Data and PDPA

How long to keep customer records, and when to delete them

The PDPA does not give one retention period. Section 10 says personal data must not be kept longer than needed for its purpose, and must be destroyed or permanently deleted once it is no longer required. The PDPC's 2015 standard adds that you must first check what other laws require, dispose of data collection forms within 14 days unless they have legal value, and keep a disposal schedule for inactive data with a 24-month period. For any record that tax, company or lender rules require you to keep, ask your accountant, lawyer or the bank for the current period.

By the NexFlows team · Published 22 June 2026 · Facts last checked 4 October 2026 · 7 min read

What the PDPA says, and what it does not

The Retention Principle in section 10 has two parts. Personal data processed for a purpose must not be kept longer than is necessary to fulfil that purpose. And it is the controller's duty to take all reasonable steps to destroy or permanently delete data that is no longer required for the purpose it was processed for.

There is no number in the Act. The Regulations say personal data must be retained in line with the retention standard the PDPC sets from time to time. Not doing so is an offence, with a fine of up to RM 250,000 or two years in prison, or both. So the PDPC's standard matters, and the next section goes through it.

What the PDPC's standard asks, item by item

The Personal Data Protection Standard, made on 23 December 2015, applies to anyone who processes personal data in commercial transactions. Its retention standard lists seven things:

  1. Work out the retention periods set by all the laws that apply to the data, and meet them before you destroy anything.
  2. Keep personal data no longer than necessary, unless another law requires longer.
  3. Keep a record of disposal, and be ready to hand it to the PDPC.
  4. Dispose of personal data collection forms used in commercial transactions within 14 days at most, unless the forms carry legal value in relation to the transaction.
  5. Review the database and dispose of personal data that is not needed.
  6. Prepare a disposal schedule for inactive data with a 24-month period, and keep it up to date.
  7. Do not use removable media to store personal data without written approval from top management.

Two of these need care. The 14-day rule reads as aimed at forms filled in only to collect details, such as a sign-up slip at a roadshow. A signed loan application usually has legal value. Whether a given form does is for you and your lawyer to judge.

The 24-month item says to prepare a schedule for inactive data "with a 24 month period" and says no more. The PDPC's own restatement in its October 2024 consultation paper words it as a schedule for inactive data within a 24-month period, which leans towards 24 months as a limit. Neither says what counts as inactive, and we found no further PDPC explanation. A cautious reading: when a record has been inactive for 24 months, delete it or write down why you still need it. If you are unsure, ask the PDPC.

As of October 2026 the PDPC site still lists the 2015 standard. The PDPC consulted on a revised standard in October 2024, and its August 2025 paper on the 2013 Regulations says the standard will be revised to add a clear retention policy, a disposal schedule and secure destruction methods. Check for a newer version.

Why keeping everything is a risk

  • A breach is bigger. The PDPC's breach guideline treats a breach of more than 1,000 people as significant scale, and old files full of IC numbers and credit reports are what a thief takes.
  • It can tip you over a limit. The PDPC's data protection officer circular counts the people whose data you handle: more than 20,000, or more than 10,000 for sensitive data including financial information. Old leads you still hold may count towards those numbers.
  • Requests get harder. A customer who asks to see their data has to be answered within 21 days. The more copies in more places, the longer it takes to find them all.
  • You may have to prove it. The PDPC can ask for your records of following the retention standard. A schedule you follow is easy to show. A shared drive nobody has cleared is not.
A keep-or-delete test to run on any record. Work down from the top.

Setting a schedule for a loan agency

Below are the kinds of record a loan agency holds, with the questions that decide how long to keep each. We give a number only where a primary source does. For the rest, the period comes from your own purpose, your agreements with banks, and the law that applies to that record.

