DPDPA is now in force in India. Run a free privacy scan on your site. Scan now

Malaysia

Malaysia PDPA Compliance with ConsentX

Personal Data Protection Act 2010 (Act 709)

Malaysia's Personal Data Protection Act 2010 (Act 709) regulates the processing of personal data in connection with commercial transactions and establishes obligations for organisations that collect, use, disclose, store or otherwise process personal data. The framework was significantly updated by the Personal Data Protection (Amendment) Act 2024 (Act A1727). The amendments were brought into force in stages on 1 January 2025, 1 April 2025 and 1 June 2025. The updated Malaysian privacy framework introduces important compliance requirements, including Data Protection Officers (DPOs), personal data breach notification, direct security obligations for data processors, data portability and the inclusion of biometric data within sensitive personal data. For organisations operating websites, applications, e-commerce platforms, SaaS products, advertising systems or other digital services in Malaysia, compliance requires more than simply displaying a privacy policy. Organisations need appropriate consent mechanisms, privacy notices, security controls, vendor governance, data-subject rights processes and evidence of compliance.
Region

Malaysia

Status

In force, as amended in 2024

The Personal Data Protection (Amendment) Act 2024 (Act A1727) was brought into force in stages on 1 January 2025, 1 April 2025 and 1 June 2025.

Group

Asia & Africa

Malaysia PDPA at a glance

Primary legislation

Personal Data Protection Act 2010 (Act 709)

Major amendment

Personal Data Protection (Amendment) Act 2024

Amendment effective dates

1 January, 1 April and 1 June 2025

Territorial focus

Processing connected with commercial transactions in Malaysia

Core terminology

Data controller / data processor

Core principles

7 Personal Data Protection Principles

Consent

Required in applicable processing circumstances, subject to statutory exceptions

Sensitive data

Express consent generally required, subject to statutory exceptions

Biometric data

Classified as sensitive personal data under the 2024 amendments

DPO

Required when specified thresholds or monitoring conditions are met

Breach notification

Required; Commissioner notification generally no later than 72 hours under the Commissioner's guidance

Data portability

Introduced by the 2024 amendments

Cross-border transfers

Regulated under Section 129 and Commissioner guidance

Supervisory authority

Personal Data Protection Commissioner

Country

Malaysia

Who must comply with Malaysia's PDPA?

The PDPA applies to persons who process personal data, or who have control over or authorise the processing of personal data, in connection with commercial transactions. This can include companies, partnerships, e-commerce businesses, financial and insurance organisations, telecommunications businesses, retailers, travel and hospitality businesses, healthcare organisations operating within the relevant commercial scope, technology companies, SaaS providers, marketing businesses, professional-service organisations and other organisations processing personal data in commercial transactions. The Act can also apply to certain organisations that are not established in Malaysia but use equipment in Malaysia to process personal data, other than merely processing data in transit. Such organisations may be required to nominate a representative established in Malaysia. The Federal and State Governments are generally excluded from the Act's application.

Penalties and enforcement

The Malaysian PDPA contains criminal offences with fines and, for certain offences, potential imprisonment. The 2024 amendments increased certain penalties and introduced new offences relating to obligations such as processor security, DPO requirements and breach notification. For example, the amended security provision applicable to data processors can carry a fine of up to RM1 million or imprisonment for up to three years, or both, where the relevant offence is established. Failure by a data controller to comply with the statutory breach-notification obligation can carry a fine of up to RM250,000 or imprisonment for up to two years, or both. Penalties vary according to the specific provision breached, so organisations should not treat a single headline fine as the penalty for all forms of non-compliance.

In short

  • Personal Data Protection Act 2010 (Act 709)
  • Personal Data Protection (Amendment) Act 2024 (Act A1727)
  • Personal Data Protection Regulations 2013
  • Personal Data Protection Standard 2015
  • Applicable sector-specific codes of practice
  • Commissioner circulars and guidelines, including guidance on breach notification, DPOs, cross-border transfers, DPIAs and automated decision-making

Malaysia's privacy framework is based primarily on the instruments above. The PDPA applies to the processing of personal data in connection with commercial transactions, and government processing is generally outside the Act's scope.

What personal data is protected?

The PDPA regulates personal data, broadly covering information relating directly or indirectly to an individual who can be identified from that information or in combination with other information.

