Malaysia

Substantial

Personal Data Protection Act 2010 (PDPA)

Authority: Department of Personal Data Protection (JPDP) | Enforcement: Active | Enacted: November 2013

Overview

Malaysia's PDPA 2010 governs processing of personal data in commercial transactions. It does not apply to the public sector. The law has 7 data protection principles and provides for a Commissioner. Amendments being considered to modernise the framework.

14-Topic Coverage

Data Protection Authority

Fully Addressed

JPDP under the Ministry of Communications and Digital oversees compliance.

Data Subject Rights

Fully Addressed

Rights to access, correct, withdraw consent, and prevent processing for direct marketing.

Cross-Border Transfer

Partially Addressed

Currently restricted — transfers allowed only to Minister-approved countries. Whitelist pending.

Breach Notification

Not Addressed

No mandatory breach notification requirement in current PDPA. Amendment may address this.

DPO Requirements

Not Addressed

No formal DPO requirement in current PDPA.

Children's Data

Partially Addressed

General provisions apply. No specific age-based provisions.

Penalties & Enforcement

Fully Addressed

Fines up to MYR 500,000 and/or imprisonment up to 3 years.

Sector-Specific Rules

Fully Addressed

BNM financial data rules, MOH health data, MCMC telecom requirements.

AI & Automated Decisions

Not Addressed

No specific provisions on AI or automated decisions.

Data Localisation

Partially Addressed

Cross-border transfer restrictions act as de facto localisation for some data.

Significant Data Fiduciary

Not Addressed

No equivalent concept.

Government Data

Not Addressed

PDPA does not apply to federal and state governments.