The Agent Switched Companies. Your Data Went With Them.

If you have not read my last post, I wrote about a case where customers on a water filter hire purchase plan started getting called by multiple agents from the same company around contract renewal time. That one was about internal data mismanagement, agents within the same company accessing customer data without proper oversight.

This one is different. But it might involve the same industry.

I came across cases where people got a call from a company they have never dealt with before. The person on the other end knows their name, knows roughly what product they are using, and is pitching an upgrade or a switch. The customer is confused. They never gave this company their number. They never signed anything with them.

Quick Summary
  • A sales agent who moves to a new employer cannot legally bring customer contact lists with them.
  • Customer data belongs to the company, not the individual agent who collected it.
  • The new company is equally liable for using unverified data sources for sales calls.
  • This is a double PDPA violation: unauthorised data extraction and unauthorised data processing.
  • Both companies can be reported. Compensation can reach RM25,000 under PDPA.

What Actually Happened

The agent who called used to work somewhere else. At their previous job, they had access to a customer database. When they left, they took some of that data with them. A list of contacts, maybe in a spreadsheet, maybe just saved in their phone. And now at their new company, they are using it to make sales calls.

This happens more than people think, especially in industries where agents move between competing companies and bring their "leads" with them. It feels like a normal sales practice. It is not. It is a breach of two separate obligations under PDPA.

Two Violations, One Phone Call

The first violation is on the agent. Taking customer data from a former employer without authorisation is illegal. It does not matter if they collected it themselves while working there. That data belongs to the company as the data controller, not to the individual. Walking out the door with it is an unauthorised disclosure and a breach of the security principle under PDPA.

The second violation is on the new company. The moment they allow their agents to use data from unverified sources to make sales calls, they become responsible for how that data is being processed. A proper data controller would have SOPs that require agents to only use data that was legitimately collected with customer consent. If nobody asked where the leads came from, that is a data governance failure and the company bears the liability for it.

Where the DPO Should Have Caught This

A DPO that is actively doing their job would have flagged this during the agent onboarding process. When a new hire joins with a ready-made contact list, the first question should be: where did this data come from, was it collected with consent, and do we have the right to use it? Those are not complicated questions. They just need to be asked.

In April 2026, the Department of Personal Data Protection released new guidelines under Data Protection by Design. The principle is that privacy controls are built into how the team operates, not added after something goes wrong. A company with proper data governance would never allow agents to import personal contact lists from previous employers because the system itself would not permit it without a verified lawful basis.

If that conversation is not happening during onboarding, it is a gap that will eventually become a complaint.

What You Can Do

If you received a call from a company you have no prior relationship with and they somehow have your details, here is what to do.

Send a written notice to the company that called you. State that you never consented to them holding or using your personal data and demand that they delete it immediately and confirm deletion in writing. CC the Personal Data Protection Commissioner in that same email.

Also write to the original company where your data likely came from. They have a duty under PDPA to investigate how their customer data ended up in the hands of a competitor. A formal written request forces them to take it seriously.

If neither company responds appropriately, file a complaint at pdp.gov.my. This kind of cross-company data transfer without consent is taken seriously under PDPA. Compensation for a proven breach can go up to RM25,000.

The uncomfortable truth is that your data can follow you even when you never agreed to go anywhere.

If your company hires sales agents and you are not sure how your customer data is being managed across staff transitions, reach out to us on WhatsApp. This is exactly the kind of risk a proper DPO helps you get ahead of.