· Rajesh Menon
PDPA questions that sit inside the signup screen
Onboarding applications collect names, emails, phone numbers, and sometimes identity documents before anyone has recorded a purpose. That is a data-protection fact as well as an admissions fact.
Malaysia’s PDPA 2010 does not disappear because the screen is labelled “Get started”. If the onboarding application stores a person’s data, you should be able to show when notice was given, what purpose was stated, and whether the record can be found again when the person asks.
We do not issue a legal opinion. We test whether the application’s event log can join a tenant to a consent or notice event, and whether abandoned signups are retained on the same terms as completed ones. Abandoned signups are still personal data.
Identity documents collected “in case we need them later” are a common finding. If the playbook does not require them for that product, they should not be in the extract. If the playbook does require them, the retention period should be in the working papers.
The practical ask from a Subang Jaya file is modest: a timestamp, a purpose string, and a way to retrieve the person’s record without exporting the whole tenant table.