Malaysia PDPA Compliance with ConsentX
Personal Data Protection Act 2010 (Act 709)
Malaysia
In force, as amended in 2024
The Personal Data Protection (Amendment) Act 2024 (Act A1727) was brought into force in stages on 1 January 2025, 1 April 2025 and 1 June 2025.
Asia & Africa
Malaysia PDPA at a glance
Personal Data Protection Act 2010 (Act 709)
Personal Data Protection (Amendment) Act 2024
1 January, 1 April and 1 June 2025
Processing connected with commercial transactions in Malaysia
Data controller / data processor
7 Personal Data Protection Principles
Required in applicable processing circumstances, subject to statutory exceptions
Express consent generally required, subject to statutory exceptions
Classified as sensitive personal data under the 2024 amendments
Required when specified thresholds or monitoring conditions are met
Required; Commissioner notification generally no later than 72 hours under the Commissioner's guidance
Introduced by the 2024 amendments
Regulated under Section 129 and Commissioner guidance
Personal Data Protection Commissioner
Malaysia
Who must comply with Malaysia's PDPA?
The PDPA applies to persons who process personal data, or who have control over or authorise the processing of personal data, in connection with commercial transactions. This can include companies, partnerships, e-commerce businesses, financial and insurance organisations, telecommunications businesses, retailers, travel and hospitality businesses, healthcare organisations operating within the relevant commercial scope, technology companies, SaaS providers, marketing businesses, professional-service organisations and other organisations processing personal data in commercial transactions. The Act can also apply to certain organisations that are not established in Malaysia but use equipment in Malaysia to process personal data, other than merely processing data in transit. Such organisations may be required to nominate a representative established in Malaysia. The Federal and State Governments are generally excluded from the Act's application.
Penalties and enforcement
The Malaysian PDPA contains criminal offences with fines and, for certain offences, potential imprisonment. The 2024 amendments increased certain penalties and introduced new offences relating to obligations such as processor security, DPO requirements and breach notification. For example, the amended security provision applicable to data processors can carry a fine of up to RM1 million or imprisonment for up to three years, or both, where the relevant offence is established. Failure by a data controller to comply with the statutory breach-notification obligation can carry a fine of up to RM250,000 or imprisonment for up to two years, or both. Penalties vary according to the specific provision breached, so organisations should not treat a single headline fine as the penalty for all forms of non-compliance.
In short
- Personal Data Protection Act 2010 (Act 709)
- Personal Data Protection (Amendment) Act 2024 (Act A1727)
- Personal Data Protection Regulations 2013
- Personal Data Protection Standard 2015
- Applicable sector-specific codes of practice
- Commissioner circulars and guidelines, including guidance on breach notification, DPOs, cross-border transfers, DPIAs and automated decision-making
Malaysia's privacy framework is based primarily on the instruments above. The PDPA applies to the processing of personal data in connection with commercial transactions, and government processing is generally outside the Act's scope.
What personal data is protected?
The PDPA regulates personal data, broadly covering information relating directly or indirectly to an individual who can be identified from that information or in combination with other information.
Examples can include:
- Name
- Identification information
- Passport information
- Contact details
- Email address
- Financial information
- Health information
- Photographs
- CCTV images
- Employment information
- Online identifiers
- Other information associated with an identifiable individual
The Malaysian Personal Data Protection Commissioner explains that processing can include collecting, recording, holding, storing, organising, changing, disclosing and destroying personal data.
Sensitive personal data
Malaysia provides additional protection for sensitive personal data.
Sensitive personal data includes information relating to matters such as:
- Physical or mental health
- Political opinions
- Religious beliefs or similar beliefs
- Commission or alleged commission of an offence
- Biometric data, following the 2024 amendments
Biometric data is defined as personal data resulting from technical processing relating to the physical, physiological or behavioural characteristics of a person.
Examples can include certain forms of:
- Facial recognition data
- Fingerprint data
- Voice or behavioural biometric information
- Other biometric identifiers
The processing of sensitive personal data generally requires express consent, unless one of the statutory exceptions applies.
