top of page
Search

Malaysia's Personal Data Protection (Amendment) Act 2024

Sep 14
3 min read

Key Changes for Businesses

The Personal Data Protection Act 2010 (“Act”) has been Malaysia's principal data protection statute since 2013, without substantive amendment until the Personal Data Protection (Amendment) Act 2024 (“Amendment Act”) was gazetted on 17 October 2024. The Amendment Act came into force in phases between 1 January 2025 and 1 June 2025, with more demanding obligations, which includes, among others, the mandatory appointment of a data protection officer and mandatory breach notification. This month’s firasat summarises the changes that matter most for businesses operating in or serving the Malaysian market.


1. From "Data User" to "Data Controller" — and Direct Duties for Processors

The Amendment Act replaces "data user" with "data controller" throughout the principal Act and clarifying that a controller determines the purposes and manner of processing while a processor acts on the controller's behalf. For the first time, processors are made directly subject to the security principle under section 9 of the Act, and can face criminal liability for failing to protect personal data from loss, misuse or unauthorised access — extending statutory exposure to outsourced vendors and cloud providers that previously carried none.


2. Mandatory Data Breach Notification

Malaysia previously had no general legal duty to report data breaches. Under the Amendment Act, a controller that has reason to believe a breach has occurred, and that it causes or is likely to cause significant harm — for example, a heightened risk of identity fraud, or a breach affecting a large number of individuals — must notify the Commissioner as soon as practicable and in any event within 72 hours, and must separately notify affected data subjects within 7 days of notifying the Commissioner. Both notices must describe the breach, its likely consequences and the remedial steps taken, and records must be kept for at least 2 years.


3. Mandatory Appointment of a Data Protection Officer

Both controllers and processors must appoint at least one data protection officer (“DPO”) and register the appointment with the Commissioner through the personal data protection system within 21 days, with any change notified within 14 days. Appointment is mandatory where an organisation processes the personal data of more than 20,000 subjects, sensitive or financial data of more than 10,000 subjects, or carries out large-scale systematic monitoring such as behavioural profiling or CCTV surveillance. The DPO must be Malaysia-resident and competent under the Act.


4. Wider Definition of Sensitive Personal Data

The Amendment Act extends "sensitive personal data" to cover biometric data — facial recognition templates, fingerprints and voice identifiers — triggering a stricter consent standard and heightened security expectations for any biometric attendance, e-KYC or access-control system.


5. New Right to Data Portability

Data subjects may now request that their personal data be transmitted from one controller to another, where this is technically feasible and the data is processed by automated means, which is considered a new operational obligation for organisations. 


6. Steeper Penalties and Personal Liability for Directors

Maximum penalties for breach of the Act's core data protection principles have more than tripled, to fines of up to RM1,000,000 (from RM300,000) and imprisonment of up to 3 years (from 2 years), or both. Directors, chief executive officers and managers can be personally liable for an offence by the company unless they prove it occurred without their knowledge and that reasonable preventive steps were taken. 


What Businesses Should Consider Now 

The changes together push Malaysia's regime much closer to international norms and raise the compliance bar for any organisation that collects, processes or transfers personal data connected to Malaysia. As a starting point, businesses should:

  • map their personal data flows, including biometric data and any transfers outside Malaysia, to see where the amended rules apply;

  • assess whether the mandatory-DPO thresholds are met and, if so, appoint and register a suitably qualified DPO;

  • put in place a breach-response plan that can meet the 72-hour and 7-day data-subject deadlines; and 

  • update privacy notices and consent mechanisms for the wider sensitive-data definition and the portability right and brief the board on directors' personal liability exposure.

 
 
bottom of page