Data and PDPA

The 2024 PDPA amendment: what changed for small firms

The Personal Data Protection (Amendment) Act 2024 changed the PDPA in three steps, on 1 January, 1 April and 1 June 2025. For a small firm the main changes are a penalty of up to RM 1,000,000 or three years, direct security duties for suppliers, a duty to report certain data breaches to the PDPC, a data protection officer where the PDPC's conditions are met, and a customer right to have their data sent to another company. Whether the officer duty applies depends on your data: confirm with the PDPC or a lawyer.

By the NexFlows team · Published 9 March 2026 · Facts last checked 4 October 2026 · 7 min read

The three start dates

The amending Act received Royal Assent on 9 October 2024 and was published in the Gazette on 17 October 2024. It did not fix its own start date. The Minister of Digital set the dates in Gazette notice P.U. (B) 522, published on 24 December 2024.

The three start dates in P.U. (B) 522, with the main change that began on each.
FromSections of the amending ActWhat began
1 January 20257, 11, 13 and 14Housekeeping: the Commissioner's bank accounts, serving notices by electronic means, a wording fix in the Malay text, and transitional rules.
1 April 20252, 3, 4, 5, 8, 10 and 12The words data controller replace data user. New definitions, including biometric data and personal data breach. Processors must follow the Security Principle. Higher penalty. New rules for sending data abroad.
1 June 20256 and 9Data protection officers (new section 12A), data breach notification (section 12B) and the right to data portability (section 43A).
The PDPC's circulars on breach notification and data protection officers also took effect on 1 June 2025.

A higher penalty, and suppliers are bound too

From 1 April 2025 the maximum penalty for breaking the seven principles rose from RM 300,000 or two years in prison to RM 1,000,000 or three years, or both. The same Act now makes a data processor directly responsible for the Security Principle, with the same penalty.

If a CRM, IT or marketing supplier handles your customers' data, ask what it does to protect it and how fast it will tell you about a problem. The PDPC's breach guideline says the breach reporting duty does not apply to the processor directly. It falls on you, and you must require the processor by contract, or by other reasonable means, to tell you promptly and give all reasonable help.

Breach notification: the 72-hour clock

A personal data breach is any breach, loss, misuse or unauthorised access of personal data. The PDPC's guideline gives everyday examples: an employee emailing customer data to the wrong person, losing a laptop with unencrypted data, leaving forms with ID details on a desk, or deliberately taking customer information and selling it.

The guideline says a breach must be reported to the PDPC when it causes or is likely to cause significant harm. It counts as significant harm if the data could lead to physical harm, financial loss, a negative effect on credit records or damage to property, could be misused for illegal purposes, includes sensitive personal data, could enable identity fraud when combined with other details, or is of significant scale, meaning more than 1,000 people. IC copies and credit reports can meet several of these at once.

The PDPC words the first limit as 72 hours from the breach, though its examples count from when you are told or confirm it. The next two run from the day you notify the PDPC, and the register is then kept for at least two years.

The guideline sets these deadlines. Notify the Commissioner as soon as practicable and within 72 hours. The guideline words the limit as 72 hours from the occurrence of the breach. Its worked examples start the count when you are told of the breach or confirm it, but do not count on that reading if you can report sooner. If a processor handles the data for you, the count runs from when the processor tells you or when you have clear evidence of a breach, whichever is earlier. If you miss the 72 hours, you must send a written notice with the reasons and evidence. You may send the remaining details in phases, no later than 30 days after the first notice.

Where significant harm is likely, tell the affected customers without unnecessary delay and not later than 7 days after you notify the Commissioner. Tell each person directly, in plain language, and send it separately from newsletters and other messages. The more-than-1,000 test does not apply to this step. Failing to notify the Commissioner is an offence, with a fine of up to RM 250,000 or two years in prison, or both.

You can report through the form on the PDPC website, or by emailing the Annex B form in the guideline to dbnpdp@pdp.gov.my. A report is not treated as submitted until the PDPC sends a confirmation notice. Keep a breach register, including incidents you decided not to report and why. Keep it for at least two years. The guideline counts from the day you notify the PDPC and the circular from the day of the breach, so count from the later date. For an incident you did not report, count from the day you recorded it.

