🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
MY v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 1 failing12 sources retrieved model claude-sonnet-5 · 2026-08-05

Based mainly on secondary sources. Only 2 of the sources retrieved for this jurisdiction are official or direct reporting of official material (tier 1 or 2), against the 3 we look for. No finding on this page is shown with confidence above “Uncertain” until stronger sources are retrieved.

Malaysia

MY schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 64 claims · 25 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
64Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Malaysia's Personal Data Protection (Amendment) Act 2024 (Act A1727) is delivering the most substantial modernisation of the jurisdiction's data-protection regime since the original 2010 Act, with staged commencement dates set by Ministerial Gazette notification. The amendments introduce Malaysia's first mandatory data-breach-notification requirement and its first mandatory Data Protection Officer appointment duty for larger data handlers, implemented respectively through Commissioner's Circular No. 1/2025 and Commissioner's Circular No. 2/2025. Alongside these new obligations, the maximum fine for breach of any single data-protection principle has been raised to RM1,000,000, more than tripling the prior RM300,000 cap.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive statute in force with a fully commenced modernising amendment; core institutional architecture (Commissioner + PDP) is stable and actively issuing implementing guidance.

Primary frameworkPersonal Data Protection Act 2010 (Act 709), as amended by the Personal Data Protection (Amendment) Act 2024
Traffic-light rationale — GreenComprehensive statute in force with a fully commenced modernising amendment; core institutional architecture (Commissioner + PDP) is stable and actively issuing implementing guidance.

Sub-modules (5)

Regulator And AuthorityGreen

The Commissioner, assisted by PDP, administers and enforces the PDPA.

Claims (1):

  • The PDPA confers powers to the Personal Data Protection Commissioner, who is assisted by the Department of Personal Data Protection (PDP) to administer and enforce the provisions of the PDPA.

Act And InstrumentsGreen

PDPA 2010 in force since 15 November 2013; Amendment Act 2024 gazetted 17 October 2024 with staged commencement through 1 June 2025.

Claims (2):

  • The Personal Data Protection (Amendment) Act 2024 was published in the Gazette on 17 October 2024 after receiving Royal Assent on 9 October 2024, following passage by the Senate (31 July 2024) and House of Representatives (16 July 2024).
  • The Amendment Act's provisions were implemented in stages, with sections coming into effect on 1 January, 1 April, and 1 June 2025, covering biometric data, controller/processor terminology, cross-border transfer rules, DPO appointment, breach notification and portability respectively.

Material ScopeGreen

PDPA covers processing of personal data in commercial transactions by an establishment in Malaysia or using equipment in Malaysia.

Claims (1):

  • The PDPA regulates the processing of personal data in commercial transactions either by an establishment in Malaysia or with equipment in Malaysia, unless the personal data only transits through Malaysia.

Territorial ScopeAmber

Extraterritorial reach is anchored to use of equipment in Malaysia rather than a pure establishment test; transit-only data is excluded.

Claims (1):

  • Extraterritorial application of the PDPA turns on use of equipment located in Malaysia (an equipment-based test), rather than a GDPR-style establishment/targeting test; data merely transiting Malaysia is expressly excluded.

Regulator Registration And FilingGreen

PDP mandates registration of 13 designated classes of data controllers/users, and separately requires DPO-appointment notification within 21 days via a dedicated registration manual.

Claims (2):

  • PDP mandates registration for 13 designated classes/groups of data controllers under the PDPA, with penalties for non-compliance with the registration requirement.
  • Controllers and processors must notify the Commissioner of DPO appointments; PDP's DPO registration manual requires such notification within 21 days of appointment.
Category narrative94 words

Malaysia's data-protection regime is anchored in the Personal Data Protection Act 2010 (Act 709, 'PDPA'), administered by the Personal Data Protection Commissioner supported by the Department of Personal Data Protection (Jabatan Perlindungan Data Peribadi, 'PDP'). The regime was materially modernised by the Personal Data Protection (Amendment) Act 2024, gazetted 17 October 2024 following Royal Assent, and commenced in three stages across 1 January, 1 April and 1 June 2025, bringing DPO appointment, mandatory breach notification, portability, processor accountability and revised cross-border rules into force. As of this run all staged provisions are in force.

Periodic update · new data 2026-09-28

Regulator & Framework

Malaysia's Department of Personal Data Protection (JPDP) is the jurisdiction's primary data-protection regulator, distinct from the Securities Commission's role in the crypto and digital-asset-exchange space. The foundational statute, the Personal Data Protection Act 2010, has been substantially amended by the Personal Data Protection (Amendment) Act 2024 (Act A1727), which represents the most significant legislative modernisation of Malaysia's data-protection regime since the original Act's passage. Commencement of the amendment's various provisions is being staged through Ministerial Gazette notification, meaning different substantive changes have taken effect, or will take effect, on different dates rather than through a single commencement.

The exact phased commencement schedule by individual provision was not fully retrieved this cycle, and the primary source confirms only that different provisions commence via separate Gazette notifications rather than laying out the complete provision-by-provision timetable. What is confirmed is that key substantive changes, including the breach-notification and DPO requirements discussed under Controller/Processor Duties, are already in force.

Outlook

As further Ministerial Gazette notifications bring additional Amendment Act provisions into force, the phased-commencement picture should become progressively clearer. Tracking each notification as it is published will be necessary to establish a complete effective-date map for the full amendment package.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (7)
  1. UncertainDataGuidance — The PDPA confers powers to the Personal Data Protection Commissioner, who is assisted by the Department of Personal Data Protection (PDP) to administer and enforce the provisions of the PDPA.observed
  2. UncertainDataGuidance — The Personal Data Protection (Amendment) Act 2024 was published in the Gazette on 17 October 2024 after receiving Royal Assent on 9 October 2024, following passage by the Senate (31 July 2024) and House of Representatives (16 July 2024).observed
  3. UncertainDataGuidance — The Amendment Act's provisions were implemented in stages, with sections coming into effect on 1 January, 1 April, and 1 June 2025, covering biometric data, controller/processor terminology, cross-border transfer rules, DPO appointment, breach notification and portability respectively.observed
  4. UncertainDataGuidance — The PDPA regulates the processing of personal data in commercial transactions either by an establishment in Malaysia or with equipment in Malaysia, unless the personal data only transits through Malaysia.observed
  5. UncertainDataGuidance — Extraterritorial application of the PDPA turns on use of equipment located in Malaysia (an equipment-based test), rather than a GDPR-style establishment/targeting test; data merely transiting Malaysia is expressly excluded.observed
  6. UncertainDataGuidance — PDP mandates registration for 13 designated classes/groups of data controllers under the PDPA, with penalties for non-compliance with the registration requirement.observed
  7. UncertainDataGuidance — Controllers and processors must notify the Commissioner of DPO appointments; PDP's DPO registration manual requires such notification within 21 days of appointment.observed

#

Core consent/sensitive-data architecture is well evidenced and in force, but consent-threshold specifics (freely-given/withdrawal standard) and pseudonymisation/anonymisation treatment were not confirmed via primary-source retrieval in this run.

