Skip to content
Legal

Privacy Policy

How we collect, use, share and protect personal data on the SEA Games 2027 Malaysia digital experience — aligned with PDPA principles and fan expectations of transparency.

Last updated · 8 August 2026

1. Introduction

This Privacy Policy explains how the SEA Games 2027 Malaysia digital experience operated at seagamesmalaysia2027.org (the “Site”, “we”, “us” or “our”) collects, uses, discloses, stores and protects personal data when you visit, browse, register interest, contact support, or otherwise interact with our online services.

This Site is the production public digital platform for the 34th Southeast Asian Games and ASEAN Para Games (Malaysia 2027), including information services, live results, schedule, ticketing and support. Where you are redirected to third-party systems (for example a payment or accreditation provider), their privacy notices apply for those services.

We design this Policy to align with the spirit of Malaysia’s Personal Data Protection Act 2010 (PDPA), good-practice transparency under ASEAN data protection frameworks, and commonly expected web privacy standards (notice, choice, security, retention and rights of access).

2. Who we are & scope

For the purposes of this Policy, the data controller of personal data collected through this Site is the operator of seagamesmalaysia2027.org and related subdomains (including cms.seagamesmalaysia2027.org for authorised staff). Controllership of analytics, contact forms, ticket orders and CMS accounts sits with that operator unless you are redirected to a third-party system.

This Policy applies to: (a) the public website and its pages; (b) on-site chat or assistant widgets; (c) ticketing and order lookup; (d) cookies and similar technologies on our domains (primary: seagamesmalaysia2027.org and cms.seagamesmalaysia2027.org; mirrors: paraaseanmalaysia2027.org, seagames2027.my and related hosts); and (e) support communications you send us about the Site.

This Policy does not cover third-party websites we link to (for example social networks, payment providers, or official federation pages). Those services have their own privacy policies.

3. Personal data we collect

We collect only what we need for the purposes described below. Categories may include:

3.1 Data you provide directly

  • Identity and contact details (name, email address, phone number, organisation) when you use Support, partnership or marketing contact channels.
  • Message content you send via forms, email or chat, including attachments you choose to upload.
  • Account or preference data if a future login or newsletter feature is enabled (username, language, communication preferences).
  • Accessibility or special-assistance requests you voluntarily disclose so we can respond appropriately.

3.2 Data collected automatically

  • Technical logs: IP address, browser type/version, device type, operating system, referring URL, pages viewed, timestamps and approximate location derived from IP (city/region level, not precise GPS unless you grant that permission on a future feature).
  • Cookie and local storage identifiers for preferences (e.g. light/dark theme), session continuity and analytics.
  • Performance metrics (page load times, error rates) to keep the Site reliable.

3.3 Data from third parties

  • If you arrive via a campaign link, we may receive UTM parameters (source, medium, campaign name) for marketing measurement.
  • If you authenticate through a future single sign-on provider, we receive the profile fields you authorise that provider to share.
  • Public content we republish or link (e.g. OCM social posts) remains subject to the original publisher’s policies.

3.4 Sensitive personal data

We do not actively seek sensitive personal data (health, biometric templates, religious belief, political opinions, etc.). If you voluntarily include such information in a support message, we will process it only to respond to your request and delete or minimise it when no longer needed, unless a longer retention is required by law.

4. How we use personal data

We process personal data for legitimate, transparent purposes, including:

  • Operating, securing and improving the Site and its features (schedule browsers, media players, chatbot, accessibility).
  • Responding to support, media, partnership and marketing enquiries.
  • Sending service messages you request (e.g. confirmation that we received your ticket-interest form) — not unsolicited bulk email without a lawful basis and unsubscribe option.
  • Measuring aggregated traffic and campaign effectiveness so we can allocate content and hosting resources responsibly.
  • Detecting, investigating and preventing fraud, abuse, security incidents and violations of our Terms.
  • Complying with applicable law, court orders or lawful requests from Malaysian authorities.
  • Establishing, exercising or defending legal claims.

6. Cookies & similar technologies

Cookies are small text files stored on your device. We use:

6.1 Essential cookies

Required for core functions such as security, load balancing, remembering your theme preference, and keeping a session stable. These cannot be switched off in our systems without breaking the Site.

6.2 Analytics cookies

Help us understand which pages are popular, how visitors move through the experience, and where technical errors occur. We prefer aggregated, de-identified reporting where feasible.

6.3 Marketing / campaign cookies

If enabled for a campaign, these measure whether a visitor arrived from a partner or social placement. You can control non-essential cookies via your browser settings and any cookie banner we display.