The 7 Personal Data Protection Principles
Malaysia's PDPA is built around seven core principles:
- General Principle
- Notice and Choice Principle
- Disclosure Principle
- Security Principle
- Retention Principle
- Data Integrity Principle
- Access Principle
These principles govern how organisations collect, use, disclose, secure, retain and provide access to personal data.
The official Malaysian privacy authority continues to identify compliance with the seven principles as a central obligation for data controllers.
Consent requirements under Malaysia's PDPA
Consent is a central part of Malaysia's PDPA framework.
However, organisations should not describe the law as requiring consent for every possible processing activity. The Act contains circumstances in which processing can occur without consent, including specified statutory exceptions.
Businesses should therefore assess:
- Whether personal data is being processed
- The purpose of processing
- The applicable legal condition
- Whether consent is required
- Whether the data is sensitive
- Whether the consent is express or otherwise required
- What information must be provided to the individual
- How consent and related decisions are documented
The PDPA also creates offences relating to certain processing after consent has been withdrawn.
Sensitive-data consent
Where sensitive personal data is processed, the statutory requirements are more stringent.
The Malaysian Personal Data Protection Commissioner states that sensitive personal data generally cannot be processed except for purposes specified by the Act and with the express consent of the data subject, subject to statutory exceptions.
For digital businesses, consent interfaces should therefore distinguish between ordinary processing and processing that requires a higher level of permission.
Privacy notices and transparency
The Notice and Choice Principle requires organisations to provide appropriate information to data subjects about the processing of their personal data.
A privacy notice should address relevant matters such as:
- The fact that personal data is being processed
- The purposes for which it is processed
- The source of the personal data where applicable
- The individual's rights
- Disclosure to third parties
- Choice and means for limiting processing
- Whether data must be supplied and the consequences of not supplying it
- Other information required by applicable requirements
Malaysia's privacy authority provides specific guidance on privacy notices and their preparation.
For digital businesses, website privacy notices should be consistent with actual website behaviour. If a website states that it does not share information with third parties but sends visitor information to advertising, analytics or other external platforms, the organisation should review and reconcile the notice and the underlying processing.
Cookies and online tracking
Malaysia's PDPA does not operate as a blanket rule that every cookie requires consent.
Instead, businesses should assess whether cookies and tracking technologies involve personal data and whether their collection, use or disclosure is covered by the PDPA.
This can include:
- Analytics cookies
- Advertising cookies
- Retargeting pixels
- Social-media pixels
- Conversion tracking
- Session identifiers
- Device identifiers
- SDKs
- Behavioural analytics
- Other online tracking technologies
For organisations using consent as the applicable basis for a particular processing activity, ConsentX can help ensure that relevant tracking technologies are not activated before the appropriate consent choice.
Data subject rights
Malaysia's PDPA provides individuals with important rights relating to their personal data.
These include rights concerning:
- Access to personal data
- Correction of personal data
- Withdrawal of consent in applicable circumstances
- Limits on certain processing
- Direct marketing objections
- Data portability under the 2024 amendments
The data portability right was introduced through new Section 43A. Subject to technical feasibility and compatible data formats, a data subject may request that personal data be transmitted directly to another data controller of their choice.
Organisations should therefore maintain a structured process for receiving, authenticating, tracking and responding to data-subject requests.
Data portability
Data portability is one of the major changes introduced by the 2024 amendments.
Under new Section 43A:
- A data subject may request transmission of their personal data to another data controller
- The request may be made electronically
- Transmission is subject to technical feasibility
- Compatibility of the data format is relevant
- The applicable prescribed period governs completion of the transmission
Businesses should consider whether their systems can:
- Locate relevant personal data
- Export it in an appropriate format
- Authenticate the requestor
- Transfer the data securely
- Maintain an audit trail
- Track the request through completion
Data Protection Officers
One of the most significant changes under the 2024 amendments is the introduction of a statutory Data Protection Officer (DPO) requirement.
