Legal · Data Protection

PDPA & Data Protection

How MagiBox meets the Singapore PDPA, Malaysia PDPA, and the Australian Privacy Act 1988 and Australian Privacy Principles.

Last updated · June 2026

Our data protection commitment

MagiBox serves educators across Singapore, Malaysia, and Australia, and we align our data-handling practices with the laws of each region. This notice summarises how we apply the Singapore Personal Data Protection Act (PDPA), the Malaysia Personal Data Protection Act (PDPA), and the Australian Privacy Act 1988 and its Australian Privacy Principles (APPs). It complements, and should be read with, our Privacy Policy.

Singapore PDPA

Under the Singapore PDPA, we collect, use, and disclose personal data only for purposes a reasonable person would consider appropriate and for which consent has been given or is deemed given or otherwise permitted by law.

  • Consent and notification: we tell individuals why their data is collected and rely on a valid basis for processing.
  • Purpose limitation: data is used for the stated education-delivery and platform purposes.
  • Access and correction: individuals may request access to and correction of their personal data.
  • Protection and retention: we apply reasonable security and stop retaining data once the purpose is fulfilled and retention is no longer required.

Malaysia PDPA

Under the Malaysia PDPA, we process personal data in line with its data protection principles, including the General, Notice and Choice, Disclosure, Security, Retention, Data Integrity, and Access principles.

  • We notify individuals of the purposes of processing and the classes of recipients.
  • We process data only for lawful, directly related purposes and do not disclose it for unrelated purposes without consent.
  • We take practical steps to keep data secure, accurate, and retained no longer than necessary.
  • Individuals may request access to and correction of their personal data.

Australia Privacy Act 1988 & APPs

For Australian customers, we handle personal information consistently with the Australian Privacy Principles under the Privacy Act 1988.

  • Open and transparent management of personal information (APP 1) and the option of anonymity where practicable (APP 2).
  • Collection of only the personal information reasonably necessary for our functions (APP 3) and use or disclosure limited to the primary or a related purpose (APP 6).
  • Reasonable steps to keep information accurate, secure, and protected (APP 10 and APP 11).
  • Access to and correction of personal information on request (APP 12 and APP 13), and notification of eligible data breaches where required.

Cross-border transfer

MagiBox operates primary infrastructure in Singapore with an Australian mirror, and may use approved sub-processors. Where personal data is transferred across borders, we put in place contractual and technical safeguards so that a comparable standard of protection applies, consistent with the transfer-limitation requirements of the Singapore PDPA, Malaysia PDPA, and the APPs.

Exercising your rights

Individuals may ask to access, correct, or withdraw consent for the processing of their personal data. Because campuses and organisations control their own learner records, we will, where appropriate, direct requests to the relevant organisation and support them in responding within the timeframes their local law requires.

Data protection contact

We maintain a point of contact responsible for data protection matters and for handling access, correction, and complaint requests across all three jurisdictions. You can reach this contact using the address below.

Questions about this page?

Reach our data protection team and we will respond within a reasonable period. For data access, correction, or deletion requests, please include the campus or account involved.

[email protected]

This page is provided for general information and does not constitute legal advice. It should be reviewed by qualified legal counsel in each operating jurisdiction before go-live.