Privacy Policy

Last Updated: 20 February 2026  |  Thornwell, George Town, Penang

Thornwell ("we", "us", "our") is committed to handling personal data responsibly and in accordance with the Personal Data Protection Act 2010 (PDPA) of Malaysia. This Privacy Policy explains what personal data we collect, why we collect it, how it is used, and the rights you hold as a data subject. If you have any questions about this policy, please contact us at [email protected].

1. Data We Collect

We collect personal data that you provide to us voluntarily through our website contact form, by telephone, by email, or during in-person consultations. This may include:

  • Full name and identification details
  • Email address and telephone number
  • Postal address, where provided
  • Details of your estate matter or enquiry
  • Family relationship information relevant to an estate
  • Technical data collected via cookies (see Section 5)

We do not collect sensitive personal data (such as health information or financial account numbers) unless it is directly relevant to the legal matter you have engaged us for and you have provided it with knowledge of its use.

2. How We Use Your Data

Personal data collected is used for the following purposes:

  • Responding to your enquiry or consultation request
  • Delivering the legal services you have engaged us for
  • Communicating updates on your matter
  • Complying with legal and regulatory obligations
  • Maintaining records required under applicable Malaysian law
  • Improving the quality and accessibility of our services

We process your personal data on the basis of contractual necessity, legal obligation, or your consent, depending on the nature of the data and the processing activity.

3. Data Retention

We retain personal data for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable law. For client matter files, we retain data for a minimum of seven years following the conclusion of the matter. Enquiry data from individuals who do not become clients is retained for up to twelve months. You may request deletion of your data at any time, subject to any overriding legal retention requirements.

4. Data Sharing

We do not sell personal data to third parties. We may share data with:

  • Courts and government authorities, where required by the legal process
  • Professional service providers (such as translators or process servers) engaged by us in connection with your matter
  • Analytics providers, in anonymised or aggregated form only
  • Law enforcement or regulatory bodies, where required by Malaysian law

Any third party with whom we share personal data is required to maintain appropriate confidentiality and data security standards.

5. Cookies

Our website uses cookies to support basic website functionality and, where consent is given, to understand how visitors use our site. Essential cookies are necessary for the site to operate correctly. Optional analytics and preference cookies are only activated where you have given your consent through our cookie banner. You can manage your cookie preferences at any time via our Cookie Policy page.

6. Data Protection Measures

We take the security of personal data seriously. Our measures include:

  • Access to client files restricted to the legal team handling the matter
  • Secure storage of physical documents in access-controlled premises
  • Use of encrypted communication channels for sensitive correspondence
  • Regular review of data handling practices
  • Prompt notification in the event of a data breach affecting your personal data, in line with PDPA requirements

7. Your Rights Under the PDPA

As a data subject under the Personal Data Protection Act 2010, you have the following rights:

  • Right of access — to request a copy of personal data we hold about you
  • Right of correction — to request correction of inaccurate or incomplete data
  • Right to withdraw consent — where processing is based on consent, you may withdraw it at any time
  • Right to limit processing — to request that we limit how we use your data in certain circumstances
  • Right to raise concerns — to lodge a complaint with the Department of Personal Data Protection Malaysia

To exercise any of these rights, please contact us at [email protected]. We will respond within the timeframe required by applicable law.

8. Third-Party Links

Our website may contain links to external websites. We are not responsible for the privacy practices or content of those sites. We encourage you to review the privacy policies of any third-party website you visit via a link from our site.

9. Children's Privacy

Our services are intended for individuals who are 18 years of age or older. We do not knowingly collect personal data from minors. If you believe a minor has submitted personal data through our website, please contact us so we can remove it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The date at the top of this page indicates when the policy was last revised. Continued use of our website following any changes constitutes acceptance of the updated policy.

11. Contact Information

For any privacy-related enquiries, requests, or concerns, please contact our data handling team:

Thornwell

38, Persiaran Gurney, 10250 George Town, Penang, Malaysia

Email: [email protected]

Phone: +60 4-2618 3946