Section 12A requires a data controller to appoint one or more DPOs where the applicable requirements are met. Data processors are also required to appoint DPOs where the statutory conditions apply.
According to the Malaysian Personal Data Protection Commissioner, a DPO is required where processing involves:
- Personal data of more than 20,000 data subjects
- Sensitive personal data, including financial information, involving more than 10,000 individuals
- Activities requiring regular and systematic monitoring, such as online user-behaviour tracking
The DPO must support compliance with the Act, advise on privacy obligations, support DPIAs, assist with data breaches and act as a liaison with the Commissioner and data subjects.
Where an organisation is required to appoint a DPO, the appointment must be notified to the Commissioner through the prescribed system. The Commissioner's FAQ states that notification should be made within 21 days from the date of appointment.
Data processors now have direct security obligations
The 2024 amendments strengthened the position of data processors under the PDPA.
Where a data processor processes personal data on behalf of a data controller, the processor must comply directly with the Security Principle under Section 9.
This is important for organisations relying on:
- Cloud providers
- SaaS platforms
- CRM providers
- Payment providers
- Marketing platforms
- Analytics vendors
- Outsourced customer-support services
- Other third-party processors
Vendor contracts should clearly allocate responsibilities for:
- Security
- Confidentiality
- Access control
- Incident response
- Data retention
- Data deletion
- Sub-processing
- Data-subject requests
- Cross-border processing
Personal data breach notification
The 2024 amendments introduced a statutory personal-data breach notification framework.
Where a data controller has reason to believe that a personal data breach has occurred, the controller must notify the Commissioner as soon as practicable in the prescribed manner. Where the breach causes or is likely to cause significant harm to the data subject, the data subject must also be notified without unnecessary delay.
The Commissioner's breach-notification guidance specifies that notification to the Commissioner should be made as soon as practicable and no later than 72 hours from the occurrence of the personal-data breach where the notification criteria are met.
The amended Act defines a personal data breach to include:
- Breach of personal data
- Loss of personal data
- Misuse of personal data
- Unauthorised access to personal data
Organisations should maintain an incident-response procedure that can rapidly identify, investigate, document and escalate qualifying incidents.
Cross-border personal data transfers
Malaysia regulates transfers of personal data outside Malaysia under Section 129 of the PDPA.
The 2024 amendments changed the structure of Section 129 and the Commissioner has issued dedicated guidance on cross-border transfers.
The Commissioner's cross-border guidance addresses issues including:
- The destination jurisdiction
- The level of protection available
- Contractual safeguards
- Risk assessment
- The recipient
- The nature of the personal data
- The purpose of the transfer
- Other applicable transfer conditions
Organisations using international cloud infrastructure, overseas SaaS providers, global analytics platforms or foreign processors should therefore maintain a current map of where personal data is transferred.
Data Protection Impact Assessments
Malaysia's privacy framework includes guidance on Data Protection Impact Assessments (DPIAs).
The Commissioner's DPIA materials identify quantitative thresholds and qualitative risk factors that can trigger or support the need for an assessment. Examples include processing:
- Sensitive personal data involving more than 10,000 data subjects
- Personal data for certain automated decision-making activities involving more than 10,000 data subjects
- Personal data involving more than 20,000 data subjects
- Data involving significant effects on individuals
- Public-area monitoring
- Innovative technologies
- Location or behavioural tracking
- Data relating to children or vulnerable individuals
A DPIA should examine:
- The purpose of processing
- Categories of personal data
- Processing operations
- Potential risks
- Impact on individuals
- Security measures
- Retention
- Third-party processing
- International transfers
- Measures to mitigate identified risks
Automated decision-making and profiling
The Malaysian Personal Data Protection Commissioner has issued guidance concerning Automated Decision-Making and Profiling (ADMP).