Examples can include:

  • Name
  • Identification information
  • Passport information
  • Contact details
  • Email address
  • Financial information
  • Health information
  • Photographs
  • CCTV images
  • Employment information
  • Online identifiers
  • Other information associated with an identifiable individual

The Malaysian Personal Data Protection Commissioner explains that processing can include collecting, recording, holding, storing, organising, changing, disclosing and destroying personal data.

Sensitive personal data

Malaysia provides additional protection for sensitive personal data.

Sensitive personal data includes information relating to matters such as:

  • Physical or mental health
  • Political opinions
  • Religious beliefs or similar beliefs
  • Commission or alleged commission of an offence
  • Biometric data, following the 2024 amendments

Biometric data is defined as personal data resulting from technical processing relating to the physical, physiological or behavioural characteristics of a person.

Examples can include certain forms of:

  • Facial recognition data
  • Fingerprint data
  • Voice or behavioural biometric information
  • Other biometric identifiers

The processing of sensitive personal data generally requires express consent, unless one of the statutory exceptions applies.

The 7 Personal Data Protection Principles

Malaysia's PDPA is built around seven core principles:

  • General Principle
  • Notice and Choice Principle
  • Disclosure Principle
  • Security Principle
  • Retention Principle
  • Data Integrity Principle
  • Access Principle

These principles govern how organisations collect, use, disclose, secure, retain and provide access to personal data.

The official Malaysian privacy authority continues to identify compliance with the seven principles as a central obligation for data controllers.

Consent requirements under Malaysia's PDPA

Consent is a central part of Malaysia's PDPA framework.

However, organisations should not describe the law as requiring consent for every possible processing activity. The Act contains circumstances in which processing can occur without consent, including specified statutory exceptions.

Businesses should therefore assess:

  • Whether personal data is being processed
  • The purpose of processing
  • The applicable legal condition
  • Whether consent is required
  • Whether the data is sensitive
  • Whether the consent is express or otherwise required
  • What information must be provided to the individual
  • How consent and related decisions are documented

The PDPA also creates offences relating to certain processing after consent has been withdrawn.

Sensitive-data consent

Where sensitive personal data is processed, the statutory requirements are more stringent.

The Malaysian Personal Data Protection Commissioner states that sensitive personal data generally cannot be processed except for purposes specified by the Act and with the express consent of the data subject, subject to statutory exceptions.

For digital businesses, consent interfaces should therefore distinguish between ordinary processing and processing that requires a higher level of permission.

Privacy notices and transparency

The Notice and Choice Principle requires organisations to provide appropriate information to data subjects about the processing of their personal data.

A privacy notice should address relevant matters such as:

  • The fact that personal data is being processed
  • The purposes for which it is processed
  • The source of the personal data where applicable
  • The individual's rights
  • Disclosure to third parties
  • Choice and means for limiting processing
  • Whether data must be supplied and the consequences of not supplying it
  • Other information required by applicable requirements

Malaysia's privacy authority provides specific guidance on privacy notices and their preparation.

For digital businesses, website privacy notices should be consistent with actual website behaviour. If a website states that it does not share information with third parties but sends visitor information to advertising, analytics or other external platforms, the organisation should review and reconcile the notice and the underlying processing.

Cookies and online tracking

Malaysia's PDPA does not operate as a blanket rule that every cookie requires consent.

Instead, businesses should assess whether cookies and tracking technologies involve personal data and whether their collection, use or disclosure is covered by the PDPA.

This can include:

  • Analytics cookies
  • Advertising cookies
  • Retargeting pixels
  • Social-media pixels
  • Conversion tracking
  • Session identifiers
  • Device identifiers
  • SDKs
  • Behavioural analytics
  • Other online tracking technologies

For organisations using consent as the applicable basis for a particular processing activity, ConsentX can help ensure that relevant tracking technologies are not activated before the appropriate consent choice.

Data subject rights

Malaysia's PDPA provides individuals with important rights relating to their personal data.

These include rights concerning:

  • Access to personal data
  • Correction of personal data
  • Withdrawal of consent in applicable circumstances
  • Limits on certain processing
  • Direct marketing objections
  • Data portability under the 2024 amendments

The data portability right was introduced through new Section 43A. Subject to technical feasibility and compatible data formats, a data subject may request that personal data be transmitted directly to another data controller of their choice.

