PDPA Compliance for Malaysian Businesses After the 2024 Amendment Act: What a Compliance Framework Must Cover
•

Written by

Malaysia's Personal Data Protection (Amendment) Act 2024 turned PDPA compliance from a privacy notice into an enforceable framework, rolled out in three phases between January and June 2025. The headline changes: a mandatory Data Protection Officer for businesses that meet a data-volume threshold (s.12A), a fixed data breach notification deadline to the Commissioner and to affected individuals (s.12B), a risk-based cross-border data transfer regime replacing the old ministerial whitelist, and penalties raised from RM300,000 to RM1 million with up to three years' imprisonment. This article covers what changed, who the new duties catch, and what an actual compliance framework needs to contain.
Most Malaysian business owners still think PDPA compliance means a privacy policy pasted into the website footer. That was survivable under the original 2010 Act. Under the amended Act, a regulator or a counterparty's due diligence team can now ask a business to produce a Data Protection Officer, a breach response protocol, and evidence of how personal data is mapped, secured and disposed of — and "we have a privacy notice" is not an answer to any of those.
What did the Personal Data Protection (Amendment) Act 2024 actually change?
The amendments were gazetted in 2024 and commenced in three phases rather than on a single date. Each phase added a distinct layer of obligation on top of the original 2010 Act.
Phase | In force from | What it added |
|---|---|---|
Phase 1 | 1 January 2025 | Administrative changes — electronic service of notices, continuity of existing Commissioner orders and codes of practice. |
Phase 2 | 1 April 2025 | "Data users" renamed "data controllers"; biometric data added as sensitive personal data; "personal data breach" formally defined; data processors made directly liable for the Security Principle; penalties raised to RM1 million and up to 3 years' imprisonment; cross-border transfer opened to jurisdictions with "adequate" or "substantially similar" protection. |
Phase 3 | 1 June 2025 | Mandatory Data Protection Officer appointment (s.12A); mandatory data breach notification (s.12B); new data portability right for data subjects. |
The practical effect: a business that only checked its privacy notice in 2023 has since acquired a DPO obligation, a breach-notification clock, direct processor liability, and a materially higher penalty exposure — without necessarily updating anything.
Does my business need to appoint a Data Protection Officer?
Section 12A creates the DPO appointment duty; the numeric triggers are set by the Commissioner's DPO Guidelines (Circular No. 2/2025), not written into s.12A itself. Under those guidelines, a data controller or data processor must appoint at least one DPO if it meets any one of these thresholds:
Processes the personal data of 20,000 or more data subjects; or
Processes sensitive personal data — which now includes financial and biometric data — of more than 10,000 data subjects; or
Carries out regular and systematic monitoring of personal data as a core business activity.
The threshold is assessed against actual processing volume, not headcount or revenue — a lean e-commerce or SaaS business with a large customer database can trip it well before a larger business with a small customer base does. The DPO's appointment must be reported to the Commissioner, and the officer is accountable for the organisation's day-to-day compliance.
What happens if there is a data breach now?
Section 12B creates two separate notification duties, both triggered only where the breach causes or is likely to cause significant harm:
Who is notified | Standard | Deadline |
|---|---|---|
The Commissioner | As soon as practicable | No later than 72 hours from the breach occurring |
Affected data subjects | Without unnecessary delay | No later than 7 days after the Commissioner is notified |
The 72-hour clock runs from when the breach occurs, not from when the business finishes investigating it — a business that spends a week confirming the scope of an incident before telling anyone has already missed the statutory window. Having an incident response plan that can identify, assess and notify within that timeframe is now a compliance requirement in itself, not just good practice.
What changed for sending data overseas?
The old regime required a business to check whether the destination country appeared on a ministerial whitelist before transferring personal data out of Malaysia — a list that was rarely updated and covered few jurisdictions. Phase 2 replaced it with a risk-based framework: a transfer is permitted where the receiving jurisdiction has laws that are "substantially similar" to or provide "adequate" protection comparable to the PDPA, or where the business puts its own safeguards in place — data subject consent, contractual necessity, standard contractual clauses, binding corporate rules, or a recognised certification. The Personal Data Protection Commissioner's implementing guidelines on DPO appointment and breach notification (Circulars No. 1/2025 and 2/2025, issued 25 February 2025) sit alongside separate cross-border transfer guidelines that call for a documented Transfer Impact Assessment, valid for three years. For any business running payroll, CRM or cloud infrastructure through an overseas vendor, this is the provision that actually governs day-to-day operations, not the DPO or breach rules.
