Personal Data Protection Notice | ARCHER BAHARI

Privacy & data protection

Personal Data Protection Notice

Notis Perlindungan Data Peribadi

How ARCHER BAHARI collects, uses, protects and manages personal data in recruitment, executive search, consultancy and specific client assignments.

Effective date
1st August 2026
Version
AB-PP.01
Privacy enquiry

ARCHER BAHARI SDN BHD

Personal Data Protection Notice

English version

Company / SyarikatARCHER BAHARI Sdn Bhd
Registration number / No. pendaftaran944357-V / 201101016223
Effective date / Tarikh kuat kuasa1st August 2026 / 1st Ogos 2026
Version / VersiAB-PP.01

1. ABOUT THIS NOTICE

ARCHER BAHARI Sdn Bhd 944357-V (201101016223) (“ARCHER BAHARI”, “we”, “us” or “our”) respects the privacy and confidentiality of personal data entrusted to us.

This Personal Data Protection Notice explains how we collect, use, record, store, disclose, transfer, protect, retain and otherwise process personal data in connection with our recruitment, executive search, human resources, consultancy, advisory and related business activities.

This Notice is issued in accordance with the Malaysian Personal Data Protection Act 2010, as amended, and its applicable regulations, standards, guidelines and codes of practice (“PDPA”).

This Notice applies to individuals including:

  1. candidates and prospective candidates;
  2. employees, former employees and prospective employees of our clients;
  3. client representatives, officers and business contacts;
  4. referees, dependants and emergency contacts;
  5. suppliers, service providers and professional advisers;
  6. visitors to our website and users of our online services; and
  7. any other individual whose personal data is processed by us in connection with our business.

2. OUR ROLE IN PROCESSING PERSONAL DATA

2.1 When we act as a data controller

We generally act as a data controller when we determine why and how personal data is processed. This may include processing personal data for:

  1. maintaining our candidate, client and business-contact databases;
  2. assessing and representing candidates;
  3. providing recruitment, executive search and consultancy services;
  4. managing our client, supplier and professional relationships;
  5. operating our website, systems and business processes; and
  6. complying with legal, regulatory, contractual and professional obligations.

2.2 When we act as a data processor for a client

For certain assignments, a client may provide us with access to personal data concerning the client’s employees, former employees, workers, officers, directors, contractors, applicants or other personnel. Access will be limited to assignments where the information is reasonably required to perform the agreed services.

Where the client determines the purposes and essential means of that processing and ARCHER BAHARI processes the personal data only on the client’s documented instructions, the client will generally act as the data controller and ARCHER BAHARI will act as a data processor.

Examples may include assignments involving:

  1. organisational or workforce reviews;
  2. employee or talent assessments;
  3. succession planning;
  4. remuneration, benefits or compensation benchmarking;
  5. competency and skills analysis;
  6. human resources audits or due diligence;
  7. restructuring or workforce planning;
  8. employee engagement or workplace surveys;
  9. leadership, management or performance assessments;
  10. recruitment, redeployment or internal selection exercises; and
  11. other agreed consultancy or advisory assignments.

When acting as a data processor, we will:

  1. process the personal data only for the specific assignment and in accordance with the client’s documented instructions;
  2. access only the personal data reasonably necessary for the assignment;
  3. not use the personal data for our own marketing, candidate database, talent pool or any unrelated purpose;
  4. restrict access to authorised personnel who require the information to perform the assignment;
  5. require authorised personnel to maintain confidentiality;
  6. implement reasonable and practical technical and organisational security measures;
  7. not disclose the personal data to another party except as authorised by the client, required for the assignment or required by law;
  8. notify and cooperate with the client in relation to relevant personal data breaches, complaints and data-subject requests;
  9. engage subprocessors only where permitted by our agreement with the client and subject to appropriate data-protection obligations; and
  10. return, delete, anonymise or securely dispose of the personal data upon completion of the assignment, subject to the client’s instructions and any applicable legal retention requirement.

The client is responsible for ensuring that it has lawful authority to provide or make available the employee or personnel data, that appropriate notices have been issued, that any required consent has been obtained, and that its instructions to ARCHER BAHARI comply with applicable law.

Where ARCHER BAHARI independently determines the purpose for which particular client employee data will be used, we may act as a data controller in respect of that specific processing. Where appropriate, the relevant individuals or the client will be informed of this arrangement.

