What Our Clients
Say About Working With Us
The relationships we build with clients are built on straightforward communication and careful work. Here are some of the experiences they've shared.
Back to Home
Client Engagements
Years in Tech Law
Average Client Rating
Core Practice Areas
From the Clients We've Worked With
"We engaged Northwyn to review our data processing practices under PDPA after expanding our operations. They were thorough without being alarmist, and gave us a clear picture of where we needed to make changes and where we were already on solid ground."
Kelvin Lim
Chief Operations Officer, Petaling Jaya
February 2025 • Data Protection Advisory
"When we discovered our systems had been accessed without authorisation, we didn't know what our notification obligations were. Northwyn helped us work through that quickly, guided our liaison with the relevant department, and helped us document everything properly."
Nurul Rashidah
IT Director, Kuala Lumpur
January 2025 • Cybersecurity Incident Response
"We needed a SaaS agreement reviewed before signing with a vendor. The team identified several provisions that would have caused us real problems — particularly around liability and data handling — and helped us negotiate amendments. Straightforward, no-fuss engagement."
Jason Tan
Finance Manager, Shah Alam
March 2025 • Technology Contract Review
"I appreciated that they took time to explain their findings rather than just sending over a marked-up document. The privacy policy they drafted for us is something our team actually understands and can implement correctly."
Syarifah Yusoff
Compliance Lead, Cyberjaya
December 2024 • Data Protection Advisory
"We had an existing IT outsourcing agreement that was up for renewal and wanted to improve the data handling provisions. Northwyn reviewed both the outgoing and proposed new versions and gave us a clear comparison of what had changed and what we should push back on."
Azrul Hafiz
Head of Procurement, Putrajaya
January 2025 • Technology Contract Review
"The post-incident support was genuinely useful. Beyond just helping with immediate notifications, they reviewed our vendor contracts to understand where responsibility sat and helped us think through what we needed to change going forward. It was a difficult situation handled sensibly."
Chong Wei Liang
CEO, Technology Company, Selangor
February 2025 • Cybersecurity Incident Response
Selected Client Situations
A few examples of the kinds of matters we've assisted with. Details have been generalised to maintain client confidentiality.
PDPA Compliance Review — Regional E-commerce Operator
The Situation
A Selangor-based e-commerce company processing personal data across multiple customer touchpoints had no formal PDPA compliance framework in place. Their legal team had limited familiarity with Malaysian data protection requirements and needed external advisory support.
What We Did
We conducted a structured review of their data collection and processing activities, assessed each against PDPA requirements, drafted a compliant privacy notice and internal data handling procedures, and provided guidance on managing data subject requests and third-party data sharing arrangements.
The Outcome
The client established a documented compliance position, with clear procedures in place for handling data subject rights requests and managing third-party data processors. The engagement took approximately six weeks and covered three key processing activities within their operations.
Cybersecurity Incident — B2B Software Provider
The Situation
A Kuala Lumpur-based software company discovered unauthorised access to a system holding customer records. They faced uncertainty about whether they were required to notify affected customers and the Personal Data Protection Department, and under what timeline.
What We Did
We assessed the nature and scope of the incident, provided a legal opinion on notification obligations under PDPA, supported preparation of communications to affected parties, and liaised with the Personal Data Protection Department. We also reviewed the company's vendor contracts to identify where security responsibilities had been allocated.
The Outcome
The client fulfilled their notification obligations in a timely and well-documented manner. The vendor contract review identified two agreements with inadequate security provisions, which were subsequently renegotiated. Post-incident documentation provided a clear record of the response taken.
Technology Development Agreement — Digital Agency and Client
The Situation
A digital agency entering a significant development contract with a corporate client needed the agreement reviewed before signature. The client had drafted the agreement, and the agency was concerned about IP ownership provisions and what happened if the project scope changed during development.
What We Did
We reviewed the agreement in full, identified the IP provisions that placed all rights with the client regardless of prior agency IP, highlighted scope change procedures that were unclear, and proposed specific amendments to address both issues. We participated in a review session with the agency's director to explain the findings.
The Outcome
The agency entered the contract with an amended IP clause protecting their pre-existing work and tooling, and a clearer scope change process. The counterparty accepted most proposed changes after a short negotiation period. The whole process from initial instruction to execution took approximately three weeks.
Professional Standing
Malaysian Bar Members
Admitted under the Legal Profession Act 1976
Cyberjaya-Based Practice
Located in Malaysia's technology hub since 2017
200+ Clients Served
Across data protection, cybersecurity and contract work
4.8 Average Rating
Across client satisfaction assessments
Reach Us Directly
Would You Like to Discuss Your Situation?
We're glad to have an initial conversation about what you're working with, without any pressure to proceed.
Get in Touch