Country:马来西亚 · Data Privacy
Malaysia · Data Privacy
Malaysia's Personal Data Protection Act (PDPA 2010), strengthened by the PDPA Amendment Act 2024 (in force), is the core law, applying domestically and extraterritorially. Processing needs a lawful basis (mainly consent), notice obligations, security measures and cross-border transfer safeguards. Regulator is JPDP. Cross-border transfer needs adequate protection or standard contractual clauses; financial data also under BNM rules.
Key points
- PDPA 2010 and 2024 amendment (strengthened consent, breach notice and penalties).
- Lawful basis mainly consent; data subjects have access, correction, deletion rights.
- Security measures required; breach must be notified to JPDP promptly (strengthened).
- Cross-border transfer: recipient must have adequate protection or sign standard clauses.
- Extraterritorial; finance (BNM), health etc. have special rules; max penalty RM1m or 2% of revenue.
- China data-export obligations (pkulaw-verified 2026-07): transfers to/back to China need one of security assessment (CAC Order 11), standard contract (Order 13) or certification (CAC-SAMR Order 20, 2025-10-14); 2024–2025 relaxed via Provisions on Promoting and Regulating Cross-Border Data Flows (Order 16) and Network Data Security Regulation (State Council Order 790), some scenarios exempt.
Procedure
- Personal-data inventory and mapping.
- Publish privacy notice and manage consent.
- DPIA for high-risk processing.
- Cross-border transfer SCC or adequacy assessment.
- Build breach-response and registration mechanism.
Hard requirements
- Lawful basis; notice obligation; security measures; cross-border safeguard; processing records.
Costs
Compliance-system build; DPO (by scale); periodic audit.⏱ ⏱ Timeline:2024 amendment in force; ongoing compliance.⚠ Common risks
- China not an adequacy country; cross-border needs SCC or clauses.
- Defective consent (pre-ticked invalid) penalised.
- Breach not notified → high fine.
- Extraterritorial: no Malaysia entity may still be subject.
Handbook
📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)
Applies to:Chinese enterprises processing Malaysian residents' personal data in Malaysia, or transferring it to China (governed by PDPA 2010 and the 2024 Amendment Act, regulated by JPDP, with extraterritorial reach).
Prerequisites
- Clear processing activities & lawful basis (mainly consent).
- Notice obligation fulfilled and processing records built.
- Reserve DPO & audit budget by business scale.
| Step | Action | Owner | Timeline | Cost | Official form / system | Notes & penalties |
|---|---|---|---|---|---|---|
| 1 | Personal-data inventory & mapping Map personal-data categories, purposes and recipients; build processing records. | Legal / IT | 2 weeks | Internal | Data inventory, processing records | Extraterritorial too Penalty:Up to RM1m fine or 2% of prior-year revenue |
| 2 | Publish privacy notice & manage consent Publish privacy notice, obtain valid consent (pre-ticked invalid), fulfil notice obligation. | Legal | 1–2 weeks | Internal | Privacy notice, consent records | 2024 amendment strengthened consent & notice Penalty:Same upper limit as step 1 |
| 3 | DPIA for high-risk processing Conduct Data Protection Impact Assessment for large-scale or sensitive processing. | Compliance / IT | 2–4 weeks | Internal | DPIA report | Per amendment Penalty:No assessment → fined |
| 4 | Cross-border SCC / adequacy Before transfer, confirm recipient has adequate protection or sign standard clauses; China not adequacy-listed → use SCC, link with PIPL export. | Legal | 3–6 weeks | Internal / legal | Adequacy assessment, SCC, PIPL export docs | Financial data also under BNM Penalty:Unguarded cross-border → fined |
| 5 | Breach-response & JPDP notification Build personal-data breach response; notify JPDP promptly per 2024 amendment. | DPO / IT | Ongoing | Internal | Breach plan, JPDP notice | Amendment strengthened notice Penalty:No notice → high fine |
| 6 | Data-subject rights response Build access, correction, deletion response (PDPA rights). | DPO / support | Ongoing | Internal | DSAR process | Must record Penalty:Refusal → fined |
| 7 | Ongoing compliance & audit Periodic audit, policy update, training; appoint DPO by scale. | Compliance | Annual | Internal | Annual audit, training | 2024 amendment in force Penalty:Continuous violations accumulate |
✅ Self-check list
⚠ Common pitfalls
Pre-ticked consent影响:Consent invalid & penalised规避:Opt-in actively
China not adequacy-listed yet no SCC transfer影响:Violation (stacks with PIPL)规避:Sign standard contractual clauses (SCC)
China transfer ignores PIPL export影响:Dual violation规避:Handle China-side mechanism in parallel
Breach not notified to JPDP影响:High fine规避:Set auto-trigger reporting
Assume no extraterritorial reach影响:Missed compliance规避:PDPA extraterritorial applies
Ignore financial etc. special rules影响:Sector penalty规避:Sync BNM etc. requirements
📅 Ongoing post-incorporation obligations
- Notify JPDP of breaches & cooperate.
- Continuously respond to DSAR.
- Periodic audit & policy update.
- China PIPL export mechanism remains effective.
- Staff training & DPO duties (if applicable).
🔗 Official portals
📎 Source:https://jpdp.gov.my ; https://www.cac.gov.cn
Want to turn this into an actionable compliance workflow?
CompliGo · Outbound Compliance Automation
You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.
CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.