Malaysia
SubstantialPersonal Data Protection Act 2010 (PDPA)
Authority: Department of Personal Data Protection (JPDP) | Enforcement: Active | Enacted: November 2013
Overview
Malaysia's PDPA 2010 governs processing of personal data in commercial transactions. It does not apply to the public sector. The law has 7 data protection principles and provides for a Commissioner. Amendments being considered to modernise the framework.
14-Topic Coverage
Data Protection Authority
Fully AddressedJPDP under the Ministry of Communications and Digital oversees compliance.
Consent Requirements
Fully AddressedConsent required for processing. Must be informed and given by a clear affirmative action.
Data Subject Rights
Fully AddressedRights to access, correct, withdraw consent, and prevent processing for direct marketing.
Cross-Border Transfer
Partially AddressedCurrently restricted — transfers allowed only to Minister-approved countries. Whitelist pending.
Breach Notification
Not AddressedNo mandatory breach notification requirement in current PDPA. Amendment may address this.
DPO Requirements
Not AddressedNo formal DPO requirement in current PDPA.
Children's Data
Partially AddressedGeneral provisions apply. No specific age-based provisions.
Penalties & Enforcement
Fully AddressedFines up to MYR 500,000 and/or imprisonment up to 3 years.
Sector-Specific Rules
Fully AddressedBNM financial data rules, MOH health data, MCMC telecom requirements.
Cookie/Tracking
Not AddressedNo specific cookie regulation.
AI & Automated Decisions
Not AddressedNo specific provisions on AI or automated decisions.
Data Localisation
Partially AddressedCross-border transfer restrictions act as de facto localisation for some data.
Significant Data Fiduciary
Not AddressedNo equivalent concept.
Government Data
Not AddressedPDPA does not apply to federal and state governments.
Coverage Summary
Quick Navigation
Need Compliance Help?
Our data privacy team can help you navigate Malaysia's regulations.
Book a Consultation