Data Protection in Malaysia

Data protection laws in Malaysia

Malaysia's first comprehensive personal data protection legislation, the Personal Data Protection Act 2010 (PDPA), was passed by the Malaysian Parliament on June 02, 2010 and came into force on November 15, 2013.

In 2024, amendments were introduced to the PDPA, namely the Personal Data Protection (Amendment) Act 2024 (“Amendment Act”). This was pursuant to the Personal Data Protection Department (PDP Department) shortlisting 5 issues as key proposed amendments out of 22 issues set out in the Public Consultation Paper No. 01/2020 – Review of Personal Data Protection Act 2010 (PC01/2020). The Amendment Act subsequently came into force in three stages throughout 2025. 

Most notably, the Amendment Act introduced new requirements such as appointment of a data protection officer (DPO), data breach notification and right of data portability. The requirements for cross-border personal data transfers were also enhanced. The Amendment Act also replaced the term ‘data user’ with ‘data controller’ and expanded the definition of ‘sensitive personal data’ to include biometric data. 

The PDP Department has also issued three (3) guidelines to complement the amendments to the PDPA, namely: 

  • Personal Data Protection Guidelines on Data Breach Notification (DBN Guidelines);
  • Personal Data Protection Guidelines on the Appointment of Data Protection Officer (DPO Guidelines); and
  • Personal Data Protection Guidelines No. 03/2025 on Cross-Border Personal Data Transfer (CBPDT Guidelines) which provide further clarity and guidance on the amendments. 

Specifically on the appointment of a DPO, the PDP Department issued guidelines specifically on DPO competency and training, which are: 

  • Data Protection Officer (DPO) Competency Guideline (DPO Competency Guideline);
  • Data Protection Officer (DPO) Professional Development Pathway & Training Roadmap (DPO Development Roadmap); and
  • Management of Data Protection Officer (DPO) Training Service Providers Guidelines (DPO Training Providers Guidelines).

The Digital Minister, Gobind Singh Deo has stated that there will be other guidelines on automated decision making and profiling, data protection by design, data protection impact assessment and the right to data portability. For this purpose, the relevant Public Consultation Papers to gather public opinion and feedback have already been completed. The guidelines are expected to be issued in 2026. 

The PDP Department has also issued a Public Consultation Paper on Proposed Amendments to the Personal Data Protection Regulations 2013 on August 22, 2025 to ensure alignment with the amendments to the PDPA.

Continue reading

  • no results

Back to top