3. PERSONAL DATA WE MAY PROCESS

The personal data we process will depend on your relationship with us and the relevant service or assignment.

3.1 Identity and contact information

  1. name, address, email address and telephone number;
  2. date of birth, age, gender, nationality, photograph and signature;
  3. National Registration Identity Card number, passport number, driving licence details and other identification information; and
  4. immigration, visa and work-authorisation information.

3.2 Candidate and employment information

  1. curriculum vitae, employment application and professional profile information;
  2. education, professional qualifications, licences and training;
  3. employment history, job titles, responsibilities, skills and experience;
  4. current and expected remuneration, benefits, notice period and work preferences;
  5. interview notes, assessments, reference information and background or credential-verification information;
  6. reasons for leaving previous employment; and
  7. information concerning job offers, placement and onboarding.

3.3 Client employee and workforce information

For specific client assignments where access is required, we may process:

  1. employee or personnel identification numbers;
  2. department, business unit, location, reporting line and organisational-chart information;
  3. position, grade, job family, job description, length of service and employment status;
  4. remuneration, allowances, incentives, benefits and payroll-related information;
  5. skills, competencies, qualifications and training records;
  6. performance, assessment, development, succession, potential and talent-management information;
  7. attendance, leave or workforce-utilisation information;
  8. survey responses and employee feedback;
  9. disciplinary, grievance or investigation information, where strictly necessary; and
  10. other employee information specifically required for the agreed assignment.

3.4 Client and business-contact information

  1. name, job title, employer, business contact details and authority;
  2. correspondence, meeting records and service requirements;
  3. contractual, billing and payment information; and
  4. records concerning our business relationship.

3.5 Website and technical information

  1. Internet Protocol address, browser, device and operating-system information;
  2. website activity, access logs, cookie and analytics information;
  3. form submissions, account or login information; and
  4. communications made through our website or online services.

3.6 Sensitive personal data

Where necessary and permitted by law, we may process sensitive personal data such as physical or mental health information, information concerning an offence or alleged offence, biometric data, religious or similar beliefs, political opinions, or other information classified as sensitive personal data under applicable law.

We will limit the collection and processing of sensitive personal data to what is reasonably necessary for a stated purpose. Where required by law, we will obtain explicit consent before processing such data.

4. SOURCES OF PERSONAL DATA

We may obtain personal data from:

  1. you directly;
  2. our clients, including through access granted for a specific assignment;
  3. your employer or former employer;
  4. referees, emergency contacts and other persons named by you;
  5. educational institutions and professional bodies;
  6. background-screening and verification providers;
  7. recruitment platforms, job boards and publicly available professional profiles;
  8. related companies or business partners, where applicable;
  9. website forms, cookies, logs and analytics tools;
  10. correspondence, interviews, meetings and telephone conversations; and
  11. other parties authorised by you, our client or applicable law.

If you provide personal data relating to another person, such as a referee, dependant or emergency contact, you confirm that you are authorised to provide that information and that the person has been informed about the processing of their personal data.

5. PURPOSES OF PROCESSING

We may process personal data for purposes including:

  1. assessing a candidate’s suitability for employment or an assignment;
  2. matching and introducing candidates to clients and prospective employers;
  3. presenting candidate information, arranging interviews and communicating about applications;
  4. verifying qualifications, employment history, references and other information;
  5. conducting permitted background or credential checks;
  6. negotiating and administering job offers, placements and onboarding;
  7. maintaining a candidate in our talent database for future opportunities, where permitted;
  8. providing executive search, recruitment, human resources, workforce and consultancy services;
  9. carrying out client assignments involving authorised access to employee or personnel data;
  10. undertaking workforce, remuneration, competency, organisational, succession or talent analysis;
  11. preparing reports, recommendations, benchmarking results and other agreed deliverables;
  12. managing client, supplier and professional relationships;
  13. preparing proposals, contracts, invoices and business records;
  14. responding to enquiries, complaints and requests;
  15. operating, securing and improving our website, systems and services;
  16. detecting and preventing fraud, misuse, cyber threats and security incidents;
  17. establishing, exercising or defending legal rights and claims;
  18. complying with contractual, legal, regulatory, tax, audit and reporting obligations; and
  19. any other purpose directly related to the purposes described above.

