The three start dates
The amending Act received Royal Assent on 9 October 2024 and was published in the Gazette on 17 October 2024. It did not fix its own start date. The Minister of Digital set the dates in Gazette notice P.U. (B) 522, published on 24 December 2024.
1 January 2025
Sections 7, 11, 13 and 14 of the amending Act
- Housekeeping and transitional rules
- Notices can be served electronically
1 April 2025
Sections 2, 3, 4, 5, 8, 10 and 12 of the amending Act
- Penalty up to RM 1,000,000 or three years
- Processors bound by the Security Principle
- Biometric data is sensitive
- New rules for sending data abroad
1 June 2025
Sections 6 and 9 of the amending Act
- Data protection officers
- Breach notification
- Data portability
- PDPC circulars start
| From | Sections of the amending Act | What began |
|---|---|---|
| 1 January 2025 | 7, 11, 13 and 14 | Housekeeping: the Commissioner's bank accounts, serving notices by electronic means, a wording fix in the Malay text, and transitional rules. |
| 1 April 2025 | 2, 3, 4, 5, 8, 10 and 12 | The words data controller replace data user. New definitions, including biometric data and personal data breach. Processors must follow the Security Principle. Higher penalty. New rules for sending data abroad. |
| 1 June 2025 | 6 and 9 | Data protection officers (new section 12A), data breach notification (section 12B) and the right to data portability (section 43A). |
A higher penalty, and suppliers are bound too
From 1 April 2025 the maximum penalty for breaking the seven principles rose from RM 300,000 or two years in prison to RM 1,000,000 or three years, or both. The same Act now makes a data processor directly responsible for the Security Principle, with the same penalty.
If a CRM, IT or marketing supplier handles your customers' data, ask what it does to protect it and how fast it will tell you about a problem. The PDPC's breach guideline says the breach reporting duty does not apply to the processor directly. It falls on you, and you must require the processor by contract, or by other reasonable means, to tell you promptly and give all reasonable help.
Breach notification: the 72-hour clock
A personal data breach is any breach, loss, misuse or unauthorised access of personal data. The PDPC's guideline gives everyday examples: an employee emailing customer data to the wrong person, losing a laptop with unencrypted data, leaving forms with ID details on a desk, or deliberately taking customer information and selling it.
The guideline says a breach must be reported to the PDPC when it causes or is likely to cause significant harm. It counts as significant harm if the data could lead to physical harm, financial loss, a negative effect on credit records or damage to property, could be misused for illegal purposes, includes sensitive personal data, could enable identity fraud when combined with other details, or is of significant scale, meaning more than 1,000 people. IC copies and credit reports can meet several of these at once.
A reportable breach is found
72 hours
Counted from the breach in the PDPC's wording. Its examples count from when you are told or confirm it, so do not wait.
Tell the PDPC, as soon as practicable. If you miss it, send a written notice with reasons and evidence.
7 days
From the day you notify the PDPC
Tell affected customers directly, if significant harm is likely.
30 days
From the day you notify the PDPC
Send any details you could not give in the first notice.
2 years
At least. The guideline counts from your notice to the PDPC, the circular from the day of the breach.
Keep the breach register, including incidents you decided not to report. Count from the later date.
The guideline sets these deadlines. Notify the Commissioner as soon as practicable and within 72 hours. The guideline words the limit as 72 hours from the occurrence of the breach. Its worked examples start the count when you are told of the breach or confirm it, but do not count on that reading if you can report sooner. If a processor handles the data for you, the count runs from when the processor tells you or when you have clear evidence of a breach, whichever is earlier. If you miss the 72 hours, you must send a written notice with the reasons and evidence. You may send the remaining details in phases, no later than 30 days after the first notice.
Where significant harm is likely, tell the affected customers without unnecessary delay and not later than 7 days after you notify the Commissioner. Tell each person directly, in plain language, and send it separately from newsletters and other messages. The more-than-1,000 test does not apply to this step. Failing to notify the Commissioner is an offence, with a fine of up to RM 250,000 or two years in prison, or both.
You can report through the form on the PDPC website, or by emailing the Annex B form in the guideline to dbnpdp@pdp.gov.my. A report is not treated as submitted until the PDPC sends a confirmation notice. Keep a breach register, including incidents you decided not to report and why. Keep it for at least two years. The guideline counts from the day you notify the PDPC and the circular from the day of the breach, so count from the later date. For an incident you did not report, count from the day you recorded it.
Data protection officers: check the facts first
Section 12A says a data controller shall appoint one or more data protection officers (DPOs), accountable for compliance, and a data processor, such as a software supplier, must do the same. The section itself sets no size limit. The PDPC's circular, in force from 1 June 2025, says the duty applies in any case where your processing involves personal data of more than 20,000 people, sensitive personal data including financial information of more than 10,000 people, or activities that need regular and systematic monitoring. The PDPC's guideline adds that a firm below these limits may keep a record of why it did not appoint.
