Privacy Policy
MTE Exhibition Sdn Bhd
1. Who we are and what this policy covers
MTE Exhibition Sdn Bhd (“MTE”, “we”, “us”) organises trade exhibitions, conferences and related events in Malaysia. We are the data controller for the personal data described in this policy, which means we are responsible for how it is handled.
This policy applies to:
- visitors, delegates and attendees at our exhibitions and conferences;
- exhibitors, sponsors, contractors and suppliers, and their staff;
- events we organise on behalf of, or jointly with, another organisation — including the Federation of Malaysia Freight Forwarders (FMFF) conference to be held in conjunction with MTE 2027;
- visitors to our websites;
- people who apply to work with us.
This policy is written to comply with the Personal Data Protection Act 2010 and the amendments brought into force by the Personal Data Protection (Amendment) Act 2024.
2. What we collect
If you register for, or attend, an event: your name, title, job title, company, business contact details including telephone and email, country, industry or nature of business, and your answers to the registration questions for that specific event. We issue you a badge carrying a code; that code identifies your registration but does not itself contain your personal details.
If you buy a ticket or pay us directly: payment details, including credit or debit card information where you pay us for a ticket to an event or conference.
If you are an exhibitor, sponsor, contractor or supplier: the contact details of your staff who deal with us, contract and billing information, company registration and tax details, and bank account details where we pay you.
If you apply to work with us: your name, address, contact details, current and past employment information, educational qualifications, and anything else in your application or provided by referees you have named.
From our websites: information about your visit through cookies — the day and time, whether you have visited before, whether a search engine brought you, and broad geographic location. You can set your browser to refuse cookies.
Sensitive personal data. Under the Personal Data Protection Act 2010 this means data about your physical or mental health, political opinions, religious beliefs, the commission of an offence, and — since the 2024 amendment — biometric data. We do not ordinarily collect any of these. Where an event requires dietary, accessibility or medical-declaration information, we collect it only for that event, use it only for that purpose, and do not pass it to exhibitors or sponsors.
Where we get it. Usually directly from you — in person, in writing, by telephone, by email, through our registration systems or through social media. We also receive delegate lists from organisations who appoint us to run their event, and contact details from referees you have named. We do not buy, rent or scrape marketing lists.
3. People under 18
Malaysian law requires the consent of a parent or guardian before we may process the personal data of anyone under 18.
Where an event admits people under 18 — for example students attending a conference with their institution — we require the consent of a parent or legal guardian for that person’s registration. A teacher, lecturer or institutional chaperone is not a parent or guardian for this purpose, even where they accompany the student at the event.
Where an event has a minimum age, we state it in that event’s registration conditions and we do not knowingly register anyone below it.
4. Why we use your personal data
To provide the service you came for:
- to process your registration and issue your badge;
- to admit you to the event and record your attendance;
- to contact you about the event you registered for, including changes to it;
- to process your ticket payment and issue receipts and invoices;
- to provide business matching — connecting visitors with exhibitors whose products or solutions match the interests and requirements in your profile;
- to answer your enquiries and handle your requests;
- to administer contracts with exhibitors, sponsors, contractors and suppliers;
- to assess employment applications.
To run and improve our business:
- to tell you about our exhibitions, conferences, products and services, and those of our exhibitors and sponsors, where you have not asked us to stop;
- to understand attendance, industry mix and visitor interests so that we can plan, improve and market future events;
- to detect and prevent fraud, misuse and unauthorised access;
- to meet our legal, tax and regulatory obligations.
What we rely on. Mostly your consent, given when you register. In some cases we rely on performing our contract with you, or on a legal obligation. You can withdraw consent at any time — see section 8.
5. Who we share it with, and what they may do
Exhibitors and sponsors. We provide your name, company, business contact details, country, and your registration answers to the exhibitors and sponsors at the event you attend, so that they may contact you with offers relating to their products and services. We do not pass on sensitive personal data.
Badge scanning. Some exhibitors have scanning devices at their stands. If you allow an exhibitor to scan your badge, you are agreeing to that exhibitor contacting you by post, telephone, email or SMS. You choose whether to present your badge at each stand.
A scan cannot be taken back. Once an exhibitor has downloaded the details of a visitor who let them scan, we cannot recall that copy. This is why the choice sits with you at the stand.
Service providers who act for us. Registration platforms, exhibitor manual systems, badge printing, email delivery, technology hosting and cloud providers, payment processors, and professional advisers. They may use your data only to perform that service for us, under contract, and not for their own purposes. Our current visitor registration and exhibitor manual services are provided in part by an external supplier.
Organisations we run events for. Where MTE organises an event on behalf of another body — such as FMFF — we share the registration and attendance data for that event with that body, for that event’s purposes.
