• Home
  • Members
  • Practice Areas
  • Contact us
  • More
    • Home
    • Members
    • Practice Areas
    • Contact us
  • Home
  • Members
  • Practice Areas
  • Contact us

Privacy Policy

SECTION 1: INTRODUCTION 


1.1.     We are committed to protecting the privacy and confidentiality of personal data entrusted to us. This Privacy Policy explains how we collect, use, disclose, store, and protect personal data in accordance with:  


(a)   The Personal Data Protection Act 2010 (“PDPA”); 

(b)   The Legal Profession Act 1976 (“LPA”); and 

(c)   Applicable Bar Council Rules and Rulings (“BCRR”) and professional obligations. 


1.2.     This policy applies to all clients, prospective clients, employees, consultants, vendors, and other individuals whose personal data that we  processes. 


1.3.     By engaging us to provide services, attending our events or using our website, you consent to the processing of your personal data as described in this Privacy Policy. 


1.4.     We reserve the right to modify or update this Privacy Policy at any time by placing the updated version on the Website. Continued use of our services signifies acceptance of such updates. 


SECTION 2: PERSONAL DATA WE COLLECT


2.1.     “Personal Data” means any information that identifies or can identify you, including but not limited to: 


(a)  Identity information (name, NRIC/passport number, nationality); 

(b)  Contact details (address, email, telephone number); 

(c)  Client and matter-related information, including documents and correspondence; 

(d)  Financial and billing information; 

(e)  Employment-related data (for associates, staff, interns, and applicants); and/or 

(f)  Know-Your-Client (“KYC”) and due diligence information, including politically exposed person checks where required. 


2.2.     Personal Data may be collected: 


(a)  Directly from you, e.g. during client engagement or communications; or  

(b)  Indirectly, e.g. from attendance at events, seminars, conferences, or via cookies on our website. 


2.3.     Providing Personal Data is voluntary; however, failure to provide it may limit our ability to communicate with you, provided requested services, or grant access to restricted website sections. 


SECTION 3: PURPOSE OF COLLECTION AND USE 


3.1     Personal data is collected and used strictly for legitimate purposes, including: 


(a)   Providing legal services and professional advice; 

(b)   Client onboarding, KYC, conflict checks, and compliance obligations; 

(c)   Managing client relationships, billing, and payments; 

(d)   Complying with legal, regulatory, and professional obligations; 

(e)   Internal administration, risk management, and record-keeping; and/or 

(f)   Responding to lawful requests from authorities or regulators. 


3.2     Additional purposes include: 


(a)   Sending newsletters, articles, write-ups, or other updates; 

(b)   Sharing information about events, seminars, conferences, and talks; 

(c)   Acting as potential referees for ranking legal publications, journals, or prospective clients requesting references. 


3.3.     If you do not consent to processing for purposes in this Section, please notify us. 


3.4.     We do not process personal data for purposes unrelated to legal or business needs. 


SECTION 4: DISCLOSURE OF PERSONAL DATA 


4.1.     Personal data may be disclosed only where necessary and lawful, including to: 


(a)   Courts, tribunals, and regulatory authorities; 

(b)   Government agencies where required by law; 

(c)   Professional advisers, experts, or service providers engaged in connection with a matter; and/or 

(d)   Third parties involved in KYC, compliance, or IT support (subject to confidentiality obligations). 


4.2.     We do not sell or trade personal data. 


4.3.     Personal Data may be transferred, stored, or processed outside Malaysia, including for the purposes described in Section 3.2(c), or where service providers or clients are overseas. We ensure that such transfers are subject to safeguards providing a standard of protection comparable to the PDPA. 


4.4.     We may engage third-party service providers to perform functions on its behalf, including: 


(a)   IT and data management providers; 

(b)   Data entry or storage facility providers; 

(c)   Bank, financial institutions, and insurers; 

(d)   Professional advisors and auditors; 

(e)   Regulatory and governmental authorities, including the Accountant General’s Department of Malaysia for unclaimed monies reporting. 


SECTION 5: CONFIDENTIALITY AND LEGAL PROFESSIONAL PRIVILEGE


5.1.     All client information is treated as strictly confidential. 


5.2.     Information subject to legal professional privilege is protected and disclosed only where permitted by law or with client consent. 


5.3.     We observe our professional duty to maintain client confidentiality under the LPA and Bar Council rules. 


SECTION 6: SECURITY AND RETENTION 


6.1.     We implement appropriate technical, administrative, and organisational safeguards to protect Personal Data. 


6.2.     Personal Data is retained only as long as necessary for the purposes described in Sections 3 and 4, and thereafter for statutory limitation periods, internal policies, or regulatory obligations. 


6.3.    Once Personal Data is no longer required, it is securely deleted or anonymised. 


SECTION 7: ACCESS AND CORRECTION 


7.1.     Subject to legal exceptions, you may request: 


(a)   Access to your Personal Data; 

(b)   Correction or rectification; 

(c)   Limitation of processing; and/or 

(d)   Further information regarding our  processing. 


7.2.     In respect of your rights under Section 7.1, we may refuse or limit your requests to access, correct, or restrict your Personal Data, including, but not limited to: 


(a)   Where disclosure would unreasonably affect the privacy or rights of another individual, such as in joint correspondence or third-party records; 

(b)   Where complying with the requests would involve disproportionate effort or expense relative to the privacy risk; or 

(c)   Where the Personal Data is subject to legal professional privilege or confidentiality obligations under the LPA or BCRR. 


SECTION 8: BREACH NOTIFICATION 


8.1.    In the event of a personal data breach, we will promptly assess the impact. 


8.2.     Where required under the PDPA, we will notify the Personal Data Protection Commissioner and affected individuals without undue delay. 


SECTION 9: CONTACT 


9.1.   Please contact us for any questions, concerns, or requests regarding this Privacy Policy or your Personal Data. 

  • Home
  • Members
  • Practice Areas
  • Contact us
  • Privacy Notice

ATLAS Group Law Practice

Advocacy · Tenacity · Litigation · Acumen · Strategy

Copyright © 2026 ATLAS Group Law Practice - All Rights Reserved.

Powered by

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

Accept