EnglishMS
Malaysia flag

Malaysia

Malaysia Data Privacy Laws: PDPA 2010 Compliance Guide (2026)

By Recording Law Editorial TeamReviewed July 23, 202624 min read
Malaysia Data Privacy Laws: PDPA 2010 Compliance Guide (2026)

Frequently Asked Questions

Does Malaysia's PDPA apply to foreign companies?

Yes. The PDPA applies to any organization that processes personal data in connection with commercial transactions using equipment or facilities located in Malaysia. Foreign companies that use Malaysian servers, data centers, or other infrastructure to process personal data fall within the PDPA's scope, regardless of where the company is incorporated. The 2024 Amendment reinforced this extraterritorial reach.

What are the penalties for violating Malaysia's PDPA?

Since the 2024 Amendment took effect on 1 April 2025, contravention of any of the seven data protection principles carries a maximum fine of RM 1,000,000 (approximately USD 210,000 to 225,000) and/or imprisonment for up to 3 years. Specific offences carry their own levels: failure to notify the Commissioner of a data breach attracts fines up to RM 250,000 and/or 2 years imprisonment; unauthorized cross-border transfers carry fines up to RM 300,000 and/or 2 years imprisonment. These are quasi-criminal offences prosecuted through Malaysia's criminal justice system.

When must a data breach be reported under the PDPA?

Data controllers must notify the Personal Data Protection Commissioner within 72 hours of becoming aware of the breach, if it causes or is likely to cause significant harm, or if it affects more than 1,000 data subjects. The JPDP's February 2025 Guideline clarified that the clock starts from discovery, not from the moment the breach occurred. Affected individuals must be notified without undue delay and no later than 7 days after notifying the Commissioner. Organizations must maintain a breach register for at least two years.

Is a Data Protection Officer required under Malaysian law?

Not all organizations need a DPO. Since 1 June 2025, organizations must appoint a DPO if they process personal data of 20,000 or more individuals, sensitive personal data of 10,000 or more individuals, or conduct systematic monitoring of individuals on a large scale. The DPO must be registered with the Commissioner within 21 days of appointment at daftar.pdp.gov.my. The DPO may be an internal employee or external consultant.

Can personal data be transferred outside Malaysia under the PDPA?

Yes, but with conditions. The 2024 Amendment replaced the old whitelist system (which was never populated) with an adequacy-based framework effective 1 April 2025. Data controllers must conduct a Transfer Impact Assessment before sending personal data overseas. Transfers are permitted to countries with data protection laws substantially similar to the PDPA. Where adequacy cannot be established, organizations can use standard contractual clauses, binding corporate rules, explicit informed consent, or contractual necessity. No formal adequacy determinations had been issued by the Commissioner as of mid-2026.

Which industries must register with the JPDP under Malaysia's PDPA?

Data controllers in 14 regulated sectors must register with the Commissioner before processing personal data. The sectors are: communications, banking and finance, insurance, healthcare, tourism, transportation, education, direct selling, professional services (legal, audit, accountancy, engineering, architecture), retail and wholesale, employment, real estate, utilities, and pawnbrokers and moneylenders. Registration certificates must be renewed at least annually and displayed at the principal place of business.

Is a DPIA required under Malaysia's PDPA?

The JPDP issued the final DPIA Guideline on 8 May 2026, following the public consultation that opened in March 2025. The guideline addresses processing that involves sensitive personal data of 10,000 or more individuals, personal data of 20,000 or more individuals for automated decision-making purposes, or general personal data of 20,000 or more individuals. Whether the guideline imposes binding obligations or advisory best practice, and its effective date, had not been independently confirmed as of this review. The DPO Appointment Guideline already expects DPOs to conduct DPIAs as part of their responsibilities, and organizations subject to DPO requirements should review the published guideline to align their procedures.