Related companies and associated entities, for the purposes set out in section 4.
Where the law requires or authorises it, and to anyone else you tell us to.
6. Sending data outside Malaysia
Some of the service providers described above operate, or store data, outside Malaysia. Where personal data leaves Malaysia we take steps to ensure it remains protected to a standard comparable with the Personal Data Protection Act 2010 — either because the receiving country provides comparable protection in law, or through contractual obligations binding the recipient.
7. How long we keep it
We keep your personal data for as long as our relationship with you continues.
Our purpose in collecting it does not end when a single show closes. MTE runs recurring exhibitions and conferences, and we retain visitor, delegate and exhibitor records so that we can invite you to, and plan, future editions and related events, and so that we can understand how our industry and our audiences change over time. That is an ongoing purpose, and we hold the data for as long as it lasts.
When we no longer need to identify you personally, we anonymise rather than delete. We remove the details that identify you — name, job title, email, telephone and address — and keep only information that cannot be traced back to an individual, such as company, country, industry and your answers to event questions. Anonymised records are no longer personal data and we keep them indefinitely for statistical, planning and historical purposes.
Where you ask us to remove your details, we act as described in section 8. Because anonymising a record does not remove an exhibitor’s own copy of a lead they have already downloaded, we will tell you when that applies.
Where the law requires us to keep something for a set period — tax and accounting records, for example — we keep it for that period.
8. Your rights
Access. You may ask what personal data we hold about you. We will respond as soon as reasonably practicable. We may charge a reasonable fee for supplying copies, but never for making the request itself.
Correction. You may ask us to correct or update anything inaccurate, incomplete, misleading or out of date. Where an event provides you with a private link to your own registration, you can correct most details yourself.
Withdrawing consent. You may withdraw your consent to our processing of your personal data at any time. Where withdrawal means we can no longer provide something — admitting you to an event, for example — we will tell you.
Stopping direct marketing. You may tell us at any time to stop using your personal data for marketing or direct marketing. Every marketing message we send carries a way to unsubscribe. Stopping marketing does not require you to withdraw consent for anything else.
Removal of your details. You may ask us to remove your personal details from our records. We will do so, or anonymise the record as described in section 7, unless we are required or permitted to keep something — to complete a transaction you asked for, to meet a legal obligation, to establish or defend a legal claim, or to investigate fraud or misuse. We will tell you which applies. Where an exhibitor has already downloaded a lead from a badge you allowed them to scan, we cannot recall their copy.
Limiting processing. You may ask us to limit how we process your personal data, and we will tell you what that means for the service.
Complaining. If you are unhappy with how we have handled your personal data, contact us using the details in section 10. If you are not satisfied with our response, you may complain to the Personal Data Protection Commissioner, Malaysia (Jabatan Perlindungan Data Peribadi).
To exercise any of these rights, email [email protected] with the subject line PDPA.
9. Keeping it safe, and telling you if something goes wrong
Security. We hold personal data in electronic systems and, where necessary, in hard copy. We take reasonable steps to protect it against misuse, loss, unauthorised access, modification and disclosure, including access controls, encryption in transit and at rest where appropriate, restricting access to staff who need it, keeping records of access, and physical security for hard copy.
Breach notification. Malaysian law requires us to notify the Personal Data Protection Commissioner of a personal data breach that meets the thresholds set under the Act, and to notify affected individuals where the breach is likely to cause them significant harm. We have a process for assessing and reporting breaches within the time limits the law allows.
10. How to contact us
Write to us about anything in this policy, to exercise any of the rights in section 8, or to complain.
| [email protected] | |
| Telephone | +603-7842 9863 |
| Address | MTE Exhibition Sdn Bhd F-1-48 Jalan PJU 1A/3, Taipan Damansara 2, Ara Damansara, 47301 Petaling Jaya, Selangor, Malaysia |
11. Monitoring at our events
Where we or a venue operate CCTV, or where we record attendance by scanning badges at entrances and sessions, we say so at the event. We use attendance records to manage the event, to report attendance to exhibitors, sponsors and event partners in aggregate, and to plan future events.
12. Changes to this policy
We may update this policy. The version number and effective date at the top will change, and previous versions are listed below. Where we register your consent against a policy version, we keep a record of the version you were shown.
| Version | Effective | What changed |
|---|---|---|
| 1.0 | — | Original policy |
| 2.0 | 21 Sep 2026 | Rewritten for the Personal Data Protection Act 2010 as amended in 2024. Retention and anonymisation stated. Consent for people under 18 stated. Breach notification stated. Business matching, badge scanning and the irrevocability of a downloaded lead stated plainly. Contact details updated. Versioning introduced. |