Businesses using the following should determine whether personal data is involved and whether additional privacy safeguards are appropriate:
- AI systems
- Behavioural profiling
- Automated eligibility decisions
- Fraud detection
- Credit or insurance scoring
- Personalised advertising
- Facial recognition
- Other automated systems
Where sensitive personal data, including biometric data, is used in automated processing, the relevant sensitive-data requirements remain important.
Security obligations
The Security Principle requires organisations to take practical steps to protect personal data against:
- Loss
- Misuse
- Modification
- Unauthorised access
- Disclosure
- Alteration
- Other security risks
The 2024 amendments make the Security Principle directly applicable to both data controllers and data processors.
Organisations should consider controls such as:
- Access management
- Authentication
- Encryption
- Secure development
- Logging and monitoring
- Vulnerability management
- Backup and recovery
- Incident response
- Employee training
- Vendor assessments
- Data minimisation
Data retention
The Retention Principle requires personal data not to be retained longer than necessary for the fulfilment of the purpose for which it was processed.
Businesses should establish documented retention schedules for:
- Customer accounts
- Marketing databases
- Employee information
- Consent records
- Website analytics
- Cookies and tracking data
- Support records
- Data-subject requests
- Security logs
- Vendor-held personal data
Retention periods should reflect both the original processing purpose and any applicable legal or contractual retention obligations.
Direct marketing
Direct marketing is specifically addressed within Malaysia's privacy framework.
Businesses conducting marketing activities should review:
- The source of marketing information
- The purpose for which it was collected
- Whether consent is required
- Marketing preferences
- Opt-out mechanisms
- Third-party disclosures
- Profiling
- Advertising platforms
- Data retention
The PDPA provides individuals with mechanisms to object to certain direct-marketing activities, and the Commissioner can issue requirements relating to direct marketing.
Data controller registration
Certain classes of data controllers are required to register under Malaysia's registration framework.
The Commissioner's materials currently identify 13 classes of data controllers subject to registration requirements. Organisations outside those classes may still be subject to the PDPA even if they do not have the same registration obligation.
In 2026, the Commissioner also issued Circular No. 1/2026 on Registration of Data Controllers, reinforcing the current registration framework.
Businesses should therefore determine:
- Whether they are a data controller
- Whether they fall within a prescribed class
- Whether registration is required
- Whether their registration certificate is current
- Whether any renewal or update is required
International businesses
A company does not necessarily avoid Malaysia's PDPA simply because it is incorporated outside Malaysia.
The Act can apply where a person not established in Malaysia uses equipment in Malaysia to process personal data, other than processing merely for transit. Such a person may need to nominate a representative established in Malaysia.
International businesses should therefore assess:
- Where personal data is collected
- Where processing occurs
- Where systems are hosted
- Where processors are located
- Whether Malaysian equipment is used
- Where personal data is transferred
- Whether a Malaysian representative is required
Major 2024 to 2026 changes to Malaysia's PDPA
The following changes are the most important for organisations reviewing their Malaysian privacy programme.
- Data users became data controllers. The 2024 amendments replace the terminology of “data user” with “data controller” across the Act in the relevant provisions.
- Biometric data added to sensitive personal data. Biometric data is now expressly included within the definition of sensitive personal data.
- Data processors have direct security obligations. Processors must comply directly with the Security Principle when processing personal data on behalf of controllers.
- DPO requirements. Data controllers and processors must appoint DPOs where the applicable statutory thresholds or conditions are met.
- Mandatory breach notification. Qualifying personal-data breaches must be reported to the Commissioner, with the Commissioner's guidance providing a 72-hour timeframe.
- Data portability. Data subjects gained a statutory data-portability right, subject to technical feasibility and compatible formats.
- Updated cross-border transfer framework. Section 129 was amended and the Commissioner has published updated cross-border transfer guidance.
Malaysia PDPA compliance checklist
Use this checklist to review your organisation's current privacy programme.
