Does the PDPA apply to a small loan agency?
Yes. The Act applies to any person who processes personal data, or who controls or authorises the processing of it, in respect of commercial transactions. The Act's own definition of a commercial transaction includes financing, banking, insurance and agency. Loan advisory sits inside that. The text of the Act has no size limit, so a one-person agent has the same duties as a large firm.
Since the 2024 amendment, the Act calls the firm that decides how data is used the data controller. It used to say data user. A supplier that handles data only on your behalf, such as a CRM or cloud provider, is a data processor. The PDPC's security standard expects you to bind a processor by contract, and since 1 April 2025 the processor has its own duty to keep the data secure.
If you work with freelance agents, who counts as controller and who as processor depends on the facts. An agent who uses your leads only on your instructions looks like your processor. An agent who also uses the data for their own business may be a controller in their own right. Put the arrangement in writing and ask a lawyer, because the answer decides who is responsible when something goes wrong.
Some kinds of business must also register with the PDPC. The classes are listed in an Order and include licensed banks, licensed insurers and moneylenders licensed under the Moneylenders Act 1951. If your firm is not in a listed class, the Act says you do not have to register, but every other part of it still applies. Check the current list on the PDPC site. The PDPC's circular in force from 1 June 2026 explains the process for those who must register.
What counts as personal data in a loan office
Personal data is information about a person who can be identified from it, held on a computer or in a paper file that is organised so that one person's details are easy to find. In your work that covers more than the obvious:
- Names and phone numbers on a lead list, including old and bought lists.
- IC numbers and IC copies.
- Payslips, EPF statements, bank statements and loan application forms.
- WhatsApp chats and call recordings in which a customer can be identified.
- Credit reports you hold for a customer.
Credit reports need one note. The Act does not cover information that a credit reporting agency such as CTOS or Experian processes for its own credit reporting business, because the Credit Reporting Agencies Act 2010 governs that. A copy of the report sitting in your office is different. You are holding it in a financing transaction, so the PDPA applies to how you handle it. If your situation is unusual, ask a lawyer where the line falls.
A smaller group is sensitive personal data: information about a person's health, political opinions, religious beliefs, or actual or alleged offences, and, since 1 April 2025, biometric data. A medical bill handed over as proof of expenses is health information. Sensitive data needs the person's explicit consent unless a listed exception applies.
The seven principles in loan office terms
Step 1
A lead comes in
GeneralNotice and choice
Ask for consent and give the notice, in Malay and English.
Step 2
You work the case
Data integrity
Keep details correct, in one place.
Step 3
You share with a bank
Disclosure
Only the parties you told the customer about.
Step 4
You store the file
Security
Named logins, limited access, locked papers.
Step 5
The case ends
Retention
Delete it when you no longer need it.
At any step the customer can ask to see their data, correct it, withdraw consent or stop marketing. You have 21 days to answer a request to see or correct data.
| Principle | What the Act asks | In a loan office |
|---|---|---|
| General | Process data only with the person's consent or under a listed exception, for a lawful purpose connected to your activity, and only data that is adequate but not excessive. | Ask before you add someone to a follow-up list. Do not collect a document the application does not need. |
| Notice and choice | Tell the person in writing, in Malay and English, what you hold, why, where you got it, who you may share it with, and how to ask to see or correct it. | A short privacy notice on your lead form, WhatsApp opt-in and application form. Name the classes of third party, for example banks. |
| Disclosure | Do not disclose data for another purpose, or to a party outside the classes you named, without consent. | Send a file to the banks you told the customer about. Do not pass the lead to an unrelated firm. |
| Security | Take practical steps against loss, misuse and unauthorised access or disclosure. | Named logins, limited access, locked cabinets. See keeping credit reports and IC copies safe. |
| Retention | Do not keep data longer than needed, and delete it when it is no longer required. | A delete-or-keep schedule. See how long to keep customer records. |
| Data integrity | Take reasonable steps to keep data accurate, complete and up to date. | Fix a wrong phone number or income figure when you learn of it. Avoid several conflicting copies. |
| Access | Let people see their data and correct it. | A named person and a simple way to take requests. |
The exceptions to consent are narrow. They do not obviously cover sending marketing messages or passing a lead to someone else. If you rely on an exception, write down which one and why, and ask a lawyer.
