- What is the purpose of this Privacy Notice, and does it apply to me?
- Who is responsible for the handling of my Personal Information?
- What Personal Information about me does Willis collect?
- Why does Willis collect my Personal Information?
- How does Willis obtain and retain my Personal Information?
- Publicly accessible registers and databases, credit reference agencies, providers of identity verification services, providers of insurance claims validation services, operators of insurance fraud and other business risk screening databases, and other like providers of due diligence services; and
- Others as described in Section 4.1.4
- Do I have to give my Personal Information to Willis or allow Willis to handle my Personal Information?
- Does Willis share my Personal Information with third parties?
- Does Willis transfer my Personal Information overseas?
- Does Willis has security measures in place to protect my Personal Information?
- Access rights regarding my Personal Information and who can I contact about my Personal Information?
- Will this Privacy Notice change in the future?
1.1 This Privacy Notice serves as an information for clients and/or prospective clients of Willis (Malaysia) Sdn Bhd (“Willis”) on the collection, processing and protection of Your personal data in accordance to the requirements of the Personal Data Protection Act 2010 (PDPA 2010).
1.2 Throughout this Privacy Notice, references to “You” or “Your” shall mean the clients or prospective clients of Willis, whereas “Our” and “We” shall refer to Willis.
1.3 By interacting with Willis, submitting information to Willis, enrolling or signing up for any products or services offered by Willis, You are providing personal information to the Company. This Privacy Notice describes how Willis handles personal information about You, which Willis collects in connection with insurance broking services that Willis provides (typically insurance-related, consultancy and solutions for employee benefits and/or risk). It also explains certain legal rights You have in connection with Your personal information, which is handled by Willis. This Privacy Notice may be revised from time to time to reflect changes in law or changes in Willis’s business operation.
1.4 Please note that this Privacy Notice does not apply to You if You are:
1.4.1 an employee, contractor, or any other type of worker engaged by Willis.
1.4.2 a visitor to any website which is maintained by the Willis Towers Watson Group (including the Willis Towers Watson Group's main website and the online tools accessible from there), in which case the collection of any personal information about You will be subject to the separate website privacy notice for the relevant website. Unless specifically stated otherwise, the website privacy notice applicable to all website maintained by the Willis Towers Watson Group can be found at Global Website Privacy Notice.
2.1. Unless indicated otherwise, and generally speaking, where Willis handles Your personal information in connection with broking of insurance, (re)insurance, employee benefits, and other like services, the responsible Company is:
Willis (Malaysia) Sdn. Bhd.
Co. No. 197601000123 (026067-X)
Level 26, Menara Dion #26-04, 27 Jalan Sultan Ismail
50250 Kuala Lumpur
3.1 Personal information collected by Willis will vary depending on various factors, including Your personal circumstances, the nature of Your relationship with Willis (or Willis's client/prospective client), and the relevant services provided by Willis, but may include any combination of the following:
3.1.1 Your contact details such as name, postal address, email address, and telephone number;
3.1.2 Your gender, date/place of birth, marital status, dependents, nationality, country of residence, occupation, hobbies, habits, and other similar demographic information;
3.1.3 Your unique identifiers such as bank account number, credit card number, NRIC number, passport number, and driver's license number;
3.1.4 Information about Your physical and mental health, including Your medical history, description of illness or injury suffered, and any specific treatment received;
3.1.5 Information about You, which Willis is obliged to check for legal or regulatory reasons, such as information relating to Your identity, any directorship of companies You keep, any breaches or alleged breaches of the law both civil and/or criminal that You may have had;
3.1.6 Other information about You, which Willis handles in connection with the services Willis provides to You or a client of Willis, such as Your personal circumstances that need to be described in arranging any (re)insurance for You or a client of Willis, details of incidents giving rise to any (re)insurance claim in which You are involved, and facts and circumstances involving You in respect of which Willis is asked to advise a client; and
3.1.7 Other information about You which Willis collects as part of its day-to-day business operation, such as information about Your visit to Willis’s office, Your attendance at meetings and events hosted by Willis, and Your correspondence with Willis's brokers, advisors and consultants.
3.2 Other information that may also include sensitive information such as Your racial/ethnic origin, religious/philosophical/political views or affiliations, trade association, criminal record if any, sex orientation and health.
