Introduction
This Privacy Policy explains how the Malaysia Design Council (“MRM”, “we”, “us” or “our”), as organiser of the Kuala Lumpur Design Summit 2026 (“KLDS 2026”), handles personal data submitted through this website, registration forms, strategic collaboration forms and related communications.
This policy is prepared with regard to the Personal Data Protection Act 2010 [Act 709], its amendments and other applicable Malaysian requirements. By providing personal data, you acknowledge the processing described here.
Information We Collect
Depending on your interaction with KLDS 2026, we may collect:
- Identity and contact details, including names, designations, departments, telephone numbers, e-mail addresses and signatures.
- Organisation details, including registered address, registration number, TIN, SST number, MSIC code, website and business activity.
- Participant, academic, project, award and programme information.
- Booth selection, participation category, collaboration level and activation interests.
- Billing, invoice, purchase order and payment information, including uploaded payment evidence.
- Corporate descriptions, logos, profiles, brand guidelines and promotional, product or technology materials.
- Correspondence, declarations, administrative notes and status history.
- Technical information reasonably generated when using the website, such as browser, device, IP address, timestamps and basic diagnostic records.
Sources of Personal Data
We generally obtain personal data directly from you, your authorised representative, your organisation, participants named in a submission, correspondence with the Secretariat, uploaded documents and your use of the website. If you provide another person’s data, you confirm that you are authorised to do so and have informed that person of this policy.
How We Use the Information
We process information where reasonably necessary to administer KLDS 2026, including to:
- Receive, verify and manage registrations and strategic collaboration commitments.
- Allocate booths, passes, programme participation and activation opportunities.
- Review eligibility, supporting documents, invoices, purchase orders and payment evidence.
- Issue references, confirmations, invoices, status updates and administrative notices.
- Communicate about programme, venue, safety, operational or schedule changes.
- Prepare event publications, websites and promotional materials using approved corporate materials.
- Prevent misuse, protect the website and maintain administrative records.
- Meet audit, governance, legal, regulatory and legitimate reporting requirements.
Disclosure and Service Providers
Information may be accessed or disclosed only where reasonably necessary to authorised MRM personnel, event delivery partners, venue or programme teams, auditors, professional advisers, banks, government authorities and technology providers supporting hosting, database, file storage and e-mail delivery.
We do not sell personal data. Providers are expected to process information only for authorised purposes and with appropriate safeguards. Disclosure may also occur where required or permitted by law, to protect safety or rights, or to investigate suspected misuse.
Security and Retention
We use reasonable technical and organisational measures to protect information against loss, misuse, unauthorised access, alteration or disclosure. Access to administrative systems is restricted to authorised users. No internet transmission or electronic storage method, however, can be guaranteed completely secure.
Records are retained only for as long as reasonably necessary for event administration, payment, audit, dispute, reporting and legal purposes. Information that is no longer required will be securely deleted, anonymised or disposed of in accordance with applicable requirements and MRM record-management practices.
Cloud Services and Cross-Border Processing
Some approved technology providers may store or process information outside Malaysia. Where this occurs, we will take reasonable steps to ensure that the transfer and processing are subject to appropriate contractual, technical or legal safeguards consistent with applicable Malaysian requirements.
Your Rights and Choices
Subject to applicable law and any permitted limitations, you may request access to or correction of your personal data, withdraw consent where processing depends on consent, object to direct marketing, or ask about retention, disclosure and processing.
Some information is mandatory to process a registration, allocate a booth, issue an invoice or meet legal and administrative requirements. If it is not provided, we may be unable to process or continue the relevant participation request. Withdrawal does not affect processing already lawfully completed or records that must be retained.
Participants Under 18
A participant under 18 should submit personal data only with the involvement and consent of a parent, legal guardian or authorised educational institution. The submitting representative is responsible for obtaining any required consent before providing the participant’s information.
Updates and Contact
We may update this policy to reflect operational, legal or technology changes. The latest version and effective date will be published on this page.
For privacy questions, access or correction requests, contact KLDS 2026 at klds@mrm.gov.my or +603 8992 6043.
