Law note · Malaysia

Personal Data Protection Act, data protection officer and breach notification

cite Act 709 (Malaysia) ss.12A-12B, as inserted by Act A1727 s.6, in force 2025-06-01 stage IN FORCE in force since 2025-06-01 kind Breach notification binds private bodies reviewed 2026-08-29

What it requires

  • An app that controls or processes the personal data of individuals in Malaysia must appoint a Data Protection Officer, and a data controller who reasonably believes a personal data breach has occurred must notify the Commissioner as soon as practicable, and must notify affected data subjects without unnecessary delay where the breach causes or is likely to cause significant harm.

When LexLint raises it

  • processes_biometrics
  • processes_voice
  • crawls_web

What we found

Act A1727 s.6 inserts new Division 1A into Part II, requiring both the data controller and data processor to appoint a Data Protection Officer (s.12A) and, at s.12B, requiring the data controller to notify the Commissioner as soon as practicable on reasonable belief that a personal data breach occurred; where the breach causes or is likely to cause significant harm to the data subject, the controller must also notify the data subject without unnecessary delay.

No fixed numeric deadline is set in the statute itself; timing and form are left to the Commissioner's own prescribed manner. Non-compliance with the Commissioner-notification duty is itself an offence, carrying a fine up to RM250,000, imprisonment up to 2 years, or both. Before this amendment, Act 709 had no statutory breach-notification duty at all.

← Back to the example  ·  Lint your app →