Data and PDPA

When an agent leaves: protect your leads and customer data

When an agent leaves, the PDPC's security standard says to end their access to personal data and cancel their user ID and password immediately. Your firm stays responsible for customers' data while the person works for it, and a leaver who collects or discloses data your firm holds, without your consent, may be committing an offence under section 130 of the PDPA, with a fine of up to RM 500,000 or three years in prison, or both. Most of the protection comes from set-up done months earlier: one place for leads, access by role, and no customer data that lives only on someone's personal phone.

By the NexFlows team · Published 18 May 2026 · Facts last checked 4 October 2026 · 6 min read

Whose data it is, and who answers for it

Customers' details are personal data about them. Your firm, as data controller, is responsible for how they are held and used. An employee is not a data processor under the Act, and the Act makes a person liable for the acts of their employees in the course of their work, and of an agent acting on their behalf. While someone works for you, you answer for what they do with the data.

Freelance agents are the harder case. The Act defines a processor as someone other than an employee who handles data solely on your behalf and not for their own purposes. A freelancer who also uses leads for their own business may be a controller in their own right. Write down, before access is given, what the agent may use the data for, that it stays in your system, and what happens when they leave. Ask a lawyer to check the wording.

Keep a note of where each lead came from. An agent who brought contacts with them before joining you will argue those are theirs, and a record of the source is the quickest way to settle it.

What the rules say about leavers

  • Access. The PDPC's security standard says to end an employee's access rights to personal data after resignation, dismissal or the end of a contract, and to cancel their user ID and password immediately once they no longer handle the data.
  • Records. The same standard says to keep a proper record of who accessed personal data, and to produce it when the PDPC asks.
  • Confidentiality. Staff involved in processing must keep customers' data confidential.
  • People you trust. The Security Principle asks you to consider the reliability, integrity and competence of the people who have access.
  • Taking data. Section 130 says a person must not knowingly or recklessly, without the consent of the data controller, collect or disclose personal data the controller holds, or arrange for it to be disclosed to someone else. The maximum is RM 500,000 or three years in prison, or both. There are defences, for example a reasonable belief that the person had a legal right, and no prosecution can start without the written consent of the Public Prosecutor.

One of the PDPC's own examples of a personal data breach is an employee with authorised access to sensitive personal data who deliberately takes customer information and sells it to a third party. A leaver who walks out with the lead list may therefore start the breach clock for your firm. See the 2024 amendment guide.

Contract terms are a separate question from the PDPA. A signed confidentiality and data-use agreement can be enforced. A clause that stops a former agent working for a competitor is likely to be void under section 28 of the Contracts Act 1950, and whether a clause against approaching your customers survives is unclear. Ask a lawyer before you rely on any of them, and see the PDPA point above.

Set up so that a departure is boring

Do these before anyone resigns. They cost little and they decide how bad the day is.

  • One system for leads and cases. No customer lists in personal spreadsheets or phone contacts. If it is not in the system, it is not yours to find later.
  • Access by role. An agent sees only their own leads. The boss sees everything. In the Loan Advisory CRM that is how the roles work (boss, team leader, sales, sales admin and freelance agent): everyone sees only their part, and an activity log shows who did what.
  • Limits on exporting. Ask whether ordinary users can download the whole list. If they can, change it.
  • A company WhatsApp number. When customers talk to agents on personal numbers, the conversation leaves with the person. A WhatsApp Business number registered to the company, which is part of our setup, keeps it with the firm.
  • Written terms from day one. Confidentiality, use of data only for the firm's work, and return or deletion on leaving. Have each person sign that they have read them.
  • An access record. The PDPC's standard asks for a record of who accessed personal data. Find out what each system actually records, and whether it is enough for that access record.

The day someone leaves

A leaver's timeline. The legal anchor is that access must end immediately once the person no longer handles the data. The other steps are good practice.
  1. Agree the last day and who takes over

    Name the person who inherits each open case. If you wait until the last afternoon, customers fall through the gap.

  2. Narrow access from the day notice is given

    Whether to cut access at once or at the end of the notice period is a judgement call. At the least, limit the person to the cases they are handing over.

  3. Switch off every login on the last day, before they leave

    The CRM, work email, shared folders, chat groups, any shared WhatsApp Web session, and any password the whole team uses. Change those shared passwords.

  4. Move open leads and cases to named people

    Do it in the system, so the history stays with the case and nothing is left in the leaver's name.

  5. Collect devices and paper files, and write down what came back

    Laptops, phones you issued, printed application files and keys.

  6. Check what your systems recorded in the weeks before they left

    Ask what each one keeps, such as an activity log of who did what, and what you have for email and shared drives. Look for anything unusual. Do not delete anything while you look.

  7. Tell the affected customers who now handles their case

    A short message from the new person. It keeps customers and shows you are in control of their data.

If you think data was taken

Treat it as a possible personal data breach from the moment you are told or confirm it. The PDPC's guideline words the 72 hours as running from the breach itself, so act at once and do not wait to be sure. Keep the logs and messages as they are, because they may be your evidence. List which customers and which kinds of data are involved, such as IC numbers and credit reports, and decide whether significant harm is likely.

The breach guideline notes that a breach involving criminal activity may also need to be reported to the police. Speak to a lawyer before you send a warning letter or file a report, so that what you say matches what you can show.

Questions people ask next

Can I stop a former agent contacting my customers?
Possibly. A signed confidentiality and data-use agreement can be enforced, and the PDPA may apply if they took data without your consent. A clause that stops them working for a competitor is likely to be void under section 28 of the Contracts Act 1950. Ask a lawyer before you rely on any clause.
Is a freelance agent an employee for PDPA purposes?
It depends. The Act does not define employee. A genuine freelancer who uses the data only for you looks like a processor. If they also use it for their own business they may be a controller. Set it out in a written agreement.
Should I delete the leaver's chats and files straight away?
No. If you suspect a problem, keep them as they are until you have looked and taken advice. Delete later under your retention schedule. See how long to keep customer records.

Sources

This guide is general information, not legal, tax or financial advice. Rules and bank policies change, so check the current position with the bank, the regulator or a professional before you act.

See the Loan Advisory CRM

Leads, calling, credit reports, team and commission in one place, for RM 1,000 a month for 20 users.