PDPA (Personal Data Protection Act 2010)
Malaysia's primary legislation governing the processing of personal data in commercial transactions, requiring organisations to protect individuals' personal information.
The Personal Data Protection Act 2010 (PDPA) is Malaysia's data privacy law, enforced by the Department of Personal Data Protection (JPDP). It regulates how businesses collect, store, use, and share personal data of individuals in the context of commercial transactions. Any organisation in Malaysia that processes customer, employee, or supplier personal data must comply.
The 7 Data Protection Principles
- General Principle — process data only with consent and for a lawful purpose
- Notice and Choice Principle — inform individuals what data is collected and how it will be used
- Disclosure Principle — do not disclose personal data without consent or legal authority
- Security Principle — take practical steps to protect data from loss, misuse, and unauthorised access
- Retention Principle — do not keep data longer than necessary for its purpose
- Data Integrity Principle — ensure data is accurate, complete, and up to date
- Access Principle — allow individuals to access and correct their personal data
Penalties for Non-Compliance
Violations of the PDPA can result in fines up to RM500,000, imprisonment up to 3 years, or both. With the 2024 amendments strengthening enforcement, Malaysian businesses — especially SMEs — must take compliance seriously. This includes having proper data protection policies, consent mechanisms, and breach notification procedures.
Practical Steps for SMEs
- Appoint a data protection officer or assign responsibility to a senior staff member
- Conduct a data inventory — know what personal data you hold and where it is stored
- Implement a clear privacy notice on your website and at all data collection points
- Obtain proper consent before collecting or using personal data
- Establish a data breach response plan with clear reporting procedures
- Train staff on data handling procedures relevant to their roles