Personal Data Protection Act 2010 (Act 709)
Malaysia
In force, as amended in 2024
The Personal Data Protection (Amendment) Act 2024 (Act A1727) was brought into force in stages on 1 January 2025, 1 April 2025 and 1 June 2025.
Asia & Africa
Personal Data Protection Act 2010 (Act 709)
Personal Data Protection (Amendment) Act 2024
1 January, 1 April and 1 June 2025
Processing connected with commercial transactions in Malaysia
Data controller / data processor
7 Personal Data Protection Principles
Required in applicable processing circumstances, subject to statutory exceptions
Express consent generally required, subject to statutory exceptions
Classified as sensitive personal data under the 2024 amendments
Required when specified thresholds or monitoring conditions are met
Required; Commissioner notification generally no later than 72 hours under the Commissioner's guidance
Introduced by the 2024 amendments
Regulated under Section 129 and Commissioner guidance
Personal Data Protection Commissioner
Malaysia
The PDPA applies to persons who process personal data, or who have control over or authorise the processing of personal data, in connection with commercial transactions. This can include companies, partnerships, e-commerce businesses, financial and insurance organisations, telecommunications businesses, retailers, travel and hospitality businesses, healthcare organisations operating within the relevant commercial scope, technology companies, SaaS providers, marketing businesses, professional-service organisations and other organisations processing personal data in commercial transactions. The Act can also apply to certain organisations that are not established in Malaysia but use equipment in Malaysia to process personal data, other than merely processing data in transit. Such organisations may be required to nominate a representative established in Malaysia. The Federal and State Governments are generally excluded from the Act's application.
The Malaysian PDPA contains criminal offences with fines and, for certain offences, potential imprisonment. The 2024 amendments increased certain penalties and introduced new offences relating to obligations such as processor security, DPO requirements and breach notification. For example, the amended security provision applicable to data processors can carry a fine of up to RM1 million or imprisonment for up to three years, or both, where the relevant offence is established. Failure by a data controller to comply with the statutory breach-notification obligation can carry a fine of up to RM250,000 or imprisonment for up to two years, or both. Penalties vary according to the specific provision breached, so organisations should not treat a single headline fine as the penalty for all forms of non-compliance.
Malaysia's privacy framework is based primarily on the instruments above. The PDPA applies to the processing of personal data in connection with commercial transactions, and government processing is generally outside the Act's scope.
The PDPA regulates personal data, broadly covering information relating directly or indirectly to an individual who can be identified from that information or in combination with other information.
Examples can include:
The Malaysian Personal Data Protection Commissioner explains that processing can include collecting, recording, holding, storing, organising, changing, disclosing and destroying personal data.
Malaysia provides additional protection for sensitive personal data.
Sensitive personal data includes information relating to matters such as:
Biometric data is defined as personal data resulting from technical processing relating to the physical, physiological or behavioural characteristics of a person.
Examples can include certain forms of:
The processing of sensitive personal data generally requires express consent, unless one of the statutory exceptions applies.
Malaysia's PDPA is built around seven core principles:
These principles govern how organisations collect, use, disclose, secure, retain and provide access to personal data.
The official Malaysian privacy authority continues to identify compliance with the seven principles as a central obligation for data controllers.
Consent is a central part of Malaysia's PDPA framework.
However, organisations should not describe the law as requiring consent for every possible processing activity. The Act contains circumstances in which processing can occur without consent, including specified statutory exceptions.
Businesses should therefore assess:
The PDPA also creates offences relating to certain processing after consent has been withdrawn.
Where sensitive personal data is processed, the statutory requirements are more stringent.
The Malaysian Personal Data Protection Commissioner states that sensitive personal data generally cannot be processed except for purposes specified by the Act and with the express consent of the data subject, subject to statutory exceptions.
For digital businesses, consent interfaces should therefore distinguish between ordinary processing and processing that requires a higher level of permission.