Where we wish to use personal data for a materially different purpose, we will provide additional notice and obtain consent where required by law.

6. CANDIDATE DISCLOSURES AND TALENT POOL

Where you apply for a specific role, we may process your personal data for that role and disclose relevant information to the client recruiting for that role.

We will not knowingly submit your identifiable curriculum vitae or candidate profile to an unrelated prospective employer without your consent or other appropriate authority.

With your agreement, we may retain your information in our candidate database and contact you about future positions that may be relevant to your qualifications, experience and preferences.

You may ask us at any time to stop considering you for future opportunities or to remove you from our active talent pool, subject to lawful retention requirements.

7. MANDATORY AND VOLUNTARY INFORMATION

Some personal data is required for us to assess or present a job application, verify identity or credentials, perform a client assignment, enter into or administer a contract, meet legal or regulatory obligations, or provide the requested service. Other information is voluntary.

Where required personal data is not provided, we may be unable to assess or progress an application, present a candidate to a client, verify suitability, complete an agreed assignment, enter into or perform a contract, or provide all or part of the requested service.

8. DISCLOSURE OF PERSONAL DATA

We may disclose personal data, where necessary and permitted, to classes of third parties including:

  1. clients and prospective employers;
  2. authorised client personnel involved in a specific assignment;
  3. referees, former employers, educational institutions and professional bodies;
  4. background-screening and credential-verification providers;
  5. applicant-tracking, cloud-hosting, data-storage, communications and IT service providers;
  6. consultants, subcontractors and project partners involved in an agreed assignment;
  7. professional advisers, including lawyers, accountants, auditors and insurers;
  8. banks, payment processors and financial institutions;
  9. regulators, courts, law-enforcement agencies and governmental authorities;
  10. related companies, where applicable;
  11. parties involved in an actual or proposed merger, acquisition, restructuring or transfer of business; and
  12. any other party authorised by you, our client or applicable law.

We will limit disclosures to information reasonably necessary for the relevant purpose. We do not sell personal data to third parties.

9. SERVICE PROVIDERS AND SUBPROCESSORS

We may appoint service providers to process personal data on our behalf, including providers of recruitment and applicant-tracking systems, cloud hosting and data storage, email and communications, IT support and cybersecurity, document management, survey and assessment tools, background screening, analytics and professional advisory services.

We will take reasonable steps to select appropriate service providers and impose contractual confidentiality, security and data-protection obligations appropriate to the services provided.

Where we act as a data processor for a client, our use of subprocessors will also be governed by our agreement with that client.

10. INTERNATIONAL TRANSFERS

Personal data may be stored, accessed or processed outside Malaysia where we or our service providers use systems, infrastructure, support personnel or subprocessors located in other countries.

Where personal data is transferred outside Malaysia, we will take reasonable steps to ensure that the transfer complies with the PDPA. Depending on the circumstances, these steps may include assessing the destination and recipient, implementing contractual safeguards, conducting due diligence, applying appropriate security measures, limiting the transfer, maintaining transfer records and obtaining consent where required by law.

11. SECURITY OF PERSONAL DATA

We maintain reasonable and practical administrative, physical and technical safeguards appropriate to the nature of the personal data and the risks involved.

  1. role-based access controls, password and authentication requirements;
  2. encryption or secure transmission where appropriate;
  3. firewalls, malware protection, system monitoring and secure backup arrangements;
  4. confidentiality obligations and staff awareness or training;
  5. service-provider due diligence and contractual security requirements;
  6. incident-response, business-continuity and recovery procedures;
  7. physical access restrictions; and
  8. secure deletion and disposal procedures.

No electronic system or transmission is completely secure. However, we will take reasonable steps to protect personal data against loss, misuse, modification, unauthorised or accidental access or disclosure, alteration or destruction.

12. RETENTION OF PERSONAL DATA

We retain personal data only for as long as reasonably necessary to fulfil the purpose for which it was collected, perform the relevant service or assignment, maintain appropriate records, comply with legal, regulatory, accounting, audit and contractual requirements, resolve disputes, and establish, exercise or defend legal claims.

Retention periods may differ according to the nature of the information and the relevant relationship or assignment.

