This Data Processing Agreement ("DPA") forms part of the Terms of Service between [Company Name] ("Processor", "we") and the Customer clinic ("Controller", "you") and governs the processing of personal data under the Malaysian Personal Data Protection Act 2010 (PDPA).
1. Roles
The Controller is the data user for patient and clinic personal data. The Processor processes such data only on the Controller's documented instructions to provide the Service.
2. Scope of processing
- Subject matter: provision of cloud clinic-management software.
- Duration: the term of the subscription, plus the export/deletion period below.
- Nature & purpose: hosting, storage, processing and display of clinic and patient records.
- Data subjects: patients, clinic staff, and the Controller's contacts.
- Data types: identity, contact, clinical/health, prescription, billing and insurance data.
3. Processor obligations
- Process personal data only on the Controller's instructions and as needed to provide the Service.
- Ensure persons authorised to process data are bound by confidentiality.
- Implement appropriate technical and organisational security measures (Section 5).
- Assist the Controller, so far as possible, with data-subject requests and security obligations.
- Make available information reasonably necessary to demonstrate compliance.
4. Sub-processors
The Controller authorises the Processor to engage sub-processors for hosting, payments, messaging and e-Invoice. Current sub-processors include [cloud host], [payment gateway], [messaging provider], [LHDN/MyInvois]. The Processor imposes data-protection obligations on each and remains responsible for their performance. We will give notice of intended changes and allow reasonable objection.
5. Security measures
- Encryption in transit (HTTPS/TLS) and at rest for direct identifiers (e.g. MyKad, contact details).
- Role-based access control and strict multi-tenant isolation.
- Audit logging of access to records; optional two-factor authentication.
- Rate limiting, security headers, and regular automated backups with monitoring.
- Redaction of personal data before any third-party AI processing.
6. Personal data breach
The Processor will notify the Controller without undue delay (target: within [72] hours) after becoming aware of a personal data breach affecting the Controller's data, with information reasonably available to support the Controller's own notification obligations.
7. Data subject requests
Where a patient contacts the Processor directly, the Processor will refer them to the Controller and assist the Controller in responding to access, correction or withdrawal requests via the Service's export and editing tools.
8. International transfer
Personal data is hosted in [region โ e.g. Singapore (asia-southeast1)]. Any transfer outside Malaysia is subject to safeguards consistent with the PDPA.
9. Return & deletion
On termination, the Controller may export Customer Data for [30] days. Thereafter the Processor will delete or anonymise the data within [90] days, except where retention is required by law (e.g. medical-records or tax retention periods).
10. Audit
The Processor will, on reasonable notice and no more than [once per year] (or after a breach), make available compliance information and allow a reasonable audit, subject to confidentiality.
11. Liability & precedence
Liability under this DPA is subject to the limitations in the Terms of Service. In case of conflict on data protection, this DPA prevails. Governed by the laws of Malaysia.
Signed on acceptance of the Terms of Service, or as a separate signed agreement: Controller: [Clinic Name] ยท Processor: [Company Name].