# Data Breach Notification in Malaysia: The 72-Hour Rule

> Section 12B says as soon as practicable; the 72 hours everyone quotes is in the guideline. Here is when the clock starts, what significant harm means, and why the 1,000-subject test does not decide whether you must tell the customers.

- Category: business
- Language: en
- Status: published
- Updated: 2026-07-20
- Canonical: https://negaraku.md/en/business/data-breach-notification-malaysia

---

The 72 hours is not in the Act.

Section 12B(1) of the Personal Data Protection Act 2010 says a data controller with reason to believe a personal data breach has occurred shall notify the Commissioner **as soon as practicable**, in the manner and form the Commissioner determines. That is the whole of the statutory deadline. The 72 hours comes from paragraph 6.1 of the *Personal Data Protection Guideline: Data Breach Notification*, Version 1.0, issued 25 February 2025 under s.48(g).

Knowing where the number lives matters. It tells you the statutory standard you will be judged against is “as soon as practicable” — 72 hours is the Commissioner's outer limit, not a licence to use all of it.

## Which breaches have to be reported?

Section 12B commenced **1 June 2025**, inserted by s.6 of Act A1727 and appointed by P.U.(B) 522/2024. It binds every data controller, regardless of whether you fall in a registrable class or need a data protection officer.

Paragraph 5.1 is blunt: not every breach is notifiable. The gate is **significant harm**, and paragraph 5.2 defines it as a risk that the compromised data:

1. may result in physical harm, financial loss, a negative effect on credit records, or damage to or loss of property;
2. may be misused for illegal purposes;
3. consists of **sensitive personal data**;
4. consists of personal data which, combined with other information, could enable **identity fraud**; or
5. is of **significant scale** — which paragraph 5.3 fixes at **more than 1,000 affected data subjects**.

The guideline's worked examples do useful work here. Unauthorised access to patient medical records is notifiable **regardless of numbers**, because medical data is sensitive personal data. An account statement emailed to the wrong recipient is notifiable, because it involves financial information. Theft of an **encrypted** laptop holding the email addresses of 200 employees is **not** notifiable — encryption plus low-sensitivity data means no significant harm.

## When does the clock start?

Paragraph 6.1 sets the deadline at no later than 72 hours **from the occurrence of the personal data breach**. Paragraph 6.2 then supplies the practical rule: on learning of a security incident you run a preliminary investigation to establish whether a breach has in fact occurred.

The examples fix the start point by scenario:

| Scenario | Clock starts |
| --- | --- |
| Lost USB key with unencrypted personal data | As soon as you are informed of the loss |
| Personal data sent without authorisation | As soon as you realise the mistake |
| Suspected network compromise | When inspection confirms the system was compromised |
| Ransomware | When you realise you have lost access, or confirm the breach after the attacker tells you |
| Breach at your data processor | When the processor notifies you, or you obtain clear evidence — **whichever is earlier** |

That last line is the one to put in your vendor contracts. Your 72 hours can start running on your processor's knowledge, not yours.

## How do you notify, and what goes in?

Paragraph 7.1 gives three channels: the form on pdp.gov.my, or the Annex B form emailed to dbnpdp@pdp.gov.my, or a hard copy to the Commissioner.

Paragraph 7.3 adds a trap worth flagging — **the Commissioner issues a confirmation notice, and the notification is not considered submitted without it.** Sending the form is not the same as having notified.

Beyond the mandatory fields, paragraph 7.4 requires the detection date and time, the type of data and nature of the breach, the detection method and suspected cause, the number of affected data subjects and estimated affected records, the system involved, the potential consequences, the chronology, the remedial and mitigation measures taken or planned, the measures for affected data subjects, and the contact details of the DPO or other contact person.

If you cannot supply all of it in time, paragraph 7.5 lets you file in phases — but no later than **30 days** from the initial notification. Where a breach touches more than one data controller, paragraph 7.6 requires each to file separately.

Miss the 72 hours and paragraph 7.7 requires a written notice of the reasons with supporting evidence: incident timeline, internal communications, technical or external factors, all submitted with the notification.

## When must you tell the customers?

Section 12B(2) requires notification to the data subject where the breach causes or is likely to cause significant harm to them, without unnecessary delay. Paragraph 9.1 sets that at **not later than 7 days** after the initial notification to the Commissioner.

Then comes the provision almost every summary omits.

**Paragraph 8.2: the significant scale criterion in paragraph 5.3 does not apply when determining whether notification to affected data subjects is required.**

So the 1,000-subject limb is a one-way door. It can make a breach notifiable to the Commissioner, but it can never, by itself, make the breach notifiable to the individuals. A leak of 50,000 records containing nothing but low-sensitivity data goes to Putrajaya and stops there. Assess the individuals' position on the other four limbs.

The guideline's illustrations confirm the direction. Theft of customer names, account numbers and passwords from a financial institution: notify the data subjects, because financial loss is likely and identity fraud is enabled. A server compromised but the data rendered unintelligible by two layers of security: **do not** notify the data subjects, but **do** notify the Commissioner. A direct seller's server seized by a ransomware operator with no backups: notify the data subjects.

Paragraph 10.1 requires notification to be **direct and individual**, in intelligible language, so the data subject can take protective steps.

## Common mistakes

**Reporting everything.** Paragraph 5.1 does not want that. A breach with no realistic path to significant harm is not notifiable, and reflex over-reporting buries the incidents that matter.

**Treating 72 hours as the standard.** The statute says as soon as practicable. If you knew on day one and filed on day three with no reason for the delay, the guideline's outer limit is not a defence to s.12B(1).

**Assuming volume forces customer notification.** Paragraph 8.2 says the opposite. Assess the four qualitative limbs separately for the individuals.

**Waiting to complete the investigation.** Notify, then use the 30-day phased-submission route in paragraph 7.5.

**Assuming the processor's clock is yours.** It starts at the earlier of the processor telling you and you finding out. If your vendor contract gives the processor 72 hours to tell you, you have already lost your own window.

**Filing and forgetting.** No confirmation notice from the Commissioner means no notification, under paragraph 7.3.

## What's next

Write the playbook before you need it: who runs the preliminary investigation, who signs off the significant-harm assessment against the five limbs, who files, and who drafts the individual notices. Amend your data processing agreements so processors must notify you within hours, not days.

Then read s.12A alongside it. Where a DPO is mandatory, paragraph 7.8 makes that officer the Commissioner's main point of contact for the breach; where it is not, you must still name a representative with sufficient seniority and expertise.

## Sources

- Personal Data Protection Guideline — Data Breach Notification, Version 1.0 — https://www.pdp.gov.my/ppdpv1/wp-content/uploads/2025/08/GP_DBN_ENG.pdf (Personal Data Protection Commissioner Malaysia)
- Personal Data Protection (Amendment) Act 2024 [Act A1727] — https://lom.agc.gov.my/ilims/upload/portal/akta/outputaktap/2430673_BI/Act%20A1727.pdf (Attorney General's Chambers)
- Personal Data Protection (Amendment) Act 2024 — Appointment of Date of Coming into Operation [P.U. (B) 522/2024] — https://lom.agc.gov.my/ilims/upload/portal/akta/outputp/2587515/PUB%20522_2024.pdf (Attorney General's Chambers)
- Guidelines and Circulars on Data Breach Notification (DBN) — https://www.pdp.gov.my/ppdpv1/en/guidelines-and-circulars-on-data-breach-notification-dbn/ (Personal Data Protection Commissioner Malaysia)

---
Source of truth: https://github.com/negaraku-md/NegaraKu.md
License: CC BY-SA 4.0
