When Multiple Agents Call About Your Water Filter Contract

I came across some cases lately where people on water filter hire purchase plans started getting calls from multiple agents once their contract was coming to an end. Not one call. Multiple. Different agents, different names, same pitch.

Most people brushed it off as bad customer service. But the more I looked at it, the clearer it became that this is actually a PDPA issue. And a fairly serious one.

Quick Summary
  • Personal data collected for a hire purchase contract can only be used for that service. Not renewals, not upsells.
  • Multiple agents calling the same customer signals a data governance failure, not just a process issue.
  • Companies are required to have a Data Protection Officer who sets proper SOPs for data access.
  • The April 2026 guidelines make the DPO role operational, not ceremonial.
  • You can withdraw consent in writing and CC the Personal Data Protection Commissioner. Compensation under PDPA can go up to RM25,000.

Why This Is a Data Problem, Not Just a Service Problem

When someone signs up for a water filter hire purchase plan, they hand over their personal details, name, phone number, address, for the purpose of that service agreement. That is the only reason the data exists in that company's system. Not for renewal campaigns. Not for upsell calls. Just the service.

So when that number gets passed around to multiple agents who are all calling independently about the same thing, it means the company has no real control over how customer data is being accessed internally. Under PDPA, this is a purpose limitation issue. Data collected for one reason cannot be used for another without fresh consent.

One agent calling could be standard process. Multiple agents calling the same customer means customer records are accessible to a wider pool of people than necessary, there is no internal tracking of who has contacted whom, and nobody is watching whether consent exists for these renewal calls in the first place. That is not a coordination failure. That is a compliance failure.

Where the DPO Should Have Stepped In

Every company that handles customer data is supposed to have a Data Protection Officer. The DPO's job is to make sure there are proper policies and SOPs in place. Who can pull customer data, under what circumstances, and for what purpose. If multiple agents can independently contact the same customer with no oversight, then either the DPO exists on paper only, or there is no DPO at all.

A functioning DPO would have flagged this at the SOP level. Renewal outreach should have a defined process: one designated team, clear records of consent, and a limit on how many times a customer can be contacted. Without that structure, agents act on their own judgment, and customers get repeated calls from people who have no idea someone else already called.

What the April 2026 Guidelines Say About This

In April 2026, the Department of Personal Data Protection released three new guidelines covering Data Protection Impact Assessment, Data Protection by Design, and Automated Decision Making. All three place the DPO at the centre of implementation.

The DPO role has officially shifted from ceremonial to operational. Companies can no longer have a DPO in name only. They are expected to be actively shaping how data is handled day to day, reviewing systems before they go live, and ensuring governance frameworks are in place before customer data is touched.

For a company running a hire purchase business with thousands of customers, not having that governance in place today is not an oversight. It is a choice. And under the updated framework, it is an increasingly exposed one.

What You Can Do

If this has happened to you, start with a written notice. Send them an email clearly stating that you are withdrawing consent for any use of your personal data beyond your original service agreement. No renewal calls, no marketing, nothing. In that same email, CC the office of the Personal Data Protection Commissioner. That CC matters because it signals you know your rights and you are not just complaining to customer service.

Most companies will act quickly once they see that.

If the calls continue after that, file a formal complaint at pdp.gov.my. That moves it from a customer service issue into a regulatory one. Under PDPA, a proven breach can result in compensation of up to RM25,000.

The frustrating part is most people never take that first step because they assume nothing will come of it. But a single well-worded email with the right CC has resolved cases like this before a formal complaint was ever needed.

You have more leverage than you think.

If your organisation handles customer data and you are not sure your team has the right SOPs in place, reach out to us on WhatsApp. We help Malaysian businesses build proper data governance frameworks.