Malaysia's Personal Data Protection Act 2010 is a sector-shaped privacy law. It regulates the processing of personal data in commercial transactions and builds the compliance framework around seven Personal Data Protection Principles. It is not structured like the GDPR, and it is not a general public-sector privacy statute. The Act is directed at data users in commercial activity and places criminal consequences behind many operational failures.
The most important point is that the Act is not satisfied by a privacy policy alone. A data user must comply with the General Principle, Notice and Choice Principle, Disclosure Principle, Security Principle, Retention Principle, Data Integrity Principle and Access Principle. Each principle has practical consequences for collection forms, contracts, marketing lists, vendor arrangements, retention schedules, access requests and cross-border transfers.
The Act applies to any person who processes, controls or authorises the processing of personal data in respect of commercial transactions. A commercial transaction includes transactions of a commercial nature, whether contractual or not, including supply or exchange of goods or services, agency, investments, financing, banking and insurance. Credit reporting business carried out by a credit reporting agency under the Credit Reporting Agencies Act 2010 is excluded from that definition.
The Act applies where the person is established in Malaysia and the personal data is processed by that person or by persons employed or engaged by that establishment. It also applies to a person not established in Malaysia who uses equipment in Malaysia for processing personal data otherwise than for transit through Malaysia. Such a person must nominate a representative established in Malaysia. The Act does not apply to the Federal Government or State Governments, and it does not apply to personal data processed outside Malaysia unless that data is intended to be further processed in Malaysia.
The role language is important. A data user is the person who processes personal data, or controls or authorises its processing, either alone, jointly or in common with others. A data processor processes personal data solely on behalf of the data user and not for its own purposes. A data subject is the individual who is the subject of the personal data.
Section 5 makes compliance with the seven principles mandatory. A data user that contravenes the principles commits an offence and may face a fine of up to RM300,000, imprisonment for up to two years, or both. This is one of the strongest reasons to treat the principles as operational controls, not high-level policy language.
The General Principle in section 6 requires consent for ordinary personal data unless processing is necessary for specified grounds such as contract performance, pre-contractual steps, legal obligation, vital interests, administration of justice, or statutory functions. It also requires that processing be for a lawful purpose directly related to the data user's activity, necessary or directly related to that purpose, and adequate but not excessive.
The Notice and Choice Principle in section 7 requires written notice to the data subject. The notice must describe the personal data, purposes, source where available, access and correction rights, complaint contact route, classes of third-party recipients, available choices for limiting processing, whether supply is obligatory or voluntary, and consequences of failure to supply obligatory data. The notice must be given as soon as practicable at the first request for personal data, first collection, or before use for a new purpose or disclosure to a third party. It must be in both the national and English languages.
The Disclosure Principle in section 8 restricts disclosure without consent for purposes other than the purpose disclosed at collection or a directly related purpose, or to parties outside the specified class of third parties. Section 39 provides specific circumstances where disclosure may occur, including consent, crime prevention or investigation, legal requirement or court order, reasonable belief of legal entitlement, reasonable belief that consent would have been given, or public interest as determined by the Minister.
The Security Principle in section 9 requires practical steps to protect personal data against loss, misuse, modification, unauthorised or accidental access or disclosure, alteration or destruction. The data user must consider the nature of the data, likely harm, storage location, equipment security, personnel reliability and secure transfer measures. Where a data processor is used, the data user must ensure that the processor gives sufficient guarantees on technical and organisational security and takes reasonable steps to comply with those measures.
The Retention Principle in section 10 prohibits keeping personal data longer than necessary for the relevant purpose and requires reasonable steps to destroy or permanently delete data when it is no longer required. The Data Integrity Principle in section 11 requires reasonable steps to ensure personal data is accurate, complete, not misleading and kept up to date. The Access Principle in section 12 gives the data subject access and correction rights, subject to statutory refusal grounds.
Malaysia's Act contains a registration system for prescribed classes of data users. The Minister may, on the Commissioner's recommendation, specify classes of data users who must register. A data user within such a class must apply to the Commissioner and obtain a certificate of registration. Processing personal data without the required certificate is an offence punishable by a fine of up to RM500,000, imprisonment for up to three years, or both.
Registration is not the whole compliance programme. A data user outside the prescribed registration classes still has to comply with the other provisions of the Act. Conversely, a registered data user can still breach the principles, ignore rights requests, violate a code of practice, or mishandle transfers. Registration is an entry gate for specified classes; it is not proof of full compliance.
The Act allows the Commissioner to designate data user forums for specific classes of data users. These forums may prepare codes of practice, and the Commissioner may register them if they are consistent with the Act and provide adequate protection. Where no forum prepares a code, or no relevant forum exists, the Commissioner may issue a code of practice directly.
Once a code of practice applies to a class of data users, all data users in that class must comply with it. Failure to comply with an applicable code is an offence punishable by a fine of up to RM100,000, imprisonment for up to one year, or both. For regulated sectors, this means compliance cannot be assessed only from the Act. The applicable registered code may contain the operational standard.
Section 30 gives an individual the right to be informed whether their personal data is being processed and to request access to that data. Under section 31, the data user must comply with a data access request within 21 days. If full compliance is not possible within that period, the data user must notify the requestor before the period expires, explain the reasons, comply to the extent possible, and complete compliance within a further 14 days.
Section 34 gives the right to request correction where personal data is inaccurate, incomplete, misleading or not up to date. Section 35 requires the data user to correct the data within 21 days where satisfied that correction is required, provide a copy of the corrected data, and in relevant cases notify third parties to whom the data was disclosed in the previous 12 months. If more time is needed, the same additional 14-day structure applies.
