Malaysia PDPA
Amended Malaysia · In force Nov 15, 2013 · no upcoming deadlines
Deadlines
Summaries for reference, not legal advice. Check the official text.
What it does
Malaysia's commercial-sector data protection law. The 2024 amendments, phased in during 2025, rename 'data users' as 'data controllers', add biometric data to sensitive data, apply the Security Principle directly to processors, replace the transfer whitelist with adequacy and safeguards tests, raise fines, and add mandatory DPOs, data breach notification and data portability.
- Who it applies to
- Anyone processing personal data in commercial transactions in Malaysia, or using equipment in Malaysia for processing (federal and state governments excluded). Certain classes of data controllers must register. The DPO and breach notification guidelines set scale-based triggers.
- Penalties
- General offences: fine up to RM 1,000,000 and/or imprisonment up to 3 years (raised from RM 500,000 / 2 years).
- Enforced by
- Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi)
- Official name
- Personal Data Protection Act 2010 (Act 709), as amended by the Personal Data Protection (Amendment) Act 2024 (Act A1727)
- Citation
- Act 709; Act A1727 (Royal Assent 9 Oct 2024, gazetted 17 Oct 2024)
- Topics
- privacy, breach-notification, biometrics, data-residency
Research notes
The phase breakdown comes from Christopher & Lee Ong's reading of the Minister's commencement notice; the pdp.gov.my notice page did not render its contents. The PDPA's original commencement (15 Nov 2013) is from established knowledge. Breach notification timelines (Commissioner within 72 hours; data subjects within 7 days) are in the Commissioner's guideline and were not re-verified here. The Personal Data Protection (Amendment) Act 2024 received royal assent on 9 Oct 2024; the original Act 709 came into force on 15 Nov 2013.
Related
Questions about Malaysia PDPA
- What are the Malaysia PDPA compliance deadlines?
- Jan 1, 2025: PDPA amendments phase 1. Apr 1, 2025: PDPA amendments phase 2. Jun 1, 2025: PDPA amendments phase 3.
- When does Malaysia PDPA take effect?
- Malaysia PDPA took effect on Nov 15, 2013.
- Who does Malaysia PDPA apply to?
- Anyone processing personal data in commercial transactions in Malaysia, or using equipment in Malaysia for processing (federal and state governments excluded). Certain classes of data controllers must register. The DPO and breach notification guidelines set scale-based triggers.
- What are the penalties under Malaysia PDPA?
- General offences: fine up to RM 1,000,000 and/or imprisonment up to 3 years (raised from RM 500,000 / 2 years).