# Personal Data Protection Act 2010 (Act 709) — the seven principles, and the scope limit most readers miss

> Statute entity page for Malaysia's data protection law — what Act 709 actually covers (personal data in commercial transactions, and nothing else), the seven Personal Data Protection Principles in sections 6 to 12, who is caught by the establishment and equipment tests, and what the 2024 amendment changed.

- Category: law
- Language: en
- Status: published
- Updated: 2026-07-24
- Canonical: https://negaraku.md/en/law/pdpa-2010

---

Most people describe Act 709 as "Malaysia's privacy law". The Act itself makes a
much narrower claim. Its long title is an Act to regulate the processing of
personal data **in commercial transactions** — and section 3(1) then removes the
Federal Government and State Governments from its reach entirely.

That boundary, not the seven principles, is where most PDPA questions are actually
decided.

## At a glance

| | |
| --- | --- |
| Short title | Personal Data Protection Act 2010 |
| Act number | Act 709 |
| Royal assent | 2 June 2010 |
| Gazetted | 10 June 2010 |
| Commencement | 15 November 2013, by P.U.(B) 464/2013 |
| Scope | Personal data processed in respect of commercial transactions |
| Regulator | Personal Data Protection Commissioner (s.47), Jabatan Perlindungan Data Peribadi |
| Principal amendment | Personal Data Protection (Amendment) Act 2024 (Act A1727) |

## The scope limit

Section 2(1) applies the Act to any person who processes, or who has control over
or authorises the processing of, any personal data **in respect of commercial
transactions**. Section 4 defines a commercial transaction as any transaction of a
commercial nature, contractual or not, including the supply or exchange of goods or
services, agency, investments, financing, banking and insurance.

Three carve-outs follow, and each one surprises somebody:

- **Government is out.** Section 3(1): the Act shall not apply to the Federal
  Government and State Governments.
- **Offshore processing is out unless it comes back.** Section 3(2): the Act does
  not apply to personal data processed outside Malaysia, unless that data is
  intended to be further processed in Malaysia.
- **Household use is out.** Section 45(1) exempts personal data processed by an
  individual only for that individual's personal, family or household affairs,
  including recreational purposes.

Credit reporting is also excluded from the definition of personal data — that
activity sits under the Credit Reporting Agencies Act 2010 (Act 710) instead.

## Who is caught

Section 2(2) reaches a person if either limb applies:

| Limb | Test |
| --- | --- |
| s.2(2)(a) | The person is **established in Malaysia**, and the data is processed by them or by anyone employed or engaged by that establishment |
| s.2(2)(b) | The person is **not established in Malaysia** but **uses equipment in Malaysia** to process the data, otherwise than for transit through Malaysia |

Section 2(4) defines "established in Malaysia" concretely: an individual physically
present in Malaysia for not less than 180 days in a calendar year; a body
incorporated under the Companies Act (see
[Companies Act 2016](/en/law/companies-act-2016)); a partnership or unincorporated
association formed under Malaysian written law; or anyone maintaining an office,
branch, agency or regular practice here.

A person caught only by the equipment limb must nominate a representative
established in Malaysia — section 2(3).

## The seven principles

Section 5(1) requires compliance with seven Personal Data Protection Principles,
each spelled out in its own section.

| # | Principle | Section | The duty in one line |
| --- | --- | --- | --- |
| 1 | General | 6 | No processing without consent, unless a s.6(2) ground applies; and the purpose must be lawful, directly related to the controller's activity, and adequate but not excessive |
| 2 | Notice and Choice | 7 | Written notice of the data, purposes, source, access and correction rights, third-party classes, and whether supply is obligatory — in the national **and** English languages |
| 3 | Disclosure | 8 | No disclosure outside the collection purpose, or to a party outside the notified class of third parties, without consent |
| 4 | Security | 9 | Practical steps against loss, misuse, modification and unauthorised access, having regard to the nature of the data, storage location, equipment and personnel |
| 5 | Retention | 10 | Keep no longer than necessary; take reasonable steps to destroy or permanently delete when no longer required |
| 6 | Data Integrity | 11 | Reasonable steps to keep data accurate, complete, not misleading and up to date for its purpose |
| 7 | Access | 12 | The data subject may access and correct their data, subject to the statutory refusal grounds |

Contravening section 5(1) is a criminal offence. After Act A1727, the penalty is a
fine up to **RM1,000,000**, imprisonment up to **three years**, or both — raised
from RM300,000 and two years.

