# Data Privacy Law in Malaysia

> Malaysia PDPA after the 2024 amendments: data controller terminology, mandatory DPO, 72-hour breach notification, biometric data and processor liability.

Canonical URL: https://www.cecolaw.com/data-privacy-law-in-malaysia/
Published: 2020-03-15
Updated: 2026-07-27
Author: Cecilia Lim (Associate), Ching, Elaine & Co — Advocates & Solicitors, Malaysia
Reviewed by: Lim Ching Yong (Partner)

---

*Updated 27 July 2026 to reflect the Personal Data Protection (Amendment) Act 2024, which came into force in phases during 2025.*

## Data privacy law in Malaysia: where the law now stands

The Personal Data Protection Act 2010 (“**PDPA**”) came into force on 15 November 2013 and regulates the processing of personal data in commercial transactions. It does not apply to the federal or state governments.

The PDPA was substantially amended by the **Personal Data Protection (Amendment) Act 2024**, which was brought into force in phases through 2025. The amendments introduced mandatory data breach notification, mandatory appointment of data protection officers, direct obligations on data processors, a right to data portability, and increased penalties. This note sets out the position as amended.

## Data controller and data processor

The amendment renamed the “data user” as the “**data controller**”, aligning Malaysian terminology with the position in other jurisdictions. The substance of the definition is unchanged: a data controller is a person who processes any personal data, or who has control over or authorises the processing of any personal data, but does not include a data processor. “Processing” includes collecting, recording, holding and storing personal data.

A **data processor** is a person who processes personal data solely on behalf of the data controller, and not for any of his own purposes. It does not include an employee of the data controller.

The practical significance of the amendment is that data processors are now **directly subject to the security requirements of the PDPA**. Previously the Data Protection Principles bound only the data user, and a processor’s obligations arose contractually. A processor that fails to secure personal data now faces direct liability.

## Scope of personal data

Information is personal data under the PDPA if a specific individual is identified or identifiable from that information, or from that information together with other information in the possession of the data controller. Anonymised data — data converted into a form which does not identify individuals — falls outside the definition.

The category of **sensitive personal data** was expanded by the 2024 amendment to include **biometric data**, alongside information as to physical or mental health, political opinions, religious beliefs and the commission or alleged commission of an offence. Sensitive personal data requires explicit consent to process.

## The Data Protection Principles

Seven principles govern the processing of personal data:

1. **General Principle** — personal data may only be processed with the data subject’s consent, unless an exemption in the PDPA applies. Consent may take any form provided it can be properly recorded and maintained.

2. **Notice and Choice Principle** — the data subject must be informed by written notice (a privacy notice) that their personal data is being processed, the purpose of processing, and the classes of third parties to whom the data may be disclosed. The notice must be issued in both Bahasa Malaysia and English.

3. **Disclosure Principle** — personal data may not be disclosed for a purpose other than that for which it was collected, or to a party other than a class disclosed in the privacy notice, without consent.

4. **Security Principle** — the data controller must take practical steps to protect personal data from loss, misuse, modification, unauthorised access or disclosure. Since the 2024 amendment this obligation binds data processors directly as well.

5. **Retention Principle** — personal data must not be kept longer than is necessary for the purpose for which it was processed, and must then be destroyed or permanently deleted.

6. **Data Integrity Principle** — the data controller must take reasonable steps to ensure personal data is accurate, complete, not misleading and kept up to date.

7. **Access Principle** — a data subject must be given access to their personal data and be able to correct it where it is inaccurate, incomplete, misleading or out of date.

## What the 2024 amendment introduced

### Mandatory appointment of a data protection officer

Data controllers and data processors must appoint at least one data protection officer accountable for compliance with the PDPA, and must notify the Commissioner of the appointment in the form the Commissioner determines. Guidelines issued by the Commissioner set out the thresholds and the criteria for who may be appointed.

### Mandatory data breach notification

Where a personal data breach occurs, the data controller must notify the Commissioner **as soon as practicable, and in any event no later than 72 hours** after the breach occurs. Where the breach causes or is likely to cause significant harm to the data subject, the data subject must also be notified without undue delay, and in any event within **7 days** of the notification to the Commissioner.

The 72-hour clock runs from the occurrence of the breach, not from the point at which the organisation concludes that it is likely to cause significant harm. In practice this means an incident response plan has to be in place before an incident happens.

### Right to data portability

Data subjects may, subject to technical feasibility and compatibility of format, require a data controller to transmit their personal data to another data controller of their choosing.

### Cross-border transfers

The amendment removed the requirement that personal data may only be transferred to jurisdictions on a list gazetted by the Minister. Transfers out of Malaysia are instead permitted where the destination jurisdiction has a law substantially similar to the PDPA, or ensures an adequate level of protection, or where another statutory ground applies.

### Increased penalties

Penalties for contravening the Data Protection Principles were increased, and failure to comply with the breach notification obligation carries its own penalty. Organisations should treat data protection compliance as a board-level risk rather than an administrative formality.

## Registration under the PDPA

Data controllers within the classes specified by the Minister must register with the Commissioner before processing personal data. The specified classes include, among others, those carrying on business in communications, banking and financial institutions, insurance, health, tourism and hospitality, transportation, education, direct selling, services (including legal, audit, accountancy, engineering and architecture), real estate, and utilities.

## Common questions

### What is the deadline for reporting a data breach in Malaysia?

The Commissioner must be notified as soon as practicable and no later than 72 hours after the breach occurs. Affected data subjects must be notified within 7 days of that notification where the breach causes or is likely to cause significant harm.

### Does my company need to appoint a data protection officer?

Data controllers and data processors falling within the thresholds set out in the Commissioner’s guidelines must appoint at least one data protection officer and notify the Commissioner of the appointment. The officer is accountable for the organisation’s compliance with the PDPA.

### Has “data user” been replaced?

Yes. The Personal Data Protection (Amendment) Act 2024 replaced “data user” with “**data controller**”. Contracts, privacy notices and internal policies drafted before the amendment should be reviewed and updated to reflect the current terminology and the new obligations.

### Are data processors liable under the PDPA?

Yes. Since the 2024 amendment, data processors are directly subject to the security requirements of the PDPA, in addition to any obligations owed to the data controller under contract.

### Is biometric data treated differently?

Yes. Biometric data is now sensitive personal data, and its processing requires the explicit consent of the data subject.

## How we can help

We advise Malaysian companies on PDPA compliance: privacy notices and consent mechanics, data processing agreements with vendors and group companies, breach response procedures, data protection officer appointments, and the data protection provisions of commercial contracts and transaction documents. Data protection is a standard workstream in our [due diligence](https://www.cecolaw.com/due-diligence-lawyer-malaysia/) work.

*This note is general in nature and is not legal advice. The Commissioner’s guidelines are updated from time to time; advice should be taken on your organisation’s specific circumstances.*

---

This commentary is general in nature and is not legal advice.
Ching, Elaine & Co, a boutique corporate law firm in Malaysia — https://www.cecolaw.com/ · info@cecolaw.com · +60 3-7664 2141
