Malaysia's Personal Data Protection Act 2010 (PDPA) was materially amended in 2024. For marketing teams, the change is not cosmetic: consent, purpose limitation, processor accountability, breach notification, data protection officer (DPO) obligations, and cross-border transfer rules all now operate with more teeth and more supervision. This playbook is what a competent marketing operations lead needs to understand and to operationalise — with the correct instruments cited so you can verify each rule against the source.
The legal landscape at a glance
| Act 709 — PDPA 2010 | Principal statute setting out the seven principles, rights, and offences | Official page |
| Act A1727 — PDP (Amendment) Act 2024 | Amends Act 709. Comes into force on dates gazetted by the Minister | Official page |
| Commencement determination | Ministerial determination of commencement dates for provisions of Act A1727 | Determination PDF |
| DPO circular / guideline | Commissioner's circular and guideline on appointment of a Data Protection Officer | Circular |
| Data Breach Notification (DBN) guideline | Commissioner's guidelines on breach notification | Guideline |
| Cross-Border Personal Data Transfer (CBPDT) | Commissioner's guideline on cross-border transfer | Guideline |
| Data Protection by Design (DPbD) | Commissioner's guideline promoting privacy-by-design | Guideline |
| Application & non-application | Explains who and what the Act covers | Page |
Where this article does not quote an exact threshold, timeline, penalty or category, it is because that detail sits in one of the linked instruments and is subject to update. Read the source before relying on a number.
Applicability
The PDPA applies to the processing of personal data in respect of commercial transactions in Malaysia. The Commissioner publishes clarifications on application and non-application (including federal and state governments, and certain categories of processing). Refer to the application and non-application page. Marketing activities that involve personal data of customers, prospects, and B2B contacts in Malaysia will almost always fall within scope.
The seven principles
The Act's substantive rules cluster around seven principles. Marketing operations must be able to demonstrate compliance with each.
1. General Principle
Lawful basis and consent for processing.
2. Notice & Choice
Clear notice of purposes, sources, disclosures and rights at the point of collection.
3. Disclosure
Disclosure only for the stated purpose or a directly related one.
4. Security
Practical steps to protect data from loss, misuse, modification and unauthorised access.
5. Retention
Keep only as long as necessary for the stated purpose.
6. Data Integrity
Accurate, complete, not misleading, and kept up to date.
7. Access
Individuals have rights to access and correct their data.
What Act A1727 (2024) changes
The amending Act introduces or strengthens, among other things, a formal data breach notification regime, a Data Protection Officer obligation for certain data users, data portability, and adjusts cross-border transfer mechanics and processor accountability. The exact scope, thresholds and commencement dates are set out in the amending Act itself and in the Commissioner's circulars and guidelines. Provisions come into force on dates appointed by the Minister; different provisions may commence at different times per the commencement determination.
Data Protection Officer (DPO)
Under the amended framework and the Commissioner's DPO circular/guideline, certain data users are required to appoint a DPO. The Commissioner's document specifies the criteria (including business categories and thresholds), the DPO's functions, and reporting obligations. Read the DPO circular in full — do not rely on a summary.
Statutory duty
Appointment where the criteria in the DPO circular apply. Registration and contact particulars submitted per the Commissioner's process.
Recommended practice
Appointing a DPO or equivalent even where not strictly mandated, if the volume or sensitivity of processing warrants it.
Data breach notification
The 2024 amendments and the Commissioner's DBN guideline establish an obligation to notify the Commissioner (and in certain cases affected data subjects) when a personal data breach meets defined thresholds. The specific timeframes, forms and criteria are set in the guideline; check the current version before relying on any number.
Detect
Security or ops function detects a potential breach.
Contain & assess
Contain the incident; assess whether it meets notification thresholds under the DBN guideline.
Notify Commissioner
Within the timeframe and using the process specified in the DBN guideline.
Notify data subjects (if applicable)
Where the guideline requires, in clear language.
Remediate & record
Root cause fix, register update, learnings distributed.
Data portability
The amending Act introduces a right of data portability for individuals, subject to conditions and limits described in the Act and any implementing guidelines. Marketing systems should be able to export a data subject's personal data in a structured, commonly used, machine-readable format on request — factor this into your CDP and CRM design.
Processor obligations
The amending Act imposes direct obligations on data processors (previously most obligations sat with the data user). Marketing teams typically engage several processors: ESPs, ad platforms, analytics vendors, CDP vendors, agencies, freelancers. Contracts must reflect the amended allocation of responsibility, security requirements and breach cooperation obligations.