Organisations should therefore maintain a structured process for receiving, authenticating, tracking and responding to data-subject requests.

Data portability

Data portability is one of the major changes introduced by the 2024 amendments.

Under new Section 43A:

  • A data subject may request transmission of their personal data to another data controller
  • The request may be made electronically
  • Transmission is subject to technical feasibility
  • Compatibility of the data format is relevant
  • The applicable prescribed period governs completion of the transmission

Businesses should consider whether their systems can:

  • Locate relevant personal data
  • Export it in an appropriate format
  • Authenticate the requestor
  • Transfer the data securely
  • Maintain an audit trail
  • Track the request through completion

Data Protection Officers

One of the most significant changes under the 2024 amendments is the introduction of a statutory Data Protection Officer (DPO) requirement.

Section 12A requires a data controller to appoint one or more DPOs where the applicable requirements are met. Data processors are also required to appoint DPOs where the statutory conditions apply.

According to the Malaysian Personal Data Protection Commissioner, a DPO is required where processing involves:

  • Personal data of more than 20,000 data subjects
  • Sensitive personal data, including financial information, involving more than 10,000 individuals
  • Activities requiring regular and systematic monitoring, such as online user-behaviour tracking

The DPO must support compliance with the Act, advise on privacy obligations, support DPIAs, assist with data breaches and act as a liaison with the Commissioner and data subjects.

Where an organisation is required to appoint a DPO, the appointment must be notified to the Commissioner through the prescribed system. The Commissioner's FAQ states that notification should be made within 21 days from the date of appointment.

Data processors now have direct security obligations

The 2024 amendments strengthened the position of data processors under the PDPA.

Where a data processor processes personal data on behalf of a data controller, the processor must comply directly with the Security Principle under Section 9.

This is important for organisations relying on:

  • Cloud providers
  • SaaS platforms
  • CRM providers
  • Payment providers
  • Marketing platforms
  • Analytics vendors
  • Outsourced customer-support services
  • Other third-party processors

Vendor contracts should clearly allocate responsibilities for:

  • Security
  • Confidentiality
  • Access control
  • Incident response
  • Data retention
  • Data deletion
  • Sub-processing
  • Data-subject requests
  • Cross-border processing

Personal data breach notification

The 2024 amendments introduced a statutory personal-data breach notification framework.

Where a data controller has reason to believe that a personal data breach has occurred, the controller must notify the Commissioner as soon as practicable in the prescribed manner. Where the breach causes or is likely to cause significant harm to the data subject, the data subject must also be notified without unnecessary delay.

The Commissioner's breach-notification guidance specifies that notification to the Commissioner should be made as soon as practicable and no later than 72 hours from the occurrence of the personal-data breach where the notification criteria are met.

The amended Act defines a personal data breach to include:

  • Breach of personal data
  • Loss of personal data
  • Misuse of personal data
  • Unauthorised access to personal data

Organisations should maintain an incident-response procedure that can rapidly identify, investigate, document and escalate qualifying incidents.

Cross-border personal data transfers

Malaysia regulates transfers of personal data outside Malaysia under Section 129 of the PDPA.

The 2024 amendments changed the structure of Section 129 and the Commissioner has issued dedicated guidance on cross-border transfers.

The Commissioner's cross-border guidance addresses issues including:

  • The destination jurisdiction
  • The level of protection available
  • Contractual safeguards
  • Risk assessment
  • The recipient
  • The nature of the personal data
  • The purpose of the transfer
  • Other applicable transfer conditions

Organisations using international cloud infrastructure, overseas SaaS providers, global analytics platforms or foreign processors should therefore maintain a current map of where personal data is transferred.

Data Protection Impact Assessments

Malaysia's privacy framework includes guidance on Data Protection Impact Assessments (DPIAs).

The Commissioner's DPIA materials identify quantitative thresholds and qualitative risk factors that can trigger or support the need for an assessment. Examples include processing:

  • Sensitive personal data involving more than 10,000 data subjects
  • Personal data for certain automated decision-making activities involving more than 10,000 data subjects
  • Personal data involving more than 20,000 data subjects
  • Data involving significant effects on individuals
  • Public-area monitoring
  • Innovative technologies
  • Location or behavioural tracking
  • Data relating to children or vulnerable individuals

A DPIA should examine:

  • The purpose of processing
  • Categories of personal data
  • Processing operations
  • Potential risks
  • Impact on individuals
  • Security measures
  • Retention
  • Third-party processing
  • International transfers
  • Measures to mitigate identified risks

Automated decision-making and profiling

The Malaysian Personal Data Protection Commissioner has issued guidance concerning Automated Decision-Making and Profiling (ADMP).

