# PDPA Compliance in Malaysia After the 2024 Amendment

> What the Personal Data Protection (Amendment) Act 2024 changed, the exact date each part commenced, and the duties that now bind every Malaysian business handling personal data.

- Category: business
- Language: en
- Status: published
- Updated: 2026-08-14
- Canonical: https://negaraku.md/en/business/pdpa-compliance-malaysia

---

If your privacy notice still says “data user”, it is describing a category of person that stopped existing on 1 April 2025.

That is not a cosmetic point. Section 2 of the Personal Data Protection (Amendment) Act 2024 substituted “data controller” for “data user” everywhere the phrase appears in Act 709, including in the shoulder notes. Alongside it came a tripled headline penalty, a new class of directly liable defendant, and — from 1 June 2025 — two obligations with hard deadlines that did not exist in Malaysian law before.

Most compliance material still on the internet was written against the 2010 Act. This page is written against the Act as amended.

## What did the 2024 amendment actually change?

The amending Act is **A1727**, not A1717. That transposition appears often enough in circulated summaries to be worth stating: Act A1717 is a different statute. A1727 received Royal Assent on 9 October 2024 and was gazetted on 17 October 2024.

It did not commence as a block. Section 1(2) let the Minister appoint different dates for different provisions, and **P.U.(B) 522/2024**, dated 19 December 2024 and gazetted 24 December 2024, did exactly that.

| Commencement | A1727 sections | What actually changed |
| --- | --- | --- |
| **1 January 2025** | 7, 11, 13, 14 | Housekeeping — national-language text of s.16(3), s.67 accounts, electronic service under s.136(1), and the saving provision |
| **1 April 2025** | 2, 3, 4, 5, 8, 10, 12 | Data user becomes data controller; biometric data added to sensitive personal data; “personal data breach” defined; deceased individuals excluded; processors bound by the Security Principle; penalty raised to RM1m; s.129 whitelist deleted |
| **1 June 2025** | 6, 9 | New Division 1a — s.12A data protection officer and s.12B breach notification — plus new s.43A, the right to data portability |

Three changes from the April tranche do real work.

**Biometric data is now sensitive personal data.** Section 3(b) inserted a definition — personal data resulting from technical processing relating to the physical, physiological or behavioural characteristics of a person — and s.3(c) slotted it into the definition of sensitive personal data. If you run fingerprint or facial-recognition attendance, you moved into the s.40 consent regime overnight.

**A deceased individual is no longer a data subject.** Section 3(f) says so expressly. Estate and legacy records fall outside Act 709.

**The maximum penalty for breaching a principle tripled.** Section 4(b)(ii) replaced “three hundred thousand ringgit or … two years” with **one million ringgit or … three years**.

## Who does the Act bind in the first place?

Before any of this matters, check that Act 709 reaches you at all — because its scope is narrower than most people assume in one direction and wider in another.

Section 2(1) applies the Act to any person who processes, or who has control over or authorises the processing of, personal data **in respect of commercial transactions**. The commercial-transaction limit runs through the definition of personal data in s.4 as well. Purely personal or household record-keeping is outside.

Section 2(2) then sets the territorial hook. The Act binds a person **established in Malaysia**, whether or not the processing happens in the context of that establishment; and a person **not established in Malaysia who uses equipment in Malaysia** for processing, other than for mere transit. Section 2(3) requires that second category to nominate a representative established in Malaysia.

Section 2(4) defines establishment generously: an individual physically present in Malaysia for at least **180 days** in a calendar year; a body incorporated under the Companies Act; a partnership or unincorporated association formed under Malaysian written law; or anyone maintaining an office, branch or agency here, or a regular practice.

Two exclusions in s.3 are worth knowing. The Act **does not apply to the Federal Government or State Governments** — a gap the amendment did not close. And it does not apply to personal data processed outside Malaysia unless that data is intended to be **further processed in Malaysia**.

Note that nothing in this turns on size. There is no de minimis, no revenue floor and no headcount test anywhere in Act 709.

## Are you a data controller or a data processor?

Before April 2025 this was largely a drafting question for your vendor contracts. It is now a question of who goes on the charge sheet.

A **data controller** determines the purposes and means of processing. A **data processor** processes personal data only on behalf of a controller and does not process it for its own purposes.