Vendor list
Maintain a live inventory of processors, their processing purposes, data categories and locations.
Contracts
Data processing terms reflecting the amended Act, including breach cooperation and cross-border basis.
Due diligence
Security assessments proportionate to the sensitivity of the data.
Ongoing oversight
Periodic review; termination and data return/destruction procedures.
Cross-border transfers
The Commissioner's CBPDT guideline sets out the mechanics for lawful transfer of personal data outside Malaysia. Marketers routinely trigger this: ad platforms, ESPs, CDPs and analytics tools frequently host data outside Malaysia. Document the destination, basis and safeguards for each transfer, and review when vendors change hosting regions.
Direct marketing
Consent per purpose
Marketing consent captured separately from analytics, personalisation, profiling and third-party sharing.
Notice at collection
Plain language, in the language of the form. Point of collection is not the footer of the site.
Right to withdraw
As easy as consent. Withdrawal must cascade to every downstream tool.
B2B contact data
Not outside PDPA merely because a person's role is professional. Treat business contact data with the same discipline.
For the field-by-field implementation, see PDPA-compliant landing page forms.
Cookies & trackers
Cookie banners are not a legal shield. Where cookies and similar technologies process personal data for purposes such as analytics, personalisation and advertising, obtain informed consent per purpose and honour withdrawal. Configure server-side tags and consent-mode integrations so that downstream tools observe consent state.
Retention
Define per purpose
Retention windows for marketing lists, analytics events, transactional records and support logs — each on its own clock.
Automate enforcement
Warehouse jobs and CDP retention rules should expire records automatically. Do not rely on quarterly clean-ups.
Document the reasoning
Be able to justify why 24 months (or whatever) is necessary for the purpose. "We might use it" is not a purpose.
Operational compliance workflow
1 · Register the purposes
List every marketing purpose and the personal data required for each. Retire what you no longer need.
2 · Design notice & consent
Purpose-specific notices at each collection surface, in appropriate languages. Consent captured, versioned and timestamped.
3 · Propagate & enforce
Consent state flows to every activation tool. Withdrawal cascades. Suppression audiences maintained.
4 · Vendors & transfers
Live vendor list, current contracts, documented cross-border basis for each processor location.
5 · Rights handling
Documented process for access, correction, withdrawal and portability requests, with SLAs and audit trail.
6 · Breach readiness
Incident playbook aligned to the DBN guideline. Tabletop exercises annually.
7 · Review
Quarterly review of purposes, retention and vendor list. Annual review of the whole programme.
Data subject rights in practice
- Access — provide a copy of the personal data held about the data subject, subject to permitted exceptions.
- Correction — correct inaccurate or out-of-date data.
- Withdrawal of consent — process the withdrawal and cease the processing that relied on it.
- Portability — provide data in a structured, machine-readable format where the amended Act applies.
Common failure modes
Consent theatre
Banners without downstream propagation. Legally weak, operationally broken.
Mystery vendors
Nobody can name every processor touching customer data. Fix the inventory first.
Blanket retention
"We keep everything forever" is not a policy. It is a risk.
Rights handling by email
Ad hoc, unmeasured, unauditable. Build a workflow.
Frequently asked questions
Which parts of the 2024 amendments are in force?
Provisions come into force on dates gazetted by the Minister. Check the current commencement determination for the authoritative list.
Do we need a DPO?
It depends on whether your organisation falls within the criteria set out in the Commissioner's DPO circular. Read it directly and, where the boundary is unclear, take legal advice.
When do we have to notify a breach?
Follow the thresholds and timeframes in the Commissioner's DBN guideline in force at the time of the incident.
Can we still use overseas SaaS?
Yes, subject to the CBPDT guideline. Document the transfer basis, the destination and the safeguards in place.
Does PDPA apply to B2B contacts?
Where personal data is processed in the course of a commercial transaction, yes. A professional email address is still personal data.
Is this legal advice?
No. This is operational guidance for marketing operations. Obtain qualified legal advice for your specific circumstances.
Related reading
PDPA-compliant landing page forms · Practical guide to CDPs · First-party data strategy · Data consulting Malaysia · Talk to us.
Sources & further reading
All sources retrieved 17 July 2026.
- Personal Data Protection Act 2010 (Act 709)
- Personal Data Protection (Amendment) Act 2024 (Act A1727)
- Commencement date determination
- DPO circular / guideline
- Data Breach Notification guideline
- Cross-Border Personal Data Transfer guideline
- Data Protection by Design guideline
- Application & non-application of the Act
