The Personal Data Protection Act 2010 (Act 709), or PDPA, is Malaysia's law for the protection of personal data used in commercial transactions. It is built on seven data-protection principles, enforced by the Personal Data Protection Commissioner, and applies to organisations that process personal data — while the Federal and State Governments are exempt. A 2024 amendment, in force in stages through 2025, raised the maximum fine to RM1,000,000, added mandatory data-breach notification, and required many organisations to appoint a data-protection officer.
- Act 709 regulates the processing of personal data in commercial transactions and applies to all individuals and organisations that process it; the Federal and State Governments are exempt.
- Section 5(1) sets out seven principles: General, Notice and Choice, Disclosure, Security, Retention, Data Integrity and Access.
- The Amendment Act 2024 renamed 'data user' to 'data controller' and, from 1 April 2025, raised the principle-breach penalty to a fine up to RM1,000,000 and/or 3 years' jail.
- Since 1 June 2025, data controllers and processors must appoint at least one data-protection officer, notify the Commissioner of a breach within 72 hours, and honour a new data-portability right.
- A DPO is mandatory once an organisation processes personal data of 20,000+ people, sensitive data of 10,000+ people, or carries out regular and systematic monitoring.
Who this applies to: Businesses and SMEs that collect or process personal data in Malaysia, compliance and legal teams, and individuals who want to understand their data-protection rights.
On this page
If a Malaysian company mishandles your personal data today, it now faces a fine of up to RM1,000,000 — and a duty to tell the regulator within 72 hours. That is the sharp end of the Personal Data Protection Act 2010 (Act 709), or PDPA, the law that governs how businesses collect, store and use personal data in commercial transactions. A round of amendments that took effect through 2025 gave the Act real teeth. This guide sets out, in plain language, what the PDPA requires of organisations and what it means for the ordinary person whose data is being collected.
What does the PDPA actually cover?
Act 709 received Royal Assent on 2 June 2010 and was published in the Gazette on 10 June 2010, but its operative provisions were only appointed to commence on 15 November 2013 — the same day its first subsidiary legislation (the Class of Data Users Order and the Registration of Data Users Regulations) came into operation.
The PDPA regulates the processing of personal data in respect of commercial transactions. It applies broadly to all individuals and organisations that process personal data. There is one major exemption: the Federal Government and the State Governments are not bound by the Act.
“Personal data” is defined widely — it is any data that allows a living individual to be identified. That includes names, identification numbers, health information, email addresses, photographs and even CCTV imagery. “Processing” is equally broad: it covers collecting, recording, storing, organising, changing, disclosing, destroying and even reading personal data. In practice, almost anything an organisation does with your details counts.
A narrower category, sensitive personal data, gets extra protection. It covers information about a person’s physical or mental health, political opinions, religious beliefs, and the commission of any offence. The 2024 amendment expanded this category to include biometric data.
What are the seven principles?
The heart of the Act is Section 5(1), which lists seven principles, each then set out in its own section — Sections 6 to 12 — that anyone processing personal data must comply with.
| Principle | Section | What it requires |
|---|---|---|
| General | s6 | Process personal data lawfully and only with the data subject’s consent |
| Notice and Choice | s7 | Tell individuals what data is collected, why, and their rights |
| Disclosure | s8 | Do not disclose data for purposes other than those notified, without consent |
| Security | s9 | Take practical steps to protect data from loss, misuse or unauthorised access |
| Retention | s10 | Do not keep data longer than necessary for its purpose |
| Data Integrity | s11 | Keep data accurate, complete, not misleading and up to date |
| Access | s12 | Let individuals access and correct their own data |
For individuals, these principles are effectively a bill of rights: you can expect to be told how your data will be used, to access what an organisation holds about you, to correct it, and to have it kept secure and not over-retained. Breaching the principles is an offence, and — as set out below — the penalty for doing so has risen sharply.
Who must register with the Commissioner?
Beyond the principles, data controllers that fall within specified classes must register with the Commissioner online before processing personal data. The Class of Data Users Order 2013 (P.U.(A) 336), made under Section 14, sets out eleven registrable classes: communications; banking and financial institutions; insurance; health; tourism and hospitality; transportation; education; direct selling; services (legal, audit, accountancy, engineering, architecture, retail/wholesale dealing and private employment agencies); real estate; and utilities.
Registration certificates carry expiry dates. Under regulation 5(2) of the Registration of Data Users Regulations 2013 (P.U.(A) 337), a data controller who fails to renew an expired certificate and keeps processing personal data commits an offence punishable by a fine not exceeding RM250,000 or imprisonment not exceeding two years, or both — a penalty the 2024 amendment left unchanged. (Processing without a certificate of registration at all is a separate, heavier offence under Section 16(4), carrying a fine of up to RM500,000 or three years’ imprisonment.)
What changed in the 2024 amendment?
The Personal Data Protection (Amendment) Act 2024 (Act A1727) is the biggest overhaul since the Act began, aligning Malaysia’s regime more closely with international standards. It received Royal Assent on 9 October 2024 and was gazetted on 24 December 2024, then came into force in three phases:
| Commencement | Provisions |
|---|---|
| 1 January 2025 | Sections 7, 11, 13, 14 — electronic service of notices |
| 1 April 2025 | Sections 2–5, 8, 10, 12 |
| 1 June 2025 | Sections 6, 9 |
The most important substantive changes are these.
