).
- 5. Event Photo Practices
• Whether separate consent is needed for promotional use. Whether parents consent for minors' photos. Policy on photo retention and deletion.
- 6. Retention Schedules
• Exact periods for each data category. Whether retention periods align with institutional requirements. Deletion/archival procedures.
- 7. Analytics & Tracking
• Whether Google Analytics or similar is used. Whether any third-party tracking cookies are present. User consent mechanisms for non-essential tracking.
- 8. User Rights Procedures
• How access requests are processed. How corrections are handled. Timelines for responses. Verification procedures.
- 9. Malaysian Law Compliance
• Current requirements for breach notification. Specific PDPA principles that apply. Cross-border transfer safeguards. Rights of individuals under PDPA. Whether any sector-specific requirements apply.
- 10. Minors & Children
• Whether under-18 data is processed. Parental consent requirements. Special safeguards for minors.
PART E — PRE-PUBLICATION COMPLIANCE CHECKLIST
PART E.1 — ORGANIZATIONAL & LEGAL REQUIREMENTS
- Legal entity identity confirmed — Which organization is the data user/controller?
- • UoSMSA registered as a student association?
- • University of Southampton Malaysia (institutional entity)?
- • Individual administrator?
- • Separate legal entity?
- Action Required: Confirm legal responsibility and update policy accordingly
- Privacy officer or contact designated
- • Who is the primary privacy contact?
- • Is there a dedicated data protection officer?
- • Backup contact if primary unavailable?
- Current: ns12n24@soton.ac.uk (individual) — Should this be formalized?
- Official registered address confirmed
- • UoSMSA physical address? Office location? Mailing address for legal documents?
- Institutional approval obtained
- • UoSMSA leadership approval? University administration approval? Data protection sign-off?
- Policy reviewed by qualified Malaysian legal/privacy counsel
- • Expert review of Malaysian PDPA compliance? Retention periods under law? User rights verification? Cross-border transfer legality?
PART E.2 — DATA HANDLING & TECHNICAL REQUIREMENTS
- Data storage confirmed (Google Firebase, server location, backup locations, encryption)
- Authentication confirmed (Firebase Auth, MFA support, session timeouts, password rules)
- Analytics & tracking verified (No tracking cookies, essential localstorage only)
- User access controls verified (RBAC implemented, access logs maintained)
- Audit logging confirmed (Log retention, access controls, logged events)
PART E.3 — THIRD-PARTY & VENDOR REQUIREMENTS
- Google Firebase agreement confirmed (DPA in place, SLA documented)
- Other third-party services identified & documented (Email delivery, document storage, CDN)
- Processor responsibilities clarified (Data use restrictions documented)
PART E.4 — DATA RETENTION & DELETION REQUIREMENTS
- Retention periods defined for each category (Account, Proposals, Financial, Bookings, Photos)
- Deletion procedures documented (Secure deletion, backup purge, audit trails)
- Institutional requirements verified (Academic records, financial audit requirements)
PART E.5 — SECURITY & INCIDENT RESPONSE
- Security controls documented (RBAC, encryption, monitoring)
- Incident response procedure established (Detection, containment, notification timeline)
- Breach notification obligations verified (Malaysian PDPA timing and requirements)
- Data loss / disaster recovery plan (Backup schedule, RTO/RPO objectives)
PART E.6 — USER RIGHTS & ACCESS PROCEDURES
- Access request procedures established (Timeline, ID verification, data format)
- Correction procedures established (Verification, timeline, update logging)
- Consent management & PDPA rights verified
PART E.7 THROUGH E.10 — SPECIAL GOVERNANCE
- Minors & Sensitive Data Handling Confirmed (Under-18 policies, photography rules)
- Cross-Border Transfer Safeguards Verified (Firebase US location legal basis)
- Policy Documentation & Publication Prepared (Archiving, change logs, multi-language)
- Administrator & User Training Established
PART E.11 — FINAL LEGAL REVIEW SIGN-OFF
Reviewer Name: _________________________________
Reviewer Firm / Credentials: _________________________________
Review Date: _________________________________
Approval Status: [ ] Approved [ ] Approved with modifications [ ] Not approved
Institutional Approval: _________________________________ Date: _______________
Privacy Officer Sign-Off: _______________________________ Date: _______________
PART E.12 — PUBLICATION READINESS
- All [TO BE CONFIRMED] items addressed (Verified or explicitly explained)
- Policy is complete and accurate (No placeholder text remains)
- Ready for publication (All legal reviews and approvals obtained)
FINAL IMPLEMENTATION NOTES
Critical Items Before Publication:
- Legal Entity Clarification: The policy assumes UoSMSA is responsible, but this must be formally confirmed.
- Malaysian Legal Review: Requires review by a qualified Malaysian data protection/privacy attorney. Key areas: PDPA requirements, cross-border transfer legality, user rights, breach notification obligations.
- Firebase Compliance: Confirm Google Firebase terms and DPA comply with Malaysian regulations.
- Retention Periods: Replace all [RETENTION TBC] items with actual institutional requirements.
- Security Controls: Verify every security claim before publishing. Do not claim unverified encryption or MFA.
- Contact Information: Verify ns12n24@soton.ac.uk is appropriate or designate a formal office.
- Minor's Data: Determine if special procedures are needed for under-18 users.
- Institutional Requirements: Verify retention periods comply with institutional record-keeping rules.
This policy is designed to be transparent, specific, and legally defensible for SOTON CNSP.
QUESTIONS REGARDING COMPLIANCE?
ns12n24@soton.ac.uk open_in_new