Home / Understand Malaysia / Law & Regulations / Key Acts

🧭 Practical ✓ Published: 25 Jul 2026 5 min read

Personal Data Protection Act 2010 (Act 709) — the seven principles, and the scope limit most readers miss

Statute entity page for Malaysia's data protection law — what Act 709 actually covers (personal data in commercial transactions, and nothing else), the seven Personal Data Protection Principles in sections 6 to 12, who is caught by the establishment and equipment tests, and what the 2024 amendment changed.

30-second answer Reviewed 25 Jul 2026

The Personal Data Protection Act 2010 (Act 709) came into operation on 15 November 2013 and regulates the processing of personal data in respect of commercial transactions. It does not apply to the Federal Government or State Governments, nor to data an individual processes purely for personal, family or household affairs. Its core duties are the seven Personal Data Protection Principles in sections 6 to 12, enforced by the Personal Data Protection Commissioner.

  • Act 709; royal assent 2 June 2010, gazetted 10 June 2010, in force 15 November 2013 by P.U.(B) 464/2013
  • Scope is limited to personal data 'in respect of commercial transactions' (s.2(1)) — that phrase is the whole boundary of the Act
  • Section 3(1): the Act does not apply to the Federal Government and State Governments
  • Seven principles: General, Notice and Choice, Disclosure, Security, Retention, Data Integrity, Access (s.5, set out in ss.6–12)
  • Contravening the principles is a criminal offence, not just a regulatory one — fine up to RM1,000,000 or three years' imprisonment, or both (s.5(2) as amended)
  • A person not established in Malaysia but using equipment in Malaysia to process data is caught, and must nominate a local representative (s.2(2)(b), s.2(3))
  • The Personal Data Protection (Amendment) Act 2024 (Act A1727) renamed 'data user' to 'data controller' and added DPO, breach notification and data portability duties in phases across 2025

Who this applies to: Readers who need the statutory identity, scope and principle structure of Act 709 — not a compliance procedure for any single obligation.

On this page
Full explanation ≈5 min

Most people describe Act 709 as “Malaysia’s privacy law”. The Act itself makes a much narrower claim. Its long title is an Act to regulate the processing of personal data in commercial transactions — and section 3(1) then removes the Federal Government and State Governments from its reach entirely.

That boundary, not the seven principles, is where most PDPA questions are actually decided.

At a glance

Short titlePersonal Data Protection Act 2010
Act numberAct 709
Royal assent2 June 2010
Gazetted10 June 2010
Commencement15 November 2013, by P.U.(B) 464/2013
ScopePersonal data processed in respect of commercial transactions
RegulatorPersonal Data Protection Commissioner (s.47), Jabatan Perlindungan Data Peribadi
Principal amendmentPersonal Data Protection (Amendment) Act 2024 (Act A1727)

The scope limit

Section 2(1) applies the Act to any person who processes, or who has control over or authorises the processing of, any personal data in respect of commercial transactions. Section 4 defines a commercial transaction as any transaction of a commercial nature, contractual or not, including the supply or exchange of goods or services, agency, investments, financing, banking and insurance.

Three carve-outs follow, and each one surprises somebody:

  • Government is out. Section 3(1): the Act shall not apply to the Federal Government and State Governments.
  • Offshore processing is out unless it comes back. Section 3(2): the Act does not apply to personal data processed outside Malaysia, unless that data is intended to be further processed in Malaysia.
  • Household use is out. Section 45(1) exempts personal data processed by an individual only for that individual’s personal, family or household affairs, including recreational purposes.

Credit reporting is also excluded from the definition of personal data — that activity sits under the Credit Reporting Agencies Act 2010 (Act 710) instead.

Who is caught

Section 2(2) reaches a person if either limb applies:

LimbTest
s.2(2)(a)The person is established in Malaysia, and the data is processed by them or by anyone employed or engaged by that establishment
s.2(2)(b)The person is not established in Malaysia but uses equipment in Malaysia to process the data, otherwise than for transit through Malaysia

Section 2(4) defines “established in Malaysia” concretely: an individual physically present in Malaysia for not less than 180 days in a calendar year; a body incorporated under the Companies Act (see Companies Act 2016); a partnership or unincorporated association formed under Malaysian written law; or anyone maintaining an office, branch, agency or regular practice here.

A person caught only by the equipment limb must nominate a representative established in Malaysia — section 2(3).

The seven principles

Section 5(1) requires compliance with seven Personal Data Protection Principles, each spelled out in its own section.

#PrincipleSectionThe duty in one line
1General6No processing without consent, unless a s.6(2) ground applies; and the purpose must be lawful, directly related to the controller’s activity, and adequate but not excessive
2Notice and Choice7Written notice of the data, purposes, source, access and correction rights, third-party classes, and whether supply is obligatory — in the national and English languages
3Disclosure8No disclosure outside the collection purpose, or to a party outside the notified class of third parties, without consent
4Security9Practical steps against loss, misuse, modification and unauthorised access, having regard to the nature of the data, storage location, equipment and personnel
5Retention10Keep no longer than necessary; take reasonable steps to destroy or permanently delete when no longer required
6Data Integrity11Reasonable steps to keep data accurate, complete, not misleading and up to date for its purpose
7Access12The data subject may access and correct their data, subject to the statutory refusal grounds

Contravening section 5(1) is a criminal offence. After Act A1727, the penalty is a fine up to RM1,000,000, imprisonment up to three years, or both — raised from RM300,000 and two years.