Section 4 of A1727 inserted a new s.5(1A): where processing is carried out by a data processor on behalf of a data controller, **the data processor shall comply with the Security Principle**. Section 5 of A1727 then rewrote s.9 itself so that the duty to take practical steps runs to “a data controller and a data processor”, and moved the vendor-guarantee obligation in s.9(2) onto the processor.

The practical effect: a Malaysian payroll bureau, hosting provider or outsourced contact centre that loses client data can now be prosecuted directly, at RM1,000,000 or three years, without the client having to be joined. Processors that priced their services on the old assumption of purely contractual exposure repriced through 2025.

One thing that did **not** change: s.12A(2) requires a data processor to appoint its own data protection officer, but the registration duty in the guideline is expressed as a duty of the **data controller**. Processors appoint; controllers register.

## What are the seven personal data protection principles?

Section 5(1) of Act 709 lists them, and A1727 left the list and the numbering alone.

| Principle | Section | The obligation in one line |
| --- | --- | --- |
| General | 6 | No processing without consent, and no processing of sensitive personal data except under s.40 |
| Notice and Choice | 7 | Written notice, in national language and English, of what you collect and why |
| Disclosure | 8 | No disclosure outside the stated purpose or class of third parties without consent |
| Security | 9 | Practical steps against loss, misuse, unauthorised access, alteration or destruction |
| Retention | 10 | Do not keep longer than necessary; destroy or permanently delete when done |
| Data Integrity | 11 | Accurate, complete, not misleading, up to date |
| Access | 12 | The data subject gets access and correction rights |

Contravention of any of them is an offence under s.5(2) — RM1,000,000 or three years or both, since 1 April 2025.

The Retention Principle is the one most Malaysian businesses fail on and the one JPDP can prove without a complaint: an inbox of a decade of customer NRIC scans is a s.10 contravention on its face.

## Do you have to register with JPDP?

Only if you fall within a class specified under s.14. There are **13 classes**, set by the Personal Data Protection (Class of Data Users) Order 2013, P.U.(A) 336/2013, as amended by P.U.(A) 326/2016 which added pawnbrokers and moneylenders.

If you are in a class and you process personal data without a certificate of registration, that is **RM500,000 or three years or both** under s.16(4). Registration fees run from RM100 for a sole proprietor to RM400 for a public company, under P.U.(A) 337/2013, and a data controller belonging to two or more classes must register separately for each.

If you are not in a class, you register nothing — but you are still bound by every principle, by s.12A and by s.12B. That last point is where most of the market gets it wrong; see the mistakes section below.

## Who needs a data protection officer?

Section 12A commenced 1 June 2025. The conditions sit in the Commissioner's guideline of 25 February 2025, at paragraph 4.2, and they are **disjunctive** — any one triggers the duty:

- personal data exceeding **20,000 data subjects**; or
- sensitive personal data including financial information exceeding **10,000 data subjects**; or
- activities that require **regular and systematic monitoring** of personal data.

There is no revenue test, no headcount test, and — critically — **no volume floor on the third limb**. The guideline's own worked example of regular and systematic monitoring is a retail website that uses algorithms to monitor searches and purchases and offers recommendations. That describes a large share of Malaysian e-commerce.

Appointment must be registered with the Commissioner through SPDP at daftar.pdp.gov.my **within 21 days** of appointment, and changes updated within 14 days.

## When must you notify a data breach?

Section 12B(1) says “as soon as practicable”. The **72 hours** everyone quotes is not in the Act — it is paragraph 6.1 of the Data Breach Notification Guideline. The trigger is that the breach causes or is likely to cause **significant harm**, defined at paragraph 5.2, which includes any breach affecting more than 1,000 data subjects.

Affected data subjects must be told within **7 days** of the notification to the Commissioner. Failure to notify the Commissioner is RM250,000 or two years under s.12B(3).

## Can you still send personal data overseas?

Yes, and the route changed on 1 April 2025.

The old s.129(1) prohibited transfer outside Malaysia except to a place the Minister gazetted on the Commissioner's recommendation. A full whitelist was never gazetted, which made the section close to unworkable and widely disregarded.

