Privacy Notice

SD Guthrie Whistleblowing Privacy Notice

  • General

    This Whistleblowing Privacy Notice (“Privacy Notice”) aims to inform you about the processing activities and the rights you have regarding your personal data for whistleblowing and investigation procedures carried out by SD Guthrie Berhad and its group of companies (“SD Guthrie”, “we”, “our” or “us”).

    This Privacy Notice should be read together with the Whistleblowing Policy ( https://www.sdguthrie.com/who-we-are/corporate-governance/).

  • Information Collection and Categories of Personal Data

    From the whistleblower, we process the personal data that is provided by the whistleblower such as name, contact number, email address, company name, preferred language and relationship to the company.

    From a person to whom a whistleblower raises a concern or complaint against, different kinds of personal data may be processed. This will depend on the nature of concern of complaint raised and can include name, contact details, email address, video recordings and interviews.

    We do not make use of automated decision-making or profiling.

  • Purposes and Lawful Basis for Processing of the Personal Data

    If you submit a concern or complaint via this portal, we will process the personal data provided by you. We will also process personal data of the person about whom a concern or complaint is raised. The personal data will be processed for different purposes as follows:

    1. to communicate with you regarding the complaint or concern raised;
    2. to confirm the receipt of your report;
    3. to keep you updated on the progress of the complaint or concern raised;
    4. to request from you further information regarding the allegation made in your complaint;
    5. to have a physical conversation or interview session with you (whether as a whistleblower, witness or the person whom the reporter makes a complaint against);
    6. to keep records of all cases reported, related documents such as fact-finding notes;
    7. to comply with our legal obligations to cooperate with authorities, such as but not limited to the Malaysian Anti-Corruption Commission, Dutch data protection authority and the house for whistleblowers under Dutch Whistleblower Protection Act;
    8. where you provide us with your consent, we will process personal data to record the conversation or interview session with you.

    We encourage you to share your identity to ease the investigation process, for us to communicate with you directly, and to request for more information regarding the allegation. However, if you still prefer to report anonymously, you may do so.

  • United Kingdom/European Processing

    This section will only be applicable if you are based in the United Kingdom (UK) or European Economic Areas (other than solely for travel purposes). We process personal data shared with us on the basis of legitimate interest, to act and investigate cases reported to us pursuant to the applicable laws and regulations such as Dutch Whistleblower Protection Act. We will ensure that the standard contractual clauses and data transfer agreements are in place with our joint controller to ensure that we meet the adequate level of security. If you are not a citizen or resident in the EEA or UK, in the case where you provide us with your personal data, you agree and consent to our collection, use and disclosure of your personal data for the purposes set out in this Privacy Notice, where applicable.

  • Sharing of Your Personal Data

    We may transfer the personal data to:

    1. third party advisors such as legal advisors and consultants. Personal data will only be transferred if necessary for the purposes of processing.
    2. our operations within Malaysia or other countries. Personal data will only be transferred if it involves the relevant operations and its personnel for purposes of administering the whistleblowing system, including interview and investigation. The personal data you share will be processed by the relevant personnel of SD Guthrie such as Human Resources, Legal and Corporate Assurance.

    Personal data and information you share may also be disclosed to supervisory, regulatory or enforcement authority based in Malaysia or other countries.

  • Cookies

    We only place necessary cookies to ensure the proper functioning of our portal and your navigation and use of the portal during a session.

    You can decide whether you want to accept or reject those cookies or whether you want your browser to notify you when a cookie is placed. To do this, you must adjust the settings in your browser. However, please note that if you reject the cookies, it will affect the functioning of the portal should you do so.

    For more information on the cookies, please refer to the table below.

    Cookie Type Purpose Retention term
    CurrentApp Necessary To store current App ID for reference of a session for internal processing purposes. Session
    IsPhoneorTablet Necessary To verify whether a visitor is using phone or tablet to access our portal. Session
    KPMG_L7_LoginPassed Necessary To store your password for identity verification. Session
    Maincookie Necessary To store cookies ID to distinguish one visitor from another. Session
    SessionId Necessary To store information such as the user’s input and tracks the movements of the user within the portal. Session
    ZukamiLogin Necessary To store your login ID for identity verification. Session

  • Your Rights

    You have the right to, inter alia, request access, correction or erasure of personal data or object to processing of your personal data for purposes of whistleblowing or investigation.

    For more information on your rights, please refer to the employee privacy notice/statement if you are an employee of SD Guthrie or where you are not an employee of SD Guthrie, please refer to our Privacy Notice at https://www.sdguthrie.com/privacy-notice/.

  • Security of Your Personal Data

    When processing personal data, we maintain, at all times, a level of security which, given the state of the art and the cost of implementation, is, among other things, appropriate to prevent unauthorised access to, modification, disclosure, loss or any other form of unlawful processing of personal data. We are to keep your personal data confidential and take appropriate measures to do so.

    Some of the measures we have put in place are as follows:

    1. Only limited authorised personnel will have access to the full reported cases and whistleblowing portal;
    2. Employee laptops are required to be connected to Virtual Private Network (VPN) when storing or transmitting the Group’s confidential information when using public cloud facilities (such as Dropbox, Google Drive, OneDrive, Gmail) and/or public sharing network connectivity (such as public or hotel Wi-fi);
    3. Authorisation to share personal data or reported cases is subject to limit of authority given; and
    4. Protection against virus and malware.

  • Retention Period

    Our retention periods differ for each processing activity. We do not process data any longer than is necessary for the purposes of processing, unless a legal retention period applies.

    If the report results in any disciplinary or judicial proceedings, the personal data should be retained for a period of ten (10) years after the proceedings are final unless the Whistleblowing Committee decides that it should be longer because of potential legal action or claim.

  • Complaint

    Where you believe that infringement or misuse of your personal data has occurred, you have the right to lodge a complaint with the relevant data protection authority in your country. However, we would encourage you to contact us before making such complaint to the relevant data protection authority so that we are first given the opportunity to understand and resolve your concerns.

  • Contact Details

    If you have any questions, comments or request regarding this Privacy Notice or our processing of your personal data, you can contact us by sending an email to whistleblowing@sdguthrie.com. If you are based in Malaysia, you may also opt to contact the Data Protection Officer at:

    Head, Industrial Relations & Compliance
    Level 10, SD Guthrie Tower
    No.2 Jalan PJU 1A/7, Ara Damansara
    47301 Petaling Jaya, Selangor
    +603-78485063
    DPO@sdguthrie.com

  • Changes or Update to Privacy Notice

    We may update, revise, vary, amend and/or modify this Notice from time to time. Please check back frequently to see the latest changes or update to this Privacy Notice.