Home / Doing Business in Malaysia / Business / Digital compliance

🧭 Practical ✓ Published: 22 Jul 2026 6 min read Next review 22 Jul 2027

Data Breach Notification in Malaysia: The 72-Hour Rule

Section 12B says as soon as practicable; the 72 hours everyone quotes is in the guideline. Here is when the clock starts, what significant harm means, and why the 1,000-subject test does not decide whether you must tell the customers.

30-second answer Reviewed 22 Jul 2026

Since 1 June 2025, s.12B of the Personal Data Protection Act 2010 requires a data controller to notify the Commissioner of a personal data breach as soon as practicable. The Data Breach Notification Guideline sets that at no later than 72 hours from the occurrence of the breach where the breach causes or is likely to cause significant harm. Affected data subjects must be notified within 7 days of that notification. Failure to notify the Commissioner is RM250,000 or 2 years.

  • Section 12B commenced 1 June 2025; the 72-hour figure is in guideline paragraph 6.1, not in the Act
  • The statutory standard in s.12B(1) is as soon as practicable — 72 hours is the outer limit
  • Notification is required only where the breach causes or is likely to cause significant harm
  • Significant scale means more than 1,000 affected data subjects — one of five significant-harm limbs
  • Paragraph 8.2: the 1,000-subject limb does NOT apply to data-subject notification
  • Data subjects must be told within 7 days of the notification to the Commissioner
  • Missing 72 hours does not end the duty — paragraph 7.7 requires a written explanation with evidence

Who this applies to: Every data controller under Act 709, whether or not it belongs to a registrable class or needs a data protection officer.

On this page
Full explanation ≈6 min

The 72 hours is not in the Act.

Section 12B(1) of the Personal Data Protection Act 2010 says a data controller with reason to believe a personal data breach has occurred shall notify the Commissioner as soon as practicable, in the manner and form the Commissioner determines. That is the whole of the statutory deadline. The 72 hours comes from paragraph 6.1 of the Personal Data Protection Guideline: Data Breach Notification, Version 1.0, issued 25 February 2025 under s.48(g).

Knowing where the number lives matters. It tells you the statutory standard you will be judged against is “as soon as practicable” — 72 hours is the Commissioner’s outer limit, not a licence to use all of it.

Which breaches have to be reported?

Section 12B commenced 1 June 2025, inserted by s.6 of Act A1727 and appointed by P.U.(B) 522/2024. It binds every data controller, regardless of whether you fall in a registrable class or need a data protection officer.

Paragraph 5.1 is blunt: not every breach is notifiable. The gate is significant harm, and paragraph 5.2 defines it as a risk that the compromised data:

  1. may result in physical harm, financial loss, a negative effect on credit records, or damage to or loss of property;
  2. may be misused for illegal purposes;
  3. consists of sensitive personal data;
  4. consists of personal data which, combined with other information, could enable identity fraud; or
  5. is of significant scale — which paragraph 5.3 fixes at more than 1,000 affected data subjects.

The guideline’s worked examples do useful work here. Unauthorised access to patient medical records is notifiable regardless of numbers, because medical data is sensitive personal data. An account statement emailed to the wrong recipient is notifiable, because it involves financial information. Theft of an encrypted laptop holding the email addresses of 200 employees is not notifiable — encryption plus low-sensitivity data means no significant harm.

When does the clock start?

Paragraph 6.1 sets the deadline at no later than 72 hours from the occurrence of the personal data breach. Paragraph 6.2 then supplies the practical rule: on learning of a security incident you run a preliminary investigation to establish whether a breach has in fact occurred.

The examples fix the start point by scenario:

ScenarioClock starts
Lost USB key with unencrypted personal dataAs soon as you are informed of the loss
Personal data sent without authorisationAs soon as you realise the mistake
Suspected network compromiseWhen inspection confirms the system was compromised
RansomwareWhen you realise you have lost access, or confirm the breach after the attacker tells you
Breach at your data processorWhen the processor notifies you, or you obtain clear evidence — whichever is earlier

That last line is the one to put in your vendor contracts. Your 72 hours can start running on your processor’s knowledge, not yours.

How do you notify, and what goes in?

Paragraph 7.1 gives three channels: the form on pdp.gov.my, or the Annex B form emailed to dbnpdp@pdp.gov.my, or a hard copy to the Commissioner.

Paragraph 7.3 adds a trap worth flagging — the Commissioner issues a confirmation notice, and the notification is not considered submitted without it. Sending the form is not the same as having notified.

Beyond the mandatory fields, paragraph 7.4 requires the detection date and time, the type of data and nature of the breach, the detection method and suspected cause, the number of affected data subjects and estimated affected records, the system involved, the potential consequences, the chronology, the remedial and mitigation measures taken or planned, the measures for affected data subjects, and the contact details of the DPO or other contact person.

If you cannot supply all of it in time, paragraph 7.5 lets you file in phases — but no later than 30 days from the initial notification. Where a breach touches more than one data controller, paragraph 7.6 requires each to file separately.

Miss the 72 hours and paragraph 7.7 requires a written notice of the reasons with supporting evidence: incident timeline, internal communications, technical or external factors, all submitted with the notification.

When must you tell the customers?

Section 12B(2) requires notification to the data subject where the breach causes or is likely to cause significant harm to them, without unnecessary delay. Paragraph 9.1 sets that at not later than 7 days after the initial notification to the Commissioner.

