PDPA Compliance in Malaysia: What the 2024 Amendment Means for Your Business
Primary Guard · July 21, 2026 · 8 min read
Malaysia's PDPA was amended in 2024, with breach notification and DPO rules live from June 2025. Here is what changed, the deadlines, and how to comply.
Malaysia's Personal Data Protection Act changed more in 2025 than it had in the previous decade. The Personal Data Protection (Amendment) Act 2024 introduced mandatory data breach notification, mandatory appointment of a data protection officer, and penalties that now reach individual decision-makers. The headline obligations took effect on 1 June 2025. For years many Malaysian organisations treated PDPA as paperwork. That is no longer a safe assumption.
This guide explains what the PDPA requires, exactly what the 2024 amendment changed, the deadlines and reporting timelines you need to build into your incident response, and the practical steps organisations should take. It is written for business owners, compliance and IT teams, and the newly required data protection officers who now sit at the centre of the regime.
What is the PDPA?
The Personal Data Protection Act 2010, known as Act 709, is Malaysia's primary law governing the processing of personal data in commercial transactions. It was passed in 2010, came into force in November 2013, and is enforced by the Personal Data Protection Commissioner under the Ministry of Digital.
Personal data means any information that can identify an individual, directly or indirectly. In practice that covers names, MyKad numbers, contact details, location data, financial records, and, following the 2024 amendment, biometric data. The Act rests on a set of core principles covering consent, purpose limitation, disclosure, security, retention, data integrity, and access, which together define how organisations may collect, use, store, and share personal data.
Crucially, the PDPA applies to almost every business, not only regulated financial institutions. If your organisation handles customer, employee, or supplier data in the course of commercial activity in Malaysia, you are in scope.
What the 2024 amendment changed
The Personal Data Protection (Amendment) Act 2024 was passed in July 2024 and rolled out in three phases across 2025: 1 January, 1 April, and 1 June. The 1 January stage covered ancillary provisions and terminology and introduced no new substantive obligations. The substantive obligations, including data processor duties, breach notification, and DPO appointment, landed through the April and June stages, with the headline requirements live from 1 June 2025. These are the changes that matter.
Data controllers and data processors
The amendment replaces the term "data user" with "data controller", aligning Malaysia's language with the EU's General Data Protection Regulation. More significantly, it creates direct obligations for "data processors", the third parties that process data on a controller's behalf. Processors are now bound by the Security Principle in their own right, which means vendor contracts and cloud arrangements need to be reviewed so responsibilities are clearly allocated.
Mandatory data breach notification
This is the single biggest operational change. Under the new breach notification regime, a data controller that has reason to believe a personal data breach has occurred must notify the Commissioner as soon as practicable, and in any case no later than 72 hours from when the breach occurred or from when the controller became aware of it. If notification cannot be made within 72 hours, the controller must submit a written explanation of the delay with supporting evidence.
The threshold works in two tiers. Where a breach is of significant scale, meaning it affects more than 1,000 data subjects, the controller must notify the Commissioner. Where a breach causes or is likely to cause significant harm, the controller must notify both the Commissioner and the affected individuals. Notification to affected data subjects must be made without unnecessary delay, and no later than 7 days after the initial notification to the Commissioner. Additional details can be provided in phases, up to 30 days from the initial notification.
The 72-hour clock is the part organisations underestimate. It runs from the occurrence or detection of the breach, not from the moment you conclude that it is serious. In practice, that means you cannot meet this obligation without the ability to detect and triage incidents quickly, which is a security operations capability, not a legal one.
Mandatory data protection officer
From 1 June 2025, both data controllers and data processors must appoint one or more data protection officers where their processing meets the thresholds set out in the Commissioner's DPO Guideline. The DPO advises the organisation, monitors compliance, and acts as the point of contact with the Commissioner and with data subjects. Appointing a DPO does not transfer the organisation's obligations to that person. The organisation remains accountable.
Data portability
Also from June 2025, individuals can request that their personal data be transferred to another service provider in a structured, commonly used format. This creates a new operational workflow for IT and compliance teams, who must be able to locate, package, and transmit an individual's data on request.
Cross-border data transfer
The amendment, together with the Commissioner's Cross Border Personal Data Transfer Guidelines, clarifies when personal data may leave Malaysia. Transfers are permitted where the destination has a law substantially similar to the PDPA or provides an adequate level of protection, supported by a transfer impact assessment. They are also permitted where another lawful basis, such as consent or contractual necessity, applies. Organisations using overseas cloud providers or offshore processing should map their data flows against these conditions.
