# Do You Need a Data Protection Officer in Malaysia?

> Section 12A has three disjunctive limbs and the third has no volume floor — the Commissioner's own example of it is a retail website that recommends products.

- Category: business
- Language: en
- Status: published
- Updated: 2026-07-20
- Canonical: https://negaraku.md/en/business/data-protection-officer-malaysia

---

Most Malaysian businesses read the DPO threshold, see “20,000 data subjects”, decide they are nowhere near it, and stop reading. The third limb is one line further down, it has no number in it at all, and the Commissioner's own worked example of it is an online shop that recommends products.

That is the trap. It is not a drafting accident, and it has been live since 1 June 2025.

## What does section 12A actually require?

Section 12A was inserted into the Personal Data Protection Act 2010 by s.6 of Act A1727 and commenced on **1 June 2025** under P.U.(B) 522/2024.

Section 12A(1) requires a **data controller** to appoint one or more data protection officers accountable for compliance with the Act. Section 12A(2) puts the same duty on a **data processor** processing on a controller's behalf. Section 12A(3) requires the controller to notify the Commissioner of the appointment. Section 12A(4) makes clear that appointing one discharges nothing.

The Act itself sets no threshold. The conditions live in the *Personal Data Protection Guideline: Appointment of Data Protection Officer*, Version 1.0, issued 25 February 2025, read with Circular of the Personal Data Protection Commissioner No. 1/2025.

## Who is caught by the threshold?

Paragraph 4.2 sets three conditions. They are joined by **“or”** — any single one triggers the duty.

| Limb | Condition | Volume floor |
| --- | --- | --- |
| 4.2.1 | Personal data exceeding **20,000** data subjects | 20,000 |
| 4.2.2 | Sensitive personal data including financial information exceeding **10,000** data subjects | 10,000 |
| 4.2.3 | Activities requiring **regular and systematic monitoring** of personal data | **none** |

There is no revenue threshold and no employee-count threshold anywhere in the paragraph.

## What counts as regular and systematic monitoring?

Paragraph 4.3 gives examples rather than a definition. Reading them in order:

- Any form of activity where data subjects are **tracked and profiled online or offline for behavioural advertising** is monitoring.
- A **retail website that uses algorithms to monitor the searches and purchases of its users and, based on that information, offers recommendations** to them “would be carrying out regular and systematic monitoring of data subjects”.
- Operating a **telecommunications network**; monitoring **wellness, fitness and health data via wearable devices**; and activities involving **CCTV** or connected devices such as smart cars and home automation systems would all be considered monitoring.
- Managing a **loyalty programme** “may not be considered” monitoring **if** the purpose is strictly to manage accounts and not to monitor purchase behaviour.

Read the second bullet again. It is not an edge case buried in an annex — it is the guideline's headline illustration, and it describes a standard Shopify or WooCommerce storefront with a recommendation widget switched on. Add a Meta or TikTok retargeting pixel and you are squarely inside the first bullet as well.

**Most guides state the DPO threshold as “20,000 data subjects”. That is only the first of three alternatives, and the one least likely to decide the question for a small Malaysian business.**

The loyalty-programme carve-out shows the line the Commissioner is drawing. Processing for **account administration** is not monitoring. Processing to **understand or predict behaviour** is. A points balance is fine; a churn-propensity score is not.

## How do you appoint and register one?

**Qualifications.** Paragraph 5.4 imposes no minimum professional qualification. Paragraph 5.5 requires demonstrable knowledge of Act 709, understanding of the business and its processing operations, understanding of IT and data security, personal integrity, and the ability to build a data protection culture. JPDP issued a separate **DPO Competency Guideline on 1 August 2025**.

**Conflict of interest.** Paragraph 6.2 allows dual-hatting but works through a specific example: a Head of Marketing asked to run a campaign should not take the DPO role, because maximising customer data capture and sales conflicts with the compliance function. Records manager and compliance officer are named as generally safe.

**Structure.** Paragraph 6.3 permits part-time or full-time. Paragraph 6.4 requires a replacement within a reasonable time frame when a DPO leaves, with an interim appointment as soon as possible.