Section 38 allows a data subject to withdraw consent by written notice. Once the notice is received, the data user must cease processing the personal data. Failure to do so is an offence punishable by a fine of up to RM100,000, imprisonment for up to one year, or both.
Section 42 gives a data subject the right to prevent processing likely to cause substantial damage or substantial distress where that damage or distress is unwarranted. Section 43 gives the right to require processing for direct marketing to stop or not begin. If the data user fails to comply and the Commissioner requires compliance, failure to obey the Commissioner's requirement is an offence punishable by a fine of up to RM200,000, imprisonment for up to two years, or both.
Sensitive personal data includes information about physical or mental health or condition, political opinions, religious beliefs or similar beliefs, commission or alleged commission of any offence, and any other personal data determined by the Minister. Section 40 prohibits processing sensitive personal data unless one of the statutory conditions applies.
The first route is explicit consent. Other routes include necessity for employment law rights and obligations, vital interests where consent cannot be given or obtained, medical purposes handled by healthcare professionals or persons under equivalent confidentiality duties, legal proceedings, legal advice, legal rights, administration of justice, statutory functions, Minister-approved purposes, or information deliberately made public by the data subject. Contravention of section 40 is an offence punishable by a fine of up to RM200,000, imprisonment for up to two years, or both.
A Malaysian e-commerce company collects customer data through a checkout form and links to an English-only privacy policy. The consent checkbox may look familiar, but the PDPA requires a written notice containing specific information and requires that notice to be in both the national and English languages. If the notice does not describe the purpose, third-party classes, access and correction rights, choices for limiting processing, whether supply is mandatory or voluntary, and consequences of non-supply, the issue is not cosmetic. It is a Notice and Choice Principle failure.
Section 129 restricts transfers of personal data outside Malaysia. A data user must not transfer personal data to a place outside Malaysia unless that place has been specified by the Minister on the Commissioner's recommendation. A place may be specified if it has a law substantially similar to the Act, serves the same purposes, or ensures an adequate level of protection at least equivalent to the Malaysian Act.
The Act also provides exceptions. A transfer may be made where the data subject consents, where the transfer is necessary for a contract with the data subject, where it is necessary for a contract with a third party at the data subject's request or in the data subject's interest, where it is for legal proceedings or legal advice or legal rights, where it is needed to avoid or mitigate adverse action and consent is impracticable but would likely have been given, where the data user has taken all reasonable precautions and exercised due diligence to ensure the data will not be processed in a way that would breach the Act if done in Malaysia, where it is necessary to protect vital interests, or where it is necessary in the public interest as determined by the Minister.
This means international transfer governance cannot be reduced to a generic clause. The data user must identify the destination, check whether it is specified, and document the transfer basis or exception relied on. Due diligence, contractual restrictions, security controls and purpose limits are especially important where the transfer relies on reasonable precautions and due diligence.
The Personal Data Protection Commissioner implements and enforces the Act, advises the Minister, promotes codes of practice, monitors compliance, issues circulars and enforcement notices, carries out inspections and investigations, and cooperates with foreign privacy authorities. Individuals may complain to the Commissioner about acts or practices that may contravene the Act or a code of practice.
The Commissioner may inspect personal data systems, publish reports, investigate complaints, issue enforcement notices, vary or cancel enforcement notices, and use enforcement powers including search and seizure, access to computerised data, production requests, attendance requirements and arrest powers in appropriate cases. Decisions of the Commissioner may be appealed to the Appeal Tribunal, whose decisions are final and binding and may be enforced through the Sessions Court.
Section 130 creates a separate offence for knowingly or recklessly collecting or disclosing personal data held by a data user, or procuring disclosure of such data, without the data user's consent. Selling or offering to sell personal data collected in breach of the section is also an offence. The penalty is a fine of up to RM500,000, imprisonment for up to three years, or both.
Sections 2–3 — Application and non-application: applies to commercial transaction processing; excludes Federal and State Governments.
Section 4 — Definitions: personal data, sensitive personal data, data user, data processor, data subject, processing and commercial transactions.
Sections 5–12 — Seven Personal Data Protection Principles: General, Notice and Choice, Disclosure, Security, Retention, Data Integrity and Access.
Sections 13–20 — Registration: prescribed classes of data users must register and obtain certificates.
Sections 21–29 — Data user forums and codes of practice: sector codes may be registered or issued; non-compliance is an offence.
Sections 30–37 — Access and correction rights, response timelines and refusal notices.
Section 38 — Withdrawal of consent: data user must cease processing after written withdrawal.
Section 40 — Sensitive personal data: explicit consent or statutory necessity conditions required.
Sections 42–43 — Rights to prevent damaging or distressing processing and to stop direct marketing.
Section 45 — Exemptions for personal or household affairs, crime, health, research, court orders, regulatory functions and journalism/literary/artistic purposes.
Sections 47–49 — Commissioner: appointment, functions and powers.
Sections 101–109 — Inspection, complaints, investigations and enforcement notices.
Section 129 — Cross-border transfers: restricted unless the destination is specified or an exception applies.
Section 130 — Unlawful collection, disclosure, procurement, sale or offer to sell personal data.
Malaysia's PDPA is an operating law for commercial data use. Your compliance programme should prove scope, registration status, bilingual notice, consent or statutory necessity, purpose limitation, disclosure control, processor security, retention deletion, data accuracy, access and correction handling, sensitive data safeguards, direct marketing suppression, cross-border transfer basis and incident-ready records. The highest-risk mistake is treating the Act as a privacy-policy exercise when it is actually a principles, registration, rights and offence framework.