Home / Doing Business in Malaysia / Business / Digital compliance

🧭 Practical ✓ Published: 14 Aug 2026 12 min read Next review 14 Aug 2027

PDPA Compliance in Malaysia After the 2024 Amendment

What the Personal Data Protection (Amendment) Act 2024 changed, the exact date each part commenced, and the duties that now bind every Malaysian business handling personal data.

30-second answer Reviewed 14 Aug 2026

The Personal Data Protection Act 2010 was rewritten by Act A1727, which commenced in three tranches — 1 January 2025, 1 April 2025 and 1 June 2025. Since 1 April 2025 you are a data controller, not a data user; biometric data is sensitive personal data; and data processors are directly bound by the Security Principle with a RM1,000,000 penalty. Since 1 June 2025 a data protection officer and 72-hour breach notification are live obligations.

  • The amending Act is A1727, gazetted 17 October 2024 — not A1717, which is a different statute entirely
  • P.U.(B) 522/2024 split commencement across 1 January 2025, 1 April 2025 and 1 June 2025
  • Data user became data controller on 1 April 2025 by a general substitution in s.2 of A1727
  • Data processors are now directly liable under the Security Principle, penalty RM1,000,000 or 3 years
  • The s.129 whitelist was deleted — cross-border transfer is now a self-assessment by the controller
  • Biometric data is sensitive personal data; a deceased individual is no longer a data subject
  • The seven principles and the 13 registrable classes are unchanged by the amendment

Who this applies to: Any Malaysian business, branch or foreign company that processes personal data in respect of commercial transactions.

On this page
Full explanation ≈12 min

If your privacy notice still says “data user”, it is describing a category of person that stopped existing on 1 April 2025.

That is not a cosmetic point. Section 2 of the Personal Data Protection (Amendment) Act 2024 substituted “data controller” for “data user” everywhere the phrase appears in Act 709, including in the shoulder notes. Alongside it came a tripled headline penalty, a new class of directly liable defendant, and — from 1 June 2025 — two obligations with hard deadlines that did not exist in Malaysian law before.

Most compliance material still on the internet was written against the 2010 Act. This page is written against the Act as amended.

What did the 2024 amendment actually change?

The amending Act is A1727, not A1717. That transposition appears often enough in circulated summaries to be worth stating: Act A1717 is a different statute. A1727 received Royal Assent on 9 October 2024 and was gazetted on 17 October 2024.

It did not commence as a block. Section 1(2) let the Minister appoint different dates for different provisions, and P.U.(B) 522/2024, dated 19 December 2024 and gazetted 24 December 2024, did exactly that.

CommencementA1727 sectionsWhat actually changed
1 January 20257, 11, 13, 14Housekeeping — national-language text of s.16(3), s.67 accounts, electronic service under s.136(1), and the saving provision
1 April 20252, 3, 4, 5, 8, 10, 12Data user becomes data controller; biometric data added to sensitive personal data; “personal data breach” defined; deceased individuals excluded; processors bound by the Security Principle; penalty raised to RM1m; s.129 whitelist deleted
1 June 20256, 9New Division 1a — s.12A data protection officer and s.12B breach notification — plus new s.43A, the right to data portability

Three changes from the April tranche do real work.

Biometric data is now sensitive personal data. Section 3(b) inserted a definition — personal data resulting from technical processing relating to the physical, physiological or behavioural characteristics of a person — and s.3(c) slotted it into the definition of sensitive personal data. If you run fingerprint or facial-recognition attendance, you moved into the s.40 consent regime overnight.

A deceased individual is no longer a data subject. Section 3(f) says so expressly. Estate and legacy records fall outside Act 709.

The maximum penalty for breaching a principle tripled. Section 4(b)(ii) replaced “three hundred thousand ringgit or … two years” with one million ringgit or … three years.

Who does the Act bind in the first place?

Before any of this matters, check that Act 709 reaches you at all — because its scope is narrower than most people assume in one direction and wider in another.

Section 2(1) applies the Act to any person who processes, or who has control over or authorises the processing of, personal data in respect of commercial transactions. The commercial-transaction limit runs through the definition of personal data in s.4 as well. Purely personal or household record-keeping is outside.

Section 2(2) then sets the territorial hook. The Act binds a person established in Malaysia, whether or not the processing happens in the context of that establishment; and a person not established in Malaysia who uses equipment in Malaysia for processing, other than for mere transit. Section 2(3) requires that second category to nominate a representative established in Malaysia.

Section 2(4) defines establishment generously: an individual physically present in Malaysia for at least 180 days in a calendar year; a body incorporated under the Companies Act; a partnership or unincorporated association formed under Malaysian written law; or anyone maintaining an office, branch or agency here, or a regular practice.