Updates

Added coverage of the three guidelines the JPDP issued on 8 May 2026 (Data Protection Impact Assessment, Data Protection by Design, and Automated Decision-Making and Profiling), concluding the 2025 consultations referenced in the prior update. Corrected four passages that still described these guidelines as unissued 'as of mid-2026' (Automated Decision-Making section, Data Protection Impact Assessments section, Recent Developments timeline, and related FAQ) without asserting whether the guidelines are binding or advisory, since that was not independently confirmed. Added 3 internal links (Data Protection Officer requirements, data localization, standard contractual clauses).

Expanded to ~5,800 words. Added Registration Regime H2 (14 regulated sectors). Added Recent Developments H2 covering 2025-2026 JPDP guidelines and Data Sharing Act 2025. Fixed critical factual error: 72-hour breach notification clock runs from discovery per JPDP Guideline (not from occurrence as previously stated). Updated [GDPR](/world-laws/world-data-privacy-laws) comparison accordingly. Added DPO systematic-monitoring threshold. Added DPO Training Guideline (July 2025). Added DPIA and automated decision-making guideline consultations. Added enforcement statistics (33 compounded cases, RM 108,000 highest fine). Fixed internal link in KeyTakeaways. Added 8 new sources.

Sources and References

  1. Personal Data Protection Act 2010 (Act 709) - Full Text(pdp.gov.my).gov
  2. Personal Data Protection (Amendment) Act 2024 - JPDP(pdp.gov.my).gov
  3. Principles of Personal Data Protection - JPDP(pdp.gov.my).gov
  4. Personal Data Protection Guidelines on DPO Appointment - JPDP(pdp.gov.my).gov
  5. Personal Data Protection Guidelines on Cross-Border Transfer - JPDP(pdp.gov.my).gov
  6. Cross Border Personal Data Transfer Guidelines No. 3/2025 - JPDP(pdp.gov.my).gov
  7. Public Consultation Paper No. 1/2025 DPIA Guideline - JPDP(pdp.gov.my).gov
  8. Malaysia Personal Data Protection Act - Malaysia Government Portal(malaysia.gov.my).gov
  9. Data Sharing Act 2025 (Act 864) Full Text - Jabatan Digital Negara(jdn.gov.my).gov
  10. Personal Data Protection Act 2010 Full Text - Invest Malaysia(investmalaysia.gov.my).gov
  11. From Legislative Reform to Practical Guidance: PDPA Amendments - Mayer Brown(mayerbrown.com)
  12. Malaysia PDPA Amendments: Enhanced Data Governance - IAPP(iapp.org)
  13. New Horizons in Data Protection: Malaysia PDPA Amendment 2024 - Data Protection Report(dataprotectionreport.com)
  14. Malaysia Guidelines on Data Breach Notification and DPO - DLA Piper Privacy Matters(privacymatters.dlapiper.com)
  15. Malaysia PDPA Amendment Act 2024 - Baker McKenzie(insightplus.bakermckenzie.com)
  16. Navigating Malaysia Mandatory Breach Notification - HHQ Law(hhq.com.my)
  17. Malaysia New Data Protection Requirements June 2025 - One Asia Lawyers(oneasia.legal)
  18. Data Protection and Privacy 2026 Malaysia - Chambers and Partners(practiceguides.chambers.com)
  19. PDPA Public Consultations DPIA and ADM - Rahmat Lim and Partners(rahmatlim.com)
  20. Malaysian Cross-Border Data Transfer Guidelines 2025 - CMS Law-Now(cms-lawnow.com)
  21. Malaysia Digital Course: Data Protection and AI - Future of Privacy Forum(fpf.org)
  22. Malaysia Data Sharing Act 2025 - DFDL(dfdl.com)
  23. JPDP, Data Protection Impact Assessment Guideline (DPIA) — and companion Data Protection by Design and Automated Decision-Making and Profiling guidelines, issued 8 May 2026(pdp.gov.my).gov
Share: