What Is the PDPA in Malaysia? A Plain-Language Guide for Business Owners
If you run a business in Malaysia and someone has mentioned PDPA to you — your lawyer, your IT team, a consultant, maybe an article like this one — you have probably wondered what it actually is and whether it genuinely applies to you.
Here is the plain-language version.
The One-Paragraph Version
PDPA (Personal Data Protection Act 2010, Act 709) is Malaysia's federal law that governs how organisations collect, use, store, and share personal data. It applies to any organisation processing personal data in Malaysia as part of a commercial transaction. If you have a customer database, employee records, or collect any personal information as part of your business operations, PDPA applies to you. The 2024 Amendment, which came into force on 1 June 2025, significantly raised penalties and introduced new obligations including mandatory DPO appointment and 72-hour breach notification.
Why Does This Law Exist?
Before PDPA came into force in 2013, Malaysia had no single comprehensive law protecting personal data. Organisations could collect as much personal data as they liked, share it freely with third parties, keep it indefinitely, and face virtually no consequences for mishandling it.
The result was predictable. Data brokers bought and sold consumer databases. Telemarketers called people who had never signed up for anything. Banks shared customer information with insurance affiliates without explicit consent. Medical records sat in unlocked filing cabinets. Employee personal data was misused.
PDPA was designed to change this — to give individuals rights over their personal data and to create legal accountability for organisations that collect and use it.
What Does PDPA Actually Cover?
PDPA applies to the processing of personal data in connection with commercial transactions in Malaysia.
Let's unpack that phrase.
"Personal data" means any information that can be used to identify a living individual, directly or indirectly. This includes obvious things like names, IC numbers, phone numbers, and email addresses. It also includes less obvious things like employee payroll records, customer transaction histories, photos, CCTV footage, location data, and in some contexts, IP addresses.
"Processing" covers a very wide range of activities: collecting data, storing it, using it, modifying it, sharing it with others, and deleting it. If your organisation does any of these things with personal data, you are processing it under PDPA.
"Commercial transactions" means any transaction of a commercial nature. Running a clinic, operating a school, managing a rental property, running a recruitment agency, selling products online — all of these are commercial activities. The exemption for non-commercial or personal use is narrow and does not apply to most business operations.
A Common Misconception
Some businesses believe PDPA only applies to large corporations or certain regulated industries. This is not accurate. PDPA applies to any organisation processing personal data commercially in Malaysia, regardless of size or sector. The only meaningful size differentiation in the Act is the DPO appointment threshold (20,000 records), which determines whether a specific role is legally mandatory — not whether PDPA applies at all.
Who Is the Regulator?
PDPA is administered by the Department of Personal Data Protection (Jabatan Perlindungan Data Peribadi, or JPDP), under the Ministry of Digital. The head of JPDP is the Personal Data Protection Commissioner.
The Commissioner has the authority to investigate complaints, conduct audits, issue enforcement notices, impose fines, and refer cases for prosecution. Since the 2024 Amendment, JPDP's enforcement activity has increased alongside the higher penalties available.
If a member of the public believes their personal data has been mishandled, they can file a complaint with JPDP. The Commissioner investigates and can require the organisation to take corrective action or face penalties.
The Seven Data Protection Principles
PDPA is structured around seven principles. Every obligation in the Act flows from one or more of these.
General Principle: You must have a valid basis to process personal data. Typically this is consent, a contract, a legal obligation, or a legitimate interest. You cannot simply collect data because it might be useful someday.
Notice and Choice Principle: At the point of collecting personal data, you must tell the individual what you are collecting, why, who you might share it with, and how they can access or correct their data. This is why every legitimate website has a Privacy Notice linked from its forms.
Disclosure Principle: You cannot share personal data with third parties without consent, except in limited circumstances (legal obligation, contracts with data processors, etc.).
Security Principle: You must implement practical security measures to protect personal data from unauthorised access, loss, or misuse. "Practical" is contextual — a hospital's security measures should be more robust than a small florist's — but no organisation gets a pass on basic security.