Primary frameworkPersonal Data Protection Act 2010, ss.6 and 40, as amended by the Personal Data Protection (Amendment) Act 2024
Traffic-light rationale — AmberCore consent/sensitive-data architecture is well evidenced and in force, but consent-threshold specifics (freely-given/withdrawal standard) and pseudonymisation/anonymisation treatment were not confirmed via primary-source retrieval in this run.

Sub-modules (4)

Lawful BasesAmber

Consent is the primary lawful basis; limited statutory exceptions exist for contract performance/formation and legal-obligation compliance. Malaysia lacks a standalone legitimate-interest basis.

Claims (3):

  • Under section 6(1) of the PDPA, a data user must not process personal data unless the data subject has given consent, or, for sensitive personal data, unless processing accords with section 40.
  • Notwithstanding the general consent requirement, section 6(2) permits processing necessary for performance of, or steps toward, a contract with the data subject, or for compliance with a legal obligation.
  • Malaysia is identified, alongside China, India and Vietnam, as one of the reviewed Asia-Pacific jurisdictions that presently lacks a distinct legitimate-interest lawful basis for processing personal data.

Special CategoriesGreen

Biometric data is newly classified as sensitive personal data under the Amendment Act; deceased-persons' data is expressly placed outside the Act's scope.

Claims (2):

  • The Amendment Act recognises biometric data as sensitive personal data, defined as personal data resulting from technical processing relating to the physical, physiological or behavioural characteristics of a person.
  • Data of deceased persons is excluded from the Amendment Act and placed expressly outside the PDPA's application.

Pseudonymisation And AnonymisationRed

No PDPA provision defining pseudonymisation or an anonymisation safe-harbour was located in the reviewed primary text or amendment commentary.

Claims (1):

  • No express PDPA provision defining pseudonymisation or providing an anonymisation safe-harbour was identified in the reviewed Act text or Amendment Act commentary.
Category narrative83 words

The PDPA operates on a consent-centric lawfulness model rather than a GDPR-style multi-basis Article 6 structure: general personal data requires data-subject consent (with limited contract/legal-obligation exceptions), and sensitive personal data requires compliance with the dedicated section 40 regime. Malaysia is noted among APAC jurisdictions as presently lacking a stand-alone 'legitimate interest' basis. The 2024 Amendment Act's headline change to this module is the addition of biometric data as a new sensitive-personal-data category, alongside express exclusion of deceased persons' data from the Act's application.

Periodic update · new data 2026-09-28

Lawful Processing & Special Data

Malaysia's category of sensitive personal data has been expanded by the Personal Data Protection (Amendment) Act 2024 to include biometric data, specifically fingerprints, facial recognition data, voice data and retinal scans, effective 1 April 2025. This addition subjects biometric data to the same heightened processing threshold already applicable to other sensitive-personal-data categories under the PDPA, meaning controllers processing biometric data for identity verification, authentication or similar purposes must now satisfy the corresponding stricter lawful-basis requirements applicable to sensitive categories rather than the general lawful-processing threshold.

This reclassification is particularly relevant given the growing use of biometric authentication in Malaysian consumer-facing financial and digital services. Controllers that had previously processed biometric identifiers under the general lawful-processing threshold, prior to 1 April 2025, would need to have transitioned their lawful-basis analysis to satisfy the sensitive-category requirements from that effective date forward.

Outlook

Watch for JPDP guidance clarifying the practical lawful-basis expectations for biometric processing specifically, given that this is a newly-created sensitive category rather than one with an established body of Malaysian regulatory interpretation. Sectors making heavy use of biometric authentication, including financial services, should be an early focus for any JPDP compliance-monitoring activity.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (7)
  1. UncertainDataGuidance (hosted copy of official Act text) — Under section 6(1) of the PDPA, a data user must not process personal data unless the data subject has given consent, or, for sensitive personal data, unless processing accords with section 40.observed
  2. UncertainDataGuidance (hosted copy of official Act text) — Notwithstanding the general consent requirement, section 6(2) permits processing necessary for performance of, or steps toward, a contract with the data subject, or for compliance with a legal obligation.observed
  3. UncertainPDPC Singapore — Malaysia is identified, alongside China, India and Vietnam, as one of the reviewed Asia-Pacific jurisdictions that presently lacks a distinct legitimate-interest lawful basis for processing personal data.observed
  4. UncertainIAPP — The Amendment Act recognises biometric data as sensitive personal data, defined as personal data resulting from technical processing relating to the physical, physiological or behavioural characteristics of a person.observed
  5. UncertainIAPP — Data of deceased persons is excluded from the Amendment Act and placed expressly outside the PDPA's application.observed
  6. UncertainDataGuidance (hosted copy of official Act text) — No confirmed primary-source detail was retrieved in this research pass specifying the PDPA's precise consent-validity thresholds (e.g., freely-given, specific, withdrawal mechanics) as amended.observed
  7. UncertainDataGuidance (hosted copy of official Act text) — No express PDPA provision defining pseudonymisation or providing an anonymisation safe-harbour was identified in the reviewed Act text or Amendment Act commentary.observed

#

Access, correction and (newly) portability rights are well evidenced and in force; restriction/objection rights and precise response deadlines remain unconfirmed gaps.

Primary frameworkPersonal Data Protection Act 2010, Division 4 (ss.30-37), as amended by the Personal Data Protection (Amendment) Act 2024
Traffic-light rationale — AmberAccess, correction and (newly) portability rights are well evidenced and in force; restriction/objection rights and precise response deadlines remain unconfirmed gaps.

Sub-modules (5)

Access RightGreen

Access Principle (s.12) and Division 4 right of access to personal data are confirmed in force.

Claims (1):

  • Under the Access Principle (section 12) and Division 4 of the PDPA, a data subject shall be given access to his personal data held by a data user, except where compliance with the access request is refused under the Act.

Rectification And ErasureAmber

A right to correct personal data exists (ss.34-37); no GDPR-style general 'right to erasure' beyond the controller's retention-destruction duty was confirmed.

Claims (1):

  • The PDPA provides a statutory right to correct personal data (sections 34-37), including circumstances in which a data user may refuse a correction request and must notify the data subject of such refusal.

Restriction And ObjectionRed

No explicit restriction-of-processing or objection/profiling opt-out right was confirmed via retrieved Malaysia-specific sources in this run.

Claims (1):

  • No explicit standalone right to restrict processing or to object to processing/profiling (analogous to GDPR Arts 18/21) was identified in the reviewed PDPA text or Amendment Act commentary.

Data PortabilityGreen

The Amendment Act introduces a portability right, qualified by technical feasibility and format compatibility, effective from the final commencement stage.

Claims (1):

  • The Amendment Act grants data subjects a right to data portability, allowing transfer of their data between controllers, subject to the technical feasibility and compatibility of the data format.

Deadlines And Response WindowsRed

No confirmed Malaysia-specific statutory day-count for responding to access/correction requests was retrieved in this run.

Claims (1):

  • No confirmed Malaysia-specific statutory response-window (day count) for access or correction requests under PDPA sections 31/35 was retrieved in this research pass.
Category narrative80 words

The PDPA's Division 4 (ss.30-37) establishes a right of access and a right to correct personal data, underpinned by the Access Principle (s.12). The 2024 Amendment Act adds a new right to data portability, subject to technical feasibility and format compatibility. However, unlike the GDPR, no explicit standalone right to restriction of processing or to object (including profiling opt-out) was confirmed, and the specific statutory response-window (day count) for access/correction requests was not confirmed via primary-source retrieval in this run.

Periodic update · new data 2026-09-28

Data Subject Rights

The Personal Data Protection (Amendment) Act 2024 introduces a new right of data portability for Malaysian data subjects, understood to be a significant addition to the rights available under the original 2010 Act, which did not include a portability right in its original form. This brings Malaysia's data-subject-rights framework closer to the fuller suite of rights found in more recently-modernised data-protection regimes internationally.

The precise operational scope and mechanics of the new portability right, including which categories of data it applies to and what format requirements apply to a portability request, were not independently confirmed with primary-source detail this cycle. The confidence on this development is accordingly qualified rather than fully confirmed, reflecting reliance on secondary characterisation of the Amendment Act's rights provisions rather than a directly parsed primary text describing the portability mechanism in full.

Outlook

Further JPDP guidance or a Ministerial Gazette notification specifying the operational mechanics of the data-portability right would materially increase confidence in this development. Controllers should treat the right as introduced in principle by the 2024 Amendment Act, pending clearer operational guidance on request-handling mechanics.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. UncertainDataGuidance (hosted copy of official Act text) — Under the Access Principle (section 12) and Division 4 of the PDPA, a data subject shall be given access to his personal data held by a data user, except where compliance with the access request is refused under the Act.observed
  2. UncertainDataGuidance (hosted copy of official Act text) — The PDPA provides a statutory right to correct personal data (sections 34-37), including circumstances in which a data user may refuse a correction request and must notify the data subject of such refusal.observed
  3. UncertainIAPP — The Amendment Act grants data subjects a right to data portability, allowing transfer of their data between controllers, subject to the technical feasibility and compatibility of the data format.observed
  4. UncertainDataGuidance (hosted copy of official Act text) — No explicit standalone right to restrict processing or to object to processing/profiling (analogous to GDPR Arts 18/21) was identified in the reviewed PDPA text or Amendment Act commentary.observed
  5. UncertainDataGuidance — No confirmed Malaysia-specific statutory response-window (day count) for access or correction requests under PDPA sections 31/35 was retrieved in this research pass.observed

#

DPO, breach-notification, security and retention duties are strongly evidenced and in force; DPIA/ROPA/joint-controller equivalents remain unconfirmed gaps versus the GDPR baseline.

Primary frameworkPersonal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024
Traffic-light rationale — AmberDPO, breach-notification, security and retention duties are strongly evidenced and in force; DPIA/ROPA/joint-controller equivalents remain unconfirmed gaps versus the GDPR baseline.

Sub-modules (7)

Accountability And DpiaRed

A general accountability principle underlies the PDPA; no DPIA-specific obligation was confirmed for Malaysia in this run.

Claims (1):

  • No PDPA/Amendment-Act provision imposing a formal Data Protection Impact Assessment obligation (analogous to GDPR Art 35) was confirmed in the reviewed Malaysia-specific materials.

Dpo RequirementsGreen

Mandatory DPO appointment for qualifying controllers/processors, with notification to the Commissioner within 21 days, effective from the final 2025 commencement stage.

Claims (2):

  • The Amendment Act introduces a mandatory Data Protection Officer appointment obligation for qualifying data controllers and processors.
  • Controllers and processors must notify the Data Protection Commissioner of DPO appointments, via a registration manual requiring notification within 21 days of appointment.

Ropa RequirementsRed

No Article-30-style records-of-processing obligation was confirmed for Malaysia in the reviewed materials.

Claims (1):

  • No PDPA/Amendment-Act obligation to maintain formal records of processing activities (analogous to GDPR Art 30) was confirmed in the reviewed Malaysia-specific materials.

Joint Controller ArrangementsRed

No explicit joint-controller regime analogous to GDPR Art 26 was confirmed for Malaysia.

Claims (1):

  • No PDPA provision establishing a joint-controller regime analogous to GDPR Art 26 was identified in the reviewed Act text or Amendment Act commentary.

Security MeasuresGreen

The Amendment Act extends the security principle to data processors directly, not solely controllers.

Claims (1):

  • The amended PDPA enhances data subjects' rights to data portability and requires data processors, not just controllers, to adhere to the security principle.

Breach NotificationGreen

Mandatory notification of the Commissioner within 72 hours of becoming aware of a breach, with sanctions for non-compliance.

Claims (2):

  • Data controllers must notify the Commissioner of a data breach within 72 hours after becoming aware of the breach, and must also notify affected data subjects within specified time frames.
  • Enhanced enforcement powers under the Amendment Act increase fines for PDPA violations to up to MYR1 million, extend the maximum imprisonment term to three years, and empower the Commissioner to conduct proactive compliance audits.

Retention And DisposalGreen

Data users must take reasonable steps to destroy or permanently delete personal data no longer required for its processing purpose.

Claims (1):

  • It is the duty of a data user to take all reasonable steps to ensure that all personal data is destroyed or permanently deleted if it is no longer required for the purpose for which it was processed.
Category narrative59 words

The Amendment Act materially expands controller/processor duties: mandatory DPO appointment, mandatory 72-hour breach notification to the Commissioner, and extension of the security principle directly to data processors (not just controllers). A pre-existing retention/disposal duty requires destruction of data no longer needed. However, GDPR-equivalent DPIA, ROPA (Article 30 records) and joint-controller-arrangement provisions were not confirmed in the reviewed Malaysia-specific materials.

Periodic update · new data 2026-09-28

Controller/Processor Duties

Malaysia's controller-duties landscape changed substantially through the Personal Data Protection (Amendment) Act 2024. Two new duties stand out as first-ever requirements for Malaysian data controllers: a mandatory Data Protection Officer appointment requirement for larger data handlers, implemented via Commissioner's Circular No. 2/2025, and Malaysia's first mandatory data-breach-notification requirement, implemented via Commissioner's Circular No. 1/2025. Both requirements accompany a raised maximum fine, now RM1,000,000 for breach of any single data-protection principle, more than tripling the prior RM300,000 ceiling.

Separately, Section 129 of the PDPA was amended to replace the terminology Data User with Data Controller, effective 1 April 2025, aligning Malaysian terminology more closely with international data-protection vocabulary and, more substantively, clarifying the accountability relationship the amended Act establishes. The Department of Personal Data Protection is understood to have issued three additional implementing guidelines on 8 May 2026, covering Data Protection Impact Assessments, Data Protection by Design, and Automated Decision-Making and Profiling. These guidelines' binding status and precise effective dates were not independently confirmed this cycle, so they are presented at qualified confidence pending fuller primary-source review.

Outlook

Confirmation of the binding status of the three 8 May 2026 guidelines, particularly the Automated Decision-Making and Profiling guideline, is the key open item for this module. Controllers should treat the DPO and breach-notification requirements as firmly in force, since these trace to confirmed primary and near-primary sourcing, while treating the three newer guidelines as provisional pending that confirmation.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (9)
  1. UncertainDataGuidance — The Amendment Act introduces a mandatory Data Protection Officer appointment obligation for qualifying data controllers and processors.observed
  2. UncertainDataGuidance — Controllers and processors must notify the Data Protection Commissioner of DPO appointments, via a registration manual requiring notification within 21 days of appointment.observed
  3. UncertainDataGuidance — Data controllers must notify the Commissioner of a data breach within 72 hours after becoming aware of the breach, and must also notify affected data subjects within specified time frames.observed
  4. UncertainIAPP — Enhanced enforcement powers under the Amendment Act increase fines for PDPA violations to up to MYR1 million, extend the maximum imprisonment term to three years, and empower the Commissioner to conduct proactive compliance audits.observed
  5. UncertainDataGuidance — The amended PDPA enhances data subjects' rights to data portability and requires data processors, not just controllers, to adhere to the security principle.observed
  6. UncertainDataGuidance (hosted copy of official Act text) — It is the duty of a data user to take all reasonable steps to ensure that all personal data is destroyed or permanently deleted if it is no longer required for the purpose for which it was processed.observed
  7. UncertainDataGuidance — No PDPA/Amendment-Act provision imposing a formal Data Protection Impact Assessment obligation (analogous to GDPR Art 35) was confirmed in the reviewed Malaysia-specific materials.observed
  8. UncertainDataGuidance — No PDPA/Amendment-Act obligation to maintain formal records of processing activities (analogous to GDPR Art 30) was confirmed in the reviewed Malaysia-specific materials.observed
  9. UncertainDataGuidance (hosted copy of official Act text) — No PDPA provision establishing a joint-controller regime analogous to GDPR Art 26 was identified in the reviewed Act text or Amendment Act commentary.observed

#

Transfer mechanism and TIA obligation are well evidenced and in force; the specific whitelist, adequacy-received status, and SCC/BCR/localisation architecture remain unconfirmed.

Primary frameworkPersonal Data Protection Act 2010, Part V, as amended by the Personal Data Protection (Amendment) Act 2024
Traffic-light rationale — AmberTransfer mechanism and TIA obligation are well evidenced and in force; the specific whitelist, adequacy-received status, and SCC/BCR/localisation architecture remain unconfirmed.

Sub-modules (6)

Transfer MechanismsGreen

Transfers permitted to adequate/whitelisted countries, under public-interest circumstances, or with data-subject consent.

Claims (1):

  • The PDPA permits international transfers of personal data where the receiving country has adequate data protection laws (a 'whitelisted' jurisdiction) or under circumstances of public interest; consent-based transfer remains an available mechanism.

Adequacy ReceivedRed

No evidence located of Malaysia having received a formal adequacy determination from another regime (e.g., EU/UK).

Claims (1):

  • No evidence was located in this research pass that Malaysia has received a formal adequacy determination from the EU, UK or another comprehensive-regime regulator.

Adequacy GrantedAmber

No published list of countries Malaysia has designated as having 'adequate' protection was retrieved in this run, though PDP issued cross-border transfer guidelines in April 2025.

Claims (1):

  • PDP published cross-border data transfer guidelines in April 2025 implementing the amended transfer regime, though the specific countries treated as having 'adequate' protection were not enumerated in the retrieved sources.

Sccs And BcrsAmber

Malaysia's transfer regime relies on a whitelist-plus-consent model rather than an EU-style SCC/BCR mechanism.

Claims (1):

  • Malaysia's cross-border transfer regime is structured around whitelisted-country adequacy and consent-based mechanisms rather than a distinct SCC or BCR instrument comparable to the EU model.