Section 12 of A1727 **deleted s.129(1) altogether**, and rewrote s.129(2) so that it now reads as a permission: a data controller may transfer personal data to a place outside Malaysia if there is in force in that place a law **substantially similar** to Act 709, or that place **ensures an adequate level of protection** at least equivalent to Act 709. The words “or that serves the same purposes as this Act” were struck out of limb (a).

This is a self-assessment — there is no application and no approval — but it is not unguided. On **29 April 2025** the Commissioner launched the **Cross Border Personal Data Transfer Guidelines** (GP_CBPDT), which set criteria for both limbs. To rely on either the *substantially similar law* or the *adequate level of protection* test, a data controller must run a **Transfer Impact Assessment (TIA)** weighing enumerated factors — comparable data-subject rights in the destination, and recipient security measures aligned to the Security Principle and the Personal Data Protection Standards — with each TIA valid for **no longer than three years**. The separate grounds in s.129(3) survive, including consent, contract necessity and legal proceedings, and the guideline explains them too; only paragraph (h), transfers the Minister deemed to be in the public interest, was deleted along with the ministerial machinery in s.129(4).

## What is the new right to data portability?

Section 9 of A1727 inserted **s.43A** with effect from 1 June 2025, and it is the change most commentary missed entirely while everyone looked at the DPO and breach provisions.

Section 43A(1) lets a data subject request the data controller to transmit his personal data **directly to another data controller of his choice**, by notice in writing given by electronic means. Section 43A(2) subjects that to **technical feasibility and compatibility of the data format** — a meaningful limit, and the one most controllers will rely on. Section 43A(3) requires transmission to be completed “within the period as may be prescribed”.

No period has been prescribed. The right is in force with no clock attached to it, which means a controller cannot currently be late, but also cannot refuse outright on timing grounds. Build the export capability now rather than after a period is gazetted.

The same amendment threaded portability into the machinery: s.3(e) of A1727 widened the definition of “requestor” in s.4 to include a person making a **data portability request**, so the existing requestor provisions carry across.

## What are the penalties?

| Contravention | Provision | Maximum |
| --- | --- | --- |
| Breach of a personal data protection principle | s.5(2) | RM1,000,000 / 3 years |
| Breach of the Security Principle by a data processor | s.5(1A) with s.5(2) | RM1,000,000 / 3 years |
| Processing without registration when in a registrable class | s.16(4) | RM500,000 / 3 years |
| Continuing to process after a certificate expires | P.U.(A) 337/2013 reg.5(2) | RM250,000 / 2 years |
| Failure to notify the Commissioner of a breach | s.12B(3) | RM250,000 / 2 years |

## Common mistakes

**Assuming registration status decides everything.** It does not. Sections 12A and 12B bind **every data controller**, whether or not you appear in any of the 13 classes. A Sdn Bhd running a subscription app registers nothing and still owes a DPO and a 72-hour clock.

**Treating the 72-hour figure as statutory.** It sits in a guideline issued under s.48(g), not in s.12B. That matters if you are arguing about it: the statutory standard is “as soon as practicable”, and the guideline explains what the Commissioner will treat as meeting it.

**Citing A1717.** The amending Act is A1727. Verify the number before you cite it in a board paper.

**Leaving “data user” in the privacy notice.** Cosmetic on its own, but it is a reliable signal that the notice has not been reviewed since 2024 — and the s.7 Notice and Choice Principle requires the notice to be accurate.

**Believing the whitelist still governs cross-border transfer.** A surprising amount of 2023-vintage guidance still tells readers to check a gazetted list of approved countries. That mechanism was deleted. Assess the destination yourself and document the assessment — the Cross Border Personal Data Transfer Guidelines expect a Transfer Impact Assessment, refreshed at least every three years.

**Assuming your cloud vendor's DPA discharges you.** Section 12A(4) is explicit: appointing a DPO does not discharge the controller or processor from any duty under the Act. The same logic runs through the Security Principle — you remain liable for your own processing.

## What's next

Work through it in this order. Decide whether you are a controller, a processor, or both for different data sets. Test yourself against the three DPO limbs, paying attention to the third one. Check whether any of the 13 registration classes reaches you. Then write the breach playbook — because 72 hours is not long enough to design a process from scratch while the incident is running.

