#
Comprehensive statute in force with a fully commenced modernising amendment; core institutional architecture (Commissioner + PDP) is stable and actively issuing implementing guidance.
Sub-modules (5)
Regulator And AuthorityGreen
The Commissioner, assisted by PDP, administers and enforces the PDPA.
Claims (1):
- The PDPA confers powers to the Personal Data Protection Commissioner, who is assisted by the Department of Personal Data Protection (PDP) to administer and enforce the provisions of the PDPA.
Act And InstrumentsGreen
PDPA 2010 in force since 15 November 2013; Amendment Act 2024 gazetted 17 October 2024 with staged commencement through 1 June 2025.
Claims (2):
- The Personal Data Protection (Amendment) Act 2024 was published in the Gazette on 17 October 2024 after receiving Royal Assent on 9 October 2024, following passage by the Senate (31 July 2024) and House of Representatives (16 July 2024).
- The Amendment Act's provisions were implemented in stages, with sections coming into effect on 1 January, 1 April, and 1 June 2025, covering biometric data, controller/processor terminology, cross-border transfer rules, DPO appointment, breach notification and portability respectively.
Material ScopeGreen
PDPA covers processing of personal data in commercial transactions by an establishment in Malaysia or using equipment in Malaysia.
Claims (1):
- The PDPA regulates the processing of personal data in commercial transactions either by an establishment in Malaysia or with equipment in Malaysia, unless the personal data only transits through Malaysia.
Territorial ScopeAmber
Extraterritorial reach is anchored to use of equipment in Malaysia rather than a pure establishment test; transit-only data is excluded.
Claims (1):
- Extraterritorial application of the PDPA turns on use of equipment located in Malaysia (an equipment-based test), rather than a GDPR-style establishment/targeting test; data merely transiting Malaysia is expressly excluded.
Regulator Registration And FilingGreen
PDP mandates registration of 13 designated classes of data controllers/users, and separately requires DPO-appointment notification within 21 days via a dedicated registration manual.
Claims (2):
- PDP mandates registration for 13 designated classes/groups of data controllers under the PDPA, with penalties for non-compliance with the registration requirement.
- Controllers and processors must notify the Commissioner of DPO appointments; PDP's DPO registration manual requires such notification within 21 days of appointment.
Regulator & Framework
Malaysia's Department of Personal Data Protection (JPDP) is the jurisdiction's primary data-protection regulator, distinct from the Securities Commission's role in the crypto and digital-asset-exchange space. The foundational statute, the Personal Data Protection Act 2010, has been substantially amended by the Personal Data Protection (Amendment) Act 2024 (Act A1727), which represents the most significant legislative modernisation of Malaysia's data-protection regime since the original Act's passage. Commencement of the amendment's various provisions is being staged through Ministerial Gazette notification, meaning different substantive changes have taken effect, or will take effect, on different dates rather than through a single commencement.
The exact phased commencement schedule by individual provision was not fully retrieved this cycle, and the primary source confirms only that different provisions commence via separate Gazette notifications rather than laying out the complete provision-by-provision timetable. What is confirmed is that key substantive changes, including the breach-notification and DPO requirements discussed under Controller/Processor Duties, are already in force.
Outlook
As further Ministerial Gazette notifications bring additional Amendment Act provisions into force, the phased-commencement picture should become progressively clearer. Tracking each notification as it is published will be necessary to establish a complete effective-date map for the full amendment package.
1 further periodic run re-emitted the standing brief unchanged and is not shown.
Sources and claims (7)
- UncertainDataGuidance — The PDPA confers powers to the Personal Data Protection Commissioner, who is assisted by the Department of Personal Data Protection (PDP) to administer and enforce the provisions of the PDPA.observed
- UncertainDataGuidance — The Personal Data Protection (Amendment) Act 2024 was published in the Gazette on 17 October 2024 after receiving Royal Assent on 9 October 2024, following passage by the Senate (31 July 2024) and House of Representatives (16 July 2024).observed
- UncertainDataGuidance — The Amendment Act's provisions were implemented in stages, with sections coming into effect on 1 January, 1 April, and 1 June 2025, covering biometric data, controller/processor terminology, cross-border transfer rules, DPO appointment, breach notification and portability respectively.observed
- UncertainDataGuidance — The PDPA regulates the processing of personal data in commercial transactions either by an establishment in Malaysia or with equipment in Malaysia, unless the personal data only transits through Malaysia.observed
- UncertainDataGuidance — Extraterritorial application of the PDPA turns on use of equipment located in Malaysia (an equipment-based test), rather than a GDPR-style establishment/targeting test; data merely transiting Malaysia is expressly excluded.observed
- UncertainDataGuidance — PDP mandates registration for 13 designated classes/groups of data controllers under the PDPA, with penalties for non-compliance with the registration requirement.observed
- UncertainDataGuidance — Controllers and processors must notify the Commissioner of DPO appointments; PDP's DPO registration manual requires such notification within 21 days of appointment.observed