Law note · Malaysia

Personal Data Protection Act, enforcement

cite Act 709 (Malaysia) ss.5(2), 12B(3) stage IN FORCE in force since 2013-11-15 effective 2025-06-01 kind Enforcement supervision binds private bodies reviewed 2026-08-30

What it requires

  • An app processing the personal data of an individual in Malaysia must be prepared to answer to the Personal Data Protection Commissioner for a Data Protection Principle violation or a breach-notification failure, each carrying criminal exposure of up to 2 years imprisonment; Malaysia's enforcement is Commissioner-driven, with no private right of action found in the sections read.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
Private right of action
No

What we found

The Personal Data Protection Commissioner is the supervisory authority. Enforcement is criminal and administrative: contravening any Data Protection Principle is an offence under the base Act's s.5(2) (fine up to RM300,000, imprisonment up to 2 years, or both), which came into force with the rest of the base Act on 15 November 2013, and the new s.12B(3) breach-notification offence, in force since 2025-06-01, carries a fine up to RM250,000, imprisonment up to 2 years, or both.

No private right of action provision was located in the sections read this pass; enforcement is Commissioner-driven and criminal, not a statutory civil cause of action for the data subject, though the search was not exhaustive across the full base Act text.

← Back to the example  ·  Lint your app →