Stronger penalties and active enforcement
The amendment raised the maximum penalty for breaching data protection principles to a fine of up to RM1 million and imprisonment of up to three years. Enforcement has become visibly more active: in March 2025 the Commissioner published a list of organisations penalised for non-compliance, with reported fines in recent actions ranging from roughly RM12,500 to RM108,000. The direction of travel is clear.
The deadlines and timelines to build in
Two categories matter here. The first is the amendment's own commencement, which is complete: the headline obligations have been in force since 1 June 2025, so compliance is due now, not at some future date. The second is the reporting clock that applies whenever an incident occurs:
- 72 hours: notify the Commissioner from the occurrence or detection of a notifiable breach.
- 7 days: notify affected data subjects, from the initial notification to the Commissioner, where significant harm is likely.
- 30 days: the window for providing additional information to the Commissioner in phases.
Because these are triggered by events rather than fixed dates, the only way to be ready is to have the detection, assessment, and notification workflow built and rehearsed before an incident happens.
How to approach PDPA compliance
For most organisations, a practical sequence looks like this. Start with a data mapping exercise. Know what personal data you hold, where it lives, who processes it, and where it flows, including across borders. Appoint and empower a DPO, and update your privacy notices and consent mechanisms to reflect the amended terminology and obligations. Review and renegotiate contracts with data processors so that security responsibilities and breach cooperation duties are explicit.
Then build the breach response capability, because the 72-hour obligation is the requirement most likely to catch an organisation out. That means a documented incident response playbook covering detection, containment, assessment, and notification, tested through tabletop exercises, and underpinned by the technical ability to detect a breach in hours rather than weeks. Finally, maintain records of processing activities and of any notification decisions, including justifications where you decided not to notify, since good documentation is what demonstrates good faith under regulatory scrutiny.
Where a managed security partner fits
Several PDPA obligations are, at their core, security operations problems rather than paperwork. The 72-hour breach notification duty depends on being able to detect and triage incidents quickly, which is exactly what a managed detection and response and security operations centre model provides. The Security Principle, now binding on processors as well as controllers, calls for technical safeguards such as identity and access control, encryption, endpoint protection and monitoring. Cross-border transfer assessments and vendor security reviews align with third-party risk and threat intelligence services. Governance, record-keeping, and DPO support align with a structured security services programme.
Primary Guard supports organisations across Malaysia, Indonesia, and Thailand on these areas, pairing regional security operations with governance and testing services. For businesses that lack the in-house capacity to detect breaches inside the 72-hour window, a free assessment is a practical first step, and partnering is often the fastest route to closing the gap between a legal obligation and an operational reality.
If your organisation is a financial institution regulated by Bank Negara Malaysia, read this alongside our BNM RMiT compliance guide, since you fall under both regimes.
Key takeaways
The 2024 amendment turned Malaysia's PDPA from a largely dormant policy into an operational duty with real deadlines and real penalties. The obligations are already in force, the 72-hour breach clock rewards organisations that can detect incidents fast, and the newly required DPO now owns day-to-day compliance. Treating this as a security and operations programme, rather than a one-off legal review, is what separates the organisations that are ready from those that will be scrambling when an incident hits.
This article is provided for general information and does not constitute legal advice. Organisations should refer to the Personal Data Protection Act 2010, the 2024 amendment, and the Commissioner's guidelines, and consult qualified advisers on their specific obligations.
Frequently Asked Questions
Is PDPA compliance mandatory in Malaysia?
Yes. The Personal Data Protection Act 2010 is mandatory for any organisation processing personal data in commercial transactions in Malaysia. The 2024 amendment strengthened obligations and increased penalties.
When did the PDPA 2024 amendment take effect?
It was passed in July 2024 and implemented in three phases across 2025, on 1 January, 1 April, and 1 June. The headline obligations, mandatory breach notification and mandatory DPO appointment, took effect on 1 June 2025.
What is the PDPA data breach notification timeline?
Notify the Commissioner as soon as practicable and no later than 72 hours from the occurrence or detection of a notifiable breach. Where significant harm is likely, also notify affected data subjects without unnecessary delay and within 7 days of the initial notification to the Commissioner.
When must a data breach be reported to affected individuals?
When the breach causes or is likely to cause significant harm to those individuals, such as physical harm, financial loss, or damage to credit records or property. Breaches of significant scale, over 1,000 data subjects, must be reported to the Commissioner even where individual notification is not required.
Does my organisation need a data protection officer?
Both data controllers and data processors must appoint at least one DPO where their processing meets the thresholds in the Commissioner's DPO Guideline, in force from 1 June 2025. Appointing a DPO does not remove the organisation's own accountability.
What are the penalties for PDPA non-compliance?
The amendment raised the maximum penalty for breaching data protection principles to a fine of up to RM1 million and imprisonment of up to three years, alongside more active enforcement by the Commissioner.