PDPA Compliance Checklist for Malaysian Companies (2026 Edition)
Following the PDPA 2024 Amendment, which came into force on 1 June 2025, the compliance bar for Malaysian organisations has moved. The original Act was largely about registering and having a privacy policy. The amended framework is about active, ongoing governance.
This checklist covers what your organisation actually needs to have in place. It is written for compliance managers, HR directors, and business owners — not for lawyers. Where each item links to a legal obligation, it is noted.
How to Use This Checklist
Go through each section. For any item you cannot confidently tick, that is a gap. Some gaps are minor (a quick policy update). Others are material (no breach response procedure). Prioritise by risk, not by effort.
1. Data Inventory and Mapping
Before you can comply with PDPA, you need to know what personal data you actually hold.
- Have you identified all personal data your organisation collects (customer data, employee data, vendor contacts, etc.)?
- Do you know where that data is stored (CRM systems, spreadsheets, email inboxes, cloud drives, physical files)?
- Do you know who internally has access to each data set?
- Do you know which third parties (vendors, cloud providers, payroll systems) receive or can access personal data you hold?
- Do you maintain a Record of Processing Activities (ROPA) that documents all of the above?
If you cannot answer these questions, everything else in this checklist is built on sand. A data inventory is the foundation.
2. Privacy Notice
Under PDPA's Notice and Choice Principle, individuals must be informed about how their personal data is used at the point of collection. This is a legal obligation for every organisation processing personal data commercially in Malaysia.
- Do you have a Privacy Notice (also called a Privacy Policy or Data Protection Notice) in place?
- Does it cover: what data is collected, the purpose of collection, who the data may be shared with, the individual's right to access and correct their data, and how to contact you with data concerns?
- Is it written in plain language that a non-lawyer can understand?
- Is it accessible at the point where personal data is collected (website forms, physical intake forms, app onboarding)?
- Has it been reviewed and updated to reflect the PDPA 2024 Amendment requirements?
Common failure point: Many Malaysian organisations have a Privacy Notice on their website footer, but it is not linked from the forms where data is actually collected. The Notice must be presented at the point of collection to satisfy the Notice and Choice Principle.
3. Consent Mechanisms
- Where you rely on consent as the basis for processing personal data, is that consent obtained explicitly and recorded?
- Is consent not bundled with terms and conditions in a way that makes it impossible to give or withdraw independently?
- Can individuals withdraw consent, and do you have a process for acting on withdrawal requests?
- For marketing communications, do you have opt-in consent (not just the absence of an opt-out)?
4. Data Security Measures
PDPA's Security Principle requires "practical steps" to protect personal data. Post-2024 Amendment, this is taken more seriously by the regulator, and breach liability has increased.
- Is access to personal data restricted to staff who need it for their role (principle of least privilege)?
- Are passwords and authentication controls in place for systems holding personal data?
- Is data in transit encrypted (HTTPS, secure email protocols)?
- Is sensitive data encrypted at rest?
- Are software systems and devices kept updated with security patches?
- Do you have controls around personal data sent via email or messaging apps (e.g., employees emailing customer lists to personal addresses)?
- For physical data: are paper records with personal data stored securely and disposed of properly (cross-cut shredding, not general waste)?
5. Data Breach Response Plan
Under the PDPA 2024 Amendment, you have 72 hours from discovery of a data breach to notify the Personal Data Protection Commissioner. If you do not have a breach response plan, you will not meet this deadline.
- Do you have a documented data breach response procedure?
- Does it specify who is responsible for leading the response (typically the DPO or a nominated person)?
- Does it include steps for: containing the breach, assessing the scope, notifying the Commissioner within 72 hours, and notifying affected individuals?
- Do staff know how to report a suspected breach internally, and to whom?
- Have you done a tabletop exercise or drill to test the procedure?
72-Hour Rule: The 72-hour notification window begins when the organisation becomes aware of the breach — not when it is fully investigated. "We are still investigating" is not a reason to delay notification. You notify with what you know, then update the Commissioner as the investigation progresses.
6. Data Retention and Disposal
- Do you have a documented data retention schedule specifying how long different categories of personal data are kept?
- Is data that is no longer needed being deleted or anonymised, rather than accumulated indefinitely?
- For employee data, are you deleting records for former employees when they are no longer legally required?
- For customer data, are you removing or anonymising records when the commercial relationship has ended and there is no legal obligation to retain?
7. Staff Training
Most PDPA violations are caused by employee error rather than malicious external attacks. Staff who handle personal data are your most significant compliance risk — and your most significant opportunity.
- Have all staff who handle personal data received PDPA awareness training?
- Is training refreshed regularly, not just done once at onboarding?
- Do staff know what constitutes a data breach, and how to report it internally?
- Are HR staff trained on employee data rights under PDPA?
- Is management aware of their personal liability under the PDPA 2024 Amendment?
OrbixTech's PDPA Awareness Training is HRD Corp SBL-Khas claimable and can be delivered in-house for your full team.
8. Third-Party and Vendor Management
- Have you identified all vendors and third parties who access or process personal data on your behalf (cloud storage, payroll, HR systems, marketing platforms, IT support)?
- Do your contracts with these parties include data protection clauses specifying how they must handle personal data and what they must do in the event of a breach?
- Have you assessed the data protection practices of your key data processors?
- If personal data is transferred outside Malaysia (e.g., to cloud servers in other countries), do you have the required safeguards in place?
9. Individual Rights Management
Under PDPA, individuals have the right to access their personal data and request corrections. They also have the right to withdraw consent for direct marketing.
- Do you have a process for receiving and responding to data access requests from customers or employees?
- Do you have a process for correcting personal data when an individual reports it is inaccurate?
- Can individuals opt out of marketing communications, and do you act on those requests promptly?
- Is there a clear contact point (email, form, or phone) for individuals to exercise their rights?
10. DPO Appointment (If Applicable)
- Does your organisation process personal data of 20,000 or more individuals, or sensitive personal data of 10,000 or more individuals?
- If yes: have you appointed a Data Protection Officer (internal or outsourced)?
- Has the DPO's appointment been registered with JPDP as required?
- Does the DPO have sufficient independence, authority, and resources to perform their role?
- If below the threshold: have you designated someone responsible for data protection oversight, even informally?
What to Do With the Gaps You Find
Most organisations working through this checklist for the first time will find gaps. That is normal and expected. The question is not whether gaps exist — it is whether you have a plan to close them.
Prioritise the items with the highest consequence: breach response (the 72-hour rule is non-negotiable), security measures (this is where breaches originate), and staff training (this is where most breaches start).
Everything else can be addressed in a structured programme over time. But those three need to be in place before anything else.
If you want support working through this systematically, OrbixTech offers a PDPA Compliance Assessment for Malaysian organisations — covering gap analysis, documentation, training, and ongoing DPO support.