The Personal Data Protection Department (Jabatan Perlindungan Data Peribadi, JPDP) is the Malaysian federal agency that administers and enforces the Personal Data Protection Act 2010 (Act 709). Established on 16 May 2011, it operates under the Digital Ministry and assists the Personal Data Protection Commissioner in regulating how personal data is processed in commercial transactions. Day to day, that means registering data controllers, handling complaints, and enforcing the seven data protection principles — a mandate reshaped by the 2024 Amendment Act.
- JPDP was established on 16 May 2011 to help enforce the Personal Data Protection Act 2010 (Act 709), which came into full force on 15 November 2013.
- It operates as an agency under the Digital Ministry and assists the Personal Data Protection Commissioner.
- The PDPA rests on seven principles; data users in the 13 classes specified by the 2013 Order must register with JPDP under section 14.
- Individuals can complain to the Commissioner via aduan@pdp.gov.my or 03-7456 3888, and register online at daftar.pdp.gov.my.
- The Personal Data Protection (Amendment) Act 2024 (Act A1727) renames 'data user' to 'data controller' and adds a mandatory 72-hour breach notification, a Data Protection Officer duty, biometric data, and a data portability right, phased in across 2025.
Who this applies to: Businesses and organisations that process personal data in Malaysia, compliance and legal teams, and individuals seeking to understand or exercise their data-protection rights.
On this page
Almost every guide to Malaysian data privacy explains the law. Far fewer explain the office that runs it. That office is the Personal Data Protection Department — Jabatan Perlindungan Data Peribadi (JPDP) — established on 16 May 2011 after Parliament passed the Personal Data Protection Act 2010 (Act 709). It operates as an agency under the Digital Ministry, and its job is to assist the Personal Data Protection Commissioner in enforcing that Act. This is the department a Malaysian business registers with, and the one an ordinary citizen complains to.
What does JPDP actually do?
JPDP’s main responsibility is to regulate how data users process the personal data of individuals involved in commercial transactions, so that it is not misused or exploited. Its stated vision is to be the main leader in protecting personal data in achieving well-being as a developed country; its mission is to regulate data protection to build the trust that contributes to increased commercial transactions.
In practice, the department does three things citizens and businesses touch directly:
- Registration — issuing and administering certificates of registration for data controllers.
- Complaints — receiving and acting on grievances that personal data has been mishandled.
- Enforcement and guidance — applying Act 709 and publishing the guidelines that flesh it out.
The Act it administers came into full force on 15 November 2013, the first legislative framework of its kind in Malaysia.
What are the rules JPDP enforces?
The PDPA is built on seven Personal Data Protection Principles: the General Principle, the Notice and Choice Principle, the Disclosure Principle, the Security Principle, the Retention Principle, the Data Integrity Principle, and the Access Principle. Together they govern how any organisation may collect, use, keep, and disclose personal data.
Individuals whose data is processed hold matching rights — to be informed that processing is happening, to access their data, to correct it, to withdraw consent, and to prevent processing for direct marketing.
Who has to register, and how do I complain?
Not everyone must register, but data users within the 13 classes specified under the Personal Data Protection (Class of Data Users) Order 2013 must register with JPDP under section 14 of the Act and hold a valid certificate. Registration is done online through the SPDP portal at daftar.pdp.gov.my.
If you believe your personal data was processed in breach of the Act, you can complain to the Commissioner by email at aduan@pdp.gov.my or by phone at 03-7456 3888.
How did the 2024 Amendment change JPDP’s mandate?