Two exclusions in s.3 are worth knowing. The Act does not apply to the Federal Government or State Governments — a gap the amendment did not close. And it does not apply to personal data processed outside Malaysia unless that data is intended to be further processed in Malaysia.

Note that nothing in this turns on size. There is no de minimis, no revenue floor and no headcount test anywhere in Act 709.

Are you a data controller or a data processor?

Before April 2025 this was largely a drafting question for your vendor contracts. It is now a question of who goes on the charge sheet.

A data controller determines the purposes and means of processing. A data processor processes personal data only on behalf of a controller and does not process it for its own purposes.

Section 4 of A1727 inserted a new s.5(1A): where processing is carried out by a data processor on behalf of a data controller, the data processor shall comply with the Security Principle. Section 5 of A1727 then rewrote s.9 itself so that the duty to take practical steps runs to “a data controller and a data processor”, and moved the vendor-guarantee obligation in s.9(2) onto the processor.

The practical effect: a Malaysian payroll bureau, hosting provider or outsourced contact centre that loses client data can now be prosecuted directly, at RM1,000,000 or three years, without the client having to be joined. Processors that priced their services on the old assumption of purely contractual exposure repriced through 2025.

One thing that did not change: s.12A(2) requires a data processor to appoint its own data protection officer, but the registration duty in the guideline is expressed as a duty of the data controller. Processors appoint; controllers register.

What are the seven personal data protection principles?

Section 5(1) of Act 709 lists them, and A1727 left the list and the numbering alone.

PrincipleSectionThe obligation in one line
General6No processing without consent, and no processing of sensitive personal data except under s.40
Notice and Choice7Written notice, in national language and English, of what you collect and why
Disclosure8No disclosure outside the stated purpose or class of third parties without consent
Security9Practical steps against loss, misuse, unauthorised access, alteration or destruction
Retention10Do not keep longer than necessary; destroy or permanently delete when done
Data Integrity11Accurate, complete, not misleading, up to date
Access12The data subject gets access and correction rights

Contravention of any of them is an offence under s.5(2) — RM1,000,000 or three years or both, since 1 April 2025.

The Retention Principle is the one most Malaysian businesses fail on and the one JPDP can prove without a complaint: an inbox of a decade of customer NRIC scans is a s.10 contravention on its face.

Do you have to register with JPDP?

Only if you fall within a class specified under s.14. There are 13 classes, set by the Personal Data Protection (Class of Data Users) Order 2013, P.U.(A) 336/2013, as amended by P.U.(A) 326/2016 which added pawnbrokers and moneylenders.

If you are in a class and you process personal data without a certificate of registration, that is RM500,000 or three years or both under s.16(4). Registration fees run from RM100 for a sole proprietor to RM400 for a public company, under P.U.(A) 337/2013, and a data controller belonging to two or more classes must register separately for each.

If you are not in a class, you register nothing — but you are still bound by every principle, by s.12A and by s.12B. That last point is where most of the market gets it wrong; see the mistakes section below.

Who needs a data protection officer?

Section 12A commenced 1 June 2025. The conditions sit in the Commissioner’s guideline of 25 February 2025, at paragraph 4.2, and they are disjunctive — any one triggers the duty:

  • personal data exceeding 20,000 data subjects; or
  • sensitive personal data including financial information exceeding 10,000 data subjects; or
  • activities that require regular and systematic monitoring of personal data.

There is no revenue test, no headcount test, and — critically — no volume floor on the third limb. The guideline’s own worked example of regular and systematic monitoring is a retail website that uses algorithms to monitor searches and purchases and offers recommendations. That describes a large share of Malaysian e-commerce.

Appointment must be registered with the Commissioner through SPDP at daftar.pdp.gov.my within 21 days of appointment, and changes updated within 14 days.

When must you notify a data breach?

Section 12B(1) says “as soon as practicable”. The 72 hours everyone quotes is not in the Act — it is paragraph 6.1 of the Data Breach Notification Guideline. The trigger is that the breach causes or is likely to cause significant harm, defined at paragraph 5.2, which includes any breach affecting more than 1,000 data subjects.

Affected data subjects must be told within 7 days of the notification to the Commissioner. Failure to notify the Commissioner is RM250,000 or two years under s.12B(3).

Can you still send personal data overseas?

Yes, and the route changed on 1 April 2025.

The old s.129(1) prohibited transfer outside Malaysia except to a place the Minister gazetted on the Commissioner’s recommendation. A full whitelist was never gazetted, which made the section close to unworkable and widely disregarded.