RecordQuestions to settleWhat we can say
Leads who never became customersDid they ask to be contacted again? When did you last speak?The standard's 24-month inactive schedule is the only figure in the PDPC text. Review at that point: delete, or write down why you still need it.
Collection forms and roadshow slipsDoes the form carry legal value for a transaction?The standard says dispose within 14 days at most, unless it does.
Open applicationsIs the case still live with a bank?Keep while the case is live and you need the data for it.
Approved and paid casesIs any fee or commission still due? Does the bank or your agreement ask you to keep records?Set by your agreements and by the bank. Ask the bank what it needs from you.
Declined or withdrawn applicationsIs there a complaint or dispute? Is the customer likely to return?Do not keep for a reason you cannot write down.
Invoices, commission and payout statementsWhich tax and company law rules apply to your business?Set by law, not by the PDPA. A company must keep its accounting and other records that explain its transactions for seven years after those transactions are completed (Companies Act 2016, section 245(3)). Anyone carrying on a business must keep records of income and expenses for seven years (Income Tax Act 1967, section 82). Ask your accountant to confirm how this applies to your firm. These periods cover accounting and tax records, not customers' IC copies or credit reports.
Credit reports and IC copiesIs the application still open?The highest-risk items. Delete working copies soon after the case closes. See keeping credit reports and IC copies safe.
Call recordings and WhatsApp chatsWhat do you use them for: training, checking a dispute?Decide a purpose and a period. Do not keep them just in case.
Records of consent and noticesDo you still hold the data that the consent covers?The Regulations put the burden of proving consent on you, so keep the proof for as long as you hold the data.
Breach registerHave you recorded every incident, including ones you did not report?Keep it for at least two years. The guideline counts from the day you notify the PDPC and the circular from the day of the breach, so count from the later date. For an incident you did not report, count from the day you recorded it.
Questions, not deadlines, except where a primary source gives a number.

How to delete properly

  1. Decide what goes

    Use the test above on each kind of record, and write the result into a one-page schedule with a review date.

  2. Delete from every place it lives

    The system, exports, spreadsheets, chat history, email and downloads. The Act says permanently deleted, and a copy in a forgotten folder is still a copy.

  3. Ask your suppliers to delete too

    If a CRM, cloud or marketing supplier holds the data for you, ask it to delete, and ask how long deleted data stays in its backups. Write down the answer.

  4. Shred paper

    The standard names shredding as a method for used papers and printouts that show personal data.

  5. Record what you did

    What was deleted, when and by whom. The standard asks for a disposal record and the PDPC can ask for it.

When a customer asks, and when to hold off

A customer can withdraw consent by written notice, and you must then stop processing their data. The Act counts holding and storing as processing, so on a plain reading you should stop holding the data too, unless another legal reason lets you keep it. A customer can also ask you to correct data that is wrong. Ask a lawyer about any record you think you must keep against the customer's wishes.

Questions people ask next

Is there a fixed number of years I must keep loan records?
Not in the PDPA. Other laws set periods for some records, such as accounting records, which companies keep for seven years, and business tax records. Banks may ask you to keep records of cases you submit. Ask your accountant and the banks you work with for the current periods.
Can I keep old leads in case they call back?
Not on that reason alone. The PDPA says personal data must not be kept longer than necessary for its purpose. Choose a review point, say in your privacy notice how long you keep leads, and delete them or write down why you are keeping them.
Does the standard's 24 months mean I must delete after two years?
The 2015 standard asks for a disposal schedule for inactive data with a 24-month period, and the PDPC's 2024 consultation paper words it as within a 24-month period. Neither says what counts as inactive. Treat 24 months as your review point: delete the record or write down why you are keeping it. Ask the PDPC if you need a firm answer.
Do I have to keep a record of what I delete?
The PDPC's retention standard says to keep a record of disposal and to make it available when the PDPC asks. A simple log of what was deleted, when and by whom is enough to start with.

Sources

This guide is general information, not legal, tax or financial advice. Rules and bank policies change, so check the current position with the bank, the regulator or a professional before you act.

Talk to us about your team

Tell us how you work. We reply on working days and will not send you a sales script.