Data and PDPA

Keeping credit reports and IC copies safe

A credit report or an IC copy gives someone enough detail to cause real harm to the customer, so the PDPA's Security Principle expects practical steps in proportion to that harm. The PDPC's 2015 security standard says what those steps look like: named logins, limited access, locked paper files, a record of who accessed the data, no transfers by removable media or cloud service without written approval, and access ended when someone leaves. In a small office the weak points are usually ordinary habits such as chat groups, personal phones and forgotten downloads.

By the NexFlows team · Published 13 April 2026 · Facts last checked 4 October 2026 · 6 min read

Why these two documents carry the most risk

An IC copy shows a name, an IC number, an address and a photo. A credit report adds loans, limits and repayment history. The PDPC's breach guideline treats a negative effect on credit records, and personal details that could enable identity fraud when combined, as signs of significant harm. A lost laptop holding either can meet that test.

Credit information also has rules of its own. Bank Negara Malaysia says a CCRIS report is confidential and can only be accessed by participating financial institutions and approved credit reporting agencies, with the borrower's consent, and that its use is regulated with penalties for unauthorised access, abuse or misuse. CTOS and Experian, in their summaries of rights under the Credit Reporting Agencies Act 2010, say a credit reporting agency needs your consent before it discloses your report, and that credit information cannot be collected and used for any purpose other than the Act allows.

In our reading, the customer's consent covers the loan application it was given for. Browsing the report, reusing it later, or passing it to people outside the application is the kind of use those rules are meant to prevent. The PDPA's purpose rules (sections 6(3) and 8) point the same way. Check the terms of your credit report subscription and the consent form you use, and ask a lawyer if you are unsure.

What the PDPA and the PDPC expect

The Security Principle in section 9 asks you to take practical steps against loss, misuse, unauthorised access, disclosure, alteration or destruction. It tells you what to weigh: the nature of the data and the harm that would follow, where it is stored, the security built into the equipment, the reliability and competence of the people with access, and how safely the data is transferred.

The Regulations go further. You must have a security policy that meets the PDPC's standard, and you must make sure a processor meets it too. Not having one is an offence, with a fine of up to RM 250,000 or two years in prison, or both. The PDPC's Personal Data Protection Standard, made on 23 December 2015, lists the minimum steps. The ones that matter most in a loan office are:

  • Register every staff member who handles personal data, and give each authorised person a user ID and password.
  • Control and limit what each person can access.
  • End access rights when someone resigns, is dismissed or their contract ends, and cancel their user ID and password immediately.
  • Keep paper files in a locked place, keep the keys safe and keep a record of where the keys are.
  • Keep back-up and anti-virus up to date, and protect computers from malware.
  • Do not move personal data by removable media (such as a USB drive) or a cloud service unless an officer authorised by top management approves in writing, and record each transfer.
  • Keep a record of who accessed personal data. The PDPC can ask for it.
  • Make sure staff keep customers' data confidential, and bind outside suppliers who handle it by contract.
  • Destroy used papers and printouts that show personal data, for example with a shredder.

As of October 2026 the PDPC site still lists the 2015 standard. The PDPC consulted on a revised standard in October 2024, and its August 2025 paper on the 2013 Regulations says the standard will be revised, so check for a newer version before you write your policy.

Where copies leak in a loan office

One credit report, two ways of handling it. The left side is typical of an office with no routine. The right side is what the standard asks for.
Where it happensWhat goes wrongSafer habit
WhatsApp groups and personal phonesReports and IC photos sit in chat history and phone galleries. They stay when the person leaves or the phone is lost.Collect documents in one controlled place. Keep customer files off personal phones where you can, and delete the chat copy once the document is filed.
Email to personal addressesA report forwarded home is out of your control for good.Send from work accounts only, and tell staff that forwarding to personal mail is not allowed.
Shared folders and open linksA link that anyone can open stays open long after the case closes.Share with named people only, and review sharing when a case closes.
The downloads folderA report opened once is saved on the laptop for years.Open reports from the system you use, and clear downloads at the end of the day.
Printed copiesLeft on desks, in bags and in bins. The PDPC's own examples of a breach include forms with ID details left unattended on a desk.Locked cabinet, and shred what you no longer need.
Old accountsA leaver's login still works.Switch it off the same day. See when an agent leaves.

The standard says transfers by removable media and cloud services need written approval and a record. Whether a chat app counts as a cloud service is not something the standard answers. The safe reading is to treat personal phones and chat apps as places where customer data can escape your control, and to decide in writing what is allowed.

The same standard item covers any cloud service, including a cloud CRM or online storage. Record top management's written approval for the ones you use, and note where the data is stored.

A handling routine that works

  1. Get consent for this report

    Take the customer's consent for the specific credit report and application, in a form you can keep. The Regulations put the burden of proving consent on you.

  2. Collect only what the application needs

    The Act allows data that is adequate but not excessive for the purpose. If the bank does not need a document, do not take it.

  3. Keep one copy, in one place

    Pick the place where reports and IC copies live, with named logins. Everything else points to it.

  4. Show it only to people working on the case

    The agent, the team leader and the admin handling the file. Not the whole team.

  5. Send it only where you told the customer it would go

    That is usually the bank. Use a channel you control, and record the transfer.

  6. Delete working copies when the case closes

    Shred paper. See how long to keep customer records for setting a schedule.

Make the safe way the easy way

People copy files to their phones because the proper place is slow. The best control is a system your team actually likes using. The CTOS analyzer on our homepage reads CTOS, eCCRIS and Experian PDFs inside your browser and does not upload them. The PDF on your own device is still yours to protect. Inside the Loan Advisory CRM it works differently: the PDF is sent to our server to be read, and a copy is kept in secure storage, so treat it like any other customer file and tell your customer.

In the Loan Advisory CRM everyone sees only their part of the work, and an activity log shows who did what. For the PDPC standard's access record, check what each system records. Whatever tool you use, ask what it records and whether each person sees only their part.

If a copy goes astray

Treat it as a possible personal data breach the same day. Note when you found out, what was in the copy and whose it was. The PDPC's own example is an email with a customer's account statement sent to the wrong person, and it says the PDPC must be told because the data is financial information. The 2024 amendment guide sets out the 72-hour clock and who to tell.

Questions people ask next

Can I keep a customer's CTOS report after the loan is approved?
Only as long as you need it for the purpose the customer agreed to. The PDPA says personal data must not be kept longer than necessary. If you need it for a dispute or a legal reason, write that down.
Is it safe to send IC photos over WhatsApp?
The PDPA does not ban it, but the Security Principle asks for practical steps in proportion to the harm if it goes wrong. A chat history on a personal phone is hard to control. Decide in writing what staff may send and where, and delete the chat copy after filing.
Do I need the customer's consent every time I pull a report?
The credit reporting agencies say they need the person's consent before they disclose a report, and your own PDPA duty to keep proof of consent applies too. Take consent for each application and keep a record you can find later.

Sources

This guide is general information, not legal, tax or financial advice. Rules and bank policies change, so check the current position with the bank, the regulator or a professional before you act.

See the Loan Advisory CRM

Leads, calling, credit reports, team and commission in one place, for RM 1,000 a month for 20 users.