# Malaysia's Personal Data Protection Act (PDPA): Your Rights and a Business's Duties

> Malaysia's Personal Data Protection Act 2010 governs how businesses collect and use personal data in commercial transactions, built on seven principles and toughened by 2025 amendments that added mandatory data-protection officers, 72-hour breach notification, and RM1 million fines.

- Category: law
- Language: en
- Status: published
- Updated: 2026-08-14
- Canonical: https://negaraku.md/en/law/personal-data-protection-act-2010

---

If a Malaysian company mishandles your personal data today, it now faces a fine of up to **RM1,000,000** — and a duty to tell the regulator within 72 hours. That is the sharp end of the **Personal Data Protection Act 2010 (Act 709)**, or **PDPA**, the law that governs how businesses collect, store and use personal data in **commercial transactions**. A round of amendments that took effect through 2025 gave the Act real teeth. This guide sets out, in plain language, what the PDPA requires of organisations and what it means for the ordinary person whose data is being collected.

## What does the PDPA actually cover?

Act 709 received **Royal Assent on 2 June 2010** and was published in the Gazette on **10 June 2010**, but its operative provisions were only appointed to commence on **15 November 2013** — the same day its first subsidiary legislation (the Class of Data Users Order and the Registration of Data Users Regulations) came into operation.

The PDPA regulates the **processing of personal data in respect of commercial transactions**. It applies broadly to all individuals and organisations that process personal data. There is one major exemption: the **Federal Government and the State Governments** are not bound by the Act.

"Personal data" is defined widely — it is any data that allows a **living individual to be identified**. That includes names, identification numbers, health information, email addresses, photographs and even **CCTV imagery**. "Processing" is equally broad: it covers collecting, recording, storing, organising, changing, disclosing, destroying and even **reading** personal data. In practice, almost anything an organisation does with your details counts.

A narrower category, **sensitive personal data**, gets extra protection. It covers information about a person's physical or mental **health**, **political opinions**, **religious beliefs**, and the **commission of any offence**. The 2024 amendment expanded this category to include **biometric data**.

## What are the seven principles?

The heart of the Act is **Section 5(1)**, which lists seven principles, each then set out in its own section — Sections 6 to 12 — that anyone processing personal data must comply with.

| Principle | Section | What it requires |
|---|---|---|
| General | s6 | Process personal data lawfully and only with the data subject's consent |
| Notice and Choice | s7 | Tell individuals what data is collected, why, and their rights |
| Disclosure | s8 | Do not disclose data for purposes other than those notified, without consent |
| Security | s9 | Take practical steps to protect data from loss, misuse or unauthorised access |
| Retention | s10 | Do not keep data longer than necessary for its purpose |
| Data Integrity | s11 | Keep data accurate, complete, not misleading and up to date |
| Access | s12 | Let individuals access and correct their own data |

For individuals, these principles are effectively a bill of rights: you can expect to be told how your data will be used, to access what an organisation holds about you, to correct it, and to have it kept secure and not over-retained. Breaching the principles is an offence, and — as set out below — the penalty for doing so has risen sharply.

## Who must register with the Commissioner?

Beyond the principles, data controllers that fall within **specified classes** must **register with the Commissioner** online before processing personal data. The **Class of Data Users Order 2013 (P.U.(A) 336)**, made under Section 14, sets out **eleven registrable classes**: communications; banking and financial institutions; insurance; health; tourism and hospitality; transportation; education; direct selling; services (legal, audit, accountancy, engineering, architecture, retail/wholesale dealing and private employment agencies); real estate; and utilities.

Registration certificates carry **expiry dates**. Under **regulation 5(2) of the Registration of Data Users Regulations 2013 (P.U.(A) 337)**, a data controller who fails to renew an expired certificate and keeps processing personal data commits an offence punishable by a fine **not exceeding RM250,000** or imprisonment **not exceeding two years**, or both — a penalty the 2024 amendment left unchanged. (Processing without a certificate of registration at all is a separate, heavier offence under Section 16(4), carrying a fine of up to RM500,000 or three years' imprisonment.)

## What changed in the 2024 amendment?

The **Personal Data Protection (Amendment) Act 2024 (Act A1727)** is the biggest overhaul since the Act began, aligning Malaysia's regime more closely with international standards. It received **Royal Assent on 9 October 2024** and was gazetted on **24 December 2024**, then came into force in three phases:

| Commencement | Provisions |
|---|---|
| 1 January 2025 | Sections 7, 11, 13, 14 — electronic service of notices |
| 1 April 2025 | Sections 2–5, 8, 10, 12 |
| 1 June 2025 | Sections 6, 9 |

The most important substantive changes are these.

**A change of name.** The amendment replaces the term **"data user"** with **"data controller"** throughout the legislation — a shift that also signals alignment with global privacy vocabulary. (The old term survives only in the definition of "register" under Section 4 and in Section 9.)

**Much higher penalties.** From **1 April 2025**, the maximum penalty for breaching the data-protection principles rose to a fine of up to **RM1,000,000** (about USD236,000) and/or imprisonment of up to **three years** — up from the previous RM300,000 and two years.

**Cross-border transfers loosened.** The same tranche **removed the "whitelist" approach** for transferring data abroad. Instead of transfers being limited to a gazetted list of approved countries, data may now be sent to jurisdictions that offer **substantially similar protection** to the PDPA.

**Duties pushed onto processors.** The amendment applied the **Security Principle directly to data processors** for the first time — previously the principles bound only the data controller.

## What do the new breach and DPO rules require?

From **1 June 2025**, two operational duties took effect that every affected organisation should have a process for.

