# Personal Data Protection Department (JPDP)

> The Personal Data Protection Department (Jabatan Perlindungan Data Peribadi, JPDP) is the federal agency under the Digital Ministry that administers and enforces Malaysia's Personal Data Protection Act 2010, registering data controllers, handling complaints, and overseeing the 2025 reforms on breach notification and data protection officers.

- Category: law
- Language: en
- Status: published
- Updated: 2026-08-14
- Canonical: https://negaraku.md/en/law/data-protection-department-jpdp

---

Almost every guide to Malaysian data privacy explains the *law*. Far fewer explain the *office that runs it*. That office is the **Personal Data Protection Department** — *Jabatan Perlindungan Data Peribadi* (**JPDP**) — established on **16 May 2011** after Parliament passed the Personal Data Protection Act 2010 (Act 709). It operates as an agency under the Digital Ministry, and its job is to assist the **Personal Data Protection Commissioner** in enforcing that Act. This is the department a Malaysian business registers with, and the one an ordinary citizen complains to.

## What does JPDP actually do?

JPDP's main responsibility is to regulate how data users process the personal data of individuals involved in commercial transactions, so that it is not misused or exploited. Its stated vision is to be the main leader in protecting personal data in achieving well-being as a developed country; its mission is to regulate data protection to build the trust that contributes to increased commercial transactions.

In practice, the department does three things citizens and businesses touch directly:

- **Registration** — issuing and administering certificates of registration for data controllers.
- **Complaints** — receiving and acting on grievances that personal data has been mishandled.
- **Enforcement and guidance** — applying Act 709 and publishing the guidelines that flesh it out.

The Act it administers came into full force on **15 November 2013**, the first legislative framework of its kind in Malaysia.

## What are the rules JPDP enforces?

The PDPA is built on **seven Personal Data Protection Principles**: the General Principle, the Notice and Choice Principle, the Disclosure Principle, the Security Principle, the Retention Principle, the Data Integrity Principle, and the Access Principle. Together they govern how any organisation may collect, use, keep, and disclose personal data.

Individuals whose data is processed hold matching rights — to be informed that processing is happening, to access their data, to correct it, to withdraw consent, and to prevent processing for direct marketing.

## Who has to register, and how do I complain?

Not everyone must register, but data users within the **13 classes specified under the Personal Data Protection (Class of Data Users) Order 2013** must register with JPDP under **section 14** of the Act and hold a valid certificate. Registration is done online through the **SPDP portal at daftar.pdp.gov.my**.

If you believe your personal data was processed in breach of the Act, you can complain to the Commissioner by email at **aduan@pdp.gov.my** or by phone at **03-7456 3888**.

## How did the 2024 Amendment change JPDP's mandate?

The **Personal Data Protection (Amendment) Act 2024 (Act A1727)** was passed by the Dewan Rakyat on 16 July 2024 and the Dewan Negara on 31 July 2024, received Royal Assent on 9 October 2024, and was gazetted on 17 October 2024. On 24 December 2024 the Minister of Digital gazetted a phased commencement across **1 January, 1 April, and 1 June 2025**. Key changes:

| Change | What it means |
|---|---|
| "Data user" → "data controller" | The term is replaced throughout the principal Act. |
| Data Protection Officer | From 1 June 2025, controllers and processors must appoint at least one DPO; thresholds include processing data of more than 20,000 subjects, or sensitive data of more than 10,000. |
| Breach notification | Controllers must notify the Commissioner within **72 hours**, and affected subjects within seven days where significant harm is likely. |
| Data portability | Subjects may ask that their data be transmitted directly to another controller, subject to technical feasibility (from June 2025). |
| Cross-border transfer | The old "whitelist" is replaced with a risk-based framework. |
| Sensitive data | Now expressly includes biometric data. |
| Penalties | Maximum fine for breaching the security principle rises from RM300,000 to **RM1,000,000**, and maximum imprisonment from two to three years. |

## What's next

If your organisation handles customer or employee data, check whether you fall within one of the 13 registered classes, confirm your DPO and breach-notification arrangements under Act A1727, and review your practices against the seven principles. JPDP is based at Level 8, Galeria PjH, Persiaran Perdana, Precinct 4, 62100 Putrajaya, and publishes the statutory texts and current guidelines at **pdp.gov.my**.

## Sources

- Personal Data Protection Department (JPDP) — official page — https://www.pdp.gov.my/ppdpv1/en/personal-data-protection-department/ (Jabatan Perlindungan Data Peribadi (JPDP), Malaysia)
- FAQ — Personal Data Protection — https://www.pdp.gov.my/ppdpv1/en/faq/ (Jabatan Perlindungan Data Peribadi (JPDP), Malaysia)
- Personal Data Protection Regulations (Registration of Data Users) — https://www.pdp.gov.my/ppdpv1/en/akta/personal-data-protection-regulations-registration-of-data-users/ (Jabatan Perlindungan Data Peribadi (JPDP), Malaysia)
- Personal Data Protection (Amendment) Act 2024 — https://www.pdp.gov.my/ppdpv1/en/akta/personal-data-protection-amendment-act-2024/ (Jabatan Perlindungan Data Peribadi (JPDP), Malaysia)
- Personal Data Protection (Amendment) Act 2024 Commencement Date Determination — https://www.pdp.gov.my/ppdpv1/en/personal-data-protection-amendment-act-2024-commencement-date-determination/ (Jabatan Perlindungan Data Peribadi (JPDP), Malaysia)
- A Sea Change in Malaysia's Data Protection Framework — coming into force of the PDP (Amendment) Act 2024 — https://www.lexology.com/library/detail.aspx?g=8a53f32c-e94e-44dd-9184-a05717c559b4 (Lexology)
- News Alert: Dates of Coming into Operation of the Personal Data Protection (Amendment) Act 2024 — https://www.christopherleeong.com/viewpoints/news-alert-dates-of-coming-into-operation-of-the-personal-data-protection-amendment-act-2024/ (Christopher & Lee Ong)
- Malaysia: Guidelines Issued on Data Breach Notification and Data Protection Officer Appointment — https://privacymatters.dlapiper.com/2025/03/malaysia-guidelines-issued-on-data-breach-notification-and-data-protection-officer-appointment/ (DLA Piper (Privacy Matters))
- From Legislative Reform to Practical Guidance: Key Amendments to Malaysia's PDPA — https://www.mayerbrown.com/en/insights/publications/2025/07/from-legislative-reform-to-practical-guidance-key-amendments-to-malaysias-pdpa-and-the-launch-of-cross-border-transfer-guidelines (Mayer Brown)

---
Source of truth: https://github.com/negaraku-md/NegaraKu.md
License: CC BY-SA 4.0
