Law / Malaysia

Malaysia

privacy

Malaysia's comprehensive private-sector data-protection law is the Personal Data Protection Act 2010 (Act 709), substantially amended by the Personal Data Protection (Amendment) Act 2024 (Act A1727), in force on a staged commencement schedule set by Ministerial gazette notification.

Act A1727 s.3, in force since 2025-04-01, added a dedicated biometric data definition (technical processing relating to physical, physiological, or behavioural characteristics) directly to the sensitive personal data list, reaching both a faceprint and a voiceprint since either is produced by exactly that kind of technical processing.

Act A1727 also relabels data user as data controller, imposes direct statutory duties on data processors for the first time, replaces the never-exercised Ministerial cross-border whitelist with controller self-assessed adequacy (s.129, in force since 2025-04-01), and adds a mandatory Data Protection Officer duty and data breach notification duty (ss.12A-12B, in force since 2025-06-01) and a data portability right (s.43A, in force since 2025-06-01).

The two confirmed working PDF source URLs are hosted at pdp.gov.my; the derived candidate's own URL now 200s to the Department of Personal Data Protection's unrelated redesigned homepage rather than the Act text.

13 instruments named 6 researched in detail As of 2026-08-29

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Biometric privacy

Personal Data Protection Act, biometric data definition and sensitive category

cite Act 709 (Malaysia) s.4, as amended by Act A1727 s.3, in force 2025-04-01 stage IN FORCE in force since 2025-04-01 binds private bodies source official Act A1727 amendment text, Department of Personal Data Protection (pdp.gov.my)
What it requires

Act A1727 s.3 inserted a dedicated biometric data definition into s.4 (any personal data resulting from technical processing relating to a person's physical, physiological, or behavioural characteristics) and added biometric data to the sensitive personal data list immediately after the offence-related category.

Both a faceprint and a voiceprint fall squarely within physical, physiological, or behavioural characteristics resulting from technical processing, which is exactly how a voice or face embedding is produced. Both are now, in force, sensitive personal data under s.4, requiring explicit consent under s.40's stricter processing conditions. No biometric-specific retention or destruction duty distinct from the Act's general data-minimisation and accuracy principles was found.

Breach notification

Personal Data Protection Act, data protection officer and breach notification

cite Act 709 (Malaysia) ss.12A-12B, as inserted by Act A1727 s.6, in force 2025-06-01 stage IN FORCE in force since 2025-06-01 binds private bodies source official Act A1727 amendment text, Department of Personal Data Protection (pdp.gov.my)
What it requires

Act A1727 s.6 inserts new Division 1A into Part II, requiring both the data controller and data processor to appoint a Data Protection Officer (s.12A) and, at s.12B, requiring the data controller to notify the Commissioner as soon as practicable on reasonable belief that a personal data breach occurred; where the breach causes or is likely to cause significant harm to the data subject, the controller must also notify the data subject without unnecessary delay.

No fixed numeric deadline is set in the statute itself; timing and form are left to the Commissioner's own prescribed manner. Non-compliance with the Commissioner-notification duty is itself an offence, carrying a fine up to RM250,000, imprisonment up to 2 years, or both. Before this amendment, Act 709 had no statutory breach-notification duty at all.

Comprehensive regime

Personal Data Protection Act, comprehensive regime and lawful bases

cite Act 709 (Malaysia), as amended by the Personal Data Protection (Amendment) Act 2024, Act A1727 stage IN FORCE in force since 2013-11-15 binds private bodies source official statute text, Department of Personal Data Protection (pdp.gov.my)
What it requires

Act 709's lawful basis is a bifurcated consent model: ordinary personal data needs the data subject's consent, subject to contract, legal-obligation, and vital-interest exceptions (s.6), while sensitive personal data needs explicit consent under s.40's stricter conditions. Contravening any of the seven Data Protection Principles is itself an offence, carrying a fine up to RM300,000, imprisonment up to 2 years, or both (s.5(2)).

Act A1727 relabels data user as data controller throughout and, for the first time, imposes direct statutory duties on data processors, who were previously reached only through contract with the data user.

Section 1(2) leaves the base Act's own commencement to a Ministerial gazette notification rather than stating a date in the Act's own text; the Department of Personal Data Protection's own published determination fixes that date at 15 November 2013, and that is recorded here as the general commencement date, distinct from the 2024 amendment's own staged commencement dates recorded on this document's other instruments.

Cross border transfer

Personal Data Protection Act, cross-border transfer

cite Act 709 (Malaysia) s.129, as amended by Act A1727 s.12, in force 2025-04-01 stage IN FORCE in force since 2025-04-01 binds private bodies source official statute and Act A1727 amendment text, Department of Personal Data Protection (pdp.gov.my)
What it requires

The original s.129 barred transferring personal data outside Malaysia except to a place the Minister specified by gazette notification as having a substantially similar law or an adequate level of protection; in practice this whitelist mechanism was never gazetted, making the provision largely inoperative.

Act A1727 s.12 restructures s.129, replacing the Minister's gazetting power with the data controller's own self-assessment against the substantially similar law or adequate level of protection standard, and drops the alternative or that serves the same purposes as this Act language, narrowing the standard. There is no data-localization mandate.

Data subject rights

Personal Data Protection Act, data portability

cite Act 709 (Malaysia) s.43A, as inserted by Act A1727 s.9, in force 2025-06-01 stage IN FORCE in force since 2025-06-01 binds private bodies source official Act A1727 amendment text, Department of Personal Data Protection (pdp.gov.my)
What it requires

Act A1727 s.9 added s.43A, giving a data subject the right to request the data controller transmit their personal data to another data controller of the subject's choice by written electronic notice, subject to technical feasibility and compatibility of the data format. The controller must complete the transmission within the period as may be prescribed, with no fixed statutory deadline; the specific period is left to subsidiary regulation not read this pass.

Enforcement supervision

Personal Data Protection Act, enforcement

cite Act 709 (Malaysia) ss.5(2), 12B(3) stage IN FORCE in force since 2013-11-15 effective 2025-06-01 binds private bodies source official statute and Act A1727 amendment text, Department of Personal Data Protection (pdp.gov.my)
What it requires

The Personal Data Protection Commissioner is the supervisory authority. Enforcement is criminal and administrative: contravening any Data Protection Principle is an offence under the base Act's s.5(2) (fine up to RM300,000, imprisonment up to 2 years, or both), which came into force with the rest of the base Act on 15 November 2013, and the new s.12B(3) breach-notification offence, in force since 2025-06-01, carries a fine up to RM250,000, imprisonment up to 2 years, or both.

No private right of action provision was located in the sections read this pass; enforcement is Commissioner-driven and criminal, not a statutory civil cause of action for the data subject, though the search was not exhaustive across the full base Act text.

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.