Section 12 of A1727 deleted s.129(1) altogether, and rewrote s.129(2) so that it now reads as a permission: a data controller may transfer personal data to a place outside Malaysia if there is in force in that place a law substantially similar to Act 709, or that place ensures an adequate level of protection at least equivalent to Act 709. The words “or that serves the same purposes as this Act” were struck out of limb (a).

This is a self-assessment — there is no application and no approval — but it is not unguided. On 29 April 2025 the Commissioner launched the Cross Border Personal Data Transfer Guidelines (GP_CBPDT), which set criteria for both limbs. To rely on either the substantially similar law or the adequate level of protection test, a data controller must run a Transfer Impact Assessment (TIA) weighing enumerated factors — comparable data-subject rights in the destination, and recipient security measures aligned to the Security Principle and the Personal Data Protection Standards — with each TIA valid for no longer than three years. The separate grounds in s.129(3) survive, including consent, contract necessity and legal proceedings, and the guideline explains them too; only paragraph (h), transfers the Minister deemed to be in the public interest, was deleted along with the ministerial machinery in s.129(4).

What is the new right to data portability?

Section 9 of A1727 inserted s.43A with effect from 1 June 2025, and it is the change most commentary missed entirely while everyone looked at the DPO and breach provisions.

Section 43A(1) lets a data subject request the data controller to transmit his personal data directly to another data controller of his choice, by notice in writing given by electronic means. Section 43A(2) subjects that to technical feasibility and compatibility of the data format — a meaningful limit, and the one most controllers will rely on. Section 43A(3) requires transmission to be completed “within the period as may be prescribed”.

No period has been prescribed. The right is in force with no clock attached to it, which means a controller cannot currently be late, but also cannot refuse outright on timing grounds. Build the export capability now rather than after a period is gazetted.

The same amendment threaded portability into the machinery: s.3(e) of A1727 widened the definition of “requestor” in s.4 to include a person making a data portability request, so the existing requestor provisions carry across.

What are the penalties?

ContraventionProvisionMaximum
Breach of a personal data protection principles.5(2)RM1,000,000 / 3 years
Breach of the Security Principle by a data processors.5(1A) with s.5(2)RM1,000,000 / 3 years
Processing without registration when in a registrable classs.16(4)RM500,000 / 3 years
Continuing to process after a certificate expiresP.U.(A) 337/2013 reg.5(2)RM250,000 / 2 years
Failure to notify the Commissioner of a breachs.12B(3)RM250,000 / 2 years

Common mistakes

Assuming registration status decides everything. It does not. Sections 12A and 12B bind every data controller, whether or not you appear in any of the 13 classes. A Sdn Bhd running a subscription app registers nothing and still owes a DPO and a 72-hour clock.

Treating the 72-hour figure as statutory. It sits in a guideline issued under s.48(g), not in s.12B. That matters if you are arguing about it: the statutory standard is “as soon as practicable”, and the guideline explains what the Commissioner will treat as meeting it.

Citing A1717. The amending Act is A1727. Verify the number before you cite it in a board paper.

Leaving “data user” in the privacy notice. Cosmetic on its own, but it is a reliable signal that the notice has not been reviewed since 2024 — and the s.7 Notice and Choice Principle requires the notice to be accurate.

Believing the whitelist still governs cross-border transfer. A surprising amount of 2023-vintage guidance still tells readers to check a gazetted list of approved countries. That mechanism was deleted. Assess the destination yourself and document the assessment — the Cross Border Personal Data Transfer Guidelines expect a Transfer Impact Assessment, refreshed at least every three years.

Assuming your cloud vendor’s DPA discharges you. Section 12A(4) is explicit: appointing a DPO does not discharge the controller or processor from any duty under the Act. The same logic runs through the Security Principle — you remain liable for your own processing.

What’s next

Work through it in this order. Decide whether you are a controller, a processor, or both for different data sets. Test yourself against the three DPO limbs, paying attention to the third one. Check whether any of the 13 registration classes reaches you. Then write the breach playbook — because 72 hours is not long enough to design a process from scratch while the incident is running.

Three of the four subject-specific guidelines JPDP had signalled are now live: on 30 April 2026 the Commissioner launched the Data Protection Impact Assessment, Data Protection by Design, and Automated Decision-Making and Profiling guidelines. Only the data portability guideline is still outstanding, remaining a consultation paper (PCP 03/2024). The s.43A portability right itself has been in force since 1 June 2025 but no transmission period has been prescribed, so it is currently a right with no clock. Watch, too, for the outcome of Public Consultation Paper 4/2025 on amendments to the Personal Data Protection Regulations 2013, which was still at consultation as at August 2026.

Frequently asked 6
Which Act amended the PDPA, and when did it come into force?

