Whose data it is, and who answers for it
Customers' details are personal data about them. Your firm, as data controller, is responsible for how they are held and used. An employee is not a data processor under the Act, and the Act makes a person liable for the acts of their employees in the course of their work, and of an agent acting on their behalf. While someone works for you, you answer for what they do with the data.
Freelance agents are the harder case. The Act defines a processor as someone other than an employee who handles data solely on your behalf and not for their own purposes. A freelancer who also uses leads for their own business may be a controller in their own right. Write down, before access is given, what the agent may use the data for, that it stays in your system, and what happens when they leave. Ask a lawyer to check the wording.
Keep a note of where each lead came from. An agent who brought contacts with them before joining you will argue those are theirs, and a record of the source is the quickest way to settle it.
What the rules say about leavers
- Access. The PDPC's security standard says to end an employee's access rights to personal data after resignation, dismissal or the end of a contract, and to cancel their user ID and password immediately once they no longer handle the data.
- Records. The same standard says to keep a proper record of who accessed personal data, and to produce it when the PDPC asks.
- Confidentiality. Staff involved in processing must keep customers' data confidential.
- People you trust. The Security Principle asks you to consider the reliability, integrity and competence of the people who have access.
- Taking data. Section 130 says a person must not knowingly or recklessly, without the consent of the data controller, collect or disclose personal data the controller holds, or arrange for it to be disclosed to someone else. The maximum is RM 500,000 or three years in prison, or both. There are defences, for example a reasonable belief that the person had a legal right, and no prosecution can start without the written consent of the Public Prosecutor.
One of the PDPC's own examples of a personal data breach is an employee with authorised access to sensitive personal data who deliberately takes customer information and sells it to a third party. A leaver who walks out with the lead list may therefore start the breach clock for your firm. See the 2024 amendment guide.
Contract terms are a separate question from the PDPA. A signed confidentiality and data-use agreement can be enforced. A clause that stops a former agent working for a competitor is likely to be void under section 28 of the Contracts Act 1950, and whether a clause against approaching your customers survives is unclear. Ask a lawyer before you rely on any of them, and see the PDPA point above.
Set up so that a departure is boring
Do these before anyone resigns. They cost little and they decide how bad the day is.
- One system for leads and cases. No customer lists in personal spreadsheets or phone contacts. If it is not in the system, it is not yours to find later.
- Access by role. An agent sees only their own leads. The boss sees everything. In the Loan Advisory CRM that is how the roles work (boss, team leader, sales, sales admin and freelance agent): everyone sees only their part, and an activity log shows who did what.
- Limits on exporting. Ask whether ordinary users can download the whole list. If they can, change it.
- A company WhatsApp number. When customers talk to agents on personal numbers, the conversation leaves with the person. A WhatsApp Business number registered to the company, which is part of our setup, keeps it with the firm.
- Written terms from day one. Confidentiality, use of data only for the firm's work, and return or deletion on leaving. Have each person sign that they have read them.
- An access record. The PDPC's standard asks for a record of who accessed personal data. Find out what each system actually records, and whether it is enough for that access record.
The day someone leaves
Months before
- One system for leads and cases
- Access by role
- Written terms signed
- Know what your system records
Notice given
- Name who takes each open case
- Limit access to the handover
- Agree the last day
Last day
Access must end now
- Switch off every login before they leave
- Change shared passwords
- Collect devices and papers
Days after
- Check what your systems recorded
- Tell customers who handles their case
- If data was taken, the 72-hour limit may already be running: act as soon as you find out
Agree the last day and who takes over
Name the person who inherits each open case. If you wait until the last afternoon, customers fall through the gap.
Narrow access from the day notice is given
Whether to cut access at once or at the end of the notice period is a judgement call. At the least, limit the person to the cases they are handing over.
Switch off every login on the last day, before they leave
The CRM, work email, shared folders, chat groups, any shared WhatsApp Web session, and any password the whole team uses. Change those shared passwords.
Move open leads and cases to named people
Do it in the system, so the history stays with the case and nothing is left in the leaver's name.
Collect devices and paper files, and write down what came back
Laptops, phones you issued, printed application files and keys.
Check what your systems recorded in the weeks before they left
Ask what each one keeps, such as an activity log of who did what, and what you have for email and shared drives. Look for anything unusual. Do not delete anything while you look.
Tell the affected customers who now handles their case
A short message from the new person. It keeps customers and shows you are in control of their data.
If you think data was taken
Treat it as a possible personal data breach from the moment you are told or confirm it. The PDPC's guideline words the 72 hours as running from the breach itself, so act at once and do not wait to be sure. Keep the logs and messages as they are, because they may be your evidence. List which customers and which kinds of data are involved, such as IC numbers and credit reports, and decide whether significant harm is likely.
The breach guideline notes that a breach involving criminal activity may also need to be reported to the police. Speak to a lawyer before you send a warning letter or file a report, so that what you say matches what you can show.
Questions people ask next
- Can I stop a former agent contacting my customers?
- Possibly. A signed confidentiality and data-use agreement can be enforced, and the PDPA may apply if they took data without your consent. A clause that stops them working for a competitor is likely to be void under section 28 of the Contracts Act 1950. Ask a lawyer before you rely on any clause.
- Is a freelance agent an employee for PDPA purposes?
- It depends. The Act does not define employee. A genuine freelancer who uses the data only for you looks like a processor. If they also use it for their own business they may be a controller. Set it out in a written agreement.
- Should I delete the leaver's chats and files straight away?
- No. If you suspect a problem, keep them as they are until you have looked and taken advice. Delete later under your retention schedule. See how long to keep customer records.
Sources
- Personal Data Protection Standard 2015, security and retention standards (PDPC, PDF)
- Personal Data Protection Act 2010 [Act 709], text before the 2024 amendment (PDPC, PDF)
- Personal Data Protection Guideline: Data Breach Notification, 25 February 2025 (PDPC, PDF)
- Commissioner's Circular on data breach notification, in Malay (No. 2/2025 on the PDF itself; the PDPC web page lists it as No. 1/2025) (PDPC, PDF)
- Personal Data Protection (Amendment) Act 2024 [Act A1727] (PDPC, PDF)
- Thomas Philip Advocates and Solicitors: enforceability of non-compete clauses in employment contracts, section 28 Contracts Act 1950 (25 October 2023)
This guide is general information, not legal, tax or financial advice. Rules and bank policies change, so check the current position with the bank, the regulator or a professional before you act.