Transfer Impact AssessmentGreen

The Amendment Act introduces a Transfer Impact Assessment requirement for cross-border transfers.

Claims (1):

  • The Amendment Act revises cross-border transfer mechanisms to require Transfer Impact Assessments (TIAs) by data controllers, including a more rigorous assessment of the receiving country's data protection framework.

Data LocalisationRed

No general data-localisation mandate was confirmed for commercial personal data in the reviewed sources.

Claims (1):

  • No general data-localisation mandate applicable to commercial personal data was identified in the reviewed PDPA/Amendment Act materials.
Category narrative76 words

The PDPA permits cross-border transfers to jurisdictions with adequate data protection laws ('whitelisted' countries), under circumstances of public interest, or with data-subject consent. The 2024 Amendment Act tightens this regime by requiring data controllers to undertake Transfer Impact Assessments and a more rigorous assessment of the receiving country's protections, while leaving existing mechanisms such as consent-based transfers unchanged. No formal SCC or BCR instrument, published adequacy whitelist, or data-localisation mandate was confirmed in the reviewed sources.

Periodic update · new data 2026-09-28

Cross-Border & Adequacy

Malaysia has officially launched its Guidelines for Cross-Border Personal Data Transfer (CBPDT Guidelines) as part of the phased implementation of the 2024 PDPA Amendment package. This is reported to move Malaysia's cross-border transfer approach beyond the original mechanism under the 2010 Act, which prohibited transfer of personal data outside Malaysia unless the destination country appeared on a government-approved whitelist, a narrow and administratively rigid approach compared to guideline-based mechanisms found in more recently modernised regimes.

The primary text of the CBPDT Guidelines was not directly retrieved this cycle, so the precise mechanics of the new approach, including whether it introduces standard-contractual-clause-style mechanisms, binding corporate rules, or another transfer basis alongside or instead of the whitelist, remain unconfirmed at primary-source level. This development is accordingly reported at qualified rather than fully assertive confidence.

Outlook

Retrieval and review of the CBPDT Guidelines' full primary text is the clear next step for this module. Until that review is completed, controllers relying on the new guidelines for cross-border transfers should treat the guidance as officially launched but not yet fully characterised in this brief's evidence base.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (6)
  1. UncertainIAPP — The PDPA permits international transfers of personal data where the receiving country has adequate data protection laws (a 'whitelisted' jurisdiction) or under circumstances of public interest; consent-based transfer remains an available mechanism.observed
  2. UncertainDataGuidance — The Amendment Act revises cross-border transfer mechanisms to require Transfer Impact Assessments (TIAs) by data controllers, including a more rigorous assessment of the receiving country's data protection framework.observed
  3. UncertainDataGuidance — PDP published cross-border data transfer guidelines in April 2025 implementing the amended transfer regime, though the specific countries treated as having 'adequate' protection were not enumerated in the retrieved sources.observed
  4. UncertainDataGuidance — No evidence was located in this research pass that Malaysia has received a formal adequacy determination from the EU, UK or another comprehensive-regime regulator.observed
  5. UncertainIAPP — Malaysia's cross-border transfer regime is structured around whitelisted-country adequacy and consent-based mechanisms rather than a distinct SCC or BCR instrument comparable to the EU model.observed
  6. UncertainDataGuidance — No general data-localisation mandate applicable to commercial personal data was identified in the reviewed PDPA/Amendment Act materials.observed

#

Financial-sector overlay mechanism is evidenced; other sectoral overlays are unconfirmed gaps in this research pass.

Primary frameworkPersonal Data Protection Act 2010, ss.23-29 (Codes of Practice)
Traffic-light rationale — AmberFinancial-sector overlay mechanism is evidenced; other sectoral overlays are unconfirmed gaps in this research pass.

Sub-modules (7)

Financial Sector OverlayAmber

PDP designates industry classes required to register and approves/registers sector Codes of Practice, including for financial-sector data users.

Claims (1):

  • PDP can designate the industry classes and business entities required to register, and approve and register Personal Data Protection Codes of Practice for various industry sectors, including the financial sector.

Health Sector OverlayRed

No Malaysia-specific health-sector data-protection overlay was confirmed in this run.

Claims (1):

  • No confirmed Malaysia-specific health-sector data-protection overlay statute or Code of Practice was located in this research pass.

Telecoms And EprivacyRed

No Malaysia-specific telecoms/ePrivacy overlay was confirmed in this run.

Claims (1):

  • No confirmed Malaysia-specific telecoms/ePrivacy overlay statute was located in this research pass.

Employment DataRed

No Malaysia-specific employment-data overlay was confirmed in this run.

Claims (1):

  • No confirmed Malaysia-specific employment-data overlay was located in this research pass.

Credit And ScoringRed

No Malaysia-specific credit-scoring overlay was confirmed in this run.

Claims (1):

  • No confirmed Malaysia-specific credit-scoring overlay was located in this research pass.

EducationRed

No Malaysia-specific education-sector overlay was confirmed in this run.

Claims (1):

  • No confirmed Malaysia-specific education-sector overlay was located in this research pass.

InsuranceRed

No Malaysia-specific insurance-sector overlay was confirmed in this run.

Claims (1):

  • No confirmed Malaysia-specific insurance-sector overlay was located in this research pass.
Category narrative51 words

The PDPA is the general commercial-transactions statute, and PDP is empowered to designate industry classes for registration and to approve sector-specific Codes of Practice (including for the financial sector). Beyond the financial-sector overlay, no health-, telecoms-, employment-, credit-scoring-, education- or insurance-specific overlay statute was confirmed via Malaysia-specific retrieval in this run.

Sources and claims (7)
  1. UncertainDataGuidance — PDP can designate the industry classes and business entities required to register, and approve and register Personal Data Protection Codes of Practice for various industry sectors, including the financial sector.observed
  2. UncertainDataGuidance — No confirmed Malaysia-specific health-sector data-protection overlay statute or Code of Practice was located in this research pass.observed
  3. UncertainDataGuidance — No confirmed Malaysia-specific telecoms/ePrivacy overlay statute was located in this research pass.observed
  4. UncertainDataGuidance — No confirmed Malaysia-specific employment-data overlay was located in this research pass.observed
  5. UncertainDataGuidance — No confirmed Malaysia-specific credit-scoring overlay was located in this research pass.observed
  6. UncertainDataGuidance — No confirmed Malaysia-specific education-sector overlay was located in this research pass.observed
  7. UncertainDataGuidance — No confirmed Malaysia-specific insurance-sector overlay was located in this research pass.observed

#

No comprehensive adtech/commercial-privacy regime was confirmed for Malaysia in this research session; this is treated as an explicit evidentiary gap rather than a substantive finding of 'no regulation'.