4.1 Willis collects and uses Your personal information primarily for the following purposes:
4.1.1 to provide services, which You personally request (e.g. where You request Willis to arrange personal insurance for Your domestic purpose or commercial insurance for Your own business purpose);
4.1.2 to provide services, which You did not personally request but is nevertheless arranged for Your benefit (e.g. where Your employer asks Willis to arrange health plan, or other forms of employee benefits, or where a client of Willis asks Willis to arrange any (re)insurance, which might directly or indirectly benefit You, or where Your employer asks Willis to provide certain types of consultancy and solutions relating to employee benefits and/or risk);
4.1.3 to provide services, which You did not personally request but were requested by Willis 's client and requires Willis to interact, directly or indirectly, with You (e.g. where You bring a claim against Our client, and We are required to handle the claim under the relevant (re)insurance policy);
4.1.4 to enable underwriters, actuaries, (re)insurers, other brokers, claims handlers, surveyors, loss adjustors/assessors, accident investigators, specialist risks advisors, pension providers, banks and other lenders (including premium finance providers), health professionals, lawyers, accountants, auditors, consultants, and other like third party professional advisors and service providers to provide their services (to the extent their involvement is inherent in or necessary in connection with the services provided by Willis);
4.1.5 to enable affiliates of the Willis Towers Watson Group and non-affiliated third party services providers (e.g. IT services providers, administrative support service providers, etc.) to provide services that directly or indirectly support Willis's business operation and the services provided by Willis;
4.1.6 to comply with legal or regulatory requirements imposed on Willis or a client of Willis (including the requirement to conduct ”Know-Your-Client” checks, anti-money laundering/sanctions screening, and other like due diligence checks);
4.1.7 to improve or develop the products and services Willis provides to Willis's clients in general (e.g. improving internal business processes, providing analysis on trends in the (re)insurance market or employee benefits market, benchmarking (re)insurance products); and
4.1.8 to contact You and generally maintain the relationship between You and Willis in connection with the services provided by Willis and other opportunities which might be of interest or benefit to You.
4.2 In relation to Section 4.1.7 above, Willis may use Your personal information to create and analyse statistical data that might be shared with third parties. However, such analysis will be conducted solely on an aggregated and anonymous basis and under no circumstance You could be identified in such analysis.
4.3 In relation to Section 4.1.8, Your personal information will be used for relationship maintenance/marketing purpose only if You are Yourself a client of Willis or if You are the business contact at Willis's client. Willis does not engage in direct marketing that targets consumers in general. However, depending on Your relationship with Willis, You might receive marketing communication from Willis. Where in this case, Willis will always respect Your marketing preference and comply to any applicable law that specifically regulates the use of personal information for direct marketing purpose.
4.4 Please note that Willis will never use Your personal information for any purpose not described above without Your prior consent (or the prior consent of the relevant client of Willis, where applicable).
5.1 Personal information handled by Willis is typically provided by a client of Willis. However, depending on the circumstances, Willis might collect personal information from other third parties who are relevant to the services Willis provides, and Willis might also collect personal information directly from You.
5.1.1 Where Willis is required to handle Your personal information, Willis generally obtains Your personal information indirectly from a client of Willis (typically a company, partnership, public authority, or other like body corporate) which receives services that affect You.
5.1.2 Occasionally, it will be necessary for Willis to obtain Your personal information directly from You.
5.1.3 Depending on the circumstances, Willis may also obtain Your personal information from other sources such as:
5.2 Willis may retain Your personal information for such time as deemed to be necessary for the purpose of fulfilling any operational, audit, investigation, legal, regulatory, tax or accounting requirements, including but not limited to any potential litigation, and future placement and claims assessment purposes.
6.1 The personal information that You have provided to Willis is necessary. If You do not provide Willis with such information or do not consent Willis handling Your personal information, it might prevent Willis from performing its services, and this might in turn, depending on Your circumstances, adversely affect You (e.g, through delays in or inability to provide placement of (re)insurance or assessment/payment of (re)insurance claims).
6.2 Additionally, where there is a relevant legal exemption that applies to the way in which Willis collects and processes Your personal information, Willis reserves the right to rely on such legal exemption to collect and process Your personal information regardless of Your wishes but only if and to the extent it is necessary to do so for one or more of the purposes described in Section 4 above.
7.1 Willis may disclose and/or share Your personal information with third parties only if and to the extent it is necessary and appropriate for one or more of the purposes set out in Section 4 above. Specifically, Willis may share Your personal information with the following types of third parties:
7.1.1 as per those listed in Section 4.1.4;
7.1.2 clients of Willis who receive services which is arranged for Your benefit, or otherwise requires Willis to interact, directly or indirectly, with You;
7.1.3 affiliates of the Willis Towers Watson Group and non-affiliated third party services providers (e.g. IT services providers, administrative support service providers, etc.) that provide services that directly or indirectly support Willis's business operation and the services provided by Willis;
7.1.4 credit reference agencies, providers of identity verification services, providers of insurance claims validation services, operators of insurance fraud and other business risk screening databases, and other like providers of due diligence services (to the extent necessary to comply with legal or regulatory requirements imposed on Willis or a client of Willis); and
7.1.5 regulators, police, courts/tribunals, and other like public authorities who have jurisdiction over Willis (to the extent necessary to comply with any legal or regulatory requirements imposed on Willis or a client of Willis).