Privacy notice vs compliance framework — what's actually required now
The gap between what most businesses have and what the amended Act requires is the reason enforcement risk has increased sharply since June 2025. A PDPA compliance framework is built to close that gap item by item, rather than leaving it as a single unresolved line in a due diligence checklist.
A privacy notice covers | A PDPA compliance framework covers |
|---|---|
A published statement of what data is collected | A data map of what is actually held, where it came from and where it sits |
Generic consent language | Notice and consent mechanisms in the form and manner the Act requires |
Nothing on security or retention | Defined security measures and retention/disposal standards |
No process for data subject requests | A working process for access, correction, and other data subject rights, including the new portability right |
Silent on vendors and processors | Processor contracts and cross-border transfer safeguards |
No named accountable person | A DPO where the thresholds are met, reported to the Commissioner |
No plan if something goes wrong | A breach response protocol built to the 72-hour/7-day clock |
What does non-compliance actually cost?
Beyond the increased statutory penalties — up to RM1 million and up to three years' imprisonment per offence for breaching the Data Protection Principles, applying now to processors as well as controllers — the more common exposure is commercial. (A missed breach notification under s.12B itself carries a separate, lower penalty — up to RM250,000 and/or two years' imprisonment — so the two penalty tracks should not be conflated.) Buyers running legal due diligence on an acquisition now routinely ask for evidence of PDPA compliance: a DPO appointment (where the thresholds are met), a breach protocol, and processor contracts. See our guide to due diligence in mergers, acquisitions and business transactions and to red flags in legal due diligence for how this now surfaces in practice. A business that cannot produce these loses negotiating leverage on price and warranties at exactly the point it has the least room to fix the gap. Regulatory enforcement is the tail risk; a discounted or renegotiated deal is the one that shows up far more often.
Frequently Asked Questions
Does the PDPA apply to my business if I only hold employee and supplier data, not customer data?
Yes. The Act's definition of "commercial transaction" has always been broad — any transaction of a commercial nature, including the supply or exchange of goods or services — and this has covered employer-employee dealings and supplier contracts since the original 2010 Act, not just customer-facing sales. The 2024 Amendment Act left this definition untouched; it added new obligations (DPO appointment, breach notification, cross-border transfer rules) on top of it, not a wider scope.
Do I need a Data Protection Officer if I am a small business?
Only if you meet one of the thresholds set by the Commissioner's DPO Guidelines under s.12A — 20,000+ data subjects, 10,000+ where the data is sensitive or financial, or regular systematic monitoring. Below that, the Act still applies to you, but a named DPO is not mandatory.
What counts as a notifiable data breach?
Any breach, loss, misuse or unauthorised access to personal data that causes or is likely to cause significant harm to the affected individuals. Not every incident meets that bar, which is itself a judgement call worth getting right before the clock starts running.
Is a privacy policy on our website enough to comply?
No. A notice satisfies part of the Notice and Choice principle, but says nothing about security, retention, data subject requests, processor contracts, cross-border transfers, or breach response — all of which the amended Act now expects a business to be able to evidence.
Building the framework, not just the notice
The compliance gap most businesses carry now is structural, not a wording problem in a privacy notice. Legal That Works advises Malaysian businesses on a PDPA Compliance Framework — data mapping, notice and consent, security and retention standards, a data subject request process, processor contracts and cross-border safeguards, and a breach protocol built to the statutory clock. If your business has not reviewed its position since the phase 3 changes took effect in June 2025, that review is the starting point.
This article is for general information only and does not constitute legal advice. Every business's data processing activities are different. Obtain specific advice from a qualified adviser before acting on any part of it.
Related guides
Disclaimer
The content provided on this website is intended for general informational and educational purposes only. It does not constitute legal advice, nor should it be relied upon as a substitute for professional consultation with a qualified lawyer. Every legal matter is unique, and you are strongly encouraged to seek tailored legal advice from a licensed legal practitioner before taking any action based on the information available here.
While we endeavour to ensure the accuracy and timeliness of the content, ASCOLAW and its affiliates make no representations or warranties of any kind, express or implied, about the completeness, accuracy, reliability, suitability or availability of the information contained on this website. Any reliance you place on such information is strictly at your own risk.
Author
AKMAL SAUFI MOHAMED KHALED
Managing Partner & Founder
Practice Area
Commercial
Corporate