Traffic-light rationale — RedNo comprehensive adtech/commercial-privacy regime was confirmed for Malaysia in this research session; this is treated as an explicit evidentiary gap rather than a substantive finding of 'no regulation'.

Sub-modules (6)

Cookies And TrackersRed

No Malaysia-specific cookie/tracker consent rule confirmed.

Claims (1):

  • No Malaysia-specific cookie/tracker consent regime was identified in the sources reviewed in this research pass.

Dark PatternsRed

No Malaysia-specific dark-pattern prohibition confirmed.

Claims (1):

  • No Malaysia-specific dark-pattern prohibition was identified in the sources reviewed in this research pass.

Opt Out SignalsRed

No Malaysia-specific recognition of Global Privacy Control/DAA-style opt-out signals confirmed.

Claims (1):

  • No Malaysia-specific recognition of technical opt-out signals (e.g., Global Privacy Control, DAA) was identified in the sources reviewed in this research pass.

Clean Rooms And DcrRed

No Malaysia-specific clean-room/data-collaboration-room rule confirmed.

Claims (1):

  • No Malaysia-specific clean-room or data-collaboration-room rule was identified in the sources reviewed in this research pass.

Cross Context AdvertisingRed

No Malaysia-specific cross-context-advertising ('sale'/'share') rule confirmed.

Claims (1):

  • No Malaysia-specific cross-context-advertising rule analogous to CPRA 'sale'/'share' concepts was identified in the sources reviewed in this research pass.

Direct MarketingRed

A search for a PDPA direct-marketing/Do-Not-Call provision returned Singapore PDPA results (section 43/DNC Provisions), which were deliberately excluded as out-of-scope for the MY JID; no Malaysia-specific direct-marketing suppression regime was confirmed.

Claims (1):

  • A targeted search for a Malaysian PDPA direct-marketing/consent-suppression provision (analogous to a 'section 43' Do-Not-Call regime) returned only Singapore PDPA materials; no Malaysia-specific direct-marketing suppression mechanism was confirmed in this research pass.
Category narrative50 words

No Malaysia-specific cookie/tracker consent regime, dark-pattern prohibition, opt-out-signal (GPC/DAA) recognition, clean-room rule, cross-context-advertising rule, or direct-marketing/Do-Not-Call regime was confirmed in this research pass. A targeted search for a PDPA direct-marketing provision returned only Singapore PDPA 'Do Not Call' materials, underscoring a JID-disambiguation risk that was deliberately avoided rather than mis-attributed.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (6)
  1. UncertainDataGuidance — No Malaysia-specific cookie/tracker consent regime was identified in the sources reviewed in this research pass.observed
  2. UncertainDataGuidance — No Malaysia-specific dark-pattern prohibition was identified in the sources reviewed in this research pass.observed
  3. UncertainDataGuidance — No Malaysia-specific recognition of technical opt-out signals (e.g., Global Privacy Control, DAA) was identified in the sources reviewed in this research pass.observed
  4. UncertainDataGuidance — No Malaysia-specific clean-room or data-collaboration-room rule was identified in the sources reviewed in this research pass.observed
  5. UncertainDataGuidance — No Malaysia-specific cross-context-advertising rule analogous to CPRA 'sale'/'share' concepts was identified in the sources reviewed in this research pass.observed
  6. UncertainDataGuidance (hosted copy of official Act text) — A targeted search for a Malaysian PDPA direct-marketing/consent-suppression provision (analogous to a 'section 43' Do-Not-Call regime) returned only Singapore PDPA materials; no Malaysia-specific direct-marketing suppression mechanism was confirmed in this research pass.observed

#

Biometric-data governance is confirmed and in force; all other sub-modules in this space remain unconfirmed gaps.

Primary frameworkPersonal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024 (biometric data provisions)
Traffic-light rationale — AmberBiometric-data governance is confirmed and in force; all other sub-modules in this space remain unconfirmed gaps.

Sub-modules (6)

Profiling RestrictionsRed

No profiling-restriction provision analogous to GDPR Art 22 confirmed.

Claims (1):

  • No PDPA/Amendment-Act provision restricting automated profiling analogous to GDPR Article 22 was identified in the reviewed materials.

Automated Decision Making TransparencyRed

No ADM-transparency/explanation right confirmed.

Claims (1):

  • No PDPA/Amendment-Act automated-decision-making transparency or explanation right was identified in the reviewed materials.

Ai Risk AssessmentsRed

No AI-specific risk-assessment obligation confirmed.

Claims (1):

  • No AI-specific risk-assessment obligation interfacing with the PDPA was identified in the reviewed materials.

Biometric RegimeGreen

Biometric data is now categorised as sensitive personal data under the Amendment Act, subject to stricter processing requirements.

Claims (1):

  • Biometric data is now recognised as sensitive personal data under the Amendment Act, subject to stricter processing requirements than general personal data.

Genetic DataRed

No Malaysia-specific genetic-data-specific regime confirmed in this run.

Claims (1):

  • No Malaysia-specific genetic-data-specific processing regime distinct from the general sensitive-personal-data category was confirmed in this research pass.

State Surveillance CarveoutsRed

No state-surveillance carveout provision confirmed in this run.

Claims (1):

  • No PDPA provision on national-security/state-surveillance carveouts and their limits was confirmed in this research pass.
Category narrative36 words

The Amendment Act's classification of biometric data as sensitive personal data is the principal confirmed finding in this module. No profiling-restriction, ADM-transparency, AI-specific risk-assessment, genetic-data-specific, or state-surveillance-carveout provision was confirmed via Malaysia-specific retrieval in this run.