**Mandatory data-breach notification.** A data controller must notify the Commissioner **as soon as practicable and no later than 72 hours** after a data breach occurs. Where the breach is **likely to cause significant harm**, the controller must also notify the **affected individuals within seven days** of the notification to the Commissioner. A breach crosses the mandatory-notification threshold when it causes or is likely to cause **significant harm** — physical harm, financial loss, or a breach involving sensitive personal data — or affects a **significant scale exceeding 1,000 individuals**.

**Mandatory Data Protection Officer (DPO).** Both **data controllers and data processors** must appoint at least one DPO. Appointment is mandatory where the organisation:

- processes personal data of **20,000 or more** data subjects; or
- processes **sensitive personal data (including financial data) of 10,000 or more** data subjects; or
- carries out processing that involves **regular and systematic monitoring**.

The appointed DPO must be **registered with the Commissioner within 21 days** of appointment.

**A new data-portability right.** Individuals gained the right to request that their personal data be **transmitted to another data controller**, subject to technical feasibility and the compatibility of the data format.

## What should a Malaysian business do now?

For an SME, the practical checklist follows directly from the thresholds above:

- Count your data subjects. If you hold data on **20,000+ people** — or sensitive data on **10,000+** — you must appoint and register a DPO.
- Have a **breach-response plan** that can hit the **72-hour** clock, including how you will assess "significant harm" and the **1,000-individual** scale trigger.
- Re-check your **notice, consent and retention** practices against the seven principles, now backed by a **RM1,000,000** penalty.
- If you are a **data processor**, remember the Security Principle now applies to you directly.

## What's next

The PDPA has moved from a light-touch statute to an enforceable regime with real financial exposure, and the regulator continues to publish guidelines that flesh out the amended Act — including the 2025 Cross-Border Personal Data Transfer Guidelines that supplement the loosened transfer regime. For the authoritative text, the registrable classes, and the latest guidance on breach notification and DPO appointment, consult the Department of Personal Data Protection (JPDP) at [pdp.gov.my](https://www.pdp.gov.my/ppdpv1/en/faq/).

## Sources

- FAQ — Personal Data Protection — https://www.pdp.gov.my/ppdpv1/en/faq/ (Department of Personal Data Protection (JPDP), Malaysia)
- Principles of Personal Data Protection — https://www.pdp.gov.my/ppdpv1/en/principles-of-personal-data-protection/ (Department of Personal Data Protection (JPDP), Malaysia)
- Personal Data Protection (Amendment) Act 2024 — https://www.pdp.gov.my/ppdpv1/en/akta/personal-data-protection-amendment-act-2024/ (Department of Personal Data Protection (JPDP), Malaysia)
- Malaysia: Implementation of the Personal Data Protection (Amendment) Act 2024 — https://www.dfdl.com/insights/legal-and-tax-updates/malaysia-implementation-of-the-personal-data-protection-amendment-act-2024/ (DFDL)
- From Legislative Reform to Practical Guidance: Key Amendments to Malaysia's PDPA — https://www.mayerbrown.com/en/insights/publications/2025/07/from-legislative-reform-to-practical-guidance-key-amendments-to-malaysias-pdpa-and-the-launch-of-cross-border-transfer-guidelines (Mayer Brown)
- Launch of the Personal Data Protection Guidelines for Mandatory Data Breach Notification and DPO Appointment — https://www.christopherleeong.com/viewpoints/launch-of-the-personal-data-protection-guidelines-for-mandatory-data-breach-notification-and-data-protection-officer-appointment/ (Christopher & Lee Ong (Rajah & Tann Asia))
- Malaysia's PDPA amendments: Delivering enhanced data governance and transparency — https://iapp.org/news/a/malaysia-s-pdpa-amendments-delivering-enhanced-data-governance-and-transparency (International Association of Privacy Professionals (IAPP))
- Personal Data Protection Act 2010 (Act 709) — original certified text (front page: Royal Assent and Gazette dates; ss5–12, the seven principles) — https://lom.agc.gov.my/ilims/upload/portal/akta/outputaktap/Act%20709%20ori.pdf (Attorney-General's Chambers of Malaysia (AGC), lom.agc.gov.my)
- Personal Data Protection (Class of Data Users) Order 2013, P.U.(A) 336 — Schedule listing the 11 registrable classes (commencement 15 November 2013) — https://www.pdp.gov.my/ppdpv1/wp-content/uploads/2024/07/Perintah-Perlindungan-Data-Peribadi-.pdf (Department of Personal Data Protection (JPDP) / AGC Federal Gazette)
- Personal Data Protection (Registration of Data Users) Regulations 2013, P.U.(A) 337 — reg 5(2) renewal-lapse penalty (RM250,000 / 2 years) — https://www.pdp.gov.my/ppdpv1/wp-content/uploads/2024/07/pua_20131114_P.U._A_337_-_peraturan-peraturan_perlindungan_data_peribadi_pendaftaran_pengguna_data_2013.pdf (Department of Personal Data Protection (JPDP) / AGC Federal Gazette)
- Personal Data Protection (Amendment) Act 2024 (Act A1727) — certified text (s9 new s43a data portability; s12 s129 cross-border amendment) — https://www.pdp.gov.my/ppdpv1/wp-content/uploads/2024/11/Act-A1727.pdf (Department of Personal Data Protection (JPDP) / AGC Federal Gazette)
- Appointment of Date of Coming into Operation, P.U.(B) 522 (24 December 2024) — phased commencement dates — https://www.pdp.gov.my/ppdpv1/wp-content/uploads/2024/12/PENETAPAN-TARIKH-PERMULAAN-KUAT-KUASA-2.pdf (Department of Personal Data Protection (JPDP) / AGC Federal Gazette)

---
Source of truth: https://github.com/negaraku-md/NegaraKu.md
License: CC BY-SA 4.0