## What Act A1727 changed

The Personal Data Protection (Amendment) Act 2024 received royal assent on
9 October 2024 and was gazetted on 17 October 2024. P.U.(B) 522/2024 brought it
into force in three tranches.

| Date | Sections of A1727 | Effect |
| --- | --- | --- |
| 1 January 2025 | 7, 11, 13, 14 | Drafting corrections, fund administration, service of documents by electronic means, savings |
| 1 April 2025 | 2, 3, 4, 5, 8, 10, 12 | "Data user" becomes **data controller**; biometric data added to sensitive personal data; "personal data breach" defined; a deceased individual is no longer a data subject; the Security Principle binds **data processors** directly; higher s.5(2) penalty; cross-border transfer rules in s.129 rewritten |
| 1 June 2025 | 6, 9 | New Division 1a — mandatory **data protection officer** (s.12a) and **data breach notification** to the Commissioner (s.12b); new **right to data portability** (s.43a) |

Two of those are structural, not cosmetic. Data processors previously owed duties
only through their contract with the controller; since 1 April 2025 the Security
Principle applies to them directly. And breach notification is a standing duty: the
controller must notify the Commissioner as soon as practicable, and notify affected
data subjects without unnecessary delay where the breach causes or is likely to
cause significant harm.

## Common mistakes

- **Treating a PDPA notice as consent.** Sections 6 and 7 are separate principles
  with separate duties; issuing a notice does not by itself establish the consent
  the General Principle requires.
- **Issuing the notice in English only.** Section 7(3) requires the national and
  English languages, and requires the means of exercising choice in both.
- **Assuming the Act covers a government dataset.** It does not — section 3(1).
- **Ignoring the criminal character of the Act.** These are offences on conviction.
  Under section 133, where a body corporate commits an offence, its directors, chief
  executive, managers, secretary and similar officers may be charged with it and are
  deemed to have committed it unless they prove the offence happened without their
  knowledge, consent or connivance and that they exercised due diligence.

## Where this connects

Employee records are the largest body of personal data most Malaysian businesses
hold, so Act 709 sits directly alongside the
[Employment Act 1955](/en/law/employment-act-1955). Tax and duty assessment is one
of the section 45(2) exemptions, which touches the
[Income Tax Act 1967](/en/law/income-tax-act-1967).

## What's next

This page is the statute record. The operating rules — registration of data
controllers, the Personal Data Protection Standard, DPO appointment and the data
breach notification form — are set by the Commissioner under the Act rather than in
the section text, and will be documented in their own articles as that cluster is
built.

## Sources

- Act 709 — Personal Data Protection Act 2010, full text — https://lom.agc.gov.my/ilims/upload/portal/akta/outputaktap/Act%20709%20ori.pdf (Attorney General's Chambers of Malaysia)
- Act 709 — principal act timeline, commencement and subsidiary legislation — https://lom.agc.gov.my/act-detail.php?act=709 (Attorney General's Chambers of Malaysia)
- Personal Data Protection (Amendment) Act 2024 (Act A1727) — https://www.pdp.gov.my/ppdpv1/wp-content/uploads/2024/11/Act-A1727.pdf (Jabatan Perlindungan Data Peribadi (JPDP))
- P.U.(B) 522/2024 — Personal Data Protection (Amendment) Act 2024, appointment of date of coming into operation — https://www.pdp.gov.my/ppdpv1/wp-content/uploads/2024/12/PENETAPAN-TARIKH-PERMULAAN-KUAT-KUASA-2.pdf (Attorney General's Chambers of Malaysia)
- Principles of Personal Data Protection — https://www.pdp.gov.my/ppdpv1/en/principles-of-personal-data-protection/ (Jabatan Perlindungan Data Peribadi (JPDP))
- Determination of Effective Commencement Date — Act 709 — https://www.pdp.gov.my/ppdpv1/en/akta/determination-of-effective-commencement-date/ (Jabatan Perlindungan Data Peribadi (JPDP))
- Introduction — Personal Data Protection — https://www.pdp.gov.my/ppdpv1/en/introduction/ (Jabatan Perlindungan Data Peribadi (JPDP))

---
Source of truth: https://github.com/negaraku-md/NegaraKu.md
License: CC BY-SA 4.0
