Data Protection in Malaysia

Security in Malaysia

Under the PDPA, data controllers have an obligation to take ‘practical’ steps to protect personal data, and in doing so, must develop and implement a security policy. The Commissioner may also, from time to time, set out security standards with which the data controller must comply. The Amendment Act has also imposed the direct obligation on data processors to comply with the Security Principle under the PDPA.

In addition, the Standards provide separate security standards for personal data processed electronically and for personal data processed non-electronically (among others) and require data controllers to have regard to the Standards in taking practical steps to protect the personal data from any loss, misuse, modification, unauthorized or accidental access or disclosure, alteration or destruction. The Standards are currently under review.

Continue reading

  • no results

Previous topic
Back to top