Then comes the provision almost every summary omits.

Paragraph 8.2: the significant scale criterion in paragraph 5.3 does not apply when determining whether notification to affected data subjects is required.

So the 1,000-subject limb is a one-way door. It can make a breach notifiable to the Commissioner, but it can never, by itself, make the breach notifiable to the individuals. A leak of 50,000 records containing nothing but low-sensitivity data goes to Putrajaya and stops there. Assess the individuals’ position on the other four limbs.

The guideline’s illustrations confirm the direction. Theft of customer names, account numbers and passwords from a financial institution: notify the data subjects, because financial loss is likely and identity fraud is enabled. A server compromised but the data rendered unintelligible by two layers of security: do not notify the data subjects, but do notify the Commissioner. A direct seller’s server seized by a ransomware operator with no backups: notify the data subjects.

Paragraph 10.1 requires notification to be direct and individual, in intelligible language, so the data subject can take protective steps.

Common mistakes

Reporting everything. Paragraph 5.1 does not want that. A breach with no realistic path to significant harm is not notifiable, and reflex over-reporting buries the incidents that matter.

Treating 72 hours as the standard. The statute says as soon as practicable. If you knew on day one and filed on day three with no reason for the delay, the guideline’s outer limit is not a defence to s.12B(1).

Assuming volume forces customer notification. Paragraph 8.2 says the opposite. Assess the four qualitative limbs separately for the individuals.

Waiting to complete the investigation. Notify, then use the 30-day phased-submission route in paragraph 7.5.

Assuming the processor’s clock is yours. It starts at the earlier of the processor telling you and you finding out. If your vendor contract gives the processor 72 hours to tell you, you have already lost your own window.

Filing and forgetting. No confirmation notice from the Commissioner means no notification, under paragraph 7.3.

What’s next

Write the playbook before you need it: who runs the preliminary investigation, who signs off the significant-harm assessment against the five limbs, who files, and who drafts the individual notices. Amend your data processing agreements so processors must notify you within hours, not days.

Then read s.12A alongside it. Where a DPO is mandatory, paragraph 7.8 makes that officer the Commissioner’s main point of contact for the breach; where it is not, you must still name a representative with sufficient seniority and expertise.

Frequently asked 6
When exactly does the 72-hour clock start?

From the occurrence of the breach, but paragraph 6.2 makes clear you first run a preliminary investigation to determine whether a breach actually occurred. The examples set the practical start points: for a lost unencrypted USB key, when you are informed of the loss; for a misdirected disclosure, when you realise the mistake; for a suspected network compromise, when your inspection confirms the system was compromised; for ransomware, when you realise you have lost access or confirm the breach after being told by the attacker; and where a data processor is involved, when the processor notifies you or you obtain clear evidence yourself, whichever is earlier.

Do I have to notify every breach?

No. Paragraph 5.1 is explicit that not all personal data breaches are notifiable. The test is whether the breach causes or is likely to cause significant harm. The guideline's own example of a non-notifiable breach is the theft of an encrypted laptop containing the email addresses of 200 employees — not likely to result in significant harm.

What counts as significant harm?

Paragraph 5.2 lists five limbs. Compromised data that may result in physical harm, financial loss, a negative effect on credit records or damage to or loss of property; that may be misused for illegal purposes; that consists of sensitive personal data; that combined with other information could enable identity fraud; or that is of significant scale. Paragraph 5.3 defines significant scale as more than 1,000 affected data subjects.

If more than 1,000 people are affected, do I have to tell them all?

Not automatically, and this is the point most summaries get wrong. Paragraph 8.2 applies the paragraph 5.2 definition of significant harm to data-subject notification but states expressly that the significant scale criterion in paragraph 5.3 does not apply when determining whether notification to affected data subjects is required. A breach that is notifiable to the Commissioner purely on volume is not, on that basis alone, notifiable to the individuals.

What if I cannot gather all the information within 72 hours?

Notify anyway. Paragraph 7.5 allows the information required by paragraph 7.4 to be supplied in phases, as soon as practicable and no later than 30 days from the date of the initial notification. What you cannot do is delay the notification itself while you investigate.

What happens if I miss the 72 hours?

Paragraph 7.7 requires a written notice to the Commissioner setting out the reasons for the delay with supporting evidence — the incident timeline, internal communications and any technical or external factors — submitted together with the notification. The duty does not lapse; it becomes a late notification with an explanation attached.

Sources & history 4 sources
⚑ Awaiting expert verification

The following are deliberately unstated or described only qualitatively until confirmed by a subject-matter expert:

  • Whether JPDP has published any enforcement outcome or compound under s.12B(3) since 1 June 2025
  • Whether the online notification form on pdp.gov.my imposes any mandatory field beyond those listed at paragraph 7.4 of the guideline

Sources

  1. Personal Data Protection Guideline — Data Breach Notification, Version 1.0 — Personal Data Protection Commissioner Malaysia
  2. Personal Data Protection (Amendment) Act 2024 [Act A1727] — Attorney General's Chambers
  3. Personal Data Protection (Amendment) Act 2024 — Appointment of Date of Coming into Operation [P.U. (B) 522/2024] — Attorney General's Chambers
  4. Guidelines and Circulars on Data Breach Notification (DBN) — Personal Data Protection Commissioner Malaysia

Change history

Version Date Change By
01.00 20 Jul 2026 Approved and published.
More in Digital compliance View all 6 →
Related knowledge