A change of name. The amendment replaces the term “data user” with “data controller” throughout the legislation — a shift that also signals alignment with global privacy vocabulary. (The old term survives only in the definition of “register” under Section 4 and in Section 9.)
Much higher penalties. From 1 April 2025, the maximum penalty for breaching the data-protection principles rose to a fine of up to RM1,000,000 (about USD236,000) and/or imprisonment of up to three years — up from the previous RM300,000 and two years.
Cross-border transfers loosened. The same tranche removed the “whitelist” approach for transferring data abroad. Instead of transfers being limited to a gazetted list of approved countries, data may now be sent to jurisdictions that offer substantially similar protection to the PDPA.
Duties pushed onto processors. The amendment applied the Security Principle directly to data processors for the first time — previously the principles bound only the data controller.
What do the new breach and DPO rules require?
From 1 June 2025, two operational duties took effect that every affected organisation should have a process for.
Mandatory data-breach notification. A data controller must notify the Commissioner as soon as practicable and no later than 72 hours after a data breach occurs. Where the breach is likely to cause significant harm, the controller must also notify the affected individuals within seven days of the notification to the Commissioner. A breach crosses the mandatory-notification threshold when it causes or is likely to cause significant harm — physical harm, financial loss, or a breach involving sensitive personal data — or affects a significant scale exceeding 1,000 individuals.
Mandatory Data Protection Officer (DPO). Both data controllers and data processors must appoint at least one DPO. Appointment is mandatory where the organisation:
- processes personal data of 20,000 or more data subjects; or
- processes sensitive personal data (including financial data) of 10,000 or more data subjects; or
- carries out processing that involves regular and systematic monitoring.
The appointed DPO must be registered with the Commissioner within 21 days of appointment.
A new data-portability right. Individuals gained the right to request that their personal data be transmitted to another data controller, subject to technical feasibility and the compatibility of the data format.
What should a Malaysian business do now?
For an SME, the practical checklist follows directly from the thresholds above:
- Count your data subjects. If you hold data on 20,000+ people — or sensitive data on 10,000+ — you must appoint and register a DPO.
- Have a breach-response plan that can hit the 72-hour clock, including how you will assess “significant harm” and the 1,000-individual scale trigger.
- Re-check your notice, consent and retention practices against the seven principles, now backed by a RM1,000,000 penalty.
- If you are a data processor, remember the Security Principle now applies to you directly.
What’s next
The PDPA has moved from a light-touch statute to an enforceable regime with real financial exposure, and the regulator continues to publish guidelines that flesh out the amended Act — including the 2025 Cross-Border Personal Data Transfer Guidelines that supplement the loosened transfer regime. For the authoritative text, the registrable classes, and the latest guidance on breach notification and DPO appointment, consult the Department of Personal Data Protection (JPDP) at pdp.gov.my.
Does the PDPA apply to the government?
No. The Act regulates the processing of personal data in commercial transactions and applies to all individuals and organisations that process such data, but the Federal Government and State Governments are exempt.
What is the penalty for breaching the seven principles?
From 1 April 2025 the maximum penalty for breaching the data-protection principles is a fine up to RM1,000,000 and/or imprisonment up to 3 years — raised from the previous RM300,000 and 2 years.
When must a data breach be reported?
A data controller must notify the Commissioner as soon as practicable and no later than 72 hours after a breach occurs, and must notify affected individuals within 7 days of that notice where the breach is likely to cause significant harm.
Sources
- FAQ — Personal Data Protection — Department of Personal Data Protection (JPDP), Malaysia
- Principles of Personal Data Protection — Department of Personal Data Protection (JPDP), Malaysia
- Personal Data Protection (Amendment) Act 2024 — Department of Personal Data Protection (JPDP), Malaysia
- Malaysia: Implementation of the Personal Data Protection (Amendment) Act 2024 — DFDL
- From Legislative Reform to Practical Guidance: Key Amendments to Malaysia's PDPA — Mayer Brown
- Launch of the Personal Data Protection Guidelines for Mandatory Data Breach Notification and DPO Appointment — Christopher & Lee Ong (Rajah & Tann Asia)
- Malaysia's PDPA amendments: Delivering enhanced data governance and transparency — International Association of Privacy Professionals (IAPP)
- Personal Data Protection Act 2010 (Act 709) — original certified text (front page: Royal Assent and Gazette dates; ss5–12, the seven principles) — Attorney-General's Chambers of Malaysia (AGC), lom.agc.gov.my
- Personal Data Protection (Class of Data Users) Order 2013, P.U.(A) 336 — Schedule listing the 11 registrable classes (commencement 15 November 2013) — Department of Personal Data Protection (JPDP) / AGC Federal Gazette
- Personal Data Protection (Registration of Data Users) Regulations 2013, P.U.(A) 337 — reg 5(2) renewal-lapse penalty (RM250,000 / 2 years) — Department of Personal Data Protection (JPDP) / AGC Federal Gazette
- Personal Data Protection (Amendment) Act 2024 (Act A1727) — certified text (s9 new s43a data portability; s12 s129 cross-border amendment) — Department of Personal Data Protection (JPDP) / AGC Federal Gazette
- Appointment of Date of Coming into Operation, P.U.(B) 522 (24 December 2024) — phased commencement dates — Department of Personal Data Protection (JPDP) / AGC Federal Gazette
Change history
| Version | Date | Change | By |
|---|---|---|---|
| 01.00 | 14 Aug 2026 | Approved and published. | — |