These figures count people, not files, and they are easy to underestimate. Old lead databases, bought lists and closed cases probably count if you still hold them. We did not find PDPC guidance on how to count across years of old records, so ask the PDPC how it applies to you.
If you do need a DPO, the guideline says:
- The DPO can be an existing employee or an outside provider, and the role can be part-time. The guideline sets no minimum professional qualification, but the person must show the skills it lists.
- The DPO must live in Malaysia (at least 180 days a year) or be easy to contact, and be proficient in Bahasa Melayu and English.
- The DPO must not have a conflict of interest. The guideline's own example is a head of marketing.
- Register the DPO with the PDPC through its online system within 21 days of appointment, and update any change within 14 days.
- Publish the DPO's business contact details on your website, privacy notice or security policy, using a dedicated business email address.
- Appointing a DPO does not remove the firm's own responsibility.
Smaller changes worth knowing
- Biometric data is now sensitive personal data. The Act defines it as personal data from technical processing of a person's physical, physiological or behavioural characteristics, which covers fingerprint or face scans used for staff attendance. Sensitive data needs explicit consent unless an exception applies, and the Act has an exception for rights and duties that the law gives or imposes in connection with employment, so ask a lawyer how it fits your case.
- Data portability lets a customer ask you in writing, by electronic means, to send their data directly to another data controller. It is subject to technical feasibility and compatible formats, and the Act leaves the deadline to be prescribed. We did not find a prescribed period as of October 2026.
- Sending data abroad no longer depends on a Minister's list of approved countries. You may send data to a place with a substantially similar law or adequate protection, or where another condition in section 129 applies, such as the person's consent. The PDPC's cross-border guideline says to tell customers in your notice if you transfer data abroad. If your CRM, email or WhatsApp provider stores data outside Malaysia, ask where.
- Deceased people are no longer data subjects under the Act.
What a small firm should do now
- Write a one-page breach plan: who decides, who contacts the PDPC, who writes to customers, and where the form is. The guideline expects a response plan.
- Count the people whose data you hold, including old leads. Compare with the circular's limits, and write down the result and your reasons.
- Check your supplier contracts for a promise to report a breach promptly.
- Update your privacy notice if data goes abroad, and add the DPO's contact details if you have one.
- Check the PDPC site every few months. As of October 2026 it also lists guidelines on impact assessments, data protection by design and automated decision-making, and consulted in 2025 on changes to the 2013 Regulations.
Questions people ask next
- Does the amendment apply to a one-person agent?
- The Act has no size limit, so the main duties apply. The data protection officer duty depends on the PDPC's conditions about how many people's data you handle, which a very small firm may not reach. Check the current circular and keep a note of your reasons.
- Do I have to tell customers about every breach?
- No. Under section 12B(2) of the Act and the PDPC guideline, you tell customers when the breach results or is likely to result in significant harm. Keep a record of the incidents you decided not to report, with your reasons.
- Who counts as a data processor?
- A person other than your employee who handles the data only on your behalf and not for their own purposes, such as a software or cloud supplier. Whether a freelance agent is your processor depends on how they use the data. See the PDPA basics.
- How do I tell the PDPC about a breach?
- Use the notification form on the PDPC website, or email the Annex B form from the breach guideline to dbnpdp@pdp.gov.my. The report counts once the PDPC sends you a confirmation notice.
Sources
- Personal Data Protection (Amendment) Act 2024 [Act A1727] (PDPC, PDF)
- Gazette notice P.U. (B) 522, appointment of date of coming into operation, 24 December 2024 (PDPC, PDF)
- Commissioner's Circular on data breach notification, in Malay (No. 2/2025 on the PDF itself; the PDPC web page lists it as No. 1/2025) (PDPC, PDF)
- Personal Data Protection Guideline: Data Breach Notification, 25 February 2025 (PDPC, PDF)
- Commissioner's Circular on appointment of data protection officer, in Malay (No. 1/2025 on the PDF itself; the PDPC web page lists it as No. 2/2025) (PDPC, PDF)
- Personal Data Protection Guideline: Appointment of Data Protection Officer, 25 February 2025 (PDPC, PDF)
- Personal Data Protection Guidelines: Cross Border Personal Data Transfer, 29 April 2025 (PDPC, PDF)
- PDPC: Act 709, circulars, guidelines and standards (pdp.gov.my)
This guide is general information, not legal, tax or financial advice. Rules and bank policies change, so check the current position with the bank, the regulator or a professional before you act.