The Personal Data Protection Act 2010 (Act 709) came into operation on 15 November 2013 and regulates the processing of personal data in respect of commercial transactions. It does not apply to the Federal Government or State Governments, nor to data an individual processes purely for personal, family or household affairs. Its core duties are the seven Personal Data Protection Principles in sections 6 to 12, enforced by the Personal Data Protection Commissioner.
- Act 709; royal assent 2 June 2010, gazetted 10 June 2010, in force 15 November 2013 by P.U.(B) 464/2013
- Scope is limited to personal data 'in respect of commercial transactions' (s.2(1)) — that phrase is the whole boundary of the Act
- Section 3(1): the Act does not apply to the Federal Government and State Governments
- Seven principles: General, Notice and Choice, Disclosure, Security, Retention, Data Integrity, Access (s.5, set out in ss.6–12)
- Contravening the principles is a criminal offence, not just a regulatory one — fine up to RM1,000,000 or three years' imprisonment, or both (s.5(2) as amended)
- A person not established in Malaysia but using equipment in Malaysia to process data is caught, and must nominate a local representative (s.2(2)(b), s.2(3))
- The Personal Data Protection (Amendment) Act 2024 (Act A1727) renamed 'data user' to 'data controller' and added DPO, breach notification and data portability duties in phases across 2025
Who this applies to: Readers who need the statutory identity, scope and principle structure of Act 709 — not a compliance procedure for any single obligation.
On this page
Most people describe Act 709 as “Malaysia’s privacy law”. The Act itself makes a much narrower claim. Its long title is an Act to regulate the processing of personal data in commercial transactions — and section 3(1) then removes the Federal Government and State Governments from its reach entirely.
That boundary, not the seven principles, is where most PDPA questions are actually decided.
At a glance
| Short title | Personal Data Protection Act 2010 |
| Act number | Act 709 |
| Royal assent | 2 June 2010 |
| Gazetted | 10 June 2010 |
| Commencement | 15 November 2013, by P.U.(B) 464/2013 |
| Scope | Personal data processed in respect of commercial transactions |
| Regulator | Personal Data Protection Commissioner (s.47), Jabatan Perlindungan Data Peribadi |
| Principal amendment | Personal Data Protection (Amendment) Act 2024 (Act A1727) |
The scope limit
Section 2(1) applies the Act to any person who processes, or who has control over or authorises the processing of, any personal data in respect of commercial transactions. Section 4 defines a commercial transaction as any transaction of a commercial nature, contractual or not, including the supply or exchange of goods or services, agency, investments, financing, banking and insurance.
Three carve-outs follow, and each one surprises somebody:
- Government is out. Section 3(1): the Act shall not apply to the Federal Government and State Governments.
- Offshore processing is out unless it comes back. Section 3(2): the Act does not apply to personal data processed outside Malaysia, unless that data is intended to be further processed in Malaysia.
- Household use is out. Section 45(1) exempts personal data processed by an individual only for that individual’s personal, family or household affairs, including recreational purposes.
Credit reporting is also excluded from the definition of personal data — that activity sits under the Credit Reporting Agencies Act 2010 (Act 710) instead.
Who is caught
Section 2(2) reaches a person if either limb applies:
| Limb | Test |
|---|---|
| s.2(2)(a) | The person is established in Malaysia, and the data is processed by them or by anyone employed or engaged by that establishment |
| s.2(2)(b) | The person is not established in Malaysia but uses equipment in Malaysia to process the data, otherwise than for transit through Malaysia |
Section 2(4) defines “established in Malaysia” concretely: an individual physically present in Malaysia for not less than 180 days in a calendar year; a body incorporated under the Companies Act (see Companies Act 2016); a partnership or unincorporated association formed under Malaysian written law; or anyone maintaining an office, branch, agency or regular practice here.
A person caught only by the equipment limb must nominate a representative established in Malaysia — section 2(3).
The seven principles
Section 5(1) requires compliance with seven Personal Data Protection Principles, each spelled out in its own section.
| # | Principle | Section | The duty in one line |
|---|---|---|---|
| 1 | General | 6 | No processing without consent, unless a s.6(2) ground applies; and the purpose must be lawful, directly related to the controller’s activity, and adequate but not excessive |
| 2 | Notice and Choice | 7 | Written notice of the data, purposes, source, access and correction rights, third-party classes, and whether supply is obligatory — in the national and English languages |
| 3 | Disclosure | 8 | No disclosure outside the collection purpose, or to a party outside the notified class of third parties, without consent |
| 4 | Security | 9 | Practical steps against loss, misuse, modification and unauthorised access, having regard to the nature of the data, storage location, equipment and personnel |
| 5 | Retention | 10 | Keep no longer than necessary; take reasonable steps to destroy or permanently delete when no longer required |
| 6 | Data Integrity | 11 | Reasonable steps to keep data accurate, complete, not misleading and up to date for its purpose |
| 7 | Access | 12 | The data subject may access and correct their data, subject to the statutory refusal grounds |
Contravening section 5(1) is a criminal offence. After Act A1727, the penalty is a fine up to RM1,000,000, imprisonment up to three years, or both — raised from RM300,000 and two years.