7.2 Willis may also share Your personal information in connection with the planning, due diligence and implementation of commercial transactions, including a reorganization, merger, sale of all or a portion of Our assets, a joint venture, assignment, transfer, or other disposition of all or any portion of Our business, assets, or stock (including in connection with any bankruptcy or similar proceedings) – in such cases, Your personal information will be transferred to the acquiring entity.
7.3 In all other cases, Willis will not share Your personal information with other third parties without Your prior consent (or the prior consent of the relevant client of Willis, where applicable) unless Willis has a legal ground on which to do so (e.g. where any applicable law requires Willis to do so, or where Willis is compelled to do so by a Court Order).
8.1 Due to the international nature of Willis's business operation and the (re)insurance market in which Willis operates, Your personal information may be shared with third parties that are located outside of Malaysia or in countries that do not have laws that protect personal information in the same way laws Malaysia do.
8.2 Your personal information may be transferred across international borders by Willis to affiliates of the Willis Towers Watson Group and non-affiliated third parties described in Section 7.1.3 above, who could be located anywhere in the world. As a minimum, such third party recipients based overseas will include other Willis Towers Watson Group companies that are based in the UK, USA, Philippines and India.
8.3 Whenever Willis transfers Your personal information across international borders, Willis will take all appropriate steps that are within Willis's control to take to ensure that such transfer complies with the applicable legal requirements.
9.1 Willis takes the privacy and confidentiality of Your personal information very seriously. Your personal information will be protected in accordance with the strict information security standards that apply across the Willis Towers Watson Group, including Willis in Malaysia.
9.2 In the unlikely and unfortunate event Your personal information under Willis's control becomes compromised due to any information security breach (e.g. unauthorised access, loss, or disclosure/alteration, including where this is caused by contractors), Willis will act promptly to identify the cause of such information security breach, and remediate and mitigate the consequences of such information security breach. Where appropriate, Willis will also notify You (and/or the relevant client of Willis, where applicable) in accordance with any applicable law which requires Willis to notify You about such incidents.
10.1 If You wish to exercise Your legal right to access/correct Your personal information, or if You have any query or complaint regarding the handling of Your personal information by Willis, please contact Willis in the first place, Under the Malaysia’s Personal Data Protection Act 2010, You have the legal right to access Your personal information held by Willis and to ask Willis to correct or delete Your personal information (e.g. where it is inaccurate or out-of-date). If You would like to exercise this right, or if You have any query or complaint regarding the way in which Your personal information is handled by Willis, please contact:
Data Privacy Officer
c/o Willis (Malaysia) Sdn. Bhd.
Level 26, Menara Dion #26-04, 27Jalan Sultan Ismail,
50250 Kuala Lumpur
Tel: +603-8681 0000
Email: Willis Malaysia Data Privacy Officer
10.2 You can also write to the Willis Towers Watson Global Privacy Office at privacy willis towers watson.
10.3 Please note that Your right to access and correct/delete Your personal information could be subject to certain legal exemptions, and where any legal exemption applies, Willis might not be able to comply with Your request to access or correct/delete Your personal information.
10.4 Willis will endeavour to respond satisfactorily to Your request to access or correct/delete Your personal information, or any question, concern, or complaint regarding Your personal information You raise with Willis. However, if You are dissatisfied with Willis’ response and wish to make a formal complaint about the way in which Willis has handled Your personal information (or if You wish to learn more about Your rights under Malaysia's Personal Data Protection Act 2010), You can contact:
Department of Personal Data Protection
Level 8, Galeria PJH, Jalan P4W
Persiaran Perdana, Precinct 4, Federal Government Administration Centre, 62100 W.P. Putrajaya, Malaysia
Tel : 03-8861 1101
Web Page : Pejabat Pesuruhjaya Perlindungan Data Peribadi
11.1 This Privacy Notice may be amended from time to time to reflect changes in law or changes in Willis's business operation, but where such revision becomes necessary in the future, Willis will notify You to the extent it is practicable for Willis to do so.
11.2 As a minimum, changes to this Privacy Notice will be publicised on Willis Towers Watson's website at (through a link to “Willis Malaysia Privacy Notice” that appears at the bottom frame of the landing page).
In the event of any inconsistencies between the English version and the Bahasa Malaysia version of the Privacy Notice, the English version shall prevail.