Law note · Malaysia

Personal Data Protection Act, biometric data definition and sensitive category

cite Act 709 (Malaysia) s.4, as amended by Act A1727 s.3, in force 2025-04-01 stage IN FORCE in force since 2025-04-01 kind Biometric privacy binds private bodies reviewed 2026-08-29

What it requires

  • An app that collects or processes a faceprint, voiceprint, or other biometric identifier from an individual in Malaysia, including one derived from technical processing of a photo, video, or audio recording, must obtain the data subject's explicit consent under Act 709's sensitive personal data standard.

When LexLint raises it

  • processes_biometrics
  • processes_voice
  • trains_models
  • crawls_web
Excludes recording-derived identifiers
No

What we found

Act A1727 s.3 inserted a dedicated biometric data definition into s.4 (any personal data resulting from technical processing relating to a person's physical, physiological, or behavioural characteristics) and added biometric data to the sensitive personal data list immediately after the offence-related category.

Both a faceprint and a voiceprint fall squarely within physical, physiological, or behavioural characteristics resulting from technical processing, which is exactly how a voice or face embedding is produced. Both are now, in force, sensitive personal data under s.4, requiring explicit consent under s.40's stricter processing conditions. No biometric-specific retention or destruction duty distinct from the Act's general data-minimisation and accuracy principles was found.

← Back to the example  ·  Lint your app →