The Personal Data Protection (Amendment) Act 2024, Act A1727, received Royal Assent on 9 October 2024 and was gazetted on 17 October 2024. It did not commence all at once. P.U.(B) 522/2024, dated 19 December 2024 and gazetted 24 December 2024, appointed 1 January 2025 for sections 7, 11, 13 and 14; 1 April 2025 for sections 2, 3, 4, 5, 8, 10 and 12; and 1 June 2025 for sections 6 and 9.

Am I a data controller or a data processor?

You are a data controller if you determine the purposes and means of processing — you decide why the data is collected and what happens to it. You are a data processor if you process personal data only on behalf of another, on instruction. A payroll bureau, a cloud provider or an outsourced call centre is typically a processor. The distinction now matters far more than before, because since 1 April 2025 processors carry direct statutory liability rather than only contractual liability.

Can I still transfer personal data outside Malaysia?

Yes, and the mechanics changed on 1 April 2025. Section 12 of A1727 deleted s.129(1), which had required the Minister to gazette a whitelist of approved destinations. No such list was ever published in full, so the old provision was widely ignored. The rewritten s.129 lets a data controller transfer where the destination has a law substantially similar to Act 709, or ensures an adequate level of protection at least equivalent to Act 709. The specific grounds in s.129(3) — consent, contract, legal proceedings and so on — survive, except paragraph (h).

Does the PDPA apply to a foreign company with no office in Malaysia?

Section 2 of Act 709 sets the territorial reach. The Act binds a person established in Malaysia who processes personal data, and a person not established in Malaysia who uses equipment in Malaysia for processing otherwise than for mere transit. It does not apply to personal data processed wholly outside Malaysia unless the data is intended to be further processed in Malaysia. There is no revenue or headcount threshold.

What are the penalties for getting this wrong?

Contravening a personal data protection principle is now RM1,000,000 or three years or both, raised from RM300,000 and two years by s.4 of A1727. Failing to notify the Commissioner of a personal data breach is RM250,000 or two years under s.12B(3). Processing without a certificate of registration when you belong to a registrable class is RM500,000 or three years under s.16(4).

Do the seven principles still apply in the same way?

The seven principles in ss.5 to 12 of Act 709 were not renumbered or rewritten. What changed is who they bind and what they cost. The Security Principle in s.9 now reads as a duty of a data controller and a data processor, so a processor no longer sits behind the controller's guarantees. The maximum penalty under s.5(2) tripled.

Sources & history 13 sources
⚑ Awaiting expert verification

The following are deliberately unstated or described only qualitatively until confirmed by a subject-matter expert:

  • The outcome of Public Consultation Paper 4/2025 on proposed amendments to the Personal Data Protection Regulations 2013 (issued 25 August 2025) — still at public consultation with no gazetted amendment as at 14 August 2026

Sources

  1. Personal Data Protection (Amendment) Act 2024 [Act A1727] — Attorney General's Chambers
  2. Personal Data Protection (Amendment) Act 2024 — Appointment of Date of Coming into Operation [P.U. (B) 522/2024] — Attorney General's Chambers
  3. Personal Data Protection Act 2010 [Act 709] — Reprint 2023 — Attorney General's Chambers
  4. Personal Data Protection Guideline — Appointment of Data Protection Officer, Version 1.0 — Personal Data Protection Commissioner Malaysia
  5. Personal Data Protection Guideline — Data Breach Notification, Version 1.0 — Personal Data Protection Commissioner Malaysia
  6. Personal Data Protection (Class of Data Users) Order 2013 [P.U. (A) 336/2013] — Attorney General's Chambers
  7. Personal Data Protection (Registration of Data User) Regulations 2013 [P.U. (A) 337/2013] — Attorney General's Chambers
  8. Cross Border Personal Data Transfer Guideline [GP_CBPDT_EN] — Personal Data Protection Commissioner Malaysia
  9. Data Protection Impact Assessment Guideline (DPIA) — Personal Data Protection Commissioner Malaysia
  10. Data Protection By Design Guideline (DpbD) — Personal Data Protection Commissioner Malaysia
  11. PDP Commissioner launches Guidelines on Data Protection Impact Assessment, Automated Decision-Making and Profiling, and Data Protection by Design — Allen & Gledhill
  12. AKTA 709 — Guidelines, Orders and Public Consultation Papers listing — Personal Data Protection Commissioner Malaysia
  13. Personal Data Protection Regulations 2013 [P.U. (A) 335/2013] — Personal Data Protection Commissioner Malaysia

Change history

Version Date Change By
01.00 14 Aug 2026 Approved and published.
More in Digital compliance View all 6 →
Related knowledge