Periodic update · new data 2026-09-28

Algorithmic, Biometric & Surveillance Governance

Two related developments define this module for Malaysia this cycle. First, biometric data, including fingerprints, facial recognition, voice and retinal scans, was added as a new category of sensitive personal data by the 2024 Amendment Act, effective 1 April 2025. Second, the Department of Personal Data Protection is understood to have issued an Automated Decision-Making and Profiling guideline on 8 May 2026, reportedly concluding a 2025 public consultation process on that topic.

Together, these developments suggest Malaysia is building out algorithmic and biometric governance as a connected regulatory theme rather than addressing each in isolation: biometric data's elevation to sensitive-category status creates a heightened lawful-processing threshold for the data most commonly used in automated identity-verification and profiling systems, while the ADM and Profiling guideline speaks directly to the governance of automated decision processes that may draw on such data. However, the binding status and precise effective date of the ADM and Profiling guideline were not independently confirmed this cycle, so this connection should be read as a structural observation rather than a confirmed compliance requirement.

Outlook

Confirmation of the ADM and Profiling guideline's binding status is the priority item to track. If confirmed as binding, it would represent a meaningful addition to Malaysia's governance framework for automated systems processing the newly-sensitive biometric-data category.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (6)
  1. UncertainDataGuidance — Biometric data is now recognised as sensitive personal data under the Amendment Act, subject to stricter processing requirements than general personal data.observed
  2. UncertainDataGuidance — No PDPA/Amendment-Act provision restricting automated profiling analogous to GDPR Article 22 was identified in the reviewed materials.observed
  3. UncertainDataGuidance — No PDPA/Amendment-Act automated-decision-making transparency or explanation right was identified in the reviewed materials.observed
  4. UncertainDataGuidance — No AI-specific risk-assessment obligation interfacing with the PDPA was identified in the reviewed materials.observed
  5. UncertainDataGuidance (hosted copy of official Act text) — No Malaysia-specific genetic-data-specific processing regime distinct from the general sensitive-personal-data category was confirmed in this research pass.observed
  6. UncertainDataGuidance (hosted copy of official Act text) — No PDPA provision on national-security/state-surveillance carveouts and their limits was confirmed in this research pass.observed

#

No comprehensive children/vulnerable-groups regime was confirmed for Malaysia in this research session; this is an explicit evidentiary gap requiring primary-source escalation, not a substantive finding of 'no protection exists'.

Traffic-light rationale — RedNo comprehensive children/vulnerable-groups regime was confirmed for Malaysia in this research session; this is an explicit evidentiary gap requiring primary-source escalation, not a substantive finding of 'no protection exists'.

Sub-modules (5)

Age VerificationRed

No Malaysia-specific age-of-consent threshold for data processing was confirmed.

Claims (1):

  • No express age-of-consent threshold for personal-data processing was identified in the reviewed PDPA/Amendment Act materials.

Minor Profiling BansRed

No Malaysia-specific minor-profiling ban was confirmed.

Claims (1):

  • No minor-specific profiling ban was identified in the reviewed PDPA/Amendment Act materials.

Education SettingsRed

No Malaysia-specific education-settings data rule was confirmed.

Claims (1):

  • No education-settings-specific data-protection rule was identified in the reviewed PDPA/Amendment Act materials.

Dependent AdultsRed

No Malaysia-specific dependent-adult (elderly/incapacitated) protection was confirmed.

Claims (1):

  • No dependent-adult (elderly/mentally-incapacitated) protection provision was identified in the reviewed PDPA/Amendment Act materials.
Category narrative47 words

No Malaysia-specific age-of-consent, parental-consent mechanism, minor-profiling ban, education-settings rule, or dependent-adult protection was confirmed via Malaysia-specific retrieval in this research pass. Searches for PDPA children/minor provisions in the Amendment Act returned no Malaysia-specific results; adjacent PDPC Singapore children's-data guidance was excluded as out-of-scope for the MY JID.

Sources and claims (5)
  1. UncertainDataGuidance (hosted copy of official Act text) — No express age-of-consent threshold for personal-data processing was identified in the reviewed PDPA/Amendment Act materials.observed
  2. UncertainDataGuidance (hosted copy of official Act text) — No express parental/guardian-consent mechanism for processing a minor's personal data was identified in the reviewed PDPA/Amendment Act materials.observed
  3. UncertainDataGuidance (hosted copy of official Act text) — No minor-specific profiling ban was identified in the reviewed PDPA/Amendment Act materials.observed
  4. UncertainDataGuidance (hosted copy of official Act text) — No education-settings-specific data-protection rule was identified in the reviewed PDPA/Amendment Act materials.observed
  5. UncertainDataGuidance (hosted copy of official Act text) — No dependent-adult (elderly/mentally-incapacitated) protection provision was identified in the reviewed PDPA/Amendment Act materials.observed

#

Statutory powers and penalties are well evidenced and in force; enforcement-activity, funding, collective-redress, private-right-of-action and within-180-day developments remain unconfirmed gaps.

Primary frameworkPersonal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024
Traffic-light rationale — AmberStatutory powers and penalties are well evidenced and in force; enforcement-activity, funding, collective-redress, private-right-of-action and within-180-day developments remain unconfirmed gaps.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

Fines up to MYR1 million and imprisonment up to three years, plus proactive audit powers, confirmed under the Amendment Act.

Claims (1):

  • The Amendment Act increases maximum fines for PDPA violations to MYR1 million, extends the maximum imprisonment term to three years, and empowers the Commissioner to conduct proactive audits of organisations.

Enforcement Activity IndexRed

No confirmed record of Malaysia PDPC enforcement decisions/fines in the last 12 months was retrieved in this run.

Claims (1):

  • No specific record of Malaysia PDPC enforcement decisions or imposed fines within the last 12 months was located in this research pass.

Regulator Funding And CapacityRed

No confirmed data on PDP's funding or headcount was retrieved in this run.

Claims (1):

  • No confirmed data on PDP's operating budget or headcount was located in this research pass.

Collective Redress And Class ActionsRed

No confirmed collective-redress or class-action mechanism under the PDPA was retrieved in this run.

Claims (1):

  • No confirmed collective-redress or class-action mechanism available to data subjects under the PDPA was located in this research pass.

Private Right Of ActionRed

No confirmed private right of direct court action for data subjects under the PDPA was retrieved in this run.

Claims (1):

  • No confirmed private right of action allowing data subjects direct court recourse (independent of Commissioner enforcement) under the PDPA was located in this research pass.