- Identify all personal data collected
- Identify processing purposes
- Determine the applicable legal condition
- Review consent mechanisms
- Review sensitive personal data
- Identify biometric-data processing
- Maintain appropriate privacy notices
- Review third-party disclosures
- Map data processors
- Confirm processor security obligations
- Review data retention periods
- Establish access and correction workflows
- Prepare for data portability requests
- Review direct-marketing practices
- Assess DPO appointment requirements
- Register the DPO where required
- Review data-controller registration requirements
- Implement breach-detection procedures
- Prepare breach-notification procedures
- Review the 72-hour notification timeframe
- Map cross-border data transfers
- Assess DPIA requirements
- Review automated decision-making and profiling
- Scan website cookies and trackers
- Block selected non-essential trackers before applicable consent
- Maintain consent evidence
- Regularly review website technologies and vendors
How ConsentX helps with Malaysia PDPA compliance
Cookie and tracker discovery
ConsentX can scan your website to identify cookies, analytics scripts, advertising trackers, pixels, third-party scripts, tags and other technologies that may process personal data.
Consent management
Where consent is the applicable legal basis, ConsentX can provide configurable consent experiences that allow users to make and manage their choices.
Prior-script blocking
ConsentX can help prevent selected non-essential cookies and trackers from executing before the required consent decision.
Consent records
ConsentX can maintain records of user choices, helping organisations establish an auditable record of consent activity.
Regional controls
Use ConsentX's region rule engine to configure different privacy and consent experiences for Malaysian users and users in other jurisdictions.
Privacy request workflows
ConsentX can support workflows for managing applicable data-subject requests, including access and other privacy requests.
Privacy compliance monitoring
Regular scans can help organisations identify changes to website technologies and third-party trackers that may affect their privacy compliance programme.
Get Malaysia PDPA ready with ConsentX
Malaysia's PDPA requires more than simply displaying a privacy policy. ConsentX helps organisations operationalise website-level privacy controls through cookie and tracker discovery, consent management, prior-script blocking, consent records, regional rules and privacy-request workflows. Build a transparent and audit-ready privacy experience for users in Malaysia with ConsentX.
This page provides a general, plain-English overview of Malaysia's Personal Data Protection Act 2010 and the Personal Data Protection (Amendment) Act 2024. It is not legal advice and does not cover every sector-specific code of practice, exemption, Commissioner circular, regulatory interpretation or individual compliance circumstance. ConsentX does not replace legal advice or an organisation's broader security, governance and compliance programme. Organisations should review the current Malaysian legislation and Commissioner guidance and obtain qualified Malaysian legal advice where necessary.
How to comply with Malaysia's PDPA using ConsentX
- 1
Scan your website
Use ConsentX to identify cookies, scripts, pixels, tags and other tracking technologies deployed across your website.
- 2
Identify personal-data processing
Determine which website technologies collect, receive, store, disclose or otherwise process information relating to identifiable individuals.
- 3
Identify the applicable legal condition
Determine whether consent is required or whether another statutory condition applies to the relevant processing.
- 4
Configure your consent banner
Create a clear consent interface that explains relevant processing purposes and gives users appropriate choices.
- 5
Block selected trackers
Configure prior-script blocking for selected non-essential technologies where processing should not begin until the applicable permission has been obtained.
- 6
Record consent
Maintain evidence of consent choices, including relevant timestamps and configuration information.
- 7
Enable withdrawal and preference management
Give users an accessible mechanism to change or withdraw applicable consent choices.
- 8
Review sensitive-data processing
Identify whether your website or digital service processes sensitive personal data, including biometric data.
- 9
Review third-party processors
Identify analytics, advertising, CRM, cloud and other third-party services that process personal data on your behalf.
- 10
Review cross-border transfers
Map where personal data is transferred outside Malaysia and assess the applicable Section 129 requirements.
- 11
Assess DPO requirements
Determine whether your organisation meets the thresholds for mandatory DPO appointment.
- 12
Prepare for breach response
Maintain a process capable of identifying and escalating personal-data breaches quickly enough to meet the applicable notification requirements.