Keep proof of consent. The Regulations say consent must be taken in a form that can be recorded and kept, and that the burden of proving it lies on you. If the consent sits inside a form about something else, it must stand out from the rest of the text.
What customers can ask you to do
| Request | What you must do | Time |
|---|---|---|
| See their data | Tell them whether you hold it and give a copy in a form they can read. You may refuse in listed cases, for example if you cannot confirm who is asking. The request is in writing and a prescribed fee may be charged. | 21 days from receiving the request. If you cannot, tell them in writing before the 21 days end, do what you can, and finish within a further 14 days. |
| Correct their data | Fix data that is inaccurate, incomplete, misleading or out of date, and send a copy of the corrected data. If you passed it to a third party in the last 12 months, take practical steps to send the correction on. | 21 days from receiving the request. |
| Withdraw consent | Stop processing their data. The Act counts holding and storing as processing, so on a plain reading that includes keeping it. If you think another law makes you keep a record, ask a lawyer. Ignoring a written withdrawal is an offence. | On receiving the written notice. |
| Stop direct marketing | Stop sending advertising or marketing material directed at them. A WhatsApp promotion to an individual can count. | After a reasonable period. |
| Send their data elsewhere | Since 1 June 2025, transmit their data to another data controller they choose, if it is technically feasible and the format is compatible. | The Act leaves the time limit to be prescribed. We did not find one set as of October 2026. |
What it costs to get it wrong
Breaking any of the seven principles is an offence. Until 1 April 2025 the maximum was RM 300,000 or two years in prison, or both. It is now RM 1,000,000 or three years, or both. Other offences carry their own limits, for example up to RM 100,000 or one year for ignoring a written withdrawal of consent.
Responsibility does not stop at the company. If a company commits an offence, its directors, managers and others involved in running it can be charged too. They are treated as guilty unless they prove the offence happened without their knowledge, consent or connivance, and that they took all reasonable precautions and exercised due diligence. A firm is also answerable for what its employees and agents do in the course of their work.
A sensible first month for a small firm
- Write one short privacy notice in Malay and English, and put it wherever you collect details: the lead form, the WhatsApp opt-in, the application form.
- Record consent where you can find it again, in your system or on a signed form.
- List who you share customer data with, such as banks, valuers and referral partners. The Regulations require you to keep this list.
- Write a short security policy that follows the PDPC's standard. The Regulations require one.
- Set a retention schedule, so old leads and closed files are reviewed and deleted on purpose.
- Name the person who takes customer requests and who handles a breach, and check whether you must appoint a data protection officer. See the 2024 PDPA amendment.
Questions people ask next
- Do I need a data protection officer?
- Possibly. The PDPC sets conditions based on how many people's data you handle and what kind, and the answer depends on your facts. Read the 2024 PDPA amendment guide, then confirm with the PDPC or a lawyer.
- Can I keep following up a customer after the loan is declined?
- Only for the purpose you told them about, and only while you still need the data. If they tell you in writing to stop marketing, you must stop after a reasonable period. Check what the customer agreed to at the start.
- Does the PDPA cover paper files?
- Yes, if the papers are organised so that one person's details are easy to find. The Act calls this a relevant filing system. Anything held on a computer or phone is covered as well.
- Is this a substitute for legal advice?
- No. This guide explains how the Act works in a loan office. How it applies to your firm depends on your facts, so check with the PDPC or a lawyer before you rely on any point.
Sources
- Personal Data Protection Act 2010 [Act 709], text before the 2024 amendment (PDPC, PDF)
- Personal Data Protection (Amendment) Act 2024 [Act A1727] (PDPC, PDF)
- Personal Data Protection Regulations 2013 [P.U. (A) 335/2013] (PDPC page, links the PDF)
- Personal Data Protection (Class of Data Users) Order 2013 [P.U. (A) 336/2013] (PDPC, PDF)
- Class of Data Users (Amendment) Order 2016 [P.U. (A) 326/2016] (PDPC, PDF)
- Commissioner's Circular No. 1/2026, registration of data controllers, in force 1 June 2026 (PDPC, PDF)
- Personal Data Protection Standard 2015, security and retention standards (PDPC, PDF)
This guide is general information, not legal, tax or financial advice. Rules and bank policies change, so check the current position with the bank, the regulator or a professional before you act.