What Act A1727 changed
The Personal Data Protection (Amendment) Act 2024 received royal assent on 9 October 2024 and was gazetted on 17 October 2024. P.U.(B) 522/2024 brought it into force in three tranches.
| Date | Sections of A1727 | Effect |
|---|---|---|
| 1 January 2025 | 7, 11, 13, 14 | Drafting corrections, fund administration, service of documents by electronic means, savings |
| 1 April 2025 | 2, 3, 4, 5, 8, 10, 12 | ”Data user” becomes data controller; biometric data added to sensitive personal data; “personal data breach” defined; a deceased individual is no longer a data subject; the Security Principle binds data processors directly; higher s.5(2) penalty; cross-border transfer rules in s.129 rewritten |
| 1 June 2025 | 6, 9 | New Division 1a — mandatory data protection officer (s.12a) and data breach notification to the Commissioner (s.12b); new right to data portability (s.43a) |
Two of those are structural, not cosmetic. Data processors previously owed duties only through their contract with the controller; since 1 April 2025 the Security Principle applies to them directly. And breach notification is a standing duty: the controller must notify the Commissioner as soon as practicable, and notify affected data subjects without unnecessary delay where the breach causes or is likely to cause significant harm.
Common mistakes
- Treating a PDPA notice as consent. Sections 6 and 7 are separate principles with separate duties; issuing a notice does not by itself establish the consent the General Principle requires.
- Issuing the notice in English only. Section 7(3) requires the national and English languages, and requires the means of exercising choice in both.
- Assuming the Act covers a government dataset. It does not — section 3(1).
- Ignoring the criminal character of the Act. These are offences on conviction. Under section 133, where a body corporate commits an offence, its directors, chief executive, managers, secretary and similar officers may be charged with it and are deemed to have committed it unless they prove the offence happened without their knowledge, consent or connivance and that they exercised due diligence.
Where this connects
Employee records are the largest body of personal data most Malaysian businesses hold, so Act 709 sits directly alongside the Employment Act 1955. Tax and duty assessment is one of the section 45(2) exemptions, which touches the Income Tax Act 1967.
What’s next
This page is the statute record. The operating rules — registration of data controllers, the Personal Data Protection Standard, DPO appointment and the data breach notification form — are set by the Commissioner under the Act rather than in the section text, and will be documented in their own articles as that cluster is built.
Does the PDPA apply to Malaysian government agencies?
No. Section 3(1) of Act 709 states plainly that the Act shall not apply to the Federal Government and State Governments. This is the single most common misreading of the Act: a citizen cannot make a PDPA data access request to a federal ministry, because the ministry is outside the Act entirely.
What makes data 'personal data' under Act 709?
Section 4 defines personal data as information in respect of commercial transactions that is processed automatically, recorded with the intention of being so processed, or held in a relevant filing system, and that relates directly or indirectly to an identified or identifiable data subject. Information processed for a credit reporting business under the Credit Reporting Agencies Act 2010 (Act 710) is carved out.
Is a foreign company outside Malaysia caught by the Act?
It can be. Section 2(2)(b) applies the Act to a person not established in Malaysia who uses equipment in Malaysia to process personal data, otherwise than for the purposes of transit through Malaysia. Section 2(3) then requires that person to nominate a representative established in Malaysia.
Are the seven principles absolute?
No. Section 45 exempts certain processing from named principles — for example, data processed for the prevention or detection of crime, for the assessment or collection of tax, for statistics or research, or for journalistic, literary or artistic purposes. Each exemption releases a specific list of principles, not the whole Act, and section 46 lets the Minister grant further exemptions by order.
Sources
- Act 709 — Personal Data Protection Act 2010, full text — Attorney General's Chambers of Malaysia
- Act 709 — principal act timeline, commencement and subsidiary legislation — Attorney General's Chambers of Malaysia
- Personal Data Protection (Amendment) Act 2024 (Act A1727) — Jabatan Perlindungan Data Peribadi (JPDP)
- P.U.(B) 522/2024 — Personal Data Protection (Amendment) Act 2024, appointment of date of coming into operation — Attorney General's Chambers of Malaysia
- Principles of Personal Data Protection — Jabatan Perlindungan Data Peribadi (JPDP)
- Determination of Effective Commencement Date — Act 709 — Jabatan Perlindungan Data Peribadi (JPDP)
- Introduction — Personal Data Protection — Jabatan Perlindungan Data Peribadi (JPDP)
Change history
| Version | Date | Change | By |
|---|---|---|---|
| 01.00 | 24 Jul 2026 | Approved and published. | — |