Businesses using the following should determine whether personal data is involved and whether additional privacy safeguards are appropriate:

  • AI systems
  • Behavioural profiling
  • Automated eligibility decisions
  • Fraud detection
  • Credit or insurance scoring
  • Personalised advertising
  • Facial recognition
  • Other automated systems

Where sensitive personal data, including biometric data, is used in automated processing, the relevant sensitive-data requirements remain important.

Security obligations

The Security Principle requires organisations to take practical steps to protect personal data against:

  • Loss
  • Misuse
  • Modification
  • Unauthorised access
  • Disclosure
  • Alteration
  • Other security risks

The 2024 amendments make the Security Principle directly applicable to both data controllers and data processors.

Organisations should consider controls such as:

  • Access management
  • Authentication
  • Encryption
  • Secure development
  • Logging and monitoring
  • Vulnerability management
  • Backup and recovery
  • Incident response
  • Employee training
  • Vendor assessments
  • Data minimisation

Data retention

The Retention Principle requires personal data not to be retained longer than necessary for the fulfilment of the purpose for which it was processed.

Businesses should establish documented retention schedules for:

  • Customer accounts
  • Marketing databases
  • Employee information
  • Consent records
  • Website analytics
  • Cookies and tracking data
  • Support records
  • Data-subject requests
  • Security logs
  • Vendor-held personal data

Retention periods should reflect both the original processing purpose and any applicable legal or contractual retention obligations.

Direct marketing

Direct marketing is specifically addressed within Malaysia's privacy framework.

Businesses conducting marketing activities should review:

  • The source of marketing information
  • The purpose for which it was collected
  • Whether consent is required
  • Marketing preferences
  • Opt-out mechanisms
  • Third-party disclosures
  • Profiling
  • Advertising platforms
  • Data retention

The PDPA provides individuals with mechanisms to object to certain direct-marketing activities, and the Commissioner can issue requirements relating to direct marketing.

Data controller registration

Certain classes of data controllers are required to register under Malaysia's registration framework.

The Commissioner's materials currently identify 13 classes of data controllers subject to registration requirements. Organisations outside those classes may still be subject to the PDPA even if they do not have the same registration obligation.

In 2026, the Commissioner also issued Circular No. 1/2026 on Registration of Data Controllers, reinforcing the current registration framework.

Businesses should therefore determine:

  • Whether they are a data controller
  • Whether they fall within a prescribed class
  • Whether registration is required
  • Whether their registration certificate is current
  • Whether any renewal or update is required

International businesses

A company does not necessarily avoid Malaysia's PDPA simply because it is incorporated outside Malaysia.

The Act can apply where a person not established in Malaysia uses equipment in Malaysia to process personal data, other than processing merely for transit. Such a person may need to nominate a representative established in Malaysia.

International businesses should therefore assess:

  • Where personal data is collected
  • Where processing occurs
  • Where systems are hosted
  • Where processors are located
  • Whether Malaysian equipment is used
  • Where personal data is transferred
  • Whether a Malaysian representative is required

Major 2024 to 2026 changes to Malaysia's PDPA

The following changes are the most important for organisations reviewing their Malaysian privacy programme.

  • Data users became data controllers. The 2024 amendments replace the terminology of “data user” with “data controller” across the Act in the relevant provisions.
  • Biometric data added to sensitive personal data. Biometric data is now expressly included within the definition of sensitive personal data.
  • Data processors have direct security obligations. Processors must comply directly with the Security Principle when processing personal data on behalf of controllers.
  • DPO requirements. Data controllers and processors must appoint DPOs where the applicable statutory thresholds or conditions are met.
  • Mandatory breach notification. Qualifying personal-data breaches must be reported to the Commissioner, with the Commissioner's guidance providing a 72-hour timeframe.
  • Data portability. Data subjects gained a statutory data-portability right, subject to technical feasibility and compatible formats.
  • Updated cross-border transfer framework. Section 129 was amended and the Commissioner has published updated cross-border transfer guidance.

Malaysia PDPA compliance checklist

Use this checklist to review your organisation's current privacy programme.

