Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Biometric privacy
What it requires →
Act A1727 s.3 inserted a dedicated biometric data definition into s.4 (any personal data resulting from technical processing relating to a person's physical, physiological, or behavioural characteristics) and added biometric data to the sensitive personal data list immediately after the offence-related category.
Both a faceprint and a voiceprint fall squarely within physical, physiological, or behavioural characteristics resulting from technical processing, which is exactly how a voice or face embedding is produced. Both are now, in force, sensitive personal data under s.4, requiring explicit consent under s.40's stricter processing conditions. No biometric-specific retention or destruction duty distinct from the Act's general data-minimisation and accuracy principles was found.
Breach notification
What it requires →
Act A1727 s.6 inserts new Division 1A into Part II, requiring both the data controller and data processor to appoint a Data Protection Officer (s.12A) and, at s.12B, requiring the data controller to notify the Commissioner as soon as practicable on reasonable belief that a personal data breach occurred; where the breach causes or is likely to cause significant harm to the data subject, the controller must also notify the data subject without unnecessary delay.
No fixed numeric deadline is set in the statute itself; timing and form are left to the Commissioner's own prescribed manner. Non-compliance with the Commissioner-notification duty is itself an offence, carrying a fine up to RM250,000, imprisonment up to 2 years, or both. Before this amendment, Act 709 had no statutory breach-notification duty at all.
Comprehensive regime
What it requires →
Act 709's lawful basis is a bifurcated consent model: ordinary personal data needs the data subject's consent, subject to contract, legal-obligation, and vital-interest exceptions (s.6), while sensitive personal data needs explicit consent under s.40's stricter conditions. Contravening any of the seven Data Protection Principles is itself an offence, carrying a fine up to RM300,000, imprisonment up to 2 years, or both (s.5(2)).
Act A1727 relabels data user as data controller throughout and, for the first time, imposes direct statutory duties on data processors, who were previously reached only through contract with the data user.
Section 1(2) leaves the base Act's own commencement to a Ministerial gazette notification rather than stating a date in the Act's own text; the Department of Personal Data Protection's own published determination fixes that date at 15 November 2013, and that is recorded here as the general commencement date, distinct from the 2024 amendment's own staged commencement dates recorded on this document's other instruments.
Cross border transfer
What it requires →
The original s.129 barred transferring personal data outside Malaysia except to a place the Minister specified by gazette notification as having a substantially similar law or an adequate level of protection; in practice this whitelist mechanism was never gazetted, making the provision largely inoperative.
Act A1727 s.12 restructures s.129, replacing the Minister's gazetting power with the data controller's own self-assessment against the substantially similar law or adequate level of protection standard, and drops the alternative or that serves the same purposes as this Act language, narrowing the standard. There is no data-localization mandate.
Data subject rights
What it requires →
Act A1727 s.9 added s.43A, giving a data subject the right to request the data controller transmit their personal data to another data controller of the subject's choice by written electronic notice, subject to technical feasibility and compatibility of the data format. The controller must complete the transmission within the period as may be prescribed, with no fixed statutory deadline; the specific period is left to subsidiary regulation not read this pass.
Enforcement supervision
cite Act 709 (Malaysia) ss.5(2), 12B(3)
stage IN FORCE in force since 2013-11-15
effective 2025-06-01
binds private bodies
source official statute and Act A1727 amendment text, Department of Personal Data Protection (pdp.gov.my)
What it requires →
The Personal Data Protection Commissioner is the supervisory authority. Enforcement is criminal and administrative: contravening any Data Protection Principle is an offence under the base Act's s.5(2) (fine up to RM300,000, imprisonment up to 2 years, or both), which came into force with the rest of the base Act on 15 November 2013, and the new s.12B(3) breach-notification offence, in force since 2025-06-01, carries a fine up to RM250,000, imprisonment up to 2 years, or both.
No private right of action provision was located in the sections read this pass; enforcement is Commissioner-driven and criminal, not a statutory civil cause of action for the data subject, though the search was not exhaustive across the full base Act text.