Mechanism
Malaysia's original Personal Data Protection Act 2010 was widely considered outdated relative to modern data-governance standards. Act A1727 was passed by Parliament in August 2024, received Royal Assent on 9 October 2024, and was gazetted on 17 October 2024. The commencement order P.U.(B) 522/2024 (gazetted 24 December 2024) spread activation across three phases to allow businesses transition time:
| Phase | Date | Key provisions |
|---|
| 1 | 1 Jan 2025 | Electronic service of notices; saving provisions |
| 2 | 1 Apr 2025 | "Data controller" terminology; processor security obligations; biometric data as sensitive personal data; removal of transfer whitelist |
| 3 | 1 Jun 2025 | Mandatory DPO; breach notification; data portability |
Phase 3 obligations in detail
Mandatory DPO (Section 6 / new s.12A of the principal Act) A data controller must appoint a Malaysia-resident (or readily contactable) DPO if it:
- processes personal data of ≥ 20,000 data subjects, or
- processes sensitive personal data (incl. financial data) of ≥ 10,000 data subjects.
The DPO appointment must be notified to the Commissioner within 21 days.
Data Breach Notification (Section 9 / new s.35A) Covered data controllers must:
- notify the Commissioner within 72 hours if a breach causes significant harm or affects ≥ 1,000 individuals;
- notify affected individuals within 7 days of the initial Commissioner report where significant harm is likely.
Implementing detail is in PDP Circular 1/2025 (issued 25 February 2025, effective 1 June 2025).
Data Portability (Section 6 / new s.33A) Data subjects may request a machine-readable copy of their personal data for transfer to another controller. The PDP Commissioner will issue technical standards for portability format and timing separately.
Penalty ceiling raised Phase 2 (1 April 2025) already raised the maximum fine for personal data breaches from RM 500,000 to RM 1 million, with possible imprisonment for natural persons. Phase 3 activates the breach-notification duty that triggers these penalties.
Downstream implications
- Foreign digital-service providers: cross-border data controllers with Malaysian customers are in scope. Act A1727 removed the transfer-whitelist mechanism (Phase 2), so ongoing transfers must now rely on contractual safeguards or binding corporate rules — increasing compliance overhead for cloud SaaS, fintech, and e-commerce operators.
- Financial services and telcos: these sectors already hold sensitive personal and financial data for large customer bases; most will meet the DPO-threshold triggers immediately and face the 72-hour notification clock from 1 June.
- Regional alignment: alongside Vietnam's PDPL (filed 2024-11-30-vietnam-law-on-data-60-2024-qh15) and India's DPDP Rules (filed 2025-11-13-india-dpdp-rules), this filing completes a southeast/south-Asian data-protection convergence arc that mirrors GDPR enforcement architecture.
- NIMP 2030 coherence: the PDPA upgrade underpins Malaysia's ambition (NIMP 2030, filed 2023-09-01) to attract high-value digital investment — international cloud and AI vendors have cited regulatory clarity as a prerequisite.
Open questions
- Technical standards for data portability format have not been published; PDP Commissioner has not set a deadline.
- Enforcement of the DPO-notification obligation for foreign controllers without Malaysian establishment is untested.
- Whether PDP Circular 2/2025 thresholds (20k / 10k data-subject triggers) will be lowered in later amendments as usage of AI-driven personalisation scales.