  • Identify all personal data collected
  • Identify processing purposes
  • Determine the applicable legal condition
  • Review consent mechanisms
  • Review sensitive personal data
  • Identify biometric-data processing
  • Maintain appropriate privacy notices
  • Review third-party disclosures
  • Map data processors
  • Confirm processor security obligations
  • Review data retention periods
  • Establish access and correction workflows
  • Prepare for data portability requests
  • Review direct-marketing practices
  • Assess DPO appointment requirements
  • Register the DPO where required
  • Review data-controller registration requirements
  • Implement breach-detection procedures
  • Prepare breach-notification procedures
  • Review the 72-hour notification timeframe
  • Map cross-border data transfers
  • Assess DPIA requirements
  • Review automated decision-making and profiling
  • Scan website cookies and trackers
  • Block selected non-essential trackers before applicable consent
  • Maintain consent evidence
  • Regularly review website technologies and vendors

How ConsentX helps with Malaysia PDPA compliance

Cookie and tracker discovery

ConsentX can scan your website to identify cookies, analytics scripts, advertising trackers, pixels, third-party scripts, tags and other technologies that may process personal data.

Consent management

Where consent is the applicable legal basis, ConsentX can provide configurable consent experiences that allow users to make and manage their choices.

Prior-script blocking

ConsentX can help prevent selected non-essential cookies and trackers from executing before the required consent decision.

Consent records

ConsentX can maintain records of user choices, helping organisations establish an auditable record of consent activity.

Regional controls

Use ConsentX's region rule engine to configure different privacy and consent experiences for Malaysian users and users in other jurisdictions.

Privacy request workflows

ConsentX can support workflows for managing applicable data-subject requests, including access and other privacy requests.

Privacy compliance monitoring

Regular scans can help organisations identify changes to website technologies and third-party trackers that may affect their privacy compliance programme.

Get Malaysia PDPA ready with ConsentX

Malaysia's PDPA requires more than simply displaying a privacy policy. ConsentX helps organisations operationalise website-level privacy controls through cookie and tracker discovery, consent management, prior-script blocking, consent records, regional rules and privacy-request workflows. Build a transparent and audit-ready privacy experience for users in Malaysia with ConsentX.

This page provides a general, plain-English overview of Malaysia's Personal Data Protection Act 2010 and the Personal Data Protection (Amendment) Act 2024. It is not legal advice and does not cover every sector-specific code of practice, exemption, Commissioner circular, regulatory interpretation or individual compliance circumstance. ConsentX does not replace legal advice or an organisation's broader security, governance and compliance programme. Organisations should review the current Malaysian legislation and Commissioner guidance and obtain qualified Malaysian legal advice where necessary.

How to comply with Malaysia's PDPA using ConsentX

  1. 1

    Scan your website

    Use ConsentX to identify cookies, scripts, pixels, tags and other tracking technologies deployed across your website.

  2. 2

    Identify personal-data processing

    Determine which website technologies collect, receive, store, disclose or otherwise process information relating to identifiable individuals.

  3. 3

    Identify the applicable legal condition

    Determine whether consent is required or whether another statutory condition applies to the relevant processing.

  4. 4

    Configure your consent banner

    Create a clear consent interface that explains relevant processing purposes and gives users appropriate choices.

  5. 5

    Block selected trackers

    Configure prior-script blocking for selected non-essential technologies where processing should not begin until the applicable permission has been obtained.

  6. 6

    Record consent

    Maintain evidence of consent choices, including relevant timestamps and configuration information.

  7. 7

    Enable withdrawal and preference management

    Give users an accessible mechanism to change or withdraw applicable consent choices.

  8. 8

    Review sensitive-data processing

    Identify whether your website or digital service processes sensitive personal data, including biometric data.

  9. 9

    Review third-party processors

    Identify analytics, advertising, CRM, cloud and other third-party services that process personal data on your behalf.

  10. 10

    Review cross-border transfers

    Map where personal data is transferred outside Malaysia and assess the applicable Section 129 requirements.

  11. 11

    Assess DPO requirements

    Determine whether your organisation meets the thresholds for mandatory DPO appointment.

  12. 12

    Prepare for breach response

    Maintain a process capable of identifying and escalating personal-data breaches quickly enough to meet the applicable notification requirements.

Soalan lazim