When personal data is no longer required, we will take reasonable steps to securely delete, destroy or anonymise it.

Where we process client employee data solely as a data processor, the return, deletion or retention of that information will be managed in accordance with the client’s instructions, our agreement with the client and applicable law.

13. ACCURACY OF PERSONAL DATA

We will take reasonable steps to ensure that personal data is accurate, complete, not misleading and kept up to date, having regard to the purposes for which it is processed. You should inform us of any change to your information.

Where personal data has been supplied by a client and ARCHER BAHARI acts only as a data processor, requests to correct that data may need to be directed to the client. We will provide reasonable assistance to the client where required.

14. YOUR RIGHTS AND CHOICES

Subject to the PDPA and applicable exceptions, you may have the right to:

  1. request access to personal data held about you;
  2. request correction of personal data that is inaccurate, incomplete, misleading or not up to date;
  3. withdraw consent previously provided;
  4. request that certain processing be limited;
  5. object to or require us to stop processing personal data for direct marketing;
  6. request the portability of personal data to another data controller, subject to technical feasibility, compatibility and applicable legal requirements;
  7. ask questions about our processing of personal data; and
  8. submit a complaint concerning our handling of personal data.

A request must be made in writing and may be subject to verification of identity, information reasonably required to locate the relevant records, any applicable prescribed fee, statutory exceptions, and circumstances in which a request may lawfully be refused or limited.

We will respond to a valid access or correction request within 21 days after receiving the request and any information or fee required to process it, subject to any additional period, exception or procedure permitted under the PDPA.

Where ARCHER BAHARI processes personal data solely on behalf of a client, the client will normally be responsible for responding to the request. If we receive such a request directly, we may refer it to the relevant client and assist the client in responding.

Withdrawal of consent will not affect processing already carried out before the withdrawal. It may affect our ability to continue providing a service, progressing an application or considering you for future opportunities.

15. DIRECT MARKETING AND COMMUNICATIONS

We may contact candidates and business contacts regarding relevant vacancies, services, events or business communications where permitted by law.

You may ask us to stop sending direct-marketing communications at any time by using the unsubscribe method included in the communication or contacting us using the details below.

Service-related, contractual, security and legal communications are not treated as marketing communications and may continue where necessary.

16. PERSONAL DATA BREACHES

If we become aware of a personal data breach, we will take reasonable steps to investigate and contain the incident, reduce potential harm, preserve relevant records, take remedial action, notify the relevant client where we process affected data on the client’s behalf, and notify the Personal Data Protection Commissioner and affected individuals where required by the PDPA.

17. COOKIES AND WEBSITE TECHNOLOGIES

Our website may use cookies and similar technologies to enable website functionality, maintain security, remember preferences, understand website usage, improve performance and support analytics or communications.

You may be able to control cookies through your browser settings. Disabling certain cookies may affect the operation of parts of the website. Where required, additional information will be provided through a separate cookie notice or consent mechanism.

18. THIRD-PARTY WEBSITES

Our website or communications may contain links to websites or services operated by third parties. ARCHER BAHARI is not responsible for the privacy practices of those third parties. You should review their privacy notices before providing personal data to them.

19. CHANGES TO THIS NOTICE

We may update this Notice from time to time to reflect changes to applicable law, regulatory guidance, our business activities, our systems and service providers, or the way we process personal data.

The current version will be published on our website with its effective date. Where a change materially affects how personal data is processed, we will take reasonable steps to provide an appropriate additional notice.

20. CONTACTING US

Questions, requests, complaints or withdrawals of consent relating to personal data may be directed to:

CompanyARCHER BAHARI Sdn Bhd
Company registration number944357-V (201101016223)
AddressB2-3-5 Publika Solaris Dutamas, No.1 Jalan Dutamas 1, 50480 Kuala Lumpur, Malaysia.
AttentionAdministration Department / Privacy Contact
General emailinfo@archerbahari.com
Privacy emailenquiry@archerbahari.com
Telephone+603 2935 0044

Data Protection Officer: Richard Archer, Managing Partner

Please include sufficient information for us to identify you and understand your request.

21. LANGUAGE

This Personal Data Protection Notice is also available in Bahasa Malaysia. If there is any inconsistency between the English and Bahasa Malaysia versions, English version will prevail, subject to applicable law.