The Notice and Choice Principle requires organisations to provide appropriate information to data subjects about the processing of their personal data.
A privacy notice should address relevant matters such as:
Malaysia's privacy authority provides specific guidance on privacy notices and their preparation.
For digital businesses, website privacy notices should be consistent with actual website behaviour. If a website states that it does not share information with third parties but sends visitor information to advertising, analytics or other external platforms, the organisation should review and reconcile the notice and the underlying processing.
Malaysia's PDPA does not operate as a blanket rule that every cookie requires consent.
Instead, businesses should assess whether cookies and tracking technologies involve personal data and whether their collection, use or disclosure is covered by the PDPA.
This can include:
For organisations using consent as the applicable basis for a particular processing activity, ConsentX can help ensure that relevant tracking technologies are not activated before the appropriate consent choice.
Malaysia's PDPA provides individuals with important rights relating to their personal data.
These include rights concerning:
The data portability right was introduced through new Section 43A. Subject to technical feasibility and compatible data formats, a data subject may request that personal data be transmitted directly to another data controller of their choice.
Organisations should therefore maintain a structured process for receiving, authenticating, tracking and responding to data-subject requests.
Data portability is one of the major changes introduced by the 2024 amendments.
Under new Section 43A:
Businesses should consider whether their systems can:
One of the most significant changes under the 2024 amendments is the introduction of a statutory Data Protection Officer (DPO) requirement.
Section 12A requires a data controller to appoint one or more DPOs where the applicable requirements are met. Data processors are also required to appoint DPOs where the statutory conditions apply.
According to the Malaysian Personal Data Protection Commissioner, a DPO is required where processing involves:
The DPO must support compliance with the Act, advise on privacy obligations, support DPIAs, assist with data breaches and act as a liaison with the Commissioner and data subjects.
Where an organisation is required to appoint a DPO, the appointment must be notified to the Commissioner through the prescribed system. The Commissioner's FAQ states that notification should be made within 21 days from the date of appointment.
The 2024 amendments strengthened the position of data processors under the PDPA.
Where a data processor processes personal data on behalf of a data controller, the processor must comply directly with the Security Principle under Section 9.
This is important for organisations relying on:
Vendor contracts should clearly allocate responsibilities for:
The 2024 amendments introduced a statutory personal-data breach notification framework.
Where a data controller has reason to believe that a personal data breach has occurred, the controller must notify the Commissioner as soon as practicable in the prescribed manner. Where the breach causes or is likely to cause significant harm to the data subject, the data subject must also be notified without unnecessary delay.
The Commissioner's breach-notification guidance specifies that notification to the Commissioner should be made as soon as practicable and no later than 72 hours from the occurrence of the personal-data breach where the notification criteria are met.
The amended Act defines a personal data breach to include:
Organisations should maintain an incident-response procedure that can rapidly identify, investigate, document and escalate qualifying incidents.
Malaysia regulates transfers of personal data outside Malaysia under Section 129 of the PDPA.
The 2024 amendments changed the structure of Section 129 and the Commissioner has issued dedicated guidance on cross-border transfers.
The Commissioner's cross-border guidance addresses issues including:
Organisations using international cloud infrastructure, overseas SaaS providers, global analytics platforms or foreign processors should therefore maintain a current map of where personal data is transferred.
Malaysia's privacy framework includes guidance on Data Protection Impact Assessments (DPIAs).
The Commissioner's DPIA materials identify quantitative thresholds and qualitative risk factors that can trigger or support the need for an assessment. Examples include processing:
A DPIA should examine:
The Malaysian Personal Data Protection Commissioner has issued guidance concerning Automated Decision-Making and Profiling (ADMP).
Businesses using the following should determine whether personal data is involved and whether additional privacy safeguards are appropriate:
Where sensitive personal data, including biometric data, is used in automated processing, the relevant sensitive-data requirements remain important.
The Security Principle requires organisations to take practical steps to protect personal data against:
The 2024 amendments make the Security Principle directly applicable to both data controllers and data processors.
