Privacy Policy

Finnlight International School respects and is committed to the protection of your personal information and your privacy. This Personal Data Protection Policy provides a framework detailing how we collect and handle your personal information in accordance with the Malaysian Personal Data Protection Act 2010 (PDPA).

For the purpose of this notice, "You" or any derivation thereof, shall mean the owner of the personal data, including both the student and the parent/legal guardian of the student. The terms used herein shall have the meanings ascribed to them in the PDPA.

1. Personal Data

1.1 Type of Personal Data

Personal data includes any information which relates to you and which was collected or provided to Finnlight International Secondary School for the purposes stated in Section 2 of this policy.

Your personal data includes but is not limited to:

  • Name

  • Identification number (NRIC)

  • Passport number

  • Contact details

  • Photos and images

  • Nationality

  • Gender

  • Date of birth

  • Previous qualifications

  • Parents’/guardian’s marital status

  • Emergency contact person(s) details

  • Billing-related information

  • Employment/occupation

  • Previous examination results

  • Academic records

  • Information in audio and/or video format (including voice, video recording, closed-circuit television (CCTV), and security recording)

Sensitive personal data, as defined by the PDPA, includes but is not limited to:

  • Race

  • Religion

  • Health

  • Records of misconduct and disciplinary action

  • Records of criminal offence

  • Family court orders

This sensitive information shall be treated carefully by Finnlight International School and used only for specific purposes in accordance with the conditions stated in Section 40 of the PDPA. Agreement to the terms of this Personal Data Protection Policy shall be deemed to be ‘explicit consent’ for Finnlight International Secondary School to use your sensitive personal data for the purposes stated in Section 2 of this policy and to disclose your sensitive personal data to the classes of third parties stated in Section 3.2 with the objective of fulfilling the purposes stated in Section 2.

1.2 Source of Personal Data

(i) Student or potential student: Collected directly from you or indirectly from your parents, guardians, and/or recruitment agents via various means, including online and physical forms, public venues, seminars, and campus visits. Also collected from cookies through our website.


(ii) Parent/guardian of our student or potential student: Collected directly from you or indirectly from your child/ward and/or recruitment agents via various means, including online and physical forms, public venues, seminars, and campus visits. Also collected from cookies through our website.


(iii) Client/customer or potential client/customer for products, services, events, conferences, seminars, and other marketing activities: Collected directly from you when expressing interest, and indirectly from sources such as trade/online directories and cookies through our website.


(iv) Vendors, suppliers, or service providers: Collected directly from you or indirectly from your employer or credit reference agencies when tendering for projects or as part of commercial transactions. Also collected from cookies through our website.

1.3 Provision of Information

All information requested in the relevant forms is obligatory unless stated otherwise. Failure to provide the obligatory information may prevent us from processing your request and/or providing relevant services.

2. Purposes Of Collecting And Further Processing (Including Disclosing) Your Personal Data

Your data is collected and processed by Finnlight International Secondary School for various academic, educational, administrative, and commercial purposes, including but not limited to:

  • Processing applications for admission

  • Managing and responding to enquiries

  • Maintaining personal details, academic, and non-academic records

  • Providing relevant administrative support, counselling, and guidance services

  • Facilitating internships, placements, and co-curricular activities

  • Administering tuition fees and other payments

  • Managing use of facilities such as libraries, laboratories, and residences

  • Conducting internal marketing analysis

  • Complying with legal and regulatory obligations

  • Contacting emergency contacts in case of emergencies

  • Contacting you regarding products, services, upcoming events, promotions, advertising, marketing, and commercial materials (with your consent)

  • Ensuring website content is presented effectively

  • Internal records management

3. Data Retention and Security

Personal data will be retained as long as necessary to fulfill the purposes for which it was collected, or as required by law. Finnlight International School implements appropriate technical and organizational measures to protect personal data against loss, misuse, and unauthorized access.

4. Your Rights

Under the PDPA, you have the right to:

  • Access and correct your personal data

  • Withdraw consent to the processing of your personal data

  • Object to the processing of your personal data

  • Complain about a breach of the PDPA

5. Contact Information

For inquiries, requests, or complaints regarding your personal data, please contact:

Data Protection Officer


Finnlight International School
Telephone: (601)8966 7626

Email: [email protected]

6. Policy Updates

This policy may be updated from time to time. We will notify you of any significant changes through appropriate channels.