Three of the four subject-specific guidelines JPDP had signalled are now live: on **30 April 2026** the Commissioner launched the **Data Protection Impact Assessment**, **Data Protection by Design**, and **Automated Decision-Making and Profiling** guidelines. Only the **data portability** guideline is still outstanding, remaining a consultation paper (PCP 03/2024). The s.43A portability right itself has been in force since 1 June 2025 but no transmission period has been prescribed, so it is currently a right with no clock. Watch, too, for the outcome of Public Consultation Paper 4/2025 on amendments to the Personal Data Protection Regulations 2013, which was still at consultation as at August 2026.

## Sources

- Personal Data Protection (Amendment) Act 2024 [Act A1727] — https://lom.agc.gov.my/ilims/upload/portal/akta/outputaktap/2430673_BI/Act%20A1727.pdf (Attorney General's Chambers)
- Personal Data Protection (Amendment) Act 2024 — Appointment of Date of Coming into Operation [P.U. (B) 522/2024] — https://lom.agc.gov.my/ilims/upload/portal/akta/outputp/2587515/PUB%20522_2024.pdf (Attorney General's Chambers)
- Personal Data Protection Act 2010 [Act 709] — Reprint 2023 — https://lom.agc.gov.my/ilims/upload/portal/akta/outputaktap/1726091_BI/ACT%20709-REPRINT%202023.pdf (Attorney General's Chambers)
- Personal Data Protection Guideline — Appointment of Data Protection Officer, Version 1.0 — https://www.pdp.gov.my/ppdpv1/wp-content/uploads/2025/08/GP_DPO_ENG.pdf (Personal Data Protection Commissioner Malaysia)
- Personal Data Protection Guideline — Data Breach Notification, Version 1.0 — https://www.pdp.gov.my/ppdpv1/wp-content/uploads/2025/08/GP_DBN_ENG.pdf (Personal Data Protection Commissioner Malaysia)
- Personal Data Protection (Class of Data Users) Order 2013 [P.U. (A) 336/2013] — https://lom.agc.gov.my/ilims/upload/portal/akta/outputp/pua_20131114_P.U.%20(A)%20336-PERINTAH%20PERLINDUNGAN%20DATA%20PERIBADI%20(GOLONGAN%20PENGGUNA%20DATA)%202013.pdf (Attorney General's Chambers)
- Personal Data Protection (Registration of Data User) Regulations 2013 [P.U. (A) 337/2013] — https://lom.agc.gov.my/ilims/upload/portal/akta/outputp/pua_20131114_P.U.%20(A)%20337.pdf (Attorney General's Chambers)
- Cross Border Personal Data Transfer Guideline [GP_CBPDT_EN] — https://www.pdp.gov.my/ppdpv1/wp-content/uploads/2025/08/GP_CBPDT_EN-1.pdf (Personal Data Protection Commissioner Malaysia)
- Data Protection Impact Assessment Guideline (DPIA) — https://www.pdp.gov.my/ppdpv1/wp-content/uploads/2026/04/Data-Protection-Impact-Assessment-Guideline-DPIA.pdf (Personal Data Protection Commissioner Malaysia)
- Data Protection By Design Guideline (DpbD) — https://www.pdp.gov.my/ppdpv1/wp-content/uploads/2026/04/Data-Protection-By-Design-Guideline-DpbD.pdf (Personal Data Protection Commissioner Malaysia)
- PDP Commissioner launches Guidelines on Data Protection Impact Assessment, Automated Decision-Making and Profiling, and Data Protection by Design — https://www.allenandgledhill.com/perspectives/publications/bulletins-malaysia/2026/pdp-commissioner-launches-guidelines-on-data-protection-impact-assessment-automated-decision-making-and-profiling-and-data-protection-by-design/ (Allen & Gledhill)
- AKTA 709 — Guidelines, Orders and Public Consultation Papers listing — https://www.pdp.gov.my/ppdpv1/en/akta709/ (Personal Data Protection Commissioner Malaysia)
- Personal Data Protection Regulations 2013 [P.U. (A) 335/2013] — https://www.pdp.gov.my/ppdpv1/en/akta/personal-data-protection-regulations-2013/ (Personal Data Protection Commissioner Malaysia)

---
Source of truth: https://github.com/negaraku-md/NegaraKu.md
License: CC BY-SA 4.0
