Law note · Malaysia
Personal Data Protection Act, enforcement
What it requires
- An app processing the personal data of an individual in Malaysia must be prepared to answer to the Personal Data Protection Commissioner for a Data Protection Principle violation or a breach-notification failure, each carrying criminal exposure of up to 2 years imprisonment; Malaysia's enforcement is Commissioner-driven, with no private right of action found in the sections read.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
- Private right of action
- No
What we found
The Personal Data Protection Commissioner is the supervisory authority. Enforcement is criminal and administrative: contravening any Data Protection Principle is an offence under the base Act's s.5(2) (fine up to RM300,000, imprisonment up to 2 years, or both), which came into force with the rest of the base Act on 15 November 2013, and the new s.12B(3) breach-notification offence, in force since 2025-06-01, carries a fine up to RM250,000, imprisonment up to 2 years, or both.
No private right of action provision was located in the sections read this pass; enforcement is Commissioner-driven and criminal, not a statutory civil cause of action for the data subject, though the search was not exhaustive across the full base Act text.