Data protection officers: check the facts first

Section 12A says a data controller shall appoint one or more data protection officers (DPOs), accountable for compliance, and a data processor, such as a software supplier, must do the same. The section itself sets no size limit. The PDPC's circular, in force from 1 June 2025, says the duty applies in any case where your processing involves personal data of more than 20,000 people, sensitive personal data including financial information of more than 10,000 people, or activities that need regular and systematic monitoring. The PDPC's guideline adds that a firm below these limits may keep a record of why it did not appoint.

These figures count people, not files, and they are easy to underestimate. Old lead databases, bought lists and closed cases probably count if you still hold them. We did not find PDPC guidance on how to count across years of old records, so ask the PDPC how it applies to you.

If you do need a DPO, the guideline says:

  • The DPO can be an existing employee or an outside provider, and the role can be part-time. The guideline sets no minimum professional qualification, but the person must show the skills it lists.
  • The DPO must live in Malaysia (at least 180 days a year) or be easy to contact, and be proficient in Bahasa Melayu and English.
  • The DPO must not have a conflict of interest. The guideline's own example is a head of marketing.
  • Register the DPO with the PDPC through its online system within 21 days of appointment, and update any change within 14 days.
  • Publish the DPO's business contact details on your website, privacy notice or security policy, using a dedicated business email address.
  • Appointing a DPO does not remove the firm's own responsibility.

Smaller changes worth knowing

  • Biometric data is now sensitive personal data. The Act defines it as personal data from technical processing of a person's physical, physiological or behavioural characteristics, which covers fingerprint or face scans used for staff attendance. Sensitive data needs explicit consent unless an exception applies, and the Act has an exception for rights and duties that the law gives or imposes in connection with employment, so ask a lawyer how it fits your case.
  • Data portability lets a customer ask you in writing, by electronic means, to send their data directly to another data controller. It is subject to technical feasibility and compatible formats, and the Act leaves the deadline to be prescribed. We did not find a prescribed period as of October 2026.
  • Sending data abroad no longer depends on a Minister's list of approved countries. You may send data to a place with a substantially similar law or adequate protection, or where another condition in section 129 applies, such as the person's consent. The PDPC's cross-border guideline says to tell customers in your notice if you transfer data abroad. If your CRM, email or WhatsApp provider stores data outside Malaysia, ask where.
  • Deceased people are no longer data subjects under the Act.

What a small firm should do now

  1. Write a one-page breach plan: who decides, who contacts the PDPC, who writes to customers, and where the form is. The guideline expects a response plan.
  2. Count the people whose data you hold, including old leads. Compare with the circular's limits, and write down the result and your reasons.
  3. Check your supplier contracts for a promise to report a breach promptly.
  4. Update your privacy notice if data goes abroad, and add the DPO's contact details if you have one.
  5. Check the PDPC site every few months. As of October 2026 it also lists guidelines on impact assessments, data protection by design and automated decision-making, and consulted in 2025 on changes to the 2013 Regulations.

Questions people ask next

Does the amendment apply to a one-person agent?
The Act has no size limit, so the main duties apply. The data protection officer duty depends on the PDPC's conditions about how many people's data you handle, which a very small firm may not reach. Check the current circular and keep a note of your reasons.
Do I have to tell customers about every breach?
No. Under section 12B(2) of the Act and the PDPC guideline, you tell customers when the breach results or is likely to result in significant harm. Keep a record of the incidents you decided not to report, with your reasons.
Who counts as a data processor?
A person other than your employee who handles the data only on your behalf and not for their own purposes, such as a software or cloud supplier. Whether a freelance agent is your processor depends on how they use the data. See the PDPA basics.
How do I tell the PDPC about a breach?
Use the notification form on the PDPC website, or email the Annex B form from the breach guideline to dbnpdp@pdp.gov.my. The report counts once the PDPC sends you a confirmation notice.

Sources

This guide is general information, not legal, tax or financial advice. Rules and bank policies change, so check the current position with the bank, the regulator or a professional before you act.

Talk to us about your team

Tell us how you work. We reply on working days and will not send you a sales script.