Law note · Malaysia
Personal Data Protection Act, comprehensive regime and lawful bases
What it requires
- An app that collects, uses, or discloses the personal data of an individual in Malaysia must obtain consent, subject to the contract, legal-obligation, or vital-interest exceptions, and processing sensitive personal data needs the data subject's explicit consent under the Act's stricter standard.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
What we found
Act 709's lawful basis is a bifurcated consent model: ordinary personal data needs the data subject's consent, subject to contract, legal-obligation, and vital-interest exceptions (s.6), while sensitive personal data needs explicit consent under s.40's stricter conditions. Contravening any of the seven Data Protection Principles is itself an offence, carrying a fine up to RM300,000, imprisonment up to 2 years, or both (s.5(2)).
Act A1727 relabels data user as data controller throughout and, for the first time, imposes direct statutory duties on data processors, who were previously reached only through contract with the data user.
Section 1(2) leaves the base Act's own commencement to a Ministerial gazette notification rather than stating a date in the Act's own text; the Department of Personal Data Protection's own published determination fixes that date at 15 November 2013, and that is recorded here as the general commencement date, distinct from the 2024 amendment's own staged commencement dates recorded on this document's other instruments.