PDPA Malaysia: The Questions Everyone Is Asking (And Honest Answers)
Every week, business owners and HR managers across Malaysia ask an AI tool some version of the same questions. What is PDPA? Do I need to comply? What happens if I don't? Am I already breaking the law?
These are the right questions. Here are the honest answers.
The Short Version
- PDPA (Act 709) applies to any Malaysian organisation processing personal data in connection with commercial transactions.
- The 2024 Amendment, in force since 1 June 2025, significantly raised the stakes: mandatory DPO appointment, 72-hour breach notification, fines up to RM 1 million.
- If you collect names, phone numbers, email addresses, or any other personal data from customers or employees, you are a data controller under PDPA. Full stop.
- Not knowing the law is not a defence. The Registrar does not accept "we didn't realise we had to comply."
What is PDPA in Malaysia?
The Personal Data Protection Act 2010, also known as Act 709, is the primary federal law governing how Malaysian organisations collect, use, disclose, store, and dispose of personal data.
It was enacted to give individuals control over their personal information and to create accountability for organisations that handle it. Before PDPA, there was no single comprehensive law on this in Malaysia. Companies could essentially do what they liked with customer data.
Under PDPA, an organisation that collects and uses personal data is called a data user (or data controller). The individual whose data is being processed is the data subject.
Key Definition
"Personal data" under PDPA means any information that directly or indirectly identifies a living individual. This includes names, IC numbers, phone numbers, email addresses, photos, location data, financial records, and health information.
Who Has to Comply With PDPA?
If your organisation processes personal data in Malaysia in connection with a commercial transaction, PDPA applies to you.
That covers a very wide range of businesses: retailers, banks, insurers, clinics, schools, law firms, recruitment agencies, property agents, e-commerce platforms, HR departments, marketing teams. Essentially, if you have a customer database or an employee database, you are a data user under the Act.
There are some exemptions. Personal data processed by the federal or state government is not covered by PDPA. Data processed purely for personal or household purposes is also exempt. But any commercial activity involving personal data falls squarely within the Act.
One question that comes up often: does PDPA apply to SMEs? Yes. The Act does not have a size threshold for basic compliance obligations. If you are running a small recruitment firm with 50 candidate profiles, those 50 people have rights under PDPA. The DPO appointment threshold (20,000 records) is a separate question — we cover that below.
What Changed With the 2024 Amendment?
The Personal Data Protection (Amendment) Act 2024 came into force on 1 June 2025. It was the most significant update to Malaysia's data protection framework since the original Act was passed in 2010.
The key changes:
Mandatory DPO appointment. Organisations that process personal data of 20,000 or more individuals, or sensitive personal data of 10,000 or more individuals, must appoint a Data Protection Officer. This can be an internal staff member or an outsourced DPO (DPOaaS).
Mandatory breach notification. If a data breach occurs, the affected organisation must notify the Personal Data Protection Commissioner within 72 hours of becoming aware of it. Affected individuals must also be notified without undue delay.
Higher penalties. The maximum fine was increased to RM 1 million per offence. Directors, managers, and senior officers of the organisation can also be held personally liable.
Expanded definition of sensitive data. The amendment broadened the categories of sensitive personal data that attract stricter processing requirements.
The 72-Hour Rule
Under the PDPA 2024 Amendment, once an organisation discovers a data breach, it has 72 hours to notify the Personal Data Protection Commissioner. This is not a working-hours window. It starts from the moment you become aware. Organisations without an incident response plan will not meet this deadline.
What Are the 7 Principles of PDPA Malaysia?
PDPA is built around seven data protection principles. Every organisation processing personal data in Malaysia is legally obligated to comply with all seven.
1. General Principle. Personal data must not be processed unless specific conditions are met — primarily that the data subject has given consent, or that processing is necessary for a contract, legal obligation, or legitimate interest.
2. Notice and Choice Principle. Data subjects must be informed, at the point of collection, of what data is being collected, why it is being collected, who it may be shared with, and their right to access and correct their data.
3. Disclosure Principle. Personal data must not be disclosed to third parties without consent, except in limited circumstances specified in the Act.
4. Security Principle. Organisations must implement practical security measures to protect personal data from loss, misuse, modification, unauthorised disclosure, and access.
5. Retention Principle. Personal data must not be kept longer than necessary for the purpose for which it was collected.
6. Data Integrity Principle. Organisations must take reasonable steps to ensure personal data is accurate, complete, not misleading, and kept up to date.
7. Access Principle. Data subjects have the right to access their personal data held by an organisation, and to request corrections if the data is inaccurate.
What Happens If I Don't Comply?
The honest answer is: the consequences are real and getting more serious.
Under the original 2010 Act, enforcement was relatively limited. The 2024 Amendment changed that. Fines now go up to RM 1 million per offence. Individuals within an organisation, including directors and senior managers, can be personally convicted and imprisoned for up to 3 years for certain violations.
Beyond regulatory penalties, there are reputational and commercial consequences. A publicised data breach or a complaint upheld by the Commissioner is damaging to customer trust. In industries like finance, healthcare, and insurance, it can also trigger regulatory consequences from sectoral regulators like BNM or MOH.
The Malaysian Personal Data Protection Department (JPDP) has become more active in investigations following the 2024 Amendment. The assumption that "nothing has happened so far" is not a compliance strategy.
Do I Need a DPO?
Under the PDPA 2024 Amendment, DPO appointment is mandatory if your organisation processes personal data of 20,000 or more individuals, or sensitive personal data of 10,000 or more individuals.
If you are below those thresholds, you are not legally required to appoint a DPO — but it is still strongly advisable. The DPO appointment threshold relates to a specific legal obligation. The security principle, the breach notification requirement, and all other PDPA obligations still apply regardless of your size.
For organisations that meet the threshold, the DPO can be an internal staff member or an outsourced Data Protection Officer (DPOaaS). Outsourcing is common among SMEs and mid-sized organisations that do not have the internal capacity to run a full DPO function.
We have a separate article covering DPO appointment in detail if you want the full picture.
Is There PDPA Training Available in Malaysia?
Yes. PDPA compliance training is available as both public and in-house programmes across Malaysia.
OrbixTech offers several options depending on your organisation's needs:
- PDPA Awareness Training — for all staff, covering the basics of personal data protection and employee responsibilities under the Act
- DPO Foundations Programme — for those being appointed as DPO or supporting a DPO function
- DPO Advanced Certification — for experienced DPOs managing full compliance programmes
- PDPA & DPO Combined Programme — a comprehensive track covering both the legal framework and the DPO role
All programmes are HRD Corp SBL-Khas claimable, which means if your organisation is registered with HRD Corp (PSMB), you can offset the training cost against your levy.
Programmes are delivered in English and Bahasa Malaysia, either in-house at your premises or online.
Where Do I Start?
The simplest starting point is a data inventory. Write down every type of personal data your organisation collects, where it is stored, who has access to it, how long you keep it, and whether you have a legitimate basis for processing it. That exercise will tell you more about your compliance gaps than any checklist.
From there, the priorities are typically:
- Make sure you have a current Privacy Notice that is actually being shown to data subjects at the point of collection
- Implement a data breach response procedure so you can meet the 72-hour notification requirement if something goes wrong
- Train staff who handle personal data — most PDPA breaches are caused by employee error, not external attacks
- If you meet the DPO threshold, appoint one
If you are not sure where your organisation stands, the most useful next step is a conversation with someone who does this every day.