Retention Principle: Keep personal data only as long as you need it for the purpose for which it was collected. After that, it should be deleted or anonymised.
Data Integrity Principle: Take reasonable steps to ensure personal data is accurate and up to date. If a customer tells you their address has changed, update it.
Access Principle: Individuals have the right to access their personal data held by your organisation and to request corrections if the data is wrong.
What Changed With the 2024 Amendment?
The Personal Data Protection (Amendment) Act 2024 received royal assent and came into force on 1 June 2025. It was the most substantial update to Malaysia's data protection framework in 15 years.
The main changes:
Mandatory DPO appointment. Organisations processing personal data of 20,000 or more individuals, or sensitive data of 10,000 or more, must appoint a Data Protection Officer. This is a new obligation — it did not exist under the original 2010 Act.
72-hour breach notification. If your organisation suffers a data breach, you must notify the Personal Data Protection Commissioner within 72 hours of becoming aware of it. Affected individuals must also be notified. This is a hard deadline, not a guideline.
Significantly higher penalties. The maximum fine was increased to RM 1 million per offence. Directors, managers, and senior officers can now be held personally liable — meaning individuals can be fined and imprisoned, not just the corporate entity.
Data Protection by Design. Working alongside the new JPDP guidelines released in April 2026, the Amendment encourages (and in practice requires) organisations to build data protection into new systems and processes from the start, rather than adding privacy controls as an afterthought.
Expanded sensitive data categories. The definition of sensitive personal data, which attracts stricter processing requirements, was broadened under the Amendment.
How Does PDPA Affect My Business Day-to-Day?
In practice, PDPA compliance shows up in several recurring ways:
Your website and intake forms. Every form that collects personal data needs to link to a Privacy Notice that explains how that data will be used.
Your marketing activities. Email campaigns, WhatsApp blasts, and SMS marketing all require valid consent from the recipients. "I found their number somewhere" is not a valid basis for marketing under PDPA.
Your HR processes. Employee personal data is subject to PDPA. Performance reviews, medical records, payroll information, and even attendance records are all personal data that must be handled according to the Act.
Your vendor relationships. When you engage cloud services, payroll providers, or any third party who accesses personal data, your contracts need to include data protection clauses. You remain responsible for data shared with your vendors.
Your security posture. The Security Principle means you need basic access controls, password policies, and data handling procedures that reduce the risk of a breach. A breach that exposes customer data is both a compliance failure and a potential criminal offence.
Where Do Most Malaysian Businesses Fall Short?
From working with Malaysian organisations across industries, the most common gaps are:
- No Privacy Notice, or one that was copied from a template and never actually links from the data collection points.
- No data breach response procedure. Most organisations discover they don't have one when they actually experience a breach and cannot meet the 72-hour notification window.
- Staff untrained on data handling. Employees emailing customer lists to personal email addresses, WhatsApp groups sharing client data, unlocked computers in open offices.
- No data retention schedule. Personal data is accumulated indefinitely because no one has decided when to delete it.
- No DPO (or no one actually doing the DPO's job). Some organisations appoint a DPO on paper but the person has no time, no authority, and no training to actually perform the role.
None of these gaps are unusual. But they are all fixable, and fixing them is significantly less expensive than the alternative.
Where Should I Start?
Start with a data audit — a practical exercise where you map out what personal data your organisation holds, where it is stored, who can access it, and whether you have a legitimate basis for processing each category. This exercise alone often surfaces the most significant compliance gaps.
From there, the priorities for most Malaysian SMEs and mid-sized organisations are:
- Put a proper Privacy Notice in place and link it from all data collection points
- Create a data breach response procedure before you need one
- Train staff who handle personal data
- Review and update vendor contracts to include data protection clauses
- If you meet the DPO threshold, appoint one
For a structured way to assess where you stand, see our PDPA Compliance Checklist for 2026. For a detailed look at DPO appointment specifically, read Do I Need to Appoint a DPO in Malaysia?