Organisations should consider controls such as:
The Retention Principle requires personal data not to be retained longer than necessary for the fulfilment of the purpose for which it was processed.
Businesses should establish documented retention schedules for:
Retention periods should reflect both the original processing purpose and any applicable legal or contractual retention obligations.
Direct marketing is specifically addressed within Malaysia's privacy framework.
Businesses conducting marketing activities should review:
The PDPA provides individuals with mechanisms to object to certain direct-marketing activities, and the Commissioner can issue requirements relating to direct marketing.
Certain classes of data controllers are required to register under Malaysia's registration framework.
The Commissioner's materials currently identify 13 classes of data controllers subject to registration requirements. Organisations outside those classes may still be subject to the PDPA even if they do not have the same registration obligation.
In 2026, the Commissioner also issued Circular No. 1/2026 on Registration of Data Controllers, reinforcing the current registration framework.
Businesses should therefore determine:
A company does not necessarily avoid Malaysia's PDPA simply because it is incorporated outside Malaysia.
The Act can apply where a person not established in Malaysia uses equipment in Malaysia to process personal data, other than processing merely for transit. Such a person may need to nominate a representative established in Malaysia.
International businesses should therefore assess:
The following changes are the most important for organisations reviewing their Malaysian privacy programme.
Use this checklist to review your organisation's current privacy programme.
ConsentX can scan your website to identify cookies, analytics scripts, advertising trackers, pixels, third-party scripts, tags and other technologies that may process personal data.
Where consent is the applicable legal basis, ConsentX can provide configurable consent experiences that allow users to make and manage their choices.
ConsentX can help prevent selected non-essential cookies and trackers from executing before the required consent decision.
ConsentX can maintain records of user choices, helping organisations establish an auditable record of consent activity.
Use ConsentX's region rule engine to configure different privacy and consent experiences for Malaysian users and users in other jurisdictions.
ConsentX can support workflows for managing applicable data-subject requests, including access and other privacy requests.
Regular scans can help organisations identify changes to website technologies and third-party trackers that may affect their privacy compliance programme.
Malaysia's PDPA requires more than simply displaying a privacy policy. ConsentX helps organisations operationalise website-level privacy controls through cookie and tracker discovery, consent management, prior-script blocking, consent records, regional rules and privacy-request workflows. Build a transparent and audit-ready privacy experience for users in Malaysia with ConsentX.
This page provides a general, plain-English overview of Malaysia's Personal Data Protection Act 2010 and the Personal Data Protection (Amendment) Act 2024. It is not legal advice and does not cover every sector-specific code of practice, exemption, Commissioner circular, regulatory interpretation or individual compliance circumstance. ConsentX does not replace legal advice or an organisation's broader security, governance and compliance programme. Organisations should review the current Malaysian legislation and Commissioner guidance and obtain qualified Malaysian legal advice where necessary.
Use ConsentX to identify cookies, scripts, pixels, tags and other tracking technologies deployed across your website.
Determine which website technologies collect, receive, store, disclose or otherwise process information relating to identifiable individuals.
Determine whether consent is required or whether another statutory condition applies to the relevant processing.
Create a clear consent interface that explains relevant processing purposes and gives users appropriate choices.
Configure prior-script blocking for selected non-essential technologies where processing should not begin until the applicable permission has been obtained.
Maintain evidence of consent choices, including relevant timestamps and configuration information.
Give users an accessible mechanism to change or withdraw applicable consent choices.
Identify whether your website or digital service processes sensitive personal data, including biometric data.
Identify analytics, advertising, CRM, cloud and other third-party services that process personal data on your behalf.
Map where personal data is transferred outside Malaysia and assess the applicable Section 129 requirements.
Determine whether your organisation meets the thresholds for mandatory DPO appointment.
Maintain a process capable of identifying and escalating personal-data breaches quickly enough to meet the applicable notification requirements.