The Personal Data Protection (Amendment) Act 2024 (Act A1727) was passed by the Dewan Rakyat on 16 July 2024 and the Dewan Negara on 31 July 2024, received Royal Assent on 9 October 2024, and was gazetted on 17 October 2024. On 24 December 2024 the Minister of Digital gazetted a phased commencement across 1 January, 1 April, and 1 June 2025. Key changes:
| Change | What it means |
|---|---|
| ”Data user” → “data controller” | The term is replaced throughout the principal Act. |
| Data Protection Officer | From 1 June 2025, controllers and processors must appoint at least one DPO; thresholds include processing data of more than 20,000 subjects, or sensitive data of more than 10,000. |
| Breach notification | Controllers must notify the Commissioner within 72 hours, and affected subjects within seven days where significant harm is likely. |
| Data portability | Subjects may ask that their data be transmitted directly to another controller, subject to technical feasibility (from June 2025). |
| Cross-border transfer | The old “whitelist” is replaced with a risk-based framework. |
| Sensitive data | Now expressly includes biometric data. |
| Penalties | Maximum fine for breaching the security principle rises from RM300,000 to RM1,000,000, and maximum imprisonment from two to three years. |
What’s next
If your organisation handles customer or employee data, check whether you fall within one of the 13 registered classes, confirm your DPO and breach-notification arrangements under Act A1727, and review your practices against the seven principles. JPDP is based at Level 8, Galeria PjH, Persiaran Perdana, Precinct 4, 62100 Putrajaya, and publishes the statutory texts and current guidelines at pdp.gov.my.
What is the difference between JPDP and the Personal Data Protection Commissioner?
The Commissioner is the office that enforces the Act; JPDP is the department that assists the Commissioner, carrying out registration, complaint handling, and enforcement. In practice the Department operates under the Commissioner's authority.
Who must register with JPDP?
Data users (now 'data controllers') falling within the 13 classes specified under the Personal Data Protection (Class of Data Users) Order 2013 must register under section 14 of the PDPA and obtain a valid certificate of registration. Registration is made online through the SPDP portal at daftar.pdp.gov.my.
The following are deliberately unstated or described only qualitatively until confirmed by a subject-matter expert:
- Exact current internal division structure of JPDP (Malay sources cite Bahagian Pendaftaran dan Operasi, Bahagian Pemantauan, Bahagian Perundangan under a Ketua Pengarah / Timbalan Ketua Pengarah) — confirm against the live pdp.gov.my organisation chart.
- Exact section-to-date mapping of the phased 2025 commencement (which sections took effect 1 Jan vs 1 Apr vs 1 June 2025) — confirm against the official commencement-date gazette on pdp.gov.my.
- Current data-user registration fee range and certificate validity period — verify against the current SPDP portal / Registration Regulations.
- Whether the office is still branded 'Personal Data Protection Commissioner' or has moved toward a 'Commission/Suruhanjaya' model — confirm current official title.
- Latest published enforcement statistics (registrations, complaints, actions) — not yet located from a primary DOSM/JPDP source.
Sources
- Personal Data Protection Department (JPDP) — official page — Jabatan Perlindungan Data Peribadi (JPDP), Malaysia
- FAQ — Personal Data Protection — Jabatan Perlindungan Data Peribadi (JPDP), Malaysia
- Personal Data Protection Regulations (Registration of Data Users) — Jabatan Perlindungan Data Peribadi (JPDP), Malaysia
- Personal Data Protection (Amendment) Act 2024 — Jabatan Perlindungan Data Peribadi (JPDP), Malaysia
- Personal Data Protection (Amendment) Act 2024 Commencement Date Determination — Jabatan Perlindungan Data Peribadi (JPDP), Malaysia
- A Sea Change in Malaysia's Data Protection Framework — coming into force of the PDP (Amendment) Act 2024 — Lexology
- News Alert: Dates of Coming into Operation of the Personal Data Protection (Amendment) Act 2024 — Christopher & Lee Ong
- Malaysia: Guidelines Issued on Data Breach Notification and Data Protection Officer Appointment — DLA Piper (Privacy Matters)
- From Legislative Reform to Practical Guidance: Key Amendments to Malaysia's PDPA — Mayer Brown
Change history
| Version | Date | Change | By |
|---|---|---|---|
| 01.00 | 14 Aug 2026 | Approved and published. | — |