6.4 Managing cookies

  • Browser controls: most browsers let you block or delete cookies; blocking all cookies may limit features (e.g. theme persistence).
  • Do Not Track: where our tooling supports honouring browser DNT/GPC signals, we will document that behaviour when implemented.
  • Local storage: theme and similar preferences may use localStorage rather than cookies; clearing site data removes them.

7. Sharing & disclosure

We do not sell your personal data. We may share data only as follows:

  • Service providers (hosting, CDN, email delivery, analytics, security monitoring) under contracts requiring appropriate confidentiality and security.
  • Professional advisers (legal, audit) under confidentiality duties.
  • Authorities when required by Malaysian law or to protect vital interests, public safety or the integrity of the Games digital estate.
  • Successors in the event of a reorganisation of the Site operator, with notice where required.
  • With your direction — e.g. if you ask us to introduce you to a host-state tourism board.

8. International transfers

Our infrastructure may use cloud regions outside Malaysia. Where personal data is transferred internationally, we take steps consistent with PDPA expectations and industry practice — such as contractual safeguards with processors, access controls, and minimisation of data fields transferred.

By using the Site from outside Malaysia, you understand that your information may be processed in Malaysia and other jurisdictions where our providers operate.

9. Security measures

We implement technical and organisational measures appropriate to the risk, including but not limited to:

  • TLS encryption in transit for the public Site.
  • Access controls and least-privilege principles for administrative systems.
  • Monitoring for abuse, scraping spikes and injection attempts.
  • Regular dependency and infrastructure updates where we control the stack.
  • Staff/contractor awareness of confidentiality when handling support tickets.

9.1 No absolute security

No method of transmission or storage is 100% secure. Please use strong unique passwords for any future accounts, and contact us immediately if you suspect unauthorised use of your data in connection with this Site.

10. Retention

We keep personal data only as long as needed for the purposes collected, including:

  • Support tickets: typically up to 24 months after closure, unless a dispute or legal hold requires longer.
  • Marketing consents and suppression lists: retained as needed to honour opt-outs.
  • Server and security logs: typically 30–180 days, longer if investigating an incident.
  • Analytics aggregates: retained in de-identified form for trend analysis.

10.1 Deletion

When retention ends, we delete or irreversibly anonymise data in backups according to our backup rotation schedule.

11. Your rights

Subject to applicable law and verification of identity, you may request to:

  • Access personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Withdraw consent where processing is consent-based.
  • Object to or restrict certain processing, including direct marketing.
  • Request deletion where we no longer have a lawful need to keep the data.
  • Lodge a complaint with the Personal Data Protection Commissioner (Malaysia) or another competent authority.

11.1 How to exercise rights

Email privacy@seagamesmalaysia2027.org (or use the Support page) with “Privacy request” in the subject line. We may ask for information reasonably needed to verify you are the data subject. We aim to respond within a timeframe consistent with PDPA practice (typically within 21 days where feasible, or as required by law).

12. Children

The Site is intended for a general audience including families. We do not knowingly collect personal data from children under 13 for marketing. If you believe a child has provided personal data without appropriate guardian consent, contact us and we will take reasonable steps to delete it.

Guardians should supervise younger users’ interactions with chat widgets and forms.

13. Third-party embeds & social

Pages may embed or load assets from third parties (fonts, video CDNs, map tiles, analytics). Those parties may process technical data under their own policies. Social “share” or “follow” links take you to external platforms we do not control.

14. Automated decisions & AI assistants

Our on-site chatbot or assistants may use rules or models to suggest answers about the Games. They do not make legally significant automated decisions about you (e.g. ticket eligibility). Do not submit passwords, full payment card numbers or highly sensitive data into chat.

Chat transcripts may be logged temporarily to improve response quality and investigate abuse.

15. Changes to this Policy

We may update this Policy to reflect new features, legal requirements or operational changes. The “Last updated” date at the top will change when we do. Material changes may be highlighted on the Site or via email if we hold a verified address for you.

Continued use of the Site after an update constitutes notice of the revised Policy, except where consent is required for a new processing purpose.

16. Contact

Privacy enquiries and data-subject requests:

  • Email: privacy@seagamesmalaysia2027.org
  • Support form: seagamesmalaysia2027.org/support
  • Postal (general): SEA Games 2027 Malaysia — Privacy, Kuala Lumpur, Malaysia.

16.1 Disclaimer

This Policy is provided for transparency regarding personal data processed on the Site. It is not legal advice. Partner ticketing, accreditation, anti-doping and volunteer systems may publish additional notices for those services.

Related: Privacy · Terms · Support · Marketing