Recent Developments 180DRed

The most recent confirmed dated development identified (PDP cross-border transfer guidance, dated October 2025) predates the 180-day window from this run's date (2026-08-05); no confirmed developments within the last 180 days were retrieved.

Claims (1):

  • The most recent confirmed dated Malaysia development in this research pass is PDP's cross-border data transfer guidance dated October 2025, which precedes the 180-day window measured from this run's date (2026-08-05); no confirmed developments from February-August 2026 were retrieved.
Category narrative81 words

The Amendment Act materially strengthens the Commissioner's enforcement toolkit: fines for violations rise to up to MYR1 million, imprisonment terms extend to up to three years, and the Commissioner gains proactive audit powers. No confirmed enforcement-activity data (fines/decisions) for the last 12 months, regulator funding/headcount signals, collective-redress mechanism, or private right of action were retrieved in this research pass; the most recent confirmed dated development (PDP cross-border transfer guidance, October 2025) falls outside the 180-day recent-developments window as of this run.

Periodic update · new data 2026-09-28

Enforcement & Redress

Malaysia's enforcement architecture for data-protection-principle breaches was materially strengthened by the Personal Data Protection (Amendment) Act 2024, which raised the maximum fine for breach of any single data-protection principle to RM1,000,000, more than tripling the prior RM300,000 cap. This increase accompanies, rather than stands apart from, the Amendment Act's new mandatory breach-notification and DPO-appointment duties: a controller that fails to meet the new notification or DPO obligations now faces meaningfully higher financial exposure than under the pre-amendment penalty regime.

The raised penalty ceiling is a clear, dated, and materially significant change to Malaysia's enforcement posture, and is corroborated at Confirmed confidence given its clear sourcing. It signals a shift toward a penalty regime intended to function as a genuine deterrent rather than one calibrated to a lower cost-of-doing-business threshold, which is a pattern seen in other jurisdictions modernising decade-old data-protection statutes.

Outlook

Watch for the first enforcement actions brought under the raised RM1,000,000 ceiling, which would provide an early indication of how JPDP intends to calibrate penalties in practice under the new maximum. Any enforcement action combining a breach-notification failure with a substantive data-protection-principle breach would be a particularly significant early test of the new penalty regime.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (6)
  1. UncertainIAPP — The Amendment Act increases maximum fines for PDPA violations to MYR1 million, extends the maximum imprisonment term to three years, and empowers the Commissioner to conduct proactive audits of organisations.observed
  2. UncertainDataGuidance — No specific record of Malaysia PDPC enforcement decisions or imposed fines within the last 12 months was located in this research pass.observed
  3. UncertainDataGuidance — No confirmed data on PDP's operating budget or headcount was located in this research pass.observed
  4. UncertainDataGuidance (hosted copy of official Act text) — No confirmed collective-redress or class-action mechanism available to data subjects under the PDPA was located in this research pass.observed
  5. UncertainDataGuidance (hosted copy of official Act text) — No confirmed private right of action allowing data subjects direct court recourse (independent of Commissioner enforcement) under the PDPA was located in this research pass.observed
  6. UncertainDataGuidance — The most recent confirmed dated Malaysia development in this research pass is PDP's cross-border data transfer guidance dated October 2025, which precedes the 180-day window measured from this run's date (2026-08-05); no confirmed developments from February-August 2026 were retrieved.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

Blocking. 1 failing check(s).

schema_validpass
min_t1_per_instrument_metwaived
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metFAIL
tier_a_b_national_primary_pct0.0
aggregator_only_jurisdiction_count1
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Malaysia
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 64 claim(s) (64 category placement(s)), 25 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacydata localisation
Art. 49Cross-Border & Adequacytransfer impact assessment
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, lawful_processing_and_special_data (core consent/sensitive-data provisions), data_subject_rights (access/correction/portability), controller_processor_duties (DPO/breach/security/retention) and cross_border_and_adequacy (transfer mechanism/TIA) modules are supported by T1 (Act text) and T2 (law-firm/IAPP/DataGuidance commentary on the Amendment Act) evidence with Confirmed/Probable confidence. sectoral_watch is populated only for the financial-sector overlay (T2, Probable); health/telecoms/employment/credit/education/insurance overlays are unresolved gaps. adtech_and_commercial_privacy and children_and_vulnerable_groups are near-fully gap modules (T3/absent), each carrying explicit absent_field_provenance rather than fabricated obligations; a direct-marketing and a children's-data search each returned Singapore PDPA materials that were deliberately excluded per JID discipline rather than misattributed to Malaysia. algorithmic_biometric_and_surveillance_governance is confirmed only for the new biometric-sensitive-data classification; profiling/ADM/AI-risk/genetic/state-surveillance sub-modules are unresolved gaps. enforcement_and_redress is confirmed for statutory powers/penalties (T2) but enforcement-activity-index, regulator funding/capacity, collective redress, private right of action, and the within-180-day recent-developments window are unresolved gaps (most recent confirmed dated item, October 2025 cross-border guidance, predates the 180-day window from 2026-08-05).

Unresolved questions (7):

  • Exact statutory response-window (day count) for PDPA access/correction requests under sections 31/35 was not confirmed via primary-source retrieval this run.
  • Whether the Amendment Act introduces a DPIA obligation (GDPR Art 35 analogue) or a formal records-of-processing (ROPA, GDPR Art 30 analogue) requirement was not confirmed.
  • The specific list of countries on Malaysia's cross-border transfer 'whitelist', and the substantive content of PDP's April 2025 cross-border transfer guidelines, were not retrieved beyond headline confirmation of publication.
  • Whether the PDPA contains a direct-marketing/Do-Not-Call suppression regime for Malaysia specifically (as opposed to Singapore's PDPA section 43/DNC Provisions) was not confirmed.
  • Whether the Amendment Act 2024 introduces any children/minor-specific consent, age-verification, or profiling-ban provisions was not confirmed; searches surfaced only Singapore PDPC children's-data guidance.
  • No Malaysia PDPC enforcement decisions or fines from the last 12 months, nor PDP funding/headcount data, were located in this research pass.
  • No development specific to Malaysia's PDPA dated within the 180 days preceding 2026-08-05 was located; the most recent confirmed item (cross-border guidance) is dated October 2025.

Escalate to primary-source review: yes