What Act A1727 changed

The Personal Data Protection (Amendment) Act 2024 received royal assent on 9 October 2024 and was gazetted on 17 October 2024. P.U.(B) 522/2024 brought it into force in three tranches.

DateSections of A1727Effect
1 January 20257, 11, 13, 14Drafting corrections, fund administration, service of documents by electronic means, savings
1 April 20252, 3, 4, 5, 8, 10, 12”Data user” becomes data controller; biometric data added to sensitive personal data; “personal data breach” defined; a deceased individual is no longer a data subject; the Security Principle binds data processors directly; higher s.5(2) penalty; cross-border transfer rules in s.129 rewritten
1 June 20256, 9New Division 1a — mandatory data protection officer (s.12a) and data breach notification to the Commissioner (s.12b); new right to data portability (s.43a)

Two of those are structural, not cosmetic. Data processors previously owed duties only through their contract with the controller; since 1 April 2025 the Security Principle applies to them directly. And breach notification is a standing duty: the controller must notify the Commissioner as soon as practicable, and notify affected data subjects without unnecessary delay where the breach causes or is likely to cause significant harm.

Common mistakes

  • Treating a PDPA notice as consent. Sections 6 and 7 are separate principles with separate duties; issuing a notice does not by itself establish the consent the General Principle requires.
  • Issuing the notice in English only. Section 7(3) requires the national and English languages, and requires the means of exercising choice in both.
  • Assuming the Act covers a government dataset. It does not — section 3(1).
  • Ignoring the criminal character of the Act. These are offences on conviction. Under section 133, where a body corporate commits an offence, its directors, chief executive, managers, secretary and similar officers may be charged with it and are deemed to have committed it unless they prove the offence happened without their knowledge, consent or connivance and that they exercised due diligence.

Where this connects

Employee records are the largest body of personal data most Malaysian businesses hold, so Act 709 sits directly alongside the Employment Act 1955. Tax and duty assessment is one of the section 45(2) exemptions, which touches the Income Tax Act 1967.

What’s next

This page is the statute record. The operating rules — registration of data controllers, the Personal Data Protection Standard, DPO appointment and the data breach notification form — are set by the Commissioner under the Act rather than in the section text, and will be documented in their own articles as that cluster is built.

Frequently asked 4
Does the PDPA apply to Malaysian government agencies?

No. Section 3(1) of Act 709 states plainly that the Act shall not apply to the Federal Government and State Governments. This is the single most common misreading of the Act: a citizen cannot make a PDPA data access request to a federal ministry, because the ministry is outside the Act entirely.

What makes data 'personal data' under Act 709?

Section 4 defines personal data as information in respect of commercial transactions that is processed automatically, recorded with the intention of being so processed, or held in a relevant filing system, and that relates directly or indirectly to an identified or identifiable data subject. Information processed for a credit reporting business under the Credit Reporting Agencies Act 2010 (Act 710) is carved out.

Is a foreign company outside Malaysia caught by the Act?

It can be. Section 2(2)(b) applies the Act to a person not established in Malaysia who uses equipment in Malaysia to process personal data, otherwise than for the purposes of transit through Malaysia. Section 2(3) then requires that person to nominate a representative established in Malaysia.

Are the seven principles absolute?

No. Section 45 exempts certain processing from named principles — for example, data processed for the prevention or detection of crime, for the assessment or collection of tax, for statistics or research, or for journalistic, literary or artistic purposes. Each exemption releases a specific list of principles, not the whole Act, and section 46 lets the Minister grant further exemptions by order.

Sources & history 7 sources

Sources

  1. Act 709 — Personal Data Protection Act 2010, full text — Attorney General's Chambers of Malaysia
  2. Act 709 — principal act timeline, commencement and subsidiary legislation — Attorney General's Chambers of Malaysia
  3. Personal Data Protection (Amendment) Act 2024 (Act A1727) — Jabatan Perlindungan Data Peribadi (JPDP)
  4. P.U.(B) 522/2024 — Personal Data Protection (Amendment) Act 2024, appointment of date of coming into operation — Attorney General's Chambers of Malaysia
  5. Principles of Personal Data Protection — Jabatan Perlindungan Data Peribadi (JPDP)
  6. Determination of Effective Commencement Date — Act 709 — Jabatan Perlindungan Data Peribadi (JPDP)
  7. Introduction — Personal Data Protection — Jabatan Perlindungan Data Peribadi (JPDP)

Change history

Version Date Change By
01.00 24 Jul 2026 Approved and published.
More in Key Acts View all 11 →
Related knowledge