Data Protection in Malaysia

Collection and processing in Malaysia

Under the PDPA, subject to certain exceptions, data controllers are generally required to obtain a data subject’s consent for the processing (which includes collection and disclosure) of his or her personal data. Where consent is required from a data subject under the age of eighteen (18) years of age, the data controller must obtain consent from the parent, guardian or person who has parental responsibility for the data subject. The consent obtained from a data subject must be in a form that such consent can be recorded and maintained properly by the data controller.

Pursuant to PC01/2020, the Commissioner has sought feedback on its proposal to amend the General Principle provision to add clarity to the data subject's consent, whether it should be in a specific provision and the impact of having a default consent. 

Malaysian law contains additional data protection obligations, including, for example, a requirement to notify data subjects regarding the purpose for which their personal data are collected and a requirement to maintain a list of any personal data disclosures to third parties.
The Personal Data Protection Standard 2015 (“Standards”) set out the Commission’s minimum requirements for processing personal data. The Standards include the following:

  • Security Standard For Personal Data Processed Electronically
  • Security Standard For Personal Data Processed Non-Electronically
  • Retention Standard For Personal Data Processed Electronically And Non-Electronically
  • Data Integrity Standard For Personal Data Processed Electronically And Non-Electronically

However, the Commissioner has issued the Public Consultation Paper No. 04/2024: Personal Data Protection Standards (PC04/2024) on October 01, 2024 to seek feedback from the public on the revision of the above minimum requirements. The proposed revisions under the PC04/2024 include:

  • Replacing “black and white” rules (i.e. prescriptive and specific instructions or measures that data controllers must comply with) with requirements that are outcome based;
  • Removing the differentiation between personal data processed electronically or physically and provide the security standards which applies to personal data generally; and
  • The role of certification schemes to demonstrate compliance with the Standards.

No formal date has been announced for the issuance of the revised Standards.

Continue reading

  • no results

Previous topic
Back to top