For most of its history, Malaysia's Personal Data Protection Act 2010 (PDPA) was a relatively low-stakes piece of legislation — modest penalties, no mandatory compliance officer, and enforcement that rarely made headlines. The Personal Data Protection (Amendment) Act 2024 changed that. By the time its final phase took effect on 1 June 2025, Malaysian organisations that process personal data were operating under materially higher compliance obligations, with much sharper penalties for getting it wrong.
A Three-Phase Rollout
The amendments didn't take effect all at once. They rolled out in three stages:
- 1 January 2025 — largely administrative changes to the Act's structure and definitions.
- 1 April 2025 — updated terminology, including the renaming of "data user" to "data controller" to align with international norms.
- 1 June 2025 — the changes with the most day-to-day impact: mandatory Data Protection Officer (DPO) appointments and new data breach notification obligations.
Do You Need to Appoint a Data Protection Officer?
Since 1 June 2025, organisations must appoint a DPO if they meet any one of three criteria under the Personal Data Protection Commissioner's (PDPC) implementing guidelines:
- Processing personal data of more than 20,000 individuals
- Handling sensitive or financial data of more than 10,000 individuals
- Carrying out regular and systematic monitoring of personal data
A DPO doesn't need a specific certification, but must be able to demonstrate competence in data protection principles, IT security, and the organisation's own operations. They must also be ordinarily resident in Malaysia — spending at least 180 days a year in the country — and proficient in both Bahasa Melayu and English. The appointment runs for a minimum of two years, and the role can be full-time or part-time depending on the organisation's size. The requirement applies equally to data controllers and data processors, so vendors who process data on a client's behalf aren't exempt.
The New Breach Notification Rules
Before the amendment, the PDPA had no statutory breach notification requirement at all. That's now changed: for a breach causing significant harm — including one affecting over 1,000 individuals, or involving sensitive data — organisations must notify the PDPC within 72 hours of becoming aware of it, and notify affected data subjects as soon as practicable afterward.
What's at Stake
Penalties under the amended Act are substantially higher than before. The maximum fine for a breach of a data protection principle rises to RM1 million, up from RM300,000, alongside up to three years' imprisonment (previously two). Directors and managers can be held personally liable for a company's breach unless they can show they had no knowledge of, and did not consent or connive in, the offence, and had taken reasonable preventative measures.
Practical Steps for Malaysian Organisations
Regardless of whether your organisation crosses the DPO threshold, the amendment is a reasonable prompt to review how personal data actually moves through your systems:
- Map what you hold — which systems store personal data, how much, and how sensitive it is, against the 20,000 / 10,000 thresholds above.
- Decide on a DPO — even organisations below the threshold often benefit from naming a data protection point of contact internally.
- Review vendor and hosting arrangements — know where your data physically resides and who else can access it, since this affects both your breach exposure and your response time if something goes wrong.
- Write down a breach response plan — with a 72-hour clock now running from the moment you become aware of an incident, an ad hoc response isn't workable.
Where Software Choices Come In
None of this is a checklist a piece of software can complete on your behalf — PDPA compliance is an organisational responsibility, and this article isn't a substitute for legal advice. But the systems an organisation runs on do shape how hard that responsibility is to carry out in practice. Knowing exactly where your workflow and communication data is hosted, and being able to produce an access and audit trail quickly, makes both the breach-notification clock and a PDPC inquiry considerably less stressful to manage. It's one of the reasons NEOREKA ASIA hosts desknet's NEO and ChatLuck customer data in a data centre located in Malaysia, rather than routing it through infrastructure overseas.
This article is for general informational purposes and does not constitute legal advice. Organisations should consult a qualified legal advisor to assess their specific obligations under the PDPA.