**Registration.** Paragraph 7.1 gives **21 days from the date of appointment** to register the DPO and submit their business contact information. Paragraph 7.2 routes this through the Sistem Perlindungan Data Peribadi at daftar.pdp.gov.my. Paragraph 7.4 requires changes of DPO or contact details to be updated **no later than 14 days** from the effective date of the new appointment.

**Independence and tenure.** Paragraph 12.2 says a DPO shall not be dismissed for performing duties in good faith, unless they have breached the law or been found negligent or guilty of misconduct.

## What does the organisation have to do for the DPO?

Part D of the guideline puts obligations on the appointing business, not only on the officer.

Paragraph 13.1 requires the DPO to be **involved in all matters relating to the protection of personal data in a timely manner** — and paragraph 13.2 pins that to the earliest stage of the data processing lifecycle, from policy formulation through collection, storage and destruction. The illustration is explicit: the DPO should sit in senior management or board meetings, or the relevant working groups, where personal data governance is discussed.

The guideline also requires the business to allocate resources to the role, to publish and communicate the DPO's contact details, and to keep records. A DPO who first hears about a new product two weeks before launch is evidence of a paragraph 13.2 failure by the company, not by the officer.

There is a practical link into breach response as well. Where a DPO is mandatory, paragraph 7.8 of the Data Breach Notification Guideline makes that officer the Commissioner's **main point of contact** for any inquiry about a breach. Where it is not mandatory, the controller must still designate a representative with sufficient seniority and expertise. Either way somebody has to be reachable when the 72-hour clock is running.

## Common mistakes

**Reading the limbs as cumulative.** They are alternatives. You do not need 20,000 data subjects *and* monitoring.

**Assuming volume is the only route in.** Limb 4.2.3 has no number. A business with 800 customers and a recommendation engine is a better candidate than a business with 19,000 customers and a plain order database.

**Treating “sensitive personal data” as medical only.** Section 4 of Act 709 covers physical or mental health, political opinions, religious beliefs, commission or alleged commission of an offence, and — since 1 April 2025 — **biometric data**. Paragraph 4.2.2 adds financial information into the same count. A fintech at 10,001 users is caught.

**Appointing but not registering.** The appointment and the registration are separate acts with a 21-day gap between them. An unregistered DPO does not satisfy s.12A(3).

**Assuming the processor's DPO covers the controller.** Section 12A(1) and 12A(2) create two separate duties. Your vendor appointing a DPO does nothing for you.

**Never writing down a negative decision.** Paragraph 4.5 invites you to record the reasons for concluding you fall outside paragraph 4.2. That file note is cheap now and valuable if JPDP ever asks.

## What's next

Run the three limbs against each processing activity, not against the business as a whole — marketing, HR and customer support can land differently. If any limb is met, appoint, then diarise the 21-day registration through SPDP. If none is met, write the paragraph 4.5 record and re-test whenever you add analytics, advertising or profiling.

Then check the breach-notification duty in s.12B, which commenced the same day and applies whether or not you need a DPO.

## Sources

- Personal Data Protection Guideline — Appointment of Data Protection Officer, Version 1.0 — https://www.pdp.gov.my/ppdpv1/wp-content/uploads/2025/08/GP_DPO_ENG.pdf (Personal Data Protection Commissioner Malaysia)
- Personal Data Protection (Amendment) Act 2024 [Act A1727] — https://lom.agc.gov.my/ilims/upload/portal/akta/outputaktap/2430673_BI/Act%20A1727.pdf (Attorney General's Chambers)
- Personal Data Protection (Amendment) Act 2024 — Appointment of Date of Coming into Operation [P.U. (B) 522/2024] — https://lom.agc.gov.my/ilims/upload/portal/akta/outputp/2587515/PUB%20522_2024.pdf (Attorney General's Chambers)
- Guidelines and Circular on Personal Data Protection — Appointment of Data Protection Officer — https://www.pdp.gov.my/ppdpv1/en/guidelines-and-circular-on-personal-data-protection-appointment-of-data-protection-officer-dpo-and-data-breach-notification/ (Personal Data Protection Commissioner Malaysia)

---
Source of truth: https://github.com/negaraku-md/NegaraKu.md
License: CC BY-SA 4.0
